Optical fiber access network safety protection detection method and system based on AI abnormal mode identification

By using an AI-based anomaly pattern recognition method, anomaly pattern mapping relationships are generated and feature matching is tracked in real time. This addresses the shortcomings of traditional fiber optic access network security protection and detection methods, enabling intelligent security protection for fiber optic access networks and improving recognition accuracy and adaptability.

CN121462292APending Publication Date: 2026-02-03SHANDONG ZHIGUANG COMM TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511726643.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

Traditional security protection and detection methods for fiber optic access networks are inadequate for identifying new security threats and lack dynamic analysis and adaptability, resulting in a decline in the efficiency and accuracy of security protection and detection.

Method used

By employing an AI-based anomaly pattern recognition method, the system obtains the correlation between the operating characteristics of the fiber optic access network and a preset anomaly pattern library, generates anomaly pattern mapping relationships, tracks feature matching in real time, and dynamically adjusts matching parameters in conjunction with historical risk records and a protection strategy library to achieve intelligent security protection for the fiber optic access network.

Benefits of technology

It improves the accuracy and adaptability of security protection for fiber optic access networks, enabling timely detection of potential anomalies, adaptive response to changes in the network environment, and significantly enhanced protection effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462292A_ABST
    Figure CN121462292A_ABST
Patent Text Reader

Abstract

The invention provides an optical fiber access network security protection detection method and system based on AI abnormal mode recognition, and relates to the technical field of security, and the method comprises the steps: firstly obtaining the operation characteristics of an optical fiber access network and a preset abnormal mode library, and analyzing the association condition through an AI abnormal mode recognition model to generate an abnormal mode mapping relation; carrying out abnormal mode matching processing based on the mapping relation to obtain a matching result containing the matching point, the difference point and the matching degree; according to a matching result and a security risk level corresponding rule, determining a current security risk type in combination with a historical risk processing record; generating a security protection instruction in combination with the security risk type and a preset protection strategy library; matching parameters in the abnormal mode mapping relation are dynamically adjusted according to the instruction execution effect and fed back to a matching processing link, and efficient and intelligent protection detection on the safety of the optical fiber access network is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically, to a method and system for security protection and detection of fiber optic access networks based on AI-based anomaly pattern recognition. Background Technology

[0002] With the rapid development of fiber optic access networks, network security issues are becoming increasingly prominent. As a critical infrastructure for information transmission, a security threat to fiber optic access networks can lead to serious consequences such as massive data transmission interruptions and information leaks, affecting the normal communication and business operations of numerous users.

[0003] Currently, traditional fiber optic access network security detection methods mainly rely on preset fixed rules and thresholds. These methods typically monitor known and simple security threats, determining network anomalies by setting specific parameter ranges. However, with the increasing diversification and complexity of network attacks, new security threats are constantly emerging, making it difficult for traditional detection methods to comprehensively and accurately identify these anomaly patterns. For example, some covert attack behaviors may not trigger preset thresholds, leading to the failure to detect security vulnerabilities in a timely manner. Furthermore, traditional methods lack the ability to dynamically analyze and adapt to anomaly patterns, failing to adjust detection strategies based on real-time changes in network operating status, significantly reducing the efficiency and accuracy of security detection. Summary of the Invention

[0004] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide a security protection detection method for fiber optic access networks based on AI anomaly pattern recognition, the method comprising:

[0005] The system acquires the operating characteristics of the fiber optic access network and a preset abnormal pattern library. It then uses an AI abnormal pattern recognition model to analyze the correlation between the operating characteristics of the fiber optic access network and the pattern characteristics in the preset abnormal pattern library, and generates an abnormal pattern mapping relationship.

[0006] Anomaly pattern matching is performed on the operating characteristics of the fiber optic access network based on the anomaly pattern mapping relationship. By tracking the feature matching situation in real time, anomaly pattern matching results containing matching points, difference points and matching degree are obtained.

[0007] Based on the anomaly pattern matching results and the corresponding rules for the security risk level of the fiber optic access network, and in conjunction with historical risk handling records, the current security risk type of the fiber optic access network is determined.

[0008] By combining security risk types with a pre-defined protection strategy library, security protection instructions for the current security risks are generated through strategy adaptation analysis.

[0009] Based on the execution effect of the security protection instructions, the matching parameters in the abnormal mode mapping relationship are dynamically adjusted, and the adjusted matching parameters are fed back to the abnormal mode matching and processing stage.

[0010] In another aspect, embodiments of the present invention also provide a security protection and detection system for fiber optic access networks based on AI anomaly pattern recognition, including a processor and a machine-readable storage medium connected to the processor. The machine-readable storage medium is used to store programs, instructions, or code, and the processor is used to execute the programs, instructions, or code in the machine-readable storage medium to implement the above-described method.

[0011] Based on the above, this invention achieves in-depth analysis of the operational characteristics of the fiber optic access network and precise location of abnormal patterns by acquiring the operational characteristics of the fiber optic access network and a preset abnormal pattern library, and using an AI abnormal pattern recognition model to analyze the correlation between the two and generate an abnormal pattern mapping relationship. Based on this mapping relationship, abnormal pattern matching processing is performed, and the matching results are obtained by tracking feature matching in real time, enabling the discovery of potential anomalies in the network. According to the matching results and the corresponding rules for security risk levels, combined with historical risk processing records, the current security risk type is determined, improving the accuracy and reliability of risk identification. Security protection instructions are generated by combining the security risk type with a preset protection strategy library, allowing for targeted protection against security risks. Simultaneously, the matching parameters in the abnormal pattern mapping relationship are dynamically adjusted based on the execution effect of the security protection instructions and fed back to the matching processing stage, enabling adaptive responses to constantly changing network environments and security threats, significantly improving the intelligence level and protection effect of fiber optic access network security protection detection. Attached Figure Description

[0012] Figure 1 This is a schematic diagram of the execution flow of the fiber optic access network security protection and detection method based on AI anomaly pattern recognition provided in an embodiment of the present invention.

[0013] Figure 2 This is a schematic diagram of exemplary hardware and software components of the fiber optic access network security protection and detection system based on AI anomaly pattern recognition provided in an embodiment of the present invention. Detailed Implementation

[0014] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating a fiber optic access network security protection and detection method based on AI anomaly pattern recognition, provided in one embodiment of the present invention. The following is a detailed description of this fiber optic access network security protection and detection method based on AI anomaly pattern recognition.

[0015] Step S110: Obtain the operating characteristics of the optical fiber access network and the preset abnormal mode library, analyze the correlation between the operating characteristics of the optical fiber access network and the mode characteristics in the preset abnormal mode library through the AI ​​abnormal mode recognition model, and generate abnormal mode mapping relationship.

[0016] In this embodiment, the fiber optic access network in a core financial district of a city is used as the application scenario. This network covers multiple bank data centers, securities trading institutions, and financial regulatory departments, carrying critical businesses such as real-time transaction data transmission and fund clearing information exchange. Operational feature collection is achieved through dedicated collection devices deployed at various network layers, covering the entire data link from the core backbone network to the edge access network. Collection objects include optical power parameters of optical transmission equipment, bit error rate performance parameters of SDH equipment, port traffic parameters of Ethernet switches, and routing table update frequency parameters of routers. The collection process adopts a distributed architecture, with collection nodes set up in each computer room. Data transmission between nodes is conducted through encrypted VPN tunnels to ensure data security during transmission. The preset abnormal mode library is built based on financial industry network security standards and historical security events in the region. It includes various types such as physical layer failure modes caused by fiber optic cable breaks, application layer DDoS attack modes targeting trading systems, and LAN spoofing attack modes based on the ARP protocol. Each mode's features are stored in a structured data format, including metadata such as feature identifiers, feature data types, and feature association rules.

[0017] The AI ​​anomaly pattern recognition model employs a bidirectional long short-term memory (LSTM) network architecture based on an attention mechanism. This architecture effectively processes time-series feature data and captures long-term dependencies between key features. The model's input layer receives pre-processed fiber optic access network operation feature data, organized in a multi-dimensional time series format. The hidden layer consists of bidirectional LSM units, each containing an input gate, a forget gate, and an output gate, controlling the flow and retention of information through a gating mechanism. Following the hidden layers is an attention mechanism layer. This layer calculates the weight distribution of features at different time steps, enabling the model to focus on key time segments that contribute significantly to anomaly recognition. The output layer uses a fully connected structure, outputting the correlation probability values ​​corresponding to each anomaly pattern in a pre-defined anomaly pattern library.

[0018] Step S111: Extract key operational features related to security risks from the acquired optical fiber access network operational features. These key operational features cover features related to optical fiber access network data transmission rate, signal attenuation, data packet loss rate, and port connection stability.

[0019] The feature extraction process begins with data cleaning of the original operational feature data to remove outliers caused by acquisition equipment malfunctions or transmission interference. Outlier detection employs a statistical method, calculating the mean and standard deviation of the feature data. Data deviating from the mean by a certain multiple of the standard deviation is marked as outliers and imputed using linear interpolation. After data cleaning, feature selection is performed using a tree-based feature importance assessment method. By training a random forest model, the reduction in the Gini coefficient for each feature during the model's decision-making process is calculated, and this reduction is used as a measure of feature importance. Based on the feature importance ranking, the top-ranked features are selected as key operational features. These include: data transmission rate-related features such as average transmission rate and rate fluctuation variance over different time periods; signal attenuation-related features such as the attenuation of optical signals over different transmission distances and the rate of attenuation change; packet loss rate-related features such as packet loss rates for different protocol types and packet loss duration; and port connection stability-related features such as port connection establishment success rate and connection disconnection frequency.

[0020] Step S112: Perform feature association strength pre-calibration on the extracted key operational features. By comparing the association records of key operational features and risks in historical security events, adjust the association weight of each key operational feature. After adjustment, compare the risk identification accuracy of key operational features in historical security events. If the accuracy reaches the preset identification standard, the feature association strength pre-calibration is completed.

[0021] The feature association strength pre-calibration first constructs an association matrix between key operational features and historical security events. Rows in the matrix represent key operational features, columns represent historical security events, and matrix elements represent the degree of anomaly of the features during the event. The degree of anomaly is calculated by the deviation of the feature value from the normal range; the greater the deviation, the larger the matrix element value. Based on this association matrix, an association rule mining algorithm is used to calculate the support and confidence indices between each key operational feature and the security risk. Support represents the probability that feature anomaly and risk occurrence occur simultaneously, and confidence represents the probability that risk occurs under the condition of feature anomaly. Based on the magnitude of support and confidence, the association weights of each key operational feature are initially determined. Then, the association weights are applied to the historical security event dataset to simulate risk identification and calculate the identification accuracy. If the accuracy does not meet the preset identification standard, the gradient descent method is used to adjust the association weights, and the identification simulation is repeated until the accuracy meets the requirements. The preset identification standard is set according to the cybersecurity requirements of the financial industry, comprehensively considering the false positive rate and the false negative rate, and the optimal accuracy threshold is determined through ROC curve analysis.

[0022] Step S113: Parse the preset abnormal pattern library, extract the pattern features corresponding to each abnormal pattern in the preset abnormal pattern library, and construct a pattern feature classification index to classify the pattern features according to the risk impact range. The pattern features include the initial performance of the features when the abnormality occurs, the rate of feature change, and the stable state of the features.

