Multi-dimensional data fusion security early warning decision support system based on artificial intelligence

CN122764589APending Publication Date: 2026-09-15GUANGDONG MEIDIAN BELL INTEGRATED TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610874917.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-09-15

Smart Images

  • Figure CN122764589A_ABST
    Figure CN122764589A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of computer security, specifically, to a multi-dimensional data fusion security early warning decision support system based on artificial intelligence, comprising: a data acquisition and standardization unit; a data fusion and situation feature extraction unit; an adaptive risk early warning deduction unit; a decision strategy generation and interpretable output unit. The present application relies on multi-semantic edge divide-and-conquer attention, security domain topology constraint mask filtering and dynamic neighborhood sampling to construct a sparse deduction subgraph, accurately distinguishes entity correlation semantics, eliminates invalid topological relationships, reduces large-scale network computing power loss, and avoids risk positioning deviation caused by topological distortion; at the same time, based on the historical propagation trajectory, a dynamic path memory factor is generated to correct the propagation dynamics parameters, combined with the bidirectional iterative deduction of the long short-term memory network, dynamically adapts to the attack evolution law, corrects the propagation path and time delay estimation deviation, improves the early warning quantitative precision and reliability, and reduces the false and missed alarm rate of security early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security technology, and more specifically, to a multi-dimensional data fusion security early warning decision support system based on artificial intelligence. Background Technology

[0002] With the continuous advancement of digital infrastructure construction, proactive cybersecurity defense systems in critical information infrastructure, industrial internet, and other fields are constantly being improved. Security situation awareness and early warning decision-making systems, as a core component of these proactive defense systems, generally adopt a hierarchical architecture of data collection, situation analysis, and decision output. They are widely used in various scenarios such as government and enterprises, energy, and transportation, undertaking the core functions of comprehensive risk identification, proactive early warning response, and decision support. They are an important carrier for the intelligent upgrading of cybersecurity protection capabilities.

[0003] Currently, the mainstream technical solutions for large-scale deployment in the industry mainly fall into two categories. The first is the traditional security early warning solution based on rule engines. This solution collects multi-source security logs and alarm data, performs matching judgments based on a preset rule base, and triggers early warnings. It boasts a mature and stable architecture, high configuration flexibility, and is widely used in scenarios with clear compliance requirements. The second is the correlation risk inference solution based on general graph neural networks. This solution constructs a correlation topology for monitored entities and uses graph neural networks to infer the propagation of correlation risks. It can identify correlation attacks that cannot be covered by single-point rules, showing an improvement in the ability to identify complex attacks compared to traditional solutions.

[0004] However, both approaches still suffer from common technical bottlenecks that hinder further improvements in protection effectiveness. First, the weight calculation accuracy for heterogeneous entity association topologies is insufficient, lacking pre-emptive compliance constraints. Existing solutions use a uniform weight calculation logic for different types of entity associations, failing to differentiate between association attributes and lacking physical transmission constraints for security domains at the topology level. This results in numerous invalid association edges that do not conform to actual transmission logic. This directly reduces the baseline accuracy of subsequent risk projections. In complex network scenarios with large node scales, invalid edges significantly increase computational overhead, limiting the system's real-time response capabilities. Second, the dynamic adaptation capability of parameters in risk cascading propagation projections is insufficient. Existing propagation dynamics models often use fixed parameter configurations, failing to dynamically calibrate parameters such as propagation probability and latency based on historical risk propagation patterns. The projection process struggles to closely match the evolution path of real attacks. This issue easily leads to distorted propagation path predictions and significant deviations in risk diffusion latency estimations. In scenarios with intertwined multi-dimensional attacks, the reliability of early warning results is insufficient, failing to provide reliable data support for subsequent response decisions. In view of this, we propose a security early warning decision support system based on artificial intelligence and multi-dimensional data fusion. Summary of the Invention

[0005] The purpose of this invention is to provide a multi-dimensional data fusion security early warning decision support system based on artificial intelligence, in order to solve the problems mentioned in the background art of existing security early warning systems, such as low accuracy of heterogeneous entity association topology construction, serious interference from invalid associations, and fixed risk propagation inference parameters with poor dynamic adaptation capabilities.

[0006] To address the aforementioned technical problems, the present invention aims to provide a multi-dimensional data fusion security early warning decision support system based on artificial intelligence, comprising: The data acquisition and standardization unit receives multi-source heterogeneous security monitoring data, performs standardization preprocessing on the multi-source heterogeneous security monitoring data, and outputs a time-consistent standardized security data stream. The data fusion and situation feature extraction unit receives a standardized security data stream, performs multi-dimensional feature extraction and fusion processing on the standardized security data stream, and outputs a multi-dimensional security situation feature matrix. An adaptive risk warning simulation unit receives a multi-dimensional security situation feature matrix, constructs a heterogeneous entity association topology using a multi-semantic edge divide-and-conquer attention mechanism, generates a sparse simulation subgraph by filtering with a security domain topology constraint mask matrix and sampling dynamic high-risk neighborhoods, calculates and generates a dynamic propagation path memory factor based on historical propagation trajectories, corrects the susceptible-infection-recovery state propagation dynamics parameters through the dynamic propagation path memory factor, performs bidirectional iterative simulation in conjunction with a long short-term memory network, and outputs a graded warning signal that includes node-level risk quantification scores, propagation path credibility, and expected diffusion delay. The decision strategy generation and interpretable output unit receives graded early warning signals, matches and generates corresponding disposal plans and risk tracing explanations, and completes structured output through a visual interactive interface.

[0007] As a further improvement to this technical solution, the data acquisition and standardization unit includes a multi-source data access module, a data cleaning and normalization module, and a time-series alignment output module, wherein: The multi-source data access module is used to access multi-source heterogeneous security monitoring data and completes protocol adaptation and data caching for different data sources through a distributed message queue protocol. The data cleaning and standardization module is based on the multi-source heterogeneous security monitoring data cached by the multi-source data access module, and uses a unified semantic data model to complete field format mapping and abnormal data removal. The time-series alignment output module performs timestamp alignment calibration and missing value interpolation on the data processed by the data cleaning and normalization module, generating a time-series consistent standardized secure data stream and outputting it.

[0008] As a further improvement to this technical solution, the data fusion and situation feature extraction unit includes a multi-dimensional feature extraction module, a cross-modal feature alignment module, and a weighted fusion output module, wherein: The multi-dimensional feature extraction module is based on standardized secure data streams and uses a multi-head self-attention mechanism to extract spatial dimension feature vectors, temporal dimension feature vectors, and attribute dimension feature vectors respectively. The cross-modal feature alignment module performs cross-modal feature alignment operations based on spatial dimension feature vectors, temporal dimension feature vectors, and attribute dimension feature vectors, mapping the feature vectors of each dimension to a unified feature space; The weighted fusion output module generates and outputs a multi-dimensional security situation feature matrix based on the feature vectors aligned by the cross-modal feature alignment module through learnable weighted fusion operations.

[0009] As a further improvement to this technical solution, the adaptive risk warning simulation unit includes a heterogeneous topology construction module, a sparse subgraph generation module, a path memory factor calculation module, a propagation dynamics correction module, and a bidirectional iterative simulation module, wherein: The heterogeneous topology construction module receives a multi-dimensional security situation feature matrix, and calculates the attention weight of each associated edge through a multi-semantic edge divide-and-conquer attention mechanism for each monitored entity and its various associations contained in the matrix, thereby generating an initial heterogeneous entity association topology adjacency matrix. The sparse subgraph generation module receives the initial heterogeneous entity association topological adjacency matrix, and sequentially performs invalid edge filtering through the security domain topological constraint mask matrix and node range pruning through dynamic high-risk neighborhood sampling to generate a sparse inference subgraph with controlled computational scale. The path memory factor calculation module receives the sparse inference subgraph, combines the historical propagation trajectory within the sliding time window, performs feature encoding and evolution law matching calculation on the candidate propagation paths in the subgraph, and generates a dynamic propagation path memory factor corresponding to each candidate path. The propagation dynamics correction module receives a sparse deduction subgraph and a dynamic propagation path memory factor. It embeds the dynamic propagation path memory factor as a propagation adjustment parameter into the susceptible-infected-recovery state propagation dynamics iterative calculation process to correct three types of propagation dynamics parameters: risk trigger probability, expected arrival delay, and risk attenuation magnitude corresponding to each associated edge. The bidirectional iterative deduction module, combined with a long short-term memory network, performs spatiotemporal bidirectional iterative deduction on the corrected propagation dynamics state. After the results converge, it completes node risk quantification and path credibility assessment, and outputs a graded early warning signal containing node-level risk quantification scores, propagation path credibility, and expected diffusion delay.

