Network security detection method

By constructing a two-layer detection model and a dynamic feedback adjustment mechanism, multi-dimensional collaborative perception of security threats to training devices is achieved, solving the problem of low network security efficiency caused by single detection methods in existing technologies, and improving the ability to protect against privacy theft and malicious monitoring.

CN121530734AInactive Publication Date: 2026-02-13GUANGZHOU SIJIN ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511949544.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-02-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In existing technologies, the microphones and cameras of training devices are limited by their single detection method and lack of multi-factor perception capabilities, making it difficult to effectively identify and block privacy theft and malicious surveillance, thus reducing the efficiency of network security detection and protection.

Method used

A two-layer correlation detection model between network risks and device call status is constructed. By collecting and analyzing network risk parameters such as process CPU utilization, data bit rate, and traffic fluctuation rate, as well as status call parameters such as call frequency, application abnormal call duration, and device coordination abnormality rate, a quantitative characterization value and dynamic feedback adjustment mechanism are established to achieve collaborative perception and accurate identification of multi-dimensional security threats.

Benefits of technology

It significantly enhances the proactive defense capabilities against privacy theft and malicious surveillance, reduces false alarm and false negative rates, forms an intelligent closed loop of detection, assessment, and dynamic handling, and improves the efficiency of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530734A_ABST
    Figure CN121530734A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides a network security detection method, which comprises the following steps: collecting network risk parameters of a target training device in a historical period; analyzing a network risk characterization value based on the network risk parameter; determining whether the network security of the target training device is abnormal or not based on a comparison result of the network risk characterization value and a preset network risk characterization threshold value; in response to the fact that the network security of the target training device is abnormal, collecting a state calling parameter of the target training device in a historical period; analyzing a state calling representation value based on the state calling parameter; based on a difference result between the state calling characterization value and a preset state calling characterization threshold value, determining whether target training device equipment calling meets a standard or not; in response to the target training apparatus equipment call not meeting the criteria, a processing policy is determined based on the state call characterization value. According to the invention, the network security detection and protection efficiency is improved through adaptive regulation and control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a network security detection method. Background Technology

[0002] With the popularization of online education, remote training, and video conferencing, specialized training devices integrating multimedia acquisition equipment such as microphones and cameras, such as smart learning terminals and video conferencing equipment, have been widely used. While providing a convenient and interactive experience, these devices have also become focal targets of cyberattacks because they directly involve users' core privacy data such as voice and video. Malware and illegal remote control tools often attempt to covertly access these hardware devices to steal privacy, illegally monitor, or hijack sessions, posing a serious threat to personal privacy and corporate information security. Existing protection technologies mainly rely on single-dimensional detection of network behavior, device call logs, or static characteristics, lacking the ability to collaboratively perceive and correlate multi-dimensional parameters such as process resource consumption, network transmission characteristics, and hardware call status. Fragmented detection methods are unable to effectively identify disguised, low-intensity, composite attacks, and fixed judgment thresholds cannot adapt to dynamically changing normal usage scenarios, resulting in high false positive and false negative rates, rigid response strategies, and ultimately a decline in the overall efficiency of network security detection and protection.

[0003] Chinese Patent Publication No. CN113487922A discloses an educational platform, more specifically, an internet-based training and education platform. This internet-based training and education platform includes a training device fixedly connected to the teacher's end, a computer fixedly connected to the training device, and the computer connected to the internet. A student's end is fixedly connected to the student's end, also connected to the internet, and the student's end connects to the training device via the internet. The training device includes a central screen, a frame, a motor II, and side shafts. Side shafts are fixedly connected to both ends of the central screen, and the two side shafts are rotatably connected to the left and right sides of the frame, respectively. Motor II is fixedly connected to the left side of the frame, and the output shaft of motor II is fixedly connected to the left side shaft. The training device also includes a motor I, a horizontal shaft, and a camera. The left and right ends of the horizontal shaft are rotatably connected to the left and right ends of the upper part of the frame, respectively. The camera is fixedly connected to the middle of the horizontal shaft. Motor I is fixedly connected to the left side of the frame, and the output shaft of motor I is fixedly connected to the left end of the horizontal shaft.

