Network security emergency management system and method based on multi-source data fusion
By constructing a network security emergency management system that integrates multi-source data, the problems of inconsistent access to multi-source data and interference from low-quality data have been solved. This has enabled efficient data access and unified processing, improved the system's response speed and decision reliability, and ensured the accuracy and integrity of the data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGDONG POWER GRID CO LTD
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-19
AI Technical Summary
Existing technologies lack a unified standard for multi-source data access, making it difficult to unify the processing of multi-source data, resulting in low-quality data interference, failing to meet the real-time requirements of emergency response, and having high transmission latency, which cannot guarantee the integrity and accuracy of critical data.
A network security emergency management system based on multi-source data fusion is adopted. Through collaborative servers and execution layers, a lightweight post-quantum encryption algorithm, PTP protocol and time-series graph neural network are used to construct a nanosecond-level clock tree, dynamically parse device and user aliases, isolate low-quality data, construct a device-user-vulnerability association graph, and use generative adversarial network to compensate for non-core data, so as to achieve efficient data access and unified processing.
It enables efficient access and unified processing of multi-source data, reduces the false alarm rate of the system, improves the retention rate of key information, shortens the response time, enhances the anti-interference ability and decision reliability of the system, and ensures the temporal consistency of data and the dynamic mapping of entity relationships.
Smart Images

Figure CN122069075A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security emergency management system and method based on multi-source data fusion. Background Technology
[0002] Cyberattacks have escalated from single system failures to major emergencies affecting the operation of critical information infrastructure such as energy, finance, and communications. With the popularization of technologies such as cloud computing, the Internet of Things, and big data, cybersecurity data has become characterized by "massive heterogeneity," encompassing structured device logs, semi-structured threat intelligence, unstructured public opinion texts, and real-time streaming network traffic. Single-type data processing technologies are insufficient to handle this, and security data from different industries and sectors is stored in a scattered manner with inconsistent data formats and semantics. This leads to inconsistent data, inaccurate analysis, and delayed response during emergency response, making it impossible to form a global situational awareness. Existing technologies lack a unified standard for multi-source data access, which means that when adding new data sources, it is necessary to repeatedly develop adaptation structures, resulting in poor scalability. Furthermore, the centralized collection mode that uses edge collection and transmission to the cloud has high transmission latency, which cannot meet the emergency needs of millisecond-level response and is also susceptible to bandwidth limitations that can lead to the loss of critical data.
[0003] Patent CN115277173B discloses a network security monitoring and management system and method. The above patent enables the prediction of network attack behavior and can identify network attacks before they are completed, thereby improving the efficiency of network attack identification and the security of network protection.
[0004] The aforementioned patent acquires sensor monitoring logs through IDS, generates attack event sets, a preprocessing module extracts information from specific fields of the attack event sets to generate event information, an event detection module determines suspicious behaviors in the event information based on a preset attack behavior set, uses a kill chain model to identify suspicious servers in the network and the current attack stage, an attack evolution module evolves attack schemes for the next attack stage of multiple network attacks, and a kill chain identification module determines whether each attack scheme is a network attack. By analyzing the attack event sets of each alarm, using the kill chain model to analyze the current stage of the network attack, and simulating an attack from the attacker's perspective, the patent predicts network attack behavior. It can identify network attacks before they are completed and has room for optimization in multi-source data fusion.
[0005] Therefore, this application proposes a network security emergency management system and method based on multi-source data fusion for efficient access to multi-source data. Summary of the Invention
[0006] The purpose of this invention is to provide a network security emergency management system and method based on multi-source data fusion, so as to solve the technical problems of lack of unified standards and low-quality data interference when accessing multi-source data as mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a network security emergency management system based on multi-source data fusion, comprising a collaborative server and an execution layer. The collaborative server consists of a perception module, a decision-making module, an identification module, and a feedback module. The perception module is used for data collection and unification. The decision-making module constructs a risk prediction model based on the information collected by the perception module. The identification module is used for dynamic threat detection. The feedback module is used to monitor prediction deviation, handling efficiency, and the reliability of synthesized data. The execution layer is used to receive and execute information and instructions transmitted by the collaborative server. The perception module dynamically loads the data source interface through a containerized framework, uses a lightweight post-quantum encryption algorithm for encrypted transmission, decouples the strong coupling between the protocol and encryption, locks the spatiotemporal verification packet metadata during data cleaning, constructs a nanosecond-level clock tree based on the PTP protocol, injects redundant synchronization packets to correct drift, uses a dynamic entity resolution engine to eliminate ambiguity in device and user aliases, updates the device-user-vulnerability association graph in real time through a time-series graph neural network, calculates data confidence weights by comprehensively considering the authority of the data source and behavioral consistency, isolates low-quality data, compensates for non-core data through a generative adversarial network, and adds labels to the generated data.
[0008] Preferably, the decision module extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model, uses data confidence weights as feature inputs, processes graph structure features and time series features in a unified manner through a graph temporal convolutional network, and uses an adaptive weighted fusion algorithm to suppress overfitting risk based on the volatility of the behavioral consistency index, thereby constructing a risk prediction model.
[0009] Preferably, the identification module receives information collected by the perception module, automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, aligns the PTP clock tree through a nanosecond-level temporal convolutional network, detects the deviation between the actual behavior and the behavioral baseline, identifies abnormal behavior, pushes it to the decision module for risk prediction and causal analysis, and links the feedback module to generate alarm information including attack entry point location and impact range assessment.
[0010] Preferably, the feedback module receives the risk prediction results output by the risk prediction model and the alarm information from the identification module, aligns the event timing through a nanosecond-level clock tree using the PTP protocol, calculates the difference between the false alarm rate and the recall rate, and uniformly analyzes the pollution ratio of non-core data and low-confidence-weight data compensated by the generative adversarial network with a confidence weight of 0.5 as the benchmark, thereby generating an optimization strategy, correcting the data confidence weight of the perception module and the parameters of the generative adversarial network in real time, and adjusting the feature fusion weight of the decision module at the same time.
[0011] Preferably, the information collected by the sensing module includes network entity status data, environmental situation data, and threat intelligence data; Network entity status data includes device operating status collected by embedded sensors, user behavior logs collected by terminal detection probes and identity authentication systems, and vulnerability exposure status collected by vulnerability scanners; Environmental situation data includes physical environment parameters collected by sensor networks, network traffic characteristics collected by deep packet inspection devices and NetFlow collectors, and geospatial information collected by GPS modules; Threat intelligence data includes external threat indicators collected by the threat intelligence platform API, social media alerts collected by web crawlers, and collaborative defense data collected by federated learning nodes and blockchain evidence storage systems.
[0012] Preferably, the non-core data consists of descriptive text that does not directly participate in security decisions, physical indicators that are not directly related to the attack chain, and low-risk metadata.
[0013] Preferably, the alarm information is divided into three levels: the first level is an emergency alarm indicating a risk of core business interruption; the second level is a high-risk alarm indicating partial business damage; and the third level is a low-risk alarm indicating a single point of failure.
[0014] Preferably, the execution layer receives alarm information generated by the identification module and triggers an automated response.
[0015] Preferably, the execution layer performs automated processing based on the alarm information level of the identification module. When the decision module receives an emergency alarm, it isolates the host and cuts off the network connection. When the decision module receives a high-risk alarm, it limits the port flow and freezes the account. When the decision module receives a low-risk alarm, it issues an alarm notification and enhances the operation of the identification module.
[0016] Preferably, the network security emergency management method is as follows: S1: The perception module collects information and builds a unified data model and a device-user-vulnerability association graph; S2: The decision-making module constructs a risk prediction model based on the unified information module and the device-user-vulnerability association graph; S3: The identification module receives a unified data model to build a behavior baseline, compares real-time behavior with the behavior baseline, and identifies covert attack paths through the device-user-vulnerability association graph, generating alarm information; S4: The feedback module compares the risk prediction results output by the risk prediction model with the actual security events, calculates the difference between the false alarm rate and the recall rate, and generates optimization strategies. S5: The execution layer receives alarm information from the identification module and optimization strategies from the feedback module, and processes the device accordingly.
[0017] Compared with the prior art, the beneficial effects of the present invention are: 1. This invention, through the design of a unified data model, realizes the function of efficient access to multi-source data, solves the problems of difficulty in unifying multi-source data, existence of identification blind spots and interference from low-quality data, can ensure the temporal consistency of multi-source data, can dynamically map entity relationships, reduce the false alarm rate of the system, and improve the retention rate of key information; 2. This invention, through the design of a risk prediction model, realizes the function of multi-scale anomaly detection, solves the problems of difficulty in associating different attack chains, ignoring long-cycle attacks and low-quality data interference, reduces blind spots in cross-device attack paths, improves the system's anti-interference capability, and shortens the system response time. 3. This invention, by designing a system that correlates a unified data model and a risk prediction model, achieves the function of proactive prediction and response, solving the problems of low-quality data contaminating decision-making, delayed anomaly detection, and lack of multi-dimensional correlation. It can automatically remove low-quality data, improve the system's detection accuracy, and enhance the connection between multi-source data. 4. This invention optimizes the unified data model and risk prediction model based on risk prediction results and alarm information, thus achieving model optimization. It solves the problems of inaccurate causal chain reconstruction, data pollution, and response delay, avoids timing deviations that lead to incorrect association of attack events, and improves the robustness and decision reliability of the system. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the network security emergency management system of the present invention; Figure 2 This is a schematic diagram of the network security emergency management operation of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Example 1: Please refer to Figure 1 and Figure 2 A network security emergency management system based on multi-source data fusion includes a collaborative server and an execution layer. The collaborative server consists of a perception module, a decision-making module, an identification module, and a feedback module. The perception module is used for data collection and unification. The decision-making module builds a risk prediction model based on the information collected by the perception module. The identification module is used for dynamic threat detection. The feedback module is used to monitor prediction deviation, response efficiency, and the reliability of synthetic data. The execution layer is used to receive and execute information and instructions transmitted by the collaborative server. The perception module dynamically loads the data source interface through a containerized framework, uses a lightweight post-quantum encryption algorithm for encrypted transmission, decouples the strong coupling between the protocol and encryption, locks the spatiotemporal verification packet metadata when cleaning the received data, constructs a nanosecond-level clock tree based on the PTP protocol, injects redundant synchronization packets to correct drift, uses a dynamic entity resolution engine to eliminate ambiguity between device and user aliases, updates the device-user-vulnerability association graph in real time through a time-series graph neural network, calculates data confidence weights by comprehensively considering the authority of the data source and the consistency of behavior, isolates low-quality data, compensates non-core data through a generative adversarial network, and adds labels to the generated data. The information collected by the perception module includes network entity status data, environmental situation data, and threat intelligence data. Network entity status data includes device operating status collected by embedded sensors, user behavior logs collected by terminal detection probes and identity authentication systems, and vulnerability exposure status collected by vulnerability scanners; Environmental situation data includes physical environment parameters collected by sensor networks, network traffic characteristics collected by deep packet inspection devices and NetFlow collectors, and geospatial information collected by GPS modules; Threat intelligence data includes external threat indicators collected by the threat intelligence platform API, social media alerts collected by web crawlers, and collaborative defense data collected by federated learning nodes and blockchain evidence storage systems. The non-core data includes descriptive text that does not directly participate in security decisions, physical indicators that are not directly related to the attack chain, and low-risk metadata. Furthermore, when external multi-source heterogeneous data is transmitted to the collaborative server, three types of data source interfaces are dynamically loaded through a capacity-based framework. These include device operating status data collected by embedded sensors, user behavior logs collected by terminal detection probes and identity authentication systems, and network entity status data on vulnerability exposure status collected by vulnerability scanners; environmental situation data including physical environment parameters collected by sensor networks, network traffic characteristics collected by deep packet inspection devices and NetFlow collectors, and geospatial information collected by GPS modules; and threat intelligence data including external threat indicators collected by threat intelligence platform APIs, social media alerts collected by web crawlers, and collaborative defense data collected by federated learning nodes and blockchain evidence storage systems. A lightweight post-quantum encryption algorithm is used to achieve decoupled transmission of protocol and encryption, avoiding the long extension cycle caused by reliance on fixed protocol adapter encryption and strong protocol coupling. The received data port locks the spatiotemporal verification packet metadata, based on the PTP protocol. A nanosecond-level clock tree is constructed and redundant synchronization packets are injected to correct clock drift, ensuring an error of no more than 0.05ms. This avoids the high errors and cross-source data timing deviations caused by NTP time synchronization. A dynamic entity parsing engine is used to eliminate ambiguity in device aliases and user accounts. A time-series graph neural network is used to update the device-user-vulnerability three-dimensional association graph in real time, avoiding the inability of static rules to handle dynamic aliases such as device IP changes. Confidence weights are dynamically calculated based on the authority of data sources and the consistency of behavior, isolating low-quality data with confidence weights less than 0.3. For non-core data, including auxiliary log text, physical treatments of irrelevant attack chains, and low-risk metadata, a generative adversarial network is used to compensate for missing values, and labels are added to mark the compensated data. This avoids the deviation of subsequent prediction results caused by the direct input of low-quality data and avoids the accidental deletion of core data, ensuring data integrity. The final output is a unified data model with spatiotemporal reference, entity relationships, confidence weights, and data attributes.
[0021] Example 2: Please refer to Figure 1 and Figure 2 A network security emergency management system based on multi-source data fusion includes a collaborative server and an execution layer. The collaborative server consists of a perception module, a decision-making module, an identification module, and a feedback module. The perception module is used for data collection and unification. The decision-making module builds a risk prediction model based on the information collected by the perception module. The identification module is used for dynamic threat detection. The feedback module is used to monitor prediction deviation, response efficiency, and the reliability of synthetic data. The execution layer is used to receive and execute information and instructions transmitted by the collaborative server. The perception module dynamically loads the data source interface through a containerized framework, uses a lightweight post-quantum encryption algorithm for encrypted transmission, decouples the strong coupling between the protocol and encryption, locks the spatiotemporal verification packet metadata when cleaning the received data, constructs a nanosecond-level clock tree based on the PTP protocol, injects redundant synchronization packets to correct drift, uses a dynamic entity resolution engine to eliminate ambiguity between device and user aliases, updates the device-user-vulnerability association graph in real time through a time-series graph neural network, calculates data confidence weights by comprehensively considering the authority of the data source and the consistency of behavior, isolates low-quality data, compensates non-core data through a generative adversarial network, and adds labels to the generated data. The decision module extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model, uses data confidence weights as feature inputs, and processes graph structure features and time series features in a unified manner through a graph temporal convolutional network. Based on the volatility of the behavior consistency index, an adaptive weighted fusion algorithm is used to suppress the risk of overfitting and construct a risk prediction model. Furthermore, based on the unified data model constructed using the perception module, graph structure features such as node centrality and edge propagation probability, as well as time series features such as vulnerability exposure frequency fluctuations, are extracted from the real-time updated three-dimensional correlation graph of device-user-vulnerability by the time-series graph neural network. Node centrality is used to calculate the betweenness centrality of device nodes in the attack propagation path, identifying key attack springboards. Edge propagation probability is quantified using a graph attention mechanism based on historical attack data, such as vulnerability one leading to an increased penetration success rate of vulnerability two. Periodic anomalies, such as scanning behavior bursting every 5 minutes, are detected using a sliding window Fourier transform. Approximate entropy is extracted to measure the randomness of traffic surges. Simultaneously, data confidence weights are incorporated as attenuation coefficients into the feature input to suppress interference from low-quality data. Data with a confidence weight less than 0.3 is considered low-quality data. To ensure no misjudgment occurs during traffic surges, a sliding window can be introduced to adaptively adjust the judgment criteria for low-quality data. Low-quality data feature values are compressed to near zero to suppress noise interference. Then, spatiotemporal features are uniformly processed through a graph temporal convolutional network. The graph convolutional layer of the graph temporal convolutional network captures the topological relationship between devices through neighborhood aggregation to identify cross-device attack paths. The temporal convolutional layer uses dilated causal convolution to analyze the continuous patterns of behavior logs to detect slow penetration attacks. The outputs of the graph convolutional layer and the temporal convolutional layer are fused through tensor concatenation to construct a joint feature space. Based on behavioral consistency indicators such as traffic surges and deviations from the baseline, an adaptive weighted fusion algorithm is adopted to dynamically adjust the weight ratio of graph features and temporal features. Combined with an online incremental learning mechanism, parameters are fine-tuned every 10 minutes. An elastic weight consolidation algorithm is used to retain important parameter memories. The FTRL optimizer is used to achieve efficient preservation of sparse features and suppress the risk of overfitting in complex scenarios. The risk prediction model is constructed and outputs the risk prediction results with quantified attack probability and impact range.
[0022] Example 3: Please refer to Figure 1 and Figure 2 The network security emergency management system based on multi-source data fusion has a decision module that extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model. It uses data confidence weights as feature inputs, processes graph structure features and time series features in a unified manner through a graph temporal convolutional network, and uses an adaptive weighted fusion algorithm to suppress overfitting risk based on the volatility of the behavior consistency index, thereby constructing a risk prediction model. The identification module receives information collected by the perception module, automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, aligns the PTP clock tree through a nanosecond-level temporal convolutional network, detects the deviation between actual behavior and behavioral baseline, identifies abnormal behavior, pushes it to the decision module for risk prediction and causal analysis, and links the feedback module to generate alarm information including attack entry point location and impact range assessment. Furthermore, after receiving the unified data model constructed by the perception module, the threshold filtering algorithm based on confidence weight automatically filters data sources with a confidence weight lower than 0.5. If there are dynamic changes in environmental risks, such as in high-risk scenarios where zero-day vulnerabilities are exposed, the judgment threshold needs to be increased to above 0.7 to improve sensitivity. In low-risk scenarios such as internal network isolation, the threshold can be reduced to 0.3 to avoid false alarms. It isolates intruded sensors or low-confidence intelligence, statistically analyzes historical data through a sliding window, adds a PTP offset correction layer, and aligns the spatiotemporal reference of the PTP clock tree through a nanosecond-level temporal convolutional network. It introduces a window adaptive algorithm based on KL three-degrees to establish a behavioral baseline model, such as a normal login frequency threshold. The system detects real-time deviations between actual behavior and baseline behavior, such as traffic peaks and abnormal login locations, and values and device interaction patterns. When the deviation exceeds an adaptive threshold, it triggers abnormal behavior identification. The adaptive threshold can be dynamically adjusted according to environmental risks. The abnormal feature sequence is pushed to the risk prediction model built by the decision module for risk prediction and causal analysis. The identification module converts the detected abnormal behavior into feature vectors, such as the Mahalanobis distance between the actual behavior and the baseline behavior as the behavior deviation, the nanosecond-level timestamp injected into the PTP clock tree synchronization as the spatiotemporal label, and the device-user-vulnerability graph node ID as the entity association. The feature vectors are then input into the risk prediction model for risk prediction.
[0023] Example 4: Please refer to Figure 1 and Figure 2The network security emergency management system based on multi-source data fusion has a decision module that extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model. It uses data confidence weights as feature inputs, processes graph structure features and time series features in a unified manner through a graph temporal convolutional network, and uses an adaptive weighted fusion algorithm to suppress overfitting risk based on the volatility of the behavior consistency index, thereby constructing a risk prediction model. The identification module receives information collected by the perception module, automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, aligns the PTP clock tree through a nanosecond-level temporal convolutional network, detects the deviation between actual behavior and behavioral baseline, identifies abnormal behavior, pushes it to the decision module for risk prediction and causal analysis, and links the feedback module to generate alarm information including attack entry point location and impact range assessment. The feedback module receives the risk prediction results output by the risk prediction model and the alarm information from the identification module. It aligns the event timing through the nanosecond-level clock tree of the PTP protocol, calculates the difference between the false alarm rate and the recall rate, and analyzes the pollution ratio of non-core data and low-confidence-weight data compensated by the generative adversarial network with a unified confidence weight of 0.5 as the benchmark. In this way, it generates an optimization strategy, corrects the data confidence weight of the perception module and the parameters of the generative adversarial network in real time, and adjusts the feature fusion weight of the decision module. Furthermore, after the decision-making module outputs risk prediction results containing attack probability and impact range, and the identification module outputs alarm information containing attack entry point location, a clock tree is constructed using the PTP protocol to align the time-series labels of the decision-making module's prediction results and the identification module's alarm information, ensuring a time error of less than 0.05ms and accurate reconstruction of the causal chain of the attack event. The deviation of the actual false positive rate and recall rate of the risk prediction model relative to the benchmark value is calculated, with the benchmark value being the historical best performance. The decision error rate of labeled non-core data and the proportion of data with confidence weights less than 0.3 in key decisions are statistically analyzed to obtain the misjudgment rate of non-core data compensated by the generative adversarial network and the pollution ratio of low-confidence-weight data in the decision. Based on the deviation analysis results, an optimization strategy is generated. The data confidence weight calculation parameters of the perception module are dynamically corrected using a Bayesian weight decay model. A gradient inversion mechanism is used to reduce the overfitting tendency of the generative adversarial network generator to low-quality data. The feature weight ratio in the adaptive weighted fusion algorithm of the decision-making module is reconstructed, such as reducing the graph feature weight contributed by low-quality data. Finally, a containerized framework is used to achieve second-level hot deployment of the strategy.
[0024] Example 5: Please refer to Figure 1 and Figure 2The network security emergency management system based on multi-source data fusion has a decision module that extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model. It uses data confidence weights as feature inputs, processes graph structure features and time series features in a unified manner through a graph temporal convolutional network, and uses an adaptive weighted fusion algorithm to suppress overfitting risk based on the volatility of the behavior consistency index, thereby constructing a risk prediction model. The identification module receives information collected by the perception module, automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, aligns the PTP clock tree through a nanosecond-level temporal convolutional network, detects the deviation between actual behavior and behavioral baseline, identifies abnormal behavior, pushes it to the decision module for risk prediction and causal analysis, and links the feedback module to generate alarm information including attack entry point location and impact range assessment. The alarm information is divided into three levels: the first level is an emergency alarm that indicates a risk of core business interruption; the second level is a high-risk alarm that indicates partial business damage; and the third level is a low-risk alarm that indicates a single point of failure. The execution layer receives alarm information generated by the identification module and triggers an automated response. The execution layer automatically processes alarm information based on the alarm level of the identification module. When the decision module receives an emergency alarm, it isolates the host and cuts off the network connection. When the decision module receives a high-risk alarm, it limits the port flow and freezes the account. When the decision module receives a low-risk alarm, it issues an alarm notification and enhances the operation of the identification module. Furthermore, the decision-making module extracts graph structure features and time-series features from the device-user-vulnerability association graph constructed by the perception module. It inputs data confidence weights as feature decay coefficients into a graph temporal convolutional network. Through the graph convolutional layers of the graph temporal convolutional network, it analyzes device topology relationships and detects behavioral continuity. Based on the volatility of the behavioral consistency index, it dynamically adjusts the feature weight ratio using an adaptive weighted fusion algorithm to suppress overfitting, thus completing the risk prediction model construction. After receiving the perception data, the identification module automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, and aligns the PTP clock tree through a nanosecond-level temporal convolutional network to achieve zero... The system features 0.05ms-level spatiotemporal synchronization. When the deviation between the actual behavior and the baseline behavior exceeds a dynamic threshold, abnormal behavior is identified and pushed to the decision-making module for risk probability prediction and causal analysis. Simultaneously, the feedback module generates a three-level alarm containing the coordinates of the attack entry point and the scope of impact. When a core business risk such as database encryption is interrupted, an emergency alarm is triggered, and the decision-making module performs host isolation and network disconnection. When a business part is damaged due to payment anomalies, a high-risk alarm is triggered, and the decision-making module performs port rate limiting and account freezing. When a single point of failure such as port scanning occurs, a low-risk alarm is triggered, and the decision-making module sends an alarm notification and increases the detection frequency of the identification module to real-time scanning.
[0025] Working principle: The system dynamically loads three types of data sources—device operating status, environmental situation data, and threat intelligence data—through a containerized framework. It employs a lightweight post-quantum encryption algorithm to decouple the protocol and encryption during transmission. When receiving data, it constructs a nanosecond-level clock tree based on the PTP protocol and injects redundant synchronization packets to control timing errors within 0.05ms. Simultaneously, it eliminates ambiguity of device aliases and user accounts through a dynamic entity parsing engine, updates the device-user-vulnerability three-dimensional association graph in real time through a time-series graph neural network, and dynamically calculates confidence weights based on the authority of the data source and behavioral consistency. It isolates low-quality data with confidence weights below 0.3, uses a generative adversarial network to compensate for missing non-core data, and adds labels to the compensated non-core data. The system outputs a unified data model with spatiotemporal reference, entity relationships, confidence weights, and data attributes. The system is based on a unified data model, extracting graph structure features and time series features from the device-user-vulnerability association graph. Data confidence weights are incorporated as attenuation coefficients into the feature input to suppress interference from low-quality data. Spatiotemporal features are uniformly processed through a graph temporal convolutional network. Graph convolutional layers are used to capture the topological relationships between devices to identify cross-device attack paths. Dilated causal convolutions are used in temporal convolutional layers to analyze behavioral continuity patterns to detect slow penetration attacks. The outputs of graph convolutional layers and temporal convolutional layers are fused through tensor concatenation. An adaptive weighted fusion algorithm is used to dynamically adjust the feature weight ratios in conjunction with behavioral consistency indicators. Parameters are fine-tuned every 10 minutes through an online incremental learning mechanism. Finally, a risk prediction model is constructed, outputting a quantitative attack probability and impact range. After receiving the unified data model, the system dynamically filters the data source based on the confidence weight threshold filtering algorithm, isolates the intruded sensor or low-confidence intelligence, statistically analyzes historical data through a sliding window, and introduces the KL divergence window adaptive algorithm to establish a behavioral baseline model. It uses a nanosecond-level temporal convolutional network to align the PTP clock tree and detects the millisecond-level deviation between the actual behavior and the behavioral baseline in real time. When the deviation exceeds the adaptive threshold, the system triggers abnormal behavior identification, pushes the feature vector to the risk prediction model for prediction, and outputs the attack probability and impact range. The identification module generates alarm information containing the location of the attack entry point and aligns the time sequence of the two through the PTP clock tree to ensure accurate reconstruction of the event causal chain. The system evaluates the risk prediction model by calculating the false positive rate and recall rate deviation, and statistically analyzes the false positive rate of non-core generated data and the pollution ratio of low-confidence weight data. It dynamically corrects the confidence weight calculation parameters of the perception module through a Bayesian weight decay model, adopts a gradient inversion mechanism to reduce the overfitting tendency of generative adversarial networks to low-quality data, reconstructs the feature weight ratio of the decision module, and implements a hierarchical response mechanism at the system execution layer. For the risk of core business interruption, it triggers an emergency alarm and performs host isolation and network disconnection; for the damage to business parts, it triggers a high-risk alarm and performs port rate limiting and account freezing; and for single-point anomalies, it triggers a low-risk alarm and increases the detection frequency of the identification module to real-time scanning.
[0026] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, it is intended that all variations falling within the meaning and scope of equivalents of the claims be included within the present invention.
Claims
1. A network security emergency management system based on multi-source data fusion, characterized in that: It includes a collaborative server and an execution layer. The collaborative server consists of a perception module, a decision module, an identification module, and a feedback module. The perception module is used for data collection and unification. The decision module builds a risk prediction model based on the information collected by the perception module. The identification module is used for dynamic threat detection. The feedback module is used to monitor prediction deviation, handling efficiency, and the reliability of synthetic data. The execution layer is used to receive and execute information and instructions transmitted by the collaborative server. The perception module dynamically loads the data source interface through a containerized framework, uses a lightweight post-quantum encryption algorithm for encrypted transmission, decouples the strong coupling between the protocol and encryption, locks the spatiotemporal verification packet metadata during data cleaning, constructs a nanosecond-level clock tree based on the PTP protocol, injects redundant synchronization packets to correct drift, uses a dynamic entity resolution engine to eliminate ambiguity in device and user aliases, updates the device-user-vulnerability association graph in real time through a time-series graph neural network, calculates data confidence weights by comprehensively considering the authority of the data source and behavioral consistency, isolates low-quality data, compensates for non-core data through a generative adversarial network, and adds labels to the generated data.
2. The network security emergency management system based on multi-source data fusion according to claim 1, characterized in that: The decision module extracts graph structure features and time series features based on the device-user-vulnerability association graph constructed by the perception model. It uses data confidence weights as feature inputs, processes graph structure features and time series features in a unified manner through a graph temporal convolutional network, and uses an adaptive weighted fusion algorithm to suppress overfitting risk based on the volatility of the behavioral consistency index, thus constructing a risk prediction model.
3. The network security emergency management system based on multi-source data fusion according to claim 2, characterized in that: The identification module receives information collected by the perception module, automatically filters data sources with confidence weights below 0.5, establishes a behavioral baseline based on historical data, aligns the PTP clock tree through a nanosecond-level temporal convolutional network, detects the deviation between the actual behavior and the behavioral baseline, identifies abnormal behavior, and pushes it to the decision module for risk prediction and causal analysis. It also links with the feedback module to generate alarm information including attack entry point location and impact range assessment.
4. The network security emergency management system based on multi-source data fusion according to claim 3, characterized in that: The feedback module receives the risk prediction results output by the risk prediction model and the alarm information from the identification module. It aligns the event timing through a nanosecond-level clock tree using the PTP protocol, calculates the difference between the false alarm rate and the recall rate, and analyzes the pollution ratio of non-core data and low-confidence-weight data compensated by the generative adversarial network with a unified confidence weight of 0.5 as the benchmark. This generates an optimization strategy, corrects the data confidence weight of the perception module and the parameters of the generative adversarial network in real time, and adjusts the feature fusion weight of the decision module.
5. The network security emergency management system based on multi-source data fusion according to claim 1, characterized in that: The information collected by the perception module includes network entity status data, environmental situation data, and threat intelligence data. Network entity status data includes device operating status collected by embedded sensors, user behavior logs collected by terminal detection probes and identity authentication systems, and vulnerability exposure status collected by vulnerability scanners; Environmental situation data includes physical environment parameters collected by sensor networks, network traffic characteristics collected by deep packet inspection devices and NetFlow collectors, and geospatial information collected by GPS modules; Threat intelligence data includes external threat indicators collected by the threat intelligence platform API, social media alerts collected by web crawlers, and collaborative defense data collected by federated learning nodes and blockchain evidence storage systems.
6. The network security emergency management system based on multi-source data fusion according to claim 1, characterized in that: The non-core data refers to descriptive text that does not directly participate in security decisions, physical indicators that are not directly related to the attack chain, and low-risk metadata.
7. The network security emergency management system based on multi-source data fusion according to claim 3, characterized in that: The alarm information is divided into three levels: the first level is an emergency alarm indicating a risk of core business interruption; the second level is a high-risk alarm indicating partial business damage; and the third level is a low-risk alarm indicating a single point of failure.
8. The network security emergency management system based on multi-source data fusion according to claim 7, characterized in that: The execution layer receives alarm information generated by the identification module and triggers an automated response.
9. The network security emergency management system based on multi-source data fusion according to claim 8, characterized in that: The execution layer automatically processes alarm information based on the alarm level of the identification module. When the decision module receives an emergency alarm, it isolates the host and cuts off the network connection. When the decision module receives a high-risk alarm, it limits the port flow and freezes the account. When the decision module receives a low-risk alarm, it issues an alarm notification and enhances the operation of the identification module.
10. A network security emergency management method based on multi-source data fusion, applicable to the network security emergency management system based on multi-source data fusion as described in any one of claims 1-9, characterized in that: The network security emergency management method is as follows: S1: The perception module collects information and builds a unified data model and a device-user-vulnerability association graph; S2: The decision-making module constructs a risk prediction model based on the unified information module and the device-user-vulnerability association graph; S3: The identification module receives a unified data model to build a behavior baseline, compares real-time behavior with the behavior baseline, and identifies covert attack paths through the device-user-vulnerability association graph, generating alarm information; S4: The feedback module compares the risk prediction results output by the risk prediction model with the actual security events, calculates the difference between the false alarm rate and the recall rate, and generates optimization strategies. S5: The execution layer receives alarm information from the identification module and optimization strategies from the feedback module, and processes the device accordingly.