An electronic data-based security inspection system and method

By combining multi-source heterogeneous terminal devices with deep residual adversarial generative networks and blockchain consensus models, the shortcomings of traditional electronic data security inspection methods in large-scale data processing and dynamic security strategy adaptability are solved, achieving efficient and accurate security inspection.

CN122160334APending Publication Date: 2026-06-05ZHEJIANG HULUWA NETWORK GRP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG HULUWA NETWORK GRP CO LTD
Filing Date
2026-03-17
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Traditional electronic data security inspection methods struggle to handle large-scale data when faced with complex and ever-changing security threats. They suffer from limited feature extraction capabilities and static security strategies that cannot adapt to dynamic changes, leading to difficulties in data integration, inaccurate security status assessments, and an inability to respond promptly to new types of attacks.

Method used

Data collection and segmentation are performed using multi-source heterogeneous terminal devices and a sliding window mechanism. Multi-dimensional feature encoding is carried out using deep residual adversarial generative networks. Distributed verification is performed by combining a blockchain consensus model and smart contracts. An adaptive security strategy optimization model is constructed and the optimal rules are solved by a mixed integer dynamic programming algorithm. Finally, security verification instructions are executed by hierarchical nodes.

Benefits of technology

It achieves efficient and flexible data acquisition and feature extraction, generates reliable verification results, adaptively adjusts security strategies, improves the efficiency and accuracy of security inspection of complex and ever-changing electronic data, and adapts to dynamic security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122160334A_ABST
    Figure CN122160334A_ABST
Patent Text Reader

Abstract

The application provides a kind of security inspection system and inspection method based on electronic data, it is related to electronic data security technical field;The application realizes efficient and flexible data acquisition and real-time segmentation by multi-source heterogeneous terminal equipment and sliding window mechanism;Utilize deep residual adversarial generative network to accurately extract and encode data features from multiple dimensions, generate fusion feature vectors;With the help of blockchain consensus model and smart contract, multi-node distributed verification is carried out, which ensures that the verification result is reliable and tamper-proof;An adaptive security policy optimization model is constructed with the dual objectives of maximizing risk suppression rate and minimizing verification delay, and a mixed integer dynamic programming algorithm is used to solve the optimal rules, achieving intelligent and efficient security inspection;Finally, through hierarchical node distributed execution of security inspection instructions, tasks are reasonably allocated, execution efficiency and flexibility are improved, and the complex and variable electronic data security inspection scene is comprehensively adapted, which is conducive to data security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic data security technology, and in particular to a security inspection system and method based on electronic data. Background Technology

[0002] Electronic data is widely used in various fields such as financial transactions, healthcare, government services, and social entertainment. Traditional electronic data security verification methods are gradually revealing many limitations in the face of complex and ever-changing security threats, making it difficult to meet current high requirements for data security. Specifically: Electronic data comes from a wide range of sources, including various electronic devices, internet service providers, and social media platforms. These sources exhibit diverse data formats, such as network packets, system logs, file operation records, and user behavior sequences, making data integration and retrieval difficult. For example, during the collection of electronic data in a case, the data may be scattered across multiple devices and systems with inconsistent formats, making data integration time-consuming, labor-intensive, and inefficient. With the advent of the big data era, the scale of electronic data continues to grow, and traditional data processing methods struggle to handle such massive volumes. In the data collection and initial processing stages, excessive data volume can lead to low processing efficiency and compromised accuracy. For instance, when conducting security checks on large-scale network traffic data, traditional processing methods may fail to process all data in a timely manner, thus overlooking potential security threats.

