A network security log anomaly detection method and system based on a spatio-temporal heterogeneous graph neural network
By constructing a heterogeneous graph structure and a spatiotemporal heterogeneous graph neural network, the problems of multi-source heterogeneous log data fusion and spatiotemporal dependency modeling are solved, achieving efficient anomaly detection and source tracing analysis, and improving the accuracy and interpretability of network security detection.
CN122437676APending Publication Date: 2026-07-21STATE GRID ELECTRIC POWER RES INST +3
View PDF 0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STATE GRID ELECTRIC POWER RES INST
- Filing Date
- 2026-04-07
- Publication Date
- 2026-07-21
Smart Images

Figure CN122437676A_ABST
Abstract
The application discloses a network security log anomaly detection method based on a space-time heterogeneous graph neural network, comprising: converting multi-source audit log data into a unified heterogeneous graph structure, and constructing node feature and edge type embedding; utilizing a heterogeneous graph attention network (HAN) and a gated recurrent unit (GRU) to jointly model the spatial dependence and time dynamics of the graph structure; adaptively integrating space-time features through a gated fusion mechanism; adopting a focal loss function to optimize model training, and solving the class imbalance problem; outputting edge-level anomaly scores, and providing interpretable detection results in combination with meta-path-based traceability analysis. The application realizes detection performance superior to existing methods on multiple public data sets, and is suitable for internal threat and advanced persistent threat (APT) detection in a complex network environment.
Need to check novelty before this filing date? Find Prior Art