[0004] Chinese Patent Publication No. CN119814457A discloses a network security detection method based on big data, relating to the field of network security detection technology. It utilizes a big data acquisition module to collect network traffic data, security event data, and system security status data for the current detection period. Using a unit that measures the degree of network traffic anomalies, it first calculates and outputs an abnormal traffic detection index YL and a threat assessment value WW. The abnormal traffic detection index YL and the threat assessment value WW are then introduced into a unit that comprehensively evaluates the overall network security status, calculating and outputting a security posture index AQ for detection and analysis. A response and handling module then takes security actions based on the security posture index AQ. This invention, by collecting and analyzing multi-dimensional data on network traffic, security events, and system status, and employing advanced algorithms and models, performs comprehensive network security detection, achieving a comprehensive and dynamic assessment of network security.

[0005] Therefore, it is evident that the existing technology has the following problems: When existing training devices such as microphones and cameras are used for cybersecurity testing, the limited detection methods and lack of multi-factor perception capabilities make it difficult to effectively identify and block privacy theft and malicious surveillance, resulting in a decline in the efficiency of cybersecurity testing and protection. Summary of the Invention

[0006] Therefore, the present invention provides a network security detection method to overcome the problem that when existing training devices use microphones and cameras for network security testing, the single detection method and lack of multi-factor perception capabilities make it difficult to effectively identify and block privacy theft and malicious monitoring, thus leading to a decrease in the efficiency of network security detection and protection.

[0007] To achieve the above objectives, the present invention provides a network security detection method, comprising: Collect network risk parameters of the target training device within a historical period; Analyze the network risk characterization value based on the aforementioned network risk parameters; The network risk characterization value is compared with the predetermined network risk characterization threshold to determine whether the network security of the target training device is abnormal. In response to the absence of network security anomalies in the target training device, the status call parameters of the target training device within the historical period are collected. Analyze the state call representation value based on the state call parameters; The difference between the state call representation value and the predetermined state call representation threshold is used to determine whether the target training device call meets the standard. In response to the non-compliance of the target training device's equipment call with the standard, a processing strategy is determined based on the status call characterization value; and the adjustment range of the network risk characterization threshold is determined. The network risk parameters include process CPU utilization, data bitrate, and traffic fluctuation rate. The status call parameters include call frequency, application exception call duration, and device collaboration exception rate.

[0008] Furthermore, the process of analyzing the network risk characterization value using the network risk parameters includes: Collect the CPU usage, data bitrate, and traffic fluctuation rate of the target training device during the historical period; The ratio of the process CPU utilization rate to the predetermined process CPU utilization rate threshold is determined as the first risk limit characterization parameter; The ratio of the calculated data bitrate to a predetermined data bitrate threshold is determined as the second risk-limiting characterization parameter; The ratio of the calculated flow volatility to a predetermined flow volatility threshold is determined as the third risk constraint characterization parameter; The network risk representation value is determined by weighted summation of the first risk limitation representation parameter, the second risk limitation representation parameter, and the third risk limitation representation parameter.

[0009] Furthermore, the process of determining that the network security of the target training device is normal by comparing the network risk characterization value with the predetermined network risk characterization threshold includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold, then the network security of the target training device is determined to be normal.

[0010] Furthermore, the process of determining network security anomalies of the target training device by comparing the network risk characterization value with a predetermined network risk characterization threshold includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; If the network risk characterization value is greater than or equal to the predetermined network risk characterization threshold, then the network security of the target training device is determined to be abnormal.

[0011] Furthermore, the process of analyzing the state call representation value using the state call parameters includes: Collect data on the call frequency of the target training device, the duration of abnormal application calls, and the device collaboration anomaly rate within the historical period; The ratio of the call frequency to the predetermined call frequency threshold is used as the first state-limited characterization parameter; The ratio of the application exception call duration to the predetermined application exception call duration threshold is used as the second state-limited characterization parameter; The ratio of the calculated equipment coordination anomaly rate to the predetermined equipment coordination anomaly rate threshold is the third state-limited characterization parameter; The summation of the first state-limited representation parameter, the second state-limited representation parameter, and the third state-limited representation parameter is determined as the state call representation value.

[0012] Furthermore, the process of determining whether the target training device's device invocation conforms to the standard by comparing the difference between the state invocation representation value and the predetermined state invocation representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the status call representation value and the predetermined status call representation threshold is less than the predetermined difference threshold, then the target training device equipment call is determined to meet the standard.