[0010] As a further improvement to this technical solution, the process of constructing the initial heterogeneous entity association topology adjacency matrix by the heterogeneous topology construction module includes the following steps: S31.1 Analyze the multidimensional security situation feature matrix, extract the node attribute features and semantic labels of the associated edges of each monitored entity, and classify the associated edges according to four semantic categories: physical connection, network reachability, business dependence, and threat origin. S31.2 Configure independent attention calculation branches and weight mapping parameters for each type of associated edge, and calculate the attention weight values ​​of the corresponding associated edges in parallel; S31.3. The attention weight values ​​of the four types of associated edges are concatenated and integrated to generate the initial heterogeneous entity association topology adjacency matrix.

[0011] As a further improvement to this technical solution, the sparse subgraph generation module includes a topological constraint filtering submodule and a high-risk neighborhood sampling submodule, wherein: The topology constraint filtering submodule receives the initial heterogeneous entity association topology adjacency matrix, performs element-wise multiplication between the security domain topology constraint mask matrix and the initial heterogeneous entity association topology adjacency matrix, filters out invalid association edges that do not conform to the topology constraints, and outputs a compliant topology adjacency matrix. The high-risk neighborhood sampling submodule receives the compliant topology adjacency matrix, analyzes the situation characteristics of each monitored entity in the multi-dimensional security situation feature matrix, calculates the initial risk score of the node, selects high-risk seed nodes based on the initial risk score of the node, samples the nodes and corresponding associated edges within the k-hop neighborhood of the seed node, and generates a sparse inference subgraph.

[0012] As a further improvement to this technical solution, the process of generating dynamic propagation path memory factors by the path memory factor calculation module includes the following steps: S33.1 Extract the historical propagation trajectory within the sliding time window, extract the node access order, propagation direction and semantic transformation relationship of associated edges from the trajectory, perform feature encoding on each candidate propagation path, and generate candidate propagation path state vector; S33.2 Calculate the cosine similarity between the candidate propagation path state vector and the threat evolution baseline feature vector statistically extracted from the historical propagation trajectory to obtain the path evolution matching degree; S33.3 After multiplying the path evolution matching degree by the preset adjustment coefficient, the result is mapped to a numerical range of 0 to 1 using the sigmoid function to obtain the dynamic propagation path memory factor of the corresponding candidate propagation path.

[0013] As a further improvement to this technical solution, the process of correcting the transmission dynamics parameters of the susceptible-infected-recovery state by the transmission dynamics correction module includes the following steps: S34.1 Configure three types of initial state parameters—susceptibility, infectivity, and recovery—for each monitoring entity within the sparse extrapolation subgraph, and construct a basic computational framework for the propagation dynamics of the susceptibility-infectivity-recovery state. S34.2. The dynamic propagation path memory factor of the corresponding candidate propagation path is used as the propagation adjustment parameter and embedded in the iterative calculation process of propagation dynamics. The dynamic propagation path memory factor is used as the weighting coefficient to correct the basic risk trigger probability, and the expected arrival delay and risk attenuation magnitude are adjusted accordingly. S34.3. Perform multiple rounds of propagation iteration calculations based on the corrected parameters to obtain the real-time risk status parameters of each monitored entity.

[0014] As a further improvement to this technical solution, the process of the bidirectional iterative deduction module executing bidirectional iterative deduction and outputting graded early warning signals includes the following steps: S35.1. Use the global risk baseline output by the Long Short-Term Memory network as the initial state parameter for propagation dynamics calculation and input it into the propagation dynamics correction module; S35.2 Feedback the node risk time series results output by the propagation dynamics correction module to the long short-term memory network to adjust the prediction parameters of the next sliding window; S35.3 Repeat the forward input and reverse correction process until the change in the node risk state parameter is lower than the preset convergence threshold, and complete the iterative convergence. S35.4 Based on the converged node risk state parameters, calculate the node-level risk quantification score, propagation path credibility, and expected diffusion delay, and generate and output graded early warning signals.

[0015] As a further improvement to this technical solution, the decision strategy generation and interpretable output unit includes an early warning signal parsing module, a handling strategy matching module, and an interpretable visualization output module, wherein: The early warning signal analysis module receives graded early warning signals and analyzes and extracts three types of early warning dimension data: node-level risk quantification score, propagation path credibility, and expected diffusion delay. The response strategy matching module generates a response plan and risk tracing explanation of the corresponding level based on the three types of early warning dimension data extracted by the early warning signal analysis module. The interpretable visualization output module performs structured integration processing on the disposal plan and risk tracing description generated by the disposal strategy matching module, and completes the output through a visual interactive interface.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention distinguishes various entity association semantics and independently calculates weights through a multi-semantic edge divide-and-conquer attention mechanism. Combined with innovative methods such as filtering invalid association edges using a security domain topological constraint mask matrix and generating sparse inference subgraphs through dynamic high-risk neighborhood sampling, it differentiates the true transmission relationships between network entities, eliminates topological associations that violate physical security logic, and reduces computational waste caused by invalid data. In large-scale multi-node network scenarios, it effectively avoids risk localization bias caused by topological distortion, strengthens the data foundation for risk inference, and simultaneously improves the real-time performance of the system, adapting to the engineering operation needs of massive monitoring nodes in critical infrastructure such as energy and transportation. 2. This invention utilizes a sliding window to generate dynamic propagation path memory factors based on historical propagation trajectories, thereby correcting the propagation dynamics parameters of the susceptible-infected-recovery state. It also employs a creative approach combining long short-term memory networks for bidirectional iterative deduction, breaking the limitations of traditional fixed-parameter deduction methods. Based on historical attack evolution patterns, it dynamically calibrates core indicators such as risk propagation probability and diffusion delay. This effectively improves the distortion problem in propagation path prediction under chain and interwoven attack scenarios, enhances the credibility of tiered early warning signals and the accuracy of quantitative scoring, and the output risk tracing information can directly support security personnel in formulating precise response plans, effectively reducing the false alarm and false negative rates in network security early warnings. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the overall system framework of the present invention; The meanings of the labels in the diagram are as follows: 1. Data acquisition and standardization unit; 11. Multi-source data access module; 12. Data cleaning and normalization module; 13. Time-series aligned output module; 2. Data fusion and situational feature extraction unit; 21. Multidimensional feature extraction module; 22. Cross-modal feature alignment module; 23. Weighted fusion output module; 3. Adaptive risk warning simulation unit; 31. Heterogeneous topology construction module; 32. Sparse subgraph generation module; 33. Path memory factor calculation module; 34. Propagation dynamics correction module; 35. Bidirectional iterative simulation module; 4. Decision strategy generation and interpretable output unit; 41. Early warning signal analysis module; 42. Disposal strategy matching module; 43. Interpretable visualization output module. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0019] like Figure 1 As shown, this embodiment provides a multi-dimensional data fusion security early warning decision support system based on artificial intelligence. This system is adaptable to mainstream application scenarios such as critical information infrastructure, government and enterprise security operations, and industrial internet security monitoring. At the hardware level, it can be deployed on a general-purpose server cluster, relying on a distributed communication architecture to achieve real-time interaction of multi-source data and computing power scheduling. The system as a whole consists of four serially coupled functional units: data acquisition and standardization unit 1, data fusion and situation feature extraction unit 2, adaptive risk early warning simulation unit 3, and decision strategy generation and interpretable output unit 4. These four units are interconnected and form a closed loop, fully realizing the entire process of security early warning functions, including data preprocessing, multi-dimensional feature fusion, adaptive risk simulation, and intelligent decision output. Specifically, the system includes: Data acquisition and standardization unit 1 receives multi-source heterogeneous security monitoring data, performs standardization preprocessing on the multi-source heterogeneous security monitoring data, and outputs a time-consistent standardized security data stream; it includes a multi-source data access module 11, a data cleaning and straightening module 12, and a time-series aligned output module 13, wherein: The multi-source data access module 11 is used to access multi-source heterogeneous security monitoring data and completes protocol adaptation and data caching of different data sources through a distributed message queue protocol. Specifically, the multi-source heterogeneous security monitoring data accessed by the multi-source data access module 11 includes six categories of routine industry monitoring data: boundary firewall access logs, deep audit messages of network traffic, terminal host security alarm records, business system operation audit ledgers, periodic vulnerability scanning reports of network assets, and industrial control equipment operation status collection indicators.

