Rule-based detection enhanced vectorization security event detection method and system

By introducing a three-job physical isolation architecture into the SOC system, and combining rule detection and vector detection, the semantic expression bottleneck of grammatical rules is broken through, enabling rapid detection of semantic similarity matching and unknown anomalies. This solves the problems of high false negative rate and delayed update in existing SOC systems, and meets the requirements of real-time detection and interpretability.

CN122346540APending Publication Date: 2026-07-07CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
Filing Date
2026-04-29
Publication Date
2026-07-07

AI Technical Summary

Technical Problem

Existing SOC systems suffer from semantic expression bottlenecks based on syntax rules when facing complex attacks, making it difficult to detect unknown or variant anomalies. Furthermore, the rules are updated slowly, resulting in high false negative rates, high resource consumption, and an inability to achieve rapid response and interpretability.

Method used

A three-operation physically isolated architecture is adopted, combining rule detection and vector detection. Rule detection handles deterministic anomalies, vector detection handles variant and similar anomalies, and side-channel clustering is used to discover unknown patterns, thereby achieving semantic similarity matching and rapid updates.

Benefits of technology

It achieves semantic matching with millisecond-level response capability, reduces the false negative rate, supports rapid detection of unknown anomalies, ensures the interpretability of detection results and seamless system upgrades, and meets real-time detection requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122346540A_ABST
    Figure CN122346540A_ABST
Patent Text Reader

Abstract

The application discloses a rule detection enhanced vectorization security event detection method and system. The method comprises the following steps: rule detection and session aggregation, performing rule matching and outputting an alarm, and simultaneously, a session unit is aggregated and pushed through a side output; vectorization detection, after extracting, vectorizing and normalizing the features of the session unit, similarity searching is performed with a standard vector library and hierarchical pushing is performed; bypass clustering mining, suspected unknown vector clustering analysis and multi-level screening are performed to generate a candidate mode template; closed loop updating, candidate mode gray is injected into the standard vector library, and after being reviewed, the temporary dimension is solidified and dynamically recycled. The application adopts a three-job physical isolation architecture, realizes parallel cooperation of rule detection and vector detection, breaks through the semantic expression bottleneck while maintaining millisecond-level response, supports fast discovery of unknown abnormalities and zero-interruption hot updating, and has the advantages of non-intrusive deployment, strong interpretability, closed loop continuous evolution and the like.
Need to check novelty before this filing date? Find Prior Art