System and method for monitoring security of credential software based on artificial intelligence

By constructing an AI-based security monitoring system for domestically developed software, the shortcomings of intelligent Q&A and real-time interaction in the security monitoring of domestically developed software have been addressed. This system enables user-friendly security status reporting and automated protection, improving the system's protection efficiency and timeliness.

CN121682848APending Publication Date: 2026-03-17CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511904405.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing domestic IT software security monitoring technologies lack intelligent question-and-answer systems, cannot analyze complex threats in real time, lack user interaction, have insufficient ability to deal with complex attacks, have response delays, and cannot effectively defend against new types of attacks by relying on traditional security tools.

Method used

Construct an AI-based security monitoring system for domestically developed software, including modules for data acquisition, AI analysis, intelligent question-and-answer interaction, and automatic control. Through feature extraction, risk prediction, and intelligent question-and-answer models, it enables real-time interaction and automatic response, and provides security status reports and protection recommendations.

Benefits of technology

It enables real-time interaction between users and administrators, improves the convenience of obtaining security information and the efficiency of protection, reduces response delay, and enhances the system's timeliness and automation capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121682848A_ABST
    Figure CN121682848A_ABST
Patent Text Reader

Abstract

The invention discloses an artificial intelligence-based security monitoring system and method for credential software, and belongs to the technical field of security monitoring of credential software, the artificial intelligence-based security monitoring system for credential software comprises a data acquisition module, a data storage module, an AI analysis module, an intelligent question and answer interaction module and an automatic regulation and control module, the data acquisition module acquires security data involved in the operation process of the credential software; the data storage module stores the collected data into a database; the AI analysis module extracts key features in the operation process of the credential software, and calculates risk scores to quantify potential threats; the intelligent question and answer interaction module establishes an intelligent question and answer interaction model and provides a safety state report through interaction with a user; the automatic regulation and control module optimizes the intelligent question and answer model according to feedback suggestions of the user, and interaction between the user and the credential software is achieved by establishing the intelligent question and answer interaction model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology application innovation software security monitoring technology, specifically to an information technology application innovation software security monitoring system and method based on artificial intelligence. Background Technology

[0002] With the rapid development of the information technology application innovation system, domestically developed operating systems, databases, middleware, and application software have been widely used. The promotion of domestically developed software has not only effectively reduced dependence on foreign technologies, but also provided important support for ensuring national information security and independent control. However, the security threats faced by domestically developed software during its application are constantly increasing. Hacker attacks, malware, and system vulnerabilities can seriously affect the stability of the system and data security. Therefore, the security protection of domestically developed software has become a technical challenge that urgently needs to be addressed.

[0003] Currently, most security protection solutions for domestically developed IT software rely on traditional security monitoring tools, including firewalls and antivirus software. These tools are typically based on rule matching or signature detection, making them ill-equipped to handle constantly evolving new attack methods. Furthermore, traditional security methods lack intelligent processing capabilities, failing to analyze complex security threats in real time and struggle to promptly identify and respond to unknown attack behaviors. To address these issues, artificial intelligence technology is widely applied in the field of network and information security. By combining machine learning, deep learning, and natural language processing technologies, security systems can analyze large amounts of complex data, identify abnormal behavior, and respond automatically. However, current security monitoring technologies for domestically developed IT software still have the following shortcomings: First, there is a lack of intelligent question-and-answer systems. Existing security protection for domestically developed IT software is mostly based on passive response, lacking effective interaction with users or administrators. Users cannot easily understand the current system security status or obtain targeted protection suggestions. Second, the ability to cope with complex security threats is insufficient. As attack methods continue to evolve, existing security protection solutions cannot effectively identify and defend against complex attack scenarios. Furthermore, there is a lack of real-time and automated response. After a threat is detected, the security system still requires manual intervention to respond effectively, leading to response delays and increasing the risk of system attacks. Summary of the Invention

[0004] The purpose of this invention is to provide an artificial intelligence-based security monitoring system and method for domestically developed software, in order to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: an artificial intelligence-based security monitoring system for domestically developed IT software. The system includes: a data acquisition module, a data storage module, an AI analysis module, an intelligent question-and-answer interaction module, and an automatic control module. The data acquisition module collects security data involved in the operation of the domestically developed IT software, including system logs, network traffic, process information, and user behavior. The data storage module stores all collected data in a database. The AI ​​analysis module includes a feature extraction unit and a risk prediction unit, extracting key features during the operation of the domestically developed IT software and quantifying potential threats by calculating risk scores. The intelligent question-and-answer interaction module establishes an intelligent question-and-answer interaction model, providing security status reports and protection suggestions through interaction with users. The automatic control module includes a feedback learning unit and an interaction history recording unit, optimizing the intelligent question-and-answer model, adjusting the knowledge base priority, automatically saving interaction records, and supporting administrators in viewing logs and protection measures.

[0006] Furthermore, the data acquisition module includes a software log acquisition unit, a network traffic acquisition unit, a process information acquisition unit, and a user behavior acquisition unit. The software log acquisition unit collects the number of log events during the operation of the software in real time. The network traffic acquisition unit is used to collect network traffic usage. The process information acquisition unit is used to track process startup frequency and resource usage. The user behavior acquisition unit is used to collect user login behavior and permission operations.

[0007] Furthermore, the AI ​​analysis module includes a feature extraction unit and a risk prediction unit. The feature extraction unit is used to extract the specific instruction sequence called by the domestic software during operation, the number of abnormal log events, abnormal network traffic, the number of abnormal processes, and the number of abnormal user behaviors. The risk prediction unit takes the extracted features as input, calculates a risk score to quantify the potential threat represented by each feature, and sets a threshold for the risk score. This value is dynamically adjusted and determined through historical data. When the risk score of a certain behavior exceeds the set risk score threshold, the behavior is marked as high-risk and given priority processing.

[0008] Furthermore, the intelligent question-answering interaction module includes an intelligent question-answering model building unit and an intelligent question-answering model training unit. The intelligent question-answering model building unit is used to identify intent and key entities from user input, and build an intelligent question-answering model that can interact with the user in natural language. It also uses a similarity calculation formula to calculate the matching degree between the user's question and relevant records in the knowledge base, and finds the security questions and related suggestions that best match the user's question. The intelligent question-answering model training unit is used to record newly emerging security events and user feedback into the knowledge base and update the intelligent question-answering interaction model.

[0009] The AI-based security monitoring method for domestically developed IT software includes the following steps: S1: Obtain security data involved in the operation of domestically developed software, including system logs, network traffic, process information, and user behavior; S2: For unknown security issues of domestically developed software, feature extraction is performed on the security data involved in the operation of domestically developed software, and risk prediction and anomaly detection are performed on it; S3: Establish an intelligent question-and-answer interaction model. Through interaction with users, provide security status reports and protection suggestions. When the administrator needs to manually intervene or adjust the system's security policy, the AI-based information technology innovation software security monitoring system will ask questions through intelligent question-and-answer interaction, inquiring whether the administrator wants to take further measures, including changing the policy, activating additional protection, and analyzing specific logs. S4: Allows users to provide feedback and suggestions, continuously optimizes the intelligent question-answering model, adjusts the knowledge base priority, automatically saves interaction records, and supports administrators in viewing logs and protection measures.

[0010] Furthermore, in step S2: For unknown security issues related to domestically developed software, feature extraction is performed on the security data involved in the operation of the domestically developed software. The specific steps are as follows: S2-1: Extract the specific instruction sequence called during the operation of the domestic software, monitor and analyze its execution trajectory, use static and dynamic code analysis techniques, focus on key instructions related to software security such as system calls, kernel operations and file access, and on the basis of extracting instruction sets, identify the number of abnormal instruction calls and instruction paths related to the core functions of the software. S2-2: Analyze system logs, network, processes, and user behavior, including identifying security-related abnormal log events by matching keywords and analyzing their frequency and time distribution; monitor the usage and protocols of network communication ports, focusing on whether uncommon or unauthorized ports are occupied, and detect abnormal traffic or malicious external communication, including abnormal port scanning and data leakage, and calculate the degree of abnormal deviation in network traffic; track process startup frequency and resource usage, paying attention to processes that start multiple times in a short period of time or processes that consume a lot of system resources, especially unregistered or high-resource-consuming processes; analyze user login behavior and permission operations, including the number of failed login attempts, privilege escalation attempts, and operations performed during abnormal times or locations.

[0011] Furthermore, the SVM machine learning algorithm is used to build a security model for risk prediction and anomaly detection in domestically developed software. The specific steps are as follows: S2-3: The ratio of the number of abnormal instruction calls to the total number of instruction calls is used as the feature value f1 of the instruction set; the ratio of the number of abnormal log events to the total number of log events is used as the feature value f2 of the system log; the ratio of abnormal network traffic to the total network traffic is used as the feature value f3 of network traffic; the ratio of the number of abnormal processes to the total number of processes is used as the feature value f4 of process information; and the ratio of the number of abnormal user actions to the total number of user actions is used as the feature value f5 of user behavior. S2-4: Using the extracted features as input, a security protection model is constructed through classification training using the SVM algorithm. This model classifies normal behavior and abnormal behavior and outputs a risk score for each behavior. The risk score calculation formula is as follows: R=w1*f1+w2*f2+w3*f3+w4*f4+w5*f5, where R represents the risk score, which is used to quantify the potential threat represented by each feature, and w1, w2, w3, w4, and w5 represent the weights of each feature, and w1+w2+w3+w4+w5=1; S2-5: Set a risk score threshold and dynamically adjust the value based on historical data. When the risk score R of a certain behavior exceeds the set risk score threshold, the behavior is marked as high-risk and given priority.

[0012] Furthermore, in step S3: an intelligent question-and-answer interaction model is established to provide security status reports and protection suggestions through interaction with users. The specific steps are as follows: S3-1: Perform intent recognition and named entity recognition on the user's question, transform the natural language question input by the user into a structured query, and extract key entities from the input through NER; S3-2: A TF-IDF-based text vectorization method transforms user questions and records in the knowledge base into vector representations. It then calculates the matching degree using a similarity formula between the user question and the records in the knowledge base, finding the security questions and related suggestions that best match the user question. The similarity S between the user question and the records in the knowledge base is calculated using the following formula: ; Among them, Q i and K i This represents the weight of the user question and the knowledge base question in the i-th word dimension, where n represents the size of the dimension after the vector, and K... w T represents the number of times the keywords in the user's input question match those in the knowledge base question. u L represents the total number of words in the user's input question. u L represents the number of words in the user's question. k The number of words in the knowledge base question represents the number of words in the question. α, β, and γ represent the weighting coefficients, and α+β+γ=1. S3-3: Sort according to similarity and introduce a threshold mechanism. When the similarity is lower than the set similarity threshold, perform fuzzy recommendation of multiple matching results instead of providing only one answer. S3-4: Generate personalized security protection suggestions based on user roles and historical behavior. For administrator-level users, the AI-based domestic software security monitoring system provides remediation steps, and administrators can manually intervene or adjust the system's security policies. For ordinary users, it provides security status reports and suggestions.

[0013] Furthermore, in step S4: users are allowed to provide feedback and suggestions, the intelligent question-answering model is continuously optimized, the knowledge base priority is adjusted, interaction records are automatically saved, and administrators are supported in viewing logs and protective measures. The specific steps are as follows: S4-1: After each suggestion is generated, users are allowed to provide feedback, including "Is this suggestion useful?" or "Do I need more details?". Based on user feedback, the intelligent question-answering model and security strategy are continuously optimized. When the AI-based information technology security monitoring system detects that the number of times a user requests the same type of suggestion is greater than q, the priority in the knowledge base is adjusted to respond to similar queries more quickly. User feedback and new security events are recorded in the knowledge base, and the intelligent question-answering interaction model is updated to better adapt to emerging threats and user needs. q represents the set threshold for the number of times a user requests the same type of suggestion. S4-2: Automatically saves all user interaction records with the intelligent question-and-answer system. Users can view past security status reports and suggestions through the interface to understand changes in the system's security status. Administrators have access to all interaction records. The AI-based information technology innovation software security monitoring system provides detailed interaction logs, including user queries, suggestions provided, and protective measures taken.

[0014] Compared with the prior art, the beneficial effects achieved by the present invention are: 1. By building an intelligent question-and-answer interaction model, it is possible to interact with users and administrators in real time, enabling users to easily obtain system security status and targeted protection suggestions. This interaction mechanism improves user experience and reduces the complexity of obtaining security information.

[0015] 2. By combining artificial intelligence technology, the AI-based domestic software security monitoring system has proactive response capabilities. When a potential threat is identified, the system can automatically take measures to reduce manual intervention and thus improve protection efficiency. At the same time, the automated response mechanism shortens the time delay between threat detection and action, reduces the risk of attacks on domestic software, and improves the timeliness of protection measures. Attached Figure Description

[0016] Figure 1 This is a structural diagram of the AI-based information technology application security monitoring system of the present invention; Figure 2 This is a flowchart of the AI-based security monitoring method for domestically developed software, as described in this invention. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0018] like Figures 1-2 As shown, this invention provides a technical solution: an AI-based security monitoring system for domestically developed IT software. The system includes a data acquisition module, a data storage module, an AI analysis module, an intelligent question-and-answer interaction module, and an automatic control module. The data acquisition module collects security data involved in the operation of the domestically developed IT software, including system logs, network traffic, process information, and user behavior. The data storage module stores all collected data in a database. The AI ​​analysis module includes a feature extraction unit and a risk prediction unit, extracting key features during the operation of the domestically developed IT software and quantifying potential threats by calculating risk scores. The intelligent question-and-answer interaction module establishes an intelligent question-and-answer interaction model, providing security status reports and protection suggestions through interaction with users. The automatic control module includes a feedback learning unit and an interaction history recording unit, optimizing the intelligent question-and-answer model, adjusting the knowledge base priority, automatically saving interaction records, and supporting administrators in viewing logs and protection measures.

[0019] The data acquisition module includes a software log acquisition unit, a network traffic acquisition unit, a process information acquisition unit, and a user behavior acquisition unit. The software log acquisition unit collects the number of log events during the operation of the software in real time. The network traffic acquisition unit is used to collect network traffic usage. The process information acquisition unit is used to track process startup frequency and resource usage. The user behavior acquisition unit is used to collect user login behavior and permission operations.

[0020] The AI ​​analysis module includes a feature extraction unit and a risk prediction unit. The feature extraction unit is used to extract the specific instruction sequence called by the domestic software during operation, the number of abnormal log events, abnormal network traffic, the number of abnormal processes, and the number of abnormal user behaviors. The risk prediction unit takes the extracted features as input, calculates a risk score to quantify the potential threat represented by each feature, and sets a threshold for the risk score. This threshold is dynamically adjusted and determined using historical data. When the risk score of a certain behavior exceeds the set risk score threshold, the behavior is marked as high-risk and given priority processing.

[0021] The intelligent question-answering interaction module includes an intelligent question-answering model building unit and an intelligent question-answering model training unit. The intelligent question-answering model building unit is used to identify intent and key entities from user input, and build an intelligent question-answering model that can interact with the user in natural language. It also uses a similarity calculation formula to calculate the matching degree between the user's question and relevant records in the knowledge base, and finds the security questions and related suggestions that best match the user's question. The intelligent question-answering model training unit is used to record newly emerging security events and user feedback into the knowledge base and update the intelligent question-answering interaction model.

[0022] The AI-based security monitoring method for domestically developed IT software includes the following steps: S1: Obtain security data involved in the operation of domestically developed software, including system logs, network traffic, process information, and user behavior; S2: For unknown security issues of domestically developed software, feature extraction is performed on the security data involved in the operation of domestically developed software, and risk prediction and anomaly detection are performed on it; S3: Establish an intelligent question-and-answer interaction model. Through interaction with users, provide security status reports and protection suggestions. When the administrator needs to manually intervene or adjust the system's security policy, the AI-based information technology innovation software security monitoring system will ask questions through intelligent question-and-answer interaction, inquiring whether the administrator wants to take further measures, including changing the policy, activating additional protection, and analyzing specific logs. S4: Allows users to provide feedback and suggestions, continuously optimizes the intelligent question-answering model, adjusts the knowledge base priority, automatically saves interaction records, and supports administrators in viewing logs and protection measures.

[0023] In step S2: For unknown security issues in domestically developed software, feature extraction is performed on the security data involved in the operation of the domestically developed software. The specific steps are as follows: S2-1: Extract the specific instruction sequence called during the operation of the domestic software, monitor and analyze its execution trajectory, use static and dynamic code analysis techniques, focus on key instructions related to software security such as system calls, kernel operations and file access, and on the basis of extracting instruction sets, identify the number of abnormal instruction calls and instruction paths related to the core functions of the software. S2-2: Analyze system logs, network, processes, and user behavior, including identifying security-related abnormal log events by matching keywords and analyzing their frequency and time distribution; monitor the usage and protocols of network communication ports, focusing on whether uncommon or unauthorized ports are occupied, and detect abnormal traffic or malicious external communication, including abnormal port scanning and data leakage, and calculate the degree of abnormal deviation in network traffic; track process startup frequency and resource usage, paying attention to processes that start multiple times in a short period of time or processes that consume a lot of system resources, especially unregistered or high-resource-consuming processes; analyze user login behavior and permission operations, including the number of failed login attempts, privilege escalation attempts, and operations performed during abnormal times or locations.

[0024] The SVM machine learning algorithm is used to build a security model for risk prediction and anomaly detection in domestically developed software. The specific steps are as follows: S2-3: The ratio of the number of abnormal instruction calls to the total number of instruction calls is used as the feature value f1 of the instruction set; the ratio of the number of abnormal log events to the total number of log events is used as the feature value f2 of the system log; the ratio of abnormal network traffic to the total network traffic is used as the feature value f3 of network traffic; the ratio of the number of abnormal processes to the total number of processes is used as the feature value f4 of process information; and the ratio of the number of abnormal user actions to the total number of user actions is used as the feature value f5 of user behavior. S2-4: Using the extracted features as input, a security protection model is constructed through classification training using the SVM algorithm. This model classifies normal behavior and abnormal behavior and outputs a risk score for each behavior. The risk score calculation formula is as follows: R=w1*f1+w2*f2+w3*f3+w4*f4+w5*f5, where R represents the risk score, which is used to quantify the potential threat represented by each feature, and w1, w2, w3, w4, and w5 represent the weights of each feature, and w1+w2+w3+w4+w5=1; S2-5: Set a risk score threshold and dynamically adjust the value based on historical data. When the risk score R of a certain behavior exceeds the set risk score threshold, the behavior is marked as high-risk and given priority.

[0025] In step S3: Establish an intelligent question-and-answer interaction model to provide security status reports and protection suggestions through interaction with users. The specific steps are as follows: S3-1: Perform intent recognition and named entity recognition on the user's question, transform the natural language question input by the user into a structured query, and extract key entities from the input through NER; S3-2: A TF-IDF-based text vectorization method transforms user questions and records in the knowledge base into vector representations. It then calculates the matching degree using a similarity formula between the user question and the records in the knowledge base, finding the security questions and related suggestions that best match the user question. The similarity S between the user question and the records in the knowledge base is calculated using the following formula: ; Among them, Q i and K i This represents the weight of the user question and the knowledge base question in the i-th word dimension, where n represents the size of the dimension after the vector, and K... w T represents the number of times the keywords in the user's input question match those in the knowledge base question. u L represents the total number of words in the user's input question. u L represents the number of words in the user's question. k The number of words in the knowledge base question represents the number of words in the question. α, β, and γ represent the weighting coefficients, and α+β+γ=1. S3-3: Sort according to similarity and introduce a threshold mechanism. When the similarity is lower than the set similarity threshold, perform fuzzy recommendation of multiple matching results instead of providing only one answer. S3-4: Generate personalized security protection suggestions based on user roles and historical behavior. For administrator-level users, the AI-based domestic software security monitoring system provides remediation steps, and administrators can manually intervene or adjust the system's security policies. For ordinary users, it provides security status reports and suggestions.

[0026] In step S4: Allow users to provide feedback and suggestions, continuously optimize the intelligent question-answering model, adjust the knowledge base priority, automatically save interaction records, and support administrators to view logs and protection measures. The specific steps are as follows: S4-1: After each suggestion is generated, users are allowed to provide feedback, including "Is this suggestion useful?" or "Do I need more details?". Based on user feedback, the intelligent question-answering model and security strategy are continuously optimized. When the AI-based information technology security monitoring system detects that the number of times a user requests the same type of suggestion is greater than q, the priority in the knowledge base is adjusted to respond to similar queries more quickly. User feedback and new security events are recorded in the knowledge base, and the intelligent question-answering interaction model is updated to better adapt to emerging threats and user needs. q represents the set threshold for the number of times a user requests the same type of suggestion. S4-2: Automatically saves all user interaction records with the intelligent question-and-answer system. Users can view past security status reports and suggestions through the interface to understand changes in the system's security status. Administrators have access to all interaction records. The AI-based information technology innovation software security monitoring system provides detailed interaction logs, including user queries, suggestions provided, and protective measures taken.

[0027] In this embodiment: Data from the domestically developed software is monitored 24 / 7 in real-time. All system logs, network traffic, user behavior, and instruction execution sequences are collected. Abnormal instruction call counts are extracted from the domestically developed software. 200 abnormal instructions are detected out of 10,000 instructions, with an extraction ratio of 200 / 10000 = 0.02, i.e., instruction set feature value f1 = 0.02. 50 instances of "unauthorized access" appear in the system logs, with a total of 500 event records, resulting in an abnormal event ratio of 50 / 500 = 0.1, i.e., system log feature value f2 = 0.1. 500MB of abnormal traffic is detected from the total traffic, accounting for 500MB / 10GB = 0.05, i.e., network traffic feature value f3 = 0.05. A total of 1... There were 00 process starts, of which 10 were high-frequency abnormal starts, with an abnormality ratio of 10 / 100 = 0.1, meaning the process information feature value f4 = 0.1. There were 5 failed user logins, 2 privilege escalations, and 7 abnormal user behavior records, for a total of 200 behavior records. The abnormal behavior ratio was 7 / 200 = 0.035, meaning the user behavior feature value f5 = 0.035. With each feature weight set to w1=w2=w3=w4=w5=0.2 and a risk score threshold set to 0.05, the risk score calculated using the formula R=w1*f1+w2*f2+w3*f3+w4*f4+w5*f5 is 0.061. This risk score exceeds the set threshold, and the behavior is flagged. For high-risk cases requiring priority handling, users query "How to prevent SQL injection attacks?" through an AI-based domestic software security monitoring system. The system's knowledge base contains the following related security questions and protection suggestions: 1. "What are the protective measures against SQL injection attacks?", 2. "How to defend against cross-site scripting attacks?", 3. "How to deal with distributed denial-of-service attacks?". Using the TF-IDF method, the user's question and the questions in the knowledge base are transformed into vector representations. The user question, "How to prevent SQL injection attacks?", is converted into the vector: [0.2, 0.8, 0.1, 0.05]. The knowledge base record, "1. What are the protective measures against SQL injection attacks?", is converted into the vector: [0.3, 0.7, ...]. 1. "How to defend against cross-site scripting attacks?" is converted into vector: [0.1, 0.05], 2. "How to defend against cross-site scripting attacks?" is converted into vector: [0.1, 0.4, 0.3, 0.2], 3. "How to deal with distributed denial-of-service attacks?" is converted into vector: [0.05, 0.3, 0.25, 0.4]. Using natural language processing technology, the system extracts keywords from user questions and questions in the knowledge base and performs matching: User question keywords: SQL injection and protection; Knowledge base question keywords: 1. SQL injection and protection 2. Cross-site scripting and protection 3. Distributed denial-of-service and defense. Based on the similarity calculation formula between user questions and records in the knowledge base, the similarity between user question and knowledge base question 1 is 0.81, and the similarity between user question and knowledge base question 2 is 0.385. The user's question has a similarity score of 0.42 with knowledge base question 3. With a set similarity threshold of 0.75, question 1, ranked by similarity, has the highest similarity score of 0.81. Therefore, the system recommends this question and its corresponding protective measures.

[0028] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. An AI-based Xinda software security monitoring system, characterized in that, The system comprises a data acquisition module, a data storage module, an AI analysis module, an intelligent question and answer interaction module, and an automatic regulation module, the data acquisition module is used to acquire security data involved in the running process of the signal creation software, including system logs, network traffic, process information, and user behavior; the data storage module is used to store all the collected data into a database; the AI analysis module comprises a feature extraction unit and a risk prediction unit, which extracts key features in the running process of the signal creation software, and quantifies potential threats by calculating risk scores; the intelligent question and answer interaction module is used to establish an intelligent question and answer interaction model, to provide security status reports and protection suggestions by interacting with the user; the automatic regulation module comprises a feedback learning unit and an interaction history recording unit, which optimizes the intelligent question and answer model according to the user's feedback suggestions, adjusts the priority of the knowledge base, automatically saves the interaction record, and supports the administrator to view the log and protection measures.

2. The AI-based Xinda software security monitoring system of claim 1, wherein: The data acquisition module comprises a signal creation software log acquisition unit, a network traffic acquisition unit, a process information acquisition unit, and a user behavior acquisition unit, the signal creation software log acquisition unit acquires the number of log events in the running process of the signal creation software in real time, the network traffic acquisition unit is used to acquire the usage of network traffic, the process information acquisition unit is used to track the process startup frequency and resource usage, and the user behavior acquisition unit is used to acquire the user's login behavior and permission operation. 3.The AI-based Xinda software security monitoring system according to claim 1, characterized in that: The AI analysis module comprises a feature extraction unit and a risk prediction unit, the feature extraction unit is used to extract the specific instruction sequence called by the signal creation software in the running process, the number of abnormal log events, abnormal network traffic, abnormal process times, and abnormal user behavior times, the risk prediction unit takes the extracted features as input, quantifies the potential threat represented by each feature by calculating the risk score, sets the threshold value of the risk score, dynamically adjusts the value through historical data, and when the risk score of a certain behavior exceeds the set risk score threshold, marks the behavior as high risk and processes it preferentially.

4. The AI-based security monitoring system for China-specific software according to claim 1, characterized in that: The intelligent question and answer interaction module comprises an intelligent question and answer model establishment unit and an intelligent question and answer model training unit, the intelligent question and answer model establishment unit is used to identify the intent and key entity from the user input, establish an intelligent question and answer model capable of natural language interaction with the user, and calculate the matching degree of the user's question and the related records in the knowledge base using a similarity calculation formula, to find the most consistent security problem and related suggestion with the user's question, the intelligent question and answer model training unit is used to record new security events and user feedback into the knowledge base, and update the intelligent question and answer interaction model.

5. The signal creation software security monitoring method based on artificial intelligence comprises the following steps: S1: acquiring security data involved in the running process of the signal creation software, including system logs, network traffic, process information, and user behavior; S2: for unknown signal creation software security, feature extraction is performed on the security data involved in the running process of the signal creation software, and risk prediction and anomaly detection are performed. S3: Establish an intelligent question and answer interaction model, provide security status report and protection suggestions through interaction with the user, when the administrator needs to manually intervene or adjust the security policy of the system, through intelligent question and answer interaction, the security monitoring system based on artificial intelligence puts forward questions and asks the administrator whether to take further measures, including changing the policy, starting additional protection and analyzing specific logs; S4: Allow users to provide feedback and continuously optimize the intelligent question and answer model, adjust the knowledge base priority, automatically save interaction records, and support administrators to view logs and protection measures.

6. The AI-based monitoring method for the security of the Xinda software according to claim 5, characterized in that: In step S2: For unknown security of the software, the security data involved in the running of the software is extracted, and the specific steps are as follows: S2-1: Extract the specific instruction sequence called during the running of the software, and monitor and analyze its execution trajectory, use static and dynamic code analysis technology, focus on key instructions related to software security such as system call, kernel operation and file access, and on the basis of extracting instruction set, identify the number of abnormal instruction calls related to core functions of the software and instruction paths; S2-2: Analyze system logs, network, processes and user behavior, including identifying security-related abnormal log events by matching keywords, and analyzing their frequency and time distribution; monitor the use of network communication ports and protocols, focus on analyzing whether unusual or unauthorized ports are occupied, and detect whether there are abnormal traffic or malicious external communication, including abnormal port scanning and data leakage, calculate the abnormal deviation degree of network traffic; track the process startup frequency and resource usage, pay attention to processes that are started multiple times in a short period of time or processes that occupy a large amount of system resources, especially unregistered or high resource consumption processes; analyze user login behavior and permission operations, including login failure times, permission elevation attempts, and operations performed at abnormal times or locations.

7. The AI-based software security monitoring method of claim 6, wherein: In step S2: Use SVM machine learning algorithm to build security model, predict risk and detect abnormalities of the software, the specific steps are as follows: S2-3: Calculate the ratio of the number of abnormal instruction calls to the total number of instruction calls as the feature value f1 of the instruction set; calculate the ratio of the number of abnormal log events to the total number of log events as the feature value f2 of the system log; calculate the ratio of abnormal network traffic to total network traffic as the feature value f3 of network traffic; calculate the ratio of the number of abnormal processes to the total number of processes as the feature value f4 of process information; calculate the ratio of the number of abnormal user behaviors to the total number of user behaviors as the feature value f5 of user behavior; S2-4: The extracted features are inputted into the SVM algorithm for classification training to build a security protection model that classifies normal behavior and abnormal behavior and outputs a risk score of each behavior, with the risk score calculation formula as follows: R = w1*f1 + w2*f2 + w3*f3 + w4*f4 + w5*f5, wherein R represents the risk score for quantifying the potential threat represented by each feature, w1, w2, w3, w4, and w5 represent the weight of each feature, and w1 + w2 + w3 + w4 + w5 = 1; S2-5: A threshold value of the risk score is set, and the value is dynamically adjusted through historical data. When the risk score R of a certain behavior exceeds the set risk score threshold, the behavior is marked as high risk and is processed preferentially.

8. The AI-based monitoring method for the security of the China software according to claim 5, characterized in that: In step S3: An intelligent question and answer interaction model is established to provide a security status report and protection suggestions through interaction with the user, with the specific steps as follows: S3-1: The intent recognition and named entity recognition are performed on the question raised by the user to convert the natural language question input by the user into a structured query, and the key entities are extracted from the input through NER; S3-2: The TF-IDF-based text vectorization method is used to convert the user question and the records in the knowledge base into vector representations, and the matching degree is calculated through the user question and the record similarity calculation formula in the knowledge base to find the most similar security question and related suggestions to the user question, with the user question and the record similarity S in the knowledge base calculated by the formula as follows: ; wherein Q i and K i represent the weight of the user question and the knowledge base question in the i-th word dimension, n represents the dimension size after the vector, K w represents the number of matching keywords in the user input question and the knowledge base question, T u represents the total number of words in the user input question, L u represents the number of words in the user question, L k represents the number of words in the knowledge base question, and a, b and g represent weight coefficients, and a+b+g=1. S3-3: The similarity is sorted, and a threshold mechanism is introduced. When the similarity is lower than the set similarity threshold, fuzzy recommendation of multiple matching results is performed instead of providing only one answer; S3-4: Individualized security protection suggestions are generated according to the user role and historical behavior. For administrator-level users, the AI-based Xinyuan software security monitoring system provides repair steps, and the administrator can manually intervene or adjust the security policy of the system, while for ordinary users, a security status report and suggestions are provided.

9. The AI-based security monitoring method for China-specific software according to claim 5, characterized in that: In step S4: The user is allowed to provide feedback to continuously optimize the intelligent question and answer model, adjust the priority of the knowledge base, automatically save the interaction records, and support the administrator to view the logs and protection measures, with the specific steps as follows: S4-1: After each suggestion is generated, the user is allowed to provide feedback, and the intelligent question and answer model and the security policy are continuously optimized according to the feedback information of the user. When the AI-based Xinyuan software security monitoring system detects that the number of times of the user requesting the same type of suggestion is greater than q, the priority in the knowledge base is adjusted to respond to similar queries faster; the user feedback and new security event records are recorded in the knowledge base, and the intelligent question and answer interaction model is updated, and q represents the set threshold value of the number of times of the user requesting the same type of suggestion; S4-2: All interaction records of the user with the intelligent question and answer system are automatically saved, and the user can view the past security status report and suggestions through the interface; Administrators have access to all interaction records, which the AI-based Xinyuan software security monitoring system provides in detail, including user queries, provided recommendations, and taken protective measures.