An artificial intelligence-based network security real-time detection system

The real-time network security detection system based on AI-private architecture solves the problems of real-time detection and data privacy security in traditional network security systems, and achieves efficient and accurate threat identification and collaborative handling. It adapts to different network environments and improves emergency response efficiency.

CN122339815APending Publication Date: 2026-07-03SHENZHEN LIHE XINNUO TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN LIHE XINNUO TECH CO LTD
Filing Date
2026-04-29
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Traditional cybersecurity defense methods are unable to detect new and variant threats in real time and accurately. Cloud AI architectures pose data privacy and security risks, have poor system scalability and adaptability, and lack integrated and automated threat perception and collaborative response capabilities.

Method used

The real-time network security detection system based on AI private architecture includes a hardware layer, an AI algorithm layer, a detection and perception layer, an analysis and handling layer, a deployment and adaptation layer, and a full-process management layer. Each layer operates in a two-way collaborative manner, with multiple built-in quantitative calculation models to achieve real-time threat identification and accurate location, and improves emergency response efficiency through collaborative handling strategies.

Benefits of technology

It achieves millisecond-level network threat identification and location, reduces detection latency and false negative rate, reduces the risk of data leakage, adapts to different network environments, and improves emergency response efficiency and system adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122339815A_ABST
    Figure CN122339815A_ABST
Patent Text Reader

Abstract

This application provides an artificial intelligence-based real-time network security detection system, relating to the field of network security detection technology. Utilizing the powerful computing power of its built-in AI all-in-one machine and multiple quantitative calculation models, this application can perform millisecond-level analysis of network traffic and behavior, achieving real-time identification and accurate location of unknown threats and variant attacks, reducing detection latency and false negative rates. This application constructs a complete closed loop from detection and perception, quantitative assessment to analysis and handling. The system can automatically assess threat levels and trigger pre-set or intelligently generated handling strategies (such as isolation, blocking, and evidence collection), achieving integrated "detection-response" and improving emergency response efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security detection technology, and more specifically, to a real-time network security detection system based on artificial intelligence. Background Technology

[0002] As cyberattacks become increasingly complex, covert, and automated, traditional cybersecurity defenses based on signature databases and rule matching face severe challenges. Traditional solutions typically rely on updates to known attack signatures, resulting in insufficient detection capabilities for new, variant, or advanced persistent threats, exhibiting lag and high false positive rates, failing to meet the demands for real-time and accurate protection. While existing technologies employ artificial intelligence (AI) algorithms for threat detection, these solutions often suffer from the following limitations: First, they frequently utilize cloud-based AI architectures, posing risks regarding data transmission latency, data privacy, and model universality, making them unsuitable for critical information infrastructures with extremely high real-time and privacy requirements. Second, the coupling between AI models and hardware / business systems is low, lacking an integrated, automated closed-loop capability from threat perception and intelligent analysis to collaborative response. Third, the systems suffer from poor scalability and adaptability, making rapid deployment and flexible adjustments difficult to adapt to different network environments and security needs. Therefore, we propose an improvement: a real-time cybersecurity detection system based on artificial intelligence. Summary of the Invention

[0003] This invention provides a real-time network security detection system based on artificial intelligence, built on a private AI architecture, including a hardware layer, an AI algorithm layer, a detection and perception layer, an analysis and processing layer, a deployment and adaptation layer, and a full-process management layer. Each layer adopts bidirectional data interaction and operates collaboratively. The hardware layer is a combination of an AI all-in-one machine and supporting hardware for network security detection. The AI ​​algorithm layer has built-in multiple quantitative calculation models to realize real-time identification, quantitative assessment, location and intelligent handling of network security threats.

[0004] As a preferred technical solution of this application, the AI ​​algorithm layer includes an external attack risk quantification model, which is used to calculate the comprehensive risk value P of external network attacks within the detection period.

[0005] As a preferred technical solution of this application, the detection and perception layer is configured with a multi-dimensional signal detection unit and a positioning correction model. The correction calculation formula for the actual positioning coordinates (X,Y) of the signal is as follows: X = X0 + ΔX = X0 + K × F × cosθ × α Y=Y0+ΔY=Y0+K×F×sinθ×α; Where (X0,Y0) are the initial detection coordinates of the signal; K is the environmental attenuation coefficient, which is 0.01-0.1 depending on the obstacle density of the detection scene; F is the actual power of the detection signal; θ is the signal propagation azimuth angle; α is the signal reflection correction coefficient, which ranges from 0.9 to 1.0; the detection coverage area of ​​the sensing layer is not less than 500m².

[0006] As a preferred technical solution of this application, the analysis and processing layer includes a threat tracing unit and a tracing matching degree calculation model, which are used to determine the homogeneity of attack behaviors.

[0007] As a preferred technical solution of this application, the analysis and handling layer further includes a security incident response unit and a response efficiency calculation model, used to quantitatively evaluate the system's handling efficiency and response efficiency for security incidents. The calculation formula is: ; in, The timestamp for the security event identified by the AI ​​algorithm layer. The timestamp for when the system completes attack blocking / fault repair; The maximum allowable response time is preset for the industry.

[0008] As a preferred technical solution of this application, the deployment adaptation layer has a built-in IT architecture adaptability assessment model, which is used to quantify the compatibility A between the calculation system and the enterprise's existing IT infrastructure.

[0009] As a preferred technical solution of this application, the hardware layer includes a UPS uninterruptible power supply, an environmental monitoring system, and an air conditioner, and has a built-in system operation stability calculation model for quantitatively evaluating the stability S of the system during continuous operation. The calculation formula is as follows: ; in, For the first Duration of the secondary system failure; This represents the number of failures within the statistical period. For the statistical period.

[0010] As a preferred technical solution of this application, the full-process management layer includes a data security compliance unit and a data compliance calculation model, which are used to quantitatively assess the enterprise's data security compliance level. .

[0011] As a preferred technical solution of this application, the AI ​​algorithm layer further includes a model training optimization unit and a large model training iteration efficiency calculation model, used to quantitatively evaluate the training efficiency η of the enterprise's self-developed large model, and the calculation formula is as follows: ; in, η represents the effective recognition accuracy improvement after a single model training iteration; T represents the actual time spent on a single model training iteration; R represents the hardware resource utilization rate during the training process, ranging from 0.0 to 1.0; the AI ​​algorithm layer optimizes the model training iteration efficiency η by more than 30% compared to traditional training methods through software and hardware co-engineering architecture.

[0012] As a preferred technical solution of this application, the AI ​​algorithm layer has a built-in asset fingerprint recognition model, which is used to actively or passively detect and identify various network devices in the network, establish a dynamic asset list including device type, operating system, open ports and service versions, and identify vulnerability exploitation behaviors targeting specific assets.

[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: In the scheme of this application: 1. This application, through the powerful computing power of its built-in AI all-in-one machine and multiple quantitative calculation models, can perform millisecond-level analysis of network traffic and behavior, enabling real-time identification and accurate location of unknown threats and variant attacks, reducing detection latency and false negative rate; this application constructs a complete closed loop from detection and perception, quantitative assessment to analysis and handling, the system can automatically assess threat levels and trigger preset or intelligently generated handling strategies (such as isolation, blocking, and evidence collection), realizing the integration of "detection-response" and improving emergency response efficiency; 2. This application is built on an AI private architecture, where all data, algorithm models and analysis processes are completed in the user's local environment, reducing the risk of leakage caused by uploading sensitive data to the cloud. It is particularly suitable for fields such as government, finance, and energy that have strict requirements for data sovereignty and privacy.

[0014] 3. Through the hierarchical design of the hardware layer, AI algorithm layer, detection and perception layer, analysis and processing layer, deployment and adaptation layer, and full-process management layer, each layer works in both directions, enabling the system to easily adapt to network environments of different sizes and heterogeneous hardware. The deployment and adaptation layer can also quickly connect to the existing security system to protect the user's existing investment. Attached Figure Description

[0015] Figure 1 A schematic diagram of the AI-based real-time network security detection system provided in this application; Figure 2 A flowchart of the AI-based real-time network security detection system provided for this application. Detailed Implementation

[0016] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0017] It should be noted that, unless otherwise specified, the embodiments and features and technical solutions in the present invention can be combined with each other.

