A network communication situation awareness system for intelligent building operation safety
Patent Information
- Application Number
- CN202611048087.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-15
- Publication Date
- 2026-09-29
AI Technical Summary
[0006]本发明的目的在于提供一种面向智慧楼宇运行安全的网络通信态势感知系统,以解决现有技术中异构网络数据难以融合分析、对未知威胁识别能力不足、缺乏全局态势实时感知与预测分析能力等技术问题
[0022]与现有技术相比,本发明的优点和积极效果在于:
Smart Images

Figure CN122845237A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of digital information transmission, and specifically relates to a network communication situational awareness system for the safe operation of smart buildings. Background Technology
[0002] With the rapid development of next-generation information technologies such as the Internet of Things, artificial intelligence, and big data, smart buildings, as the core carrier of building intelligence, have become an important component of the digital transformation of modern cities. Smart buildings achieve the dual goals of efficient energy utilization and safe operational management by integrating and intelligently controlling systems such as heating, ventilation, air conditioning, lighting, fire protection, and security within the building. In this system, network communication, as the infrastructure connecting various intelligent devices and management systems, undertakes key functions such as data collection, transmission, and control command issuance. Its stability and security directly affect the overall operational efficiency of the smart building.
[0003] Network communication situational awareness technology is a key component in ensuring the safe operation of smart buildings. Situational awareness aims to comprehensively perceive the current status, trends, and potential risks of network communication by collecting multi-source information such as network traffic data, equipment operating status, and security event logs, based on data analysis and mining techniques, thereby providing support for security decision-making and emergency response.
[0004] However, existing network communication management in smart buildings still faces significant challenges: the complexity of the network architecture leads to a wide variety of devices and protocols, making it difficult to effectively integrate and analyze heterogeneous network data; traditional security protection methods rely heavily on feature matching and rule detection, which are insufficient in identifying unknown threats and advanced persistent attacks; existing network management systems lack the ability to perceive and predict the overall communication situation in real time, making it difficult to proactively warn and respond quickly to network security risks. Furthermore, in smart buildings where multiple business systems coexist and are jointly managed, the network attack surface is large and attack paths are numerous. Once a security incident occurs, it can easily trigger a chain reaction, seriously impacting the safety of people's lives and property.
[0005] Therefore, there is an urgent need for a network communication situational awareness system for the safe operation of smart buildings, in order to achieve comprehensive, real-time, and intelligent perception and risk warning of the building network communication environment. Summary of the Invention
[0006] The purpose of this invention is to provide a network communication situational awareness system for the safe operation of smart buildings, in order to solve the technical problems in the prior art, such as the difficulty in integrating and analyzing heterogeneous network data, insufficient ability to identify unknown threats, and lack of real-time global situational awareness and predictive analysis capabilities.
[0007] The technical solution of the present invention includes a multi-source data acquisition unit, a heterogeneous data fusion unit, an intelligent threat detection unit, a situation prediction and analysis unit, and an early warning command and dispatch unit.
[0008] The multi-source data acquisition unit is used to collect network traffic data, device operating status data, security event log data, and building automation system data from various intelligent devices within the smart building. The network traffic data includes, but is not limited to, TCP protocol data packets, UDP protocol data packets, and HTTP protocol data packets. The device operating status data includes, but is not limited to, device CPU utilization, memory usage, network bandwidth usage, and device online time. The security event log data includes, but is not limited to, user login authentication records, access control policy change records, and system alarm records. The building automation system data includes, but is not limited to, fire alarm signals, security intrusion alarm signals, and building automation system operating parameters.
[0009] The heterogeneous data fusion unit is used to perform standardization processing, protocol parsing, and correlation fusion on various types of data collected by the multi-source data acquisition unit. The standardization processing includes data format unification, timestamp alignment, and data cleaning. The protocol parsing process includes extracting message header information from different network protocols and decoding payload content. The correlation fusion process includes cross-data source event correlation based on time windows and network entity identification based on device fingerprints.
[0010] As one embodiment of the present invention, the heterogeneous data fusion unit further includes a protocol conversion module, which is used to uniformly convert the data formats of building automation special protocols such as BACnet, Modbus, KNX and ZigBee existing in the building into standard IP data formats, so as to realize the normalization processing of heterogeneous network data.
[0011] As one embodiment of the present invention, the heterogeneous data fusion unit further includes a data quality assessment module, which is used to quantitatively assess the integrity, consistency and timeliness of the fused data, and to mark or filter low-quality data according to the assessment results, so as to ensure the reliability of the subsequent analysis process.
[0012] The intelligent threat detection unit is used to perform multi-dimensional network security threat detection based on the fused data output by the heterogeneous data fusion unit; the multi-dimensional network security threat detection includes anomaly detection based on traffic behavior characteristics, intrusion detection based on sequence pattern mining, and association threat analysis based on knowledge graphs.
[0013] In one embodiment of the present invention, the anomaly detection based on traffic behavior features is implemented using a deep autoencoder model; the deep autoencoder model includes an encoder network and a decoder network; the encoder network is used to compress the input high-dimensional traffic feature data into a low-dimensional latent space to extract the implicit representation of the traffic data; the decoder network is used to reconstruct the low-dimensional latent representation into the original dimensional data; the reconstruction error is used to characterize the degree of anomaly of the traffic data; when the reconstruction error exceeds a preset anomaly threshold, it is determined that the current traffic data has abnormal behavior.
