Machine room security intelligent management method and system

By performing multi-source intelligent processing and comprehensive analysis on data center security monitoring data, security event identification data is generated, enabling automatic patrol and collaborative response. This solves the problems of response delay and false alarms in existing security systems, and improves the real-time performance and accuracy of security systems.

CN122157411APending Publication Date: 2026-06-05四川华鲲振宇智能科技有限责任公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
四川华鲲振宇智能科技有限责任公司
Filing Date
2026-02-25
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing data center security systems lack intelligent fusion analysis mechanisms, making it impossible to effectively identify complex security threats in multi-source heterogeneous data. This results in security response delays, high false alarm rates, and low handling efficiency, failing to meet the requirements for real-time performance, accuracy, and automation.

Method used

By acquiring security monitoring data from the computer room, performing multi-source data processing, generating security event identification data, and combining automatic patrol and patrol results, generating security alarm data, and executing collaborative response operations, including comprehensive analysis and multi-factor weighted scoring of video anomaly identification, environmental anomaly identification, and access control anomaly identification, intelligent security management is achieved.

Benefits of technology

It improves the real-time performance, accuracy, and efficiency of data center security, reduces false alarms and response delays, and meets the needs of high-level data centers for automated and intelligent security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122157411A_ABST
    Figure CN122157411A_ABST
Patent Text Reader

Abstract

The application discloses a machine room security and protection intelligent management method and system, relates to the technical field of security and protection monitoring, and discloses the machine room security and protection intelligent management method and system, acquires multi-source security and protection monitoring data, intelligently processes event identification data, and automatically executes patrol and response operations, solves the data island and response delay problems in the prior art, can improve the real-time performance, accuracy and efficiency of machine room security and protection, and reduces false positives and response delays.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security monitoring technology, and in particular to intelligent management methods and systems for computer room security. Background Technology

[0002] With the rapid development of information technology, data centers, as core infrastructure hosting critical business operations and data assets, are crucial for ensuring business continuity through their secure and stable operation. Currently, data center security systems generally employ multiple independently operating models, such as video surveillance, environmental sensors, and access control systems. Data from these systems is isolated, forming information silos. While these systems generate massive amounts of monitoring data, they lack effective intelligent fusion and analysis mechanisms, making it impossible to comprehensively identify potential security threats from multi-source heterogeneous data. Existing technical solutions are often limited to single-dimensional alarm triggering or simple device linkage, such as alarms based solely on video analysis or environmental thresholds, which are insufficient to handle complex, cross-system security events. Furthermore, after an incident occurs, from initial identification to final response, issues such as untimely event confirmation, inaccurate risk assessment, and uncoordinated response operations lead to delayed security responses, high false alarm rates, and low handling efficiency. These problems make existing systems highly dependent on manual intervention for analysis and decision-making, failing to meet the stringent requirements of modern high-level data centers for real-time performance, accuracy, and automation.

[0003] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of this application is to provide a smart management method and system for data center security, which aims to improve the real-time performance, accuracy and efficiency of data center security, and reduce false alarms and response delays.

[0005] To achieve the above objectives, this application proposes a smart management method for computer room security, the method comprising: Acquire data on security monitoring in the computer room, including video surveillance data, environmental sensor data, and access control system data; The data from the computer room security monitoring is processed to obtain security event identification data; Based on the security event identification data, automatic patrol instruction data is generated; Based on the automatic inspection command data, the computer room inspection equipment is controlled to perform inspection actions to obtain inspection result data; Based on the security event identification data and the patrol result data, security alarm data is generated; Based on the security alarm data, execute a coordinated response operation.

[0006] In one embodiment, the step of processing the data from the computer room security monitoring data to obtain security event identification data includes: The video frame sequence data is obtained by extracting the monitoring image frame sequence from the video surveillance data. Personnel detection is performed on the video frame sequence data to identify personnel location data; Based on the personnel location data, personnel trajectory analysis is performed to obtain personnel behavior trajectory data; The personnel behavior trajectory data is compared with a preset normal behavior pattern database to obtain video anomaly identification data; The environmental sensor data is compared with an anomaly threshold. When the environmental sensor data exceeds a preset threshold, environmental anomaly identification data is obtained. The access control system data is used to identify abnormal entry and exit. When unauthorized entry and exit, entry and exit at abnormal times, or frequent entry and exit are detected, access control abnormal identification data is obtained. The security event identification data is formed by combining the video anomaly identification data, environmental anomaly identification data, and access control anomaly identification data.

[0007] In one embodiment, the step of comparing the personnel behavior trajectory data with a preset normal behavior pattern database to obtain video anomaly identification data includes: Retrieve the allowed behavior pattern data for each computer room from the preset normal behavior pattern database; Based on the personnel location data, the area of ​​the computer room where the personnel are located is determined, and the personnel location area data is obtained; Based on the personnel behavior trajectory data and personnel location area data, retrieve the permitted behavior pattern data for the corresponding computer room area; The matching degree of the personnel behavior trajectory data is calculated by matching it with the allowed behavior pattern data of the corresponding computer room area to obtain behavior matching degree data. When the behavior matching data is lower than a preset threshold, the video anomaly identification data is generated.

[0008] In one embodiment, the step of calculating the matching degree between the personnel behavior trajectory data and the allowed behavior pattern data of the corresponding computer room area to obtain behavior matching degree data includes: Analyze the trajectory features of the personnel behavior trajectory data to obtain trajectory feature data, which includes dwell time features, movement speed features, and direction change features; Extract the normal trajectory feature range corresponding to the computer room area from the permitted behavior pattern data to obtain normal feature range data; The trajectory feature data is compared item by item with the normal feature range data, and the conformity of each feature is calculated to obtain feature conformity data. The behavior matching degree data is obtained by weighted summation of the feature matching degree data for each item.

[0009] In one embodiment, the step of generating security alarm data based on the security event identification data and the patrol result data includes: The security event identification data is used to assess the severity of the event, resulting in event severity level data. The inspection result data is verified to obtain event confirmation status data; Based on the event severity level data and event confirmation status data, a comprehensive risk score is calculated to obtain risk score data; The security alarm data is generated based on the risk score data.

[0010] In one embodiment, the step of calculating a comprehensive risk score based on the event severity level data and event confirmation status data to obtain risk score data includes: Assign weight coefficients to the event severity level data to obtain severity weight data; Assign confidence coefficients to the event confirmation status data to obtain confirmation confidence data; Based on the event occurrence time in the security event identification data, the time urgency coefficient is calculated to obtain the time urgency data; Based on the severity weight data, confirmation confidence data, and time urgency data, a multi-factor weighted calculation is performed to obtain the risk score data.

