Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

79 results about "Alarm correlation" patented technology

Network threat multi-modal detection method based on large model

The invention discloses a network threat multi-modal detection method based on a large model, and belongs to the technical field of network security, and the method comprises the steps: collecting three types of heterogeneous data of NetFlow flow of a network layer, a system call chain sequence of a host layer and a protocol load of an application layer, and carrying out the desensitization processing and feature coding to generate a unified tensor format; the method comprises the following steps: through network security threat intelligence and MITRE ATTamp; performing supervision fine tuning on the large model by using a CK attack chain sample, and constructing a network threat identification special model; cross-device behavior characteristics are extracted through a model self-attention mechanism, and a dynamic behavior map is constructed; and finally, comprehensively evaluating an attack mode matching degree, a node vulnerability mean value, historical alarm association and an attack path risk by adopting a weighted fusion algorithm, and triggering a high-confidence alarm when a comprehensive score exceeds 0.8. According to the method, through multi-modal data fusion and dynamic graph analysis, the detection precision and response efficiency of the complex attack chain are improved.
Owner:SOUTHEAST UNIV

Automatic guarantee method and device for high-guarantee link, electronic equipment and storage medium

The invention relates to the technical field of micro-services, can be applied to the field of science and technology finance / digital medical treatment, and discloses a high-guarantee link automatic guarantee method and device, electronic equipment and a storage medium. The method comprises the following steps: performing series recording on a calling link of a service interface of a first micro-service through a proxy probe to obtain service interface calling link data; rendering a screening result of the calling link data as a high-guarantee link panorama; analyzing the high-guarantee link panorama to obtain a high-guarantee link dependency relationship, and calculating a micro-service dependency score of the first micro-service; screening the first micro-service according to the micro-service dependency score to obtain a second micro-service; when the service interface of the second micro-service generates an alarm, automatically collecting alarm associated data; and inputting alarm data to the high-insurance decision large model for analysis, and automatically issuing and executing an alarm self-healing strategy output by the high-insurance decision large model through the model context protocol server. According to the method, high-guarantee link automation and system stability are improved.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Alert analysis method, server, and storage medium

Embodiments of the present disclosure provide an alert analysis method, a server, and a storage medium. In the alert analysis method, once a target question associated with a target security alert of a user resource is obtained, a security model is used to perform action planning for the target question to obtain action planning information. On the basis of tool invocation information in the action planning information, a target alert handling tool is invoked to perform an alert information processing operation associated with the target question to obtain an alert information processing result. On the basis of the alert information processing result, the security model can output an alert analysis result corresponding to the target question. On the one hand, the security knowledge capability of the security model is used to realize automatic replies to security alert related questions; on the other hand, by using the action planning capability of the security model, an alert handling tool is invoked to process the alert information associated with the target question, so that security knowledge beyond the security model can be fully utilized, thereby effectively improving the accuracy of the alert analysis result corresponding to the target question.
Owner:HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD

Equipment fault processing method and system

The invention relates to the technical field of operation and maintenance, and discloses an equipment fault processing method and system. The method comprises the following steps: acquiring alarm messages of a plurality of devices in real time, identifying associated alarm messages caused by the same fault according to an alarm association rule, and compressing the associated alarm messages and an existing fault group to obtain new alarm messages; determining the work order type and the circulation process of the new work order according to the alarm type of the newly sent alarm message, and carrying out order dispatching priority configuration on each process link based on the alarm level of the newly sent alarm message and the pre-configured authority information of each process link; and calling a corresponding work order template based on the work order type, configuring the work order template to generate a new work order, monitoring the full life cycle of the new work order, and synchronously updating the processing state of the new work order. According to the method, the fault processing efficiency of the machine room intelligent connection equipment is effectively improved, resource configuration is optimized through real-time monitoring and data analysis, and the method can meet the fault troubleshooting requirements of equipment of different scales and types.
Owner:CHINA TOWER CO LTD

Log alarm data processing method and device, storage medium and electronic equipment

The invention relates to a log alarm data processing method and device, a storage medium and electronic equipment, and relates to the technical field of big data processing.The method comprises the steps that the data source category of original log alarm data is determined, and a key information extraction model corresponding to the data source category is distributed to the original log alarm data; performing semantic analysis on the original log alarm data based on the key information extraction model to obtain alarm key information in the original log alarm data corresponding to the data source category; performing multi-dimensional correlation analysis on the alarm key information of the different data source categories based on a preset correlation analysis model to obtain a correlation relationship between the alarm key information of the different data source categories; and performing alarm root cause reasoning on the association relationship between the alarm key information based on a preset fault reasoning model to obtain an alarm association analysis result. According to the invention, the accuracy of the alarm association analysis result is improved.
Owner:HANGZHOU FRAUDMETRIX TECH CO LTD

