Intelligent safety operation center system
By constructing an intelligent security operation central system, standardized processing of multi-source heterogeneous data and collaborative work of various analysis models have been achieved, solving the problems of inconsistent data quality and rigid analysis in existing technologies, and improving the overall efficiency and automation level of security operations.
Patent Information
- Application Number
- CN202511689802.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-18
- Publication Date
- 2026-02-27
AI Technical Summary
Existing security operation platforms or systems are inadequate in terms of data integration, analysis capabilities, and automation of response actions, resulting in inconsistent data quality, rigid analysis, and delayed responses, making it difficult to cope with complex threats and unknown attacks.
Construct an intelligent security operation hub system, including a data access and processing module, an intelligent analysis and decision-making module, a collaborative response and scheduling module, a knowledge management module, and a system management interface. This system enables standardized processing of multi-source heterogeneous data, collaborative operation of multiple analysis models, and automated response processes. It also supports intelligent decision-making through graphical orchestration and knowledge graphs.
It has improved the availability and credibility of data, enhanced the ability to detect unknown threats, improved the speed and accuracy of emergency response, and formed a closed-loop optimization system from response practice to knowledge accumulation and then feeding back into decision-making.
Smart Images

Figure CN121585408A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and more specifically, to an intelligent security operation hub system. Background Technology
[0002] The field of cybersecurity operations has evolved from single-point protection to collaborative defense. Early on, security operations relied on manual analysis and handling of alerts from independent security devices such as firewalls and intrusion detection systems. As cyberattacks have become increasingly complex and organized, traditional "siloed" security products have resulted in information silos and inefficiency. To address this, concepts and technologies such as Security Operations Centers (SOCs) and Security Orchestration, Automation, and Response (SOAR) have emerged, aiming to improve the efficiency and effectiveness of security operations by integrating multiple security capabilities and introducing automated processes. This signifies that the field is rapidly developing towards intelligence, integration, and automation.
[0003] However, existing security operation platforms or systems still have shortcomings. First, their data integration capabilities are limited. Security data from different vendors and in different formats is difficult to standardize and process in a truly unified manner, resulting in inconsistent data quality and affecting the accuracy of subsequent analysis. Second, their analytical capabilities are fragmented or rigid, often relying on pre-set static rules and lacking the organic integration and synergy of various analytical models (such as machine learning and graph computing), making it difficult to effectively respond to unknown threats and conduct in-depth correlation analysis. Finally, the automation level of response actions is low, there is insufficient linkage between different security components, predefined response processes (scripts) lack flexibility, and there is a lack of a continuously optimized knowledge system to support them, leading to lagging security decisions and responses and difficulty in adapting to rapidly changing threat landscapes.
[0004] Therefore, an intelligent security operation hub system is proposed to address the aforementioned issues. It aims to solve the key problems in the existing technologies mentioned above, namely: how to efficiently integrate and process multi-source heterogeneous security data; how to deeply integrate multiple analysis models to achieve more accurate and proactive threat identification and risk assessment; and how to achieve intelligent and automated collaborative response across security components, thereby comprehensively improving the overall efficiency and automation level of security operations. Summary of the Invention
[0005] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide an intelligent security operation hub system to solve the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution: an intelligent security operation central system, comprising:
[0007] The data access and processing module is used to collect security-related data from multiple heterogeneous security data sources in real time, and to standardize and normalize the collected data to form a security event stream in a unified format.
[0008] The intelligent analysis and decision-making module is connected to the data access and processing module. It is used to receive the security event stream and use a variety of pre-set analysis models to perform correlation analysis, threat identification and risk assessment on the security events. The various analysis models include rule-based analysis models, anomaly detection-based machine learning models and graph computing models for predicting attack paths.
[0009] The collaborative response and scheduling module is connected to the intelligent analysis and decision-making module. It is used to generate standardized response action instructions based on the analysis results and handling suggestions output by the intelligent analysis and decision-making module, and to schedule the corresponding security components or external systems to execute the preset response process.
[0010] The knowledge management module, connected to the intelligent analysis and decision-making module and the collaborative response and scheduling module, is used to store and manage threat intelligence, event context, response strategies and model update information generated during security operations, and to provide knowledge retrieval and calling services for other modules.
[0011] The system management interface provides authorized users with a graphical user interface for configuring system parameters, defining security policies, monitoring system operation status, and visually displaying the security posture.