[0014] As one embodiment of the present invention, the intrusion detection based on sequence pattern mining is implemented using a long short-term memory network; the long short-term memory network is used to learn the temporal dependencies of network traffic sequences and classify and identify traffic sequences based on the learned temporal patterns in order to detect known types of network intrusion behavior.
[0015] As one embodiment of the present invention, the knowledge graph-based association threat analysis includes an entity construction module and a relationship reasoning module; the entity construction module is used to extract network attack-related entity information from the fused data, including attacker IP address, target device, attack method type and attack time window; the relationship reasoning module is used to infer the attack association relationship between entities based on the preset attack knowledge graph topology structure, so as to identify the attack chain of advanced persistent threats.
[0016] The situation prediction and analysis unit is used to perform time-series prediction and trend evolution analysis of network communication situation based on the detection results of the intelligent threat detection unit and the fused data of the heterogeneous data fusion unit. The time-series prediction is implemented using a spatiotemporal joint prediction model. The spatiotemporal joint prediction model includes a spatial feature extraction subnetwork and a temporal feature extraction subnetwork. The spatial feature extraction subnetwork is used to capture the spatial correlation between different network segments and devices. The temporal feature extraction subnetwork is used to capture the temporal pattern of network situation evolution over time. The spatial features and temporal features are fused and input into the prediction output layer to generate network situation prediction values within the future time window.
[0017] As one embodiment of the present invention, the situation prediction and analysis unit further includes a situation evolution simulation module, which is used to simulate the network situation evolution path under different attack strategies based on a multi-agent reinforcement learning framework; the multi-agent reinforcement learning framework is configured with agents representing different attacker roles and agents representing defender roles; through iterative learning of strategies by both attackers and defenders, a variety of possible situation evolution scenarios are generated, and the probability of occurrence of each scenario is labeled to assist in security decision-making.
[0018] As one embodiment of the present invention, the situation prediction and analysis unit further includes a risk level assessment module, which is used to comprehensively consider the threat severity, threat impact range and threat duration in the threat detection results, and output a comprehensive risk level score of the network communication situation; the comprehensive risk level score is calculated using a weighted summation model, and the weight parameters are determined based on the statistical analysis results of historical security events.
[0019] The early warning command and dispatch unit is used to receive the situation prediction results output by the situation prediction and analysis unit and the comprehensive risk level score output by the risk level assessment module, and generate corresponding early warning instructions according to the preset early warning triggering rules. The early warning triggering rules set multiple early warning thresholds based on the risk level score. When the risk level score reaches the first-level early warning threshold, a yellow early warning instruction is generated and pushed to the building management personnel. When the risk level score reaches the second-level early warning threshold, an orange early warning instruction is generated and the emergency response process is initiated. When the risk level score reaches the third-level early warning threshold, a red early warning instruction is generated and the fire protection and security systems are linked to perform emergency response.
[0020] As one embodiment of the present invention, the early warning instruction includes information such as early warning level, early warning time, risk area location, suspected attack path, and recommended handling measures; the recommended handling measures are automatically generated based on the attack response strategy library in the knowledge graph.
[0021] As one embodiment of the present invention, the early warning command and dispatch unit further includes an early warning feedback module, which is used to receive feedback from building management personnel on the handling of early warning instructions and input the handling feedback information into the situation prediction and analysis unit to realize online learning and continuous optimization of the early warning model.
[0022] Compared with the prior art, the advantages and positive effects of the present invention are as follows: This solution achieves standardized processing, protocol parsing, and correlation fusion of multi-source heterogeneous network data within a building through a heterogeneous data fusion unit. It effectively solves the problem of data fusion and analysis difficulties caused by the large number of equipment types and different protocols in traditional solutions, providing a unified data foundation for subsequent threat detection and situational analysis, and significantly improving the system's adaptability to complex network environments.
[0023] This solution employs a deep autoencoder for traffic behavior anomaly detection, a long short-term memory network for intrusion behavior identification, and a knowledge graph for related threat analysis through an intelligent threat detection unit. This constructs a multi-layered and multi-dimensional threat detection system, overcoming the technical shortcomings of traditional solutions that rely on feature matching and rule detection, which result in insufficient ability to identify unknown threats and advanced persistent attacks. This significantly improves the system's ability to detect new types of network attacks.
[0024] This solution employs a spatiotemporal joint prediction model in the situation prediction and analysis unit to predict the network situation in a temporal sequence and a multi-agent reinforcement learning framework to simulate the situation evolution. This enables the system to shift from passive detection to proactive prediction, providing early warning and rapid response capabilities for network security risks. It effectively solves the technical problem of existing network management systems lacking real-time perception and predictive analysis capabilities of global communication situation.