[0020] Furthermore, this embodiment selects Kafka distributed message queue as a unified transmission cache carrier, and configures dedicated adaptation and parsing components for different data source communication protocols, as detailed below: Real-time alarms are generated for devices that actively send data using the Syslog protocol. The Syslog parsing adapter is configured to strip the protocol header payload and extract the valid fields of the service. Configure the JDBC synchronization adapter to incrementally retrieve existing audit and vulnerability data stored in relational databases at fixed intervals; For real-time traffic metrics pushed by third-party security operations platforms via RESTful interfaces, an HTTP long-connection listening adapter is set up to continuously receive messages.

[0021] Next, the raw monitoring data after protocol parsing is uniformly encapsulated into a standard message body and written into the message queue partition storage. The standard message body contains at least four core fields: unique asset identifier, data source type, collection timestamp, and valid data payload. Independent partitions are divided according to monitoring area and asset type to achieve data isolation. The queue is set with a two-hour data survival period. Raw messages that exceed the survival period and have not been consumed by downstream processes are automatically deleted to avoid invalid data from continuously occupying storage and computing resources.

[0022] Finally, after the multi-source data access module 11 completes protocol adaptation and cache storage, it outputs a heterogeneous cached dataset labeled with the data source identifier and pushes it completely to the data cleaning and straightening module 12.

[0023] The data cleaning and regularization module 12 uses multi-source heterogeneous security monitoring data cached by the multi-source data access module 11 to complete field format mapping and abnormal data removal using a unified semantic data model. Specifically, a globally unified semantic data model is pre-built, defining five core standard semantic fields: unique asset identifier, original data collection timestamp, asset spatial location code, basic asset security attributes, and security event behavior description. A corresponding mapping table is also established, mapping each third-party data source's private fields to these standard fields. The data cleaning and standardization module 12 iterates through the original samples in the heterogeneous cached dataset, referring to the mapping table to complete the semantic conversion from private fields to standard fields: numerical risk indicators are uniformly converted to decimal floating-point storage format; text-based event descriptions are uniformly standardized to UTF-8 character encoding; and identifier fields such as IP addresses and device asset numbers undergo unified encoding formatting, eliminating heterogeneous differences in field naming, data types, and character encoding across different data sources.

[0024] Furthermore, after the field mapping process is completed, a triple anomaly check is performed in parallel to filter out distorted data: the first is integrity check, which directly removes invalid samples where all five core standard semantic fields are empty; the second is value range check, which presets reasonable value ranges for quantitative indicators such as network traffic and asset basic risk scores, and removes distorted collection records whose values ​​exceed the upper and lower limits of the range; the third is redundancy deduplication check, which calculates the hash value using the asset's unique identifier and the original collection timestamp as a combined primary key, and removes duplicate collection samples whose hash values ​​completely overlap within a short window.

[0025] Finally, after all field normalization and anomaly removal are completed, the data cleaning and normalization module 12 outputs a normalized dataset with semantically unified and distortion-free redundant samples, which is then unidirectionally sent to the time-series alignment output module 13.

[0026] The timing alignment output module 13 performs timestamp alignment calibration and missing value interpolation on the data processed by the data cleaning and normalization module 12, and generates a time-consistent standardized secure data stream and outputs it.

[0027] Specifically, all original acquisition timestamps in the regularized dataset are uniformly converted to UTC standard millisecond-level timestamps. The system selects 60 seconds as the time series slice unit and collects the regularized data generated by different assets and different types of monitoring data sources within the same time series slice interval into the same slice unit. This corrects the timing misalignment problem caused by the device's local time zone offset and the drift of the acquisition hardware clock, and establishes a unique timing benchmark for the entire system.

[0028] Furthermore, after the time series calibration is completed, missing value imputation and repair are carried out. For cases of local field missingness within a single time series slice, differentiated processing is performed based on field attributes, as follows: The discrete classification attribute fields are filled with the attribute values ​​that appear most frequently within the corresponding asset's time-series slice. Continuous numerical safety indicators are filled by linear interpolation using the corresponding asset's adjacent time-series slice values. Missing samples of key fields, such as unique asset identifiers, that cannot be restored through interpolation are directly discarded to prevent interpolation calculations from introducing false security posture information.

[0029] Finally, after the entire time series standardization process is completed, the time series alignment output module 13 constructs a standardized security data stream with a 60-second time series slice as the smallest encapsulation unit. Within a single time series slice, all corresponding monitoring data are aggregated according to the unique asset identifier, forming a time series data unit with a single asset as the basic granularity. Each data stream sample carries a unified millisecond time series label and a global standard semantic field. The field dimensions, time series benchmark, and semantic definition remain consistent throughout the process, and the data is continuously output to the downstream data fusion and situation feature extraction unit 2.

[0030] The data fusion and situation feature extraction unit 2 receives a standardized security data stream, performs multi-dimensional feature extraction and fusion processing on the standardized security data stream, and outputs a multi-dimensional security situation feature matrix. Specifically, it includes a multi-dimensional feature extraction module 21, a cross-modal feature alignment module 22, and a weighted fusion output module 23, wherein: The multi-dimensional feature extraction module 21 extracts spatial dimension feature vectors, temporal dimension feature vectors, and attribute dimension feature vectors based on standardized secure data streams and using a multi-head self-attention mechanism. Specifically, the multi-dimensional feature extraction module 21 is configured with three independent multi-head self-attention operation branches. These three branches execute feature extraction operations synchronously. The original outputs of each branch are mapped to a feature space of the same dimension via independent fully connected mapping layers, and the dimension of the output feature vectors of each branch remains consistent, satisfying the basic requirements for subsequent cross-modal alignment operations. The details are as follows: The spatial dimension feature extraction branch reads the asset spatial location code and network topology connectivity data within the standardized security data stream. It uses a multi-head self-attention mechanism to quantify the association weights of physical connections and business logic reachability between different asset nodes, and generates a spatial dimension feature vector representing the asset topology distribution state. The time dimension feature extraction branch takes a data stream sequence consisting of multiple consecutive 60-second time slices as input, and relies on a multi-head self-attention mechanism to mine the time-series fluctuation patterns of security indicators and the sequential triggering correlation of security events, generating a time dimension feature vector that represents the time-series evolution trend of risks. The attribute dimension feature extraction branch reads static security attributes such as asset vulnerability level, business importance, and system access permission configuration from the standardized security data stream. It quantifies the impact weight of various inherent attributes on security risks through a multi-head self-attention mechanism, and generates attribute dimension feature vectors that represent the inherent security baseline level of assets.

[0031] Finally, after the three-way feature extraction branch operation is completed, the multi-dimensional feature extraction module 21 synchronously outputs the spatial dimension feature vector, the temporal dimension feature vector, and the attribute dimension feature vector to the cross-modal feature alignment module 22.

