Intelligent network data security protection method, system and device and medium thereof

By combining adaptive deep learning and graph neural networks, homomorphic encryption and federated learning, multimodal data fusion and incremental learning, and quantum key distribution and quantum firewall methods, the problems of complex attack pattern recognition, insufficient data privacy protection, contradiction between real-time and resource consumption and poor interpretability of protection mechanisms in intelligent network data security protection are solved, and efficient, real-time and transparent network data security protection is achieved.

CN120017327APending Publication Date: 2025-05-16SHICHUAN DIGITAL TECH (SHENZHEN) CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510072175.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing intelligent network data security protection methods are difficult to identify when facing complex attack modes, insufficient data privacy protection, conflicts with resource consumption, and poor interpretability of the protection mechanism.

Method used

Adaptive deep learning and graph neural networks are adopted to achieve data privacy protection through homomorphic encryption and federated learning, multimodal data fusion and incremental learning are used to improve real-time and adaptability, and enhance the resistance of the protection system through quantum key distribution and quantum firewall.

Benefits of technology

It improves the detection accuracy of complex attack modes, ensures data privacy protection, optimizes real-time and resource consumption, and enhances the transparency of the protection system and user trust.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017327A_ABST
    Figure CN120017327A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent network data security protection method, system and device and a medium thereof, and the method comprises the following steps: obtaining network flow data, monitoring the network flow of the network flow data through a flow collection device and a network monitoring tool, extracting the feature information of a data packet, carrying out the preprocessing based on the feature information of the data packet, and obtaining the network flow data; according to the convolutional neural network and the LSTM, time sequence features are captured, modeling is carried out according to the convolutional neural network, and a relation between devices in the network and a topological structure of a data stream are determined; on the basis of privacy protection and calculation sharing of homomorphic encryption, encryption calculation is carried out through a Paillier encryption algorithm, summation and multiplication operations are carried out on encrypted data, the encrypted data are distributed on multiple nodes, local training is carried out on the basis of a federal learning technology, and the data are obtained. According to the method, deep adaptive learning is combined with the graph neural network, so that the detection precision of an attack mode is improved, particularly modeling of complex attack behaviors is realized, data privacy protection is ensured, and meanwhile, the calculation efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network data technology, and in particular to an intelligent network data security protection method, system, device and medium thereof. Background Art

[0002] Network data security protection is a strategy and means to monitor, analyze, detect and prevent data leakage, intrusion, malicious attacks and other security threats in the network in real time by using advanced technologies such as artificial intelligence (AI), machine learning (ML), deep learning (DL) and big data analysis. It not only relies on traditional static technologies such as firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS), but also combines dynamic intelligent analysis models to cope with increasingly complex and changing network attack methods.

[0003] Key features include:

[0004] Automated monitoring: Detect anomalies and issue alerts by monitoring network traffic, data behavior, and user activities in real time.

[0005] Intelligent threat identification and response: Use machine learning models to predict and identify potential threats and automatically trigger defense measures.

[0006] Dynamic defense mechanism: Dynamically adjusts protection strategies based on real-time attack intelligence and network behavior to avoid the limitations of traditional static protection methods.

[0007] Encryption and Authentication: Use the latest encryption algorithms and authentication technologies to protect the privacy and integrity of data during transmission.

[0008] There are many technical problems in the existing intelligent network data security protection methods, mainly including:

[0009] Difficulty in identifying complex attack patterns: Although existing protection systems utilize technologies such as deep learning and machine learning, these systems still have difficulty in identifying increasingly complex and variable attack patterns, especially when the attack strategy has not yet been identified by the trained model, which can easily lead to missed reports.

[0010] Insufficient data privacy protection: With the increasing demand for privacy protection, especially in the context of regulations such as GDPR, existing protection solutions often do not address how to analyze and process data without leaking data content, leading to the risk of privacy leakage.

[0011] The contradiction between real-time performance and resource consumption: Some efficient security protection methods (such as deep learning-based detection systems) often require a lot of computing resources and processing time, making real-time detection and response difficult, especially in large-scale networks.

[0012] Poor explainability of protection mechanisms: Existing protection systems based on deep learning and other machine learning often lack sufficient transparency and explainability, resulting in difficulty in explaining why the system makes certain decisions when making protection decisions, thus affecting users' trust in the system.

[0013] Based on one of these problems, we propose an intelligent network data security protection method, system, device and medium. Summary of the invention

[0014] In order to solve one of the above technical problems, an intelligent network data security protection method, system, device and medium are provided, which will combine the most cutting-edge technologies (such as adaptive deep learning, federated learning, graph neural networks) to solve the problem of complex attack pattern recognition, and on this basis, perform privacy protection, real-time optimization and interpretability enhancement.

[0015] In order to achieve the above objectives, the technical inventions adopted by the present invention are:

[0016] A first aspect: an intelligent network data security protection method, comprising the following steps:

[0017] Obtain network traffic data, the network traffic data is monitored through traffic collection equipment and network monitoring tools, characteristic information of data packets is extracted, preprocessing is performed based on the characteristic information of data packets, time series characteristics are captured according to convolutional neural networks and LSTM, and the relationship between devices in the network and the topological structure of data flows are determined according to graph convolutional neural network modeling;

[0018] Privacy protection and computing sharing based on homomorphic encryption, encrypted computing is performed through the Paillier encryption algorithm, summation and multiplication operations are performed on encrypted data, encrypted data is distributed on multiple nodes, local training is performed based on federated learning technology, and gradient updates are sent to the central node for aggregation;

[0019] Build a multimodal data fusion model, input multimodal data into the model and conduct comprehensive analysis, and provide real-time feedback based on incremental learning technology to update and adjust protection data;

[0020] According to the key exchange during data transmission based on quantum key distribution encryption, according to the quantum firewall, the firewall is trained by simulating quantum computing attacks;

[0021] Automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to current network traffic status and attack patterns, and dynamically trace attack patterns and adjust protection strategies through analysis of historical attack behaviors.

[0022] Preferably: the federated learning technology includes: each participating node trains a model and shares model parameters to a central server for aggregation to form a global model.

[0023] Preferably: the Paillier encryption algorithm and decryption formula:

[0024] E(m)=g m ·r n mod N 2 ;

[0025]

[0026] Where m is the plaintext data; r is a random number; g is the generator; N is the modulus; E(m) is the encrypted data; c is the ciphertext; λ is the Cardano exponent; μ is the auxiliary parameter for calculating decryption; D(c) is the decrypted data;

[0027] The gradient update formula in federated learning is:

[0028]

[0029] Where: θ i is the model parameter of the i-th client; K is the number of clients; θ global are global model parameters.

[0030] Preferably, the multimodal data includes network traffic data, device behavior log data and user activity data.

[0031] Preferably, the real-time feedback based on incremental learning technology, updating and adjusting the protection data, the specific formula is:

[0032] θ new =θ old +η·Δθ;

[0033] Where: θ new is the updated model parameter; θ old are the old model parameters; η is the learning rate; Δθ is the incremental parameter update.

[0034] Preferably, the multi-level protection mechanism is used to automatically respond to attacks and adjust strategies to deal with different types of attacks, specifically including:

[0035] Collect data sets of different network attack types, including: information D output by network traffic analysis flow 、Information output by IDS system D ids And the output information of log analysis D logs :

[0036] 1) Information D output by the network traffic analysisflow :

[0037] D flow ={d1, d2, ..., d N};

[0038] The d i Includes source IP address, destination IP address, protocol and / or port; N represents the total number;

[0039] 2) Information D output by the IDS system ids :

[0040] D ids ={d1, d2, ..., d m};

[0041] Each of the j represents an intrusion detection record, which includes the intrusion type and / or the detection time; m represents the total number;

[0042] 3) Output information D of the log analysis logs :

[0043] D logs ={d1, d2, ..., d p};

[0044] Each of the k represents a log record, which includes an event description and / or occurrence time; p represents the total number;

[0045] Based on deep reinforcement learning, an intelligent decision engine is determined, which automatically adjusts firewalls, intrusion prevention systems and intrusion detection systems according to different attack types.

[0046] Preferably: the characteristic information of the data packet includes flow size, transmission delay, IP address, port number and protocol type, the preprocessing includes denoising, normalization and outlier removal, the flow collection equipment includes Net Flow and sFlow, and the network monitoring tool includes Wire shark.

[0047] A second aspect: an intelligent network data security protection system, comprising:

[0048] A data acquisition module is used to acquire network traffic data. The network traffic data is monitored through traffic collection equipment and network monitoring tools, and feature information of data packets is extracted. Preprocessing is performed based on the feature information of data packets. Time series features are captured based on convolutional neural networks and LSTM. Based on graph convolutional neural network modeling, the relationship between devices in the network and the topological structure of data flows are determined;

[0049] The privacy protection and computing module is used for privacy protection and computing sharing based on homomorphic encryption. It performs encrypted computing through the Paillier encryption algorithm, performs summation and multiplication operations on encrypted data, distributes encrypted data on multiple nodes, performs local training based on federated learning technology, and then sends gradient updates to the central node for aggregation;

[0050] Build a data fusion model module to build a multimodal data fusion model, input multimodal data into the model and conduct comprehensive analysis, and provide real-time feedback based on incremental learning technology to update and adjust protection data;

[0051] A quantum computing module for quantum key distribution encryption based on key exchange during data transmission and for training firewalls by simulating quantum computing attacks based on quantum firewalls;

[0052] The dynamic adjustment module is used to automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to the current network traffic status and attack mode, and dynamically trace back attack modes and adjust protection strategies through analysis of historical attack behaviors.

[0053] A third aspect: A computer device comprising:

[0054] processor;

[0055] A memory for storing executable instructions;

[0056] Wherein, the processor is used to read the executable instructions from the memory and execute the executable instructions to implement the intelligent network data security protection method.

[0057] A fourth aspect: A computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor implements the intelligent network data security protection method.

[0058] Compared with the prior art, the present invention has the following beneficial effects:

[0059] 1. The present invention combines deep adaptive learning with graph neural network (GNN): improving the detection accuracy of attack patterns, especially the modeling of complex attack behaviors.

[0060] 2. The present invention uses homomorphic encryption and distributed computing to ensure data privacy protection while improving computing efficiency.

[0061] 3. The present invention enhances the adaptability of the model in a dynamic network environment through multimodal data fusion and incremental learning.

[0062] 4. The present invention uses quantum encryption and quantum firewall to enhance the protection system's resistance to future quantum computing threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a flow chart of the intelligent network data security protection method of the present invention;

[0064] Figure 2 It is a module diagram of the intelligent network data security protection system of the present invention.

[0065] Figure 3 It is a schematic diagram of the structure of the computer device of the present invention;

[0066] In the figure, 10 is a computer device; 1002 is a processor; 1004 is a memory; and 1006 is a transmission device. DETAILED DESCRIPTION

[0067] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art may think of other obvious variations.

[0068] Embodiment 1:

[0069] Reference Figure 1 As shown, an intelligent network data security protection method includes the following steps:

[0070] Step 10: Obtain network traffic data, where the network traffic data is monitored through traffic collection equipment and network monitoring tools, feature information of data packets is extracted, preprocessing is performed based on the feature information of data packets, time series features are captured based on convolutional neural networks and LSTM, and the relationship between devices in the network and the topological structure of data flows are determined based on graph convolutional neural network modeling;

[0071] Specifically: the characteristic information of the data packet includes flow size, transmission delay, IP address, port number and protocol type, the preprocessing includes denoising, normalization and outlier removal, the flow collection equipment includes NetFlow and sFlow, and the network monitoring tool includes Wireshark.

[0072] Collect network traffic data from various network nodes (such as firewalls, routers, switches, servers, etc.);

[0073] Graph neural network model formula:

[0074] H (k) =σ(∑ v∈N(v) W (k) H (k-1) (v));

[0075] Where: H (k) is the k-th layer node representation; N(v) is the set of neighbor nodes of node v; W (k) is the weight matrix of the kth layer; σ is the activation function (such as ReLU).

[0076] By passing information layer by layer, the complex correlation of network behavior is captured.

[0077] Use graph neural network models to analyze network behavior and identify potential attack patterns (such as DDoS, malicious scanning, data leakage, etc.).

[0078] The identified attacks are classified by a classifier (e.g., SVM, random forest) and provide the type and severity score of the attack.

[0079] Specifically: Use traffic collection equipment and network monitoring tools to continuously monitor network traffic and capture the characteristic information of each data packet;

[0080] These data are preprocessed, including denoising, normalization, outlier removal, etc., and data enhancement technology is used to expand the training set to prevent overfitting.

[0081] Data normalization formula:

[0082]

[0083] Among them, X is the original data, μ is the mean, σ is the standard deviation, X ′ is the normalized data.

[0084] Deep adaptive learning model: Combining convolutional neural network and LSTM to capture time series features.

[0085] CNN is used to extract spatial features from network traffic, and LSTM is used to capture temporal variation trends and dependencies.

[0086] The state update formula in the LSTM model is:

[0087] h t =f(W hh h t-1 +W xh x t +b h );

[0088] Among them, h t is the hidden state of the current time step, x t is the input data, W hh and W xh are the state transfer and input weight matrices, respectively, and b h For bias.

[0089] Combined with graph convolutional neural networks to model the relationship between devices in the network (such as hosts, routers, etc.) and the topological structure of data flows.

[0090] The convolution operation formula of one layer of graph convolutional network is:

[0091]

[0092] Among them, H (l) is the node feature matrix of the lth layer, is the normalized adjacency matrix, W (l) is the weight matrix of the convolutional layer, and σ is the activation function.

[0093] By combining deep adaptive learning and graph neural networks, the system can more accurately identify complex attack patterns, especially in highly dynamic network environments.

[0094] Step 20: Privacy protection and computation sharing based on homomorphic encryption. Encrypted computation is performed using the Paillier encryption algorithm. Sum and multiplication operations are performed on encrypted data. The encrypted data is distributed on multiple nodes. Local training is performed based on federated learning technology. Gradient updates are then sent to the central node for aggregation.

[0095] Specifically, the federated learning technology includes: each participating node trains the model and shares the model parameters to the central server for aggregation to form a global model; the Paillier encryption algorithm and decryption formula:

[0096] E(m)=g m ·r n mod N 2 ;

[0097]

[0098] Where m is the plaintext data; r is a random number; g is the generator; N is the modulus; E(m) is the encrypted data; c is the ciphertext; λ is the Cardano exponent; μ is the auxiliary parameter for calculating decryption; D(c) is the decrypted data;

[0099] The gradient update formula in federated learning is:

[0100]

[0101] Where: θ i is the model parameter of the i-th client; K is the number of clients; θ global are global model parameters.

[0102] Specifically, homomorphic encryption algorithms perform calculations on encrypted data to protect data privacy. For blockchain data or sensitive information, the Paillier encryption algorithm can be used for encrypted calculations, so that the original data does not need to be exposed during the processing.

[0103] Paillier encryption supports addition and multiplication operations on encrypted data and is particularly suitable for privacy-preserving computing.

[0104] Through this encryption method, data addition and multiplication operations can be performed in an encrypted state to avoid exposing sensitive information.

[0105] Distribute encrypted data on multiple nodes for local training to avoid uploading all data to a central server for processing. All calculations are performed on encrypted data to ensure data privacy is not leaked.

[0106] In the federated learning method, each participating node (such as user equipment) independently trains its own model and shares the model parameters (rather than the original data) to a central server for aggregation to form a global model.

[0107] All calculation processes are performed on encrypted data to prevent data leakage.

[0108] Homomorphic encryption calculations are relatively inefficient, so encryption calculations need to be optimized. Technologies such as ciphertext polynomial optimization and batch processing can be used to reduce calculation delays and resource consumption. Optimized encryption calculations can make encryption processing more efficient, which is especially important in real-time data processing.

[0109] Step 30: Build a multimodal data fusion model, input the multimodal data into the model and conduct comprehensive analysis, and update and adjust the protection data based on real-time feedback of incremental learning technology;

[0110] Specifically, the multimodal data includes network traffic data, device behavior log data and user activity data.

[0111] The incremental learning technology is used to provide real-time feedback, update and adjust the protection data. The specific formula is:

[0112] θ new =θ old +η·Δθ;

[0113] