Low-delay network security situation awareness system based on artificial intelligence
By using an AI-based low-latency network security situation awareness system, local sensing clusters are dynamically constructed and data is aggregated in real time. Encrypted transmission and anomaly assessment solve the problems of poor topology adaptability and insufficient firmware security identification in dynamic IoT networks, achieving efficient security management closed loop and low-latency response.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU SIYUN DATA TECH CO LTD
- Filing Date
- 2026-01-16
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional network security situation awareness systems are difficult to adapt to IoT dynamic terminal access scenarios, and have problems such as poor static topology adaptability, high data transmission latency, disconnect between situation assessment and protection response, and insufficient identification of security risks at the firmware level, which cannot meet the low-latency security protection requirements of IoT dynamic networks.
An AI-based low-latency network security situation awareness system is adopted, including a dynamic perception topology reconstruction module, an edge gateway module, an endpoint security agent module, a situation assessment and anomaly identification engine module, a cross-domain linkage engine module, and a situation warning and visualization module. By dynamically building local perception clusters, real-time data aggregation and encryption, situation assessment and anomaly identification, cross-domain linkage, and hierarchical warning, a complete security management closed loop is formed.
It enhances the consistency of security situation awareness and low-latency response capabilities in dynamic network environments, accurately identifies firmware-level vulnerabilities, improves the adaptability of protection strategies and emergency response efficiency, and ensures the security of IoT terminals and the overall network protection effectiveness.
Smart Images

Figure CN121887494A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) security technology, and in particular to a low-latency network security situational awareness system based on artificial intelligence. Background Technology
[0002] Low-latency network security situation awareness systems collect multi-source security data in real time, utilize artificial intelligence for anomaly detection and situation assessment, quickly identify threats and automatically or in conjunction with other systems to block them, thereby shortening response time, reducing losses caused by attacks, and achieving continuous awareness and rapid protection of network and IoT environment security situation.
[0003] Currently, traditional network security situation awareness systems are difficult to adapt to IoT dynamic terminal access scenarios. They not only suffer from poor static topology adaptability, high data transmission latency, and a disconnect between situation assessment and protection response, but also lack the ability to accurately identify security risks at the firmware level. Furthermore, they have shortcomings such as limited situation display, delayed early warning response, and insufficient targeting of protection strategies. They cannot form an efficient closed-loop security management system and cannot meet the low-latency security protection requirements of IoT dynamic networks.
[0004] Therefore, a low-latency network security situation awareness system based on artificial intelligence is proposed to solve the above problems. Summary of the Invention
[0005] The main objective of this invention is to provide a low-latency network security situational awareness system based on artificial intelligence to solve the problems mentioned in the background above.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: a low-latency network security situation awareness system based on artificial intelligence, the system comprising a dynamic perception topology reconstruction module, an edge gateway module, a terminal security proxy module, a situation assessment and anomaly identification engine module, a cross-domain linkage engine module, and a situation warning and visualization module; The dynamic sensing topology reconstruction module is used to collect the network access status of IoT terminals in real time, and dynamically construct local sensing clusters and elect cluster heads based on the access status to reconstruct the network topology. The edge gateway module is used to receive and aggregate data from IoT terminals within the cluster uploaded by the cluster head, as well as device operation data directly uploaded by IoT terminals that have not joined the sensing cluster. The terminal security proxy module is used to collect the firmware operation characteristics of the IoT terminal and perform local normalization and encryption, send the encrypted firmware characteristic data to the cross-domain linkage engine module, and execute the protection instructions issued by the cross-domain linkage engine module. The situation assessment and anomaly identification engine module is used to receive network topology data sent by the dynamic perception topology reconstruction module and device operation data sent by the edge gateway module, and use the situation inference model to perform security situation assessment and anomaly identification to generate abnormal situation data. The cross-domain linkage engine module is used to receive firmware feature data sent by the terminal security agent module and abnormal situation data sent by the situation assessment and anomaly identification engine module, perform data fusion and correlation analysis, and generate linkage response instructions based on the analysis results. The linkage response instructions include the protection instructions sent to the terminal security agent module. The situation warning and visualization module is used to receive and display the global situation assessment report generated by the situation assessment and anomaly identification engine module, and trigger graded warnings based on the risk level in the report.
[0007] Preferably, when the dynamic sensing topology reconstruction module performs the function of real-time acquisition of the network access status of IoT terminals and dynamic construction of local sensing clusters and election of cluster heads based on the access status, it is specifically used for: Collect mobile attributes, connection stability, and signal strength of IoT terminals to construct a terminal status profile; When a mobile IoT terminal is connected, it is combined with the surrounding fixed IoT terminals to form a local sensing cluster. Cluster heads are elected from the fixed IoT terminals according to predetermined connection stability parameters; The cluster head is used to aggregate local data shared by IoT terminals within the cluster through an encrypted short-range communication protocol and upload it to the edge gateway module. When a mobile IoT terminal leaves the current sensing cluster, the cluster structure is reorganized and temporary shared data associated with the mobile IoT terminal is cleared.
[0008] Preferably, when the terminal security proxy module performs the function of collecting the firmware operation characteristics of the IoT terminal and performing local normalization and encryption, it is specifically used for: Collect the firmware operation characteristics of the IoT terminal, and perform local format standardization and redundancy removal on the collected firmware operation characteristics; The processed feature data is encrypted, and the encrypted data carrying the IoT terminal identity is transmitted to the cross-domain linkage engine module through a secure channel.
[0009] Preferably, when the edge gateway module performs the function of receiving and aggregating intra-cluster IoT terminal data uploaded by the cluster head, and device operation data directly uploaded by IoT terminals not joined to the sensing cluster, it is specifically used for: The received cluster head uploaded data and IoT terminal direct transmitted data are formatted and redundancy is removed to form a device operation data summary set; The device operation data is aggregated, encrypted, and then transmitted to the situation assessment and anomaly identification engine module.
[0010] Preferably, when the situation assessment and anomaly identification engine module performs the functions of receiving the network topology data and device operation data, and using the situation inference model to perform security situation assessment and anomaly identification, it is specifically used for: The network topology data and device operation data are analyzed by the situation reasoning model to identify network attack links and abnormal device behavior, and to generate the abnormal situation data. The abnormal situation data is pushed to the cross-domain linkage engine module; The system receives the protection execution results from the cross-domain linkage engine module and updates the global situation assessment report based on these results and real-time data.
[0011] Preferably, when the cross-domain linkage engine module executes the function of receiving the firmware feature data and the abnormal situation data, performing data fusion and correlation analysis, and generating linkage response instructions based on the analysis results, it is specifically used for: Establish a mapping relationship between firmware feature data and network anomaly status data; By fusing and comparing the firmware feature data with the abnormal situation data, security vulnerabilities or anomalies at the firmware level can be identified. When it is detected that the attack originates from a firmware vulnerability, the corresponding protection command is generated and sent to the terminal security agent module. The system receives the protection execution results from the terminal security agent module and pushes them to the situation assessment and anomaly identification engine module.
[0012] Preferably, when the situation warning and visualization module performs the function of receiving and displaying the global situation assessment report, and triggering graded warnings based on the risk level in the report, it is specifically used for: The attack chain, firmware security risks, and IoT terminal status in the global situation assessment report are displayed through a dynamic topology map and situation dashboard. Based on risk level rules, tiered warnings are triggered, including local audible and visual warnings for IoT terminals, remote SMS warnings, and remote email warnings. It receives defense commands input manually and transmits the defense commands to the cross-domain linkage engine module through an encrypted channel.
[0013] Preferably, the connection stability parameter is calculated based on the continuous access duration of the IoT terminal and the signal fluctuation frequency.
[0014] Preferably, the firmware runtime characteristics include firmware version information, process call sequence, permission allocation record, and firmware update log.
[0015] Preferably, the cross-domain linkage engine module is also connected to a security policy library; When executing the linkage response command generated based on the analysis results, the cross-domain linkage engine module is also specifically used for: Based on the results of the fusion analysis, the corresponding protection policy is matched and invoked from the security policy library to generate the linkage response command.
[0016] The present invention has the following beneficial effects: 1. The present invention discloses an artificial intelligence-based low-latency network security situation awareness system. This system uses a dynamic perception topology reconstruction module to collect terminal access status in real time, dynamically build perception clusters and reconstruct the network topology. Combined with an edge gateway module to aggregate and organize device operation data, and a situation assessment and anomaly identification engine module to perform model fusion analysis, it accurately identifies network anomalies and attack links. A cross-domain linkage engine module connects data channels to generate protection commands, which are then executed by a terminal security agent module. Finally, a situation warning and visualization module displays the global situation and provides tiered warnings, forming a complete security management closed loop encompassing perception, aggregation, assessment, linkage, protection, and warning. This improves the consistency and low-latency response capability of security situation awareness in dynamic network environments, ensuring that protection measures are accurately adapted to dynamic terminal access scenarios. It solves the problems of poor static topology adaptability, high data transmission latency, and disconnect between situation assessment and protection response in existing technologies, providing reliable security for dynamic IoT networks.
[0017] 2. The low-latency network security situation awareness system based on artificial intelligence described in this invention collects firmware operation characteristics through a terminal security agent module and performs local regularization and encryption. Combined with a cross-domain linkage engine module, it establishes a correlation mapping between firmware characteristics and network anomaly data. Through fusion comparison and analysis, it identifies firmware-level vulnerabilities and anomalies, matches them with a security policy library to generate customized protection instructions, which are then executed by the terminal security agent module, which provides feedback. Finally, the situation assessment and anomaly identification engine module updates the global situation report, forming a closed loop for firmware security protection. This improves the accuracy of firmware security threat identification and the adaptability of protection strategies, solving the problems of insufficient firmware-level risk identification and the lack of generality and specificity in existing technologies. It enhances the system's ability to prevent and control firmware-related security threats, ensuring the security of IoT terminal firmware operation and the overall network protection effectiveness.
[0018] 3. The artificial intelligence-based low-latency network security situation awareness system described in this invention constructs local sensing clusters and elects highly stable cluster heads through a dynamic sensing topology reconstruction module. When a terminal disconnects, it triggers dynamic reorganization of the cluster structure and clears temporary data. Combined with a situation warning and visualization module, it displays the global situation with a dynamic topology map and situation dashboard. It triggers local and remote graded warnings based on risk levels, supports manual input of defense commands and encrypted transmission to the cross-domain linkage engine module, forming an efficient emergency response system. This improves the efficiency of network data transmission and the timeliness of emergency response to security situations, solves the problems of chaotic transmission, single situation display, and delayed warning response caused by mobile IoT terminal access in existing technologies, enhances the system's operational standardization and emergency protection reliability in dynamic network environments, and provides strong support for IoT network security emergency response. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the overall system architecture of the present invention; Figure 2 This is a schematic diagram of the dynamic sensing topology reconstruction module of the present invention; Figure 3 This is a flowchart illustrating the cross-domain linkage engine module of the present invention. Detailed Implementation
[0020] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.
[0021] Example 1, please refer to Figure 1 and Figure 2 As shown: A low-latency network security situation awareness system based on artificial intelligence, the system includes a dynamic perception topology reconstruction module, an edge gateway module, an endpoint security agent module, a situation assessment and anomaly identification engine module, a cross-domain linkage engine module, and a situation warning and visualization module; The dynamic sensing topology reconstruction module is used to collect the network access status of IoT terminals in real time, and dynamically construct local sensing clusters and elect cluster heads based on the access status to reconstruct the network topology. Specifically, it is used for: Collect mobile attributes, connection stability, and signal strength of IoT terminals to construct a terminal status profile; When a mobile IoT terminal is connected, it is combined with the surrounding fixed IoT terminals to form a local sensing cluster. Cluster heads are elected from fixed IoT terminals based on predetermined connection stability parameters; The cluster head is used to aggregate local data shared by IoT terminals within the cluster via encrypted short-range communication protocols and upload it to the edge gateway module; When a mobile IoT terminal leaves the current sensing cluster, the cluster structure is reorganized and temporary shared data associated with the mobile IoT terminal is cleared.
[0022] The connection stability parameter is calculated based on the continuous access duration of the IoT terminal and the signal fluctuation frequency.
[0023] Furthermore, the hardware carrier of the dynamic sensing topology reconstruction module is integrated into the edge-side network controller. It establishes communication connections with each IoT terminal through wired or wireless communication interfaces. Before operation, the dynamic sensing topology reconstruction module has completed communication protocol adaptation with the edge gateway module and the situation assessment and anomaly identification engine module. It adopts the TCP / IP secure communication protocol, and the data transmission is encrypted with SSL / TLS before transmission. At the same time, the scope and permissions of data collection are clearly defined, and all collection actions are subject to explicit authorization from the user in advance. It strictly complies with laws and regulations such as the "Cybersecurity Law" and the "Personal Information Protection Law", and only collects necessary data related to network security situation awareness, and prohibits the collection of terminal privacy data.
[0024] Mobility attribute data comes from the terminal's built-in location sensor and network access point switching records. The collected content includes the terminal's mobility status, location change frequency, and historical access point switching trajectory. For terminals without a built-in positioning module, mobility attributes are determined by the number of access point switching within a time period. If the number of switching reaches a threshold, the terminal is identified as a mobile IoT terminal.
[0025] Connection stability data is derived from the communication interaction logs between the terminal and the current access point. The collected data includes continuous access duration, signal fluctuation frequency, data transmission packet loss rate, and latency jitter. Among these, packet loss rate and latency jitter are correction indicators for connection stability parameters, used to optimize the accuracy of parameter calculation.
[0026] Signal strength data is obtained from real-time feedback from the terminal's wireless communication module. It is collected using conventional RSSI detection technology and records the current signal reception strength and its changing trend, including rising, falling, and stable states, as an auxiliary reference for cluster head election.
[0027] All the collected data were initially screened by the terminal's local security agent to remove invalid data before being transmitted to the module's data processing unit via an encrypted channel, ensuring the authenticity and security of the collected data.
[0028] The dynamic sensing topology reconstruction module receives the filtered data and initiates the terminal status profile construction process. It uses conventional data standardization methods to complete multi-dimensional data standardization processing, including format standardization, dimension weight allocation, and profile generation and updating. Based on the security requirements of the terminal access scenario, it assigns differentiated weights to mobility attributes, connection stability, and signal strength, with connection stability having the highest weight, followed by signal strength, and mobility attributes having the lowest weight. Based on the standardized data and weight allocation results, it constructs a dynamic status profile for each terminal. The profile includes basic terminal information, access status information, and historical behavior records. The basic terminal information includes device ID, manufacturer, and model. The access status information includes mobility attribute tags, connection stability level, and signal strength level. The historical behavior records include access duration statistics and handover trajectory.
[0029] When the dynamic sensing topology reconstruction module detects a new mobile IoT terminal access, it immediately initiates the local sensing cluster construction process based on the mobile attribute tags of the terminal status profile and access records. The steps are as follows: Cluster range determination: The cluster range is defined based on the current access point of the newly connected mobile IoT terminal and the signal coverage radius. This ensures that the range contains a sufficient number of fixed IoT terminals. Fixed terminals are determined by their status profiles, i.e., if there are no access point switching records within the specified time. If the number of fixed terminals within the range is insufficient, the signal coverage radius is expanded until the cluster formation conditions are met.
[0030] In-cluster terminal screening: Terminals meeting certain criteria are screened from within the cluster. Screening criteria include: the terminal is in normal operating condition, signal strength is higher than the system's minimum threshold, and data transmission packet loss rate is lower than the threshold. After screening, newly connected mobile IoT terminals and qualified fixed terminals are combined to form a local sensing cluster. A unique identifier is assigned to the cluster and associated with the status profile of each terminal.
[0031] Cluster head election: The cluster head is elected based on the connection stability parameters of fixed terminals within the cluster. Mobile IoT terminals with unstable access states do not participate in the election. The connection stability parameters are calculated using a weighted summation method, which comprehensively reflects the reliability of continuous terminal access and signal stability. The specific calculation steps are as follows: Continuous access duration normalization: Obtain the cumulative continuous access duration of fixed terminals. The data is sourced from the access log and compared with the system's longest continuous access duration threshold. Linear normalization is used to convert it into a normalized value in the range of 0 to 1, denoted as A. If the actual duration exceeds the threshold, A is taken as the maximum value. For newly connected fixed terminals, A is taken as the basic threshold to avoid the parameter being 0.
[0032] Signal fluctuation frequency normalization: The number of times the terminal signal strength changes within the time window is obtained. The data comes from real-time signal feedback and is compared with the system's maximum signal fluctuation frequency threshold. Linear normalization is used to convert it into a normalized value in the range of 0 to 1, denoted as B. The lower the signal fluctuation frequency, the closer B is to the maximum value, indicating that the signal is more stable. If the fluctuation frequency exceeds the threshold, B is taken as the basic threshold.
[0033] The connection stability parameter is calculated using the formula: S = 0.6 × A + 0.3 × B + 0.1 × C, where A, B, and C are all normalized values in the range of 0 to 1. A is the normalized value of continuous access duration, B is the normalized value of signal fluctuation frequency, and C is the normalized value of packet loss rate. The final value of S ranges from 0 to 1, and the higher the value, the stronger the stability.
[0034] Set quantization thresholds: After the fixed terminals within the cluster are sorted by S value, the top 30% are high-stability terminals and are eligible to participate in the cluster head election, 30% to 70% are medium-stability terminals, and below 70% are low-stability terminals. If the original cluster head's S value drops to below the medium-stability threshold of 0.5 and this state continues for 3 system scan cycles, the cluster head re-election process is immediately triggered to ensure cluster head stability.
[0035] After cluster head election, the dynamic sensing topology reconstruction module sends an activation command to the cluster head, associating the status profiles of terminals within the cluster with the cluster head. The cluster head then initiates the data aggregation function. To ensure data transmission security and low latency, local data sharing between terminals within the cluster and between terminals and the cluster head uses the ZigBee 3.0 encryption protocol. This protocol is suitable for short-range communication scenarios, balancing efficiency and security. Shared data includes operational status data and basic firmware characteristic data. After preprocessing the received data, such as removing duplicate data and labeling the data source terminal ID, the cluster head uploads the data to the edge gateway module through an encrypted channel. Here, the ZigBee 3.0 encryption channel is used again, without repeated encryption, to avoid redundant processing affecting transmission efficiency. Simultaneously, the system establishes a unified key management system, with the cross-domain linkage engine module serving as the core key management center. Dynamic keys are generated based on the terminal's unique identifier and timestamp, and these keys are rotated hourly. They are synchronized to various related modules, including the cluster head, edge gateway, and situation assessment and anomaly detection engine, via independent encrypted channels, ensuring key consistency for encrypted communication. The cluster head and each module must retain a full log of key rotation for subsequent security traceability and fault diagnosis. Cross-module data transmission, such as data transmission from the edge gateway to the situation assessment and anomaly detection engine module, employs the AES-256 symmetric encryption algorithm, balancing high security and transmission efficiency in cross-module transmission, forming a layered encryption system.
[0036] The dynamic sensing topology reconstruction module scans the access status of terminals within the cluster in real time, updating the terminal status profile synchronously with each scan, and monitors the disconnection of mobile IoT terminals. The processing flow is as follows: Disengagement Detection: When the signal strength of a mobile IoT terminal remains below the threshold for an extended period of time, or when the status profile indicates that the access point has switched to outside the cluster range, the terminal is determined to have left the current sensing cluster, and the module immediately sends a disengagement notification to the cluster head.
[0037] Cluster structure reorganization: The cluster head feeds back the status information of the remaining terminals. The module determines whether to reorganize based on the status profile of the remaining terminals: If there are no mobile IoT terminals among the remaining terminals and the number of fixed terminals is insufficient to meet the cluster formation conditions, the cluster is disbanded and the remaining fixed terminals are merged into the nearest sensing cluster; if the remaining terminals meet the formation conditions but there are terminals with poor connection stability, the terminals are re-selected and the original cluster structure is retained without re-election of the cluster head; if the connection stability parameter of the original cluster head drops to below the average level of the fixed terminals in the cluster, the re-election process is initiated and the original cluster head is restored to a normal terminal.
[0038] Temporary data clearing: After the cluster structure is reorganized, the module sends a temporary data clearing command to the cluster head. The cluster head immediately clears the temporary shared data related to the disconnected terminal, including running data, firmware feature data, and access records, and uploads the data clearing log to the module. The module synchronizes the log to the edge gateway module to avoid redundant data occupying storage resources and affecting transmission efficiency.
[0039] After completing the topology reconstruction, the dynamic sensing topology reconstruction module will prioritize the transmission of real-time updated network topology data to the situation assessment and anomaly identification engine module via an AES-256 encrypted channel, providing a basic topology basis for situation assessment. At the same time, it will synchronize the cluster head election results and cluster structure reorganization records to the edge gateway module, so that the gateway can accurately connect to the cluster head and efficiently summarize the data.
[0040] When the situation assessment and anomaly detection engine module detects an anomaly in a terminal within a cluster, it feeds back the anomaly terminal information to this module. The module immediately increases the scanning frequency of the terminal and its cluster, focusing on monitoring the access status and cluster structure stability. If the anomaly terminal is a mobile IoT terminal and shows a tendency to leave the cluster, it immediately sends a warning message to the cluster head and edge gateway modules, prioritizing the interception of abnormal data to ensure the system's low-latency response capability.
[0041] Example 2, please refer to Figure 1 As shown: A low-latency network security situational awareness system based on artificial intelligence, with an edge gateway module, is used to receive and aggregate data from IoT terminals within the cluster uploaded by the cluster head, as well as device operation data directly uploaded by IoT terminals not joined to the sensing cluster. Specifically, it is used for: The received cluster head uploaded data and IoT terminal direct transmitted data are formatted and redundancy is removed to form a summary set of device operation data; After the equipment operation data is aggregated and encrypted, it is transmitted to the situation assessment and anomaly detection engine module.
[0042] Furthermore, the edge gateway module utilizes industrial-grade edge computing gateway equipment, integrating multi-protocol adapter interfaces and high-performance data processing chips, supporting simultaneous access from both wired and wireless terminals. Before operation, the module has completed communication protocol adaptation and encryption key negotiation with the dynamic perception topology reconstruction module and the situation assessment and anomaly identification engine module, clearly defining the data reception scope and processing permissions. All data reception, processing, and transmission activities are subject to prior explicit user authorization, strictly adhering to relevant laws and regulations such as the Cybersecurity Law and the Data Security Law. It only processes device operation data directly related to network security situation awareness, preventing the collection or retention of terminal privacy information.
[0043] After the edge gateway module starts, it first initializes the communication interface and protocol parsing engine, and opens dual data receiving channels to connect to the sensing cluster heads and direct transmission terminals not joined to the sensing clusters, respectively. The data uploaded by the cluster heads comes from each sensing cluster head. The cluster head first summarizes the device operation data of the terminals within the cluster. This data includes the terminal hardware operating status, network connection parameters, and basic firmware operating information, etc., and then uploads it to the edge gateway module through an encrypted short-range communication protocol. The data includes the unique identifier of the sensing cluster and the data source identifier of each terminal. The transmission frequency is synchronized with the scanning cycle of the sensing cluster.
[0044] The data uploaded by the direct transmission terminal originates from terminals not integrated into any sensing cluster. These terminals include temporarily accessed mobile IoT terminals, fixed IoT terminals outside signal coverage areas, and independently operating high-priority terminals. They directly upload device operation data via their own secure communication modules and secure communication protocols. The data includes a unique terminal identifier, access time, and data priority tag. When a terminal is in an abnormal operating state, the data transmission frequency will be higher than during normal operation. The module adapts to various encrypted communication protocols through a built-in multi-protocol parsing engine and employs a dual access authentication mechanism. First, it verifies the terminal's identity based on a whitelist, and then performs a secondary verification using the device key. Data from terminals that pass both verifications can proceed to subsequent processing, preventing unauthorized terminal access.
[0045] After receiving data, the module initiates a parallel preprocessing process. First, it standardizes the data format by mapping and reconstructing fields for heterogeneous data from different sources based on the system's data field specifications, unifying field names, data types, and units of expression. If key fields are missing or formatted incorrectly, the module sends a completion request to the data source terminal. If completion fails, the data is marked as invalid and discarded, while relevant logs are retained. Subsequently, a unified timestamp is added to valid data using the module's own high-precision clock to avoid data timing discrepancies caused by terminal clock deviations.
[0046] After standardizing the format, redundant data is removed. Based on the historical baseline data of the terminal, abnormal data that exceeds the normal value range or is caused by sensor failure is identified and removed. At the same time, a fault warning is sent to the corresponding terminal. Duplicate data and redundant fields that are not related to situational awareness within the time window are removed, and only core fields are retained to reduce transmission and processing pressure and adapt to the low latency requirements of the system.
[0047] After data preprocessing, the module constructs a summary set of equipment operation data, categorizes and integrates it into four dimensions according to data source, and generates a unique identifier after verification of completeness, consistency, and standardization. The summary set is then encrypted using a symmetric encryption algorithm, with the encryption key being a dynamic key negotiated with the situation assessment module. This dynamic key is periodically rotated according to network security levels. A message authentication code is added after encryption, and high-priority transmission and breakpoint resumption mechanisms ensure transmission efficiency and reliability. Upon successful transmission, a verification confirmation message is received; if successful, it is logged; otherwise, transmission is re-initiated.
[0048] As the core hub of the data flow, the edge gateway module works efficiently with other modules: it receives the sensing cluster structure information synchronized by the dynamic sensing topology reconstruction module and adjusts the data reception strategy in real time when the cluster structure is reorganized; it responds to the data analysis needs of the situation assessment module, extracts local cached data, preprocesses it, and then transmits it; it feeds back the data reception status to the security agent module of the direct transmission terminal, and sends collection optimization instructions when there is too much invalid data.
[0049] Example 3, please refer to Figure 1 As shown: A low-latency network security situation awareness system based on artificial intelligence, the terminal security agent module is used to collect the firmware operation characteristics of the IoT terminal and perform local normalization and encryption, send the encrypted firmware characteristic data to the cross-domain linkage engine module, and execute the protection instructions issued by the cross-domain linkage engine module. When the terminal security agent module performs tasks to collect the firmware runtime characteristics of the IoT terminal and then performs local normalization and encryption, it specifically handles the following: Collect the firmware operation characteristics of the IoT terminal, and perform local format standardization and redundancy removal on the collected firmware operation characteristics; The processed feature data is encrypted, and the encrypted data carrying the IoT terminal identity is transmitted to the cross-domain linkage engine module through a secure channel.
[0050] Firmware runtime characteristics include firmware version information, process call sequence, permission allocation records, and firmware update logs.
[0051] Furthermore, the terminal security agent module is integrated into the terminal firmware as a lightweight agent program, adapting to IoT terminals with different architectures and achieving deep compatibility with terminal hardware, operating systems, and firmware systems. Before running, the terminal security agent module has completed communication protocol adaptation and key negotiation with the cross-domain linkage engine module and edge gateway module, clearly defining the data collection scope and command execution permissions. All firmware feature collection behaviors are authorized by the user in advance, strictly complying with relevant laws and regulations, collecting only the necessary feature data for firmware operation, and preventing the collection of terminal privacy or business data.
[0052] After the terminal security agent module starts, it first completes the initial configuration and verifies its own running status and compatibility with the terminal firmware. If there is a compatibility anomaly or a running failure, it immediately sends a fault alarm to the edge gateway module, and at the same time suspends data collection and retains fault logs. After the fault is investigated and repaired, it resumes operation, forming a fallback mechanism for data collection failures.
[0053] After initialization, the terminal security agent module initiates the firmware runtime characteristic collection process. The collected data all originates from the firmware system and operating system of the terminal. Firmware version information is taken from the firmware configuration file, covering version identifier, release information, compatible models, and historical update records. Process call sequences are taken from the operating system's process manager, recording all process call details triggered by firmware operation, including process information, call sequence, priority, and relationships. Permission allocation records are taken from the firmware permission management module, covering permission type, authorization scope, effective sequence, and change history. Firmware update logs are taken from the firmware update module, recording update triggering methods, core content, execution results, and exception information.
[0054] To ensure data timeliness and effectiveness, the terminal security agent module employs a combined triggering mechanism of real-time and periodic data collection. Process call and permission change-related features are collected in real-time, while the collection cycle for firmware version and update logs is dynamically adjusted based on the terminal's operating status. In case of terminal anomalies, the cycle is shortened to improve response speed. After collection, the module initiates local standardization processing. First, it standardizes the format based on system field specifications, reconstructs field mappings for heterogeneous feature data, and unifies field definitions, data types, and representation methods to ensure data format consistency. Then, it performs redundancy removal, eliminating duplicate records, invalid logs, and redundant information unrelated to firmware security. Simultaneously, it combines this with baseline data from normal terminal firmware operation to identify and remove abnormal feature data exceeding the normal range, retaining removal logs for subsequent traceability.
[0055] To accurately determine abnormal firmware operation characteristics, the process for constructing and updating the normal operating baseline data of the terminal firmware is as follows: Initial baseline import: When the terminal leaves the factory, the standard operating baseline of the corresponding model firmware is imported. This baseline is determined by the original data provided by the manufacturer and after multi-scenario testing and calibration in the laboratory to ensure that it is adapted to the basic operating state of the terminal. Dynamic incremental update: During terminal operation, the baseline is incrementally updated weekly based on firmware feature data during periods without security anomalies, after removing extreme values using the sliding window method. The sliding window method requires data from the past 7 days to adapt to the dynamic changes in the terminal's operating status and avoid deviations in anomaly judgment caused by baseline aging. New terminal adaptation: When a new terminal is added, the system automatically matches the baseline of the same model. If no matching model is found, a temporary baseline is generated based on the same type of firmware. The same type of firmware includes the same manufacturer and the same architecture. After the terminal has been running stably for 14 days, it is optimized into a formal baseline based on actual abnormal operation data, so as to achieve baseline coverage for all terminal scenarios.
[0056] After local normalization, the module uses a symmetric encryption algorithm to encrypt the feature data as a whole. The encryption key is a dynamic key negotiated with the cross-domain linkage engine module. The key is rotated periodically based on the terminal's unique identifier, and the rotation cycle is dynamically adjusted according to the terminal's security level to avoid the risk of key leakage. After encryption, the module adds the terminal's unique identifier and collection timestamp to the data and transmits it to the cross-domain linkage engine module through a secure encrypted channel. The transmission channel is adapted to the terminal's communication method selection. Fixed terminals use a wired secure communication protocol, while mobile IoT terminals use a wireless encrypted communication protocol. During transmission, data fragmentation and verification mechanisms are enabled to ensure the integrity and reliability of data transmission. If transmission fails, re-encryption and transmission are triggered until the receiving end sends back confirmation information.
[0057] While transmitting data, the endpoint security agent module continuously listens for protection commands issued by the cross-domain linkage engine module. After receiving the command, it first performs integrity and permission verification. After confirming that the source is legitimate and the content is complete, it parses the command requirements and executes the corresponding protection operations, including pausing abnormal processes, adjusting firmware permission allocation, closing insecure communication ports, and triggering emergency firmware updates.
[0058] After the protection operation is completed, the module records the execution process and results, generates a protection execution feedback report, encrypts it, and transmits it to the cross-domain linkage engine module through a secure channel while simultaneously storing local logs. Furthermore, the module maintains real-time collaboration with the edge gateway module, periodically reporting the terminal firmware's running status and its own operational status, receiving data collection optimization instructions, and dynamically adjusting the collection cycle and processing strategy to improve data collection accuracy and efficiency. Simultaneously, it reduces data transmission volume through local processing to meet the system's low-latency operation requirements.
[0059] Example 4, please refer to Figure 1 The system illustrates a low-latency network security situation awareness system based on artificial intelligence. Its situation assessment and anomaly identification engine module receives network topology data from a dynamic perception topology reconstruction module and device operation data from an edge gateway module. It then uses a situation inference model to perform security situation assessment and anomaly identification, generating abnormal situation data. Specifically, this data is used for: By analyzing network topology data and device operation data through situational reasoning models, network attack links and abnormal device behavior are identified, and abnormal situational data is generated. Push abnormal situation data to the cross-domain linkage engine module; Receive the protection execution results from the cross-domain linkage engine module, and update the global situation assessment report based on these results and real-time data.
[0060] Furthermore, the hardware carrier of the situation assessment and anomaly detection engine module adopts a high-performance edge computing unit, integrating data processing, situation inference model deployment, and report generation modules, possessing efficient data processing and situation analysis capabilities. Before operation, the situation assessment and anomaly detection engine module has completed communication protocol adaptation and data interface debugging with the dynamic perception topology reconstruction module, edge gateway module, and cross-domain linkage engine module, clarifying the data reception scope and situation assessment standards. Before deployment, the situation inference model has undergone sufficient training and verification. The training data comes from historical network security incidents, normal operation of IoT terminals, and simulated attack scenarios. All training data has been anonymized and complies with legal and regulatory requirements. The model can only be deployed and run after passing verification.
[0061] After the situation assessment and anomaly identification engine module starts, it first completes the initialization operation, verifies the running status of the situation inference model, the connectivity of the data interface, and the availability of its own computing resources. If there are problems such as model anomalies, interface failures, or insufficient resources, it immediately sends alarm information to the system management module and suspends the situation assessment operation. It will resume operation after the problem is resolved.
[0062] After initialization, the module initiates a dual-channel high-priority data reception process, receiving network topology data from the dynamic sensing topology reconstruction module and device operation data from the edge gateway module, adapting to the system's low-latency requirements. The network topology data originates from real-time topology reconstruction results, covering the sensing cluster structure, terminal access status, topology connection relationships, and cluster head information, along with a topology update timestamp and reconstruction identifier. The device operation data originates from pre-processed aggregated data, covering terminal hardware operating status, network connection parameters, and basic firmware information, along with a terminal identifier and data priority tag.
[0063] After receiving the two types of data, the situation assessment and anomaly identification engine module first performs preprocessing and fusion operations. It performs format verification and integrity checks on the network topology data, removes data with incomplete structure or missing labels, and supplements topology association information. It performs validity verification on the device operation data, filters valid data by combining the terminal's historical operation baseline data, and sorts the data according to priority, prioritizing the processing of high-priority data to ensure low-latency response.
[0064] After the data fusion is completed, the following logical process will be followed: First, the fused data will be input into the situational reasoning model to clarify the model's architecture, training process, and input-output relationship. A hybrid deep learning model architecture combining Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN) is adopted. This model architecture has both temporal data modeling and spatial feature extraction capabilities, and can accurately discover abnormal correlation features in dynamic changes in network topology and equipment operation data.
[0065] The model is divided into three parts: CNN feature extraction layer, LSTM temporal modeling layer, and fully connected and output layer. The CNN feature extraction layer adopts a structure of three convolutional layers and two pooling layers. The first convolutional layer uses 64 3x3 convolutional kernels with a stride of 1 and the same padding mode. The second layer uses 128 3x3 convolutional kernels with a stride of 1 and the same padding mode. The third layer uses 256 3x3 convolutional kernels with a stride of 1 and the same padding mode. The pooling layer uses 2x2 max pooling with a stride of 2 to extract spatial correlation features. LSTM Temporal Modeling Layer: A two-layer bidirectional LSTM structure is adopted, with 128 hidden units per layer and a Dropout rate of 0.2, to capture temporal dependencies; Fully connected and output layers: The output features of CNN and LSTM are concatenated and processed through two fully connected layers. The first fully connected layer has 512 neurons and the second fully connected layer has 256 neurons. After processing, a 17-dimensional anomaly type vector is output through the softmax activation function, and a 1-dimensional risk level score vector is also output.
[0066] Before deploying the model, complete training and validation are required. The specific steps are as follows: First, data preparation and preprocessing are performed: historical network security incident data, normal operation data of IoT terminals, and simulated attack scenario data are collected. Historical network security incident data refers to data related to security threats that have actually occurred in the dynamic network scenario of IoT, covering information on the attack initiation point, attack propagation link records, changes in the operating status of affected terminals, firmware vulnerability triggering trajectories, attack handling processes and results, etc.; normal operation data of IoT terminals refers to the operating data of IoT terminals of different models and manufacturers in a dynamic topology environment without security threats, including terminal hardware operating parameters, network connection parameters, basic firmware operating characteristics, normal data interaction records within the sensing cluster, and access information under stable topology conditions, etc.; simulated attack scenario data refers to data generated by artificially simulating various potential security threats through a simulated dynamic network environment of IoT consistent with the application scenario of this invention, including covert attacks during the process of mobile IoT terminals leaving the sensing cluster, short-term high-frequency attacks in low-latency networks, targeted attacks against cluster heads, firmware permission tampering attacks, etc.
[0067] Historical cybersecurity incident data, IoT terminal normal operation data, and simulated attack scenario data are anonymized, and then outliers are removed using the IQR quartile method, redundant samples are deleted using the deduplication algorithm, and missing data is supplemented using the interpolation method.
[0068] The system extracts 16-dimensional topology features, 22-dimensional device operation features, and 10-dimensional time-series features. The 16-dimensional topology features include the number of sensing clusters, sensing cluster structure type, terminal access density, terminal access status category, cluster head stability, cluster head election result category, and topology connection redundancy. The 22-dimensional device operation features include CPU utilization, memory usage, network latency, packet loss rate, firmware process resource consumption, firmware version type, network connection protocol type, and terminal device type. The 10-dimensional time-series features include 5-minute indicator change rate, 15-minute indicator change rate, 30-minute indicator change rate, and indicator fluctuation amplitude.
[0069] One-hot encoding was applied to categorical features, and min-max normalization was applied to numerical features to the [0,1] interval. The dataset was divided into training set: validation set: test set = 7:1.5:1.5. Categorical features refer to non-numerical features that cannot be directly measured by numerical value and are only used to distinguish different categories, states, or attributes. Specifically, these include: perceptual cluster structure type, terminal access status category, and cluster head election result category in topological features. Perceptual cluster structure types include different topological structure categories such as "star cluster" and "mesh cluster"; terminal access status categories include "connected", "not connected", "temporary access", and "long-term access"; and cluster head election result categories include "as cluster head" and "ordinary terminal". Device operating characteristics include firmware version type, network connection protocol type, and terminal device type; Firmware version types include firmware models from different manufacturers, categories corresponding to different version numbers, and relationships between numbers other than the numerical values of the version number itself; network connection protocol types include different protocol categories such as "encrypted short-range communication protocol" and "TCP / IP protocol"; and terminal device types include the classification of "fixed IoT terminal" and "mobile IoT terminal".
[0070] Next, model training was performed: the weight parameters were initialized using the He normal method, the bias parameters were initialized to 0, the batch size was set to 64, and the number of training epochs was set to 50. The total loss function was constructed by weighted summation of cross-entropy loss and mean squared error loss, with the weight of cross-entropy loss being 0.6 and the weight of mean squared error loss being 0.4. The Adam optimizer was used for optimization, with the initial learning rate set to 0.001. The learning rate was decayed by 0.8 times every 10 training epochs. Combined with the early stopping strategy, training was stopped if the validation set loss did not decrease for 5 consecutive training epochs to avoid overfitting. Validation and optimization were conducted: performance thresholds were set at an accuracy of no less than 95%, an F1 score of no less than 94%, and a mean absolute error of no more than 0.3. Hyperparameters were tuned using a grid search method, with adjustments ranging from 32 to 512 convolutional kernels and 64 to 256 LSTM units. The test set validation results showed an accuracy of 96.3%, an F1 score of 94.7%, and a mean absolute error of 0.28, all exceeding the set thresholds. This demonstrates that the model possesses high anomaly detection accuracy and low prediction error. After achieving the performance targets, the model was converted to the ONNX lightweight format for deployment and iterative updates were performed. Incremental training was conducted quarterly using newly added data to adapt to dynamic network changes.
[0071] Secondly, based on the model architecture and parameters, a comprehensive security situation analysis is completed, generating abnormal situation data. Input-output relationship: ① Input data: a fusion feature map with a size of 1×64×64×48, where 64×64 is the feature map size and 48 is the number of feature map channels. It is reconstructed by splicing 16-dimensional topological features, 22-dimensional device operation features, and 10-dimensional temporal features, corresponding to the result of feature extraction and normalization of the original data. The feature map reconstructing rules are defined. Based on a 5-minute time window sampling, one set of data is collected every 1 second, for a total of 300 sets. The 48-dimensional features are arranged into a 48×300 matrix according to the time series. The matrix edges are expanded using a constant zero-padding method. At the same time, the matrix dimensions are normalized to 64×64 using linear interpolation, finally forming a 1×64×64×48 fusion feature map. It is also adapted to dynamic network scenarios. The time window can be flexibly adjusted according to the terminal density. In areas with dense terminals, the time window is shortened to 2 minutes, taking into account both data integrity and low latency requirements. ② Processing Link: The input feature map is processed by a CNN feature extraction layer to extract 256-dimensional spatial features, and then by a bidirectional LSTM temporal modeling layer to extract 256-dimensional temporal features. The two types of features are concatenated and then mapped and reduced in dimensionality by a fully connected layer. ③ Output data: The 17-dimensional vector corresponds to 12 types of attacks, 4 types of faults, and 1 type of normal state. The dimension with the largest value is the current state of judgment. The 1-dimensional scoring vector with a value range of [0,10] maps to four levels of risk. The value range of [0,2.5) corresponds to level 1 risk, the value range of [2.5,5) corresponds to level 2 risk, the value range of [5,7.5) corresponds to level 3 risk, and the value range of [7.5,10] corresponds to level 4 risk. Based on the above architecture and parameters, the situational reasoning model combines the network security situational assessment index system to conduct comprehensive analysis. The network security situational assessment index system covers four dimensions: topology security, device operation, firmware status, and attack protection. It focuses on identifying network attack links and abnormal device behavior. Network attack links include attack source location, propagation path tracing, and determination of the scope of affected terminals. Abnormal device behavior includes hardware failure, firmware operation abnormality, network connection abnormality, and privilege abuse. Finally, it generates abnormal situational data that includes anomaly type, risk level, scope of impact, occurrence time, and preliminary handling suggestions.
[0072] Finally, abnormal data is pushed and a global situation assessment report is built and updated, forming a complete functional closed loop. After abnormal situation data is generated, the situation assessment and anomaly identification engine module first uses a priority push mechanism to push high-risk data to the cross-domain linkage engine module first. Encryption is enabled during the push process to ensure transmission security. At the same time, the initial construction of the global situation assessment report is initiated. The report covers topology security status, device anomaly statistics, attack link analysis, risk level and protection recommendations, and adopts a structured format for easy subsequent display and early warning.
[0073] The subsequent situation assessment and anomaly identification engine module continuously monitors the protection execution results fed back by the cross-domain linkage engine module. After receiving the results, it parses and verifies the execution status, handling effect, and unresolved issues. Then, it dynamically updates the global situation assessment report by combining the real-time collected topology and device operation data. The updated content includes anomaly handling progress, risk level changes, new anomalies, and protection effect assessment, ensuring that the report reflects the dynamic changes in network security situation in real time. This fully realizes the functional closed loop of receiving data, model analysis to generate anomaly data, pushing anomaly data, and updating the report with the received results. In addition, the situation assessment and anomaly identification engine module maintains real-time collaboration with the dynamic perception topology reconstruction module, receiving topology structure update information and adjusting the assessment basis data to improve the accuracy of attack link identification; it also collaborates with the situation warning and visualization module to regularly push updated assessment reports, providing support for situation display and hierarchical early warning.
[0074] The situation assessment and anomaly identification engine module encrypts and stores analysis logs, anomaly records, and report update records locally for at least 6 months for security audit traceability. At the same time, it regularly evaluates the model's performance and dynamically optimizes the evaluation indicators based on actual security incidents to improve the accuracy of situation assessment and anomaly identification.
[0075] Example 5, please refer to Figure 1 and Figure 3 The system illustrates a low-latency network security situational awareness system based on artificial intelligence. Its cross-domain linkage engine module receives firmware feature data from the terminal security agent module and abnormal situational data from the situational assessment and anomaly identification engine module. It performs data fusion and correlation analysis, and generates linkage response instructions based on the analysis results. These instructions include protection commands issued to the terminal security agent module, specifically for: Establish a mapping relationship between firmware feature data and network anomaly status data; By fusing and comparing firmware feature data and abnormal situation data, security vulnerabilities or anomalies at the firmware level can be identified. When it is detected that the attack originates from a firmware vulnerability, a corresponding protection instruction is generated and sent to the terminal security agent module. It receives the protection execution results from the terminal security agent module and pushes them to the situation assessment and anomaly detection engine module.
[0076] The cross-domain linkage engine module is also connected to a security policy library; When executing the cross-domain linkage engine module to generate linkage response instructions based on analysis results, it is also specifically used for: Based on the results of the fusion analysis, the corresponding protection policies are matched and invoked from the security policy library to generate linkage response instructions.
[0077] Furthermore, the hardware carrier of the cross-domain linkage engine module adopts a high-performance edge gateway device. Before the cross-domain linkage engine module runs, it has completed communication protocol adaptation and key negotiation with the terminal security agent module, situation assessment and anomaly identification engine module, and security policy library, clarifying the data reception scope, analysis permissions, and command issuance specifications. All data processing and command transmission behaviors are authorized by users in advance and strictly comply with relevant laws and regulations to ensure that data fusion analysis is compliant and that the issuance of protection commands is accurate and controllable.
[0078] After the cross-domain linkage engine module starts, it first completes the initial configuration, verifies the connectivity of communication links with each associated module, the integrity of the security policy library, and the availability of its own data processing resources. If there are problems such as link anomalies, missing policy libraries, or insufficient resources, it immediately sends an alarm to the system management module, suspends data reception and analysis, and resumes operation after the problem is resolved. After initialization, the module starts a dual-channel high-priority data reception process, receiving firmware feature data sent by the terminal security agent module and abnormal situation data sent by the situation assessment and anomaly identification engine module, adapting to the system's low-latency requirements.
[0079] Firmware feature data originates from the security agent modules of each terminal, is locally standardized and encrypted before transmission, and includes the terminal's unique identifier, firmware version, process call sequence, permission allocation records, update logs, and collection timestamps, along with an integrity checksum. Anomaly situation data originates from the situation assessment and anomaly identification engine module, covering anomaly type, risk level, impact scope, attack chain, and preliminary handling suggestions, along with an assessment timestamp and priority tag. Upon receiving data, the module first performs integrity and legality checks, discards data that fails the checks and logs it, and simultaneously feeds back the check results to the data source module to ensure the reliability of the received data.
[0080] After the data verification is successful, the module starts the data fusion and correlation analysis process. Using the terminal's unique identifier as the core correlation key, it establishes a three-dimensional correlation mapping between firmware features and abnormal situation data, realizing cross-domain linkage between firmware and network layer data.
[0081] The security policy library includes a firmware vulnerability feature sub-library, a network attack feature sub-library, and a terminal adaptation rule sub-library. By combining the firmware vulnerability feature library and the network attack feature library in the security policy library, the matched data is comprehensively analyzed. The matching degree between vulnerability features and attack trajectory is used as the judgment criterion to identify firmware-level security vulnerabilities or anomalies. If it is confirmed that the attack originates from a firmware vulnerability, it is marked as a high-priority handling event, and the protection policy matching is initiated first.
[0082] The security policy library includes built-in firmware vulnerability protection policies, network anomaly handling solutions, and terminal adaptation rules, supporting dynamic updates. Update trigger conditions include periodic verification, synchronization of newly added vulnerability information, and optimization based on protection effectiveness feedback. After fusion analysis, the module matches the corresponding protection policy and generates customized linkage response instructions based on the anomaly level, impact scope, and terminal type, clearly defining the protection operation details, execution priority, and adapted terminal identifiers to ensure accurate execution on the terminal.
[0083] After the instruction is generated, the cross-domain linkage engine module uses an encrypted transmission mechanism to send the instruction through a secure channel, and enables a verification code to ensure the integrity and authenticity of the transmission. If the transmission fails, it is re-encrypted and sent until confirmed. The module monitors the terminal protection execution results, analyzes the handling effect and generates a linkage protection handling report, which is then encrypted and pushed to the situation assessment and anomaly identification engine module.
[0084] Example 6, please refer to Figure 1 As shown: A low-latency network security situational awareness system based on artificial intelligence, including a situational early warning and visualization module. This module receives and displays a global situational assessment report generated by the situational assessment and anomaly detection engine module, and triggers tiered early warnings based on the risk level reported in the report. Specifically, it is used for: The attack chain, firmware security risks, and IoT terminal status are displayed in the global situation assessment report through dynamic topology maps and situation dashboards. Based on risk level rules, tiered warnings are triggered, including local audible and visual warnings for IoT terminals, remote SMS warnings, and remote email warnings. It receives defense commands input manually and transmits them to the cross-domain linkage engine module through an encrypted channel.
[0085] Furthermore, the hardware carrier of the situation warning and visualization module can be adapted to edge-side visualization terminals or cloud display platforms, integrating data reception, situation display, warning triggering, and command reception modules. It has the ability to intuitively present the situation and respond quickly to emergencies. Before the situation warning and visualization module is put into operation, the protocol adaptation and interface debugging with the situation assessment and anomaly identification engine module and the cross-domain linkage engine module have been completed, and the scope of situation report reception, warning rule configuration, and manual command transmission specifications have been clarified. All situation display and warning behaviors are authorized by users in advance, strictly comply with relevant laws and regulations, ensure the security of warning information transmission, and ensure that the issuance of manual commands is compliant and controllable.
[0086] After startup, the situational awareness and visualization module first completes its initial configuration, verifying the connectivity of communication links with related modules, the integrity of the visualization interface, and the validity of warning rules. If any issues such as link anomalies, interface malfunctions, or missing rules are found, an alarm is immediately sent to the system management module, suspending situational awareness reception and display. Operation resumes once the problem is resolved. After initialization, the situational awareness and visualization module initiates a high-priority data reception process, continuously receiving global situational assessment reports from the situational assessment and anomaly identification engine module. Upon receipt, it performs integrity checks, discards failed reports and provides feedback, and synchronizes the reports to the local cache after successful verification, providing support for situational awareness display and warning triggering.
[0087] In the situational awareness display phase, the situational awareness warning and visualization module provides a clear and intuitive overall situational overview through a dynamic topology map and a situational awareness dashboard. The dynamic topology map displays the overall IoT network topology in real time, including the distribution of sensor clusters, terminal access status, and topology connection relationships. It marks abnormal terminals, attack links, and firmware security risk nodes, using different colors to distinguish terminal operating status. It supports topology zooming, panning, and node detail queries for easy and rapid vulnerability identification. The situational awareness dashboard integrates core indicators, covering the overall network risk level, abnormal terminal statistics, firmware vulnerability distribution, attack type ratio, and protection effectiveness assessment. Presented in chart and data dashboard formats, it supports viewing situational trends over time, providing a basis for operational and maintenance analysis.
[0088] The situational early warning and visualization module triggers tiered early warnings based on risk level rules. The rules are divided according to the scope of impact, severity, and urgency of the security threat. The core indicators for the level division include the number of affected terminals, the speed of attack propagation, and the severity of firmware vulnerabilities. Different risk levels correspond to different combinations of early warning methods.
[0089] Tiered early warnings are triggered based on risk level rules, which are categorized according to the scope of the security threat's impact, the degree of harm, and the urgency of the response: Level 1 Risk: Number of affected terminals < 5, no trend of attack spread, firmware vulnerability is of low severity. Level 2 risk: 5-20 affected terminals, slow attack spread, firmware vulnerability is classified as medium hazard. Level 3 risk: 20-50 affected terminals, rapid attack spread, and high-risk firmware vulnerability. Level 4 risk: More than 50 terminals are affected, the attack is spreading on a large scale, and the firmware vulnerability is classified as a serious threat.
[0090] When the risk level in the report reaches the threshold, a tiered warning is immediately triggered, including local audible and visual warnings on the terminal, and remote SMS and email warnings. The warning information includes the risk level, scope of impact, details of the anomaly, attack chain, and preliminary handling suggestions to ensure that relevant personnel receive information in a timely manner and carry out emergency response.
[0091] The situational awareness and visualization module supports manual intervention. Operations personnel can input defense commands through the visual interface. Commands include the type of operation, target terminal identifier, execution priority, and timeliness requirements. After input, multi-role permission verification is required, including the operations personnel's operating permissions and command approval permissions. Once verification is successful, the module encrypts the command and transmits it to the cross-domain linkage engine module through a secure channel. A command verification mechanism ensures transmission security; if transmission fails, the user is prompted to re-enter and send the command. After receiving the command execution results, the module synchronously updates the visualization interface, displaying the execution progress and handling effect, providing a reference for subsequent analysis.
[0092] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A low-latency network security situational awareness system based on artificial intelligence, characterized in that, The system includes a dynamic perception topology reconstruction module, an edge gateway module, an terminal security proxy module, a situation assessment and anomaly identification engine module, a cross-domain linkage engine module, and a situation warning and visualization module. The dynamic sensing topology reconstruction module is used to collect the network access status of IoT terminals in real time, and dynamically construct local sensing clusters and elect cluster heads based on the access status to reconstruct the network topology. The edge gateway module is used to receive and aggregate data from IoT terminals within the cluster uploaded by the cluster head, as well as device operation data directly uploaded by IoT terminals that have not joined the sensing cluster. The terminal security proxy module is used to collect the firmware operation characteristics of the IoT terminal and perform local normalization and encryption, send the encrypted firmware characteristic data to the cross-domain linkage engine module, and execute the protection instructions issued by the cross-domain linkage engine module. The situation assessment and anomaly identification engine module is used to receive network topology data sent by the dynamic perception topology reconstruction module and device operation data sent by the edge gateway module, and use the situation inference model to perform security situation assessment and anomaly identification to generate abnormal situation data. The cross-domain linkage engine module is used to receive firmware feature data sent by the terminal security agent module and abnormal situation data sent by the situation assessment and anomaly identification engine module, perform data fusion and correlation analysis, and generate linkage response instructions based on the analysis results. The linkage response instructions include the protection instructions sent to the terminal security agent module. The situation warning and visualization module is used to receive and display the global situation assessment report generated by the situation assessment and anomaly identification engine module, and trigger graded warnings based on the risk level in the report.
2. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the dynamic sensing topology reconstruction module performs the function of real-time acquisition of network access status of IoT terminals and dynamic construction of local sensing clusters and election of cluster heads based on the access status, it is specifically used for: Collect mobile attributes, connection stability, and signal strength of IoT terminals to construct a terminal status profile; When a mobile IoT terminal is connected, it is combined with the surrounding fixed IoT terminals to form a local sensing cluster. Cluster heads are elected from the fixed IoT terminals according to predetermined connection stability parameters; The cluster head is used to aggregate local data shared by IoT terminals within the cluster through an encrypted short-range communication protocol and upload it to the edge gateway module. When a mobile IoT terminal leaves the current sensing cluster, the cluster structure is reorganized and temporary shared data associated with the mobile IoT terminal is cleared.
3. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the terminal security proxy module performs the function of collecting firmware runtime characteristics of the IoT terminal and performing local normalization and encryption, it is specifically used for: Collect the firmware operation characteristics of the IoT terminal, and perform local format standardization and redundancy removal on the collected firmware operation characteristics; The processed feature data is encrypted, and the encrypted data carrying the IoT terminal identity is transmitted to the cross-domain linkage engine module through a secure channel.
4. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the edge gateway module performs the function of receiving and aggregating intra-cluster IoT terminal data uploaded by the cluster head, as well as device operation data directly uploaded by IoT terminals not joined to the sensing cluster, it is specifically used for: The received cluster head uploaded data and IoT terminal direct transmitted data are formatted and redundancy is removed to form a device operation data summary set; The device operation data is aggregated, encrypted, and then transmitted to the situation assessment and anomaly identification engine module.
5. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the situation assessment and anomaly identification engine module receives the network topology data and device operation data, and performs security situation assessment and anomaly identification using the situation inference model, it is specifically used for: The network topology data and device operation data are analyzed by the situation reasoning model to identify network attack links and abnormal device behavior, and to generate the abnormal situation data. The abnormal situation data is pushed to the cross-domain linkage engine module; The system receives the protection execution results from the cross-domain linkage engine module and updates the global situation assessment report based on these results and real-time data.
6. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the cross-domain linkage engine module executes the function of receiving the firmware feature data and the abnormal situation data, performing data fusion and correlation analysis, and generating linkage response instructions based on the analysis results, it is specifically used for: Establish a mapping relationship between firmware feature data and network anomaly status data; By fusing and comparing the firmware feature data with the abnormal situation data, security vulnerabilities or anomalies at the firmware level can be identified. When it is detected that the attack originates from a firmware vulnerability, the corresponding protection command is generated and sent to the terminal security agent module. The system receives the protection execution results from the terminal security agent module and pushes them to the situation assessment and anomaly identification engine module.
7. The low-latency network security situational awareness system based on artificial intelligence according to claim 1, characterized in that, When the situational awareness and visualization module receives and displays the global situational assessment report, and triggers tiered warnings based on the risk level in the report, it is specifically used for: The attack chain, firmware security risks, and IoT terminal status in the global situation assessment report are displayed through a dynamic topology map and situation dashboard. Based on risk level rules, tiered warnings are triggered, including local audible and visual warnings for IoT terminals, remote SMS warnings, and remote email warnings. It receives defense commands input manually and transmits the defense commands to the cross-domain linkage engine module through an encrypted channel.
8. A low-latency network security situational awareness system based on artificial intelligence according to claim 2, characterized in that, The connection stability parameter is calculated based on the continuous access duration of the IoT terminal and the signal fluctuation frequency.
9. A low-latency network security situational awareness system based on artificial intelligence according to claim 3, characterized in that, The firmware runtime characteristics include firmware version information, process call sequence, permission allocation record, and firmware update log.
10. A low-latency network security situational awareness system based on artificial intelligence according to claim 6, characterized in that, The cross-domain linkage engine module is also connected to a security policy library; When executing the linkage response command generated based on the analysis results, the cross-domain linkage engine module is also specifically used for: Based on the results of the fusion analysis, the corresponding protection policy is matched and invoked from the security policy library to generate the linkage response command.