[0032] The cross-modal feature alignment module 22 performs cross-modal feature alignment operations based on spatial dimension feature vectors, temporal dimension feature vectors, and attribute dimension feature vectors, mapping the feature vectors of each dimension to a unified feature space; Specifically, the cross-modal feature alignment module 22 configures independent learnable projection matrices for the three dimensions of space, time, and attributes, respectively, and maps the original heterogeneous feature vectors to a common feature space with uniform dimensional specifications through linear projection transformation. After the mapping is completed, L2 normalization is performed on all feature vectors in the common space to eliminate the numerical scale differences of the original features in different dimensions and avoid the problem of single-dimensional feature weight imbalance in subsequent fusion operations.

[0033] Finally, the cross-modal feature alignment module 22 synchronously completes the mapping and normalization processing of the three sets of feature vectors corresponding to all monitored assets under a single time slice, outputs the three sets of feature vectors aligned under a unified feature space, and sends them to the weighted fusion output module 23.

[0034] The weighted fusion output module 23 generates and outputs a multi-dimensional security situation feature matrix based on the feature vector aligned by the cross-modal feature alignment module 22 through learnable weighted fusion operation.

[0035] Specifically, the weighted fusion output module 23 configures independent learnable weight parameters for each feature component in the common feature space. These weight parameters can be dynamically updated iteratively according to the distribution of security events in each time-series slice, unlike fixed-weight fusion schemes. The dynamic weight update employs a periodic incremental fine-tuning mechanism, using a fixed time period as the update window. Newly added verified security event data within the window are used as fine-tuning samples, with the accuracy of risk warning simulation results as the optimization objective. The fusion weights are iteratively updated through backpropagation. The fusion operation is implemented using a component-wise weighted summation: for three sets of aligned feature vectors under the same asset and the same time-series slice, the corresponding dimension feature components are multiplied by the matching weights and then summed to obtain the comprehensive situational feature vector corresponding to the current time-series slice of the asset.

[0036] The system iterates through all monitored assets covered by the current time-series slice, arranging the comprehensive situation feature vectors generated by each asset in an orderly manner according to the asset's unique identifier. A two-dimensional structured matrix, namely the multi-dimensional security situation feature matrix, is constructed with the monitored entity as the row dimension and the fused feature components as the column dimension. The fused feature components in the column dimension correspond to three core situation attributes: spatial correlation, temporal evolution trend, and inherent risk baseline. This matrix has clear row and column definitions and uniform numerical dimensions, fully carrying the fused situation information of all assets in a single time-series slice. The weighted fusion output module 23 pushes the multi-dimensional security situation feature matrix to the downstream adaptive risk warning and inference unit 3 for heterogeneous entity topology construction and risk inference calculation.

[0037] The adaptive risk warning simulation unit 3 receives a multi-dimensional security situation feature matrix, constructs a heterogeneous entity association topology using a multi-semantic edge divide-and-conquer attention mechanism, generates a sparse simulation subgraph through security domain topology constraint mask matrix filtering and dynamic high-risk neighborhood sampling, and uses a fixed-duration sliding time window to extract recent historical propagation trajectories. The sliding time window uses a 60-second time-series slice defined by data acquisition and standardization unit 1 as the smallest unit, and the window sliding step size is equal to the single slice duration. The window contains several consecutive time-series slices, and the window duration and the number of slices can be flexibly configured according to the monitoring scenario. A dynamic propagation path memory factor is calculated and generated based on the historical propagation trajectory. The propagation dynamics parameters of the susceptible-infected-recovery state are corrected through the dynamic propagation path memory factor. Combined with the long short-term memory network, bidirectional iterative simulation is performed, and a graded warning signal including node-level risk quantification score, propagation path credibility, and expected diffusion delay is output. Specifically, it includes a heterogeneous topology construction module 31, a sparse subgraph generation module 32, a path memory factor calculation module 33, a propagation dynamics correction module 34, and a bidirectional iterative simulation module 35, wherein: The heterogeneous topology construction module 31 receives a multi-dimensional security situation feature matrix. For each monitored entity and its various relationships contained in the matrix, it calculates the attention weights of each associated edge using a multi-semantic edge divide-and-conquer attention mechanism, generating an initial heterogeneous entity association topology adjacency matrix. Specifically, the heterogeneous topology construction module 31 uses a divide-and-conquer approach with independent attention branches to calculate the weights of different semantic edges, unlike the unified single-branch calculation method of general graph attention networks. This avoids interference between semantic edges with different risk transmission characteristics, and the weight calculation is more aligned with the heterogeneous association characteristics of the security scenario. The process of the heterogeneous topology construction module 31 constructing the initial heterogeneous entity association topology adjacency tensor includes the following steps: S31.1 Analyze the multidimensional security situation feature matrix, extract the node attribute features and semantic labels of the associated edges of each monitored entity, and classify the associated edges according to four semantic categories: physical connection, network reachability, business dependence, and threat origin. In this step, let the first... The node attribute feature vector corresponding to each monitored entity is: The feature dimension is All associated edges are classified according to four semantic categories: physical connectivity, network reachability, business dependency, and threat origin. The semantic category number is denoted as follows: , These correspond to the four semantic categories mentioned above, respectively.

[0038] S31.2 Configure independent attention calculation branches and weight mapping parameters for each type of associated edge, and calculate the attention weight values ​​of the corresponding associated edges in parallel; In this step, for the first Node pairs under class semantics First, the raw attention score is calculated using a linear mapping. Then, within the corresponding semantic category range, the attention score is applied to the nodes. All outgoing edge attention raw scores are subjected to softmax normalization to obtain the final attention weight values, calculated using the following formula: ; ; Indicates the first Class semantics under node To the node Raw attention score for associated edges; , Representing nodes respectively ,node Node attribute feature vectors; This represents a vector concatenation operation; Indicates the first The learnable weight mapping parameter vector corresponding to the semantic branch of the class has a dimension of The learned parameters are obtained through end-to-end training of historical threat propagation samples using a link prediction task. All of the above learnable parameters are trained in offline mode. The training data are taken from the system's historical full security monitoring data and labeled threat propagation event samples. After training is completed, the parameters are fixed and put into online operation. No retraining is required during the operation phase. This represents the activation function for a leaky linear rectified circuit. Indicates the first Class semantics under node To the node The attention weight values ​​of the associated edges range from [0,1]. Indicates the first Class semantics under node The set of all adjacent nodes; This represents the natural exponential function.

[0039] S31.3. The attention weight values ​​of the four types of associated edges are concatenated and integrated to generate the initial heterogeneous entity association topology adjacency matrix.

[0040] In this step, the weight sub-matrices corresponding to the four semantic categories are concatenated along the channel dimension to form a multi-channel initial heterogeneous entity association topological adjacency matrix, expressed as: ; This represents the initial heterogeneous entity association topological adjacency matrix, with dimension 1. ,in To monitor the total number of entities, the channel dimension corresponds to four semantic categories; Indicates the first The adjacency submatrix corresponding to the class semantics has a dimension of The matrix elements are the attention weights of the corresponding node pairs. Unrelated entities have a value of 0 for their corresponding elements.

[0041] The sparse subgraph generation module 32 receives the initial heterogeneous entity association topological adjacency matrix, and sequentially performs invalid edge filtering through the security domain topological constraint mask matrix and node range pruning through dynamic high-risk neighborhood sampling to generate a sparse inference subgraph with controlled computational scale. The sparse subgraph generation module 32 includes a topological constraint filtering submodule and a high-risk neighborhood sampling submodule, wherein: The topology constraint filtering submodule receives the initial heterogeneous entity association topology adjacency matrix, performs element-wise multiplication between the security domain topology constraint mask matrix and the initial heterogeneous entity association topology adjacency matrix, filters out invalid association edges that do not conform to the topology constraints, and outputs a compliant topology adjacency matrix. Specifically, the security domain topology constraint mask matrix is ​​generated according to the network security domain partitioning rules. Its dimensions are consistent with the initial heterogeneous entity association topology adjacency matrix. Within the same security domain, compliant associations have elements with a value of 1, while unauthorized associations across security domains have elements with a value of 0. The four semantic channels share the same topology constraint rules. The element-level multiplication formula is as follows: ; Represents a compliant topological adjacency matrix, with dimensions and Consistent; Represents the element-wise multiplication (Hadamard product) operation of matrices; Represents the topological constraint mask matrix of the security domain, which is related to... A 0-1 matrix of the same dimension.

[0042] The high-risk neighborhood sampling submodule receives the compliant topology adjacency matrix, analyzes the situation characteristics of each monitored entity in the multi-dimensional security situation feature matrix, and calculates the initial risk score of the node. This score is calculated uniformly for all monitored entities, and the value is retained and participates in subsequent dynamic initialization regardless of whether it is selected as a seed node. A fixed risk score threshold is set, and entities with an initial risk score higher than the preset threshold are judged as high-risk seed nodes. High-risk seed nodes are selected based on the initial risk score of the node, and nodes and corresponding associated edges within the k-hop neighborhood of the seed node are sampled to generate a sparse inference subgraph.

[0043] Specifically, the formula for calculating the initial risk score of a node is as follows: ; Indicates the first The initial risk score of each monitored entity node, with a value range of [0,1]; This represents the sigmoid activation function; This represents the initial risk score calculation weight vector, with dimension 1. The weight vector is trained using the cross-entropy loss function from historically labeled risk samples. It is trained offline and then permanently used; it is not updated during online operation. High-risk seed nodes are selected in descending order of their initial risk scores, with the number preset based on the system's computing power. `k` is the maximum number of hops for neighborhood sampling, a positive integer, specifically configured according to the network asset size: 2-3 hops for small to medium-sized monitoring networks and 1-2 hops for large networks. The generated sparse inference subgraph is denoted as... The total number of monitored entities included is denoted as .

[0044] The path memory factor calculation module 33 receives the sparse inference subgraph, combines it with the historical propagation trajectory within the sliding time window, performs feature encoding and evolution law matching calculation on the candidate propagation paths within the subgraph, and generates a dynamic propagation path memory factor corresponding to each candidate path; the process of generating the dynamic propagation path memory factor by the path memory factor calculation module 33 includes the following steps: S33.1 Extract the historical propagation trajectory within the sliding time window, extract the node access order, propagation direction and semantic transformation relationship of associated edges from the trajectory, perform feature encoding on each candidate propagation path, and generate candidate propagation path state vector; In this step, candidate propagation paths are limited to all simple paths within the sparse inference subgraph that start from a high-risk seed node and have no more than k hops. They also include valid acyclic paths between other nodes within the subgraph. During traversal, paths with cycles and duplicate paths are automatically removed, retaining only valid acyclic simple paths for feature encoding and computation. Feature encoding is achieved by concatenating node attribute feature sequences and edge semantic category sequences, then mapping them to a fixed-dimensional vector via a fully connected layer. Let the... The candidate propagation path state vector corresponding to each candidate propagation path is .

[0045] S33.2 Calculate the cosine similarity between the candidate propagation path state vector and the threat evolution baseline feature vector statistically extracted from the historical propagation trajectory to obtain the path evolution matching degree; In this step, the threat evolution baseline feature vector is generated by averaging the state vectors corresponding to historically verified typical threat propagation paths, with the same dimension as the candidate propagation path state vectors. The cosine similarity calculation formula is: ; Indicates the first The path evolution matching degree of the candidate propagation paths, with a value range of [-1, 1]; Indicates the first The candidate propagation path state vector corresponding to each candidate propagation path; Represents the baseline eigenvectors of threat evolution; This represents the vector dot product operation; This represents the L2 norm of a vector.

[0046] S33.3 After multiplying the path evolution matching degree by the preset adjustment coefficient, the result is mapped to a numerical range of 0 to 1 using the sigmoid function to obtain the dynamic propagation path memory factor of the corresponding candidate propagation path.

[0047] In this step, the formula for calculating the dynamic propagation path memory factor is as follows: ; Indicates the first The dynamic propagation path memory factor corresponding to each candidate propagation path has a value range of [0, 1]. This represents the preset adjustment coefficient, a dimensionless positive real number used to control the mapping sensitivity. In engineering, it is usually set to 1~5, and the value is selected according to the degree of dispersion of the threat trajectory. If the trajectory difference is large, a larger value is selected. The default value in normal scenarios is 2.

[0048] The propagation dynamics correction module 34 receives the sparse inference subgraph and the dynamic propagation path memory factor, and embeds the dynamic propagation path memory factor as a propagation adjustment parameter into the susceptible-infected-recovery state propagation dynamics iterative calculation process to correct three types of propagation dynamics parameters corresponding to each associated edge: risk trigger probability, expected arrival delay, and risk attenuation magnitude. The process of the propagation dynamics correction module 34 in correcting the susceptible-infected-recovery state propagation dynamics parameters includes the following steps: S34.1 Configure three types of initial state parameters—susceptibility, infectivity, and recovery—for each monitoring entity within the sparse extrapolation subgraph, and construct a basic computational framework for the propagation dynamics of the susceptibility-infectivity-recovery state. In this step, the three types of initial state parameters are defined as follows: Indicates the first The susceptibility of a monitored entity represents the degree to which the entity is susceptible to risk infection. The initial value is set based on the entity's inherent security attributes. Indicates the first The infectivity of a monitored entity characterizes the entity's ability to carry risk and spread it outwards. The initial value is set based on the node's initial risk score. Indicates the first The recoverability of a monitored entity characterizes the entity's ability to recover from a risky state to a safe state, with the initial value set based on the entity's protection capabilities; The three types of initial state parameters satisfy the normalization constraint. The values ​​of each parameter are all in the range of [0,1].

[0049] S34.2. The dynamic propagation path memory factor of the corresponding candidate propagation path is used as the propagation adjustment parameter and embedded in the iterative calculation process of propagation dynamics. The dynamic propagation path memory factor is used as the weighting coefficient to correct the basic risk trigger probability, and the expected arrival delay and risk attenuation magnitude are adjusted accordingly. In this step, the dynamic propagation path memory factor is generated on a per-candidate propagation path basis, while the propagation dynamics calculation is performed on a per-single-association-edge basis. Therefore, the mapping rule between the two is first established: for any associate edge within the sparse inference subgraph The dynamic propagation path memory factor corresponding to the path with the highest path evolution matching degree among all candidate propagation paths is selected as the edge-level memory factor corresponding to the associated edge. For associated edges that do not belong to any candidate propagation path, their edge-level memory factor is set to a fixed default value of 0.5. The default value of 0.5 means that such associated edges have no historical propagation trajectory reference and participate in the calculation with medium risk transmission capacity. Such associated edges participate normally in subsequent propagation dynamics iterations and are not subject to special shielding.

[0050] Based on this, three types of parameters are adjusted using the edge-level memory factor as a weighting coefficient: the risk trigger probability increases positively with the memory factor, matching the strong propagation capability of historically high-incidence paths; the expected arrival delay decreases negatively with the memory factor, matching the rapid spread of historically high-incidence paths; and the risk attenuation magnitude decreases synchronously with the memory factor, matching the low propagation loss of historically high-incidence paths. The basic risk trigger probability, basic expected arrival delay, and basic risk attenuation magnitude are pre-configured based on the protection level of the monitored asset, its security domain, and historical threat baseline. The correction formulas for the three types of propagation dynamics parameters are as follows: ; ; ; Indicates the corrected node To the node The probability of risk triggering propagation, dimensionless, with a value range of [0,1]. Represents a node To the node The basic risk trigger probability of propagation is a preset initial parameter, dimensionless, with a value range of [0,1]. This indicates that the corrected risk originates from the node. Diffusion to nodes The estimated arrival time is measured in seconds; Indicates risk from nodes Diffusion to nodes The estimated arrival time is based on preset initial parameters, and the unit is seconds. Indicates the corrected risk along the node To node The risk attenuation magnitude of path propagation, dimensionless, with a value range of [0,1]. Indicates risk along nodes To node The basic risk attenuation magnitude of path propagation is a preset initial parameter, dimensionless, with a value range of [0,1]. Indicates associated edges The corresponding edge memory factor has a value range of [0,1].