[0018] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0019] For an example, please refer to... Figures 1-2 A real-time network security detection system based on artificial intelligence is built on a private AI architecture, including a hardware layer, an AI algorithm layer, a detection and perception layer, an analysis and processing layer, a deployment and adaptation layer, and a full-process management layer. Each layer adopts bidirectional data interaction and operates collaboratively. The hardware layer is a combination of an AI all-in-one machine and supporting hardware for network security detection. The AI ​​algorithm layer has built-in multiple quantitative calculation models to achieve real-time identification, quantitative assessment, location and intelligent handling of network security threats.

[0020] Furthermore, the AI ​​algorithm layer includes an external attack risk quantification model, used to calculate the comprehensive external attack risk value P within the detection period. The formula for calculating the comprehensive external attack risk value P is as follows: ; is the harm weight coefficient of the i-th type of attack behavior, with a value range of 0.1-1.0. The higher the harm level of the attack, the larger the coefficient value; Si is the AI ​​recognition confidence of the i-th type of attack behavior, with a value range of 0.5-1.0; Ti is the duration of the i-th type of attack behavior, in hours (h); n is the total number of attack behavior types identified within the detection period. The network environment risk correction coefficient ranges from 0.8 to 1.2 and is determined according to the network boundary protection level. When the calculated P ≥ 0.7, the system automatically triggers a level 1 security warning and starts an automatic attack blocking mechanism.

[0021] Furthermore, the detection and perception layer is equipped with multi-dimensional signal detection units and a positioning correction model to achieve 1m-level positioning of high-volume network signals. The correction calculation formula for the actual signal positioning coordinates (X,Y) is as follows: X = X0 + ΔX = X0 + K × F × cosθ × α Y=Y0+ΔY=Y0+K×F×sinθ×α; Where (X0,Y0) are the initial detection coordinates of the signal; K is the environmental attenuation coefficient, which is 0.01-0.1 depending on the obstacle density of the detection scene; F is the actual power of the detection signal, in decibels and milliwatts (dBm); θ is the signal propagation azimuth angle, in degrees (°); α is the signal reflection correction coefficient, with a value range of 0.9-1.0; the detection coverage area of ​​the sensing layer is not less than 500m².

[0022] Furthermore, the analysis and handling layer includes a threat attribution unit and an attribution matching degree calculation model, used to determine the homogeneity of attack behaviors and the attack attribution matching degree. The calculation formula is: ; in For the first The degree of overlap between each extracted feature and the attack features in the sample library, with a value ranging from 0.0 to 1.0; For the first The uniqueness weight value of each extracted feature ranges from 0.1 to 1.0. The higher the uniqueness of the feature, the larger the weight value. To detect the number of effective attack features extracted; when When the attack rate is ≥85%, the system determines it to be a same-origin attack and automatically displays historical attack tracing data and handling solutions.

[0023] Furthermore, the analysis and handling layer also includes a security incident response unit and a response efficiency calculation model, used to quantitatively evaluate the system's efficiency in handling security incidents and its response efficiency. The calculation formula is: ; in, The timestamp for the security event identified by the AI ​​algorithm layer. The timestamps for when the system completes attack blocking / fault repair are in seconds (s). The system presets a maximum permissible response time for different industries, ranging from 5 to 30 seconds, based on the specific needs of finance, government affairs, and smart manufacturing. It also optimizes the processing flow through AI algorithms to improve response efficiency. It has remained stable at over 85%.

[0024] Furthermore, the deployment adaptation layer includes a built-in IT architecture adaptability assessment model to quantify the compatibility degree A between the computing system and the enterprise's existing IT infrastructure. The formula for calculating the compatibility degree A is as follows: A = ω1 × A1 + ω2 × A2 + ω3 × A3; Wherein, ω1, ω2, and ω3 are weight coefficients, and ω1+ω2+ω3=1. ω1, ω2, and ω3 correspond to the weights of hardware compatibility, network integration, and software adaptability, respectively, and the values ​​of ω1, ω2, and ω3 are all in the range of 0.2-0.5; A1 is hardware compatibility, with a value of 0-100, calculated from the device docking success rate; A2 is network integration, with a value of 0-100, calculated from the average data transmission latency and packet loss rate; A3 is software adaptability, with a value of 0-100, calculated from the smoothness of existing system linkage; when A≥80, the system supports rapid deployment without modification; when 60≤A<80, a lightweight architecture modification plan is automatically output.

