Rule-based detection enhanced vectorization security event detection method and system
By introducing a three-job physical isolation architecture into the SOC system, and combining rule detection and vector detection, the semantic expression bottleneck of grammatical rules is broken through, enabling rapid detection of semantic similarity matching and unknown anomalies. This solves the problems of high false negative rate and delayed update in existing SOC systems, and meets the requirements of real-time detection and interpretability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
- Filing Date
- 2026-04-29
- Publication Date
- 2026-07-07
AI Technical Summary
Existing SOC systems suffer from semantic expression bottlenecks based on syntax rules when facing complex attacks, making it difficult to detect unknown or variant anomalies. Furthermore, the rules are updated slowly, resulting in high false negative rates, high resource consumption, and an inability to achieve rapid response and interpretability.
A three-operation physically isolated architecture is adopted, combining rule detection and vector detection. Rule detection handles deterministic anomalies, vector detection handles variant and similar anomalies, and side-channel clustering is used to discover unknown patterns, thereby achieving semantic similarity matching and rapid updates.
It achieves semantic matching with millisecond-level response capability, reduces the false negative rate, supports rapid detection of unknown anomalies, ensures the interpretability of detection results and seamless system upgrades, and meets real-time detection requirements.
Smart Images

Figure CN122346540A_ABST