[0003] Traditional methods often suffer from limitations in feature extraction, offering only a narrow perspective on electronic data and failing to capture its full and accurate characteristics. For instance, when conducting security checks on electronic data, they may focus solely on statistical features while neglecting temporal and spatial characteristics, leading to inaccurate assessments of the data's security status. Traditional algorithms struggle to learn deeper features and patterns when dealing with complex data. They may also be unable to effectively identify potential security threats hidden within electronic data. For example, in detecting cyberattacks, traditional rule-matching methods are ill-equipped to handle new and evolving attack methods, as these attacks may possess complex characteristics and patterns exceeding the scope of traditional rules. Furthermore, traditional security strategies are typically static, making dynamic adjustments difficult once formulated. However, electronic data security threats are constantly changing and evolving, rendering static security strategies inadequate for addressing new security challenges.

[0004] Therefore, it is necessary to provide a security inspection system and method based on electronic data to solve the above-mentioned technical problems. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention provides a security inspection system and method based on electronic data to solve the problems of data processing difficulties, limited feature extraction, and static security strategies that are difficult to adapt to dynamic changes in the prior art.

[0006] This invention provides a security inspection method based on electronic data, comprising the following steps: S1. Collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and use a sliding window mechanism to segment the data in real time to obtain segmented data information streams; S2. Multi-dimensional feature encoding is performed on the segmented data information stream through a deep residual adversarial generative network to generate a fused feature vector. S3. Input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results; S4. Based on the verification results, construct an adaptive security policy optimization model. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as the dual objective functions, and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rule. S5. The optimal security inspection rules are output through the adaptive security strategy optimization model, security inspection instructions are generated, and the security inspection instructions are executed in a distributed manner through hierarchical nodes.

[0007] Preferably, the specific steps of step S1 are as follows: S101. Collect the raw information stream of electronic data through multi-source heterogeneous terminal devices deployed in different network areas, wherein the raw information stream includes network packets, system logs, file operation records, and user behavior sequence data; S102. A sliding window mechanism is used to dynamically segment the original information stream. Specifically, a window of a fixed size is set and slides on the original information stream according to a preset time interval or data volume. Each time the window slides, the data in the window is taken as a segment to divide the continuous original information stream into multiple segmented data information streams and obtain segmented data information streams.

[0008] Preferably, the specific steps of step S2 are as follows: The obtained segmented data information stream is input into a pre-trained deep residual adversarial generative network (DGNN) to extract and encode features from multiple dimensions to generate a fused feature vector. The DGNN consists of a deep residual network and an adversarial generative network (ADN) and is used to perform nonlinear transformations on the input segmented data information stream. The multiple dimensions include statistical features, temporal features, or spatial features.

[0009] Preferably, the training process of the deep residual adversarial generative network is as follows: historical electronic data is acquired and a labeled segmented dataset is constructed based on the historical electronic data. The segmented dataset specifically includes a normal dataset and an abnormal dataset. Then, the normal dataset is used as the training set and input into the deep residual network as the feature encoder. Adversarial training is performed through the adversarial generative network to obtain the deep residual adversarial generative network.

[0010] Preferably, the specific steps of step S3 are as follows: The generated fused feature vector is input into a pre-trained blockchain consensus model. In the blockchain consensus model, smart contracts automatically trigger each node to independently verify and calculate the input fused feature vector. The blockchain consensus mechanism is used to ensure that all nodes agree on the verification result. After verification, the final verification result is generated, which includes timestamp and hash fingerprint information. The blockchain consensus model is the mechanism in the blockchain network that ensures that all nodes agree on the transaction order and ledger state.

[0011] Preferably, the dual objective function calculation formula in step S4 is: risk suppression rate maximization maxR = total high-risk data volume / successfully intercepted high-risk data volume, verification delay minimization minD = ∑(average verification time for each type of data); the calculation formula of the mixed integer dynamic programming algorithm is: max(α·R-β·D).

[0012] Preferably, the specific steps of step S5 are as follows: S501. The optimal security inspection rule is output through the adaptive security policy optimization model, and the optimal security inspection rule is transformed into a security inspection instruction for computer execution. S502. The converted security inspection command is sent to each preset hierarchical node, and each hierarchical node executes the corresponding security inspection command; wherein, the hierarchical nodes include high-level nodes, medium-level nodes and low-level nodes.