[0025] Furthermore, the hardware layer includes a UPS uninterruptible power supply, an environmental monitoring system, and air conditioning, and incorporates a built-in system stability calculation model to quantitatively evaluate the system's continuous operation stability S. The calculation formula is as follows: ; in, For the first The duration of the subsystem failure is expressed in seconds (s). This represents the number of failures within the statistical period. The statistical period is in hours (h), with a default value of 8760h (year).

[0026] Furthermore, the end-to-end management layer includes a data security compliance unit and a data compliance calculation model, used to quantitatively assess the enterprise's data security compliance level. The calculation formula is: ; in, For the first The severity weight of each data compliance violation item ranges from 0.05 to 0.2, with higher weight values ​​indicating greater violation severity. For the first The real-time probability of occurrence of each type of violation, ranging from 0.0 to 1.0; The total number of core items for data security compliance checks should include at least three core categories: data encryption, access control auditing, and sensitive information identification; this reflects the enterprise's data security compliance level. ≥95%.

[0027] Furthermore, the AI ​​algorithm layer also includes a model training optimization unit and a large model training iteration efficiency calculation model, used to quantitatively evaluate the training efficiency η of the enterprise's self-developed large model. The calculation formula is as follows: ; in, The effective recognition accuracy improvement after a single model training session is expressed as a percentage (%); T represents the actual training time for a single model training session, expressed in hours (h); R represents the hardware resource utilization rate during training, ranging from 0.0 to 1.0; the AI ​​algorithm layer optimizes the software-hardware co-engineering architecture, thereby improving the model training iteration efficiency η by more than 30% compared to traditional training methods.

[0028] Furthermore, the AI ​​algorithm layer has a built-in asset fingerprinting model, which is used to actively or passively detect and identify various network devices in the network, establish a dynamic asset list including device type, operating system, open ports and service versions, and identify vulnerability exploitation behaviors targeting specific assets.

[0029] The detection and perception layer is also used to collect and preprocess security data in real time from network traffic, terminal behavior, and log data, and push the standardized data stream to the AI ​​algorithm layer and the full-process management layer at the same time. The analysis and handling layer is also used to receive the threat identification and assessment results output by the AI ​​algorithm layer, and generate and execute corresponding handling instructions based on preset strategies or dynamic decision-making models. The handling instructions include at least one of network blocking, traffic scrubbing, host isolation, and vulnerability repair. The deployment adaptation layer also provides standardized interfaces for data exchange and command linkage with users' existing firewalls, intrusion prevention systems, security information and event management platforms, enabling collaborative protection with third-party security components; The end-to-end management layer also provides a unified human-computer interaction interface for centralized configuration, monitoring, auditing, and visualization of strategies, models, and tasks at all levels within the system.

[0030] When using it, the system first uses the built-in IT architecture compatibility assessment model in the adaptation layer to quantify the compatibility between the system and the enterprise's existing IT infrastructure. When the compatibility is ≥80, it can be deployed quickly without modification. When the compatibility is 60≤compatibility<80, the system should be modified according to the lightweight architecture modification plan automatically output by the system before deployment. During the deployment, the system provides standardized interfaces to complete data docking and command linkage with the enterprise's existing firewalls, intrusion prevention systems and other third-party security components to achieve collaborative protection. Start the hardware layer UPS uninterruptible power supply, environmental monitoring system and other equipment, and simultaneously start the AI ​​algorithm layer, detection and perception layer and other modules. The system automatically enters the real-time detection mode. The detection and perception layer collects security data in real time from network traffic, terminal behavior and log data through multi-dimensional signal detection unit and completes preprocessing. The standardized data stream is pushed to the AI ​​algorithm layer and the full-process management layer to provide support for subsequent analysis and detection. Through the unified human-computer interaction interface provided by the full-process management layer, the system can centrally configure and monitor the operation status of each level, and view core information such as threat identification results output by the AI ​​algorithm layer, signal location data of the detection and perception layer, and data security compliance level in real time, so as to realize the visualization monitoring and auditing of the entire system operation process. The system automatically identifies threats and calculates parameters such as risk value and source matching degree. After triggering an alert, it executes corresponding blocking, repair and other disposal instructions. Users can view disposal details and link historical data.

[0031] By configuring strategies and models at each level through the entire management process, improving model accuracy by utilizing the training and optimization units of the AI ​​algorithm layer, and regularly checking the system status through the hardware layer stability model and compliance model.

[0032] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection, an electrical connection, or a connection that allows communication between them; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0033] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.

Claims

1. A real-time network security detection system based on artificial intelligence, characterized in that, Built on a private AI architecture, it includes a hardware layer, an AI algorithm layer, a detection and perception layer, an analysis and processing layer, a deployment and adaptation layer, and a full-process management layer. Each layer adopts bidirectional data interaction and operates collaboratively. The hardware layer is a combination of an AI all-in-one machine and supporting hardware for network security detection. The AI ​​algorithm layer has built-in multiple quantitative calculation models to realize real-time identification, quantitative assessment, location and intelligent handling of network security threats.

2. The AI-based real-time network security detection system according to claim 1, characterized in that, The AI ​​algorithm layer includes an external attack risk quantification model, which is used to calculate the comprehensive risk value P of external network attacks during the detection period.

3. The AI-based real-time network security detection system according to claim 1, characterized in that, The detection and perception layer is equipped with multi-dimensional signal detection units and a positioning correction model. The formula for calculating the correction of the actual positioning coordinates (X,Y) of the signal is as follows: X = X0 + ΔX = X0 + K × F × cosθ × α Y=Y0+ΔY=Y0+K×F×sinθ×α; Where (X0,Y0) are the initial detection coordinates of the signal; K is the environmental attenuation coefficient, which is 0.01-0.1 depending on the obstacle density of the detection scene; F is the actual power of the detection signal; θ is the signal propagation azimuth angle; α is the signal reflection correction coefficient, which ranges from 0.9 to 1.0; the detection coverage area of ​​the sensing layer is not less than 500m².

4. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The analysis and handling layer includes a threat tracing unit and a tracing matching degree calculation model, which are used to determine the homogeneity of attack behaviors.

5. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The analysis and handling layer also includes a security incident response unit and a response efficiency calculation model, used to quantitatively evaluate the system's efficiency in handling security incidents and its response efficiency. The calculation formula is: ; in, The timestamp for the security event identified by the AI ​​algorithm layer. The timestamp for when the system completes attack blocking / fault repair; The maximum allowable response time is preset for the industry.

6. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The deployment adaptation layer has a built-in IT architecture adaptability assessment model, which is used to quantify the compatibility A between the system and the enterprise's existing IT infrastructure.

7. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The hardware layer includes a UPS uninterruptible power supply, an environmental monitoring system, and air conditioning, and has a built-in system stability calculation model for quantitatively evaluating the system's continuous operation stability S. The calculation formula is as follows: ; in, For the first Duration of the secondary system failure; This represents the number of failures within the statistical period. For the statistical period.

8. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The end-to-end management layer includes a data security compliance unit and a data compliance calculation model, used to quantitatively assess the enterprise's data security compliance level. .

9. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The AI ​​algorithm layer also includes a model training optimization unit and a large model training iteration efficiency calculation model, used to quantitatively evaluate the training efficiency η of the enterprise's self-developed large model. The calculation formula is as follows: ; in, η represents the effective recognition accuracy improvement after a single model training iteration; T represents the actual time spent on a single model training iteration; R represents the hardware resource utilization rate during the training process, ranging from 0.0 to 1.0; the AI ​​algorithm layer optimizes the model training iteration efficiency η by more than 30% compared to traditional training methods through software and hardware co-engineering architecture.

10. The real-time network security detection system based on artificial intelligence according to claim 1, characterized in that, The AI ​​algorithm layer has a built-in asset fingerprinting model, which is used to actively or passively detect and identify various network devices in the network, establish a dynamic asset list including device type, operating system, open ports and service versions, and identify vulnerability exploitation behaviors targeting specific assets.