[0013] Furthermore, the process of determining whether the target training device's equipment call does not meet the standard based on the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the status call representation value and the predetermined status call representation threshold is greater than or equal to the predetermined difference threshold, then the target training device equipment call is determined to be non-compliant with the standard.

[0014] Furthermore, the process of determining the corresponding handling strategy in response to a non-compliance of the target training device's equipment call includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; The adjustment range of the network risk representation threshold is determined based on the difference between the state call representation value and the predetermined state call representation threshold.

[0015] Furthermore, the process of determining the adjustment range of the network risk representation threshold by the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the state call representation value and the predetermined state call representation threshold is greater than the predetermined difference threshold, then the state call representation threshold is determined to be reduced.

[0016] Furthermore, the process for responding to network security and device invocation of the target training device in compliance with standards includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold and the difference between the state call characterization value and the predetermined state call characterization threshold is less than the predetermined difference threshold, then the network security and device invocation of the target training device are determined to meet the standards.

[0017] Compared with existing technologies, the beneficial effects of this invention are that it provides a network security detection method. By constructing a two-layer correlation detection model of network risk and device call status, and introducing quantitative representation values ​​and dynamic feedback adjustment mechanisms, it achieves collaborative perception and accurate identification of multi-dimensional security threats, effectively overcoming the shortcomings of traditional single detection methods, and can keenly detect hidden composite attacks; its adaptive threshold adjustment function significantly reduces false alarms and false negatives; the final intelligent closed loop of detection, evaluation, and dynamic handling greatly improves the training device's proactive defense capabilities against privacy theft and malicious monitoring, and enhances the overall network security protection efficiency.

[0018] In particular, this invention constructs a three-dimensional network risk profile from three dimensions—computing load, data scale, and transmission mode—by selecting three key parameters: process CPU utilization, data bitrate, and traffic fluctuation rate. Normalization is performed through ratio calculation, and then a weighted summation is used to merge these parameters into a single network risk characterization value. This not only achieves collaborative perception of multi-dimensional abnormal behavior, significantly improving the comprehensiveness of detection and its anti-bypass capability, but also refines and configures risk assessment. By efficiently comparing this characterization value with a predetermined threshold, a fast and reliable automated initial screening decision is formed, laying a precise data foundation for subsequent in-depth analysis and dynamic adjustment. This comprehensively solves the problem of low identification accuracy caused by the single detection dimension and lack of quantitative correlation in traditional methods.

[0019] In particular, this invention selects three key parameters—call frequency, application anomaly call duration, and device collaboration anomaly rate—to accurately characterize the behavioral features of malicious monitoring from three dimensions: call frequency, persistence, and correlation, achieving comprehensive and in-depth monitoring of hardware operations. By using ratio normalization and direct summation calculation, a state call representation value is generated, ensuring that significant anomalies in any dimension can be keenly detected. By introducing a two-layer comparison mechanism between the state call representation value and the difference threshold, the system can not only quantify the degree of anomaly but also effectively distinguish between normal fluctuations and real threats, thereby significantly reducing the false alarm rate while improving the sensitivity to detecting covert attacks.

[0020] In particular, this invention establishes a cross-layered dynamic feedback and adaptive adjustment mechanism, thereby elevating the entire system into an intelligent protection closed loop with proactive evolution capabilities. When a device detects an anomaly at the detection layer, the system does not take isolated blocking measures, but dynamically lowers the judgment threshold of the network risk detection layer based on the quantified anomaly difference. Suspicious signs at the hardware level will immediately trigger a more rigorous review of network behavior, making it difficult for related attacks that attempt to hide to escape detection. The combination of dual-compliance security criteria and adjustment mechanism constitutes a continuously running self-optimization cycle of evaluation, adjustment, and re-evaluation, enabling the system to autonomously optimize detection strategies based on the real-time threat situation. This fundamentally changes the static and passive defects of traditional protection, achieving a qualitative leap from single response to proactive prediction and adaptive defense, and significantly improving the overall effectiveness against complex, persistent, and low-intensity network attacks. Attached Figure Description

[0021] Figure 1 This is a flowchart illustrating the steps of the network security detection method according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating the steps involved in analyzing network risk characterization values ​​according to an embodiment of the present invention. Figure 3 This is a logic diagram for determining whether the network security of the target training device is abnormal, as shown in this embodiment of the invention. Figure 4 This is a logic diagram for determining whether the calling of the target training device conforms to the standard in an embodiment of the present invention. Detailed Implementation

[0022] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0023] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0024] Please see Figure 1 The diagram shown is a flowchart illustrating the steps of a network security detection method according to an embodiment of the present invention. The present invention provides a network security detection method, comprising: Step S1: Collect network risk parameters of the target training device within the historical period; Step S2: Analyze the network risk characterization value based on the network risk parameters; Step S3: Determine whether the network security of the target training device is abnormal based on the comparison result between the network risk characterization value and the predetermined network risk characterization threshold. Step S4: In response to the absence of network security anomalies in the target training device, collect the status call parameters of the target training device within the historical period; analyze the status call characterization value based on the status call parameters; Step S5: Determine whether the target training device device call meets the standard based on the difference between the state call representation value and the predetermined state call representation threshold. Step S6: In response to the target training device calling not conforming to the standard, a processing strategy is determined based on the status calling characterization value to determine the adjustment range of the network risk characterization threshold; The network risk parameters include process CPU utilization, data bitrate, and traffic fluctuation rate. The status call parameters include call frequency, application exception call duration, and device collaboration exception rate.

[0025] In this embodiment, by constructing a two-layer correlation detection model of network risk and device call status, and introducing quantitative representation values ​​and dynamic feedback adjustment mechanisms, the collaborative perception and accurate identification of multi-dimensional security threats are realized, effectively overcoming the shortcomings of traditional single detection methods and enabling the keen detection of hidden composite attacks. Its adaptive threshold adjustment function significantly reduces false alarms and false negatives. The resulting intelligent closed loop of detection, evaluation, and dynamic handling greatly improves the training device's proactive defense capabilities against privacy theft and malicious monitoring, as well as the overall network security protection efficiency.

[0026] Please see Figure 2 The diagram shown is a flowchart illustrating the steps involved in analyzing network risk characterization values ​​according to an embodiment of the present invention. The process of analyzing network risk characterization values ​​according to the present invention includes: Step S21: Collect the process CPU utilization, data bitrate, and traffic fluctuation rate of the target training device within the historical period; Step S22: The ratio of the process CPU utilization rate to the predetermined process CPU utilization rate threshold is determined as the first risk limit characterization parameter; the ratio of the data bit rate to the predetermined data bit rate threshold is determined as the second risk limit characterization parameter; the ratio of the traffic fluctuation rate to the predetermined traffic fluctuation rate threshold is determined as the third risk limit characterization parameter. Step S23: The first risk limitation characterization parameter, the second risk limitation characterization parameter, and the third risk limitation characterization parameter are weighted and summed to determine the network risk characterization value.

[0027] In this embodiment, the formula for calculating process CPU utilization is as follows: Process CPU utilization = CPU usage time of the target process in the historical period / Total time of the historical period In this embodiment, the formula for calculating the data bitrate is: Data bitrate = Total amount of data sent and received by the target process within the historical period / Duration of the historical period In this embodiment, the formula for calculating the flow fluctuation rate is: Flow volatility = Standard deviation of flow rate over historical periods / Average flow rate over historical periods In this embodiment, the predetermined process CPU utilization threshold, data bitrate threshold, and traffic fluctuation rate threshold are all obtained in advance. The process CPU utilization, data bitrate, and traffic fluctuation rate of the target training device are collected within 3 months of stable use, and their average values ​​are calculated as the process CPU utilization threshold, data bitrate threshold, and traffic fluctuation rate threshold.

[0028] In this embodiment, by selecting three key parameters—process CPU utilization, data bitrate, and traffic fluctuation rate—a three-dimensional network risk profile is constructed from three dimensions: computing load, data scale, and transmission mode. The profile is normalized by ratio calculation and then fused into a single network risk characterization value by weighted summation. This not only enables collaborative perception of multi-dimensional abnormal behavior and significantly improves the comprehensiveness of detection and anti-bypass capability, but also refines and configures risk assessment.