[0011] In one embodiment, the step of performing a multi-factor weighted calculation based on the severity weight data, confirmation confidence data, and time urgency data to obtain the risk score data includes: A risk scoring calculation formula model is established, which includes a severity factor, a confirmation factor, and a time factor; Substitute the severity weight data into the severity factor to obtain the severity score components; Substitute the confirmation confidence data into the confirmation factor to obtain the confirmation score components; Substitute the time urgency data into the time factor to obtain the time score component; The risk score data is obtained by performing a weighted summation based on the severity score component, the confirmation score component, and the time score component.

[0012] In one embodiment, the step of performing a coordinated response operation based on the security alarm data includes: The security alarm data is analyzed to obtain the corresponding alarm level, and the response priority is determined according to the alarm level to obtain response priority data; Based on the response priority data, the corresponding response strategy combination is selected to obtain response strategy data, and based on the response strategy data, device control command data is generated. Based on the device control command data, a coordinated response operation is executed.

[0013] In one embodiment, the step of performing a coordinated response operation based on the device control command data includes: Based on the device control command data, a response execution queue is established, and an execution sequence number is assigned to each response operation to obtain response execution sequence data; Based on the response execution sequence data, notification operations and device control operations are executed sequentially to obtain response operation execution data; Based on the execution data of the response operations, the execution status of each response operation is monitored to obtain execution status monitoring data; When an execution failure is detected based on the execution status monitoring data, a backup response plan is initiated, and the response operation execution data is updated based on the execution result of the backup response plan.

[0014] Furthermore, to achieve the above objectives, this application also proposes a data center security intelligent management system, which includes: a memory, a processor, and a data center security intelligent management program stored in the memory and executable on the processor, wherein the data center security intelligent management program is configured to implement the steps of the data center security intelligent management method.

[0015] The intelligent management method and system for data center security proposed in this application acquires multi-source security monitoring data, intelligently processes and generates event identification data, and automatically executes inspection and response operations. This solves the problems of data silos and response delays in existing technologies, and can improve the real-time performance, accuracy and efficiency of data center security, while reducing false alarms and response delays. Attached Figure Description

[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart illustrating an embodiment of the intelligent management method for computer room security according to this application. Figure 2This is a structural diagram of an embodiment of the intelligent security management system for computer rooms provided in this application.

[0019] Explanation of icon numbers: 10. Memory; 20. Processor.

[0020] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0021] The technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of this application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0022] It should be understood that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, the terms "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0023] In existing technologies, data center security systems generally rely on multiple systems operating independently, such as video surveillance, access control, and environmental sensors. Each system generates massive amounts of monitoring data, but lacks an effective intelligent fusion analysis and collaborative processing mechanism. This results in difficulty in accurately identifying complex security events from multi-source heterogeneous data, leading to delayed security response, high false alarm rates, low processing efficiency, and a high dependence on manual judgment and intervention. Consequently, it fails to meet the real-time, accurate, and automated intelligent security requirements of high-level data centers.

[0024] Based on this, the embodiments of this application provide a method for intelligent management of data center security, referring to... Figure 1 The intelligent security management method for the computer room includes steps S100 to S600, wherein: Step S100: Obtain data on the security monitoring of the computer room, including video surveillance data, environmental sensor data, and access control system data. Step S200: Process the data of the computer room security monitoring to obtain security event identification data; Step S300: Based on the security event identification data, generate automatic patrol instruction data; Step S400: Based on the automatic inspection instruction data, control the computer room inspection equipment to perform inspection actions and obtain inspection result data; Step S500: Based on the security event identification data and the patrol result data, generate security alarm data; Step S600: Perform a collaborative response operation based on the security alarm data.

[0025] In this embodiment, data from the computer room security monitoring system refers to the raw data collected from various security devices deployed within the computer room, serving as the foundation for security analysis. This data specifically includes video surveillance data, environmental sensor data, and access control system data. Video surveillance data refers to images or video streams collected in real-time by cameras installed within the computer room, used to monitor visual information such as personnel activity and equipment status. Environmental sensor data refers to data collected by environmental monitoring devices such as temperature sensors, humidity sensors, smoke sensors, and water immersion sensors, used to reflect the physical environment conditions inside the computer room. Access control system data refers to personnel entry and exit information recorded by access control devices such as access controllers and card readers, including entry and exit times, personnel identities, and access control status. Security event identification data refers to detailed information about potential or actual security events identified through intelligent analysis and processing of the raw computer room security monitoring data, such as abnormal personnel behavior, environmental anomalies, and unauthorized intrusion. Automatic patrol instruction data refers to instructions automatically generated by the system based on identified security events or preset patrol plans, used to guide computer room patrol devices in performing specific patrol tasks. Patrol result data refers to the feedback information collected by the data center patrol equipment through its onboard sensors or cameras after performing patrol actions. This data is used to verify security incidents or obtain real-time on-site information. Security alarm data refers to the notification data generated by the system after confirming a security incident or risk reaching a certain level, containing information such as alarm level, incident details, and suggested response measures. Collaborative response operations refer to a series of coordinated measures automatically or semi-automatically triggered by the system based on security alarm data. These measures include sending notifications, controlling access control, adjusting environmental equipment, and activating fire protection systems to address security incidents.

[0026] In this embodiment, the intelligent security management method for the computer room first acquires security monitoring data. This data includes video surveillance data, environmental sensor data, and access control system data. The data can be acquired by simply integrating the data interfaces of the independently deployed video surveillance system, environmental sensor system, and access control system within the computer room, with the data acquisition module periodically pulling raw data from each system. For example, video recordings, environmental parameter logs, and access control card swipe records can be downloaded periodically from the servers of each system via file transfer protocols or simple API calls.

[0027] Furthermore, the security monitoring data of the computer room is processed to obtain security event identification data. The acquired security monitoring data can be sent to the data processing module. In this module, a series of simple thresholds or rules can be preset. For example, when a drastic change in screen brightness is detected in the video surveillance data, or the temperature value in the environmental sensor data exceeds a fixed upper limit, or multiple consecutive card swipe failures occur in the access control system data, these are marked as potential anomalies. These marked anomalies are then aggregated to form security event identification data.

[0028] Based on this security event identification data, automatic patrol instruction data is generated. Once the security event identification data is generated, the instruction generation module can generate automatic patrol instruction data according to a preset event type and patrol task mapping table. For example, if an environmental anomaly is detected, an instruction is generated requiring the patrol device to proceed to a designated environmental monitoring point; if an access control anomaly is detected, an instruction is generated requiring the patrol device to proceed to the access control area. These instructions can include simple target location information.