[0013] A security inspection system based on electronic data, wherein the inspection system: The data acquisition module is used to collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and to perform real-time data segmentation using a sliding window mechanism to obtain segmented data information streams; The feature processing module is used to encode multi-dimensional features of segmented data information streams through a deep residual adversarial generative network to generate fused feature vectors. The distributed verification module is used to input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results. The model building module is used to build an adaptive security policy optimization model based on the verification results. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as dual objective functions and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rules. The security detection module is used to optimize the model through adaptive security strategy, output the optimal security inspection rules, generate security inspection instructions, and perform distributed execution of the security inspection instructions through hierarchical nodes.

[0014] Compared with related technologies, the security inspection system and method based on electronic data provided by this invention have the following beneficial effects: This invention achieves efficient and flexible data acquisition and real-time segmentation through multi-source heterogeneous terminal devices and a sliding window mechanism; it utilizes a deep residual adversarial generative network to accurately extract and encode data features from multiple dimensions, generating a fused feature vector; it leverages a blockchain consensus model and smart contracts to conduct multi-node distributed verification, ensuring the credibility and immutability of verification results; it constructs an adaptive security strategy optimization model with the dual objectives of maximizing risk suppression rate and minimizing verification latency, and uses a mixed-integer dynamic programming algorithm to solve for the optimal rules, achieving intelligent and efficient security verification; finally, it executes security verification instructions through hierarchical node distributed execution, rationally allocating tasks, improving execution efficiency and flexibility, and comprehensively adapting to complex and ever-changing electronic data security verification scenarios, thus contributing to data security protection. Attached Figure Description

[0015] Figure 1 This is a flowchart of a security inspection method based on electronic data according to the present invention; Figure 2 This is a system block diagram of a security inspection system based on electronic data according to the present invention. Detailed Implementation

[0016] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0017] Example 1 like Figure 1 As shown, a security inspection method based on electronic data includes the following steps: S1. Collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and use a sliding window mechanism to segment the data in real time to obtain segmented data information streams; S2. Multi-dimensional feature encoding is performed on the segmented data information stream through a deep residual adversarial generative network to generate a fused feature vector. S3. Input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results; S4. Based on the verification results, construct an adaptive security policy optimization model. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as the dual objective functions, and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rule. S5. The optimal security inspection rules are output through the adaptive security strategy optimization model, security inspection instructions are generated, and the security inspection instructions are executed in a distributed manner through hierarchical nodes.

[0018] In the specific implementation process, the specific steps of step S1 are as follows: S101. Collect raw information streams of electronic data through multi-source heterogeneous terminal devices deployed in different network areas, wherein the raw information streams include network packets, system logs, file operation records, and user behavior sequence data.

[0019] Specifically, various types of terminal devices are deployed in different network areas, each with different functions and data acquisition capabilities. For example, in an enterprise network, network traffic acquisition devices can be deployed at the core switch to collect network packets; log collection tools can be installed on the server to obtain system logs; and monitoring software can be deployed on user terminal devices to record file operation records and user behavior sequence data. Each terminal device collects the corresponding raw electronic data stream in real time according to its own acquisition mechanism and frequency. Specifically, the network traffic acquisition device continuously captures data packets in the network, forming a network packet stream; the log collection tool periodically reads the server's log files to generate a system log stream; and the monitoring software records users' file operation behaviors and operation sequences on the terminal devices in real time, forming a file operation record stream and a user behavior sequence data stream.

[0020] S102. A sliding window mechanism is used to dynamically segment the original information stream. Specifically, a window of a fixed size is set and slides on the original information stream according to a preset time interval or data volume. Each time the window slides, the data in the window is taken as a segment to divide the continuous original information stream into multiple segmented data information streams and obtain segmented data information streams.