[0051] S34.3. Perform multiple rounds of propagation iteration calculations based on the corrected parameters to obtain the real-time risk status parameters of each monitored entity.

[0052] In this step, the iterative calculation follows the union probability rule of independent events, calculating the joint probability of non-occurrence of infection events among multiple neighboring nodes through a multiplication method, thus avoiding probability overflow caused by the superposition of multi-path infection contributions. Simultaneously, a transformation mechanism from infected to recovered state is incorporated into the iteration, fully covering the dynamic characteristics of the entire process from susceptible to infected and from infected to recovered states. Node recovery rate. The value range is [0,1], which is set according to the node protection capability, and can be slightly adaptively adjusted in conjunction with the dynamic propagation path memory factor; this step is a steady-state iteration of the SEIR model within a single time window, and the iteration process continues until the convergence threshold is met; a maximum number of iterations is set as a fallback, and if convergence is not achieved after the maximum number of iterations is reached, the process is forcibly terminated, and the state of the last iteration is taken as the result.

[0053] No. The state update formula for each iteration is: ; ; ; ; superscript , They represent the first Wheel, First The parameter values ​​corresponding to the round iteration; Indicates the first Nodes in round iteration The probability of incremental infection, dimensionless; Represents nodes in a sparse inference subgraph The set of all adjacent nodes; This represents a multiplication operation, corresponding to the joint probability that multiple independent infection events do not occur; Represents a node The unit iteration step recovery rate is dimensionless and ranges from [0,1], set according to the node protection capability.

[0054] After the iteration reaches the preset basic rounds, if the iteration reaches the preset maximum rounds and still has not entered a stable state, the iteration is forcibly terminated, and the state parameters of the last round are taken as the calculation result, and the real-time risk state parameters of each monitored entity are output.

[0055] The bidirectional iterative deduction module 35, combined with a long short-term memory network, performs spatiotemporal bidirectional iterative deduction on the corrected propagation dynamics state. After iterating until convergence, it completes node risk quantification and path reliability assessment, outputting a graded early warning signal containing node-level risk quantification scores, propagation path reliability, and expected diffusion delay. The process of the bidirectional iterative deduction module 35 executing bidirectional iterative deduction and outputting graded early warning signals includes the following steps: S35.1. Use the global risk baseline output by the Long Short-Term Memory Network as the initial state parameter for propagation dynamics calculation and input it into the propagation dynamics correction module 34. In this step, the Long Short-Term Memory (LSTM) network is pre-trained based on historical sliding window risk time-series data and can output a global risk baseline corresponding to the current time-series slice. This is used to uniformly calibrate the initial infection level of each node. The initial infection level calibration formula is: ; Indicates the node after calibration The initial infectivity parameter; This represents the global risk baseline output by the Long Short-Term Memory (LSTM) network. It is dimensionless and ranges from 0 to 1. A value of 0 indicates no overall risk in the current domain, while a value of 1 indicates the domain is at a high-risk baseline. Both boundary values ​​are normally used in the initial infection rate calibration calculation. After the initial infection rate calibration is completed, the baseline ratio of the node's initial susceptibility to its recovery rate is kept constant, and their values ​​are adjusted proportionally according to the normalization constraint to ensure that the initial state always meets the requirements. During the current sliding window derivation process, the sparse derivation subgraph structure, dynamic propagation path memory factor, and corrected propagation dynamics parameters remain fixed and do not change dynamically with the iteration process.

[0056] S35.2 Feedback the node risk time series results output by the propagation dynamics correction module 34 to the long short-term memory network to adjust the prediction parameters of the next sliding window; In this step, the feedback node risk time series results include the state change sequence of each node in the current window across all iterations. The Long Short-Term Memory (LSTM) network performs incremental training based on this sequence, updating its internal weight parameters to improve the prediction accuracy of the global risk baseline for the next sliding window. The LTM network's weight updates only apply to subsequent sliding windows and do not participate in the iterative calculation of the current window, thus avoiding data circular dependency issues.

[0057] S35.3 Repeat the forward input and reverse correction process until the change in the node risk state parameter is lower than the preset convergence threshold, and complete the iterative convergence. In this step, the bidirectional iterative deduction module 35 repeatedly performs state iterative calculations, and each complete update of the full node state is counted as one iteration. When the average absolute change in node infection level obtained from two adjacent iterations is lower than the preset convergence threshold, the iteration is considered converged, and the iterative calculation is stopped. The convergence determination formula is: ; This represents the total number of monitored entities contained in the sparse inference subgraph; This represents the preset convergence threshold, which is a dimensionless positive real number. In engineering, it is usually set to 0.001~0.01. If the early warning accuracy requirement is high, a smaller value is used. The default value for general safety monitoring scenarios is 0.005. This represents absolute value operations.

[0058] S35.4 Based on the converged node risk state parameters, calculate the node-level risk quantification score, propagation path credibility, and expected diffusion delay, and generate and output graded early warning signals.

[0059] In this step, the implementation process of calculating the three types of early warning dimension indicators, generating and outputting graded early warning signals is as follows: The first type is node-level risk quantification scoring, which directly takes the infection rate value of the converged node as the scoring result, i.e., the node... The node-level risk quantification score for each node is the converged infectivity score. The higher the value, the higher the risk level of the node.

[0060] The second category is the credibility of the propagation path, which is calculated by combining the historical propagation patterns and theoretical propagation probabilities of the path. It reflects both the degree of matching between the path and the evolution of historical threats, as well as the transmission capability of the path itself. The calculation formula is as follows: ; Indicates the first The reliability of the propagation path, with a value range of [0,1]. Indicates the first The dynamic propagation path memory factor corresponding to each candidate propagation path; Indicates the first All associated edges contained in the path.

[0061] The third category is the estimated diffusion delay. This involves traversing all reachable candidate paths from the high-risk seed node to the target node, and taking the minimum total path delay as the estimated diffusion delay. The calculation formula is as follows: ; This indicates that the risk has spread to the node. The expected diffusion delay, in seconds; This indicates the path from the high-risk seed node to the node. The set of all candidate propagation paths.

[0062] If no reachable candidate path exists for the target node, its latency is marked as infinite, and the corresponding node is classified as low-risk by default.

[0063] Finally, after the calculation of the three types of indicators is completed, the bidirectional iterative deduction module 35 performs a graded judgment. The warning level is set with reference to the "Information Security Technology - Network Security Warning Guide" (GB / T32924-2016) and the general four-level classification framework of the National Network Security Incident Emergency Response Plan, from low to high as follows: Blue (General Warning), Yellow (Significant Warning), Orange (Major Warning), and Red (Extremely Major Warning). The classification threshold is determined with reference to the risk level classification rules of "Information Security Technology - Information Security Risk Assessment Method" (GB / T20984-2022), the machine learning confidence judgment engineering criteria, and the network security emergency response time granularity specification, combined with the normalized value range of 0~1 of the output parameters in this embodiment. It can be dynamically adjusted according to the asset importance and protection level requirements of the monitoring scenario. The specific judgment rules are as follows: Core Indicators Basic Tier: Using node-level risk quantification scoring as the core judgment criterion, and referring to the industry-standard normalization rule that maps five-level risk levels to four-level early warning, the boundary threshold is set. The basic alert level is blue (general warning); when The basic alert level is yellow, indicating a relatively high level of alert; when The basic alert level is orange, indicating a major warning. The basic alert level is red, indicating an extremely serious situation.