[0012] Alternatively, the data access and processing module may also include a data quality assessment unit, which is used to verify the integrity, accuracy and timeliness of the input data source, and to mark or filter data that does not meet the quality requirements.
[0013] Multiple options are available. The various analysis models in the intelligent analysis and decision-making module are integrated into the model container in a pluggable manner. The model container provides a unified model calling interface, resource management and lifecycle management functions, and supports dynamic loading, updating and unloading of analysis models.
[0014] Alternatively, the collaborative response and scheduling module may also include a response script management unit, which is used to define, edit and store a variety of preset response scripts, wherein each response script contains a series of standardized response actions and their execution logic triggered based on a specific security scenario.
[0015] Multiple options are available. The response script management unit supports arranging the logical order and execution conditions of response actions in a graphical drag-and-drop manner through the system management interface.
[0016] Alternatively, the knowledge management module may also include a knowledge graph construction unit, which is used to automatically construct and update a knowledge graph expressing the relationships between security entities based on the collected security events, asset information, vulnerability data and threat intelligence.
[0017] Alternatively, the system management interface also provides a unified application development interface, which allows authorized third-party systems to programmatically query security status, submit analysis tasks, or subscribe to security event notifications through this application development interface.
[0018] Alternatively, the system also includes a runtime support framework, which provides basic service capabilities for each module, such as distributed task scheduling, service registration and discovery, unified logging, and system resource monitoring.
[0019] The technical effects and advantages of this invention are as follows:
[0020] Compared to existing technologies, this invention achieves automated parsing, standardization, and quality measurement of multi-source heterogeneous security data by constructing a data access and processing module with a data quality assessment unit. This module utilizes predefined pattern templates and normalization techniques to transform raw data into a high-quality unified event stream and performs real-time verification and labeling of data quality. This effectively solves the problems of data clutter and inconsistent quality, providing a reliable and clean data foundation for upper-level analysis. Its advantage lies in improving data availability and reliability from the source, reducing false positives and false negatives caused by data quality issues.
[0021] Compared to existing technologies, this invention integrates and manages multiple analysis models by employing pluggable model containers, providing a unified calling interface and resource management functions. This design enables different models, such as rule-based, machine learning, and graph computing, to work collaboratively, achieving multi-dimensional and in-depth correlation analysis and threat assessment of security events. This overcomes the shortcomings of traditional systems, such as single, rigid, and difficult-to-expand analysis models. Its advantages lie in enhancing the system's ability to detect unknown threats and complex attack chains, while ensuring the continuous evolution and flexible deployment of analytical capabilities.
[0022] Compared to existing technologies, this invention achieves flexible definition and execution of automated response processes by introducing graphically orchestrated response scripts and a continuously evolving knowledge graph. The collaborative response and scheduling module can automatically trigger pre-set or customized response scripts based on analysis results, scheduling various security components to perform actions. Simultaneously, the knowledge management module provides comprehensive contextual information and intelligence support for decision-making and response. This addresses the pain points of traditional automated responses, such as poor flexibility and lack of intelligent knowledge support. Its advantages lie in improving the speed and accuracy of emergency response and forming a closed-loop optimization system from response practice to knowledge accumulation and further decision-making. Attached Figure Description
[0023] Figure 1 This is a system framework diagram of the present invention.
[0024] Figure 2 This is a flowchart of the process of the present invention. Detailed Implementation
[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] Example 1:
[0027] As attached Figures 1-2 The intelligent security operation hub system shown includes: a data access and processing module, which is used to continuously collect security-related data from heterogeneous security data sources such as firewalls, intrusion detection systems, endpoint protection agents, cloud platform audit logs and network traffic probes through various standardized communication protocols and application programming interfaces. The types of data collected include structured log records, unstructured text alarm information, network flow data tuples and system call tracing sequences.
[0028] This module has a built-in data parsing engine that can extract fields, parse formats and unify semantics from raw data according to predefined data pattern templates. It can convert data from different sources into event objects with unified timestamp, event type, source and destination addresses and severity level fields, and combine them into an ordered security event stream according to the order of event occurrence.
[0029] During the data standardization process, a field matching method based on regular expressions, a normalization technique based on dictionary enumeration values, and an address resolution service based on geographic information databases are used to ensure that all input data conforms to predefined semantic patterns and structural specifications.
[0030] The normalized event stream is processed by the event deduplication unit, which eliminates duplicate event records based on the event feature hash value and a preset time window, and finally forms a standardized security event stream to be output to the downstream module.