[0021] Specifically, in this embodiment, for network packet streams, if network traffic is large and changes frequently, the window size is set to contain 1000 data packets; for system log streams, the window size is set to contain 100 log records. Simultaneously, a preset time interval or data volume is set as the trigger condition for window sliding. For example, for time-sensitive data, the window can be set to slide every 5 seconds; for data volume-driven data, the window can be set to slide when the data volume within the window reaches 80% of the set size. The sliding operation is performed on the original information stream according to the set sliding window mechanism. Each time the window slides, the data within the window is treated as a segment. For example, in the network packet stream, initially the window covers from the 1st data packet to the 1000th data packet, and these 1000 data packets are treated as a segment; after 5 seconds, the window slides, at which point it covers from the 1001st data packet to the 2000th data packet, and these new 1000 data packets are treated as the next segment. In this way, the continuous raw information stream is divided into multiple segmented data streams. Similarly, a similar sliding window mechanism is used to segment the system log stream, file operation record stream, and user behavior sequence data stream.

[0022] In the specific implementation process, the specific steps of step S2 are as follows: The obtained segmented data information stream is input into a pre-trained deep residual adversarial generative network (DGNN) to extract and encode features from multiple dimensions to generate a fused feature vector. The DGNN consists of a deep residual network and an adversarial generative network (ADN) and is used to perform nonlinear transformations on the input segmented data information stream. The multiple dimensions include statistical features, temporal features, or spatial features.

[0023] Specifically, the training process of a deep residual generative adversarial network (GAN) includes the following steps: constructing a labeled segmented dataset based on historical electronic data, specifically including normal and abnormal datasets; inputting the normal dataset as the training set into a deep residual network acting as a feature encoder; and performing adversarial training through a generative adversarial network to obtain the deep residual GAN. The deep residual GAN ​​consists of a deep residual network and a generative adversarial network. The deep residual network can effectively perform nonlinear transformations on the input segmented data stream, extracting more representative and discriminative features. Statistical feature extraction specifically includes: for the input segmented data flow, the deep residual network calculates various statistical features. For example, for network packet segmented data, it can calculate statistics such as the number of data packets of different protocol types, average data packet size, and data packet arrival frequency within each time window; for system log segmented data, it can count the occurrence frequency of different types of events such as error events, warning events, and information events, and the distribution of time intervals between events; for file operation record segmented data, it can calculate the proportion of different file operation types, the mean and variance of operation times, etc.; for user behavior sequence data segmentation, it can count the transition probability between different behaviors and the length distribution of behavior sequences. Temporal feature extraction specifically includes: for network packets, analyzing the time sequence patterns of data packet arrivals to identify periodic, trend, or sudden changes; for system logs, identifying the time sequence of events and analyzing the temporal correlations between events. Spatial feature extraction specifically includes: for data with spatial structure, such as network packets related to network topology, spatial relationships can be reflected by analyzing the distribution of source IPs and destination IPs. The extracted statistical features, temporal features, and spatial features are fused together, and the encoding layer of a deep residual network maps these different types of features into a low-dimensional space to generate a fused feature vector.