[0023] During the parsing of the pre-defined anomaly pattern library, the structured storage file of the pattern library can be read to extract information such as the unique identifier, pattern name, and pattern feature description for each anomaly pattern. For feature extraction, based on the metadata information in the feature description, specific content in three aspects—initial feature behavior, feature change rate, and feature stable state—is located and extracted. Initial feature behavior refers to the range of feature values ​​or the description of the feature state at the initial stage of an anomaly; feature change rate refers to the speed at which the feature value changes from a normal state to an anomaly state, usually expressed as the change in feature value per unit time; feature stable state refers to the relatively stable range or state of the feature value after the anomaly occurs. The pattern feature classification index is constructed using a multi-level index structure. First, pattern features are divided into three categories according to the scope of risk impact: globally impacted patterns, regionally impacted patterns, and locally impacted patterns. Globally impacted patterns refer to anomaly patterns that may affect the normal operation of the entire fiber optic access network, such as a core router failure mode; regionally impacted patterns refer to anomaly patterns that affect the network function of a specific area, such as a failure mode of a certain aggregation node; locally impacted patterns refer to anomaly patterns that only affect individual users or devices, such as a single optical network unit failure mode. Within each category of impact, further subdivisions are made based on the type of abnormal pattern, creating a secondary index. The index information is stored in a relational database, allowing for quick retrieval of the corresponding pattern characteristics using the index keywords.

[0024] Step S114: Compare the pre-calibrated key operational features with the pattern features of each classified abnormal pattern one by one, and record the specific content, overlap range and overlap duration of the feature overlap in each comparison process.

[0025] The comparison process employs a sliding time window technique, dividing the time-series data of key operational features into multiple consecutive time windows. The length of each time window is determined based on the characteristic change cycle of the abnormal pattern. For the key operational feature data within each time window, it is compared with the pattern features of the abnormal pattern. The specific content of feature overlap refers to the matching between the key operational feature and the pattern feature in terms of feature name, feature data type, and feature value range; the overlap range refers to the proportion of key operational features that meet the pattern feature requirements out of the total number of features; the overlap duration refers to the number of consecutive time windows in which the key operational feature and the pattern feature remain in an overlapping state. During the comparison process, for numerical features, overlap is determined by whether the feature value falls within the value range of the pattern feature; for state features, overlap is determined by whether the feature state is consistent with the state described by the pattern feature. After each comparison, the specific content of the overlap, the overlap range, and the overlap duration are recorded in the comparison log. The log information includes metadata such as the comparison timestamp, key operational feature identifier, and abnormal pattern identifier.

[0026] Step S115: Based on the overlapping content, overlapping range, and overlapping duration of features, calculate the correlation degree between key operational features and each abnormal mode feature through a correlation degree calculation model; wherein, the correlation degree calculation model generates a single correlation degree index to reflect the closeness of the correlation between key operational features and each abnormal mode feature at the feature level and the consistency of the time sequence by comprehensively evaluating the matching degree of overlapping content in terms of type, the coverage of overlapping range in terms of degree, and the continuity of overlapping duration in terms of time sequence.

[0027] The correlation calculation model first quantifies the overlapping content, overlapping range, and overlapping duration of features. The type matching degree of overlapping content is obtained by calculating the ratio of the number of matched feature types to the total number of feature types; the higher the ratio, the higher the type matching degree. The coverage rate of the overlapping range is directly adopted from the overlapping range ratio calculated during the comparison process. The temporal continuity of the overlapping duration is obtained by calculating the ratio of the number of consecutive overlapping time windows to the total number of comparison time windows. After quantification, these three quantitative indicators are used as inputs to the correlation calculation model, and the correlation index is calculated by weighted summation. The weight coefficients are determined based on the importance of each quantitative indicator in the correlation assessment. A judgment matrix is ​​constructed using the analytic hierarchy process (AHP) to calculate the weight value of each indicator. The type matching degree weight reflects the importance of feature type consistency, the coverage rate weight reflects the importance of the overlapping range, and the temporal continuity weight reflects the importance of the duration of overlapping time. The correlation index ranges from 0 to 1; the closer the value is to 1, the higher the correlation between the key operational feature and the abnormal pattern feature.

[0028] Step S116: Based on the calculated correlation degree and combined with the pattern feature classification index, construct the correspondence between key operational features and abnormal patterns, and label the abnormal pattern, correlation degree and risk classification label corresponding to each key operational feature to form an abnormal pattern mapping relationship.

[0029] The abnormal pattern mapping relationship is constructed using a graph data structure, where nodes represent key operational features and abnormal patterns, and edges represent the association between key operational features and abnormal patterns. Each edge includes an association degree attribute and a risk classification label attribute. The association degree attribute value is the association degree index calculated in step S115; the risk classification label attribute is determined according to the risk impact range in the pattern feature classification index, and is divided into global risk label, regional risk label, and local risk label. The construction process first adds key operational features and abnormal patterns as two types of nodes to the graph, respectively. Then, based on the association degree calculation results, for key operational features and abnormal patterns with an association degree greater than a preset threshold, an edge is created between them, and the association degree attribute and risk classification label attribute of the edge are set. The preset threshold is determined based on the distribution of historical association degree data. By analyzing the difference in association degree values ​​between normal and abnormal states in historical data, a threshold that can effectively distinguish between normal and abnormal associations is selected. The abnormal pattern mapping relationship is stored in a graph database, supporting efficient association query and path analysis operations.

[0030] Step S120: Perform abnormal pattern matching processing on the operating characteristics of the optical fiber access network based on the abnormal pattern mapping relationship. By tracking the feature matching situation in real time, obtain the abnormal pattern matching result including the matching point, the difference point and the degree of matching.

[0031] The abnormal pattern matching process employs a real-time stream processing architecture. It receives real-time collected fiber optic access network operational characteristic data via a message queue and performs real-time matching between the operational characteristic data and the mapping relationship between abnormal patterns. The matching process utilizes a multi-threaded parallel processing mechanism, assigning different abnormal patterns to different processing threads, with each thread independently responsible for matching a specific type of abnormal pattern. Real-time tracking is achieved by setting log recording points at key nodes in the matching process, recording the results of each feature comparison, the specific information of the matching points, and the differences. Matching points refer to feature items that match the operational characteristics and abnormal pattern characteristics; differences refer to feature items that do not match the operational characteristics and abnormal pattern characteristics; the degree of matching is a quantitative evaluation indicator of the overall matching situation, comprehensively considering factors such as the number and importance of matching points and the number and importance of differences.

[0032] Step S121: Decompose the operation characteristics of the optical fiber access network into multiple characteristic units according to the characteristic type, so that each characteristic unit corresponds to the key operation characteristic type in the abnormal mode mapping relationship. At the same time, classify the importance of each characteristic unit and determine the classification result of each characteristic unit based on the contribution of historical risk identification.

[0033] Feature unit decomposition is performed based on the physical meaning and business logic of the features, grouping features belonging to the same category of business indicators or physical parameters into a single feature unit. For example, features related to data transmission rate, such as average transmission rate, peak transmission rate, and rate fluctuation variance, are grouped into a transmission rate feature unit; features related to signal attenuation, such as optical power attenuation and attenuation change rate, are grouped into a signal attenuation feature unit. Each feature unit corresponds to a key operational feature type in the anomaly pattern mapping relationship, ensuring a one-to-one correspondence between feature units and key operational feature types. Feature unit importance grading employs an evaluation method based on historical data, collecting data on the contribution of each feature unit in successfully identifying security risk events during historical risk identification processes. Contribution assessment is achieved by calculating the weight parameters of the feature unit in the risk identification model; a larger weight parameter indicates a higher contribution of the feature unit in the risk identification process. Based on the magnitude of contribution, feature units are divided into three levels: Level 1, Level 2, and Level 3. First-level feature units are those that contribute the most to risk identification, such as the packet loss rate feature unit, and are given the highest priority and weight in the abnormal pattern matching process; second-level feature units contribute the next most, such as the transmission rate feature unit; third-level feature units contribute relatively less, such as the port connection stability feature unit.

[0034] Step S122: For each feature unit, query the corresponding abnormal pattern and correlation in the abnormal pattern mapping relationship according to its importance classification result, determine the range of abnormal patterns that the feature unit may match, and adaptively set the matching threshold based on the classification result. For feature units whose historical risk identification contribution is higher than the preset contribution threshold, set their matching threshold to be lower than the matching threshold of other feature units.

[0035] The anomaly pattern range query is performed on the anomaly pattern mapping graph based on the feature unit's identifier. Through the graph database query interface, all anomaly pattern nodes connected to the feature unit node are retrieved; these nodes constitute the range of anomaly patterns that the feature unit may match. During the query process, the correlation attribute value of the edges between the anomaly pattern nodes and the feature unit nodes is simultaneously obtained as a reference for subsequent matching threshold setting. The adaptive setting of the matching threshold is based on the importance classification results of the feature units. For first-level feature units, due to their high contribution to risk identification, the matching threshold is set at a low level to capture as many possible anomalies as possible, allowing even anomaly patterns with relatively low correlation to enter the matching candidate set. For second-level feature units, the matching threshold is set at a medium level; for third-level feature units, the threshold is set at a high level, retaining only anomaly patterns with high correlation as candidates. The preset contribution threshold is determined through statistical analysis of historical risk identification contribution data. Feature units with a contribution higher than this threshold are identified as high-contribution feature units, and their matching thresholds are lowered accordingly.

[0036] Step S123: Perform feature detail comparison between each feature unit and the corresponding abnormal pattern in the range of abnormal patterns. First, compare the attributes in the feature unit that are directly related to risk identification, and then compare the attributes in the feature unit that assist in risk identification. Record the points of agreement and difference between the feature unit and each abnormal pattern at the two attribute levels.

[0037] Step S1231: Decompose the feature unit into a first type of attribute detail item and a second type of attribute detail item according to the degree of correlation between the attribute and risk identification. The first type of attribute detail item is the attribute whose contribution in historical risk identification is higher than the preset contribution threshold, and the second type of attribute detail item is the attribute whose contribution in historical risk identification is lower than the preset contribution threshold. At the same time, assign a weight to each detail item, and the weight value is proportional to the contribution of the attribute in historical risk identification.

[0038] The attribute decomposition process first assesses the historical risk identification contribution of each attribute within a feature unit. The assessment method is similar to the feature unit importance classification, determining the contribution by analyzing the weight parameters of the attribute in the historical risk identification model. A preset contribution threshold is set based on the overall distribution of attribute contributions. Attributes with contributions above this threshold are classified as first-category attribute details; these are key attributes directly related to risk identification, such as the average packet loss rate attribute in the packet loss rate feature unit. Attributes with contributions below this threshold are classified as second-category attribute details; these are attributes that assist in risk identification, such as the packet loss rate variance attribute in the packet loss rate feature unit. The weight allocation for attribute details uses a normalization method, dividing the contribution value of each attribute by the sum of all attribute contribution values ​​to obtain a normalized weight value, ensuring that the sum of all weight values ​​is 1. The weight value reflects the importance of each attribute in the feature detail comparison process; the higher the weight value, the greater the influence in judging the matching and difference points.

[0039] Step S1232: For each first-category attribute detail item, query the standard representation, standard value range, and allowable fluctuation range of the first-category attribute detail item in the corresponding abnormal mode. At the same time, combine the actual matching deviation of the first-category attribute detail item in the historical matching records to dynamically correct the standard value range.

[0040] Standard representation query is achieved by accessing a preset anomaly pattern library. Based on the anomaly pattern identifier and attribute detail item identifier, the library retrieves the standard data format, unit, precision, and other representation information of the attribute under the anomaly pattern. The standard numerical range refers to the typical value range of the attribute when the anomaly pattern occurs, and the allowable fluctuation range refers to the allowable upward and downward fluctuation range based on the standard numerical range. Historical matching record analysis collects the deviations between the actual values ​​of the first type of attribute detail item and the standard numerical range in past matching processes, and calculates the mean and variance of the deviations. Dynamic correction is achieved by adjusting the upper and lower limits of the standard numerical range by a certain proportion towards the deviation mean. The adjustment proportion is determined by the magnitude of the deviation variance; the larger the variance, the smaller the adjustment proportion to avoid over-correction; the smaller the variance, the larger the adjustment proportion, making the standard numerical range closer to the actual matching situation. The dynamically corrected standard numerical range is stored in a cache for current feature detail comparison, and the correction results are periodically fed back to the preset anomaly pattern library for updates.

