Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

513 results about "Event correlation" patented technology

Event correlation is a technique for making sense of a large number of events and pinpointing the few events that are really important in that mass of information. This is accomplished by looking for and analyzing relationships between events.

Community intelligent monitoring and emergency linkage method and system fusing BIM spatial semantics

The invention discloses a community intelligent monitoring and emergency linkage method and system fusing BIM spatial semantics, and the method comprises the steps: constructing a BIM scene map, and obtaining the attributes and mutual relationships of components and spatial regions in a BIM model; mapping a dynamic target detected in video monitoring into the BIM model, and obtaining spatial semantic information of the dynamic target; based on BIM spatial semantic information of a dynamic target, a target-environment interaction graph is constructed, a graph neural network model is used for training and reasoning, and specific complex events related to spatial contexts are recognized; taking the BIM model as a space-time reference, fusing multi-source heterogeneous data, and reconstructing by adopting a graph-based event association algorithm to form a complete event chain containing an atomic event sequence and an association relationship; and when an emergency event or an event chain is detected to indicate an emergency state, combining BIM preset information and real-time sensor data, dynamically generating an optimal emergency plan, and performing visual commanding and dispatching through a BIM three-dimensional scene and augmented reality.
Owner:ZHEJIANG LEISHENG CONSTRUCTION ENGINEERING CO LTD

Distributed server cluster log processing method and device

The embodiment of the invention provides a distributed server cluster log processing method and device, and the method comprises the steps: constructing a distributed server cluster log collection network, and dynamically distributing collection tasks through a load balancing scheduling center. An incremental data acquisition channel is designed, efficient transmission is realized by using a websocket long connection pool, and the transmission efficiency is optimized in combination with real-time compression coding and a repeated data detection mechanism. An intelligent log analysis model is constructed, the intelligent log analysis model comprises an anomaly detection sub-model, a mode recognition sub-model and an event association analysis sub-model, anomaly score calculation, log classification labeling and multi-dimensional association analysis are achieved based on a deep learning method, and visual display and data export functions are provided. According to the method, the defects of the traditional technology in the aspects of distributed acquisition, data transmission, intelligent analysis and the like are effectively overcome, and the performance and practicability of a log processing system are remarkably improved.
Owner:富盛科技股份有限公司

Method and system for detecting and defending cross-domain threats of power system

The invention provides a method and a system for detecting and defending cross-domain threats of a power system. The method comprises the following steps: after carrying out anomaly identification on operation monitoring data of a physical domain node in a target power grid region to obtain an anomaly identification result and carrying out denial of service attack identification according to network flow data of an information domain node to obtain an attack identification result, carrying out abnormal event association analysis on the anomaly identification result and the attack identification result to obtain an attack cross-domain anomaly identification result; according to key nodes and key risk propagation paths in a cross-domain attack chain generated based on a graph theory algorithm, generating an attack tracing atlas, and according to vulnerability information of the key nodes in the atlas, obtaining a corresponding power system topological graph and a corresponding communication network topological graph; and iteratively generating an active defense rule based on a game theory algorithm and a reinforcement learning algorithm, and issuing the active defense rule to the node. According to the method, the cross-domain attack risk is accurately perceived in real time and adaptive security defense is executed through cross-domain abnormal event association analysis, so that the comprehensiveness and reliability of security protection of the power system are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

Early warning method and system for operation and maintenance delivery abnormal event based on cloud platform

The invention discloses an operation and maintenance delivery abnormal event early warning method and system based on a cloud platform, and relates to the technical field of event early warning. The method comprises the steps of collecting a real-time operation data set of an operation and maintenance delivery link, performing multi-dimensional analysis based on the real-time operation data set, and constructing a multi-dimensional monitoring data set; performing context correlation analysis on the multi-dimensional monitoring data set, and constructing dynamic baseline parameters; deviation degree calculation is carried out on the real-time operation data set, a data deviation value is generated to trigger the cloud platform to carry out abnormal event judgment of operation and maintenance delivery, and an abnormal judgment result is obtained; performing event association according to an abnormality judgment result, determining an abnormality risk level, synchronizing the abnormality risk level to a cloud platform for tracing, generating a multi-level early warning instruction, and pushing the multi-level early warning instruction to a target terminal for graded warning. The technical problem that early warning of the operation and maintenance delivery event is not accurate and timely enough in the prior art is solved, and the technical effect of improving the accuracy and timeliness of early warning of the abnormal event is achieved.
Owner:WUXI LANSHAN INFORMATION TECH CO LTD