Clustering-based alarm association rule generation method and device, equipment and medium

The invention discloses an alarm association rule generation method and device based on clustering, equipment and a medium. The method comprises the following steps: collecting alarm logs in response to an alarm log information collection instruction, and sorting the alarm logs according to a timestamp sequence; performing clustering processing on the sorted alarm logs based on an elbow rule to obtain a plurality of alarm clustering groups; dividing each alarm cluster group into at least one transaction according to a time window, and generating an item set; and performing frequent item set mining on each item set by adopting an association rule learning algorithm, generating an alarm association rule for describing an attribution relationship among the fault description information, and storing the alarm association rule in the graph database. Different from the prior art which only depends on timestamp sorting, the embodiment of the invention creatively puts forward that alarm logs in a time window are grouped by utilizing an elbow rule to form a high-cohesion alarm clustering group, so that subsequent association rule mining focuses on an alarm combination with strong space-time association, and the rule confidence is remarkably improved.
Owner:BEIJING YOUTEJIE INFORMATION TECH

Intelligent alarm analysis and diagnosis method and device based on AI algorithm

The invention provides an intelligent alarm analysis and diagnosis method and device based on an AI algorithm, and the method comprises the steps: obtaining historical alarm data, and generating an intelligent alarm analysis and diagnosis large model according to the historical alarm data and historical disposal data; acquiring all real-time alarm data in a preset time window, inputting all the real-time alarm data into the intelligent alarm analysis and diagnosis large model, and associating all the real-time alarm data into a plurality of combined alarm records through an alarm association engine, according to the type confidence degree distribution of each combined alarm record by the trend classification model and the component probability distribution of each combined alarm record by the component positioning model, the fault type and the specific fault position are obtained; and generating an alarm disposal suggestion for each combined alarm record according to the fault type and the specific fault position by the matching disposal rule, and then distributing the alarm disposal suggestion. According to the invention, the problems of difficult alarm problem tracing, difficult problem root cause positioning and long fault recovery time are solved.
Owner:FUJIAN FUNO MOBILE COMM TECH CO LTD

Power system multi-mode graph attention attack traceability blocking method and device

The invention relates to an attention attack traceability blocking method and device for a multi-mode graph of a power system. The method comprises the following steps: cooperatively matching and screening abnormal flow data by utilizing alarm data and flow data; secondly, real attack traffic data are screened out through an undirected abnormal flow graph based on an aggregation and clustering mechanism, and the screening accuracy can be improved through an attention mechanism; then constructing a directed alarm graph associated with the alarm, generating an initial attack chain based on the directed alarm graph, and realizing association and traceability of fine-grained multi-step attack behaviors; nodes in the initial attack chain are pruned based on negative causal association to obtain a final attack chain, so that attack blocking is carried out; according to the method, through multi-mode collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, fine-grained attack behavior traceability is realized, attack chain analysis is carried out by using a non-causal reasoning method, causal relevance of alarm types can be ensured, and dependence on expert knowledge, attack marks and simulation work can be reduced to the greatest extent.
Owner:WUQIANG XISHUI POWER PLANT OF WULING ELECTRIC POWER CO LTD

Multi-source heterogeneous system and method based on liquid air energy storage plant-level monitoring

The invention relates to the technical field of plant-level monitoring systems, in particular to a multi-source heterogeneous system and method for plant-level monitoring based on liquid air energy storage. According to the technical scheme, the method comprises the following steps of S1, collecting and preprocessing multi-source heterogeneous data in real time; s2, constructing a cross-system equipment graph; s3, formulating a hierarchical response intelligent strategy; s31, making a topological graph; s32, according to a hierarchical response strategy, dynamic adjustment is carried out according to the severity degree and the propagation range of the alarm; s33, calculating a weight; and S34, dividing response levels according to the weights. Multi-source heterogeneous data real-time acquisition and preprocessing can align millisecond-level and second-level data streams and eliminate time sequence errors, so that the system alarm association accuracy is improved, six system data formats are unified through JSON structured conversion, the analysis error rate can be reduced, and a basis is provided for large-scale monitoring; a three-flow topology model is established, a key equipment network is constructed, the root cause positioning time is shortened, and the false alarm rate is reduced through a topology weight optimization mechanism.
Owner:ZHONGLU ZHONGKE ENERGY STORAGE TECH CO LTD