[0025] This solution triggers corresponding early warning instructions based on multi-level risk level scores through an early warning command and dispatch unit, and coordinates with fire protection and security systems to carry out emergency response. It achieves a complete closed loop from threat detection to emergency response, effectively reducing the risk of chain reactions caused by network attacks in scenarios where multiple business systems coexist, and ensuring the safety of people's lives and property in smart buildings. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the overall technical solution architecture proposed in this invention; Figure 2 This is a schematic diagram of the core principle framework of the intelligent threat detection unit based on multi-dimensional AI model fusion in this invention; Figure 3 This is a flowchart illustrating the standardized processing, protocol parsing, and associated fusion logic of the heterogeneous data fusion unit in this invention. Figure 4 This is a schematic diagram illustrating the spatiotemporal joint prediction and multi-agent reinforcement learning evolution simulation interaction relationship of the situation prediction and analysis unit in this invention. Figure 5 This is a schematic diagram of the multi-level risk assessment and emergency response process of the early warning command and dispatch unit in this invention. Detailed Implementation
[0027] Example 1 Please refer to the attached document. Figure 1 The overall technical architecture of the network communication situation awareness system for smart building operation security proposed in this invention includes five core functional modules: multi-source data acquisition unit, heterogeneous data fusion unit, intelligent threat detection unit, situation prediction and analysis unit, and early warning command and dispatch unit. The modules are connected sequentially according to the data flow direction to form a complete technical closed loop from data acquisition to early warning response.
[0028] The multi-source data acquisition unit serves as the data entry point for the entire system, responsible for collecting network traffic data, device operating status data, security event log data, and building automation system data from various intelligent devices within the smart building. Network traffic data acquisition is achieved through traffic mirroring ports deployed on the core network switches and access switches. The collected data includes three main protocol types: TCP packets, UDP packets, and HTTP packets. TCP packet acquisition focuses on control flags, SYN and ACK sequence numbers, window size, and other fields during the three-way and four-way handshake processes. UDP packet acquisition focuses on source and destination ports, packet length, and checksum fields. HTTP packet acquisition focuses on request method, URI path, request headers, and response status codes. The traffic acquisition module uses the NetFlow or sFlow protocol to convert raw data packets into traffic records. Each traffic record contains key fields such as source IP address, destination IP address, source port, destination port, protocol type, number of packets, number of bytes, and traffic duration. The acquisition period is set to 5 seconds to ensure real-time traffic data transmission.
[0029] Device operating status data is collected by deploying a lightweight agent program on each smart device. This agent program periodically collects four core metrics—CPU utilization, memory usage, network bandwidth usage, and device online duration—via the operating system's system call interface. CPU utilization is collected using a weighted sliding window algorithm with a 1-second sampling interval and a 60-second window length. The calculation formula is the arithmetic mean of CPU usage at each sampling point within the current 60 seconds. Memory usage is collected by directly reading the allocated memory and total memory fields from the system's memory management data structure, with the ratio calculated and rounded to two decimal places. Network bandwidth usage is collected by reading the network interface driver's statistical counter to obtain the number of bytes sent and received, and then calculating the percentage of bandwidth used in conjunction with the device's nominal network interface bandwidth. Device online duration is collected by recording the timestamp of the device's last communication; the difference between this timestamp and the current timestamp is the device's online duration. When the difference exceeds a preset 300-second threshold, the system determines that the device is offline.
[0030] Security event log data is collected through integration with the building's existing security information and event management system. The collection scope covers three categories: user login authentication records, access control policy change records, and system alarm records. User login authentication records include fields such as login username, login time, login source IP address, authentication method, authentication result, and session identifier. Access control policy change records include fields such as the identity of the operator making the change, change time, comparison of policy content before and after the change, and policy scope. System alarm records include fields such as alarm generation time, alarm source device, alarm type code, alarm severity level, and alarm description text. Log collection uses Syslog or CEF format and pushes log data to the log buffer of the data collection unit via an SSL encrypted transmission channel.
[0031] Data acquisition for building automation systems is achieved through an OPC interface connection with the building automation system's data server. The acquired data includes three categories: fire alarm signals, security intrusion alarm signals, and building automation system operating parameters. Fire alarm signal acquisition focuses on fire alarm signals, fault signals, shielded signals, and linkage control signals from the fire alarm controller, using either dry contact signals or the Modbus protocol for access, with signal change delays not exceeding 500 milliseconds. Security intrusion alarm signal acquisition focuses on the alarm status of front-end detectors such as infrared detectors, door magnetic detectors, and glass break detectors, polling the detector's status register once per second. Building automation system operating parameter acquisition covers the operating status data of HVAC systems, lighting control systems, elevator control systems, and water supply and drainage systems. Acquired parameters include equipment operating modes, set temperatures, actual temperatures, cumulative operating time, and energy consumption data.
[0032] The multi-source data acquisition unit performs data preprocessing operations during data acquisition, including three stages: data format unification, timestamp standardization, and data filtering. Data format unification converts various types of raw data into a unified data structure defined internally by the system. This unified data structure includes standardized data segments such as data identifiers, data type codes, timestamps, data source identifiers, data payloads, and verification fields. Timestamp standardization converts timestamps from different data sources into UTC time format, accurate to the millisecond level. Data with a time deviation exceeding 100 milliseconds is marked with a time calibration tag. Data filtering filters out invalid and interfering data according to preset blacklist and whitelist rules. The blacklist rules are constructed based on a list of known scanning and detection source IP addresses, while the whitelist rules are constructed based on a list of authorized building device IP addresses.