Language model collaborative target event processing method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as financial science and technology and medical health, and discloses a target event processing method, device, equipment and medium based on language model collaboration.The method comprises the steps that a target event is monitored and recognized, multi-source data associated with the target event are collected, the multi-source data are fused to generate fused data, and the fused data are sent to a server; and inputting the fusion data into a pre-training language model to generate a decision scheme, performing decision coordination and matching based on the decision scheme, distributing a processing agent, executing a matched decision task by using the processing agent, and generating a decision result. According to the invention, through fusion of multi-source data and pre-training language model deep reasoning and combination of an intelligent agent dynamic cooperation mechanism, intelligent perception, rapid response and cooperative processing of complex events are realized, and the adaptive ability and processing efficiency of the system in response to unknown faults and complex tasks are improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Event root cause intelligent diagnosis method and system for financial service operation risk

ActiveCN120655396AFinanceData setFeature set
The invention provides an event root cause intelligent diagnosis method and system for financial service operation risks, and the method comprises the steps: firstly collecting an operation risk event data set which is generated by an operation risk event in a financial service system and contains various information, and then carrying out the feature extraction of the operation risk event data set; the method comprises the following steps: generating an event feature set containing multi-aspect features, constructing a dynamic event association network based on the event feature set, determining nodes and influence intensity parameters, performing causal path weight iterative calculation on the network by using a preset root cause inference rule set, and positioning a root cause node set; and finally, according to the root cause node set, generating a root cause diagnosis result containing the root cause type identifier, the influence path description and the correlation feature contribution degree, thereby improving the accuracy and efficiency of financial service operation risk root cause diagnosis.
Owner:CHENGDU BINGJIAN INFORMATION TECH CO LTD

Power transmission line mountain fire disaster risk assessment method and system based on space-time event driving

The invention provides a power transmission line mountain fire disaster risk assessment method and system based on space-time event driving, and the method comprises the steps: obtaining mountain fire monitoring data of a to-be-assessed region, and generating a space-time event according to the mountain fire monitoring data; according to an event association rule, the space-time event is associated with a power transmission line tower through a directional edge, and then a power transmission line mountain fire disaster hidden danger map is constructed; performing similarity matching on the time-space events generated in real time and the time-space events in the power transmission line mountain fire disaster hidden danger map, and searching the corresponding time-space events in the power transmission line mountain fire disaster hidden danger map by adopting a map traversal algorithm; and for the searched towers influenced by the space-time events, quantitatively calculating the risk score of each tower based on the data values of the real-time space-time events, and dividing the risk grades according to the risk scores. According to the method, the association precision of power transmission line risk assessment and the precision and efficiency of power transmission line forest fire prevention and control can be improved.
Owner:ZHUHAI POWER SUPPLY BUREAU GUANGDONG POWER GIRD CO

Automatic template generation method and system based on UG software

The invention belongs to the technical field of intelligent manufacturing and automatic design optimization, and discloses an automatic template generation method and system based on UG software, and the method comprises the steps: capturing a sketch operation event flow, carrying out the deep binding of geometric parameters and tolerance rules, generating a technology enhancement parameter set, and constructing a dual-channel instruction set; synchronously generating a two-dimensional engineering drawing projection and a three-dimensional expansion drawing preview; detecting conflicts in real time, and calling an exception correction plan library for dynamic correction; generating a zero-conflict BREP boundary model and a correction track log, and establishing a log-plan library mapping relation; generating an enhanced BERP model through a template drawing optimization mechanism; further generating a processing path instruction set, and integrating the processing path instruction set into a process compliance template drawing package; generating a cross-platform manufacturing package; constructing a quality index set, and generating an abnormal event association graph; and calculating a rule parameter adjustment amount, dynamically updating the process rule base, generating a global strategy packet, and reversely injecting sketch parameter constraints to form a continuous optimization cycle.
Owner:河北鑫泰轴承锻造有限公司