[0024] In this embodiment, after processing in step S1, different types of segmented data information streams are obtained, including: network packet segmented data, system log segmented data, file operation record segmented data, and user behavior sequence data segments. Statistical features are extracted as follows: For network packet segmented data, the average size of HTTP request packets within the time window is calculated to be 2KB, the number of GET requests is 100, and the number of POST requests is 20; for system log segmented data, 5 error events, 10 warning events, and 50 information events are recorded; for file operation record segmented data, 15 image upload operations and 8 order file modification operations are calculated; for user behavior sequence data segments, the probability of transitioning from browsing products to adding them to the shopping cart is 0.6, and the probability of transitioning from adding products to the shopping cart to checkout is 0.8. Temporal Feature Extraction: Network packet segmentation data shows that the arrival frequency of HTTP request packets increases significantly during the periods of 10:00-12:00 and 20:00-22:00 daily, exhibiting periodic peaks. System log segmentation data indicates that user login events are typically more frequent between 9:00-23:00 daily, with a relatively higher number of users logging in at the top of the hour. File operation record segmentation data reveals that image upload operations are concentrated between 10:00 AM and 4:00 PM on weekdays, while order file modification operations occur frequently within one hour of order creation. User behavior sequence data segmentation shows that most users add 3-5 items to their shopping cart after browsing them, and then complete the checkout process within 10-30 minutes after adding them to the cart. Spatial Feature Extraction: Analysis of the distribution of source and destination IPs in network packet segmentation data reveals that most requests originate from several major cities in China, and there is a certain degree of IP address clustering. File operation record segmentation data shows that product images are mainly stored in specific disk partitions on the server, while order files are concentrated in another partition.

[0025] In the specific implementation process, the specific steps of step S3 are as follows: The generated fused feature vector is input into a pre-trained blockchain consensus model. In the blockchain consensus model, smart contracts automatically trigger each node to independently verify and calculate the input fused feature vector. The blockchain consensus mechanism is used to ensure that all nodes agree on the verification result. After verification, the final verification result is generated, which includes timestamp and hash fingerprint information. The blockchain consensus model is the mechanism in the blockchain network that ensures that all nodes agree on the transaction order and ledger state.

[0026] Specifically, during the construction of the blockchain consensus model, smart contracts are pre-deployed in the blockchain network. A smart contract is an automatically executing computer program containing predefined rules and conditions. In this embodiment, the smart contract specifies how to trigger verification calculations by each node upon receiving a fused feature vector. When the fused feature vector is input into the blockchain consensus model, the smart contract is automatically activated and sends verification task instructions to each node in the blockchain network according to preset rules. Each node, upon receiving the instruction, independently performs verification calculations on the input fused feature vector. Specifically, nodes employ various verification algorithms; for example, nodes verify the legality of data by comparing it with pre-stored security feature templates. The blockchain consensus model employs a specific consensus mechanism, such as Proof-of-Work (PoW), Proof-of-Stake (PoS), or Practical Byzantine Fault Tolerance (PBFT). During the verification calculation process, each node broadcasts its verification results to other nodes. After receiving verification results from other nodes, each node performs statistical analysis according to certain rules. For example, in a blockchain network with N nodes, when a node receives the same verification result from at least 2f+1 other nodes (where f is the number of potentially malicious nodes, and N≥3f+1), that node considers the verification result credible. Once all nodes reach a consensus on the verification result, a final verification result is generated. This result includes a timestamp and hash fingerprint information. The timestamp records the specific time the verification operation occurred, used to track the temporal order of data verification and ensure data consistency. The hash fingerprint information is a unique identifier obtained by hashing the fused feature vector; it can be used to verify the integrity and authenticity of the data.

[0027] In the specific implementation process, step S4: The dual objective function calculation formula is: Maximize risk suppression rate maxR = total high-risk data volume / successfully intercepted high-risk data volume; minimize verification delay minD = ∑(average verification time for each class of data); the mixed integer dynamic programming algorithm calculation formula is: max(α R-β D).