[0029] In this embodiment, the automatic inspection command data is then used to control the computer room inspection equipment to perform inspection actions and obtain inspection result data. The automatic inspection command data can be sent to the control unit of the computer room inspection equipment. After receiving the command, the control unit drives the inspection equipment (e.g., a mobile robot equipped with a camera) to move along the path or target point specified in the command. During the inspection process, the inspection equipment can transmit back images or video clips captured by its onboard camera, along with its own position information, as inspection result data.

[0030] Furthermore, based on the security incident identification data and the patrol result data, security alarm data is generated. The security incident identification data and patrol result data can be sent to the alarm generation module. In this module, a simple comparison can be performed. For example, if the security incident identification data indicates an anomaly in a certain area, and the patrol result data fails to find any obvious anomalies in the images captured in that area, a lower-level alarm may be generated; if the patrol result data confirms an anomaly, a higher-level alarm is generated. These alarm information are integrated into the security alarm data.

[0031] In this embodiment, a coordinated response operation is ultimately executed based on the security alarm data. The generated security alarm data can be sent to the response execution module. This module triggers the corresponding coordinated response operation based on the event type contained in the alarm data or preset fixed rules. For example, for all alarms, the system uniformly sends email notifications to a preset list of security personnel and automatically records event logs. For certain specific types of alarms, simple device linkage can also be triggered, such as automatically turning off the lighting in a certain area.

[0032] In this embodiment, the intelligent management method for data center security intelligently integrates and processes multi-source heterogeneous data center security monitoring data, enabling accurate identification of complex security events. This method further combines on-site verification with automated patrol equipment, effectively reducing the false alarm rate and generating security alarm data based on event identification and patrol results, thereby triggering collaborative response operations. Thus, it achieves real-time monitoring, intelligent analysis, automated verification, and rapid response for data center security, significantly improving the accuracy of security event identification, the timeliness of response, and the efficiency of handling, reducing reliance on manual intervention, and meeting the needs of high-level data centers for automated intelligent security.

[0033] In one feasible implementation, the step of processing the data from the computer room security monitoring data to obtain security event identification data includes: extracting a sequence of monitoring image frames from the video surveillance data to obtain video frame sequence data; performing personnel detection on the video frame sequence data to identify personnel location data; performing personnel trajectory analysis based on the personnel location data to obtain personnel behavior trajectory data; comparing the personnel behavior trajectory data with a preset normal behavior pattern database to obtain video anomaly identification data; comparing the environmental sensor data with anomaly thresholds, and obtaining environmental anomaly identification data when the environmental sensor data exceeds a preset threshold; performing abnormal entry and exit identification on the access control system data, and obtaining access control anomaly identification data when unauthorized entry and exit, abnormal time entry and exit, or frequent entry and exit are identified; and combining the video anomaly identification data, environmental anomaly identification data, and access control anomaly identification data to form the security event identification data.

[0034] In this embodiment, a sequence of monitored image frames is extracted from the video surveillance data to obtain video frame sequence data, aiming to transform a continuous video stream into a discrete image sequence that can be processed by a computer. This can be achieved through fixed frame rate sampling, such as extracting 25 or 30 frames per second, to ensure continuous coverage of the video content. Alternatively, keyframe extraction technology can be used to intelligently select representative image frames by analyzing changes in video content (such as scene transitions and motion detection), thereby reducing the amount of data processed subsequently while ensuring information integrity.

[0035] In this embodiment, personnel detection is performed on the video frame sequence data to identify personnel location data. The purpose is to accurately locate and identify personnel targets in the video image. This is typically achieved by applying deep learning models, such as object detection algorithms based on convolutional neural networks (CNNs). These models are trained on a large amount of labeled data and are able to identify the bounding boxes of personnel and their coordinate information in the image, thereby obtaining personnel location data.

[0036] In this embodiment, based on the personnel location data, personnel trajectory analysis is performed to obtain personnel behavior trajectory data. After identifying the personnel location data, it is necessary to associate the same person in different frames to construct their movement path in the time series. This can be achieved through multi-object tracking (MOT) algorithms, such as Kalman filtering combined with the Hungarian algorithm or more advanced deep learning tracking algorithms. Through these algorithms, personnel location data in consecutive frames can be connected to form complete personnel behavior trajectory data, recording the personnel's movement path, dwell points, and time information within the computer room area.

[0037] In this embodiment, the personnel behavior trajectory data is compared with a preset normal behavior pattern database to obtain video anomaly identification data. This step aims to determine whether abnormal behavior exists by analyzing the personnel's movement trajectory. The preset normal behavior pattern database stores behavior patterns that are permitted or considered normal within a specific computer room area, such as the inspection routes of specific personnel and equipment operation areas within a specific time period. The system compares the real-time acquired personnel behavior trajectory data with these preset patterns to identify behaviors that deviate from the normal pattern, such as entering unauthorized areas, prolonged lingering, and abnormal movement speed, thereby generating video anomaly identification data.

[0038] In this embodiment, the environmental sensor data is compared against anomaly thresholds. When the environmental sensor data exceeds a preset threshold, environmental anomaly identification data is obtained. This step is used to monitor whether the environmental parameters of the computer room are within a safe range. Environmental sensor data typically includes temperature, humidity, smoke concentration, water leakage, power supply voltage, etc. The system sets one or more safety thresholds (upper and / or lower limits) for each environmental parameter. When the real-time collected environmental sensor data exceeds these preset thresholds, such as excessively high temperature, excessively low humidity, or excessive smoke concentration, it is determined to be an environmental anomaly, and corresponding environmental anomaly identification data is generated.

[0039] In this embodiment, abnormal entry and exit data is identified from the access control system. When unauthorized entry or exit, entry or exit at abnormal times, or frequent entry and exit are detected, access control anomaly identification data is obtained. This step focuses on analyzing the legality and compliance of personnel entering and exiting the computer room. The access control system data records information such as personnel identity, entry and exit time, and access card number. The system compares this information against a preset authorization list, schedule, and behavioral rules. For example, when unauthorized personnel attempt to swipe their cards, authorized personnel enter or exit outside of working hours, or frequently enter and exit the same area within a short period, these are identified as access control anomalies, and access control anomaly identification data is generated.

[0040] In this embodiment, the security event identification data is formed by integrating the video anomaly identification data, environmental anomaly identification data, and access control anomaly identification data. This step is crucial for the fusion of multi-source heterogeneous data. By integrating and analyzing various anomaly identification data from video surveillance, environmental sensors, and access control systems, the existence of a genuine security event can be determined more comprehensively and accurately. For example, rule engines, expert systems, or machine learning models can be used for comprehensive judgment. When multiple abnormal signals occur simultaneously, or when the severity of a certain abnormal signal reaches a certain level, the system will confirm it as a complete security event and generate the final security event identification data. This comprehensive judgment helps reduce false alarms that may arise from a single data source and improves the ability to identify complex security events.

[0041] In this embodiment, by performing personnel detection and trajectory analysis on video surveillance data and comparing it with normal behavior patterns, abnormal personnel behavior can be effectively identified. Simultaneously, by combining abnormal threshold comparison with environmental sensor data and abnormal entry / exit identification with access control system data, comprehensive monitoring of the computer room's internal environment and personnel entry / exit status is achieved. This deep fusion and comprehensive analysis of multi-source data significantly improves the accuracy and timeliness of security event identification, avoiding misjudgments or missed reports that may occur with a single data source. This provides more reliable event evidence for subsequent automatic patrols and collaborative responses, greatly enhancing the overall efficiency of intelligent security management in the computer room.

[0042] In one feasible implementation, the step of comparing the personnel behavior trajectory data with a preset normal behavior pattern database to obtain video anomaly identification data includes: retrieving allowed behavior pattern data for each computer room from the preset normal behavior pattern database; determining the computer room area where the personnel are located based on the personnel location data to obtain personnel location area data; retrieving allowed behavior pattern data for the corresponding computer room area based on the personnel behavior trajectory data and personnel location area data; calculating the matching degree between the personnel behavior trajectory data and the allowed behavior pattern data for the corresponding computer room area to obtain behavior matching degree data; and generating the video anomaly identification data when the behavior matching degree data is lower than a preset threshold.

[0043] In this embodiment, retrieving permitted behavior pattern data for each computer room from a preset normal behavior pattern database means that the database stores legal behavior patterns defined for different physical or logical areas within the computer room. These patterns may include, but are not limited to, activity patterns within a specific time period, operation sequences of specific devices, permitted movement paths, or areas of stay. The retrieval process typically involves a query operation based on area identifiers to obtain a set of behavior rules related to the currently monitored area.

[0044] In this embodiment, determining the area of ​​the computer room where the personnel are located based on the personnel location data means obtaining the personnel location data in various ways, such as target positioning in video analysis, Wi-Fi / Bluetooth positioning, RFID tag positioning, etc. Determining the area of ​​the computer room where the personnel are located means mapping the personnel's real-time location onto a pre-divided map of the internal areas of the computer room. For example, the computer room can be divided into server areas, power distribution areas, passageways, operating console areas, etc. The system uses a Geographic Information System (GIS) or preset area boundary coordinates to determine the area to which the personnel currently belong.

[0045] In this embodiment, retrieving permitted behavior pattern data for the corresponding computer room area based on the personnel behavior trajectory data and personnel location area data means that after obtaining the complete behavior trajectory data of the personnel and their current or historical computer room area data, the system uses this information as an index to accurately retrieve the permitted behavior patterns applicable to that specific computer room area from a preset normal behavior pattern database. This retrieval is dynamic and context-sensitive, ensuring the accuracy of subsequent comparisons.

[0046] In this embodiment, the matching degree data of the personnel's behavior trajectory is calculated by comparing it with the permitted behavior pattern data of the corresponding computer room area. This results in behavior matching degree data, which quantifies the similarity or conformity between the personnel's actual behavior trajectory and the permitted behavior pattern of the area. This can be achieved using various algorithms, such as comparing the geometric similarity of the trajectory, kinematic characteristics (e.g., velocity, acceleration), dwell time distribution, and access area sequence. The matching degree data is typically represented by a numerical value; a higher value indicates that the behavior conforms more closely to the normal pattern, and vice versa.

[0047] In this embodiment, when the behavior matching data is lower than a preset threshold, the video anomaly identification data is generated. The preset threshold is a configurable parameter used to define the boundary between normal and abnormal behavior. When the calculated behavior matching data is lower than this threshold, it indicates a significant deviation between the personnel's behavior and the normal behavior pattern in the computer room area. At this time, the system will generate video anomaly identification data as a preliminary basis for judging potential security events.

[0048] In this embodiment, through the above technical solution, this application can dynamically retrieve and apply data on permitted behavior patterns specific to the area where personnel are located within the computer room for comparison. This avoids misjudgments that may result from using a single, universal pattern, significantly improving the accuracy and specificity of video anomaly identification. For example, in the server area, prolonged lingering or abnormal operations by personnel will be accurately identified; while in the passageway area, rapid passage is considered normal behavior. This regionalized behavior pattern matching mechanism enables the system to more precisely understand and judge the compliance of personnel behavior, thereby effectively reducing false alarms and promptly identifying real security risks, thus improving the level of intelligence in computer room security management.

[0049] In one feasible implementation, the step of calculating the matching degree between the personnel behavior trajectory data and the permitted behavior pattern data of the corresponding computer room area to obtain behavior matching degree data includes: analyzing the trajectory features of the personnel behavior trajectory data to obtain trajectory feature data, wherein the trajectory features include dwell time features, movement speed features, and direction change features; extracting the normal trajectory feature range corresponding to the computer room area from the permitted behavior pattern data to obtain normal feature range data; comparing the trajectory feature data with the normal feature range data item by item, calculating the conformity of each feature to obtain feature conformity data; and performing a weighted summation of the feature conformity data to obtain the behavior matching degree data.

[0050] In this embodiment, when analyzing the trajectory features of the personnel behavior trajectory data to obtain trajectory feature data, the system extracts key dynamic attributes from the personnel behavior trajectory data and quantifies them into comparable feature data. For example, the dwell time feature can be obtained by calculating the duration of a person's continuous stay in a specific area or near a coordinate point; the movement speed feature can be obtained by calculating the rate of change of a person's position at consecutive time points, for example, by calculating the instantaneous speed by dividing the Euclidean distance between the person's positions in adjacent frames by the frame interval time, and further calculating the average speed, maximum speed, etc.; the direction change feature can be obtained by analyzing the continuous change of the person's movement direction, for example, by calculating the angle between adjacent movement vectors, or by statistically analyzing the frequency and magnitude of direction changes over a period of time. The extraction and quantification of these features can be achieved through various trajectory analysis algorithms.

[0051] In this embodiment, the normal trajectory feature range corresponding to the data center area is then extracted from the permitted behavior pattern data to obtain normal feature range data. Permitted behavior pattern data is typically obtained in advance through expert experience, historical data analysis, or machine learning training. It defines which trajectory features are "normal" within a specific data center area, and their corresponding numerical ranges. For example, for a certain data center area, permitted behavior pattern data might specify "staying in front of the server rack for no more than 5 minutes" or "moving speed within the passageway between 0.5 m / s and 1.5 m / s," etc. These patterns are quantified into specific numerical ranges or distributions, forming normal feature range data, which serves as a benchmark for subsequent comparisons.