Security event association analysis and question and answer method and system and medium

The invention provides a security event association analysis and question answering method and system and a medium, and the method comprises the following steps: context-aware query completion: receiving an original query input by a user, obtaining a historical record of a current dialogue, and forming a context enhanced query according to the original query and the historical record of the current dialogue; dynamic task identification: outputting a prediction task model according to the context enhancement query in combination with a dynamic task identification strategy; multi-dimensional retrieval: performing multi-dimensional retrieval on the prediction task model to obtain a final knowledge context packet; and knowledge-driven response generation: generating a knowledge-driven response based on the knowledge context packet, and outputting a final security analysis report after the generated content passes verification. According to the method, efficient, accurate and explainable intelligent association analysis of the multi-source heterogeneous security data is realized by constructing a multi-dimensional knowledge base, designing a dynamic task recognition mechanism and realizing context-aware query completion.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Electricity consumption information acquisition intelligent configuration method based on pattern recognition algorithm

The invention discloses an electricity utilization information acquisition intelligent configuration method based on a pattern recognition algorithm, and relates to the technical field of intelligent power grids, and the method comprises the steps: collecting a directional data stream, inputting a federal map neural network to construct a power distribution network physical connection relation, and generating a spatio-temporal topological feature vector; extracting a current effective value component of the directional data flow as an electrical load sequence, extracting an equipment state code to identify a voltage sag event, injecting voltage sag event associated disturbance into the electrical load sequence in combination with an event propagation path weight of a spatio-temporal topological feature vector, and generating an anti-fact sample set; and compressing the new configuration strategy through a knowledge distillation engine, and outputting an event response logic and a parameter adjustment instruction to form an executable configuration strategy. According to the method, through anti-fact sample generation and reinforcement learning optimization under spatial-temporal topological feature vector constraint, a physical rule deep embedding decision is realized.
Owner:HANGZHOU HUALONG ELECTRONIC TECH CO LTD

Network security situation real-time perception and visual display system

The invention belongs to the technical field of network security, and discloses a network security situation real-time perception and visual display system, which comprises the following modules: a real-time data acquisition module, an intelligent analysis and situation evaluation module, a three-dimensional visual display module and an automatic decision processing module. According to the system, dual mechanisms of unsupervised anomaly detection and a supervised machine learning model are fused through an intelligent analysis and situation evaluation module, the recognition precision of unknown anomaly and known threats is improved, and warning, abnormal traffic and asset vulnerability are deeply correlated by using a time sequence event correlation analysis technology; according to the method and the system, the real-time and accurate global situation portrait is formed, meanwhile, a multi-dimensional safety index quantification system is constructed by means of a situation evaluation unit, and a scientific basis is provided for risk hotspot identification and early warning in combination with threat intelligence, asset vulnerability, service criticality and topology dynamic calculation.
Owner:李师谦

Multi-terminal cooperative processing method and system

The invention discloses a multi-terminal cooperative processing method and system, and relates to the field of terminal communication, and the method comprises the steps: responding to a trigger signal of an event, determining event information, and initiating a cooperative processing request to at least one second terminal in a communication range; determining a target terminal responding to the cooperative processing request in the second terminal, and constructing a temporary cooperative group including the target terminal; acquiring shared event associated data in the temporary collaborative group, and determining a consensus event description based on the event associated data and / or the event information; a dominant reporting terminal is determined in the temporary cooperation group, and the dominant reporting terminal is used for packaging the consensus event description into a data packet and sending the data packet to a remote management platform; and receiving a response confirmation message returned by the remote management platform, and broadcasting the unique event ID and the processing state in the response confirmation message to all terminals in the temporary collaborative group. The computing resource consumption of the remote management platform can be effectively reduced.
Owner:WUHAN SHENGBOHUI INFORMATION TECH CO LTD