Alarm processing method and device, equipment, storage medium and program product

The invention provides an alarm processing method and device, equipment, a storage medium and a program product, and relates to the field of artificial intelligence. The method comprises the following steps: extracting a plurality of alarms in a historical time period based on a preset time window size to obtain a historical alarm transaction corresponding to each time window in a plurality of time windows; wherein the alarms comprise event type alarms and business index type alarms, and the event type alarms and the business index type alarms respectively comprise a plurality of alarm types; determining a frequent item set combination according to the historical alarm transaction corresponding to each time window in the plurality of time windows, and constructing an alarm association knowledge graph; wherein the alarm association knowledge graph comprises a plurality of nodes, and each node corresponds to one alarm type; according to the to-be-queried current event type alarm set, the alarm association knowledge graph is queried, and the business index type alarm corresponding to each event type alarm in the current event type alarm set is determined, so that the business index influenced by the system fault is accurately determined.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Security alarm processing method and device, equipment and storage medium

The invention discloses a security alarm processing method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: carrying out the data preprocessing of multi-source heterogeneous data, and obtaining security alarm data; identifying the security alarm data through an alarm identification model, and determining an alarm type and a threat level; performing graph construction on the security alarm data through a graph database to generate a security knowledge graph; performing association analysis on the security knowledge graph to obtain attack chain information; and carrying out risk research and judgment on the attack chain information according to the alarm type and the threat level to obtain a comprehensive risk level. According to the method, the security alarm data is identified through the alarm identification model, so that the detection capability of novel attacks can be improved; and meanwhile, alarm correlation analysis is carried out in combination with the constructed security knowledge graph, and potential attack chains and complex attack behaviors are effectively identified, so that the alarm can be deeply analyzed, and the hazard degree of the alarm can be accurately judged.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Fault positioning method, system and device and storage medium

The invention discloses a fault positioning method, system and device and a storage medium, and relates to the technical field of data processing, and the method comprises the steps: collecting alarm data, carrying out the entity relation extraction and link traceability tracking of the alarm data, and obtaining a corresponding text entity relation triple and a potential fault propagation path; performing multi-dimensional alarm association aggregation on the alarm data to generate a corresponding alarm clustering set; and in combination with variable information and multi-dimensional feature values in the text entity relationship triple, performing deep aggregation and association degree evaluation on the alarm clustering set to obtain a target fault set and a corresponding association degree score, and in combination with the association degree score and a potential fault propagation path, positioning a target root cause fault. According to the method, identification and convergence of alarm storm are realized through multi-dimensional alarm association aggregation, and root cause faults are quickly positioned in combination with a fault propagation path and a text entity relationship triple.
Owner:CHINA MERCHANTS BANK

Large-screen real-time monitoring system and method for automobile charging pile

The invention discloses an automobile charging pile large screen real-time monitoring system and method, and relates to the technical field of screen monitoring. The large-screen real-time monitoring system for the automobile charging pile is established and comprises a connection module, a data acquisition module, a data processing module, a large-screen visualization module and an alarm notification module, and the monitoring process comprises the steps that 1, the charging pile and a server side establish long connection through the connection module by means of tcp, 2, the charging pile reports pile information to the data acquisition module in real time, and 3, the data acquisition module sends the pile information to the server side; the method comprises the following steps of 1, sending data to a data acquisition module, 2, sending collected information to a data processing module through a data acquisition module, 4, carrying out data processing through the data processing module, 5, selecting or developing a new component through a large-screen visualization module, and displaying summarized information according to needs, and 6, receiving abnormal information through an alarm notification module. And sending an alarm notice: notifying a processor associated with the alarm.
Owner:SHANDONG ARTAPLAY INTELLIGENT TECH CO LTD

Automatic fault monitoring method and system for operation and maintenance of base station

The invention relates to the technical field of mobile communication network operation and maintenance, and discloses an automatic fault monitoring method and system for base station operation and maintenance. The method comprises the following steps: acquiring operation indexes of a base station and performing time sequence analysis to obtain a drift vector; according to the drift vector, track clustering is carried out by adopting a K-means algorithm, and an initial performance baseline is determined to construct a baseline model; deviation is calculated and filtering processing is carried out to obtain a pure residual error sequence; micro degradation modes in the pure residual sequence are identified and aggregated, and an early signal list is obtained; constructing a correlation graph in combination with historical alarm logs, and mining a dependency relationship to obtain a correlation alarm cluster; performing root cause positioning rule fusion and feature aggregation on the cluster to obtain a labeled fault description; and finally, matching the early warning template and determining the priority to obtain final early warning output. According to the method, tiny hidden dangers of base station performance can be effectively identified, the problem that massive alarms are difficult to associate is solved, and early-stage accurate early warning and root cause positioning of faults are achieved.
Owner:GUANGDONG HUIDE TECH DEV CO LTD

Risk assessment and scheduling method and system based on main and distribution networks

The invention discloses a risk assessment and scheduling method and system based on a main distribution network, and the method comprises the steps: recognizing a fault of the main distribution network, and transmitting a first alarm signal based on the recognized fault; setting an observation period, obtaining all alarm signal fault types in the observation period, and constructing a fault-weight corresponding table; based on the fault-weight corresponding table, calculating a comprehensive risk coefficient of all fault types in the observation period; judging the comprehensive risk coefficient, and sending out a second alarm signal based on a first judgment result; and constructing a scheduling objective function based on the operation and maintenance cost, and solving the scheduling objective function in combination with the operation and maintenance information of the first alarm signal at the current moment. According to the method, risk analysis is associated through real-time alarm, so that the risk conditions of the same week based on different areas can be compared, or the risk conditions of different periods of the same area can be compared; the target function is constructed through the matching cost, the labor cost and the transportation cost, the resource configuration is optimized, and the transportation cost is reduced.
Owner:GUANGXI POWER GRID CORP

Alarm analysis method and device, computer equipment and storage medium

The invention provides an alarm analysis method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information; generating alarm query data corresponding to the plurality of alarm associated data sources according to the alarm time period information and the alarm range information, and sending the corresponding alarm query data to each alarm associated data source; when a query result returned by any alarm association data source based on the corresponding alarm query data is received, determining an association degree corresponding to at least one received query result according to the alarm scene information; calculating the confidence coefficient of the analysis result according to the correlation degree; and when the analysis result confidence is greater than a preset confidence threshold, analyzing the alarm root cause corresponding to the alarm information according to the at least one query result. According to the method, the alarm analysis efficiency can be improved.
Owner:TENCENT TECH WUHAN

Facilitation of deep service path discovery for 5g or other next generation network

PendingUS20250301394A1Network traffic/resource managementTransmissionPathPingAlert correlation
A software defined network (SDN) can add network repository functions (NRF) into a configurations database to enable NF discovery. The SDN can subscribe to NRF notifications to receive new cloud native functions (CNF), registrations, or any other update to the CNF status in 5G system. In addition to listening to NRF notifications, the SDN can implement CNF pooling processes to periodically retrieve CNF from an NRF repository and stay in sync with 5G systems. Thus, a deep service path discovery can be developed from network service configurations and container call flows to enable an accurate alarm correlation and troubleshooting for the operations. This service path deep discovery can be designed and implemented as a standalone system or in an SDN framework with integration of a container management framework such as K8 kubernetes.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Automatic alarm disposal method, system and related device based on threat mode recommendation

The invention provides an alarm automatic processing method and system based on threat mode recommendation, and a related device. The method comprises the following steps: step 1, constructing an alarm association diagram by using obtained alarm data; 2, performing community detection on the alarm association graph by adopting a graph division algorithm to obtain a plurality of security events; 3, matching the obtained multiple security events with a pre-constructed mode knowledge base to obtain a risk level and disposal information corresponding to the alarm data, and completing alarm automatic disposal; according to the method, the alarm association efficiency, the threat identification accuracy and the automatic disposal capability are remarkably improved, the problems of weak alarm association, rigid disposal strategy and high manual intervention cost in a traditional method are effectively solved, and the method is suitable for enterprise-level network security operation scenes.
Owner:XI AN JIAOTONG UNIV

An online maintenance and overload control method for a vehicle-mounted multi-source IDS alarm correlation tracking graph

PendingCN122339939AArea networkIn vehicle
This invention discloses an online maintenance and overload control method for multi-source IDS alarm correlation tracing graphs in vehicles. Rule-based intrusion detection systems (IDS) are deployed in the vehicle host domain, vehicle Ethernet domain, and Controller Area Network (CAN) to generate alarms. At the vehicle gateway electronic control unit (ECU) side, multi-source alarms undergo event standardization, sliding time window buffering and waterline out-of-order tolerance, deduplication aggregation, and indexed candidate retrieval. Under the condition of satisfying alarm correlation judgment rules, a directed alarm tracing graph is incrementally constructed. By suppressing forks and overloads through in / out-degree limits, node / edge budgets, and priority pruning, combined with two-stage expiration recycling and tracking record solidification, stable alarm correlation and tracing are achieved under resource-constrained conditions. This method can be used for real-time tracing and offline forensic analysis on the vehicle side.
Owner:ZHEJIANG UNIV +1

Alarm correlation analysis method and device, equipment and storage medium

The invention discloses an alarm correlation analysis method, device and equipment and a storage medium, and relates to the technical field of data processing, and the method comprises the steps: carrying out the feature extraction of target alarm data, and obtaining the multi-mode alarm feature information in the target alarm data; performing alarm data association analysis based on the target alarm data and the multi-modal alarm feature information through a preset alarm association model to generate alarm data association representation; performing clustering analysis on the alarm data association representation, and generating an alarm association group and an alarm attack chain identification result according to a clustering analysis result; and generating an alarm association analysis result based on the alarm association group and the alarm attack chain identification result. According to the technical scheme, the technical problem that in the prior art, a rule-based alarm correlation analysis method depends on manual definition and maintenance of rules, and consequently the efficiency and flexibility of alarm analysis are not high is solved.
Owner:STATE GRID HUBEI ELECTRIC POWER CO LTD

A method, apparatus and device for correlation analysis of alarm events

The application discloses a kind of correlation analysis methods, device and equipment of warning event, the method includes: based on the matching of the obtained warning label in the preset warning correlation analysis rule to warning label group, obtain matching result;According to the matching result, determine warning label set;Based on the warning label set, generate the prompt warning event corresponding to the warning label group of the warning label group.It can be seen that, in the method, a variety of warning events are generated into uniform warning labels, and the warning correlation analysis rules suitable for the uniform format of the warning labels are set to realize the correlation analysis of the warning events generated by various security protection products, output the prompt warning events that have an impact on network security, effectively reduce the number of alarms, improve the accuracy of alarm, and provide reliable basis for the analysis and research of network security by staff.
Owner:QI AN XIN TECHNOLOGY GROUP INC +1

Alarm association method, device, equipment and computer storage medium

The application discloses an alarm correlation method, device and equipment and a computer storage medium, the alarm correlation method comprises the following steps: constructing a training set according to obtained original data, and determining characteristic data of alarm data pairs in the training set; determining all network elements according to the characteristic data, and constructing a network topology graph according to the network elements; determining all network element sequences in the network topology graph, and constructing an alarm correlation model according to network element vectors corresponding to the network element sequences; if an input test alarm data pair is received, performing alarm correlation prediction on the test alarm data pair according to the alarm correlation model, so as to determine an alarm correlation relationship of the test alarm data pair. The application realizes deep mining of alarm data, and improves the correlation effect between correlated alarm data.
Owner:CHINA MOBILE COMM GRP CO LTD +1

A power system multi-modal graph attention attack tracing blocking method and device

The application relates to a power system multimodal graph attention attack tracing and blocking method and device. The method uses alarm data and traffic data to cooperatively match and screen abnormal traffic data. Then, based on an aggregation and clustering mechanism, real attack traffic data is screened out through a non-directional abnormal flow graph, and the accuracy of screening is improved through an attention mechanism. Then, a directional alarm graph associated with alarms is constructed, an initial attack chain is generated based on the directional alarm graph, and the correlation and tracing of fine-grained multi-step attack behaviors are realized. Based on negative causal correlation, nodes in the initial attack chain are pruned to obtain a final attack chain, so that attack blocking is realized. Through multimodal cooperative analysis between the non-directional abnormal flow graph and the directional alarm graph, fine-grained attack behavior tracing is realized, attack chain analysis is performed using a non-causal reasoning method, the causal correlation of alarm types can be ensured, and the dependence on expert knowledge, attack markers and simulation work can be maximally reduced.
Owner:WUQIANG XISHUI POWER PLANT OF WULING ELECTRIC POWER CO LTD

A method for tracing the source of network attacks

The present invention discloses a method for tracing the source of network attacks, including: obtaining threat intelligence of a specified type and caching it in a local threat intelligence database; obtaining current alarm information and the local threat intelligence to determine the attack source of the alarm; correlating the alarms based on the device identifiers of the attack source and / or the attack target, determining the attack stage of the device and determining the device vulnerability level based on the attack stage; obtaining the asset information of the device and determining the impact range of the attack based on the alarm correlation results. This method achieves effective tracing and analysis of network attacks, obtains multiple tracing results, and updates the tracing data each time the tracing is performed, which provides a basis for network operation and maintenance personnel to handle problems and strengthen security policies.
Owner:XIAN JIAODA JIEPU NETWORK SCI & TECH CO LTD

Power grid penetration level coupling alarm association method, system, equipment and medium

The invention belongs to the technical field of power system network security and intelligent power grid operation monitoring, and discloses a power grid penetration level coupling alarm association method, system and device and a medium, and the method comprises the steps: obtaining a suspicious range of an alarm log based on a monitoring host and a time label; constructing an alarm association graph, and performing extraction processing in a local adjacent sub-graph mode to obtain an attack path; constructing a natural language processing mechanism in a classified manner to obtain an attack database; matching and identifying by using a graph matching algorithm with label classification to obtain a network information layer attack event; carrying out delay sampling on abnormal data, carrying out state aggregation by utilizing a prior fault knowledge base, constructing an initial state sequence, and carrying out compression and merging to obtain a target state sequence; and carrying out hierarchical coupling analysis on the network information layer attack event and the target state sequence to obtain an attack event sequence after alarm association. According to the invention, cross-level and multi-stage abnormal alarm association of power grid penetration attacks is realized, and a complete link can be identified and tracked.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +2

Alarm aggregation method, device, equipment and storage medium

The present application provides an alarm aggregation method, device, equipment and storage medium. The method includes: for each alarm event, intercepting the alarm timing subgraph in each alarm accompanying time period where the alarm event is located from the formed alarm timing landscape, the alarm timing landscape is formed by the time sequence distribution of each of the alarm events; for each alarm event, determining the alarm correlation relationship under the alarm event according to the accompanying alarm hotspot after the alarm timing subgraphs in each of the alarm accompanying time periods where the alarm event is located are superimposed; according to the alarm correlation relationship under each alarm event, performing alarm aggregation on each of the alarm events. The present application determines the alarm correlation relationship under each alarm event from the perspective of global accompanying alarms, realizes comprehensive detection of alarm correlation relationships, ensures the comprehensiveness of alarm event aggregation, further reduces the number of alarms in the business system, and avoids the generation of alarm storms.
Owner:NEUSOFT CORP

Security alarm processing method, device, equipment and storage medium

This application discloses a security alarm processing method, apparatus, device, and storage medium, relating to the field of network security technology. The method includes: preprocessing multi-source heterogeneous data to obtain security alarm data; identifying the security alarm data using an alarm identification model to determine the alarm type and threat level; constructing a security knowledge graph from the security alarm data using a graph database; performing correlation analysis on the security knowledge graph to obtain attack chain information; and assessing the risk of the attack chain information based on the alarm type and threat level to obtain a comprehensive risk level. Because this application identifies security alarm data using an alarm identification model, it can improve the detection capability of new attacks; simultaneously, by combining the constructed security knowledge graph with alarm correlation analysis, it effectively identifies potential attack chains and complex attack behaviors, thereby enabling in-depth analysis of alarms and accurate judgment of their severity.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Optical cable network natural language operation and maintenance method and system

The application provides an optical cable network natural language operation and maintenance method and system, belongs to the technical field of optical cable communication, is applied to an optical cable network natural language operation and maintenance system, collects multi-dimensional data including optical cable vibration, temperature, environment, optical power and OTDR link attenuation through an enhanced optical fiber distribution robot of a physical perception layer, encapsulates into a multi-sensing data package MSDP, reports after data alignment relying on clock synchronization, carries out unified semantic modeling, fusion storage and semantic reasoning on the MSDP data package and network resource data, GIS geographic information and service data through a data fusion layer, constructs an optical cable operation and maintenance knowledge graph, receives natural language instructions of operation and maintenance personnel through an application interaction layer, completes intention understanding, knowledge retrieval, task planning and execution scheduling by the intelligent decision layer through multi-agent collaboration, simultaneously carries out alarm correlation analysis and health degree scoring, generates a preventive maintenance work order, and thus reduces the operation and maintenance threshold, improves the fault early warning and emergency recovery efficiency.
Owner:BEIJING RUIQI HAODI TECH CO LTD