The invention relates to the field of internet
attack detection, in particular to a
data security event real-time monitoring method and
system, and the method comprises data collection, multi-
modal fusion,
threat detection,
causal reasoning, dynamic response and feedback optimization. Compared with the traditional
security analysis which depends on isolated
data dimension or simple rule association, is difficult to capture a cross-data-source complex
attack mode, and is faced with the limitations of low calculation efficiency, slow link
traceability, storage access
bottleneck and the like in
mass data association analysis, the scheme integrates multi-source heterogeneous data into a dynamic association network through graph structure modeling, so that the
security analysis efficiency is improved. Hidden association and behavior patterns among users, equipment and IPs are deeply mined by utilizing a GNN framework, the suspicious degree among entities can be accurately quantified, and hidden
attack chains can be identified; and meanwhile, a
hybrid storage architecture and a
query optimization technology are adopted, so that a
security analyst can backtrack a complex attack path in a second level while breaking through the
bottleneck of large-scale graph
data access performance, and the
threat hunting efficiency and the high-level attack
traceability are remarkably improved.