[0052] In this embodiment, the trajectory feature data is then compared item by item with the normal feature range data to calculate the conformity of each feature, thus obtaining feature conformity data. For each extracted trajectory feature (such as dwell time, movement speed, and direction change), the system compares its actual value with the corresponding normal feature range. If the actual value falls within the normal range, the conformity of that feature can be set to a high score; if the actual value exceeds the normal range, the conformity can be decreased according to the degree of exceedance, for example, using a Gaussian function, a Sigmoid function, or a linear decreasing function for calculation. In this way, the degree of conformity between the various features of the person's actual behavioral trajectory and the preset normal range is quantified.

[0053] In this embodiment, the final step is to perform a weighted sum of the feature conformity data to obtain the behavior matching score. To comprehensively consider the conformity of all trajectory features, the system assigns different weight coefficients to different trajectory features to reflect their importance in judging abnormal behavior. For example, dwell time may be more critical than movement speed in certain scenarios, and therefore can be given a higher weight. The final behavior matching score is the weighted sum of the conformity data of each feature multiplied by its corresponding weight, resulting in a single matching score that comprehensively reflects the normality of the behavior.

[0054] In this embodiment, the complex personnel behavior trajectory data is decomposed into quantifiable trajectory feature data through the above technical solution, and compared item by item with a preset normal trajectory feature range, thus achieving refined calculation of behavior matching degree. This weighted summation method based on multi-dimensional trajectory features can more accurately capture subtle changes and potential anomalies in personnel behavior, significantly improving the accuracy and robustness of video anomaly recognition. For example, even if a person is in a permitted area, but their stay time is too long or their movement speed is abnormal, it can still be effectively identified, thereby avoiding missed or false alarms that may be caused by simple pattern matching. This enables the intelligent management method for data center security to generate video anomaly recognition data more reliably, thereby improving the overall intelligence level of security event recognition.

[0055] In one feasible implementation, the step of generating security alarm data based on the security event identification data and the patrol result data includes: assessing the severity of the security event identification data to obtain event severity level data; verifying the patrol result data to obtain event confirmation status data; calculating a comprehensive risk score based on the event severity level data and the event confirmation status data to obtain risk score data; and generating the security alarm data based on the risk score data.

[0056] In this embodiment, assessing the severity of security incident identification data to obtain incident severity level data refers to the process of quantifying or classifying the urgency and potential consequences of an incident based on factors such as the nature, potential harm, and scope of impact of the security incident identification data. For example, the system can preset an assessment rule base or use a machine learning model to score or classify different types of security incidents (such as illegal intrusion, equipment failure, environmental anomalies, etc.) according to dimensions such as the potential losses, scope of impact, and duration. The assessment results can be discrete levels, such as "low," "medium," and "high" severity, or continuous values ​​from 0 to 100.

[0057] In this embodiment, verifying the inspection results data to obtain event confirmation status data refers to using inspection results data acquired by computer room inspection equipment (such as inspection robots, fixed cameras, or manual inspections) to verify previously identified security events and determine whether the event actually occurred, whether it has been controlled, or whether it is a false alarm. Inspection results data may include images and videos captured by inspection equipment, environmental sensor readings, and personnel conversation records. The system can use image recognition, video analysis, or data comparison technologies to cross-verify the inspection results with the initial security event identification data, thereby determining the authenticity and current status of the event. For example, the confirmation status can be "confirmed," "excluded," or "pending further verification."

[0058] Based on this, a comprehensive risk score is calculated using event severity level data and event confirmation status data. This risk score data combines the potential harm of an event (reflected by the event severity level data) with the event's authenticity (reflected by the event confirmation status data) for a comprehensive quantitative assessment, resulting in a numerical value that fully reflects the current security risk level. This calculation process can employ various methods such as weighted averaging, fuzzy logic reasoning, or decision trees. For example, different weights can be assigned to the event severity level and confirmation status, and a pre-defined mathematical model can be used for calculation to arrive at a unified risk score.

[0059] In this embodiment, ultimately, generating security alarm data based on risk scoring data means generating a standardized data packet containing information such as alarm level, event description, and suggested response measures based on the comprehensive risk score results. This packet is used to trigger subsequent coordinated response operations. The system can preset the mapping relationship between risk scores and alarm levels. For example, when the risk score exceeds a certain preset threshold, a level one alarm is generated; when the risk score exceeds another higher threshold, a level two alarm is generated. The security alarm data can record in detail the event type, occurrence time, location, risk score, suggested response level, and related evidence links, such as video clips or sensor readings.

[0060] In this embodiment, the above technical solution effectively addresses the problem of insufficient alarm accuracy after security incident identification. By assessing the severity of security incidents and verifying them in conjunction with patrol results, false alarms caused by misjudgments from a single data source can be avoided, significantly improving alarm accuracy. The introduction of comprehensive risk scoring allows alarm levels to more precisely reflect the true threat level and urgency of the incident, ensuring that only truly relevant events trigger corresponding responses, avoiding resource waste and unnecessary interference. This not only improves the reliability and efficiency of the intelligent security management method for data centers but also provides a more accurate and reliable decision-making basis for subsequent collaborative response operations, enabling the entire security management system to operate more intelligently and efficiently.

[0061] In one feasible implementation, the step of calculating a comprehensive risk score based on the event severity level data and event confirmation status data to obtain risk score data includes: assigning weight coefficients to the event severity level data to obtain severity weight data; assigning confidence coefficients to the event confirmation status data to obtain confirmation confidence data; calculating a time urgency coefficient based on the event occurrence time in the security event identification data to obtain time urgency data; and performing multi-factor weighted calculation based on the severity weight data, confirmation confidence data, and time urgency data to obtain the risk score data.

[0062] In this embodiment, weighting coefficients are assigned to event severity level data to obtain severity weight data, aiming to more precisely quantify the relative importance of different severity levels in comprehensive risk assessment. Event severity level data is typically a classification or numerical assessment of the potential harm of identified security events. By assigning weighting coefficients, for example, setting the weighting coefficient for high-severity events to be much higher than that for low-severity events, it can be ensured that events with greater harm receive higher attention in risk scoring. These weighting coefficients can be preset based on factors such as the value of key assets in the data center, business interruption risk, and compliance requirements, or they can be dynamically adjusted and optimized through historical event data analysis or expert experience to adapt to constantly changing security needs.

[0063] In this embodiment, a confidence coefficient is assigned to the event confirmation status data to obtain confirmation confidence data, in order to reflect the reliability differences of different confirmation sources or confirmation methods. Event confirmation status data indicates the degree to which a security event has been verified, for example, confirmation through the inspection results data after the data is processed by a data center inspection device, or confirmation through manual review. Since different confirmation mechanisms may have different accuracy and reliability, a confidence coefficient is introduced to quantify this reliability. For example, an event confirmed simultaneously by multiple independent inspection devices or by humans can have a higher confidence coefficient; while an event triggered by only a single sensor and not verified by other methods may have a lower confidence coefficient. The confidence coefficient can be set based on factors such as the historical accuracy of the confirmation source, the inherent characteristics of the confirmation method, and the completeness of the confirmation information.

[0064] Furthermore, calculating the time urgency coefficient based on the event occurrence time in security incident identification data is crucial for capturing the changing risk characteristics of events over time. For certain security incidents, such as equipment overheating or abnormal intrusion, the risk escalates rapidly over time, requiring immediate response. The time urgency coefficient can be calculated using various models; for example, the more recent the event, the higher the urgency coefficient, which decays exponentially over time. Different urgency decay curves can also be set according to the event type; for example, the urgency decay rate is faster for fire-related events. Additionally, the specific time period of the event can be considered; for example, events occurring outside of working hours or at night may have a higher time urgency coefficient due to potentially scarcer response resources.

[0065] In this embodiment, the risk score data is ultimately obtained by performing a multi-factor weighted calculation based on the severity weight data, confidence level data, and time urgency data. This multi-factor weighted calculation is a comprehensive assessment method. By multiplying the three key influencing factors by their respective weights or coefficients and then summing them or combining them through other mathematical models, a unified risk score data that comprehensively reflects the overall risk level of the event can be obtained. For example, linear weighted summation models, nonlinear models, or fuzzy logic reasoning can be used to adapt to more complex risk assessment scenarios.

[0066] In this embodiment, the above-described technical solution, when calculating the comprehensive risk score, not only considers the severity level and confirmation status of the event, but also introduces severity weight data, confirmation confidence data, and time urgency data for multi-factor weighted calculation. This allows the risk score data to more comprehensively and dynamically reflect the true risk level and response urgency of security events. Specifically, by assigning weights to different severity levels, the importance of high-risk events can be highlighted; by introducing confirmation confidence, events with different confirmation reliability can be effectively distinguished, avoiding resource waste or insufficient response due to false alarms or missed alarms; and the introduction of a time urgency coefficient ensures priority response to time-sensitive events. This comprehensive risk assessment mechanism can significantly improve the accuracy and timeliness of security alarms, thereby optimizing the allocation of data center security resources, ensuring that critical events are handled most appropriately and quickly, and effectively reducing data center operational risks.

[0067] In one feasible implementation, the step of obtaining the risk score data by performing multi-factor weighted calculation based on the severity weight data, confirmation confidence data, and time urgency data includes: establishing a risk score calculation formula model, the formula model including a severity factor, a confirmation factor, and a time factor; substituting the severity weight data into the severity factor to obtain a severity score component; substituting the confirmation confidence data into the confirmation factor to obtain a confirmation score component; substituting the time urgency data into the time factor to obtain a time score component; and performing a weighted summation calculation based on the severity score component, the confirmation score component, and the time score component to obtain the risk score data.

[0068] In this embodiment, the risk scoring calculation formula model aims to provide a clear and quantitative mathematical framework for risk assessment of data center security incidents. This model is the core structure for comprehensively considering multiple risk influencing factors. It abstracts key dimensions such as the inherent severity of the event, the reliability of event confirmation, and the urgency of event handling into severity factors, confirmation factors, and time factors, respectively. These factors, as the basic components of the model, each contribute differently to the risk. For example, the model can be a linear weighted model or a more complex nonlinear model; its core lies in defining how the factors interact and affect the final risk score. By establishing such a model, the standardization and repeatability of the risk assessment process can be ensured.

[0069] In this embodiment, the severity weight data is then substituted into the severity factor to obtain the severity score component. This step maps the severity weight data of the event, i.e., the quantitative assessment of the potential harm of the event, to the severity factor in the risk scoring formula model. The severity weight data can be pre-set to different values ​​or levels according to the event type, the potential losses or impacts, etc. By substituting it into the severity factor, the abstract concept of severity is transformed into a calculable value in the model, thereby forming the severity score component. This component directly reflects the inherent risk level of the event itself and is a fundamental component of risk assessment.

[0070] In this embodiment, the confirmation confidence data is simultaneously substituted into the confirmation factor to obtain the confirmation score component. This step maps the confirmation confidence data of the event, i.e., the assessment of the event's authenticity or reliability, to the confirmation factor in the risk scoring calculation formula model. The confirmation confidence data typically originates from the verification of security event identification data by patrol result data, reflecting the degree to which the event has been verified. By substituting it into the confirmation factor, the confirmation confidence is converted into a calculable value in the model, thereby forming the confirmation score component. This component helps reduce the risk of false alarms, ensuring that only events that have undergone a certain degree of confirmation are assigned the corresponding risk weight.

[0071] Furthermore, the time urgency data is substituted into the time factor to obtain the time score component. This step maps the event's time urgency data, i.e., the degree of urgency requiring a response and handling, to the time factor in the risk scoring calculation formula model. The time urgency data can be dynamically calculated based on the event's occurrence time, the event type's preset response time limit, etc. By substituting it into the time factor, the time dimension is transformed into a calculable value in the model, thus forming the time score component. This component ensures that events with high timeliness requirements receive higher risk attention, prompting the system to prioritize handling urgent situations.

[0072] In this embodiment, the risk score data is finally obtained by performing a weighted summation calculation based on the severity score component, confirmation score component, and time score component. This step is the core of the comprehensive assessment. It involves weighting and summing the previously obtained severity score component, confirmation score component, and time score component using preset weighting coefficients. Each score component is multiplied by its corresponding weight to reflect its relative importance in the overall risk assessment. Through weighted summation calculation, a comprehensive risk score data is finally obtained, which can comprehensively and quantitatively reflect the overall risk level of the current security incident.

[0073] In this embodiment, through the above-described technical solution, this application provides a structured and systematic risk scoring calculation method. By establishing a clear risk scoring calculation formula model and decomposing it into severity factors, confirmation factors, and time factors, the risk assessment process for data center security incidents becomes more transparent and controllable. Substituting various quantitative data into the corresponding factors and performing weighted summation ensures that key dimensions such as the inherent hazard of the incident, verification status, and time urgency are fully and reasonably considered. This not only improves the accuracy and reliability of risk scoring and effectively avoids subjective judgment or experience bias, but also makes the risk assessment results more interpretable, facilitating understanding and decision-making by management personnel. Ultimately, this accurate risk scoring data provides a solid, quantitative basis for subsequent security alarm data generation and collaborative response operations, thereby significantly improving the efficiency and effectiveness of intelligent data center security management.

[0074] In one feasible implementation, the steps of performing a coordinated response operation based on the security alarm data include: parsing the security alarm data to obtain the corresponding alarm level, and determining the response priority based on the alarm level to obtain response priority data; selecting a corresponding response strategy combination based on the response priority data to obtain response strategy data, and generating device control command data based on the response strategy data; and performing a coordinated response operation based on the device control command data.

[0075] In this embodiment, security alarm data typically includes information such as event type, occurrence time, affected area, and risk score assessed by the system. This step aims to perform in-depth analysis of this raw alarm data to extract or calculate the event's "alarm level." The alarm level is a quantitative assessment of the severity and urgency of the event, and can be categorized into multiple levels such as "general warning," "moderate risk," and "high alert." Based on these alarm levels, the system further determines a "response priority," which directly indicates the execution order of subsequent response actions, the urgency of resource allocation, and the scope of notification to relevant personnel. For example, alarms involving equipment malfunctions may have a lower priority, while alarms involving illegal intrusion or fire have the highest priority.

[0076] In this embodiment, once the response priority is determined, the system will intelligently select one or more "response strategy combinations" from a preset strategy library based on that priority. Each strategy combination predefines a series of response measures for specific priority events. These measures may include notifying relevant personnel, starting or stopping specific equipment, adjusting environmental parameters, or activating machine room patrol equipment. These abstract response strategies are then transformed into specific "equipment control command data." These commands are standardized commands or API calls that can be directly recognized and executed by various intelligent devices in the machine room (such as surveillance cameras, access control systems, fire-fighting equipment, air conditioning systems, etc.).

[0077] In this embodiment, coordinated response means that the system will coordinate multiple data center devices and systems to execute their respective actions simultaneously or sequentially according to predetermined logic. This ensures that when a security incident occurs, all necessary resources can be mobilized quickly and comprehensively for a coordinated response. For example, when a fire is detected, not only will the fire protection system be triggered, but the power to the relevant areas will also be shut off, access control will be locked, and an emergency notification will be sent to on-duty personnel, thus forming an efficient and integrated security response closed loop.

[0078] In this embodiment, through the above technical solution, this application can perform refined analysis of received security alarm data and dynamically determine response priorities based on alarm levels, thereby avoiding a one-size-fits-all approach to all alarm events. Based on different response priorities, the system can intelligently select the most suitable combination of response strategies and generate precise device control command data, ensuring the pertinence and effectiveness of response measures. This collaborative response operation not only improves the efficiency and accuracy of security incident handling and avoids resource waste, but also enables rapid mobilization of relevant resources based on the severity and urgency of the incident, achieving linkage between multiple devices and systems, thereby significantly improving the overall security response capability and risk management level of the data center, and effectively protecting the security of data center equipment and data.

[0079] In one feasible implementation, the steps of performing a coordinated response operation based on the device control command data include: establishing a response execution queue based on the device control command data, assigning an execution sequence number to each response operation to obtain response execution sequence data; executing notification operations and device control operations sequentially based on the response execution sequence data to obtain response operation execution data; monitoring the execution status of each response operation based on the response operation execution data to obtain execution status monitoring data; and when an execution failure is detected based on the execution status monitoring data, activating a backup response scheme and updating the response operation execution data based on the execution result of the backup response scheme.

[0080] In this embodiment, upon receiving device control command data, the system does not immediately execute all commands in a random order. Instead, it first performs structured processing on these commands. The system adds each response operation contained in the device control command data to a preset response execution queue. To ensure that operations are performed according to the expected logical order or priority, the system assigns a unique execution sequence number to each response operation in the queue. This execution sequence number can be determined based on the operation's type, importance, dependencies, or a preset execution flow. In this way, the system can generate a clear and ordered response execution sequence data, providing clear guidance for subsequent automated execution.

[0081] In this embodiment, after obtaining the response execution sequence data, the system will strictly follow the defined execution sequence numbers to initiate each notification operation and device control operation one by one. Notification operations may include sending SMS messages, emails, app push notifications, or voice alarms to relevant personnel to inform them of the occurrence and current status of a security incident. Device control operations involve sending control commands to specific security devices to enable or disable them, adjust parameters, or execute specific functions. After each operation is completed, the system records the execution result, execution time, target device status, and other information, and summarizes this information to form response operation execution data for subsequent status monitoring and result evaluation.

[0082] In this embodiment, to ensure the effectiveness and integrity of the collaborative response operations, the system continuously monitors each initiated response operation in real time while executing various operations. This monitoring includes, but is not limited to, checking whether the command was successfully sent, whether the target device received and executed the command, whether the device's post-execution status meets expectations, and whether any errors or anomalies occurred. All these monitored status information, including success, failure, timeout, and anomalies, will be collected and integrated to form execution status monitoring data, providing a basis for subsequent fault diagnosis and handling.

[0083] In this embodiment, during the continuous monitoring of the response operation execution status, if the execution status monitoring data indicates that one or more response operations have failed to execute successfully, the system will immediately identify the failure. For the identified failed operations, the system will automatically activate the corresponding backup response plan according to a preset strategy. The backup response plan can be an alternative operation for a specific fault, or it can be escalating the alarm level, notifying a higher-level manager, or attempting to resend the command through a different channel. After the backup response plan is executed, its results will be used to update the original response operation execution data, ensuring the integrity and reliability of the entire security response process.

[0084] In this embodiment, through the above technical solution, this application can effectively cope with possible execution failures when performing collaborative response operations, significantly improving the robustness and reliability of the intelligent security management system for the data center. First, by establishing a response execution queue and assigning execution sequence numbers, it ensures that various notification operations and equipment control operations are executed in an orderly manner according to predetermined logic and priority, avoiding conflicts or omissions that may occur due to concurrent execution. Second, real-time monitoring of the execution status of each response operation enables the system to promptly detect and identify any execution failures, thereby avoiding the risk that security incidents may not be effectively controlled due to partial response failures. More importantly, when an execution failure is detected, the system can automatically activate a backup response plan and update the response operation execution data based on the execution results of the backup plan. This greatly enhances the system's fault tolerance and self-healing capabilities. Even when critical equipment or channels malfunction, the system can quickly switch to alternative solutions, ensuring the continuity and effectiveness of security responses, thereby minimizing potential losses from security incidents and ensuring the continuous safe and stable operation of the data center environment.

[0085] In the embodiments of this application, the intelligent management method for data center security acquires multi-source security monitoring data, intelligently processes and generates event identification data, and automatically executes inspection and response operations. This solves the problems of data silos and response delays in the prior art, and can improve the real-time performance, accuracy and efficiency of data center security, while reducing false alarms and response delays.

[0086] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the intelligent management method for computer room security in this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0087] This application also provides a data center security intelligent management system, see reference. Figure 2 The intelligent security management system for the computer room includes: a memory 10, a processor 20, and an intelligent security management program for the computer room stored on the memory 10 and capable of running on the processor 20. The intelligent security management program for the computer room is configured to implement the steps of the intelligent security management method for the computer room.

[0088] The intelligent data center security management system provided in this application, employing the intelligent data center security management method described in the above embodiments, can improve the real-time performance, accuracy, and efficiency of data center security, while reducing false alarms and response delays. Compared with the prior art, the beneficial effects of the intelligent data center security management system provided in this application are the same as those of the intelligent data center security management method provided in the above embodiments, and other technical features in the intelligent data center security management system are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0089] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0090] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any equivalent structural transformations made under the technical concept of this application using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included within the scope of patent protection of this application.

Claims

1. A method for intelligent security management of a computer room, characterized in that, The method includes: Acquire data on security monitoring in the computer room, including video surveillance data, environmental sensor data, and access control system data; The data from the computer room security monitoring is processed to obtain security event identification data; Based on the security event identification data, automatic patrol instruction data is generated; Based on the automatic inspection command data, the computer room inspection equipment is controlled to perform inspection actions to obtain inspection result data; Based on the security event identification data and the patrol result data, security alarm data is generated; Based on the security alarm data, execute a coordinated response operation.

2. The intelligent management method for computer room security as described in claim 1, characterized in that, The steps for processing the data from the computer room security monitoring data to obtain security event identification data include: The video frame sequence data is obtained by extracting the monitoring image frame sequence from the video surveillance data. Personnel detection is performed on the video frame sequence data to identify personnel location data; Based on the personnel location data, personnel trajectory analysis is performed to obtain personnel behavior trajectory data; The personnel behavior trajectory data is compared with a preset normal behavior pattern database to obtain video anomaly identification data; The environmental sensor data is compared with an anomaly threshold. When the environmental sensor data exceeds a preset threshold, environmental anomaly identification data is obtained. The access control system data is used to identify abnormal entry and exit. When unauthorized entry and exit, entry and exit at abnormal times, or frequent entry and exit are detected, access control abnormal identification data is obtained. The security event identification data is formed by combining the video anomaly identification data, environmental anomaly identification data, and access control anomaly identification data.

3. The intelligent management method for computer room security as described in claim 2, characterized in that, The steps of comparing the personnel behavior trajectory data with a preset normal behavior pattern database to obtain video anomaly identification data include: Retrieve the allowed behavior pattern data for each computer room from the preset normal behavior pattern database; Based on the personnel location data, the area of ​​the computer room where the personnel are located is determined, and the personnel location area data is obtained; Based on the personnel behavior trajectory data and personnel location area data, retrieve the permitted behavior pattern data for the corresponding computer room area; The matching degree of the personnel behavior trajectory data is calculated by matching it with the allowed behavior pattern data of the corresponding computer room area to obtain behavior matching degree data. When the behavior matching data is lower than a preset threshold, the video anomaly identification data is generated.

4. The intelligent management method for computer room security as described in claim 3, characterized in that, The steps for calculating the matching degree data of the personnel behavior trajectory data and the allowed behavior pattern data of the corresponding computer room area include: Analyze the trajectory features of the personnel behavior trajectory data to obtain trajectory feature data, which includes dwell time features, movement speed features, and direction change features; Extract the normal trajectory feature range corresponding to the computer room area from the permitted behavior pattern data to obtain normal feature range data; The trajectory feature data is compared item by item with the normal feature range data, and the conformity of each feature is calculated to obtain feature conformity data. The behavior matching degree data is obtained by weighted summation of the feature matching degree data for each item.

5. The intelligent management method for computer room security as described in claim 1, characterized in that, The steps for generating security alarm data based on the security event identification data and the patrol result data include: The security event identification data is used to assess the severity of the event, resulting in event severity level data. The inspection result data is verified to obtain event confirmation status data; Based on the event severity level data and event confirmation status data, a comprehensive risk score is calculated to obtain risk score data; The security alarm data is generated based on the risk score data.

6. The intelligent management method for computer room security as described in claim 5, characterized in that, The steps for calculating a comprehensive risk score based on the event severity level data and event confirmation status data include: Assign weight coefficients to the event severity level data to obtain severity weight data; Assign confidence coefficients to the event confirmation status data to obtain confirmation confidence data; Based on the event occurrence time in the security event identification data, the time urgency coefficient is calculated to obtain the time urgency data; Based on the severity weight data, confirmation confidence data, and time urgency data, a multi-factor weighted calculation is performed to obtain the risk score data.

7. The intelligent management method for computer room security as described in claim 6, characterized in that, The steps for obtaining the risk score data by performing multi-factor weighted calculation based on the severity weight data, confirmation confidence data, and time urgency data include: A risk scoring calculation formula model is established, which includes a severity factor, a confirmation factor, and a time factor; Substitute the severity weight data into the severity factor to obtain the severity score components; Substitute the confirmation confidence data into the confirmation factor to obtain the confirmation score components; Substitute the time urgency data into the time factor to obtain the time score component; The risk score data is obtained by performing a weighted summation based on the severity score component, the confirmation score component, and the time score component.

8. The intelligent management method for computer room security as described in claim 1, characterized in that, The steps for performing a coordinated response operation based on the security alarm data include: The security alarm data is analyzed to obtain the corresponding alarm level, and the response priority is determined according to the alarm level to obtain response priority data; Based on the response priority data, the corresponding response strategy combination is selected to obtain response strategy data, and based on the response strategy data, device control command data is generated. Based on the device control command data, a coordinated response operation is executed.

9. The intelligent management method for computer room security as described in claim 8, characterized in that, The steps for performing a coordinated response operation based on the device control command data include: Based on the device control command data, a response execution queue is established, and an execution sequence number is assigned to each response operation to obtain response execution sequence data; Based on the response execution sequence data, notification operations and device control operations are executed sequentially to obtain response operation execution data; Based on the execution data of the response operations, the execution status of each response operation is monitored to obtain execution status monitoring data; When an execution failure is detected based on the execution status monitoring data, a backup response plan is initiated, and the response operation execution data is updated based on the execution result of the backup response plan.

10. A smart security management system for computer rooms, characterized in that, The intelligent data center security management system includes: a memory, a processor, and an intelligent data center security management program stored in the memory and executable on the processor. The intelligent data center security management program is configured to implement the steps of the intelligent data center security management method as described in any one of claims 1 to 9.