[0033] Please refer to the attached document. Figure 3The heterogeneous data fusion unit performs standardization, protocol parsing, and correlation fusion on various types of data collected by the multi-source data acquisition unit, outputting fused data in a unified format for use by downstream modules. The standardization process includes three sub-steps: data format unification, timestamp alignment, and data cleaning. Data format unification converts BACnet, Modbus, KNX, and ZigBee protocol data contained in the original data into a standard IP data format. The BACnet protocol converter in the protocol conversion module parses the BACnet type length value encoding field in the BACnet protocol message, extracts the object identifier, attribute identifier, and current value, and encapsulates the extracted results into a JSON-formatted IP data packet for output. The Modbus protocol converter parses the function code, data address, and data fields in the Modbus protocol message, mapping register data and coil status to a standard device operating parameter format. The KNX protocol converter parses the CIF field and group address field in the KNX protocol message, extracting lighting control commands and sensor data. The ZigBee protocol converter parses the APS and NWK layer messages of the ZigBee protocol stack and extracts environmental parameters such as temperature, humidity, smoke concentration, and light intensity collected by sensors.
[0034] The timestamp alignment operation employs a sliding window-based time association algorithm, mapping timestamps from different data sources to a unified time grid with a resolution of 1 second. The time association algorithm first identifies the time window to which each data record's timestamp belongs, then allocates the data to the corresponding grid cells based on the start and end times of the time window. For multiple data records with timestamps within the same window, the system sorts them according to the priority of the data source: network traffic data has the highest priority, followed by security event log data, and then building automation system data has the lowest priority.
[0035] Data cleaning includes three stages: null value handling, outlier filtering, and duplicate data removal. Null value handling fills missing key fields with their historical averages; if historical data is insufficient, the statistical average of similar devices is used instead. Outlier filtering uses a box plot algorithm to identify data points exceeding 1.5 times the interquartile range; data outside this range is marked as potentially outliers and placed in a manual review queue. Duplicate data removal uses hash calculations based on data identifiers; for multiple data entries with the same hash value, only the one with the earliest timestamp is retained.
[0036] The protocol parsing process extracts header information and decodes payload content for different network protocols. The network protocol parser first identifies the protocol type based on the data packet's characteristic fields. For TCP packets, it parses extended fields in the TCP header such as timestamp options, window scaling factor, and selective acknowledgment options. For UDP packets, it parses application layer protocols that may be embedded in the payload content, such as DNS queries or NTP responses. For HTTP packets, it parses key fields such as request lines, request headers, response status lines, and content encoding and caching control in the response headers. The decoding operation converts the binary payload content into a readable text format. For compressed HTTP response content, it performs gzip or deflate decompression, and for Base64 encoded data, it performs Base64 decoding.
[0037] The association and fusion process comprises two core functions: cross-data source event association based on time windows and network entity identification based on device fingerprints. The cross-data source event association algorithm based on time windows sets a 300-second event association window. Event records from different data sources appearing within this window are extracted as candidate associated event sets. These candidate event sets are then clustered using an event similarity matrix, with similarity calculation considering three dimensions: temporal proximity, spatial proximity, and semantic relevance. Event clusters containing more than two different data sources are identified as associated events. Each associated event generates a unique event association identifier, which is then appended to the fused data.
[0038] Network entity identification based on device fingerprinting employs a combination of passive fingerprint acquisition and active fingerprint detection to construct a device fingerprint database. Passive fingerprint acquisition builds an initial fingerprint by analyzing device characteristic information carried in network traffic, including MAC address vendor prefixes, TCP protocol stack fingerprints, HTTP user agent strings, SSH client keys, etc. Active fingerprint detection sends standard probe packets to unidentified devices and infers the device type and operating system version based on response characteristics. The device fingerprint database uses a key-value pair storage structure, where the key is the device IP address or MAC address, and the value is a composite field containing information such as device type, vendor, model, operating system version, and communication protocol preferences.
[0039] The data quality assessment module quantitatively evaluates the integrity, consistency, and timeliness of the merged data. Integrity assessment calculates the proportion of non-empty fields to the total number of fields in each merged data entry; data with a proportion below 80% is marked as low-quality data. Consistency assessment compares the attribute values of the same entity from different data sources; data with attribute value differences exceeding a threshold is marked as suspicious data and enters the manual review process. Timeliness assessment calculates the difference between the data timestamp and the current time; data exceeding 600 seconds is marked as expired data. The assessment results are appended to each merged data entry in metadata form for downstream analysis modules to reference when selecting data.
[0040] Please refer to the attached document. Figure 2 The intelligent threat detection unit performs multi-dimensional network security threat detection based on the fused data output by the heterogeneous data fusion unit. The detection dimensions cover three levels: anomaly detection based on traffic behavior characteristics, intrusion detection based on sequence pattern mining, and association threat analysis based on knowledge graphs.
[0041] Anomaly detection based on traffic behavior features is implemented using a deep autoencoder model, which consists of an encoder network and a decoder network. The encoder network employs a multi-layer fully connected neural network structure. The number of nodes in the input layer is equal to the dimension of the traffic feature vector. The feature vector is composed of statistical indicators from the traffic data, such as packet rate, byte rate, average packet length, TCP connection establishment rate, TCP connection closure rate, and HTTP request rate. The encoder network has four hidden layers with 128, 64, 32, and 16 nodes respectively, using the ReLU activation function. A batch normalization layer is added after each hidden layer to accelerate model convergence. The encoder's output layer has 8 nodes, representing the compression of high-dimensional traffic features into an 8-dimensional low-dimensional latent space. Each dimension in the low-dimensional latent space represents a latent characteristic of the traffic data.
