A network security log anomaly detection method and system based on a spatio-temporal heterogeneous graph neural network

By constructing a heterogeneous graph structure and a spatiotemporal heterogeneous graph neural network, the problems of multi-source heterogeneous log data fusion and spatiotemporal dependency modeling are solved, achieving efficient anomaly detection and source tracing analysis, and improving the accuracy and interpretability of network security detection.

CN122437676APending Publication Date: 2026-07-21STATE GRID ELECTRIC POWER RES INST +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID ELECTRIC POWER RES INST
Filing Date
2026-04-07
Publication Date
2026-07-21

Smart Images

  • Figure CN122437676A_ABST
    Figure CN122437676A_ABST
Patent Text Reader

Abstract

The application discloses a network security log anomaly detection method based on a space-time heterogeneous graph neural network, comprising: converting multi-source audit log data into a unified heterogeneous graph structure, and constructing node feature and edge type embedding; utilizing a heterogeneous graph attention network (HAN) and a gated recurrent unit (GRU) to jointly model the spatial dependence and time dynamics of the graph structure; adaptively integrating space-time features through a gated fusion mechanism; adopting a focal loss function to optimize model training, and solving the class imbalance problem; outputting edge-level anomaly scores, and providing interpretable detection results in combination with meta-path-based traceability analysis. The application realizes detection performance superior to existing methods on multiple public data sets, and is suitable for internal threat and advanced persistent threat (APT) detection in a complex network environment.
Need to check novelty before this filing date? Find Prior Art