[0064] Adjustment of auxiliary indicator levels: Using the credibility of the propagation path and the expected diffusion delay as auxiliary correction dimensions, adjustment conditions are set with reference to commonly used confidence thresholds and emergency response time levels in engineering. If the corresponding propagation path credibility... (High confidence interval, meeting the general credibility criteria for risk transmission determination) and expected diffusion delay If the spread is rapid (within seconds or minutes, corresponding to high-priority emergency response scenarios), the basic level will be raised by one level; if the credibility of the corresponding propagation path is... (Low confidence interval, limited reference value) and expected diffusion delay If the risk level is within seconds (slow spread range, sufficient time window for emergency response), the basic risk level will be downgraded by one level. These two adjustment conditions are mutually exclusive. In special scenarios where both conditions are met simultaneously, the basic risk level of the node will prevail, and no upgrade or downgrade will be made.

[0065] Boundary constraints: After the level adjustment, the highest level shall not exceed the red extremely serious warning and the lowest level shall not be lower than the blue general warning; if the expected diffusion delay of a node is infinite, that is, there is no reachable risk propagation path, it shall be directly judged as a blue general warning.

[0066] Finally, once the grading is complete, the bidirectional iterative deduction module 35 generates a graded early warning signal that includes node-level risk quantification scores, propagation path credibility, and expected diffusion delay, and outputs it to the decision strategy generation and interpretable output unit 4.

[0067] The decision strategy generation and interpretable output unit 4 receives tiered early warning signals, matches and generates corresponding response plans and risk tracing explanations, and completes structured output through a visual interactive interface. Specifically, it includes an early warning signal parsing module 41, a response strategy matching module 42, and an interpretable visual output module 43, wherein: The early warning signal analysis module 41 receives graded early warning signals and analyzes and extracts three types of early warning dimension data: node-level risk quantification score, propagation path credibility, and expected diffusion delay. Specifically, the early warning signal parsing module 41 performs field decomposition and structured conversion on the input hierarchical early warning signals. The system supports the concurrent reception of multiple early warning messages, prioritizing their processing according to their early warning level from high to low. Early warnings of the same level are processed in order of their acquisition time. The system extracts the monitoring entity identifier, early warning level, and node-level risk quantification score corresponding to each early warning. The credibility of the propagation path corresponding to the associated propagation path Expected diffusion delay Five categories of core information; synchronous data integrity verification is performed. The key fields for this verification include five categories: monitoring entity identifier, warning level, node-level risk quantification score, propagation path credibility, and expected spread delay. If any key field is missing, it is directly judged as an invalid warning message and removed. If the indicator value exceeds the preset value range, it is also marked as an invalid warning message. The valid data is organized into a structured warning dataset with a unified format. The dataset uses a single warning as an independent entry and stores all field information in a key-value pair format. It is then completely transmitted to the handling strategy matching module 42.

[0068] The response strategy matching module 42 generates a response plan and risk tracing explanation of the corresponding level based on the three types of early warning dimension data extracted by the early warning signal analysis module 41. Specifically, the handling strategy matching module 42 has a built-in pre-set hierarchical handling strategy library. This library is categorized and stored using the warning level as the main index. Each warning level corresponds to a set of standardized handling solutions. The strategy library is compiled with reference to the general specifications for emergency response to cybersecurity incidents and the security control requirements of graded protection. Differentiated handling procedures are set for the four warning levels, covering four types of handling intensity: monitoring and verification, isolation and investigation, threat blocking, and emergency response. The matching process is based on the warning level and makes fine-tuning adjustments by combining three dimensions of data: Basic level matching: Based on the warning level, the corresponding basic handling plan is retrieved from the policy library. Blue general warning corresponds to asset inspection and log verification plan; yellow major warning corresponds to risk isolation and vulnerability investigation plan; orange major warning corresponds to threat blocking and attack tracing plan; red extremely major warning corresponds to full-domain emergency response and business degradation plan. Each plan includes clear handling steps, responsible roles and operating procedures.

[0069] Slight adjustment of the handling intensity: if the credibility of the transmission path is low And the expected diffusion delay Seconds, based on the basic plan, supplement pre-processing steps and shorten the response time; if the propagation path is credible And the expected diffusion delay To prevent mishandling from affecting business continuity, the basic solution is modified by adding an information verification step and delaying mandatory handling operations. If the credibility of the propagation path and the expected propagation delay do not meet the above two types of fine-tuning conditions, the basic handling solution is directly adopted without additional adjustments.

[0070] Risk source tracing description generation: Simultaneously extract three types of source tracing information corresponding to the early warning: high-risk seed nodes, core propagation paths, and key transmission links. Combine this with the node risk contribution ratio ranking, which is calculated based on the node risk quantification score and the comprehensive impact of the propagation path. Nodes are ranked from highest to lowest contribution ratio. The source tracing description forms standardized text content with the risk source, propagation link, and high-risk nodes as the main body, generating a structured risk source tracing description that clearly identifies the risk spread source, main propagation link, and key protection nodes. After the response strategy matching module 42 completes the scheme matching and source tracing description generation, it outputs the corresponding early warning response plan and risk source tracing description, transmitting them to the interpretable and visualized output module 43.

[0071] The interpretable visualization output module 43 performs structured integration processing on the disposal plan and risk tracing description generated by the disposal strategy matching module 42, and completes the output through a visual interactive interface.

[0072] Specifically, the interpretable visualization output module 43 performs multi-dimensional integrated presentation of the received handling plan, risk tracing explanation, and early warning indicator data, as follows: High-risk nodes, risk propagation paths, and risk transmission directions are marked on the network topology view, and the node-level risk quantification score is mapped by the color intensity. The data panel area displays four core indicators in a structured manner: early warning level, node risk score, propagation path credibility, and expected spread delay. The handling guidance area displays the handling plan and key points of operation step by step, and the risk tracing explanation is also attached for operators to refer to.

[0073] In addition, the visual interactive interface supports interactive operations such as node drill-down, path backtracking, and viewing details of handling steps. The visual interface supports role-based data permission isolation, allowing different operation and maintenance roles to view asset warning information only within their authorized scope. If the current warning has no effective risk propagation path, the topology view only marks high-risk nodes and does not draw the propagation path. All interactive operations are equipped with a response timeout mechanism, which retains the current page content and displays the operation status after the timeout, ensuring that security operation personnel can intuitively understand the risk causes, propagation logic, and handling basis, achieving interpretable output of warning results. After the interpretable visual output module 43 completes integration and rendering, it outputs complete warning handling and tracing information to the terminal through the visual interactive interface.

[0074] Those skilled in the art will understand that the process of implementing all or part of the steps of the above embodiments can be carried out by hardware or by a program instructing the relevant hardware.

[0075] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention.

Claims

1. An artificial intelligence-based multi-dimensional data fusion security early warning decision support system, characterized in that, include: The data acquisition and standardization unit (1) receives multi-source heterogeneous security monitoring data, performs standardization preprocessing on the multi-source heterogeneous security monitoring data, and outputs a time-consistent standardized security data stream. The data fusion and situation feature extraction unit (2) receives a standardized security data stream, performs multi-dimensional feature extraction and fusion processing on the standardized security data stream, and outputs a multi-dimensional security situation feature matrix. The adaptive risk warning simulation unit (3) receives a multi-dimensional security situation feature matrix, constructs a heterogeneous entity association topology using a multi-semantic edge divide-and-conquer attention mechanism, generates a sparse simulation subgraph by filtering the security domain topology constraint mask matrix and sampling the dynamic high-risk neighborhood, calculates and generates a dynamic propagation path memory factor based on the historical propagation trajectory, corrects the susceptible-infection-recovery state propagation dynamic parameters through the dynamic propagation path memory factor, performs bidirectional iterative simulation in combination with the long short-term memory network, and outputs a graded warning signal containing node-level risk quantification score, propagation path credibility and expected diffusion delay. The decision strategy generation and interpretable output unit (4) receives the graded early warning signal, matches and generates the corresponding disposal plan and risk tracing explanation, and completes the structured output through the visual interactive interface.

2. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 1, characterized in that, The data acquisition and standardization unit (1) includes a multi-source data access module (11), a data cleaning and normalization module (12), and a time-series aligned output module (13), wherein: The multi-source data access module (11) is used to access multi-source heterogeneous security monitoring data and completes protocol adaptation and data caching of different data sources through a distributed message queue protocol. The data cleaning and regularization module (12) uses a unified semantic data model to complete field format mapping and abnormal data removal based on the multi-source heterogeneous security monitoring data cached by the multi-source data access module (11). The time-series alignment output module (13) performs timestamp alignment calibration and missing value interpolation processing on the data processed by the data cleaning and normalization module (12) to generate a time-series consistent standardized secure data stream and output it.

3. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 1, characterized in that, The data fusion and situation feature extraction unit (2) includes a multi-dimensional feature extraction module (21), a cross-modal feature alignment module (22), and a weighted fusion output module (23), wherein: The multi-dimensional feature extraction module (21) extracts spatial dimension feature vectors, temporal dimension feature vectors and attribute dimension feature vectors respectively based on standardized secure data stream and multi-head self-attention mechanism; The cross-modal feature alignment module (22) performs cross-modal feature alignment operations based on spatial dimension feature vectors, temporal dimension feature vectors and attribute dimension feature vectors, mapping the feature vectors of each dimension to a unified feature space; The weighted fusion output module (23) generates a multidimensional security situation feature matrix and outputs it based on the feature vector aligned by the cross-modal feature alignment module (22) through learnable weighted fusion operation.

4. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 1, characterized in that, The adaptive risk warning simulation unit (3) includes a heterogeneous topology construction module (31), a sparse subgraph generation module (32), a path memory factor calculation module (33), a propagation dynamics correction module (34), and a bidirectional iterative simulation module (35), wherein: The heterogeneous topology construction module (31) receives a multi-dimensional security situation feature matrix, and calculates the attention weight of each associated edge through a multi-semantic edge divide-and-conquer attention mechanism for each monitored entity and its various association relationships contained in the matrix, thereby generating an initial heterogeneous entity association topology adjacency matrix. The sparse subgraph generation module (32) receives the initial heterogeneous entity association topology adjacency matrix, and sequentially performs invalid edge filtering through the security domain topology constraint mask matrix and node range pruning through dynamic high-risk neighborhood sampling to generate a sparse inference subgraph with controlled computational scale. The path memory factor calculation module (33) receives the sparse inference subgraph, combines the historical propagation trajectory within the sliding time window, performs feature encoding and evolution law matching calculation on the candidate propagation paths in the subgraph, and generates the dynamic propagation path memory factor corresponding to each candidate path; The propagation dynamics correction module (34) receives the sparse derivation subgraph and the dynamic propagation path memory factor, and embeds the dynamic propagation path memory factor as a propagation adjustment parameter into the susceptible-infected-recovery state propagation dynamics iterative calculation process to correct the three types of propagation dynamics parameters corresponding to each associated edge: risk trigger probability, expected arrival delay and risk attenuation magnitude. The bidirectional iterative deduction module (35) combines a long short-term memory network to perform spatiotemporal bidirectional iterative deduction on the corrected propagation dynamics state. After the result converges, it completes node risk quantification and path credibility assessment, and outputs a graded early warning signal containing node-level risk quantification score, propagation path credibility and expected diffusion delay.

5. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 4, characterized in that, The process of constructing the initial heterogeneous entity association topology adjacency matrix by the heterogeneous topology construction module (31) includes the following steps: S31.1 Analyze the multidimensional security situation feature matrix, extract the node attribute features and semantic labels of the associated edges of each monitored entity, and classify the associated edges according to four semantic categories: physical connection, network reachability, business dependence, and threat origin. S31.2 Configure independent attention calculation branches and weight mapping parameters for each type of associated edge, and calculate the attention weight values ​​of the corresponding associated edges in parallel; S31.

3. The attention weight values ​​of the four types of associated edges are concatenated and integrated to generate the initial heterogeneous entity association topology adjacency matrix.

6. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 4, characterized in that, The sparse subgraph generation module (32) includes a topological constraint filtering submodule and a high-risk neighborhood sampling submodule, wherein: The topology constraint filtering submodule receives the initial heterogeneous entity association topology adjacency matrix, performs element-wise multiplication between the security domain topology constraint mask matrix and the initial heterogeneous entity association topology adjacency matrix, filters out invalid association edges that do not conform to the topology constraints, and outputs a compliant topology adjacency matrix. The high-risk neighborhood sampling submodule receives the compliant topology adjacency matrix, analyzes the situation characteristics of each monitored entity in the multi-dimensional security situation feature matrix, calculates the initial risk score of the node, selects high-risk seed nodes based on the initial risk score of the node, samples the nodes and corresponding associated edges within the k-hop neighborhood of the seed node, and generates a sparse inference subgraph.

7. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 4, characterized in that, The process of generating dynamic propagation path memory factors by the path memory factor calculation module (33) includes the following steps: S33.1 Extract the historical propagation trajectory within the sliding time window, extract the node access order, propagation direction and semantic transformation relationship of associated edges from the trajectory, perform feature encoding on each candidate propagation path, and generate candidate propagation path state vector; S33.2 Calculate the cosine similarity between the candidate propagation path state vector and the threat evolution baseline feature vector statistically extracted from the historical propagation trajectory to obtain the path evolution matching degree; S33.3 After multiplying the path evolution matching degree by the preset adjustment coefficient, the result is mapped to a numerical range of 0 to 1 using the sigmoid function to obtain the dynamic propagation path memory factor of the corresponding candidate propagation path.

8. The AI-based multi-dimensional data fusion security early warning decision support system according to claim 4, characterized in that, The process of the transmission dynamics correction module (34) correcting the transmission dynamics parameters of the susceptible-infected-recovery state includes the following steps: S34.1 Configure three types of initial state parameters—susceptibility, infectivity, and recovery—for each monitoring entity within the sparse extrapolation subgraph, and construct a basic computational framework for the propagation dynamics of the susceptibility-infectivity-recovery state. S34.

2. The dynamic propagation path memory factor of the corresponding candidate propagation path is used as the propagation adjustment parameter and embedded in the iterative calculation process of propagation dynamics. The dynamic propagation path memory factor is used as the weighting coefficient to correct the basic risk trigger probability, and the expected arrival delay and risk attenuation magnitude are adjusted accordingly. S34.

3. Perform multiple rounds of propagation iteration calculations based on the corrected parameters to obtain the real-time risk status parameters of each monitored entity.

9. The multi-dimensional data fusion security early warning decision support system based on artificial intelligence according to claim 1, characterized in that, The process by which the bidirectional iterative deduction module (35) performs bidirectional iterative deduction and outputs graded early warning signals includes the following steps: S35.

1. Use the global risk baseline output by the long short-term memory network as the initial state parameter for propagation dynamics calculation and input it into the propagation dynamics correction module (34). S35.

2. Feed back the node risk time series results output by the propagation dynamics correction module (34) to the long short-term memory network and adjust the prediction parameters of the next sliding window. S35.3 Repeat the forward input and reverse correction process until the change in the node risk state parameter is lower than the preset convergence threshold, and complete the iterative convergence. S35.4 Based on the converged node risk state parameters, calculate the node-level risk quantification score, propagation path credibility, and expected diffusion delay, and generate and output graded early warning signals.

10. The multi-dimensional data fusion security early warning decision support system based on artificial intelligence according to claim 1, characterized in that, The decision strategy generation and interpretable output unit (4) includes an early warning signal parsing module (41), a disposal strategy matching module (42), and an interpretable visualization output module (43), wherein: The warning signal analysis module (41) receives the graded warning signal and analyzes and extracts three types of warning dimension data: node-level risk quantification score, propagation path credibility and expected diffusion delay. The disposal strategy matching module (42) generates corresponding disposal plans and risk tracing descriptions based on the three types of early warning dimension data extracted by the early warning signal analysis module (41). The interpretable visualization output module (43) performs structured integration processing based on the disposal plan and risk tracing description generated by the disposal strategy matching module (42), and completes the output through the visualization interactive interface.