多源先验门控增强威胁入侵检测与关联分析方法及系统

By constructing a multi-source prior knowledge system and a knowledge-enhanced gating adapter, the problem of insufficient accuracy and robustness of the detection model in the computing power network hub is solved, and efficient detection of similar attack variants and real-time response in resource-constrained environments are achieved.

CN122419989APending Publication Date: 2026-07-17GUIZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUIZHOU UNIV
Filing Date
2026-06-16
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In computing power network hubs, existing detection models struggle to effectively distinguish between complex heterogeneous traffic, similar attack variants, class imbalance, and edge real-time detection. Furthermore, they lack a unified expression of multi-source prior knowledge and a dynamic enhancement mechanism, resulting in insufficient detection accuracy and robustness.

Method used

A multi-source prior knowledge system is constructed, including structural priors, category conditional statistical priors, and global feature importance priors. Traffic features are dynamically modulated through a knowledge-enhanced gating adapter, and online detection is performed in conjunction with a lightweight temporal detection model to achieve dynamic enhancement or suppression of features.

Benefits of technology

It improves the ability to detect similar attack variants, reduces false positive and false negative rates, is suitable for deployment in resource-constrained environments, and maintains millisecond-level detection latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419989A_ABST
    Figure CN122419989A_ABST
Patent Text Reader

Abstract

本发明涉及网络安全、物联网安全、算力网络安全与人工智能技术领域,公开了一种多源先验门控增强威胁入侵检测与关联分析方法及系统,该方法在离线阶段构建三类先验知识,之后将三类先验进行维度对齐和融合,形成融合先验表示;在在线检测阶段,将融合先验输入知识增强门控适配器,使融合先验参与门控值计算,对实时流量特征进行动态增强或抑制;最后通过轻量时序检测模型提取局部突发模式和长程依赖特征,并输出正常流量或攻击流量类别。本发明通过离线构建攻击相关的多源先验知识,并基于在线检测阶段利用知识增强门控适配机制进行动态调制,实现对正常流量、异常流量、僵尸网络流量、扫描攻击、拒绝服务攻击及其他网络入侵行为的细粒度识别。
Need to check novelty before this filing date? Find Prior Art