[0029] Please see Figure 3 As shown, this is a logic diagram for determining whether the network security of a target training device is abnormal according to an embodiment of the present invention. The process of determining whether the network security of a target training device is abnormal based on the comparison result of the network risk characterization value and the predetermined network risk characterization threshold includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold, then the network security of the target training device is determined to be normal. If the network risk characterization value is greater than or equal to the predetermined network risk characterization threshold, then the network security of the target training device is determined to be abnormal.

[0030] In this embodiment, the predetermined network risk characterization threshold is obtained in advance. All network risk characterization values ​​of the target training device are collected within 3 months of stable use, and their average value is calculated as the network risk characterization threshold. The network risk characterization threshold is selected within the range [3.05, 3.15], and is preferably 3.10 in this embodiment.

[0031] In this embodiment, by efficiently comparing the characterization value with a predetermined threshold, a fast and reliable automated initial screening decision is formed, laying a precise data foundation for subsequent in-depth analysis and dynamic adjustment. This solves the problem of low recognition accuracy caused by the single detection dimension and lack of quantitative correlation in traditional methods.

[0032] Specifically, the process of analyzing the state call representation value using the state call parameters includes: Collect data on the call frequency of the target training device, the duration of abnormal application calls, and the device collaboration anomaly rate within the historical period; The ratio of the call frequency to the predetermined call frequency threshold is used as the first state-limited characterization parameter; The ratio of the application exception call duration to the predetermined application exception call duration threshold is used as the second state-limited characterization parameter; The ratio of the calculated equipment coordination anomaly rate to the predetermined equipment coordination anomaly rate threshold is the third state-limited characterization parameter; The summation of the first state-limited representation parameter, the second state-limited representation parameter, and the third state-limited representation parameter is determined as the state call representation value.

[0033] In this embodiment, the predetermined call frequency threshold, application abnormal call duration threshold, and device collaboration abnormal rate threshold are all obtained in advance. The call frequency, application abnormal call duration, and device collaboration abnormal rate of the target training device are collected within 3 months of stable use, and their average values ​​are calculated as the call frequency threshold, application abnormal call duration threshold, and device collaboration abnormal rate threshold.

[0034] In this embodiment, the formula for calculating the call frequency is: Invocation frequency = Total number of successful invocations to the target device within the historical period / Duration of the historical period In this embodiment, the formula for calculating the duration of an application exception call is: Abnormal call duration = Application's continuous device usage time - Normal call duration threshold In this embodiment, the formula for calculating the device coordination anomaly rate is: Device collaboration anomaly rate = Number of abnormal collaboration call events / Total number of events called In this embodiment, by selecting three key parameters—call frequency, application abnormal call duration, and device collaboration abnormality rate—the behavioral characteristics of malicious monitoring are accurately characterized from three dimensions: call frequency, persistence, and correlation, respectively, thus achieving in-depth monitoring of hardware operations in a three-dimensional manner. By normalizing the ratio and performing direct summation calculation, a status call representation value is generated. This design ensures that significant anomalies in any dimension can be keenly captured.

[0035] Please see Figure 4 As shown, this is a logic diagram for determining whether a target training device call conforms to a standard according to an embodiment of the present invention. The process of determining whether a target training device call conforms to a standard based on the difference between the state call representation value and a predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the status call representation value and the predetermined status call representation threshold is less than the predetermined difference threshold, then the target training device equipment call is determined to meet the standard. If the difference between the status call representation value and the predetermined status call representation threshold is greater than or equal to the predetermined difference threshold, then the target training device equipment call is determined to be non-compliant with the standard.

[0036] In this embodiment, the predetermined state call representation threshold is obtained in advance. All state call representation values ​​of the target training device are collected within 3 months of stable use, and their average value is calculated as the state call representation threshold. The state call representation threshold is selected within the range [3.05, 3.15], and is preferably 3.10 in this embodiment.

[0037] In this embodiment, the predetermined difference threshold is obtained in advance. The difference between all the state call characterization values ​​of the target training device within 3 months of stable use and the state call characterization threshold is collected, and the average value is calculated as the difference threshold. The predetermined difference threshold is selected in the range [0.15, 0.35], and is preferably 0.20 in this embodiment.