Dynamic electric power question answering system optimization method and system based on knowledge graph

The invention provides a dynamic electric power question-answering system optimization method and system based on a knowledge graph, and the method comprises the steps: collecting heterogeneous operation data of multiple positions of electric power equipment in real time, including regulation document rule constraint items, sensor time sequence state signals and historical maintenance event association items; and mapping the rule constraint item and the event association item to a unified semantic space, eliminating semantic cross interference, and constructing a topological structure. And then dynamically coupling the topological structure with a real-time sequence signal to form a power equipment state evolution graph. Based on the atlas and current state verification parameters uploaded by the distributed sensors, basic association strength values among the nodes are dynamically calibrated, and boundary condition constraints are applied through rule constraint terms. And finally, matching the event association item with the constrained association strength value to generate an abnormal reasoning path optimization strategy for the question and answer request. According to the invention, the accuracy and real-time performance of power equipment abnormity diagnosis are improved.
Owner:HANHOU (BEIJING) TECH CO LTD

Intelligent prediction method and system applied to system log security audit

The invention provides an intelligent prediction method and system applied to system log security audit, and the method comprises the steps: firstly obtaining a historical log data set of a power monitoring system, carrying out the event correlation modeling, generating a log event correlation model, generating a security event prediction rule library based on the log event correlation model through a rule mining algorithm, and carrying out the prediction of the security event. And then obtaining a real-time log data stream, inputting the log event association model to obtain a real-time event association result, matching the real-time event association result with the rule base to generate an abnormal event prediction result, finally generating a security audit report according to the abnormal event prediction result, sending the security audit report to the power monitoring terminal, and updating rule base parameters according to feedback information. Therefore, the abnormal event in the power monitoring system can be predicted in advance, and the intelligent level and the safety guarantee capability of system safety auditing are improved.
Owner:XINYUAN NETWORK TECH CO LTD

Grassroots social governance intelligent decision support system and method based on multi-modal fusion

The invention discloses an intelligent decision support system and method for grassroots social governance based on multi-modal fusion. The method comprises the following steps: S1, acquiring and preprocessing multi-modal data in the field of grassroots social governance; s2, constructing a heterogeneous graph structure according to the data type and the treatment subject category; s3, extracting single-modal features respectively and generating cross-modal dynamic association features; s4, performing collaborative optimization on the heterogeneous graph structure and the cross-modal fusion parameters by adopting a flying fox optimization algorithm; s5, analyzing data in real time according to the optimized heterogeneous graph, and generating potential risk early warning, event trend prediction and event association deduction information; s6, pushing an auxiliary decision-making scheme and a disposal strategy in real time; and S7, continuously optimizing the heterogeneous graph structure by using a feedback result. The decision-making efficiency and accuracy of grassroots social governance are effectively improved.
Owner:INNER MONGOLIA GUOFENG NETWORK TECHNOLOGY CO LTD

User behavior tracking and portrait generation system

The invention provides a user behavior tracking and portrait generation system, which is characterized in that multi-source original behavior data is acquired through a data acquisition module, and a standard behavior event stream is generated through cleaning and standardization; the behavior modeling module is used for carrying out cross-event association and self-defined time window combination modeling on a standard event flow based on a configurable rule engine to generate a complex event flow; the real-time processing and calculation module performs real-time aggregation calculation on the complex event stream, generates a real-time behavior index, a trigger signal and an incremental portrait snapshot in combination with a preset rule, and pushes a behavior trigger signal to a downstream service system; the user portrait management module dynamically updates user tag weights and values according to the real-time indexes, and generates a target user portrait tag library and a lightweight tag change event stream; the data storage and query module stores data of each link; and the visual configuration and operation and maintenance module issues a configuration instruction through a visual interface, and monitors full-link operation and task scheduling. And real-time accurate portrait construction and instant service response are realized.
Owner:DIGITAL HAINAN CO LTD