[0031] The data access and processing module also includes a data quality assessment unit, which synchronously calculates the integrity, accuracy and timeliness metrics of each data source during the data parsing process.
[0032] Among them, S=α·C+β·A+γ·T;
[0033] S represents the overall quality score of this data record.
[0034] C represents the integrity metric, which is calculated from the required field fill rate.
[0035] A represents the accuracy metric, which is calculated from the pass rate of field values validated by the rule engine.
[0036] T represents the timeliness metric, which is derived from the delay time from event generation to system reception.
[0037] α, β, and γ represent the weighting coefficients for completeness, accuracy, and timeliness, respectively, and satisfy α + β + γ = 1. These weighting coefficients can be configured and adjusted through the system management interface.
[0038] Integrity measurement is achieved by checking the existence and non-emptiness of required fields; accuracy measurement uses a rule engine to verify the reasonable range and logical consistency of field values; and timeliness measurement is based on the delay between the event generation time and the system reception time.
[0039] This unit maintains a dynamic data quality scoring table and attaches a quality score label to each data record. The data quality assessment unit has a built-in threshold judgment mechanism. When the quality score of a data source is continuously lower than the set threshold, an alarm is automatically triggered and the system administrator is notified. For data records with excessively low quality scores, real-time filtering, isolated storage, or marked retention operations can be performed according to pre-configured policies. At the same time, a data quality audit report is generated to record detailed quality anomaly information and processing action logs.
[0040] The intelligent analysis and decision-making module integrates various analysis models in a pluggable manner into a model container. This model container provides a unified model calling interface that encapsulates the input and output specifications of all analysis models. The model calling interface accepts standardized security event streams as input and outputs structured threat determination results and confidence scores.
[0041] in,
[0042] A s This represents the anomaly score for the event.
[0043] n represents the total number of behavioral feature dimensions monitored.
[0044] i represents the index of the feature dimension.
[0045] w i This represents the weight of the i-th feature dimension.
[0046] f i This represents the observation value of the current event in the i-th feature dimension.
[0047] μ iThis represents the mean of normal behavior for the i-th feature dimension, calculated based on historical data.
[0048] σ i This represents the standard deviation of normal behavior for the i-th feature dimension, calculated based on historical data.
[0049] The model container implements a resource isolation mechanism, allocating independent computing resource quotas and memory space to each analysis model, and using a resource monitor to monitor the CPU utilization, memory usage, and response latency metrics during model runtime in real time.
[0050] Lifecycle management features include model version management, hot upgrade deployment, canary release and rollback mechanisms, supporting updates to model algorithms or parameters without interrupting system services;
[0051] The model container also provides a model performance monitoring interface to continuously collect the detection accuracy, false alarm rate and processing throughput of each analysis model, and feeds this performance data back to the knowledge management module for model optimization and iteration.
[0052] The analysis models deployed within the container include a rule engine-based correlation analysis model that loads hundreds of predefined attack scenario rules and uses complex event processing techniques to perform real-time pattern matching on event streams.
[0053] The machine learning-based anomaly detection model uses unsupervised learning algorithms to establish a baseline of normal behavior and uses the isolation forest algorithm and autoencoder neural network to detect abnormal activities that deviate from the baseline. The graph computing model constructs a network asset relationship graph and uses a graph neural network algorithm based on random walks to infer potential attack paths and key threat nodes.
[0054] The collaborative response and scheduling module also includes a response script management unit, which provides a graphical interface for defining, editing and storing various preset response scripts. Each response script consists of trigger conditions, execution action sequence, branch judgment logic and termination conditions. The trigger conditions are defined based on the feature patterns of specific security scenarios, and the script is automatically activated when a security event that meets the conditions is received from the intelligent analysis and decision module.
[0055] The sequence of actions includes a series of standardized response operations, including but not limited to isolating affected hosts, blocking network connections, resetting user sessions, revoking access tokens, triggering vulnerability patching processes, and notifying relevant personnel; each action has predefined success or failure criteria and a timeout control mechanism.
[0056] The branch decision logic determines the subsequent execution path based on the action execution result and the real-time environment status; the response script adopts a state machine-based execution engine to track the execution status of each script instance in real time and provide control operations such as pause, continue, and terminate; all script execution processes generate detailed audit logs, recording the execution time, execution result, and operator information of each action.