[0028] Specifically, the risk suppression rate (maxR) is calculated as: total high-risk data volume / successfully intercepted high-risk data volume. The total high-risk data volume represents the total number of high-risk data items present in the system within a given timeframe. The successfully intercepted high-risk data volume represents the number of high-risk data items successfully identified and blocked by the current security inspection rules. A higher risk suppression rate indicates a better interception effect of the security inspection method on high-risk data, and thus higher system security. During the security inspection process, relevant information on high-risk data is continuously collected and recorded. First, the statistical timeframe is determined, such as one day, one week, or one month. Then, the total high-risk data volume appearing in the system within this timeframe is calculated, which can be obtained through analysis of system logs, alarm information from security monitoring tools, etc. Simultaneously, the number of high-risk data items successfully intercepted by the current security inspection rules is also calculated, which can be obtained from the interception records of the security inspection system. Finally, the total high-risk data volume is divided by the successfully intercepted high-risk data volume to obtain the risk suppression rate (R). The validation delay is minimized as minD = ∑(average validation time for each data class). Validation delay refers to the time taken from inputting data to generating validation results. For each data class, the start and end times of each validation are recorded during the security validation process, and the time taken for each validation is calculated. Then, the validation times of a certain number of validations (e.g., 100) are statistically analyzed, and their average value is calculated to obtain the average validation time for each data class. Finally, the average validation times for all data types are summed to obtain the validation delay D. The mixed-integer dynamic programming algorithm calculates this using the formula max(α). R-β In section D): α and β are weighting coefficients used to balance the importance of the two objectives of risk suppression rate and verification delay. A larger α indicates a greater emphasis on risk suppression rate; a larger β indicates a greater emphasis on verification delay. The values ​​of α and β can be adjusted according to specific needs or security strategies.

[0029] In the specific implementation process, the specific steps of step S5 are as follows: S501. The optimal security inspection rule is output through the adaptive security policy optimization model, and the optimal security inspection rule is transformed into a security inspection instruction for computer execution.

[0030] In this embodiment, when a network packet from a specific IP address (192.168.1.100) is detected, and the packet content contains sensitive keywords such as "password" and "confidential," it is intercepted and logged. After parsing the rule, the key elements are extracted: the source IP address is 192.168.1.100, the packet content contains sensitive keywords, and the actions are interception and logging. Then, a matching network packet verification instruction template is found in the instruction template library. The parsed rule elements are filled into the matching instruction template to generate a specific security verification instruction. The source IP address 192.168.1.100 is filled into the source IP address parameter of the instruction template, the keywords "password" and "confidential" are filled into the keyword list parameter, and the actions "intercept" and "log" are filled into the corresponding action parameters, which is the generated security verification instruction.

[0031] S502. The converted security inspection instructions are distributed to the preset hierarchical nodes, and each hierarchical node executes the corresponding instructions. These include high-level nodes, mid-level nodes, and low-level nodes. Specifically: high-level nodes are located in the system core layer and are responsible for global coordination, policy decision-making, and data aggregation; mid-level nodes are located in the aggregation layer and are responsible for the management and forwarding of local areas; low-level nodes are located in the access layer, directly connected to terminal devices, and execute specific tasks.

[0032] Example 2 like Figure 2 As shown, a security inspection system based on electronic data includes: The data acquisition module is used to collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and to perform real-time data segmentation using a sliding window mechanism to obtain segmented data information streams; The feature processing module is used to encode multi-dimensional features of segmented data information streams through a deep residual adversarial generative network to generate fused feature vectors. The distributed verification module is used to input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results. The model building module is used to build an adaptive security policy optimization model based on the verification results. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as dual objective functions and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rules. The security detection module is used to optimize the model through adaptive security strategy, output the optimal security inspection rules, generate security inspection instructions, and perform distributed execution of the security inspection instructions through hierarchical nodes.

[0033] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0034] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0035] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

Claims

1. A security inspection method based on electronic data, characterized in that, The detection method includes the following steps: S1. Collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and use a sliding window mechanism to segment the data in real time to obtain segmented data information streams; S2. Multi-dimensional feature encoding is performed on the segmented data information stream through a deep residual adversarial generative network to generate a fused feature vector. S3. Input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results; S4. Based on the verification results, construct an adaptive security policy optimization model. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as the dual objective functions, and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rule. S5. The optimal security inspection rules are output through the adaptive security strategy optimization model, security inspection instructions are generated, and the security inspection instructions are executed in a distributed manner through hierarchical nodes.