Historical interaction information processing method based on artificial intelligence

The invention provides a historical interaction information processing method based on artificial intelligence. The method comprises the following steps: processing a historical interaction data set associated with a user and generating structured heterogeneous data; performing semantic analysis, emotion recognition and cross-modal association coding on the structured heterogeneous data through a pre-trained multi-modal feature extraction model to generate a multi-modal feature vector containing text semantic features and voice emotion features; based on the multi-modal feature vectors, event association features, appeal evolution paths and risk prediction indexes in historical interaction data are extracted through a time sequence deep learning model; and through a cross-modal attention fusion algorithm, dynamically weighting and integrating the multi-modal feature vector and event association features, an appeal evolution path and a risk prediction index, and constructing a dynamic prompt template adaptive to a real-time scene and a user state. According to the method, the customer service efficiency of the OTA platform is remarkably improved, and the method has remarkable commercial values in the aspects of improving the service efficiency, reducing the operation cost, avoiding legal risks and the like.
Owner:FEIYOU TECH CO LTD

Power data communication network security situation prediction method

The invention discloses a power data communication network security situation prediction method, which comprises the following steps of: aiming at a hot spot multi-dimensional orientation description vector, acquiring a network security event log, adopting a time sequence event chain construction technology, and determining event triggering frequency and service interruption duration related to a hot spot through matching of event triggering frequency and event association strength, so as to predict the security situation of the hot spot. Obtaining an event chain sequence; extracting an event trigger frequency, a service interruption duration and a hotspot influence range from the event chain sequence, and judging a hotspot life cycle stage through quantification of a node load state and traffic abnormal fluctuation to obtain a life cycle quantitative index; and extracting a hot spot influence range and traffic abnormal fluctuation from the global security situation view data, and if the hot spot influence range or the traffic abnormal fluctuation exceeds a preset threshold, adjusting weight redistribution through a node load state to obtain an incremental change feature set. According to the method, the hotspot situation in the power data communication network can be comprehensively and dynamically analyzed, and powerful support is provided for network security management and decision making.
Owner:SUQIAN POWER SUPPLY COMPANY OF JIANGSU PROVINCE POWER

Credit investigation management system, credit investigation management method and equipment based on cloud edge collaboration

The invention provides a cloud edge collaboration-based credit investigation management system, a credit investigation management method and equipment. The credit investigation management system comprises an edge node and a central management and control device. The edge node obtains credit behavior data generated when the user executes the target event, and inputs the credit behavior data, event associated data corresponding to the target event and a historical credit score of the user into a credit evaluation model deployed in the local of the edge node in advance, obtaining a credit score increment output by the credit evaluation model after the user executes the target event; the credit score increment is uploaded to a central management and control device; and the central management and control equipment updates the historical credit score according to the received credit score increment to obtain the latest credit score of the user, and sends the latest credit score to the edge node so as to replace the local historical credit score of the edge node through the latest credit score.
Owner:QIANTANG CREDIT INFORMATION CO LTD

Event attribution convergence method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as machine room monitoring, financial science and technology and medical health, and discloses an event attribution convergence method, device and equipment and a medium. Analyzing and generating an attribution parameter table containing attribution parameters and probability values by utilizing a pre-training language model, analyzing concurrency and association convergence conditions of event data pairs to generate association degrees among events, dynamically updating the attribution parameter table according to the association degrees, receiving to-be-processed event data, judging whether the to-be-processed event data exist in the attribution parameter table or not, and if yes, executing the next step; and if yes, executing hierarchical convergence judgment and executing convergence or release, and if not, executing model-assisted convergence and executing convergence or release. According to the method, automatic extraction and dynamic updating of the attribution parameters are achieved by combining the historical convergence data and the pre-training language model, the convergence mode is selected according to the matching condition, the event association recognition accuracy and convergence processing adaptivity are improved, and the processing efficiency is improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Data flow supervision method and system