[0057] The response script management unit supports the arrangement of the logical order and execution conditions of response actions in a graphical drag-and-drop manner through the visual editing interface provided by the system management interface; the visual editing interface provides an action component library, condition judgment components and flow control components, and users can build response workflows by dragging and dropping components;
[0058] The workflow editor verifies the completeness and rationality of the process logic in real time to prevent logical loops or unterminated branches; during the orchestration process, dependencies between actions and execution timing constraints can be set, and parallel execution branches and synchronous convergence point settings are supported.
[0059] Each action component can be configured with detailed parameters, including target object selector, execution parameter settings, timeout and retry policy; the condition judgment component supports writing complex condition judgment logic based on expression language, and can reference real-time system status variables, security event attributes and previous action execution results;
[0060] Once the response script is edited, a machine-executable script definition file is automatically generated. This file is written in a standardized script description language, contains complete metadata information and version identifiers, and is stored in a version-controlled script repository for scheduling and execution.
[0061] The knowledge management module also includes a knowledge graph construction unit, which continuously collects security-related information from multiple internal and external data sources, including security event records, asset configuration information, vulnerability databases, threat intelligence subscription sources, and malware signature databases.
[0062] The knowledge graph construction adopts an automated pipeline process, which includes four stages: information extraction, entity linking, relation extraction, and graph fusion. The information extraction stage uses natural language processing technology to extract secure entities and their attributes from unstructured text. The entity linking stage disambiguates and aligns the extracted entities with existing entities in the knowledge base. The relation extraction stage uses rule-based pattern matching and neural network-based relation classification technology to identify semantic relationships between entities. The graph fusion stage integrates the newly extracted knowledge with the existing graph and removes duplicates.
[0063] The constructed knowledge graph is stored using an attribute graph data model. Nodes represent security entities (such as hosts, users, vulnerabilities, attack indicators, etc.), and edges represent relationships between entities (such as running on, owning, exploiting, associating, etc.). The knowledge graph supports multi-hop query reasoning and provides a query interface based on a graph database, allowing other modules to retrieve entity association information through a structured query language. The knowledge graph construction unit also implements an incremental update mechanism, which automatically acquires the latest threat intelligence and vulnerability information on a regular basis, updates the graph content, and maintains the version history.
[0064] The system management interface also provides a unified application development interface, which adopts a representational state transfer architecture style and uses the Hypertext Transfer Protocol to provide data exchange based on JavaScript object representation format. The application development interface implements a role-based access control mechanism, and all interface calls must pass digital signature authentication and permission verification.
[0065] The interface set includes four main categories: security posture query interface, analysis task submission interface, event subscription interface, and system management interface. The security posture query interface provides multiple query endpoints, allowing authorized third-party systems to retrieve current security posture data by time range, asset range, threat type, and other dimensions. The analysis task submission interface accepts batch analysis task requests submitted by external systems and supports asynchronous processing mode and result callback notification.
[0066] The event subscription interface allows third-party systems to register as security event subscribers and receive real-time notifications via push notifications when specific types of security events occur. The system management interface provides system configuration management, user management, and operational status monitoring functions. All interfaces provide complete application programming interface documentation and software development kits to support integration with third-party systems.
[0067] The system also includes a runtime support framework, which is built using a microservice architecture style to provide a basic environment for distributed deployment and collaborative work of all functional modules. The runtime support framework includes a distributed task scheduling component, which implements a highly available architecture based on a distributed consensus algorithm and supports the scheduling and execution of scheduled tasks, dependent tasks, and real-time tasks.
[0068] The service registration and discovery component maintains network endpoint information for all microservices and provides service discovery, health checks, and load balancing functions; the unified logging component collects operation logs, runtime logs, and audit logs generated by all modules and provides log aggregation, index retrieval, and long-term archiving capabilities.
[0069] The system resource monitoring component monitors the CPU utilization, memory usage, disk I / O performance, and network bandwidth usage of each microservice in real time, and sets resource threshold alarm mechanisms. The runtime support framework also provides a distributed configuration management service to centrally manage the configuration parameters of all modules, supporting dynamic configuration updates and version rollbacks. The components within the framework exchange data through encrypted communication channels to ensure the security and integrity of data transmission.
[0070] Example 2
[0071] The detailed workflow of the intelligent safety operation hub system described in this invention is as follows.
[0072] The workflow of this invention begins with the data access and processing module collecting raw security data from various heterogeneous security data sources in real time, and then using the data parsing engine to perform field extraction, format parsing and semantic normalization processing based on predefined pattern templates to form a security event stream in a unified format.
[0073] Subsequently, the data quality assessment unit verifies the completeness, accuracy, and timeliness of the event stream, and marks or filters out unqualified data to ensure the quality of input data.