2. The security inspection method based on electronic data according to claim 1, characterized in that, The specific steps of step S1 are as follows: S101. Collect the raw information stream of electronic data through multi-source heterogeneous terminal devices deployed in different network areas, wherein the raw information stream includes network packets, system logs, file operation records, and user behavior sequence data; S102. A sliding window mechanism is used to dynamically segment the original information stream. Specifically, a window of a fixed size is set and slides on the original information stream according to a preset time interval or data volume. Each time the window slides, the data in the window is taken as a segment to divide the continuous original information stream into multiple segmented data information streams and obtain segmented data information streams.

3. The security inspection method based on electronic data according to claim 1, characterized in that, The specific steps of step S2 are as follows: The obtained segmented data information stream is input into a pre-trained deep residual adversarial generative network (DGNN) to extract and encode features from multiple dimensions to generate a fused feature vector. The DGNN consists of a deep residual network and an adversarial generative network (ADN) and is used to perform nonlinear transformations on the input segmented data information stream. The multiple dimensions include statistical features, temporal features, or spatial features.

4. The security inspection method based on electronic data according to claim 3, characterized in that, The training process of the deep residual adversarial generative network is as follows: historical electronic data is acquired and a labeled segmented dataset is constructed based on the historical electronic data. The segmented dataset specifically includes normal dataset and abnormal dataset. Then, the normal dataset is used as the training set and input into the deep residual network as the feature encoder. Adversarial training is performed through the adversarial generative network to obtain the deep residual adversarial generative network.

5. The security inspection method based on electronic data according to claim 1, characterized in that, The specific steps of step S3 are as follows: The generated fused feature vector is input into a pre-trained blockchain consensus model. In the blockchain consensus model, smart contracts automatically trigger each node to independently verify and calculate the input fused feature vector. The blockchain consensus mechanism is used to ensure that all nodes agree on the verification result. After verification, the final verification result is generated, which includes timestamp and hash fingerprint information. The blockchain consensus model is the mechanism in the blockchain network that ensures that all nodes agree on the transaction order and ledger state.

6. The security inspection method based on electronic data according to claim 1, characterized in that, In step S4, the formula for calculating the dual objective function is: Maximize the risk suppression rate maxR = total high-risk data volume / successfully intercepted high-risk data volume, and minimize the verification delay minD = ∑(average verification time for each type of data); the formula for calculating the mixed integer dynamic programming algorithm is: max(α·R-β·D).

7. The security inspection method based on electronic data according to claim 1, characterized in that, The specific steps of step S5 are as follows: S501. The optimal security inspection rule is output through the adaptive security policy optimization model, and the optimal security inspection rule is transformed into a security inspection instruction for computer execution. S502. The converted security inspection command is sent to each preset hierarchical node, and each hierarchical node executes the corresponding security inspection command; wherein, the hierarchical nodes include high-level nodes, medium-level nodes and low-level nodes.

8. A security inspection system based on electronic data, employing a security inspection method based on electronic data as described in any one of claims 1-7, characterized in that, The inspection system: The data acquisition module is used to collect the raw information stream of electronic data through multi-source heterogeneous terminal devices, and to perform real-time data segmentation using a sliding window mechanism to obtain segmented data information streams; The feature processing module is used to encode multi-dimensional features of segmented data information streams through a deep residual adversarial generative network to generate fused feature vectors. The distributed verification module is used to input the fused feature vector into the blockchain consensus model, trigger multi-node distributed verification through pre-deployed smart contracts, and generate verification results. The model building module is used to build an adaptive security policy optimization model based on the verification results. The adaptive security policy optimization model takes maximizing the risk suppression rate and minimizing the verification delay as dual objective functions and uses a mixed integer dynamic programming algorithm to solve for the optimal security verification rules. The security detection module is used to optimize the model through adaptive security strategy, output the optimal security inspection rules, generate security inspection instructions, and perform distributed execution of the security inspection instructions through hierarchical nodes.