This invention relates to the field of
big data technology and discloses an
information security alarm
system based on
big data. The
system comprises a
data acquisition unit that collects multi-source security data in real time, a
processing unit that generates standardized
event data, an analysis unit that performs aggregation and statistics, a calculation unit that calculates a preliminary screening value SX, a
central unit that analyzes the preliminary screening value SX and marks preliminary abnormal events, a
learning unit that marks real abnormal events, an association unit that associates the standardized
event data corresponding to the real abnormal events and matches
attack patterns, and an early warning unit that displays the data on the platform. This invention standardizes the multi-source heterogeneous security data acquired by the acquisition unit through a
processing unit, generating standardized
event data in a unified format. This eliminates differences between different data sources in terms of
data format, field definitions, and time precision, improving
data consistency and
usability, and providing unified data for subsequent analysis, calculation, learning, and association units.