[0038] In this embodiment, a refined two-layer judgment mechanism is constructed by introducing the difference calculation between the state call representation value and the state call representation threshold, and setting an independent difference threshold for secondary comparison. This mechanism effectively distinguishes between normal device usage fluctuations and real malicious behavior, significantly reducing the false alarm rate while maintaining high sensitivity to covert attacks. The output quantitative difference result provides a precise basis for subsequent dynamic feedback adjustment, supporting the system's adaptive optimization capability. Moreover, the entire judgment process is logically clear and the results are interpretable, greatly improving the efficiency of traceability analysis and decision-making in security operations and maintenance. This logic diagram is a key bridge for transforming multi-dimensional state perception into stable, reliable, and automated decision-making, fundamentally enhancing the accuracy and practicality of the protection system.

[0039] Specifically, the process of determining the corresponding handling strategy in response to a non-compliance of the target training device's equipment call includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; The adjustment range of the network risk representation threshold is determined based on the difference between the state call representation value and the predetermined state call representation threshold.

[0040] In this embodiment, by using the abnormal difference at the device call level as an adjustment signal, the judgment threshold for network risk detection is dynamically reduced, thereby transforming the isolated detection module into an intelligent and collaborative defense system. This enables internal hardware anomalies to proactively trigger enhanced monitoring of external network behavior, significantly improving the ability to counter complex attacks. A self-optimizing closed loop of detection, evaluation, and adjustment is formed, allowing the system to adjust the protection strength in real time and quantitatively according to the severity of the threat. This represents a fundamental improvement from static rule response to dynamic intelligent defense, effectively solving the problem of low protection efficiency caused by isolated detection and rigid strategies in traditional solutions.

[0041] Specifically, the process of determining the adjustment range of the network risk representation threshold by the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the state call representation value and the predetermined state call representation threshold is greater than the predetermined difference threshold, then the state call representation threshold is determined to be reduced.

[0042] In this embodiment, the predetermined difference threshold is obtained in advance. The difference between all the state call characterization values ​​of the target training device within 3 months of stable use and the state call characterization threshold is collected, and the average value is calculated as the difference threshold. The predetermined difference threshold is selected in the range [0.15, 0.35], and is preferably 0.20 in this embodiment.

[0043] In this embodiment, the originally separate risk perception dimensions are integrated into an organically linked defense system through explicit causal logic. A deterministic control link from internal anomalies to external monitoring is established, enabling the network layer to proactively and directionally improve the detection sensitivity of confirmed risks at the device layer. This achieves cross-layer collaboration and proactive prediction of security capabilities. It also enables fine-tuning of strategies based on the severity of risks. The system implements gradient responses based on precise difference measurements, avoiding the coarse-grained operation of Boolean-based protection strategies and optimizing the balance between security strength and business continuity. As the core actuator of the feedback control loop, this mechanism drives the system to form a continuous self-optimization cycle of perception, decision-making, adjustment, and re-perception, enabling it to dynamically adapt to the evolution of the threat situation, thereby fundamentally improving the long-term effectiveness and intelligence level of the protection system.

[0044] Specifically, the process for responding to network security and device access of the target training device in compliance with standards includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold and the difference between the state call characterization value and the predetermined state call characterization threshold is less than the predetermined difference threshold, then the network security and device invocation of the target training device are determined to meet the standards.

[0045] In this embodiment, by integrating multi-dimensional parameters of network behavior and device call status, an intelligent closed-loop defense system combining quantitative perception, hierarchical judgment, and dynamic feedback adjustment is constructed. A dynamic feedback mechanism across security layers is established. When the device call layer detects quantitative anomalies, the system can adaptively adjust the judgment threshold of the network risk detection layer, thereby achieving a qualitative leap from isolated detection to collaborative joint defense and from static rules to dynamic intelligence. Not only does it significantly improve the accuracy and coverage of identifying covert and complex attacks through multi-factor correlation analysis, but it also enables the system to have long-term self-optimization capabilities to cope with continuously evolving threats through an adaptive closed loop of perception, evaluation, and adjustment. This fundamentally solves the problem of low protection efficiency caused by the single detection dimension and rigid strategy of traditional solutions.