[0042] The decoder network employs a structure symmetrical to the encoder, sequentially mapping the 8-dimensional latent representation to intermediate representations of 16, 32, 64, and 128 dimensions, ultimately reconstructing an output vector with the same dimensions as the input. The decoder network uses a sigmoid activation function to map the output values to the range of 0 to 1, matching the normalized value range of the traffic flow features. The deep autoencoder model is trained using a mean squared error loss function. The training dataset consists of historical traffic flow data during normal building operation, with the validation set accounting for 20% of the training process, and the early stop strategy using a waiting period of 10 rounds.
[0043] The anomaly detection process calculates the reconstruction error of the input traffic features, which is the Euclidean distance between the input feature vector and the reconstructed feature vector. The system sets a static anomaly threshold of 0.15 as the decision threshold; when the reconstruction error exceeds 0.15, the current traffic data is considered to exhibit abnormal behavior. Simultaneously, the system employs a dynamic threshold adjustment mechanism, dynamically updating the anomaly threshold based on the statistical distribution of historical reconstruction errors. The dynamic threshold is calculated as the mean of the historical reconstruction errors plus twice the standard deviation.
[0044] in Indicates the dynamic anomaly threshold. This represents the mean of historical reconstruction errors. This represents the standard deviation of historical reconstruction errors. The dynamic threshold is updated weekly, with an update window length of the reconstruction error records for the most recent four weeks.
[0045] Intrusion detection based on sequence pattern mining employs a Long Short-Term Memory (LSTM) network. The LSM network takes time-series network traffic data as input and outputs classification labels for the traffic sequences. The network traffic sequences are constructed by organizing traffic records within consecutive time windows into variable-length sequences in chronological order. Each time window is 60 seconds long, and the sliding step between time windows is 30 seconds to ensure sequence overlap. The LSM network contains two layers of LSTM units: the first LSTM unit has a hidden state dimension of 128, and the second LSTM unit has a hidden state dimension of 64.
[0046] Long Short-Term Memory (LSTM) networks identify intrusion behaviors by learning the temporal dependencies of network traffic sequences. Each time step in the network traffic sequence corresponds to a feature vector of the traffic record, and the dimension of the feature vector is the same as that used for anomaly detection. The gating mechanism of the LSTM unit includes three control gates: the input gate, the forget gate, and the output gate. The input gate determines how much information from the current time step is added to the cell state, the forget gate determines how much historical information is retained in the cell state, and the output gate determines how much information from the cell state is output to the hidden state. The fully connected classification output layer of the network receives the hidden state of the last LSTM layer and outputs the probability distribution of various intrusion types through the Softmax function.
[0047] The model is trained using the cross-entropy loss function. The training dataset includes normal traffic samples and samples of known intrusion types. Normal traffic samples are extracted and labeled from traffic data during normal building operations, while samples of known intrusion types are obtained from publicly available network intrusion datasets and actual attack and defense drill records. The model classifies traffic into five categories: normal traffic, DoS attacks, brute-force attacks, malware communication, and insider threats. The classification result is adopted when the maximum probability value output by Softmax exceeds 0.8; otherwise, the traffic sequence is marked as a gray sample awaiting manual review.
[0048] The knowledge graph-based association threat analysis comprises two sub-modules: an entity construction module and a relationship reasoning module. The entity construction module extracts network attack-related entity information from the fused data. The extracted entity types include four categories: attacker IP address, target device, attack method type, and attack time window. The attacker IP address entity includes attribute fields such as IP address value, geographic location, network operator, number of historical attack records, and reputation score. The target device entity includes attribute fields such as device IP address, device type, device purpose, network region, and importance of the services it carries. The attack method type entity includes attribute fields such as attack method name, attack technique classification, associated vulnerability number, and scope of impact. The attack time window entity includes attribute fields such as attack start time, attack duration, peak attack time, and attack end time.
[0049] The relation reasoning module infers attack relationships between entities based on a pre-defined attack knowledge graph topology. The attack knowledge graph topology defines a series of predefined relation edge types, including remote control relationships, lateral movement relationships, privilege escalation relationships, data theft relationships, and destructive impact relationships. Relationship reasoning employs a link prediction algorithm based on a graph neural network. The graph neural network takes the feature vectors of entity nodes and the type encoding of relation edges as input, and outputs the probability value of the existence of the relation edge. When the relation edge probability exceeds 0.7, the reasoning result is added to the knowledge graph. The knowledge graph is updated every 15 minutes.
[0050] Knowledge graphs are also used to identify attack chains for advanced persistent threats. The algorithm for identifying attack chains searches the knowledge graph for attack paths that satisfy time-series constraints. In these paths, attacker IP entities and target device entities are connected sequentially in chronological order, and the time interval between adjacent nodes does not exceed a preset threshold of 7200 seconds. The identified attack chains generate unique threat chain identifiers. Detailed information about the threat chain includes a list of participating entities, a sequence of attack methods, key time points, and a threat level score.
[0051] Please refer to the attached document. Figure 4The situation prediction and analysis unit performs time-series prediction and trend evolution analysis of network communication situation based on the detection results of the intelligent threat detection unit and the fused data of the heterogeneous data fusion unit. The time-series prediction is implemented using a spatiotemporal joint prediction model, which consists of two parts: a spatial feature extraction subnetwork and a temporal feature extraction subnetwork.
[0052] The spatial feature extraction subnetwork is used to capture the spatial relationships between different network segments and devices. The network is abstracted as a graph structure, where nodes represent network devices or network segments, and edges represent communication links between devices. Spatial feature extraction is implemented using a graph attention network. The input to the graph attention network is the initial feature vector of each node, which is composed of the device's traffic statistics features, device attribute features, and threat detection result features. The graph attention network contains three graph attention layers, each containing a multi-head attention mechanism with four attention heads and an attention dimension of 32 for each head.
[0053] The computation process of the graph attention layer first calculates the attention weights between node pairs based on node features. The calculation of these attention weights considers three factors: source node features, destination node features, and edge features. After being normalized using the Softmax function, the attention weights are used to weighted aggregate the features of adjacent nodes. The three graph attention layers are stacked sequentially to obtain the spatial representation vector of each node. The output of the spatial feature extraction subnetwork is a feature matrix composed of the spatial representation vectors of all nodes.
[0054] The temporal feature extraction sub-network is used to capture the temporal patterns of network situation evolution over time. Temporal feature extraction is implemented using an improved Transformer architecture, which replaces the standard multi-head self-attention mechanism with a temporal convolutional self-attention mechanism to better capture local features of time-series data. The input to the temporal feature extraction sub-network is time-series data, with each time step of the sequence corresponding to a network situation feature vector within a time window. The dimension of the situation feature vector is consistent with the feature dimension of the output of the spatial feature extraction sub-network. The temporal convolutional self-attention mechanism uses a one-dimensional causal convolutional kernel with a width of 3 and a number of 32 kernels.
[0055] The encoder of the temporal feature extraction subnetwork consists of 6 Transformer layers, each containing a multi-head attention sublayer and a feedforward neural network sublayer. The multi-head attention sublayer has 8 attention heads, each with a dimension of 64. The feedforward neural network sublayer uses a two-layer fully connected network with an intermediate layer dimension of 1024 and employs the GELU activation function. The output of the temporal feature extraction subnetwork is a temporal representation vector for each time step.
[0056] The spatiotemporal feature fusion layer fuses the spatial representation output by the spatial feature extraction subnetwork and the temporal representation output by the temporal feature extraction subnetwork. The fusion operation employs bilinear interpolation, first mapping the spatial and temporal representations to a unified fusion feature space, and then performing feature concatenation and linear transformation within this unified fusion feature space. The fused feature vector is input to the prediction output layer, which uses a fully connected neural network structure with only one node, representing the predicted network situation within a future time window.
[0057] The situation prediction model is trained using the Mean Absolute Percentage Error loss function, with training data derived from historical building network security situation data. The model's input sequence length is set to 12 time steps, with a 5-minute time window for each time step, and the output is a prediction of the situation value for the next 3 time steps. The Adam optimizer is used during training, with a learning rate of 0.001. The learning rate decay strategy employs cosine annealing, and the training epochs are set to 500. The early stopping strategy has a waiting epoch of 30 epochs.
[0058] The situational evolution simulation module simulates network situational evolution paths under different attack strategies based on a multi-agent reinforcement learning framework. This framework includes three types of agents: attacker agent, defender agent, and environment agent. The attacker agent simulates different types of attackers, including opportunistic attackers, organized attackers, and nation-state attackers, each with different policy spaces and reward function parameters. The defender agent simulates the defensive behaviors of building security personnel, including four action options: traffic monitoring, threat isolation, system repair, and alarm escalation.
[0059] The multi-agent reinforcement learning framework adopts a training paradigm of Centralized Training and Decentralized Execution. During training, the attacker and defender agents share global situational information as training signals, while during execution, each agent makes decisions based solely on local observations. The agent's observation space includes network topology information, historical situational data, current threat information, and available resource information. The action space contains a discrete set of action options, and the reward function comprehensively considers three factors: the degree of situational deterioration, the degree of resource consumption, and the response time latency.
[0060] The iterative learning of strategies for both attackers and defenders employs the Actor-Critic algorithm framework. The Actor network updates policy parameters using the policy gradient method, while the Critic network estimates the state value function using a value function approximation method. The Actor network is a multi-layer fully connected neural network, with the agent's observation vector as input and the action probability distribution as output. The Critic network is also a multi-layer fully connected neural network, with the global state vector as input and the estimated state value as output. The exploration strategy during training uses the ε-greedy method, with the ε value linearly decaying from 1.0 to 0.1 over the first 10,000 training steps.
[0061] The situation evolution simulation module generates multiple possible situation evolution scenarios, with a maximum of 20 scenarios. Each scenario includes five types of information: attacker type, attack time point, attack path, defense response measures, and situation evolution curve. Each scenario is labeled with its probability of occurrence, calculated based on factors such as the historical activity frequency of the attacker type, the prevalence of attack techniques, and the current threat level. The probability calculation formula is as follows:
[0062] in Indicates the probability of the scenario occurring. Frequency factor indicating attacker type Indicates the popularity factor of attack techniques. Indicates the current threat level factor. , , These are weighting coefficients, with values of 0.3, 0.3, and 0.4 respectively.
[0063] The risk level assessment module comprehensively considers three dimensions in the threat detection results: threat severity, threat impact scope, and threat duration, outputting a comprehensive risk level score for the network communication situation. Threat severity assessment is based on the detected threat type and threat confidence level, quantified according to a pre-defined threat type severity comparison table. This table includes 15 common threat types and their corresponding basic severity scores, ranging from 0 to 100. Threat impact scope assessment calculates the proportion of affected devices to the total number of devices in the building; this proportion is determined by statistically analyzing the coverage of threat-related entities. Threat duration assessment calculates the length of time since the threat was first detected; threats lasting longer than 7200 seconds receive an additional 20% weighting factor in the duration assessment.
[0064] The comprehensive risk level score is calculated using a weighted summation model:
[0065] wherein represents a comprehensive risk level score, represents a standardized score of threat severity, represents a standardized score of threat influence scope, represents a standardized score of threat duration, , , are weight coefficients with values of 0.5, 0.3, and 0.2 respectively. The standardization process adopts the Max-Min normalization method to map the scores of each dimension to a unified interval from 0 to 100. The weight parameters are determined based on the statistical analysis results of historical security events. In the statistical analysis process, historical security event records of the most recent year are collected, and the optimal weight ratio is determined through regression analysis.
[0066] please refer to the appendix Figure 5 , the early warning command and scheduling unit receives the situation prediction result output by the situation prediction and analysis unit and the comprehensive risk level score output by the risk level assessment module, and generates corresponding early warning instructions according to preset early warning trigger rules. The early warning trigger rules set three-level early warning thresholds according to the risk level score: the first-level early warning threshold is 60 points, the second-level early warning threshold is 75 points, and the third-level early warning threshold is 90 points. When the risk level score reaches the first-level early warning threshold, the system generates a yellow early warning instruction and pushes it to the mobile terminal of building management personnel and the large-screen display system of the building monitoring center. The content of the yellow early warning instruction includes five basic pieces of information: early warning level, early warning time, risk area location, overview of suspected attack path and recommended disposal measures.
[0067] When the risk level score reaches the second-level early warning threshold, the system generates an orange early warning instruction and starts the emergency response process. In addition to the five basic pieces of information included in the yellow early warning instruction, the orange early warning instruction also adds three extended pieces of information: attack technology analysis, affected business scope assessment and emergency resource demand list. The start of the emergency response process includes three standard actions: notifying members of the emergency response team, convening a threat analysis and judgment meeting, and preparing emergency disposal resources. The contact information and responsibility division information of emergency response team members are stored in the emergency contact database of the system.
[0068] When the risk level score reaches the third-level early warning threshold, the system generates a red early warning instruction and links the fire protection system and the security system to perform emergency disposal. The content of the red early warning instruction is the most comprehensive, it includes all information of the yellow and orange early warning instructions and adds three pieces of information: emergency broadcast instruction, area evacuation guidelines and external rescue request. The linked operation of the fire protection system includes actions such as triggering sound and light fire alarm signals, starting the fire broadcast system, and turning on emergency evacuation indication signs. The linked operation of the security system includes actions such as locking the entrance and exit of the affected area, starting video monitoring and tracking, and activating the high-sensitivity mode of intrusion detection.
[0069] The recommended response measures in the warning instructions are automatically generated based on an attack response strategy library in a knowledge graph. This library stores standard response procedures for various known attack types, including four categories of standard actions: containment, eradication, recovery, and follow-up evaluation. The automatic matching algorithm retrieves corresponding response strategies from the knowledge graph based on information such as the attacker's IP address, target device, and attack method type included in the warning instructions. The search results are sorted by matching degree, and the highest-ranked strategy is output as the recommended measure. The recommended measures are presented in the form of structured instructions, each containing four fields: action name, execution parameters, execution time limit, and expected effect.
[0070] The early warning feedback module receives feedback from building management personnel regarding their handling of early warning instructions and inputs this feedback information into the situation prediction and analysis unit to enable online learning and continuous optimization of the early warning model. Feedback information is collected using a structured form, where management personnel fill in fields such as the early warning number, actual handling measures, evaluation of the handling effect, and improvement suggestions. After verification, the feedback information is stored in the feedback database. Historical data in the feedback database is periodically used for model fine-tuning training. Fine-tuning training employs an incremental learning approach, updating only the last few layers of the model network in each adjustment to avoid overwriting historical knowledge. The model's online learning cycle is set to once a week, and the fine-tuning training dataset consists of feedback information collected within the past week.
[0071] The early warning command and dispatch unit also includes an early warning record management function, which persistently stores all generated early warning instructions. The early warning record content includes fields such as the unique identifier of the early warning instruction, generation time, early warning level, trigger threshold, associated threat chain identifier, instruction content, sending record, receipt confirmation status, and handling feedback information. The early warning records are stored using a distributed database cluster, with a master-slave replication architecture to ensure high data availability. The default retention period for early warning records is set to three years.
[0072] The above embodiments describe in detail the complete technical solution of a network communication situational awareness system for smart building operation security, including the data acquisition mechanism of the multi-source data acquisition unit, the data processing flow of the heterogeneous data fusion unit, the multi-dimensional detection method of the intelligent threat detection unit, the predictive analysis model of the situational prediction and analysis unit, and the early warning response mechanism of the early warning command and dispatch unit. The various modules of the system are connected through standardized data interfaces, forming a complete technical closed loop from data acquisition to early warning response, realizing real-time perception and predictive analysis capabilities of the smart building network communication situation.
Claims
1. A network communication situational awareness system for the operational security of smart buildings, characterized in that, include: The multi-source data acquisition unit is used to collect network traffic data, equipment operation status data, security event log data, and building automation system data of various intelligent devices in smart buildings; The heterogeneous data fusion unit is used to perform standardization processing, protocol parsing, and correlation fusion on the various types of data collected by the multi-source data acquisition unit. The heterogeneous data fusion unit is used to: uniformly convert the building automation special protocol data existing in the building into a standard IP data format, and realize the correlation fusion of cross-source data based on time windows and device fingerprints. The intelligent threat detection unit is used to perform multi-dimensional network security threat detection based on the fused data output by the heterogeneous data fusion unit. The intelligent threat detection unit is used to: combine anomaly detection based on traffic behavior characteristics, intrusion detection based on sequence pattern mining, and association threat analysis based on knowledge graphs to identify known and unknown network attacks. The situation prediction and analysis unit is used to perform time-series prediction and trend evolution analysis of network communication situation based on the detection results of the intelligent threat detection unit and the fused data of the heterogeneous data fusion unit. The situation prediction and analysis unit is used to: capture the network space topology association and time-series evolution law by adopting a spatiotemporal joint prediction model, and simulate the situation evolution path under attack and defense confrontation through multi-agent reinforcement learning. The early warning command and dispatch unit is used to receive the situation prediction results and risk level scores output by the situation prediction and analysis unit, and generate corresponding early warning instructions according to the preset multi-level early warning thresholds, and link the fire protection and security systems to perform emergency response.
2. The network communication situational awareness system for smart building operation security according to claim 1, characterized in that, The heterogeneous data fusion unit includes: The protocol conversion module is used to convert data formats of BACnet, Modbus, KNX or ZigBee protocols into standard IP data formats. The data quality assessment module is used to quantitatively assess the integrity, consistency, and timeliness of the merged data, and to mark or filter low-quality data. The timestamp alignment module is used to map timestamps from different data sources to a unified time grid and sort them by priority; The device fingerprint recognition module is used to construct network entity identity identifiers based on passive fingerprint collection and active detection.
3. The network communication situational awareness system for smart building operation security according to claim 2, characterized in that, The protocol conversion module includes: The BACnet protocol parsing submodule is used to extract object identifiers, attribute identifiers, and current values and encapsulate them into structured data. The Modbus protocol mapping submodule is used to map function codes and register data into device operating parameters; The KNX protocol decoding submodule is used to parse group addresses and control commands. The ZigBee protocol extraction submodule is used to extract environmental sensing parameters from the middle-layer messages in the protocol stack.
4. The network communication situational awareness system for smart building operation security according to claim 1, characterized in that, The intelligent threat detection unit includes: The traffic anomaly detection module is used to compress and reconstruct high-dimensional traffic features using a deep autoencoder model, and to determine abnormal behavior based on the reconstruction error. The sequence intrusion identification module is used to learn the temporal dependencies of traffic using a long short-term memory network and classify the intrusion types. The knowledge graph association analysis module is used to extract attack-related entities and infer attack chains from fused data.
5. The network communication situational awareness system for smart building operation security according to claim 4, characterized in that, The traffic anomaly detection module includes: The feature vector construction submodule is used to extract statistical indicators such as packet rate, byte rate, and connection establishment rate from network traffic; The encoder-decoder submodule is used to compress the input features into a low-dimensional latent space and reconstruct the original features. The anomaly detection submodule is used to calculate the reconstruction error and compare it with a dynamically adjusted threshold to output the anomaly detection result.
6. The network communication situational awareness system for smart building operation security according to claim 4, characterized in that, The knowledge graph association analysis module includes: The attack entity construction submodule is used to extract the attacker's IP address, the target device, the attack method type, and the attack time window; The relation reasoning submodule is used to infer remote control, lateral movement, or privilege escalation relationships between entities based on a preset attack knowledge graph topology. The threat chain identification submodule is used to identify the complete attack path of advanced persistent threats under time-series constraints.
7. The network communication situational awareness system for smart building operation security according to claim 1, characterized in that, The situation prediction and analysis unit includes: The spatial feature extraction subnetwork is used to abstract network devices as graph nodes and aggregate neighborhood features through a graph attention mechanism; A temporal feature extraction subnetwork is used to capture long-term dependencies and temporal local features of situational evolution using an improved Transformer architecture; The spatiotemporal fusion prediction module is used to generate situation prediction values for future time windows by fusing spatial and temporal representations.
8. The network communication situational awareness system for smart building operation security according to claim 7, characterized in that, The spatial feature extraction subnetwork includes: The network graph construction submodule is used to construct a weighted graph structure based on device communication relationships; The multi-layer graph attention submodule is used to calculate the association weights between nodes and iteratively update the node representation through a multi-head attention mechanism. The spatial representation output submodule is used to output the spatial correlation feature vectors of each network node.
9. The network communication situational awareness system for smart building operation security according to claim 1, characterized in that, The early warning command and dispatch unit includes: The multi-level early warning triggering module is used to match yellow, orange, or red early warning thresholds based on the comprehensive risk level score and generate corresponding early warning instructions. The emergency response module is used to automatically trigger fire alarms, security locks, or emergency broadcasts under high-level early warning conditions. The response strategy recommendation module is used to automatically match and output structured recommended measures based on the attack response strategy library in the knowledge graph.
10. The network communication situational awareness system for smart building operation security according to claim 9, characterized in that, The early warning command and dispatch unit also includes: The early warning feedback module is used to receive feedback information from management personnel regarding their handling of early warning instructions. The online learning module is used to input the handling feedback information into the situation prediction and analysis unit to achieve incremental updates and continuous optimization of model parameters.