[0041] Step S1233: Compare the actual performance of the first type of attribute detail item in the feature unit with the corrected standard performance form, standard value range and allowable fluctuation range, and determine whether the actual performance meets the requirements. If it does, record the first type of attribute detail item as the first type of matching point, and record the specific content and degree of matching.

[0042] The comparison process first checks whether the actual value conforms to the standard value, including data format, units, and precision. If the formats are inconsistent, it is directly judged as a mismatch; if the formats are consistent, it is further judged whether the actual value is within the corrected standard value range. If the actual value is within the standard value range, it is judged as a match; if the actual value exceeds the standard value range, but the excess is within the allowable fluctuation range, it is also judged as a match; if it exceeds the allowable fluctuation range, it is judged as a mismatch. The degree of match is calculated based on the deviation of the actual value from the center value of the standard value range; the smaller the deviation, the higher the degree of match. The specific content of the match includes attribute identifiers, actual values, standard value ranges, allowable fluctuation ranges, etc., and this information, along with the degree of match, is recorded in the match point log.

[0043] Step S1234: If the actual performance of the first type of attribute detail item does not meet the requirements, record the first type of attribute detail item as the first type of difference point, and record the specific content of the difference, the difference value and the possible reasons for the difference, and mark the first type of difference point as an important point.

[0044] The specific details of the discrepancies include attribute identifiers, actual representation formats, actual values, standard representation formats, and standard value ranges. Comparing this information clarifies the differences. For numerical attributes, the difference between the actual value and the boundary of the standard value range is calculated; for non-numerical attributes, a type mismatch indicator is used. The analysis of possible causes of the discrepancies is based on historical failure cases and expert experience databases. By matching the discrepancy characteristics with those in historical cases, potential causes such as equipment hardware failures, transmission link interference, and incorrect configuration parameters are identified. The first type of discrepancies is highlighted using special symbols and color coding. In subsequent matching assessments and risk type determination, the impact of these discrepancies on the overall matching results is given special attention.

[0045] Step S1235: For each second-category attribute detail item, query the standard performance form and allowable deviation range of the second-category attribute detail item in the corresponding abnormal mode, compare the actual performance of the second-category attribute detail item in the feature unit with the standard requirements, and determine whether it meets the requirements.

[0046] The standard representation and allowable deviation range query method for the details of the second type of attribute are similar to those of the first type of attribute, and are obtained from a preset abnormal pattern library. Since the second type of attribute is an auxiliary risk identification attribute, its allowable deviation range is usually set wider than that of the first type of attribute. The comparison process also first checks the consistency of the representation, and then determines whether the actual value is within the allowable deviation range. The allowable deviation range can be a fixed numerical interval or a percentage range relative to the standard value.

[0047] Step S1236: If the actual performance of the second type of attribute detail item meets the requirements, then record the second type of attribute detail item as the second type of matching point; if it does not meet the requirements, then record it as the second type of difference point, and at the same time record the corresponding matching content or difference content.

[0048] The matching information includes attribute identifiers, actual values, and allowable deviation ranges; the difference information includes attribute identifiers, actual values, allowable deviation ranges, and difference types (out of range or inconsistent format). The recording format for the second type of matching and difference points is consistent with that of the first type, but in the subsequent matching degree assessment, their weight is lower than that of the first type of matching and difference points.

[0049] Step S1237: Summarize all first-type matching points, first-type difference points, second-type matching points, and second-type difference points, classify and organize them according to attribute type, and form a feature detail comparison record table.

[0050] The feature detail comparison record table adopts a structured data format, including metadata such as comparison record identifier, feature unit identifier, anomaly pattern identifier, and comparison timestamp, as well as a detailed list of various matching points and differences. Each matching point or difference entry in the list includes information such as attribute detail item identifier, type (Category 1 / Category 2), matching / difference status, specific content, degree of matching (matching points only), and difference value (difference points only). Matching points and differences within the same attribute type (Category 1 or Category 2) are categorized separately, facilitating subsequent calculation of matching and difference statistical indicators for various attributes. The feature detail comparison record table is stored in a relational database, supporting querying and statistical analysis by feature unit, anomaly pattern, time, and other dimensions.

[0051] Step S124: Count the number of matching points of the two types of attributes and the total number of differences for each abnormal pattern. Combine the correlation degree and the importance classification results of the feature units in the abnormal pattern mapping relationship, and use a weighted calculation model to comprehensively judge the overall degree of consistency between the abnormal pattern and the operating characteristics of the optical fiber access network. Before the comprehensive calculation, the weighted calculation model standardizes the number of matching points, the number of differences, the correlation degree and the importance classification results to generate a degree of consistency evaluation value.

[0052] The statistical process summarizes the data in the feature detail comparison record table, groups them according to anomaly patterns, and calculates the number of first-type attribute matching points, second-type attribute matching points, first-type attribute difference points, and second-type attribute difference points for each anomaly pattern. The total number of difference points is the sum of the number of first-type and second-type attribute difference points. Standardization transforms each indicator value to a uniform dimensionless interval, typically [0,1]. For the number of matching points, standardization is performed by dividing the number of matching points under that anomaly pattern by the total number of attribute detail items under that pattern; for the number of difference points, standardization is performed by subtracting (the number of difference points divided by the total number of attribute detail items) from 1 to obtain the difference suppression index; the correlation index is already in the [0,1] interval and does not require standardization; the feature unit importance classification results are converted into corresponding values, such as 1 for level 1, 0.7 for level 2, and 0.4 for level 3. The weighted calculation model multiplies the standardized number of matching points, difference suppression index, correlation index, and importance classification values ​​by their respective weight coefficients, and then sums them to obtain the overall matching degree evaluation value. The weighting coefficients are determined using the analytic hierarchy process, taking into account the importance of each indicator in the assessment of the degree of agreement. The weights of correlation and the number of agreement points of the first type of attribute are usually set higher.

[0053] Step S125: Based on the overall degree of matching, filter out the abnormal patterns that meet the preset conditions. Integrate the filtering results with the corresponding degree of matching, the matching points of the two types of attributes, the differences, and the weighted calculation basis to form the abnormal pattern matching results.

[0054] The preset conditions are set according to business needs and security policies, typically including a matching score greater than a preset threshold, and the proportion of matching points of the first type of attribute to the total number of first type attributes being greater than a preset proportion threshold. The screening process judges the overall matching score of each anomaly pattern and selects anomaly patterns that meet the preset conditions as matching candidate patterns. The integration process combines the candidate anomaly pattern's identifier, matching score, lists of matching points of the first and second types of attributes, a list of differences, and the standardized values ​​and weight coefficients of each indicator in the weighted calculation process to form a structured anomaly pattern matching result. The matching result is encapsulated in JSON format for easy parsing and processing by subsequent modules.

[0055] Step S130: Based on the abnormal pattern matching results and the corresponding rules for the security risk level of the fiber optic access network, and in conjunction with historical risk handling records, determine the current security risk type of the fiber optic access network.

[0056] The rules for corresponding security risk levels in fiber optic access networks are formulated based on the financial industry's cybersecurity risk assessment standards. They clearly define the correspondence between different combinations of anomaly patterns, their degree of similarity, and scenario factors with security risk types and levels. The rules are represented in the form of a decision table. The condition section of the decision table includes anomaly pattern identifiers, degree of similarity ranges, and scenario labels, while the conclusion section includes the security risk type and risk level. Historical risk handling records contain detailed information about past security risk events, such as risk type, occurrence time, scope of impact, handling measures, and handling effects. The determination process first matches the anomaly patterns and degree of similarity in the anomaly pattern matching results with the condition section of the security risk level corresponding rules to initially determine the range of possible security risk types. Then, it queries historical risk handling records for risk events similar to the current anomaly pattern and scenario, analyzes the types and handling results of historical risk events, adjusts and verifies the initially determined range of risk types, and finally determines the current security risk type.

[0057] Step S131: Analyze the abnormal pattern matching results, extract the abnormal patterns that meet the preset conditions, extract the feature performance, risk impact range label and time sequence features corresponding to each abnormal pattern, and add a scene label to each abnormal pattern. The scene label is determined based on the network environment, time period and service type in which the abnormality occurred.

[0058] The parsing process analyzes the JSON data of the anomaly pattern matching results and extracts a list of anomaly patterns that meet preset conditions. For each anomaly pattern, its corresponding feature description is retrieved from a preset anomaly pattern library, including typical changes in each feature when the anomaly occurs. The risk impact scope label is obtained from the anomaly pattern mapping relationship, i.e., global risk, regional risk, or local risk label. The temporal features include information such as the anomaly start time, duration, and time sequence of feature changes, extracted from the timestamp data of the fiber optic access network's operational features. Scenario label generation comprehensively considers three factors: network environment, time period, and service type at the time of the anomaly. The network environment includes location information such as the core network, aggregation network, and access network; the time period includes peak hours on weekdays, off-peak hours on weekdays, and holidays; and the service type includes real-time transaction services, non-real-time data transmission services, and voice services. The format of the scenario label is "network environment-time period-service type," generated by combining the specific values ​​of the three factors, such as "aggregation network-peak hours on weekdays-real-time transaction services." Scenario labels are stored in association with anomaly pattern identifiers, serving as an important basis for subsequent risk type determination and protection strategy adaptation.

[0059] Step S132: Query the historical risk handling records of the fiber optic access network, extract the historical records that are consistent with the current abnormal mode scenario tags, organize the risk types, handling measures and handling effects in the historical records, and form a historical risk scenario mapping table.

[0060] Historical risk handling records can be queried via database queries. The query criteria are that the scenario label equals the current anomaly mode's scenario label, and the time range is limited to a recent period to ensure the timeliness of historical data. Extracted historical record fields include risk event identifier, risk type, occurrence time, handling measure description, handling start time, handling end time, and handling effect evaluation. Handling effect evaluations are typically categorized as "successfully resolved," "partially resolved," and "unresolved," each corresponding to different effectiveness levels. The historical risk scenario mapping table is grouped by risk type, summarizing historical records for the same risk type and calculating the frequency of occurrence, commonly used handling measures, and average handling effect level for that risk type under that scenario label. The mapping table is organized in tabular form, containing columns for risk type, frequency of occurrence, main handling measures, and average handling effect, facilitating intuitive comparison of historical handling performance for different risk types.

[0061] Step S133: Obtain the security risk level correspondence rules of the fiber optic access network. These rules clarify the correspondence between different anomaly modes, scenario labels and security risk types and risk impact scope, and also include the priority ranking of risk types under different scenarios.

[0062] The rules corresponding to security risk levels are stored in rule files, which are in XML or JSON format for easy parsing and maintenance. Each rule contains multiple rule entries, and each entry consists of two parts: conditions and conclusions. The conditions include a list of anomaly pattern identifiers, scenario tags, and the range of similarity; the conclusions include the security risk type, the scope of risk impact, and the risk level. The priority of risk types in different scenarios is determined by the severity, scope of impact, and urgency of handling. Risk types with higher severity, wider impact, and more urgent handling have higher priority. Priority ranking information is stored as an additional attribute of the rule. When multiple risk types simultaneously meet the rule conditions, the final risk type is determined based on the priority ranking.

[0063] Step S134: Compare the abnormal patterns and scene tags in the abnormal pattern matching results with the corresponding rules for the security risk level of the fiber optic access network, find out the preliminary range of security risk types corresponding to the abnormal patterns and scene tags in the corresponding rules for the security risk level of the fiber optic access network, and at the same time, perform preliminary screening of the preliminary range of security risk types by combining the historical risk scene mapping table.

[0064] The comparison process iterates through each rule entry in the rules corresponding to the security risk level, checking whether the abnormal pattern and scenario label in the current abnormal pattern matching result meet the conditions of the rule entry. If they do, the security risk type in the conclusion part of that rule entry is added to the preliminary scope. Preliminary screening is based on information from the historical risk scenario mapping table. For each security risk type in the preliminary scope, it is checked whether there is a corresponding historical record in the historical risk scenario mapping table, and whether the historical processing effect meets certain standards. If a risk type has never appeared in the historical record, or if the historical processing effect is generally poor, it is removed from the preliminary scope to reduce the number of candidate risk types for subsequent processing.

[0065] Step S135: Analyze the matching points and differences in the abnormal pattern matching results, compare the feature differences of similar scenarios in the historical risk scenario mapping table, and determine the degree of fit between the current abnormal pattern and each security risk type in the preliminary range of security risk types; wherein, the determination of the degree of fit is achieved by constructing a multi-factor evaluation model. This multi-factor evaluation model quantifies and standardizes the evaluation factors of three different dimensions: feature matching degree, scenario consistency, and historical processing effect, and integrates them based on preset rules to generate a quantitative index reflecting the overall level of fit.

[0066] Feature matching is calculated based on the matching degree evaluation value in the abnormal pattern matching results. This value has been standardized to the [0,1] range and is directly used as the quantitative value of feature matching. Scene consistency is achieved by comparing the similarity between the current scene label and the scene label in the historical risk scene mapping table. The higher the similarity, the larger the quantitative value of scene consistency. Historical processing effect quantification converts the processing effect level in the historical risk scene mapping table into numerical values, such as "successfully resolved" into 1, "partially resolved" into 0.5, and "unresolved" into 0. Then, the average processing effect value of this risk type under similar scenarios is calculated as the quantitative value of historical processing effect. The multi-factor evaluation model sums the three quantitative indicators according to preset weights. The weights are determined according to the importance of each factor to the degree of fit. Feature matching usually has the highest weight, followed by scene consistency, and finally historical processing effect. The comprehensive quantitative indicator is the degree of fit evaluation value, with a value range of [0,1]. The higher the value, the higher the degree of fit between the current abnormal pattern and the security risk type.

[0067] Step S136: Determine the current security risk type of the fiber optic access network according to the adaptation degree and the priority ranking in the rules corresponding to the security risk level of the fiber optic access network. At the same time, record the matching points, differences, historical records and priority ranking results used in the determination process to form the basis for determining the security risk type.

[0068] The determination process begins by sorting the risk types within the initial scope of security risk types according to their suitability evaluation values ​​from highest to lowest. If the suitability values ​​are the same, a secondary sorting is performed based on the priority ranking in the fiber optic access network security risk level correspondence rules. The risk type ranked first is selected as the current security risk type. A detailed record of the decision-making process is maintained, including the calculation process of the suitability evaluation values ​​for each risk type, key information on characteristic matching points and differences, comparative analysis results of historical risk handling records, and the specific basis for priority ranking. The determination basis is stored in document form for easy subsequent auditing and traceability.

[0069] Step S1361: Extract the first type of matching point, the first type of difference point, the second type of matching point, and the second type of difference point from the abnormal pattern matching results, and count the number of feature dimensions involved in the first type of matching point, the first type of difference point, the second type of matching point, and the second type of difference point.

[0070] The feature dimension count involves deduplicating and counting the attribute details in each type of match and discrepancy point. Each distinct attribute detail represents a feature dimension. For example, if the first type of match involves two distinct attribute details—average packet loss rate and packet loss duration—then the first type of match involves 2 feature dimensions. The statistical process iterates through all attribute entries in the feature detail comparison record table, deduplicates them using attribute identifiers, and then counts the number of each feature dimension.

[0071] Step S1362: Based on the contribution weight of each feature dimension in historical risk identification, perform weighted calculation on the number of statistical dimensions to obtain the first type of matching weighted value, the first type of difference weighted value, the second type of matching weighted value, and the second type of difference weighted value. During the weighted calculation, the feature dimension weight value corresponding to the first type of attribute detail item is higher than the feature dimension weight value corresponding to the second type of attribute detail item.

[0072] The weighted calculation multiplies the number of each feature dimension by its contribution weight, and then sums the results to obtain the weighted value. The contribution weights are obtained from the feature importance assessment results of the historical risk identification model. The feature dimension weights corresponding to the details of the first type of attribute are pre-set to be higher than those corresponding to the details of the second type of attribute to reflect the importance of the first type of attribute. For example, if the first type of match involves two feature dimensions with weights of 0.6 and 0.5 respectively, and a quantity of 1 for each, then the weighted value for the first type of match is 0.6 × 1 + 0.5 × 1 = 1.1; if the second type of match involves one feature dimension with a weight of 0.3 and a quantity of 1, then the weighted value for the second type of match is 0.3 × 1 = 0.3.

[0073] Step S1363: Query the historical risk scenario mapping table, extract historical records that are consistent with the current abnormal mode scenario label, organize the first type of matching features, the first type of difference features and the adaptation results corresponding to each security risk type under the same scenario in the historical records, and form a historical feature comparison library.

[0074] The historical feature comparison database is categorized by security risk type. Each risk type entry includes a list of first-category matching features, a list of first-category discrepancies, and adaptation result statistics for similar scenarios. The first-category matching feature list records the matching status of first-category attribute details when this risk type occurred historically, including attribute identifiers and typical matching value ranges. The first-category discrepancy feature list records the differences in first-category attribute details. The adaptation result statistics include the number of times this risk type was correctly identified and the number of times it was misidentified in similar scenarios. The historical feature comparison database provides historical feature references for judging the degree of adaptation between current anomaly patterns and security risk types.

[0075] Step S1364: Compare the first type of matching points and the first type of difference points of the current abnormal pattern with the first type of matching features and the first type of difference features of the same scene in the historical feature comparison library, and calculate the similarity between the two in terms of feature dimension, feature value and feature change trend. In the similarity calculation process, the feature dimension corresponding to the first type of matching point is given a higher calculation weight.

[0076] Feature dimension similarity is calculated by the ratio of the number of intersections to the number of unions of the first-type matching feature dimensions between the current anomaly pattern and historical risk types; this is known as the Jaccard similarity coefficient. Feature numerical similarity is calculated for each common feature dimension by determining the relative deviation between the current feature value and the central value of the range of typical historical matching values; the average of these relative deviations is used as the numerical similarity index. Feature trend similarity is achieved by comparing the shape similarity between the current feature value's curve over time and the historical feature's curve. A dynamic time warping algorithm is used to calculate the distance between the curves; the smaller the distance, the higher the trend similarity. In the comprehensive similarity calculation, feature dimension similarity, numerical similarity, and trend similarity are multiplied by different weights, with feature dimension similarity having the highest weight. Furthermore, the feature dimension corresponding to the first-type matching point is given a higher weight coefficient in the dimension similarity calculation.

[0077] Step S1365: Evaluate the confidence level of the calculated similarity, and determine the reliability of the similarity results by combining the number of historical samples and the matching accuracy, and exclude similarity results whose confidence level does not reach the preset confidence threshold.

[0078] Similarity confidence assessment considers two factors: the number of historical samples and matching accuracy. A larger sample size results in more reliable statistical results and higher confidence. Matching accuracy refers to the proportion of correct identifications at a given similarity threshold historically; a higher proportion indicates higher confidence. Confidence is calculated by converting the sample size and matching accuracy into scores within the [0,1] interval and then weighting and summing them. The preset confidence threshold is set based on the business's requirements for risk identification accuracy; for scenarios with extremely high security requirements, such as the financial industry, the threshold is set relatively high. Similarity results with confidence below the threshold are marked as unreliable and are not considered in subsequent fit calculations.

[0079] Step S1366: Based on the similarity results and similarity confidence, and combined with the characteristic requirements of each security risk type in the preliminary range of security risk types, calculate the matching score between the current anomaly pattern and each security risk type; wherein, the calculation process of the matching score is as follows: the standardized intermediate indicators, such as the first type of matching weighted value, the second type of matching weighted value, the first type of difference weighted value, and the second type of difference weighted value, are combined according to the preset contribution ratio and deduction ratio to generate a final matching score for priority ranking.

[0080] Standardization transforms each weighted value to the [0,1] interval, placing it on the same scale as the similarity result and similarity confidence score. The contribution ratio defines the positive contribution proportion of the first-type and second-type matching weighted values ​​to the fit score, with the contribution proportion of the first-type matching weighted value being higher than that of the second-type matching weighted value. The deduction ratio defines the negative deduction proportion of the first-type and second-type difference weighted values ​​to the fit score, with the deduction proportion of the first-type difference weighted value being higher than that of the second-type difference weighted value. The formula for calculating the fit score is: Fit Score = (First-type matching weighted value × First-type contribution ratio + Second-type matching weighted value × Second-type contribution ratio) × Similarity result × Similarity confidence score - (First-type difference weighted value × First-type deduction ratio + Second-type difference weighted value × Second-type deduction ratio). This formula comprehensively considers factors such as matching, difference, similarity, and confidence score to generate the final fit score.

[0081] Step S1367: Sort the security risk types in the preliminary range of security risk types according to the adaptation score. The top K security risk types are output as the most suitable types for the current anomaly mode. At the same time, record the calculation basis of the adaptation score, the similarity result and the confidence assessment result to form an adaptation degree judgment report.

[0082] The K value is set according to actual business needs, typically 1 or 3. When K=1, the risk type with the highest score is directly selected as the most suitable type; when K=3, the top three risk types with the highest scores are output as candidates. The suitability assessment report records in detail the calculation process of the suitability score for each candidate risk type, including the standardized values ​​of each intermediate indicator, contribution ratio, deduction ratio, similarity results, confidence assessment results, etc. The report also compares and analyzes the characteristic matching points and differences of each candidate risk type, explaining the reasons for the score differences. The suitability assessment report serves as an important reference document for determining the current security risk type and is archived together with the basis for determining the security risk type.

[0083] Step S140: Combine the security risk type with the preset protection strategy library, and generate security protection instructions for the current security risk through strategy adaptation analysis.

[0084] A pre-defined protection strategy library stores protection measure templates corresponding to various security risk types, including technical measures, management measures, and emergency response procedures. Policy adaptation analysis retrieves suitable protection strategy templates from the library based on the currently identified security risk type and scenario tags, and adjusts and optimizes them according to the real-time operating status of the fiber optic access network. Each protection strategy template includes a policy identifier, applicable risk type, applicable scenario tags, protection target, protection measure steps, parameter configuration range, and execution conditions. The generated security protection commands are directly executable operation commands, containing information such as command identifier, target device identifier, operation type, parameter configuration values, and execution time window, and are issued to the corresponding network devices for execution via network management protocols.

[0085] Step S141: Query the preset protection strategy library, extract the corresponding protection strategy entries according to the current security risk type and scenario label. Each protection strategy entry includes protection target, protection measures, implementation steps and applicable scenario scope.

[0086] The protection policy database query is achieved through the search function of the policy management system. Search criteria include a security risk type equal to the currently identified security risk type, and applicable scenario tags containing the scenario tags of the current abnormal mode. Search results are sorted by policy priority and version number, selecting the latest high-priority policy entries. The protection objective clearly defines the security effect the policy aims to achieve, such as "preventing DDoS attack traffic from entering the core network" or "restoring service interruptions caused by fiber optic cable breaks." Protection measures are the specific technical or management methods to achieve the protection objective, such as "configuring ACL access control lists," "activating backup fiber optic links," or "notifying maintenance personnel for on-site repairs." Implementation steps describe the execution flow of the protection measures, outlining the sequence and specific content of operations chronologically. The applicable scenario scope further clarifies the specific scenarios in which the policy is applicable, such as specific network topologies or specific device models.

[0087] Step S1411: Access the storage location of the preset protection policy library, call the protection policy index stored in the preset protection policy library. The protection policy index is organized into secondary categories according to security risk type and scenario tag, and also includes the update time and version information of the protection policy entries.

[0088] The default protection policy library adopts a distributed storage architecture, deployed across multiple storage nodes, and provides services through a unified access interface. Access to storage locations is achieved through the storage node IP address and port number specified in the configuration file, using a load balancing algorithm to select the appropriate storage node for access. The protection policy index uses a B+ tree index structure, with the first-level index key representing the security risk type and the second-level index key representing the scenario label. Each index entry contains a pointer to the protection policy entry data block, the policy entry's update time, and its version number. The update time records the timestamp of the last modification to the policy entry, and the version number uses semantic versioning, such as "V1.2.0," facilitating the tracking of policy iteration history. The protection policy index is loaded into memory, supporting fast index lookups and range queries.

[0089] Step S1412: Perform dynamic update verification on the called protection policy index, compare the update time of the protection policy entries in the protection policy index with the update time of the latest protection policy entries in the preset protection policy library. If there is a difference, update the protection policy index synchronously to make the protection policy index consistent with the protection policy entries in the preset protection policy library.

[0090] The dynamic update verification of the index is performed periodically, with the verification cycle set according to the update frequency of the policy library. The verification process iterates through each entry in the protection policy index, comparing its update time with the current update time of the corresponding policy entry in the preset protection policy library. If the update time in the index is earlier than the latest update time in the library, it indicates that the policy entry has been modified or updated. The latest policy entry information, including update time, version number, and data pointer, needs to be retrieved from the library to update the corresponding entry in the protection policy index. If a new policy entry exists in the library but is not in the index, a new index entry is added. Through dynamic update verification, it is ensured that the protection policy index always remains consistent with the latest state of the preset protection policy library, avoiding policy retrieval errors due to index obsolescence.

[0091] Step S1413: Based on the current security risk type, search for the primary category directory in the protection strategy index, and then search for the secondary category directory under the primary category directory based on the scenario tag, and determine the identifiers of all protection strategy entries under the secondary category directory.

[0092] The primary category search matches the security risk type identifier against the primary index key of the protection policy index to find the corresponding primary category node. The secondary category search, under the primary category node, matches the scenario tag identifier against the secondary index key to find the corresponding secondary category node. The secondary category node stores a list of all protection policy entry identifiers under that security risk type and scenario tag combination. Each entry identifier is a unique string or numeric code that identifies a protection policy entry. After determining the list of entry identifiers, the data pointer in the index item is used to locate the specific protection policy entry data stored in the preset protection policy library.

[0093] Step S1414: Based on the protection strategy item identifier, retrieve the corresponding protection strategy item content from the preset protection strategy library. During the retrieval process, check whether the protection strategy item content includes protection objectives, protection measures, implementation steps, and applicable scenario scope. If any are missing, supplement them from the preset protection strategy library.

[0094] The content retrieval of protection policy entries involves reading data blocks from distributed storage nodes using entry identifiers and data pointers, and parsing these data blocks into structured policy entry objects. Content verification uses field validation to confirm that the policy entry object contains all required fields: protection objective, protection measures, implementation steps, and applicable scenario scope. If a field is missing, the system checks if a historical version of the entry or related supplementary information exists in the preset protection policy library. If it does, the system attempts to extract the missing field content from the supplementary information; if it cannot be supplemented, the policy entry is marked as incomplete, and the missing field information is recorded. In subsequent policy effectiveness pre-assessment, its priority is reduced or it is directly excluded.

[0095] Step S1415: Compare the version information of the protection policy entry with the latest version information in the preset protection policy library. If it is an older version, retrieve the latest version from the preset protection policy library to replace it. After replacement, check the version consistency again.

[0096] The version information comparison compares the version number of the currently retrieved protection policy entry with the latest version number of the corresponding entry in the preset protection policy library. If the current version number is lower than the latest version number, the latest version of the policy entry is retrieved from the library to replace the old version. After replacement, the version number of the replaced entry is checked again to ensure that it matches the latest version number, thus ensuring successful version replacement. For policy entries with version dependencies, such as a main policy entry referencing multiple sub-policy entries, the version information of all related entries needs to be checked simultaneously to ensure version compatibility between the main and sub-entries.

[0097] Step S1416: Sort the complete and consistent protection strategy entries according to the priority of the protection target. The priority is determined based on the degree of protection of the core business and the urgency of implementation of the protection strategy entries, forming an ordered list of protection strategy entries.

[0098] The priority assessment of protection targets considers two factors: the degree of protection for core services and the urgency of implementation. The degree of protection for core services is determined by the importance level of the service systems protected by each policy item within the overall network; the higher the importance level, the higher the priority. The urgency of implementation is determined by the time limit for handling security risks; the shorter the time limit, the higher the urgency. Priority assessment uses a scoring system, scoring both factors separately and then weighted and summing the scores to obtain a priority score. Protection policy items are then sorted from highest to lowest priority score to form an ordered list of protection policy items. In subsequent policy effectiveness pre-assessment and applicability judgment, these items are processed in this order, with higher-priority policy items being evaluated first.

[0099] Step S142: Conduct a pre-assessment of the effectiveness of the extracted protection strategy items, combine the implementation effects of similar protection strategy items in historical risk handling records, calculate the effectiveness probability of each protection strategy item, and exclude protection strategy items whose effectiveness probability does not reach the preset standard.

[0100] The strategy effectiveness pre-assessment is based on historical data statistics, collecting the number of times the protection strategy item was successfully resolved for security risk events and the total number of uses in historical risk handling records. The effectiveness probability is calculated by dividing the number of successful resolutions by the total number of uses. Preset standards are set according to the severity of security risks. For high-severity risk types, the effectiveness probability standard is set higher to ensure that the selected strategy can reliably address the risk; for low-severity risk types, the standard can be appropriately lowered. Strategy items with an effectiveness probability lower than the preset standard are excluded to reduce the selection of ineffective strategies.

[0101] Step S143: Analyze the characteristics, scope of impact, and real-time network operating status of the current security risk type, determine the applicability of the remaining protection policy items, check the compatibility of the implementation steps of the protection policy items with the current network operating status, and eliminate protection policy items that conflict with the current network status.

[0102] Real-time network operating status is obtained through a network monitoring system, including parameters such as device load rate, link bandwidth utilization, service traffic distribution, and critical service operating status. Applicability assessment analyzes whether the implementation steps of the protection strategy items match the current real-time network operating status. For example, if a protection strategy requires a large amount of bandwidth resources, but the current link bandwidth utilization is nearing saturation, then the strategy conflicts with the network state and is not feasible for implementation. Conflict checks also include the compatibility of protection measures with existing network configurations, such as whether ACL rules conflict with existing rules, and whether adjustments to routing policies will cause routing loops. Conflicting protection strategy items are eliminated to ensure that the selected strategy can be implemented securely and smoothly.

[0103] Step S144: Make detailed adjustments to the remaining applicable protection strategy items, adjust the parameter settings of the protection measures according to the specific characteristics of the current security risks, and adjust the execution order and duration of the implementation steps according to the real-time network service load.

[0104] Parameter adjustments are determined based on the specific characteristics of the current security risks. For example, for DDoS attack risks, the filtering thresholds and rate limiting parameters of the traffic scrubbing equipment are adjusted according to the size and source of the attack traffic; for signal attenuation risks, the gain parameters of the optical amplifier are adjusted according to the amount of attenuation. The parameter adjustment range refers to the parameter configuration range in the protection strategy template to ensure that the adjusted parameters are within a safe and effective range. The execution order of implementation steps is adjusted based on the real-time network service load, using a priority scheduling algorithm to prioritize steps with less impact on critical services, or to execute steps that may affect services during periods of low service load. The execution time is adjusted based on the complexity of the steps and the processing capacity of the network equipment, estimating the execution time of each step and dynamically adjusting it based on real-time monitoring data to ensure that the protection strategy is implemented within the specified time.

[0105] Step S145: Perform policy conflict detection and resolution on the adjusted protection policy items. If there are multiple protection policy items, check the conflict points of the implementation steps between the protection policy items and determine the conflict resolution scheme by priority ranking.

[0106] Policy conflict detection employs a rule-based conflict detection algorithm to analyze conflicts such as resource contention and operational mutual exclusion between the implementation steps of different protection policy items. Resource contention conflicts occur when two policies simultaneously require modification of the same configuration parameter on the same device; operational mutual exclusion conflicts occur when one policy requires disconnecting a link, while another policy requires using that link to transmit backup traffic. The conflict resolution scheme is based on policy priority ranking, with preset policy priority rules. For example, for different policies of the same risk type, they are ranked from highest to lowest effective probability; for policies of different risk types, they are ranked from highest to lowest risk severity. High-priority policy items retain their implementation steps in the event of a conflict, while low-priority policy items modify or delete conflicting steps, or adjust their execution order to avoid conflict.

[0107] Step S146: Convert the adjusted and conflict-resolved protection strategy entries into executable operation instructions. Each operation instruction specifies the operation content, operation object, operation parameters, and operation time window.

[0108] Operation command translation maps protection measures into command formats recognizable by network devices, such as CLI commands, SNMPSet commands, and NETCONF protocol configuration data. The operation content describes the specific action, such as "configure ACL rules," "modify route metric values," or "start backup power." The operation object is the identifier of the network device, such as the device IP address, port number, or VLAN ID. The operation parameters are the specific values ​​required for command execution, such as the source IP address, destination port range, and route metric values ​​of the ACL rule. The operation time window refers to the time period during which the command is allowed to execute, determined based on network service load and the execution duration of policy implementation steps, such as "2023-10-01 02:00-04:00." Operation commands are encapsulated in a standardized format, including a command header, command body, and checksum. The command header contains metadata such as command identifier, version number, and priority; the command body contains execution information such as operation content, object, parameters, and time window; and the checksum ensures the integrity of the command during transmission.

[0109] Step S147: Integrate all operation instructions in the order of implementation, add judgment criteria for instruction execution effect and contingency plans for abnormal handling, and form security protection instructions for the current security risks.

[0110] The implementation sequence is integrated according to the implementation steps of the protection policy items and the execution order after conflict resolution, arranging the operation instructions into an ordered sequence. The criteria for judging the execution effect of each instruction clearly define the conditions for determining the success or failure of each instruction, such as "after configuring ACL rules, verify the existence of the rules and the correct parameters using the showaccess-list command" and "after modifying routes, verify route reachability using the ping command." The contingency plan for handling anomalies addresses potential failures during instruction execution, such as device unresponsiveness, instruction timeouts, and post-execution service anomalies, and formulates corresponding countermeasures, such as retrying instructions, rolling back configurations, and executing backup instructions. The security protection instruction sequence, the criteria for judging the execution effect, and the contingency plan for handling anomalies together constitute a complete security protection instruction set, which is issued to the network management system for execution through an encrypted channel.

[0111] Step S150: Based on the execution effect of the security protection command, dynamically adjust the matching parameters in the abnormal mode mapping relationship, and feed back the adjusted matching parameters to the abnormal mode matching processing stage.

[0112] The effectiveness evaluation of security protection command execution is achieved by monitoring changes in the operational characteristics of the fiber optic access network. Key operational characteristic data are collected before and after command execution, and the trends of these data are compared to determine whether security risks have been mitigated or eliminated. Dynamically adjusted matching parameters include the correlation threshold in the anomaly pattern mapping relationship, the importance ranking weight of feature units, and the matching threshold. Based on the evaluation results, if security risks are not effectively controlled, it indicates that the current matching parameters may be biased and need adjustment. The adjusted matching parameters are written to the graph database through the anomaly pattern mapping relationship update interface, and the anomaly pattern matching processing stage is notified in real time to update its parameter values, forming a closed-loop feedback mechanism.

[0113] Step S151: Monitor the execution process of security protection commands, collect the operating characteristics of the fiber optic access network at preset time intervals, record the changes in the operating characteristics of the fiber optic access network during the execution process, and record the rate and trend of change of characteristics related to security risks.

[0114] The execution process monitoring system tracks the execution status of security protection commands in real time through a network monitoring system, including whether the command was successfully issued, whether the target device has started execution, and the execution progress. The preset time interval for collecting operational features is set according to the rate of change of security risk characteristics. For rapidly changing risk types, such as DDoS attacks, the time interval is set shorter; for slowly changing risk types, such as signal attenuation due to fiber optic aging, the time interval is set longer. The collected operational features focus on key characteristics related to the current security risk, such as attack traffic, signal attenuation, and packet loss rate. The feature change rate is calculated as the ratio of the difference between two adjacent feature values ​​to the time interval; the change trend is determined by curve fitting of feature values ​​at multiple time points, judging the slope and magnitude of the curve to determine whether the feature is rising, falling, or stabilizing.

[0115] For example, in step S1511: before the security protection command is executed, multiple fiber optic access network operation characteristics are collected, and the stability verification algorithm is used to determine whether the multiple fiber optic access network operation characteristics are stable. If the multiple fiber optic access network operation characteristics are unstable, the collection time is extended until the characteristics are stable, and the stable characteristics are used as the baseline characteristics before execution.

[0116] Pre-execution baseline feature acquisition is conducted during a preparation period before the security protection command is executed. The number of acquisitions is set according to the stability requirements of the features, typically 3-5 times. A stability verification algorithm calculates the coefficient of variation (standard deviation divided by mean) of the feature values ​​acquired multiple times. If the coefficient of variation is less than a preset stability threshold, the feature is considered stable; otherwise, it is considered unstable, and the acquisition time and number of acquisitions are increased until the coefficient of variation of the feature values ​​acquired consecutively is less than the stability threshold. The stable feature value is then used as the baseline feature before execution, taking into account the random error of a single acquisition.

[0117] Step S1512: Based on the execution duration of the security protection command and the sensitivity of feature changes, set the time interval for collecting the operating features of the fiber optic access network. For features in historical data whose change rate is higher than the preset rate threshold, set the collection time interval to be lower than the collection time interval of other features.

[0118] The time interval setting comprehensively considers two factors: the execution duration of security protection commands and the sensitivity of feature changes. Longer execution durations result in longer overall data collection cycles, allowing for a more appropriate increase in the time interval; shorter execution durations require a shorter time interval to capture short-term changes. Feature change sensitivity is determined through statistical analysis of feature change rates in historical data. Features with change rates exceeding a preset threshold are considered highly sensitive, and their collection time interval is set to 1 / 2 or 1 / 3 of that of less sensitive features for more intensive monitoring. For example, the time interval for highly sensitive attack traffic features is set to 1 minute, while the time interval for less sensitive port connection count features is set to 5 minutes.

[0119] Step S1513: Collect the operating characteristics of the fiber optic access network multiple times during the execution of the security protection command according to the set time interval, and form an execution process characteristic sequence.

[0120] The execution process feature sequence is a set of runtime feature data points arranged chronologically. Each data point contains a collection timestamp and a feature value at the corresponding time. Data collection is achieved through a scheduled task of the network management system. At each time interval, a data collection operation is triggered, and the collected feature values ​​are appended with timestamps and stored in a memory buffer. When the buffer data reaches a certain amount or the execution process ends, the feature sequence is written to a disk file or a time-series database to support subsequent trend analysis and rate of change calculation.

[0121] Step S1514: Perform sequence anomaly detection on the feature sequence of the execution process. Identify feature data points in the sequence that deviate from the normal trend of change through anomaly detection algorithm, mark the anomalies, and record the time and feature values ​​of the anomalies.

[0122] Anomaly detection algorithms employ model-based methods, such as the Isolation Forest algorithm and autoencoders, to model the feature sequences of the execution process. First, the anomaly detection model is trained using feature sequences from normal conditions. Then, the current execution process feature sequences are input into the model to calculate anomaly scores for each data point. Data points with anomaly scores exceeding a preset anomaly threshold are marked as anomalies. The timestamps and feature values ​​of anomalies are recorded, and possible causes are analyzed, such as abnormal execution of protection commands or sudden changes in the network environment. Anomaly detection results serve as a reference factor for evaluating execution effectiveness. If anomalies are concentrated in critical stages of command execution, it may indicate problems in the command execution process.

[0123] Step S1515: After the security protection command is executed, the operating characteristics of the fiber optic access network are collected multiple times. Stable post-execution result characteristics are obtained by calculating the average value. The difference between the baseline characteristics before execution and the post-execution result characteristics is compared. Combined with the trend prediction report, it is determined whether the security protection command has achieved the preset protection target, and an execution effect evaluation conclusion is formed.

[0124] Post-execution result feature collection begins after the security protection command is executed, with the same number of collections as the pre-execution baseline features. After collection, the average of the collected feature values ​​is calculated as the stable post-execution result feature. Difference comparison is performed to calculate the absolute and relative percentage differences between the post-execution result feature and the pre-execution baseline feature on each key indicator. Combined with the predicted feature value range in the trend prediction report, if the key indicators of the post-execution result feature are within the normal range of the preset protection target and better than the predicted risk regression trend, the execution effectiveness evaluation conclusion is "Preset protection target achieved"; otherwise, it is "Preset protection target not achieved". The execution effectiveness evaluation conclusion is output in the form of an evaluation report, including feature comparison charts, difference analysis, and trend prediction comparison.

[0125] Step S1516: Select features related to the current security risk type from the pre-execution baseline features, execution process feature sequence, and post-execution result features; exclude irrelevant features based on the key feature list determined by the security risk type; organize the selected features in chronological order; record the specific value, rate of change, and trend of each feature at each time point; and mark the abnormal points and causes of abnormalities in the execution process feature sequence to form a feature change record document.

[0126] The key feature list is retrieved from a pre-defined feature knowledge base based on the current security risk type, including core and auxiliary indicators for that risk type. The screening process filters all collected features based on the key feature list, retaining relevant features and excluding irrelevant ones to reduce data volume and interference. The processed feature content is arranged in timestamp order to form a time series table. Table columns include timestamp, feature name, feature value, rate of change (difference from the previous moment divided by the time interval), and trend (rising, falling, stable). Outliers are marked in the corresponding timestamp row of the table, with anomaly markers and descriptions of the reasons for the anomalies. The feature change record document is generated in PDF or HTML format, containing feature time series charts, outlier analysis, and a summary of trend changes, serving as an important basis for performance evaluation and parameter adjustment.

[0127] Step S152: Based on the collected feature change data, make short-term predictions on the feature change trend through a trend prediction model, determine whether the feature may regress to a risk state, and generate a trend prediction report.

[0128] The trend prediction model employs time series forecasting algorithms, such as the ARIMA model and LSTM neural network, to model the collected feature change data. The model input is a historical feature change sequence, and the output is a predicted sequence of feature values ​​for the next short period (e.g., 1 hour, 3 hours). By comparing the predicted sequence with a safety risk threshold, it determines whether the feature may regress to a risky state, i.e., whether the predicted value will exceed the risk threshold again. The trend prediction report includes the prediction period, the predicted feature value sequence, a regression probability assessment (high, medium, low), and a predicted regression time point. If the regression probability assessment is high, it indicates the need for enhanced monitoring or further protective measures.

[0129] Step S153: After the security protection command is executed, collect the operating characteristics of the fiber optic access network as the post-execution result characteristics, compare the differences between the baseline characteristics before execution and the post-execution result characteristics, and combine the trend prediction report to determine whether the security protection command has achieved the preset protection target, and form an execution effect evaluation conclusion.

[0130] Pre-execution baseline characteristics are the operational characteristic data of the fiber optic access network collected before the execution of security protection instructions, serving as the baseline for evaluation. Post-execution result characteristics are collected after the instructions have been executed, following a stabilization period (to ensure the full manifestation of the strategy's effects). Difference comparison is calculated by determining the percentage difference between the post-execution result characteristics and the pre-execution baseline characteristics on key indicators, such as "attack traffic reduced by X%" or "packet loss rate decreased by Y%". Combined with the trend prediction report, if the post-execution result characteristics are better than the predicted regression trend, and the key indicators meet the threshold requirements of the preset protection target (e.g., attack traffic is below the security threshold, packet loss rate returns to normal range), then the evaluation conclusion for the execution effect is "preset protection target achieved"; otherwise, it is "preset protection target not achieved". The preset protection target is determined based on the type of security risk and the protection objectives of the protection strategy, and is clearly specified in the protection strategy entries.

[0131] Step S154: If the performance evaluation conclusion is that the preset protection target has not been achieved, extract the feature difference data corresponding to the actual security risk from the abnormal pattern matching results, and at the same time retrieve the real-time value records of each matching parameter during the abnormal pattern matching process and the matching parameter values ​​of the same scenario in the historical risk handling records.

[0132] Feature difference data extraction is obtained from the difference point records of abnormal pattern matching results, with a focus on the first type of attribute differences. These differences may lead to inaccurate matching and thus affect the effectiveness of protection strategies. Real-time matching parameter values ​​are retrieved from the logs of the abnormal pattern matching process, including the specific values ​​of parameters such as correlation threshold, feature unit importance weight, and matching threshold during this matching process. Matching parameter values ​​for similar scenarios in historical risk handling records are obtained by querying the historical database, collecting the range and optimal values ​​of matching parameters from past cases that handled similar security risks with good results.

[0133] Step S155: Construct a deviation-parameter correlation matrix, where the row dimension of the matrix represents the deviation type between the classified and quantified anomaly pattern matching results and the actual safety risk, and the column dimension represents the matching parameters in the anomaly pattern mapping relationship. The dimensionless correlation strength value between each deviation type and the matching parameter is determined through training with historical data.

[0134] The deviation types are categorized based on the representation of feature difference data, such as "insufficient number of first-type matching points deviation," "feature change trend matching deviation," and "association calculation deviation." Each deviation type is represented by a quantitative indicator of its severity, such as deviation percentage or number of deviations. Matching parameters are used as column dimensions of the matrix, including all adjustable matching parameters. Association strength values ​​are obtained through training on historical data; the training dataset contains past deviation types, matching parameter values, and performance evaluation results. Machine learning algorithms, such as linear regression and decision trees, are used to analyze the impact of different matching parameter values ​​on various deviation types, quantifying the impact as association strength values ​​in the [0,1] interval; a larger value indicates a stronger association between the matching parameter and the deviation type.

[0135] Step S156: Match the extracted feature difference data, real-time value records of matching parameters with the deviation-parameter correlation matrix, and filter out the matching parameters whose correlation strength value is higher than the preset correlation threshold as deviation correlation parameters.

[0136] The matching process first maps feature difference data to corresponding deviation types, determining the current set of deviation types. Then, it searches the deviation-parameter correlation matrix for the rows corresponding to these deviation types and extracts the correlation strength values ​​of all matching parameters in those rows. A preset correlation threshold, set based on the distribution of correlation strength values ​​in historical data, is used to filter out matching parameters highly correlated with the current deviation type. Matching parameters with correlation strength values ​​higher than the preset threshold are marked as deviation-related parameters; these parameters are potential factors contributing to poor current performance.

[0137] Step S157: For each deviation-related parameter, compare its value in the current matching process with the value range of similar scenarios in the historical risk handling records. If the current value exceeds the historical value range, mark the deviation-related parameter as a deviation-affecting parameter.

[0138] Historical value range analysis calculates the minimum, maximum, average, and standard deviation of the deviation-related parameters under similar scenarios to determine the normal value range. Current value comparison compares the real-time value of the deviation-related parameter during the current matching process with the historical value range. If the real-time value is less than the minimum or greater than the maximum, it is determined to be outside the historical value range, and the parameter is marked as a deviation-influencing parameter. Deviation-influencing parameters are direct candidate parameters causing matching deviations and require focused adjustment.

[0139] Step S158: For each deviation-affecting parameter, adjust its value to the median value within the historical value range, re-execute the abnormal pattern matching process, and observe whether the deviation is reduced. If the deviation reduction is higher than the preset reduction threshold, then the deviation-affecting parameter is determined to be the deviation attribution parameter.

[0140] Parameter adjustment employs a trial-and-error approach. First, the value of the deviation-influencing parameter is adjusted to the median of its historical range (e.g., the average value), while keeping other parameters unchanged. Abnormal pattern matching is then re-executed to calculate the reduction in deviation between the adjusted feature difference data and the original difference data. The reduction in deviation is calculated as the ratio of the change in the deviation quantification index to the original deviation quantification index. A preset reduction threshold is set based on the deviation control requirements. If the reduction in deviation exceeds this threshold, it indicates that adjusting the parameter has a significant effect on improving deviation, and the deviation-influencing parameter is identified as a deviation attribution parameter; otherwise, the parameter is excluded, and other deviation-influencing parameters are examined further.

[0141] Step S159: Adjust the corresponding matching parameter values ​​in the abnormal mode mapping relationship according to the type of deviation attribution parameter; wherein, the process of determining the adjustment range is as follows: first, convert the deviation reduction range and the parameter value change into a dimensionless relative rate of change, and then determine the final parameter adjustment range based on the preset mapping relationship of the relative rate of change.

[0142] The relative rate of change is calculated as the ratio of the deviation reduction (dimensionless) to the change in parameter value (relative to the historical value range), yielding an efficiency index for parameter adjustment. A pre-defined mapping relationship defines the correspondence between the relative rate of change and the parameter adjustment range. A higher relative rate of change indicates a better deviation reduction effect per unit parameter adjustment, allowing for a more appropriate increase in the adjustment range; conversely, a lower relative rate of change requires a smaller adjustment range to avoid over-adjustment. Once the adjustment range is determined, the deviation attribution parameter is adjusted from its current value to a new value within the historical value range, moving closer to the median or optimal historical value based on the adjustment range. The adjusted matching parameters are written to the graph database of the abnormal pattern mapping relationship, updating the associated edge or node attributes.

[0143] Step S160: Transmit the adjusted matching parameters to the abnormal pattern matching processing stage, update the matching parameters used in the abnormal pattern matching processing stage, and record the parameter adjustment basis, deviation-related parameters, deviation-affected parameters, deviation-attributed parameters, and parameter values ​​before and after adjustment to form a parameter adjustment log.

[0144] Parameter transmission is achieved through inter-process communication. The exception pattern matching process periodically polls the parameter update interface or receives parameter adjustment events via a message notification mechanism. Upon receiving the adjusted matching parameters, the parameter values ​​in the local cache are updated to ensure that subsequent exception pattern matching processes use the latest parameters. The parameter adjustment log records detailed information for each parameter adjustment, including the time of adjustment, the operator (or system identifier for automatic adjustments), the name of the adjusted parameter, the value before adjustment, the value after adjustment, the adjustment range, a list of parameters associated with the deviation, a list of parameters affecting the deviation, a list of parameters attributing the deviation, and the basis for adjustment (such as the degree of deviation reduction and relative rate of change). The parameter adjustment log is stored in the audit database and retained for at least one year to facilitate subsequent analysis of the parameter adjustment effects and audit traceability.

[0145] Figure 2 The illustration shows exemplary hardware and software components of an AI-based anomaly pattern recognition-based fiber optic access network security protection and detection system 100, which can implement the ideas of this application, according to some embodiments of this application. For example, a processor 120 can be used in the AI-based anomaly pattern recognition-based fiber optic access network security protection and detection system 100 and to perform the functions in this application.

[0146] For example, the AI-based anomaly pattern recognition-based fiber optic access network security protection and detection system 100 may include a network port 110 connected to the network, one or more processors 120 for executing program instructions, a communication bus 130, and various forms of storage media 140, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the AI-based anomaly pattern recognition-based fiber optic access network security protection and detection system 100 may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The methods of this application can be implemented according to these program instructions. The AI-based anomaly pattern recognition-based fiber optic access network security protection and detection system 100 also includes an I / O interface 150 between the computer and other input / output devices.

[0147] Furthermore, this embodiment of the invention also provides a readable storage medium, wherein computer-executable instructions are preset in the readable storage medium, and when the processor executes the computer-executable instructions, the above-mentioned fiber optic access network security protection and detection method based on AI abnormal pattern recognition is implemented.

[0148] It should be noted that, in order to simplify the description of the present invention and thus help to understand one or more embodiments of the invention, multiple features may sometimes be grouped into one embodiment, drawing or description thereof in the foregoing description of the embodiments of the present invention.

Claims

1. A security protection and detection method for fiber optic access networks based on AI-based anomaly pattern recognition, characterized in that, The method includes: The system acquires the operating characteristics of the fiber optic access network and a preset abnormal pattern library. It then uses an AI abnormal pattern recognition model to analyze the correlation between the operating characteristics of the fiber optic access network and the pattern characteristics in the preset abnormal pattern library, and generates an abnormal pattern mapping relationship. Anomaly pattern matching is performed on the operating characteristics of the fiber optic access network based on the anomaly pattern mapping relationship. By tracking the feature matching situation in real time, anomaly pattern matching results containing matching points, difference points and matching degree are obtained. Based on the anomaly pattern matching results and the corresponding rules for the security risk level of the fiber optic access network, and in conjunction with historical risk handling records, the current security risk type of the fiber optic access network is determined. By combining security risk types with a pre-defined protection strategy library, security protection instructions for the current security risks are generated through strategy adaptation analysis. Based on the execution effect of the security protection instructions, the matching parameters in the abnormal mode mapping relationship are dynamically adjusted, and the adjusted matching parameters are fed back to the abnormal mode matching and processing stage.

2. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 1, characterized in that, The process of acquiring the operating characteristics of the fiber optic access network and a preset abnormal pattern library, and analyzing the correlation between the operating characteristics of the fiber optic access network and the pattern characteristics in the preset abnormal pattern library using an AI abnormal pattern recognition model to generate an abnormal pattern mapping relationship, includes: From the acquired fiber optic access network operation characteristics, key operation characteristics related to security risks are extracted. These key operation characteristics cover features related to fiber optic access network data transmission rate, signal attenuation, packet loss rate, and port connection stability. The key operational features extracted are pre-calibrated for feature association strength. By comparing the association records of key operational features and risks in historical security events, the association weight of each key operational feature is adjusted. After adjustment, the risk identification accuracy of key operational features in historical security events is compared. If the accuracy reaches the preset identification standard, the feature association strength pre-calibration is completed. The preset abnormal pattern library is parsed, and the pattern features corresponding to each abnormal pattern in the preset abnormal pattern library are extracted. At the same time, a pattern feature classification index is constructed, and the pattern features are classified according to the risk impact range. The pattern features include the initial performance of the features when the abnormality occurs, the rate of feature change, and the stable state of the features. The key operational features after pre-calibration are compared one by one with the pattern features of each abnormal pattern after classification. The specific content of feature overlap, overlap range and overlap duration are recorded in each comparison process. Based on overlapping content, overlapping range, and overlapping duration, the correlation degree between key operational features and each abnormal mode feature is calculated using a correlation degree calculation model. The correlation degree calculation model generates a single correlation degree index that reflects the closeness of the correlation between key operational features and each abnormal mode feature at the feature level and the consistency of the time sequence by comprehensively evaluating the matching degree of overlapping content in terms of type, the coverage of overlapping range in terms of degree, and the continuity of overlapping duration in terms of time sequence. Based on the calculated correlation degree and combined with the pattern feature classification index, a correspondence between key operational features and abnormal patterns is constructed. The abnormal pattern, correlation degree and risk classification label corresponding to each key operational feature are labeled to form an abnormal pattern mapping relationship.

3. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 1, characterized in that, The abnormal pattern matching processing based on the abnormal pattern mapping relationship for the operating characteristics of the optical fiber access network, by tracking the feature matching status in real time during the matching process, obtains abnormal pattern matching results including matching points, difference points, and degree of matching, including: The operational characteristics of the fiber optic access network are decomposed into multiple characteristic units according to characteristic type, so that each characteristic unit corresponds to the key operational characteristic type in the abnormal mode mapping relationship. At the same time, the importance of each characteristic unit is classified, and the classification result of each characteristic unit is determined based on its contribution to historical risk identification. For each feature unit, the corresponding abnormal pattern and correlation in the abnormal pattern mapping relationship are queried according to its importance classification result to determine the range of abnormal patterns that the feature unit may match. At the same time, the matching threshold is adaptively set based on the classification result. For feature units whose historical risk identification contribution is higher than the preset contribution threshold, their matching threshold is set to be lower than the matching threshold of other feature units. For each feature unit, perform feature detail comparison with the anomaly patterns in the corresponding anomaly pattern range. First, compare the attributes in the feature unit that are directly related to risk identification, and then compare the attributes in the feature unit that assist in risk identification. Record the points of agreement and difference between the feature unit and each anomaly pattern at the two attribute levels. The number of matching points between the two types of attributes and the total number of differences for each abnormal pattern are counted. Combining the correlation degree and the importance classification results of the feature units in the abnormal pattern mapping relationship, a weighted calculation model is used to comprehensively judge the overall degree of consistency between the abnormal pattern and the operating characteristics of the optical fiber access network. Before the comprehensive calculation, the weighted calculation model standardizes the number of matching points, the number of differences, the correlation degree and the importance classification results to generate a degree of consistency evaluation value. Based on the overall degree of matching, abnormal patterns that meet the preset conditions are selected. The selection results are then integrated with the corresponding degree of matching, the matching points of the two types of attributes, the differences, and the weighted calculation basis to form the abnormal pattern matching results.

4. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 3, characterized in that, The process of comparing each feature unit with the corresponding anomaly pattern range involves first comparing the attributes directly related to risk identification in the feature unit, and then comparing the attributes that assist in risk identification in the feature unit. The matching and difference points between the feature unit and each anomaly pattern at the two attribute levels are recorded, including: The feature unit is decomposed into two categories of attribute details based on the degree of correlation between the attribute and risk identification: the first category of attribute details consists of attributes whose contribution to historical risk identification is higher than a preset contribution threshold, and the second category of attribute details consists of attributes whose contribution to historical risk identification is lower than a preset contribution threshold. At the same time, each detail item is assigned a weight, and the weight value is proportional to the contribution of the attribute to historical risk identification. For each first-category attribute detail item, query the standard representation, standard value range, and allowable fluctuation range of the first-category attribute detail item in the corresponding abnormal mode. At the same time, combine the actual matching deviation of the first-category attribute detail item in the historical matching records to dynamically correct the standard value range. Compare the actual performance of the first type of attribute detail item in the feature unit with the corrected standard performance form, standard value range and allowable fluctuation range to determine whether the actual performance meets the requirements. If it does, record the first type of attribute detail item as the first type of matching point, and record the specific content and degree of matching. If the actual performance of the first type of attribute detail item does not meet the requirements, then record the first type of attribute detail item as the first type of difference point, and record the specific content of the difference, the difference value and the possible reasons for the difference, and mark the first type of difference point as a key point; For each second-type attribute detail item, query the standard performance and allowable deviation range of the second-type attribute detail item in the corresponding abnormal mode, compare the actual performance of the second-type attribute detail item in the feature unit with the standard requirements, and determine whether it meets the requirements. If the actual performance of the second type of attribute detail item meets the requirements, then record the second type of attribute detail item as the second type of matching point; if it does not meet the requirements, then record it as the second type of difference point, and record the corresponding matching content or difference content at the same time. All first-type matching points, first-type difference points, second-type matching points, and second-type difference points are summarized, categorized and organized according to attribute type, and a feature detail comparison record table is formed.

5. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 1, characterized in that, The method of determining the current security risk type of the fiber optic access network based on the abnormal pattern matching results and the corresponding rules for the security risk level of the fiber optic access network, combined with historical risk handling records, includes: Analyze the abnormal pattern matching results, extract the abnormal patterns that meet the preset conditions, extract the feature performance, risk impact range label and time sequence features corresponding to each abnormal pattern, and add a scene label to each abnormal pattern. The scene label is determined based on the network environment, time period and service type in which the abnormality occurred. Query the historical risk handling records of the fiber optic access network, extract the historical records that are consistent with the current abnormal mode scenario tags, and organize the risk types, handling measures and handling effects in the historical records to form a historical risk scenario mapping table. Obtain the security risk level correspondence rules for the fiber optic access network. These rules clearly define the correspondence between different anomaly modes, scenario labels, security risk types, and risk impact scope, and also include the priority ranking of risk types under different scenarios. By comparing the abnormal patterns and scene tags in the abnormal pattern matching results with the corresponding rules for the security risk level of the fiber optic access network, a preliminary range of security risk types corresponding to the abnormal patterns and scene tags in the corresponding rules for the security risk level of the fiber optic access network is found. At the same time, the preliminary range of security risk types is preliminarily screened by combining the historical risk scene mapping table. The matching and discrepancies in the abnormal pattern matching results are analyzed, and the feature differences of similar scenarios in the historical risk scenario mapping table are compared to determine the degree of fit between the current abnormal pattern and each security risk type in the preliminary range of security risk types. The degree of fit is determined by constructing a multi-factor evaluation model. This multi-factor evaluation model quantifies and standardizes three different dimensions of evaluation factors: feature matching degree, scenario consistency, and historical processing effect. Based on preset rules, it is integrated to generate a quantitative index that reflects the overall fit level. Based on the degree of compatibility and the priority ranking in the rules corresponding to the security risk level of the fiber optic access network, the current security risk type of the fiber optic access network is determined. At the same time, the points of agreement, differences, historical records and priority ranking results are recorded during the determination process to form the basis for determining the security risk type.

6. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 5, characterized in that, The analysis of the matching points and differences in the abnormal pattern matching results, compared with the characteristic differences of similar scenarios in the historical risk scenario mapping table, determines the degree of fit between the current abnormal pattern and each security risk type in the preliminary range of security risk types, including: Extract the first type of matching points, the first type of difference points, the second type of matching points, and the second type of difference points from the abnormal pattern matching results, and count the number of feature dimensions involved in the first type of matching points, the first type of difference points, the second type of matching points, and the second type of difference points. Based on the contribution weight of each feature dimension in historical risk identification, the number of statistical dimensions is weighted to obtain the first type of matching weighted value, the first type of difference weighted value, the second type of matching weighted value, and the second type of difference weighted value. During the weighting calculation, the feature dimension weight value corresponding to the first type of attribute detail item is higher than the feature dimension weight value corresponding to the second type of attribute detail item. Query the historical risk scenario mapping table, extract historical records that are consistent with the current abnormal mode scenario label, organize the first type of matching features, the first type of difference features and the adaptation results corresponding to each security risk type under the same scenario in the historical records, and form a historical feature comparison library. The first type of matching points and the first type of difference points of the current abnormal pattern are compared with the first type of matching features and the first type of difference features of the same scene in the historical feature comparison library. The similarity between the two in terms of feature dimension, feature value and feature change trend is calculated. In the similarity calculation process, the feature dimension corresponding to the first type of matching point is given a higher calculation weight. The calculated similarity is evaluated for confidence level. The reliability of the similarity results is judged by combining the number of historical samples and the matching accuracy, and similarity results that do not reach the preset confidence threshold are excluded. Based on the similarity results and similarity confidence, and combined with the characteristic requirements of each security risk type in the preliminary range of security risk types, the matching score between the current anomaly pattern and each security risk type is calculated. The calculation process of the matching score is as follows: the standardized intermediate indicators, such as the first type of matching weighted value, the second type of matching weighted value, the first type of difference weighted value, and the second type of difference weighted value, are combined according to the preset contribution ratio and deduction ratio to generate a final matching score for priority ranking. Based on the fit score, the security risk types in the preliminary range of security risk types are sorted. The top K security risk types with the highest scores are output as the most suitable types for the current anomaly mode. At the same time, the calculation basis of the fit score, the similarity results and the confidence assessment results are recorded to form a fit degree judgment report.

7. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 1, characterized in that, The process of combining security risk types with a preset protection strategy library and generating security protection instructions for the current security risks through strategy adaptation analysis includes: Query the preset protection strategy library and extract the corresponding protection strategy entries based on the current security risk type and scenario tag. Each protection strategy entry includes the protection objective, protection measures, implementation steps and applicable scenario scope. The effectiveness of the extracted protection strategy items is pre-evaluated. Combined with the implementation effect of similar protection strategy items in historical risk handling records, the effectiveness probability of each protection strategy item is calculated, and protection strategy items whose effectiveness probability does not reach the preset standard are excluded. Analyze the characteristics, impact scope, and real-time network operating status of the current security risk types; determine the applicability of the remaining protection policy items; check the compatibility of the implementation steps of the protection policy items with the current network operating status; and eliminate protection policy items that conflict with the current network status. Make detailed adjustments to the remaining applicable protection strategy items, adjust the parameter settings of protection measures according to the specific characteristics of the current security risks, and adjust the execution order and duration of implementation steps according to the real-time network service load; The adjusted protection strategy items are subjected to strategy conflict detection and resolution. If there are multiple protection strategy items, the conflict points of the implementation steps between the protection strategy items are checked, and the conflict resolution scheme is determined by priority ranking. The adjusted and conflict-resolved protection strategy entries are transformed into executable operation instructions, each of which specifies the operation content, operation object, operation parameters, and operation time window. All operational instructions are integrated in the order of implementation, and criteria for judging the effect of instruction execution and contingency plans for handling anomalies are added to form security protection instructions for current security risks.

8. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 7, characterized in that, The query of the preset protection strategy library extracts corresponding protection strategy entries based on the current security risk type and scenario tag, including: Access the storage location of the preset protection policy library, call the protection policy index stored in the preset protection policy library. The protection policy index is organized into secondary categories according to security risk type and scenario tag, and also includes the update time and version information of the protection policy entries. The protection policy index is dynamically updated and verified. The update time of the protection policy entries in the protection policy index is compared with the update time of the latest protection policy entries in the preset protection policy library. If there is a difference, the protection policy index is updated synchronously to make the protection policy index consistent with the protection policy entries in the preset protection policy library. Based on the current security risk type, search for the primary category directory in the protection strategy index, and then search for the secondary category directory under the primary category directory based on the scenario tag to determine the identifier of all protection strategy entries under the secondary category directory; Based on the protection strategy item identifier, the corresponding protection strategy item content is retrieved from the preset protection strategy library. During the retrieval process, it is checked whether the protection strategy item content includes protection objectives, protection measures, implementation steps and applicable scenarios. If there are any missing items, they are supplemented from the preset protection strategy library. Compare the version information of the protection policy entries with the latest version information in the preset protection policy library. If it is an older version, retrieve the latest version from the preset protection policy library to replace it. After replacement, check the version consistency again. Completed and consistent protection strategy entries are sorted according to the priority of the protection objectives. The priority is determined based on the degree of protection of core business and the urgency of implementation of the protection strategy entries, forming an orderly list of protection strategy entries.

9. The fiber optic access network security protection and detection method based on AI anomaly pattern recognition according to claim 1, characterized in that, The process of dynamically adjusting the matching parameters in the abnormal mode mapping relationship based on the execution effect of the security protection command, and feeding back the adjusted matching parameters to the abnormal mode matching processing stage, includes: Monitor the execution process of security protection commands, collect the operating characteristics of the fiber optic access network at preset time intervals, record the changes in the operating characteristics of the fiber optic access network during the execution process, and record the rate and trend of change of characteristics related to security risks; Based on the collected feature change data, a trend prediction model is used to make short-term predictions on the feature change trend, determine whether the feature may regress to a risk state, and generate a trend prediction report. After the security protection command is executed, the operating characteristics of the fiber optic access network are collected as the post-execution result characteristics. The difference between the baseline characteristics before execution and the post-execution result characteristics is compared. Combined with the trend prediction report, it is determined whether the security protection command has achieved the preset protection target, and an execution effect evaluation conclusion is formed. If the evaluation result of the implementation effect is that the preset protection target is not achieved, extract the feature difference data corresponding to the actual security risk from the abnormal pattern matching results, and at the same time retrieve the real-time value records of each matching parameter during the abnormal pattern matching process and the matching parameter values ​​of the same scenario in the historical risk handling records. Construct a deviation-parameter correlation matrix, where the row dimension of the matrix represents the deviation type between the classified and quantified anomaly pattern matching results and the actual safety risks, and the column dimension represents the matching parameters in the anomaly pattern mapping relationship. The dimensionless correlation strength between each deviation type and the matching parameter is determined by training with historical data. The extracted feature difference data and real-time value records of matching parameters are matched with the deviation-parameter correlation matrix, and the matching parameters with correlation strength values ​​higher than the preset correlation threshold are selected as deviation correlation parameters. For each deviation-related parameter, compare its value in the current matching process with the value range of similar scenarios in the historical risk handling records. If the current value exceeds the historical value range, mark the deviation-related parameter as a deviation-affecting parameter. For each deviation-affecting parameter, adjust its value to the median value within the historical range, re-execute the abnormal pattern matching process, and observe whether the deviation is reduced. If the deviation reduction is greater than the preset reduction threshold, then the deviation-affecting parameter is determined to be the deviation attribution parameter. According to the type of deviation attribution parameter, the corresponding matching parameter value in the abnormal mode mapping relationship is adjusted; wherein, the process of determining the adjustment range is as follows: first, the deviation reduction range and the parameter value change are converted into a dimensionless relative rate of change, and then the final parameter adjustment range is determined based on the preset mapping relationship of the relative rate of change. The adjusted matching parameters are transmitted to the abnormal pattern matching processing stage to update the matching parameters used in the abnormal pattern matching processing stage. At the same time, the basis for parameter adjustment, deviation-related parameters, deviation-affected parameters, deviation-attributed parameters, and parameter values ​​before and after adjustment are recorded to form a parameter adjustment log.

10. A fiber optic access network security protection and detection system based on AI anomaly pattern recognition, characterized in that, The fiber optic access network security protection and detection system based on AI anomaly pattern recognition includes a processor and a memory, the memory and the processor are connected, the memory is used to store programs, instructions or code, and the processor is used to execute the programs, instructions or code in the memory to implement the fiber optic access network security protection and detection method based on AI anomaly pattern recognition as described in any one of claims 1-9.

Citation Information

Cited By

  • Risk early warning method and system for sewage treatment trusteeship operation project

    CN121724449A

  • A risk early warning method and system for wastewater treatment outsourcing and operation projects

    CN121724449B