[0074] The pre-processed high-quality event stream is sent to the intelligent analysis and decision-making module. This module calls upon the rule-based analysis model, the anomaly detection-based machine learning model, and the graph computing model for predicting attack paths integrated in its model container to perform multi-dimensional correlation analysis, threat identification, and risk assessment of the events, and generate analysis results containing handling recommendations.
[0075] The collaborative response and scheduling module receives the analysis results and automatically generates standardized response instructions based on preset response scripts that can be arranged through a graphical interface. It then schedules and triggers corresponding security components or external systems to perform response actions such as isolation, blocking, and notification.
[0076] Throughout the process, the knowledge management module continuously provides threat intelligence, contextual information, and historical policy support for analysis, decision-making, and response scheduling. It also utilizes knowledge graph building units to dynamically integrate security entity relationships, enabling the accumulation and evolution of knowledge.
[0077] Meanwhile, the system management interface provides administrators with global situation visualization, policy configuration and system monitoring capabilities, while the operation support framework provides basic support for all the above processes such as distributed task scheduling, service discovery and log management, ultimately forming a complete and automated security operation process from data input to intelligent response closed loop.
[0078] Finally, the following points should be noted: First, in the description of this application, it should be noted that, unless otherwise specified and limited, the terms "installation", "connection", and "linkage" should be interpreted broadly, and can be mechanical or electrical connections, or internal connections between two components, or direct connections. "Up", "down", "left", "right", etc. are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may change.
[0079] Secondly: The accompanying drawings of the embodiments disclosed in this invention only involve the structures involved in the embodiments disclosed in this invention. Other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of this invention can be combined with each other.
[0080] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An intelligent safety operations hub system, characterized by, The system comprises: a data access and processing module for collecting security-related data from multiple heterogeneous security data sources in real time, and performing standardization and normalization processing on the collected data to form a unified format security event stream; an intelligent analysis and decision module connected to the data access and processing module, for receiving the security event stream and performing correlation analysis, threat identification and risk assessment on security events using pre-configured multiple analysis models, wherein the multiple analysis models include rule-based analysis models, machine learning models based on anomaly detection, and graph computing models for predicting attack paths; a collaborative response and scheduling module connected to the intelligent analysis and decision module, for generating standardized response action instructions based on the analysis results and handling suggestions output by the intelligent analysis and decision module, and scheduling corresponding security components or external systems to execute pre-configured response processes; a knowledge management module connected to the intelligent analysis and decision module and the collaborative response and scheduling module, for storing and managing threat intelligence, event context, response strategies, and model update information generated during security operations, and providing knowledge retrieval and invocation services for other modules; a system management interface providing a graphical operation interface for authorized users to configure system parameters, define security policies, monitor system running status, and visually display security posture.
2. The intelligent safety operation hub system of claim 1, wherein: The data access and processing module further comprises a data quality assessment unit for checking the integrity, accuracy, and timeliness of input data sources, and marking or filtering data that does not meet quality requirements.
3. The intelligent safety operation hub system of claim 1, wherein: The multiple analysis models in the intelligent analysis and decision module are integrated in a model container in a pluggable manner, which provides unified model invocation interfaces, resource management, and life cycle management functions, supporting dynamic loading, updating, and unloading of analysis models.
4. The intelligent safety operation hub system of claim 1, wherein: The collaborative response and scheduling module further comprises a response script management unit for defining, editing, and storing multiple pre-configured response scripts, wherein each response script contains a series of standardized response actions and their execution logic triggered based on specific security scenarios.
5. The intelligent safety operation hub system of claim 4, wherein: The response script management unit supports graphical drag-and-drop arrangement of the logical order and execution conditions of response actions through the system management interface.
6. The intelligent safety operation hub system of claim 1, wherein: The knowledge management module further comprises a knowledge graph construction unit for automatically constructing and updating a knowledge graph expressing the relationships between security entities based on collected security events, asset information, vulnerability data, and threat intelligence.
7. The intelligent safety operation hub system of claim 1, wherein: The system management interface further provides a unified application development interface, allowing authorized third-party systems to query security posture, submit analysis tasks, or subscribe to security event notifications through the application development interface in a programmatic manner.
8. The intelligent safety operation hub system of any one of claims 1 to 7, wherein: The system further comprises a running support framework for providing distributed task scheduling, service registration and discovery, unified log recording, and system resource monitoring basic service capabilities for each module.