[0046] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

Claims

1. A network security detection method, characterized in that, include: Collect network risk parameters of the target training device within a historical period; Analyze the network risk characterization value based on the aforementioned network risk parameters; The network risk characterization value is compared with the predetermined network risk characterization threshold to determine whether the network security of the target training device is abnormal. In response to the absence of network security anomalies in the target training device, the status call parameters of the target training device within the historical period are collected. Analyze the state call representation value based on the state call parameters; The difference between the state call representation value and the predetermined state call representation threshold is used to determine whether the target training device call meets the standard. In response to the non-compliance of the target training device's equipment call with the standard, a processing strategy is determined based on the status call characterization value to determine the adjustment range of the network risk characterization threshold; The network risk parameters include process CPU utilization, data bitrate, and traffic fluctuation rate. The status call parameters include call frequency, application exception call duration, and device collaboration exception rate.

2. The network security detection method according to claim 1, characterized in that, The process of analyzing network risk characterization values ​​based on the aforementioned network risk parameters includes: Collect the CPU usage, data bitrate, and traffic fluctuation rate of the target training device during the historical period; The ratio of the process CPU utilization rate to the predetermined process CPU utilization rate threshold is determined as the first risk limit characterization parameter; The ratio of the calculated data bitrate to a predetermined data bitrate threshold is determined as the second risk-limiting characterization parameter; The ratio of the calculated flow volatility to a predetermined flow volatility threshold is determined as the third risk constraint characterization parameter; The network risk representation value is determined by weighted summation of the first risk limitation representation parameter, the second risk limitation representation parameter, and the third risk limitation representation parameter.

3. The network security detection method according to claim 2, characterized in that, The process of determining that the network security of the target training device is normal based on the comparison between the network risk characterization value and the predetermined network risk characterization threshold includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold, then the network security of the target training device is determined to be normal.

4. The network security detection method according to claim 3, characterized in that, The process of determining network security anomalies of the target training device based on the comparison result between the network risk characterization value and the predetermined network risk characterization threshold includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; If the network risk characterization value is greater than or equal to the predetermined network risk characterization threshold, then the network security of the target training device is determined to be abnormal.

5. The network security detection method according to claim 4, characterized in that, The process of analyzing the state call representation value based on the state call parameters includes: Collect data on the call frequency of the target training device, the duration of abnormal application calls, and the device collaboration anomaly rate within the historical period; The ratio of the call frequency to the predetermined call frequency threshold is used as the first state-limited characterization parameter; The ratio of the application exception call duration to the predetermined application exception call duration threshold is used as the second state-limited characterization parameter; The ratio of the calculated equipment coordination anomaly rate to the predetermined equipment coordination anomaly rate threshold is the third state-limited characterization parameter; The summation of the first state-limited representation parameter, the second state-limited representation parameter, and the third state-limited representation parameter is determined as the state call representation value.

6. The network security detection method according to claim 5, characterized in that, The process of determining whether the target training device's equipment call conforms to the standard based on the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the status call representation value and the predetermined status call representation threshold is less than the predetermined difference threshold, then the target training device equipment call is determined to meet the standard.

7. The network security detection method according to claim 6, characterized in that, The process of determining whether the target training device's equipment call does not meet the standard based on the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the status call representation value and the predetermined status call representation threshold is greater than or equal to the predetermined difference threshold, then the target training device equipment call is determined to be non-compliant with the standard.

8. The network security detection method according to claim 7, characterized in that, The process of determining the corresponding handling strategy in response to a non-compliance of the target training device's equipment call includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; The adjustment range of the network risk representation threshold is determined based on the difference between the state call representation value and the predetermined state call representation threshold.

9. The network security detection method according to claim 8, characterized in that, The process of determining the adjustment range of the network risk representation threshold based on the difference between the state call representation value and the predetermined state call representation threshold includes: Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the difference between the state call representation value and the predetermined state call representation threshold is greater than the predetermined difference threshold, then the state call representation threshold is determined to be reduced.

10. The network security detection method according to claim 9, characterized in that, The process for ensuring that the cybersecurity and device access of the target training device comply with standards includes: Extract the comparison results between the network risk characterization value and the predetermined network risk characterization threshold; Calculate the difference between the state call representation value and the predetermined state call representation threshold; If the network risk characterization value is less than the predetermined network risk characterization threshold and the difference between the state call characterization value and the predetermined state call characterization threshold is less than the predetermined difference threshold, then the network security and device invocation of the target training device are determined to meet the standards.

Citation Information

Patent Citations

  • Training education platform based on the Internet

    CN113487922A

  • Network security detection method based on big data

    CN119814457A