The invention relates to the technical field of data processing, and provides a data flow supervision method and system.The method comprises the steps that log data and safety data of different systems are collected, various risk key features related to risk events are obtained through analysis, multi-dimensional risk event correlation analysis is conducted, risk links corresponding to the risk events are constructed, and the risk events are monitored; performing risk assessment calculation on each risk link, determining a risk level of each risk link, and identifying a collaborative risk behavior; and on the basis of the obtained feature matching calculation result, the obtained semantic matching analysis result and the case quality score of each candidate case obtained by matching, performing comprehensive evaluation on each candidate case matched with the to-be-identified event, and determining a final candidate case. According to the invention, the risk event identification precision is improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD

Heterogeneous database synchronization method and device, electronic equipment and storage medium

The invention relates to a heterogeneous database synchronization method and device, electronic equipment and a storage medium, and the method comprises the steps: analyzing a transaction log of a source database, extracting and generating an abstract syntax tree of a DDL event, and carrying out the node-level syntax conversion of the abstract syntax tree according to the database type of a target database and a preset syntax mapping rule base, and obtaining an equivalent DDL operation sequence of the target database, blocking a data processing operation corresponding to the database object associated with the DDL event, and executing the equivalent DDL operation sequence on the target database. The whole-process intelligent processing of the isomerous database DDL is realized without depending on manpower, the equivalent DDL operation sequence of the target database having semantic consistency with the DDL event of the source database is obtained through dynamic replenishment and deep analysis of the DDL event and the context semantics of the DDL event in combination with the grammar mapping rule base, the processing efficiency of isomerous database DDL synchronization is improved, and the processing efficiency of isomerous database DDL synchronization is improved. And meanwhile, the safety and reliability of synchronous processing can be ensured.
Owner:JINZHUAN INFORMATION TECHNOLOGY CO LTD

Cross-platform income data closed-loop analysis method

The invention discloses a cross-platform income data closed-loop analysis method, and particularly relates to the technical field of data closed-loop analysis. The method comprises the following steps: collecting original multi-platform interaction data, and generating a cross-platform interaction data set; executing multi-layer anonymous identifier mapping, and outputting a unified user link identifier sequence and event sequence mapping table; calculating an observability matrix of each platform event chain to obtain a cross-platform observability score set; a cross-platform implicit path sequence set is mined based on a probabilistic graph reasoning method, and a backflow path complete sequence is constructed in combination with a cross-platform observability score set; performing income event association calculation and link credibility weight normalization, and outputting a closed-loop income attribution result; the closed-loop income attribution result is fed back to the cross-platform putting strategy database, closed-loop optimization is completed, accurate reduction of the real conversion path of the user and closed-loop quantitative analysis of multi-platform income contribution are achieved, and the optimization effect and the actual income performance of the cross-platform putting strategy are improved.
Owner:YUNDONG (SHANGHAI) TECH CO LTD

Reactor turn-to-turn short circuit monitoring method fusing magnetic field difference method and loss factor method

The invention relates to the technical field of electromagnetic data processing, in particular to a reactor turn-to-turn short circuit monitoring method fusing a magnetic field difference method and a loss factor method. According to the method, a plurality of event pairs are constructed by adopting an event correlation method, fundamental decoupling of fault features of thermal response and normal working condition fluctuation is realized by comparing differences between event response features and standard event response features corresponding to working condition data, and dynamic thermal response deviation is obtained. Two-dimensional diagnosis features are mapped into a parameter space by using a parameter space method, so that the position of a mapping point represents the dynamic trend of a fault, tracking is carried out based on the position, a future state can be determined in advance based on the trend before a fault result occurs, and the problem of monitoring time lag is solved. And an effective fusion diagnosis result is obtained for reference of workers.
Owner:UHV CO OF STATE GRID HEILONGJIANG ELECTRIC POWER CO LTD

Event correlation determination in extended detection and response systems

This disclosure describes techniques for evaluating a correlation between two monitoring events based on a regularized co-occurrence occurrence measure associated with the two monitoring events. For example, in some cases, the techniques described herein include determining a co-occurrence measure associated with two monitoring events by regularizing an initial co-occurrence measure based on the respective occurrence measures associated with the two monitoring events. In some cases, an example system: (i) determines a first occurrence measure associated with a first event and a second occurrence measure associated with a second event, (ii) determines a co-occurrence measure associated with the two events, (iii) determines a regularization parameter based on the first and second occurrence measures as well as the co-occurrence measure, and (iv) determines a regularized co-occurrence measure based on the co-occurrence measure and the regularization parameter.
Owner:CISCO SYSTEMS INC

Automatic operation and maintenance event processing method and system based on AI intelligent agent

The invention discloses an operation and maintenance event automatic processing method and system based on an AI intelligent agent, and the system comprises a data collection module which is used for collecting various types of data in an operation and maintenance system and carrying out the preprocessing of the data; the event association analysis module is used for generating operation and maintenance event types and association mode information; the event time prediction module is used for predicting the evolution trend of the operation and maintenance event; the event processing strategy optimization module is used for adjusting the priority of operation and maintenance events and a resource scheduling scheme; the event automatic processing module is used for executing automatic processing of operation and maintenance events; the processing effect evaluation module is used for evaluating the processing effect of the operation and maintenance event; and the strategy dynamic adjustment module is used for realizing dynamic optimization of the strategy. The invention relates to the technical field of intelligent operation and maintenance, aims to solve the problems of slow response and stiff strategy in traditional operation and maintenance event processing, can provide an efficient and scientific optimization scheme in operation and maintenance event automatic processing, and brings remarkable technical value for practical application.
Owner:HARBIN UNIV OF SCI & TECH

Urban public security risk chain identification method and system based on graph neural network

The invention provides an urban public security risk chain identification method and system based on a graph neural network, and relates to the technical field of public security risk management.The method comprises the steps that an event association topological graph is constructed, and an optimal sampling path is determined by adopting a self-adaptive two-way jump sampling algorithm; identifying logic breaking points, searching potential transition events to construct a complete risk chain, and finally calculating credibility scores based on conduction strength characteristics to screen the risk chain. According to the invention, the implicit association in the risk chain can be automatically found, the risk early warning precision is improved, and a scientific basis is provided for urban public safety management decisions.
Owner:HANGZHOU ZHUIXING VIDEO TECH CO LTD

Network security event association detection method based on big data analysis

The invention relates to the technical field of information security, in particular to a network security event association detection method based on big data analysis. Comprising the following steps: data acquisition; feature extraction and fusion; correlation detection is carried out, wherein an improved Apriori-Bayesian fusion algorithm is adopted, and discretization processing is carried out on the event feature vectors; mining a frequent item set by using an improved Apriori algorithm; and risk assessment and result output. According to the method, an improved Apriori-Bayesian fusion algorithm is adopted, discretization processing is carried out on event feature vectors according to types, meanwhile, a security event weight factor is introduced to calculate the item set weighted support degree, and a minimum support degree threshold value is dynamically adjusted to mine a frequent item set; the association confidence coefficient is calculated in combination with the Bayesian network, and the confidence coefficient is corrected through the space-time association coefficient, so that the association relationship between the network security events can be scientifically judged, the problems of limited association judgment accuracy and lack of quantitative correction in the traditional technology are solved, and the association false alarm and missing report probability is reduced.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH

Video processing method and system based on big data technology

The invention discloses a video processing method and system based on a big data technology, and constructs an intelligent video processing system with semantic driving, man-machine collaboration and continuous evolution by fusing advanced technologies such as big data processing, bimodal AI analysis, knowledge graph, natural language understanding and feedback learning. Compared with a traditional video monitoring system, the scheme has the advantages that the retrieval efficiency, the semantic understanding depth, the event association analysis capability, the user interaction experience, the system self-optimization capability and the like are remarkably improved, and the problems of incomplete seeing, difficulty in finding, inaccuracy in judgment and poor use are effectively solved.
Owner:HANGZHOU LINPIN SECURITY TECH CO LTD

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE