Construction method of network crime-based case investigation training platform

By constructing a virtual 3D spatial model, injecting multimodal evidence data streams, and deploying probes, combined with a dynamic response engine and a case deduction logic layer, the problem that existing training platforms cannot simulate complex case changes has been solved, thus realizing an intelligent training environment and skills enhancement.

CN121767561BActive Publication Date: 2026-05-15FUJIAN ZHONGRUI ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FUJIAN ZHONGRUI ELECTRONIC TECH CO LTD
Filing Date
2025-12-25
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing training platforms for investigating cybercrime cases cannot simulate the concealment and relevance of evidence in real cases, as well as the dynamic changes brought about by the suspect's counter-investigation behavior. The training scenarios are rigid and cannot effectively train trainees' ability to discover evidence and reason logically in complex environments. They also lack intelligent behavior recognition and feedback mechanisms.

Method used

A case investigation training platform based on cybercrime is constructed. A virtual three-dimensional space model is generated by spatial topology modeling of the physical training site, and virtual partitioning is carried out according to the elements of cybercrime cases. Multimodal virtual crime evidence data streams are injected, environmental status and user behavior probes are deployed, a dynamic response engine and a case inference logic layer are constructed, and an integrated interactive console is established to realize real-time data collection and dynamic response.

Benefits of technology

It enhances the realism and relevance of training scenarios, hones the skills of constructing chains of evidence in complex information environments, systematically improves trainees' on-the-spot decision-making and comprehensive judgment abilities, and creates an intelligent training environment with flexible feedback.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121767561B_ABST
    Figure CN121767561B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of virtual simulation training, and discloses a construction method of a case investigation training platform based on network crime. The method comprises the following steps: performing spatial topology modeling on a physical training site, generating a virtual three-dimensional space model, and performing function partitioning of case simulation, electronic evidence collection, and command research and judgment; dynamically injecting multi-modal virtual evidence into the simulation area according to real case files; collecting environmental state and user operation behavior data in real time through a deployed probe; processing data according to preset case state transition rules by using a dynamic response engine, driving virtual scene elements to evolve in real time in a logical manner; and realizing state monitoring and deduction parameter adjustment through an integrated interactive console. The constructed platform realizes dynamic correlation of evidence and intelligent deduction of case information, and can improve the fidelity and practicality of investigation training.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of virtual simulation training technology, specifically to a method for constructing a training platform for investigating cybercrime cases. Background Technology

[0002] Currently, training in cybercrime investigation skills largely relies on theoretical lectures, case reviews, or simulation systems using pre-written scripts. These existing solutions have significant limitations in creating training environments that closely resemble real-world scenarios. Traditional simulation training platforms typically fix static evidence materials such as images and documents in specific locations within a virtual environment, and the training process depends on pre-written linear scripts. This model cannot simulate the concealment and relevance of evidence in real cases, nor the dynamic changes brought about by suspects' counter-investigation behaviors. This results in rigid training scenarios, where trainees follow a rigid formula, making it difficult to develop their ability to proactively discover, connect, and uncover evidence in complex and uncertain environments.

[0003] Existing training systems lack intelligent mechanisms for recognizing and responding to trainees' actions. System interactions are mostly based on simple trigger-response patterns, such as displaying information upon clicking an object, resulting in a fixed evolution path throughout the training process. The system cannot adjust the training scenarios and challenge difficulty in real-time, in accordance with the trainees' actual investigation sequence, evidence collection methods, and analytical logic, or in a manner consistent with the patterns of real case investigation. The training process is disconnected from the spiral progression of "behavior-feedback-analysis-new behavior" in real case investigation, failing to effectively train investigators' comprehensive abilities in on-the-spot decision-making, logical reasoning, and responding to changes in case circumstances. Summary of the Invention

[0004] The purpose of this invention is to provide a method for constructing a training platform for investigating cybercrime cases, in order to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides a method for constructing a training platform for investigating cybercrime cases, the method comprising:

[0006] Perform spatial topology modeling on the pre-set physical training site to generate a corresponding virtual three-dimensional space model;

[0007] In the virtual three-dimensional space model, virtual partitions are formed based on the elements of cybercrime cases, creating a case scene simulation area, an electronic data fixation area, and an investigation command and analysis area;

[0008] Based on historical case files, multimodal virtual crime evidence data streams are injected into the crime scene simulation area;

[0009] Deploy environmental status probes and user behavior capture probes to collect environmental status data streams and user operation behavior data streams in real time for each partition within the virtual three-dimensional space model;

[0010] A dynamic response engine is constructed to receive and process the environmental state data stream and the user operation behavior data stream, and drive the changes of elements within the virtual three-dimensional space model based on the processing results;

[0011] A case deduction logic layer is created, which pre-sets case state transition rules based on evidence chain deduction;

[0012] An integrated interactive console is established, which is used to present the real-time status of the virtual three-dimensional space model and receive external instructions to modify the parameters in the case deduction logic layer.

[0013] Preferably, the step of performing spatial topology modeling on the preset physical training site to generate a corresponding virtual three-dimensional space model specifically includes:

[0014] The point cloud data set of the physical training site is obtained by using a three-dimensional laser scanning device;

[0015] The point cloud dataset is subjected to denoising and surface reconstruction to generate a basic three-dimensional mesh model of the physical training site.

[0016] The virtual coordinate positions of network device nodes, IoT sensor terminals, and computing servers are embedded in the basic three-dimensional mesh model.

[0017] Based on the virtual space flow paths involved in the investigation of cybercrime cases, the data transmission channels and logical isolation boundaries are marked in the basic three-dimensional mesh model;

[0018] The labeled basic 3D mesh model, virtual coordinate positions, data transmission channels, and logical isolation boundaries are merged and rendered to output an interactive virtual 3D space model.

[0019] Preferably, the virtual partitioning in the virtual three-dimensional space model based on elements of cybercrime cases specifically includes:

[0020] The system analyzes the input elements of cybercrime cases, which include at least the virtual location of the crime scene, a list of electronic devices involved in the case, and a fund flow map.

[0021] Based on the virtual location of the crime scene, a closed logical boundary is defined in the virtual three-dimensional space model, and the area inside the logical boundary is defined as the crime scene simulation area;

[0022] Based on the list of electronic devices involved in the case, a data preprocessing area is generated around the simulated area of ​​the case scene, which is defined as the electronic data fixing area. The electronic data fixing area is used to simulate the process of data extraction, hash verification and read-only image creation.

[0023] Based on the fund flow map, a multi-level analysis view area is constructed in the virtual three-dimensional space model, defined as the investigation command and analysis area. The investigation command and analysis area is used to integrate and display the correlation of case-related data.

[0024] Preferably, the injection of multimodal virtual crime evidence data streams into the crime scene simulation area based on historical real case files specifically includes:

[0025] The historical case files are structured and analyzed to extract the time, people, actions, electronic evidence and communication records.

[0026] Generate a data packet with time and space attributes for each extracted entity;

[0027] The data packets are encapsulated into a continuous data stream according to time sequence and logical association;

[0028] The encapsulated data stream is injected into the corresponding logical location in the case scene simulation area of ​​the virtual three-dimensional space model, based on its spatial attributes.

[0029] In the case scene simulation area, the data stream is represented by virtual objects or log fragments that can be discovered, viewed, and associated by the user.

[0030] Preferably, the deployment of the environment status probe and user behavior capture probe, which collects environmental status data streams and user operation behavior data streams of each partition within the virtual 3D space model in real time, specifically includes:

[0031] In the system architecture of the virtual three-dimensional space model, a software probe module is embedded, which includes an environmental state probe cluster and a user behavior capture probe cluster.

[0032] The environmental status probe cluster is mounted on the virtual partition boundary and key logical nodes, and continuously collects information on the computing load, network latency and data access popularity of each partition in the virtual three-dimensional space model to form an environmental status data stream.

[0033] The user behavior capture probe cluster is embedded in the bottom layer of the user interaction interface, recording the user's movement trajectory in the virtual three-dimensional space model, the operation sequence of virtual objects, and the logical reasoning assumptions submitted in the reconnaissance command and analysis area, forming a user operation behavior data stream.

[0034] The environmental status data stream and user operation behavior data stream are timestamped and cached.

[0035] Preferably, the construction of the dynamic response engine for receiving and processing the environmental state data stream and the user operation behavior data stream specifically includes:

[0036] Create a message queue middleware to receive and temporarily store the environment status data stream and user operation behavior data stream;

[0037] Design a rule parser, which loads a scene response rule library, which defines the virtual world events that should be triggered for different data flow patterns;

[0038] The dynamic response engine sequentially reads data streams from the message queue middleware and matches the data stream patterns with the scenario response rule base.

[0039] When a match is successful, the dynamic response engine generates one or more virtual world event instructions. These virtual world event instructions are used to drive changes in the state of corresponding objects within the virtual three-dimensional space model, the appearance or hiding of clues, or to trigger preset case plot branches.

[0040] Preferably, the creation of the case deduction logic layer specifically includes:

[0041] Define the entities of evidence and their logical relationships, including support, contradiction, and derivation;

[0042] Based on the defined logical relationships, a network logic reasoning graph is constructed, where the nodes of the network logic reasoning graph are evidence entities and the edges are logical relationships;

[0043] On the network logic reasoning graph, state transition conditions are set, which are associated with the logical reasoning assumptions submitted in the user operation behavior data stream and the virtual world event instructions;

[0044] When the virtual world event command issued by the dynamic response engine or the logical reasoning assumption submitted by the user meets the specific state transition conditions, the case deduction logic layer will update the state of the relevant nodes in the mesh logic reasoning graph and activate the downstream logical relationships connected to them, thereby promoting the evolution of the case virtual state to the next stage.

[0045] Preferably, establishing the integrated interactive console specifically includes:

[0046] Develop a graphical rendering interface to synchronously display the real-time three-dimensional state of the virtual three-dimensional space model and the current topology of the mesh logic reasoning graph in the case deduction logic layer;

[0047] The graphical rendering interface integrates a case script editor, which allows authorized users to modify the state transition conditions in the case deduction logic layer or inject new multimodal virtual crime evidence data streams into the case scene simulation area.

[0048] The graphical rendering interface integrates a sand table simulation controller, which allows users to revert to any historical state node in the case simulation logic layer and restart the simulation from that historical state node.

[0049] The integrated interactive console communicates with the dynamic response engine and the case deduction logic layer via network protocols.

[0050] Preferably, the workflow of the case script editor includes:

[0051] A visual rule configuration panel is provided, on which authorized users can define new evidence entities and logical relationships by dragging and dropping, and add them to the network logic reasoning graph;

[0052] Provides a timeline editing tool, allowing authorized users to set the appearance, disappearance, or attribute change events of any virtual object in the case scene simulation area at a specific point in time on the timeline;

[0053] Serialize all new rules, entities, and events configured by the user through the case script editor into a structured description file;

[0054] The structured description file is submitted to the scene response rule base and case deduction logic layer of the dynamic response engine for loading, thereby updating the platform's built-in logic.

[0055] Preferably, the workflow of the sand table simulation controller includes:

[0056] During user operation, the case deduction logic layer continuously takes snapshots and archives the complete state change history of the network logic reasoning graph, along with the corresponding timestamps.

[0057] The sand table simulation controller provides a state history timeline interface, on which all archived snapshots are displayed in the form of time nodes;

[0058] When a user selects a historical time point on the status history timeline interface, the sand table simulation controller sends a status rollback command to the case simulation logic layer.

[0059] According to the state rollback instruction, the case deduction logic layer restores the internally maintained mesh logic reasoning graph to the complete state corresponding to the selected historical time node, and synchronizes this state to the graphics rendering interface for update. At the same time, it notifies the dynamic response engine to pause the processing of data streams after the current time point.

[0060] Compared with the prior art, the beneficial effects of the present invention are:

[0061] Based on historical case files, multimodal virtual crime evidence data streams are injected into a virtual 3D spatial model, changing the traditional isolated and static presentation of evidence in training. This technology transforms case file materials into an interactive, logically connected, and dynamically manifested evidence set in a virtual space, constructing a highly realistic digital crime scene ecosystem. When trainees conduct investigations and evidence collection within this environment, they need to use logical thinking to discover and connect discrete evidence points. This evidence environment, dynamically constructed based on data streams, frees training stages such as electronic data fixation and scene reconstruction from the constraints of pre-set scripts, enhancing the realism of scenario simulations and the relevance of training, and honing the core skill of constructing evidence chains in complex information environments.

[0062] By deploying environmental and behavioral probes, and combining a dynamic response engine with a case deduction logic layer pre-configured with case state transition rules, the training process has been transformed from one-way script execution to two-way intelligent interaction. The system can collect and understand the trainee's operational behaviors in real time and compare them with a rule base derived from the chain of evidence. When a behavioral sequence meets specific rule conditions, the engine automatically drives the virtual environment to evolve in accordance with criminal investigation logic. This dynamic case deduction mechanism based on real operational behaviors creates an intelligent training environment with flexible feedback, forcing trainees to consider the logical consequences and related impacts of each action as if handling a real case, thereby systematically improving their ability to make on-the-spot decisions, adjust strategies, and conduct comprehensive analysis under dynamic adversarial conditions. Attached Figure Description

[0063] Figure 1 This is a schematic diagram illustrating the working principle of the construction method of the case investigation training platform based on cybercrime described in this invention.

[0064] Figure 2 Flowchart generated for a virtual 3D space model;

[0065] Figure 3 Flowchart for injecting virtual crime evidence data stream;

[0066] Figure 4 A statistical chart showing the daily processing volume and priority of communication message types between the integrated interactive console and backend services;

[0067] Figure 5 A comparison chart showing the time taken to operate the timeline editing tool. Detailed Implementation

[0068] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0069] Please see Figure 1 This invention provides a method for constructing a training platform for investigating cybercrime cases. The method includes: performing spatial topology modeling on a pre-set physical training site to generate a corresponding virtual three-dimensional spatial model; virtually partitioning the virtual three-dimensional spatial model according to the elements of cybercrime cases to form a case scene simulation area, an electronic data fixation area, and an investigation command and analysis area; injecting multimodal virtual crime evidence data streams into the case scene simulation area based on historical real case files; deploying environmental state probes and user behavior capture probes to collect environmental state data streams and user operation behavior data streams from each partition within the virtual three-dimensional spatial model in real time; constructing a dynamic response engine to receive and process environmental state data streams and user operation behavior data streams, and driving changes in elements within the virtual three-dimensional spatial model based on the processing results; creating a case deduction logic layer, which pre-sets case state transition rules based on evidence chain deduction; and establishing an integrated interactive console to present the real-time status of the virtual three-dimensional spatial model and receive external commands to modify parameters within the case deduction logic layer.

[0070] Example 1: See Figure 2In the process of generating the virtual 3D space model, a point cloud dataset of the physical training site is acquired using a 3D laser scanning device. The point cloud dataset is then denoised and reconstructed to generate a basic 3D mesh model of the physical training site. Virtual coordinates of network device nodes, IoT sensor terminals, and computing servers are embedded in this basic 3D mesh model. Based on the virtual spatial flow paths involved in investigating cybercrime cases, data transmission channels and logical isolation boundaries are marked in the basic 3D mesh model. The marked basic 3D mesh model, virtual coordinates, data transmission channels, and logical isolation boundaries are then fused and rendered to output an interactive virtual 3D space model. When performing virtual partitioning within the virtual 3D space model, the input cybercrime case elements are parsed. These elements include at least the virtual location of the crime scene, a list of involved electronic devices, and a fund flow map. Based on the virtual location of the crime scene, a closed logical boundary is defined in the virtual 3D space model; the area inside this logical boundary is defined as the crime scene simulation area. Based on the list of electronic devices involved in the case, a data preprocessing area, defined as the electronic data fixing area, is generated around the simulated crime scene area. This area is used to simulate the processes of data extraction, hash verification, and read-only image creation. Based on the fund flow map, a multi-level analysis view area is constructed within the virtual 3D space model, defined as the investigation command and analysis area. This area is used to integrate and display the relationships between relevant case data.

[0071] In its implementation, a method for constructing a training platform for investigating cybercrime involves spatial topology modeling of a pre-designed physical training site to generate a virtual three-dimensional spatial model, and then virtually partitioning the virtual three-dimensional spatial model according to elements of cybercrime cases. Spatial topology modeling uses a 3D laser scanning device to acquire a point cloud dataset of the physical training site, which contains the 3D coordinate information of a large number of sampled points in the physical space. The point cloud dataset undergoes denoising and surface reconstruction processing. Denoising removes outliers from the point cloud dataset, and surface reconstruction generates a basic 3D mesh model of the physical training site based on the remaining point cloud data. This basic 3D mesh model consists of vertices, edges, and faces. Virtual coordinate positions of network device nodes, IoT sensor terminals, and computing servers are embedded in the basic 3D mesh model, corresponding to the actual layout of these entities in the physical training site. Based on the virtual spatial flow paths involved in investigating cybercrime cases, data transmission channels and logical isolation boundaries are marked in the basic 3D mesh model. Data transmission channels represent the transmission paths of virtual data flows between network device nodes, and logical isolation boundaries represent the separation interfaces between different security domains or functional areas. The labeled basic 3D mesh model, virtual coordinate position, data transmission channel and logical isolation boundary are merged and rendered. The fusion rendering process integrates geometric information and logical information and outputs it as an interactive virtual 3D space model. Users can freely navigate and operate in this virtual 3D space model.

[0072] In some embodiments, the implementation of virtual partitioning is accomplished by parsing input cybercrime case elements, which at least include the virtual location of the crime scene, a list of involved electronic devices, and a fund flow map. Based on the virtual location of the crime scene, a closed logical boundary is delineated in the virtual three-dimensional spatial model, and the area inside the logical boundary is defined as the crime scene simulation area. The logical boundary can be defined by a set of spatial plane equations, where the coordinates of any point in the virtual three-dimensional spatial model are given by equations. If the system of inequalities is satisfied Then it is determined that the point is located within the simulated crime scene area, where: parameters The coefficients of the j-th boundary plane are defined. The total number of planes surrounding the simulated crime scene area is determined. Based on the list of electronic devices involved in the case, a data preprocessing area is generated around the simulated crime scene area. This data preprocessing area is defined as the electronic data fixing area, which is used to simulate the processes of data extraction, hash verification, and read-only image creation. Based on the fund flow map, a multi-level analysis view area is constructed in the virtual 3D space model. This multi-level analysis view area is defined as the investigation command and analysis area, which is used to integrate and display the correlations between case-related data.

[0073] In practice, a 3D laser scanning device acquires surface geometric information of the physical training site at a specific resolution to form a point cloud dataset. Denoising and surface reconstruction are performed using iterative algorithms to optimize the topological consistency of the point cloud dataset. Virtual coordinate positions are embedded using a coordinate mapping table, which stores the correspondence between physical and virtual positions. Data transmission channels are labeled according to the network topology configuration file, and logical isolation boundaries are labeled according to the security policy configuration file. Fusion rendering uses a real-time graphics rendering engine to uniformly render the basic 3D mesh model and the overlaid logical annotation information onto the display interface.

[0074] Optionally, during the virtual partitioning process, the virtual location of the crime scene can be obtained from address information extracted from the case file through geocoding. The list of involved electronic devices details the types and quantities of devices requiring simulated evidence collection. The fund flow map represents account and transaction relationships using a graphical structure of nodes and edges. The logical boundaries of the crime scene simulation area are presented as semi-transparent, visual fences in the virtual 3D space model. The electronic data fixation area is configured with virtual evidence collection workstations and storage device models in the virtual 3D space model. The investigation command and analysis area provides multiple switchable analysis view layers in the virtual 3D space model. It can be understood that spatial topology modeling establishes the digital twin foundation of the physical training site. Virtual partitioning divides functionally defined simulation areas in the digital twin based on the elements of cybercrime cases. The crime scene simulation area provides an environment for recreating crime scenes. The electronic data fixation area provides a simulation environment for electronic data evidence collection operations. The investigation command and analysis area provides a simulation environment for case data analysis and decision-making.

[0075] Example 2: See Figure 3 When injecting multimodal virtual crime evidence data streams into the crime scene simulation area, historical real case files are structurally analyzed to extract time, people, behaviors, electronic evidence, and communication records. A data packet with time and spatial attributes is generated for each extracted entity. These data packets are then encapsulated into a continuous data stream according to time sequence and logical association. The encapsulated data stream is then injected into the corresponding logical location within the virtual 3D spatial model of the crime scene simulation area, based on its spatial attributes. In the crime scene simulation area, the data stream manifests as virtual objects or log fragments that can be discovered, viewed, and associated by the user.

[0076] When deploying probes to collect data streams, software probe modules are embedded in the system architecture of the virtual 3D space model. These modules include an environmental status probe cluster and a user behavior capture probe cluster. The environmental status probe cluster is mounted on virtual partition boundaries and key logical nodes, continuously collecting information on the computational load, network latency, and data access frequency of each partition within the virtual 3D space model, forming an environmental status data stream. The user behavior capture probe cluster is embedded in the underlying user interface, recording the user's movement trajectory within the virtual 3D space model, the sequence of operations on virtual objects, and the logical reasoning hypotheses submitted in the reconnaissance, command, and analysis area, forming a user operation behavior data stream. The environmental status data stream and the user operation behavior data stream are timestamped and cached.

[0077] In practice, the process of injecting multimodal virtual crime evidence data streams into the crime scene simulation area based on historical real case files begins with the structured parsing of these files. This parsing extracts time entities, person entities, behavioral entities, electronic evidence entities, and communication record entities from the historical real case files. For each entity extracted from the historical real case files, a data packet with time and spatial attributes is generated. The time attribute marks the moment the entity occurred on the case timeline, and the spatial attribute defines the entity's logical location coordinates in the crime scene simulation area. Multiple generated data packets are encapsulated according to time sequence and logical association. The time sequence is ordered based on the time attributes of the data packets, and the logical associations are linked based on the semantic relationships between entities, forming a continuous data stream. This encapsulated continuous data stream is then injected into the corresponding logical location in the crime scene simulation area of ​​the virtual 3D spatial model according to the spatial attributes of the data packets. The injection process maps the data packets to interactive objects in the virtual 3D spatial model. In the crime scene simulation area, continuous data streams are represented by virtual objects or log fragments that can be discovered, viewed, and associated by users. Virtual objects include computer models, mobile phone models, and file icons, while log fragments include network access record text windows and communication chat record windows.

[0078] In some embodiments, environmental status probes and user behavior capture probes are deployed to collect data streams in real time. This is achieved by embedding software probe modules into the system architecture of the virtual 3D spatial model. The software probe modules include an environmental status probe cluster and a user behavior capture probe cluster. The environmental status probe cluster is mounted on key logical nodes within the virtual partition boundaries and the virtual 3D spatial model. The virtual partition boundaries refer to the logical interfaces between the case scene simulation area, the electronic data fixing area, and the investigation command and analysis area. The key logical nodes refer to the locations of virtual servers and virtual network switches. The environmental status probe cluster continuously collects computational load information, network latency information, and data access popularity information for each partition within the virtual 3D spatial model. The computational load information reflects the utilization rate of the processor and memory within the virtual partition; the network latency information reflects the data transmission delay between virtual nodes; and the data access popularity information counts the frequency with which virtual objects are viewed or operated by users. The information collected by the environmental status probe cluster forms an environmental status data stream. The user behavior capture probe cluster is embedded in the underlying layer of the user interface, which is the graphical interface for users to operate the virtual 3D space model. The user behavior capture probe cluster records the user's movement trajectory coordinate sequence within the virtual 3D space model, the user's operation sequence on virtual objects (including clicks, drags, opening, and associated actions), and the logical reasoning hypothesis text submitted by the user in the reconnaissance command and analysis area. The information recorded by the user behavior capture probe cluster forms a user operation behavior data stream. The environmental state data stream and the user operation behavior data stream are timestamped and cached. Timestamping synchronization marks each data record with a unified system time, and caching temporarily stores the data stream in memory or high-speed storage devices.

[0079] In its implementation, structured parsing employs natural language processing and pattern recognition technologies to identify and extract entities from the text of historical case files. The data packet generation process assigns a unique identifier to each entity and encapsulates temporal and spatial attributes into metadata. When encapsulating the data stream, link weights are set based on the strength of relationships between entities. Relationship strength is calculated from co-occurrence frequency and semantic similarity. The calculation of relationship strength is as follows:

[0080]

[0081] in: This represents the strength of the overall relationship between entity a and entity b. Indicates the total number of relation dimensions. This represents the weight coefficient of the i-th dimension. This represents the semantic association between entity a and entity b in the i-th dimension. The software probe module is deployed as a microservice within the runtime environment of the virtual 3D spatial model. The environment status probe cluster obtains system resource metrics by calling the monitoring interface of the virtualization platform. The user behavior capture probe captures user actions by listening to the event bus of the user interface. Timestamp synchronization uses a network time protocol to ensure that all probe clocks are consistent.

[0082] Optionally, the multimodal virtual crime evidence data stream can contain digital simulations in various formats, such as text, images, video clips, and database files. The spatial attribute of the data packet can be a three-dimensional coordinate or a defined area with volume in virtual space. The collection frequency of the environmental status probe cluster can be configured, for example, collecting once per second or collecting when the indicator changes exceed a threshold. The user behavior capture probe cluster can filter invalid operations, such as duplicate click events, to reduce the data volume. The cached data stream can be indexed by partition and time window for easier subsequent queries.

[0083] It is understandable that injecting data streams based on historical real case files provides training content for the virtual 3D spatial model that conforms to the logic of real cases. Multimodal virtual crime evidence data streams enrich the presentation of evidence in training scenarios. Structured parsing is a fundamental step in converting unstructured case files into machine-processable data. Deploying environmental state probes and user behavior capture probes enables comprehensive data collection of the virtual training environment's state and the trainees' behavior. The environmental state data stream reflects the virtual system's own operational load and performance. The user operation behavior data stream fully records the trainees' investigative evidence collection operations and reasoning processes in the virtual environment.

[0084] Example 3: When building the dynamic response engine, a message queue middleware is created to receive and temporarily store environmental state data streams and user operation behavior data streams. A rule parser is designed, which loads a scene response rule library. The scene response rule library defines the virtual world events that should be triggered for different data stream patterns. The dynamic response engine sequentially reads the data streams from the message queue middleware and matches the data stream patterns with the scene response rule library. When a match is successful, the dynamic response engine generates one or more virtual world event instructions. These virtual world event instructions are used to drive the state changes of corresponding objects in the virtual 3D space model, the appearance or hiding of clues, or to trigger preset case plot branches. When creating the case deduction logic layer, evidence entities and logical relationships are defined. Logical relationships include support, contradiction, and derivation. Based on the defined logical relationships, a mesh logic reasoning graph is constructed. The nodes of the mesh logic reasoning graph are evidence entities, and the edges are logical relationships. State transition conditions are set on the mesh logic reasoning graph. The state transition conditions are associated with the logical reasoning assumptions submitted in the user operation behavior data stream and the virtual world event instructions. When the virtual world event command issued by the dynamic response engine or the logical reasoning assumption submitted by the user meets the specific state transition conditions, the case deduction logic layer will update the state of the relevant nodes in the mesh logic reasoning graph and activate the downstream logical relationships connected to them, thereby promoting the evolution of the case virtual state to the next stage.

[0085] In implementation, a dynamic response engine is constructed to receive and process environmental state data streams and user operation behavior data streams. This process is achieved by creating a message queue middleware, which receives and temporarily stores environmental state data streams and user operation behavior data streams sent from various probe clusters. A rule parser is designed, loading a scene response rule library, which defines the virtual world events that should be triggered for different data stream patterns. The dynamic response engine sequentially reads the data streams from the message queue middleware and matches the data stream patterns with the predefined rule patterns in the scene response rule library. When a data stream pattern successfully matches a rule in the scene response rule library, the dynamic response engine generates one or more virtual world event commands. These virtual world event commands are used to drive changes in the state of corresponding objects within the virtual 3D space model, the appearance or hiding of clues, or the triggering of preset case plot branches.

[0086] The creation of the case deduction logic layer begins with defining evidentiary entities and logical relationships, including support, contradiction, and derivation. Based on these defined logical relationships, a mesh logic reasoning graph is constructed, where nodes represent evidentiary entities and edges represent the logical relationships between them. State transition conditions are set on the mesh logic reasoning graph, which are associated with logical reasoning assumptions submitted in the user's action data stream and virtual world event commands. When a virtual world event command issued by the dynamic response engine or a logical reasoning assumption submitted by the user satisfies a specific state transition condition, the case deduction logic layer updates the state of the relevant nodes in the mesh logic reasoning graph and activates the downstream logical relationships connected to those nodes, thereby propelling the virtual state of the case to the next stage.

[0087] In some embodiments, the message queue middleware adopts a publish-subscribe pattern, with the environment state probe cluster and user behavior capture probe cluster acting as producers to publish data streams, and the dynamic response engine acting as consumers to subscribe to and consume the data streams. Rules in the scene response rule base are stored in the form of "condition-action" pairs. The condition part describes the characteristics of the data stream pattern, and the action part defines the set of virtual world event instructions that are triggered. The data stream pattern matching process involves multi-dimensional feature extraction and comparison of the data stream's timing, content, and source. Virtual world event instructions include three basic fields: target object identifier, operation type, and operation parameters. The case deduction logic layer maintains a global state machine, and the state changes of each evidence entity node in the network logic reasoning graph serve as input events for state transitions.

[0088] In practice, the evaluation of state transition conditions involves logical operations on the current evidence state and the input events. For a given state transition condition... Whether it is activated can be determined by the function:

[0089]

[0090] in: A Boolean value indicating whether the state transition condition is met. This represents the logical reasoning assumption submitted by the current user. This indicates virtual world event commands issued by the dynamic response engine. This represents the current set of relevant evidence entities in a network logic reasoning graph. This indicates the timeline context of the case's development. Represents a set of logical relationship constraints, a function The evaluation logic is encapsulated. It verifies the validity of U and V; matches the correlation between U / V and M; confirms the rationality of the timing based on T; determines whether the state transition rules are met based on L; and outputs P (a Boolean value: true if the transition condition is met, false otherwise) based on the above four points. When true, the case deduction logic layer executes a state transition, updates the activation state of the corresponding node in the network logic reasoning graph, and propagates the reasoning along the logical relationship edges. The reasoning propagation follows the definition of logical relationships; for example, a "support" relationship will lead to an increase in the confidence level of the supported evidence entity.

[0091] Optionally, the message queue middleware can have data persistence capabilities to prevent data loss due to system failures. The scenario response rule base supports dynamic loading and updates, allowing new response rules to be added during platform runtime. The rule parser can be implemented using a rule-based inference engine or a complex event processing engine. The mesh logic inference graph can be stored and retrieved using a graph database to improve the efficiency of state updates and traversal. State transition conditions can be configured with priorities; when multiple conditions are met simultaneously, the higher-priority condition triggers the state evolution first.

[0092] The dynamic response engine serves as the real-time processing hub connecting virtual environment data with feedback from the virtual world. The message queue middleware decouples data production and consumption, improving the system's ability to handle asynchronous data streams. The scenario response rule base solidifies business logic into rules, making platform response behavior configurable and predictable. The case deduction logic layer is the core logical model simulating the case investigation and reasoning process. The network logic reasoning graph visually represents the complex relationships between evidence. State transition conditions map user interactions and system events into the driving force for the evolution of the case state. The evolution of the virtual case state to the next stage simulates the process in real case investigation where the investigation deepens and the case gradually becomes clearer.

[0093] Example 4: When establishing an integrated interactive console, a graphical rendering interface is developed to synchronously display the real-time 3D state of the virtual 3D space model and the current topology of the mesh logic reasoning graph in the case deduction logic layer. A case script editor is integrated into the graphical rendering interface, allowing authorized users to modify state transition conditions in the case deduction logic layer or inject new multimodal virtual crime evidence data streams into the case scene simulation area. A sandbox deduction controller is also integrated into the graphical rendering interface, allowing users to revert to any historical state node in the case deduction logic layer and restart the deduction from that node. The integrated interactive console communicates with the dynamic response engine and the case deduction logic layer via a network protocol.

[0094] In its implementation, an integrated interactive console is established through the development of a graphical rendering interface (GUI). This GUI synchronously displays the real-time 3D state of the virtual 3D space model and the current topology of the mesh logic reasoning graph in the case deduction logic layer. A case script editor is integrated into the GUI, allowing authorized users to modify state transition conditions in the case deduction logic layer or inject new multimodal virtual crime evidence data streams into the case scene simulation area. A sandbox deduction controller is also integrated into the GUI, allowing users to revert to any historical state node in the case deduction logic layer and restart the deduction from that node. The integrated interactive console communicates with the dynamic response engine and the case deduction logic layer via a network protocol. This network protocol defines the format and order of data and command exchange between the integrated interactive console and the backend services.

[0095] In some embodiments, the graphical rendering interface employs a hybrid rendering technology combining a 3D rendering engine and a 2D vector graphics library. The 3D rendering engine is responsible for rendering the visual scene of the virtual 3D space model, while the 2D vector graphics library is responsible for drawing scalable vector graphics of the network logic reasoning diagram. The case script editor provides form input boxes and a visual connection canvas, allowing authorized users to edit the logical expressions of state transition conditions through the form input boxes and modify evidentiary relationships by dragging nodes and connecting lines on the visual connection canvas. The sand table simulation controller maintains a list of historical state snapshots, each containing a complete serialized copy of the case simulation logic layer at a specific moment. The integrated interactive console exchanges messages with the dynamic response engine and the case simulation logic layer via network protocols using request-response or WebSocket long connections.

[0096] In practical implementation, the synchronous display of the graphical rendering interface is achieved by subscribing to the data update event stream of the backend service. When the state of the virtual 3D space model changes or the topology of the mesh logic reasoning graph is updated, the backend service pushes an update event, and the graphical rendering interface refreshes the display content of the corresponding area after receiving the event. The modification operation of state transition conditions by the case script editor is encapsulated as structured editing instructions. The structured editing instructions are sent to the case deduction logic layer via network protocol. The case deduction logic layer verifies and applies the instructions to update the internal set of state transition conditions. When injecting new multimodal virtual crime evidence data streams into the case scene simulation area, the case script editor packages the new evidence data into a payload that conforms to the data format of the virtual 3D space model and sends it to the dynamic response engine via network protocol. The dynamic response engine coordinates the injection operation. The rollback function of the sand table deduction controller is achieved by sending a state recovery request containing the target historical timestamp to the case deduction logic layer. The case deduction logic layer retrieves and loads the corresponding data copy from the historical state snapshot list according to the target historical timestamp, thereby rolling back the entire deduction state to the specified time. Referring to Table 1, the data communication interface between the integrated interactive console and the backend service defines various types of messages.

[0097] Table 1: Main Communication Message Types Between the Integrated Interactive Console and Backend Services

[0098] Message type identifier sender Recipient Message Content Summary STATE_UPDATE Dynamic response engine / case deduction logic layer Integrated Interactive Control Console Data packets containing virtual environment state changes or inference graph topology updates EDIT_COMMAND All-in-one interactive console Case deduction logic layer Including instructions to modify state transition conditions or evidentiary entities. EVIDENCE_INJECT Integrated Interactive Control Console Dynamic response engine Includes new evidence data payload to be injected into the crime scene simulation area. SNAPSHOT_REQUEST Integrated Interactive Control Console Case deduction logic layer Request a snapshot of the case status at the current or a specified historical point in time. STATE_ROLLBACK All-in-one interactive console Case deduction logic layer Request to restore the case simulation status to a specified historical snapshot.

[0099] In practical implementation, the graphical rendering interface needs to calculate and maintain the visual synchronization between the 3D scene view and the 2D reasoning graph view. For example, when a user selects a virtual object in the 3D scene, the corresponding evidence entity node in the 2D reasoning graph should be highlighted. This synchronization is achieved by maintaining a global identifier mapping table, which records the correspondence between the unique identifiers of virtual objects and the unique identifiers of evidence entity nodes. The synchronization state is determined by the following function:

[0100]

[0101] in: A consistency flag indicating the synchronized state of the interface. This represents the i-th virtual object selected by the user in the 3D scene. This represents the j-th evidence entity node object in the two-dimensional reasoning graph. Represents the global identifier mapping table, function By querying the mapping table judge and Check if it points to the same logical entity and return the corresponding synchronization operation instruction.

[0102] Optionally, the graphical rendering interface can provide a split-screen or picture-in-picture layout, allowing users to simultaneously view a virtual 3D spatial model and a mesh logic reasoning diagram. The case script editor can support importing externally defined condition rule files or evidence data templates to simplify the configuration process. The historical state snapshots of the sand table simulation controller can be configured with an automatic saving strategy, such as saving at fixed time intervals or automatically after key state changes. The integrated interactive console can ensure that only authorized users can use the advanced functions of the case script editor and the sand table simulation controller through user authentication and access control. The network communication protocol can adopt an HTTP-based REST API or a custom binary protocol based on TCP, depending on real-time requirements.

[0103] The integrated interactive console serves as a unified portal for users to interact with the entire training platform. The graphical rendering interface provides a dual visual representation of the virtual environment and reasoning logic. The case script editor empowers administrators or instructors to flexibly customize the logic and content of training cases. The sand table simulation controller supports the replay and recapture of the training process, facilitating debriefing analysis and teaching explanations.

[0104] See Figure 4In the communication architecture between the integrated interactive console and backend services, the daily processing volume and corresponding priority distribution characteristics of different types of communication messages are quantitatively presented. Specifically, the message types include STATE_UPDATE, EDIT_COMMAND, EVIDENCE_INJECT, SNAPSHOT_REQUEST, and STATE_ROLLBACK. The horizontal axis is expanded with the message type identifier as the dimension, the left vertical axis is the daily processing volume (unit: messages), and the right vertical axis is the message priority (level 1-5). Data characteristic analysis shows that the daily processing volume of STATE_UPDATE type messages reaches 1200, the highest among all types, with a priority level of 2, indicating that this type of message (carrying virtual environment state or inference graph topology update data) belongs to high-frequency, low-priority basic interaction data; the daily processing volume of EDIT_COMMAND type messages is around 350, with the priority level increased to 4, reflecting that it (carrying state transition conditions or evidence entity modification instructions) belongs to medium-volume but high-weight interaction instructions; the daily processing volume of EVIDENCE_INJECT and SNAPSHOT_REQUEST type messages are 280 and 420 respectively, with the priority level maintained at 3, corresponding to regular functional interaction messages (evidence data injection, state snapshot requests); the daily processing volume of STATE_ROLLBACK type messages is 180, with a priority level of 5, the highest among all types, indicating that this type of message (inference state rollback request) belongs to low-volume but highly impactful core instructions. The visualization method with dual-axis linkage clearly shows the matching relationship between business traffic and priority of different communication messages, providing data support for resource scheduling of backend services and priority strategy configuration of message queues. It also reflects the communication load characteristics of the core functional modules of the integrated interactive console (such as the case script editor and the sand table simulation controller).

[0105] Example 5: The workflow of the case script editor includes: providing a visual rule configuration panel, on which authorized users can define new evidence entities and logical relationships by dragging and dropping, and add them to the network logic reasoning graph. A timeline editing tool is provided, allowing authorized users to set the appearance, disappearance, or attribute change events of any virtual object in the case scene simulation area at a specific time point on the timeline. All new rules, entities, and events configured by the user through the case script editor are serialized into a structured description file. The structured description file is submitted to the scene response rule library and case deduction logic layer of the dynamic response engine for loading, thereby updating the platform's built-in logic. The workflow of the sand table deduction controller includes: during user operation, the case deduction logic layer continuously snapshots and archives the complete state change history of the network logic reasoning graph along with the corresponding timestamps. The sand table deduction controller provides a state history timeline interface, displaying all archived snapshots in the form of time nodes. When the user selects a historical time node on the state history timeline interface, the sand table deduction controller sends a state rollback command to the case deduction logic layer. The case deduction logic layer restores its internally maintained mesh logic reasoning graph to the complete state corresponding to the selected historical time node according to the state rollback instruction, and synchronizes this state to the graphics rendering interface for update. At the same time, it notifies the dynamic response engine to suspend the processing of data streams after the current time point.

[0106] In its implementation, the case script editor's workflow begins with providing a visual rule configuration panel. On this panel, authorized users define new evidence entities and logical relationships by dragging and dropping graphical elements, adding these entities and relationships to the network logic reasoning graph maintained by the case deduction logic layer. The case script editor also provides a timeline editing tool, allowing authorized users to set appearance, disappearance, or attribute change events for any virtual object in the case scene simulation area at specific times. All new rules, entities, and events configured by authorized users through the case script editor are serialized into a structured description file. This file records the complete semantics of the editing operations using JSON or XML format. The serialized structured description file is then submitted to the scene response rule library of the dynamic response engine and the case deduction logic layer for loading. The dynamic response engine's scene response rule library parses and integrates the new response rules, while the case deduction logic layer parses and integrates the new entity and event definitions, thereby updating the platform's built-in logic.

[0107] In some embodiments, the workflow of the sandbox simulation controller involves the case simulation logic layer continuously taking snapshots of the complete state change history of the mesh logic reasoning graph along with corresponding timestamps during user operations. The sandbox simulation controller provides a state history timeline interface, displaying all archived snapshots in the form of time nodes. When the user selects a historical time node on the state history timeline interface, the sandbox simulation controller sends a state rollback instruction to the case simulation logic layer. The state rollback instruction contains the precise timestamp identifier of the target historical time node. Based on the received state rollback instruction, the case simulation logic layer restores the mesh logic reasoning graph maintained internally to the complete state corresponding to the selected historical time node, and synchronizes this restored complete state to the graphics rendering interface for visual updates. Simultaneously, the case simulation logic layer instructs the dynamic response engine to pause processing of data streams after the current time point to maintain state consistency.

[0108] In practical implementation, the drag-and-drop operations in the visual rule configuration panel are mapped to CRUD operations on the network logic reasoning graph data structure at the underlying level. The timeline editing tool allows users to precisely specify the absolute time point of virtual object events relative to the case timeline or their relative time offset relative to other events. The serialization process of the structured description file needs to ensure unambiguous encoding of complex logical relationships, such as the directional and conditional descriptions of "derivative" relationships. Submitting the structured description file to the backend service involves an asynchronous process of file upload and parsing. The platform performs syntax and semantic checks before loading new logic to prevent incorrect configurations from causing system malfunctions. Snapshot archiving does not simply store a complete memory image of the entire network logic reasoning graph; instead, it employs a hybrid strategy combining incremental storage and full storage of key states. Incremental storage only records the state differences between adjacent snapshots to optimize storage space. The storage space optimization strategy can be evaluated by calculating the storage efficiency of the snapshot chain.

[0109]

[0110] in: This indicates the storage efficiency ratio. This represents the basic storage space required to perform a complete full storage of the entire mesh logic reasoning graph. This represents the space required to store a complete baseline full snapshot in the snapshot chain. This represents the total number of incremental snapshots based on the baseline snapshot. This represents the space required to store the k-th incremental snapshot. The time nodes on the state history timeline interface are typically arranged in the natural chronological order of the case deduction and provide brief descriptive labels for the snapshots. After executing a state rollback command, the dynamic response engine needs to clear the pending data streams in its message queue whose timestamps are later than the rollback point to ensure that the deduction environment restarts from the accurate historical point.

[0111] Optionally, the visual rule configuration panel provides a rule template library, allowing authorized users to quickly configure rules by directly reusing commonly used logic patterns from the template library. The timeline editing tool supports batch operations, allowing users to edit the event attributes of multiple virtual objects simultaneously. The structured description file supports version management, facilitating the tracking of case script modification history and reverting to previous versions. Snapshot archiving can be set with automatic trigger conditions, such as automatically creating a snapshot when the state of a key evidence node in the network logic reasoning diagram changes. The state history timeline interface allows users to add bookmarks or annotations to important historical snapshots, facilitating quick location of key deduction moments during teaching.

[0112] It is understandable that the case script editor's workflow enables the visualization and structured editing of platform training content and logical rules. The sandbox simulation controller's workflow provides the ability to rewind and replay the case investigation simulation process. The visual rule configuration panel lowers the technical barrier to directly configuring complex network logic reasoning diagrams. The timeline editing tool makes the chronological arrangement of case plots intuitive and easy to operate. The structured description file, as an intermediate representation, decouples editing operations from the platform's core logic. The snapshot archiving mechanism fully preserves the historical state of the simulation process, serving as the data foundation for supporting the rewind function. The state history timeline interface provides users with an intuitive entry point for browsing and selecting historical states. The state rollback command and state recovery operation together enable the function of resetting the virtual training environment to any historical moment. The notification dynamic response engine suspends processing of subsequent data streams to ensure that after a state rollback, the system can restart responding to new user operations from a clean and consistent state point.

[0113] See Figure 5In the time consumption analysis of the timeline editing tool in the case script editor (platform usage stage: script editing - time sequence arrangement), there was a significant difference in operation time between novice users and expert users. Specifically, for six types of operations—single event creation, batch event creation, event modification, event deletion, time offset adjustment, and event association configuration—novice users' operation times were significantly longer than those of expert users. The largest time difference was observed in batch event creation (novice users took over 80 seconds, while expert users took about 30 seconds), while the smallest difference was observed in event deletion (novice users took about 20 seconds, while expert users took about 8 seconds). This difference reflects the high learning cost of the timeline editing tool's operational complexity for novice users, while expert users have already developed an advantage in operational proficiency. From the perspective of operation type, batch operations (batch event creation) and association configuration operations (event association configuration) had relatively higher overall time consumption, suggesting that there is room for optimization in the interaction flow of batch operations and the simplification of the logic of association configuration.

[0114] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0115] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for constructing a training platform for investigating cybercrime cases, characterized in that, The steps involved in constructing the method include: Perform spatial topology modeling on the pre-set physical training site to generate a corresponding virtual three-dimensional space model; In the virtual three-dimensional space model, virtual partitions are formed based on the elements of cybercrime cases, creating a case scene simulation area, an electronic data fixation area, and an investigation command and analysis area; Based on historical case files, multimodal virtual crime evidence data streams are injected into the crime scene simulation area; Deploy environmental status probes and user behavior capture probes to collect environmental status data streams and user operation behavior data streams in real time for each partition within the virtual three-dimensional space model; A dynamic response engine is constructed to receive and process the environmental state data stream and the user operation behavior data stream, and drive the changes of elements within the virtual three-dimensional space model based on the processing results; A case deduction logic layer is created, which pre-sets case state transition rules based on evidence chain deduction; An integrated interactive console is established, which is used to present the real-time status of the virtual three-dimensional space model and receive external instructions to modify the parameters in the case deduction logic layer. The establishment of the integrated interactive console specifically includes: Develop a graphical rendering interface to synchronously display the real-time three-dimensional state of the virtual three-dimensional space model and the current topology of the mesh logic reasoning graph in the case deduction logic layer; The graphical rendering interface integrates a case script editor, which allows authorized users to modify the state transition conditions in the case deduction logic layer or inject new multimodal virtual crime evidence data streams into the case scene simulation area. The graphical rendering interface integrates a sand table simulation controller, which allows users to revert to any historical state node in the case simulation logic layer and restart the simulation from that historical state node. The integrated interactive console communicates with the dynamic response engine and the case deduction logic layer via a network protocol. The workflow of the case script editor includes: A visual rule configuration panel is provided, on which authorized users can define new evidence entities and logical relationships by dragging and dropping, and add them to the network logic reasoning graph; Provides a timeline editing tool, allowing authorized users to set the appearance, disappearance, or attribute change events of any virtual object in the case scene simulation area at a specific point in time on the timeline; Serialize all new rules, entities, and events configured by the user through the case script editor into a structured description file; The structured description file is submitted to the scene response rule base and case deduction logic layer of the dynamic response engine for loading, thereby updating the platform's built-in logic; The workflow of the sand table simulation controller includes: During user operation, the case deduction logic layer continuously takes snapshots and archives the complete state change history of the network logic reasoning graph, along with the corresponding timestamps. The sand table simulation controller provides a state history timeline interface, on which all archived snapshots are displayed in the form of time nodes; When a user selects a historical time point on the status history timeline interface, the sand table simulation controller sends a status rollback command to the case simulation logic layer. According to the state rollback instruction, the case deduction logic layer restores the internally maintained mesh logic reasoning graph to the complete state corresponding to the selected historical time node, and synchronizes this state to the graphics rendering interface for update. At the same time, it notifies the dynamic response engine to pause the processing of data streams after the current time point.

2. The method for constructing a training platform for investigating cybercrime according to claim 1, characterized in that, The step of performing spatial topology modeling on the preset physical training site to generate a corresponding virtual three-dimensional space model specifically includes: The point cloud data set of the physical training site is obtained by using a three-dimensional laser scanning device; The point cloud dataset is subjected to denoising and surface reconstruction to generate a basic three-dimensional mesh model of the physical training site. The virtual coordinate positions of network device nodes, IoT sensor terminals, and computing servers are embedded in the basic three-dimensional mesh model. Based on the virtual space flow paths involved in the investigation of cybercrime cases, the data transmission channels and logical isolation boundaries are marked in the basic three-dimensional mesh model; The labeled basic 3D mesh model, virtual coordinate positions, data transmission channels, and logical isolation boundaries are merged and rendered to output an interactive virtual 3D space model.

3. The method for constructing a training platform for investigating cybercrime according to claim 2, characterized in that, In the aforementioned virtual three-dimensional space model, the virtual partitioning based on the elements of cybercrime cases specifically includes: The system analyzes the input elements of cybercrime cases, which include at least the virtual location of the crime scene, a list of electronic devices involved in the case, and a fund flow map. Based on the virtual location of the crime scene, a closed logical boundary is defined in the virtual three-dimensional space model, and the area inside the logical boundary is defined as the crime scene simulation area; Based on the list of electronic devices involved in the case, a data preprocessing area is generated around the simulated area of ​​the case scene, which is defined as the electronic data fixing area. The electronic data fixing area is used to simulate the process of data extraction, hash verification and read-only image creation. Based on the fund flow map, a multi-level analysis view area is constructed in the virtual three-dimensional space model, defined as the investigation command and analysis area. The investigation command and analysis area is used to integrate and display the correlation of case-related data.

4. The method for constructing a training platform for investigating cybercrime according to claim 3, characterized in that, The injection of multimodal virtual crime evidence data streams into the crime scene simulation area based on historical real case files specifically includes: The historical case files are structured and analyzed to extract the time, people, actions, electronic evidence and communication records. Generate a data packet with time and space attributes for each extracted entity; The data packets are encapsulated into a continuous data stream according to time sequence and logical association; The encapsulated data stream is injected into the corresponding logical location in the case scene simulation area of ​​the virtual three-dimensional space model, based on its spatial attributes. In the case scene simulation area, the data stream is represented by virtual objects or log fragments that can be discovered, viewed, and associated by the user.

5. The method for constructing a training platform for investigating cybercrime according to claim 4, characterized in that, The deployment environment status probe and user behavior capture probe, which collect environmental status data streams and user operation behavior data streams in real time for each partition within the virtual 3D space model, specifically include: In the system architecture of the virtual three-dimensional space model, a software probe module is embedded, which includes an environmental state probe cluster and a user behavior capture probe cluster. The environmental status probe cluster is mounted on the virtual partition boundary and key logical nodes, and continuously collects information on the computing load, network latency and data access popularity of each partition in the virtual three-dimensional space model to form an environmental status data stream. The user behavior capture probe cluster is embedded in the bottom layer of the user interaction interface, recording the user's movement trajectory in the virtual three-dimensional space model, the operation sequence of virtual objects, and the logical reasoning assumptions submitted in the reconnaissance command and analysis area, forming a user operation behavior data stream. The environmental status data stream and user operation behavior data stream are timestamped and cached.

6. The method for constructing a training platform for investigating cybercrime according to claim 5, characterized in that, The construction of the dynamic response engine, used to receive and process the environmental state data stream and the user operation behavior data stream, specifically includes: Create a message queue middleware to receive and temporarily store the environment status data stream and user operation behavior data stream; Design a rule parser, which loads a scene response rule library, which defines the virtual world events that should be triggered for different data flow patterns; The dynamic response engine sequentially reads data streams from the message queue middleware and matches the data stream patterns with the scenario response rule base. When a match is successful, the dynamic response engine generates one or more virtual world event instructions. These virtual world event instructions are used to drive changes in the state of corresponding objects within the virtual three-dimensional space model, the appearance or hiding of clues, or to trigger preset case plot branches.

7. The method for constructing a training platform for investigating cybercrime according to claim 6, characterized in that, The case deduction logic layer specifically includes: Define the entities of evidence and their logical relationships, including support, contradiction, and derivation; Based on the defined logical relationships, a network logic reasoning graph is constructed, where the nodes of the network logic reasoning graph are evidence entities and the edges are logical relationships; On the network logic reasoning graph, state transition conditions are set, which are associated with the logical reasoning assumptions submitted in the user operation behavior data stream and the virtual world event instructions; When the virtual world event command issued by the dynamic response engine or the logical reasoning assumption submitted by the user meets the specific state transition conditions, the case deduction logic layer will update the state of the relevant nodes in the mesh logic reasoning graph and activate the downstream logical relationships connected to them, thereby promoting the evolution of the case virtual state to the next stage.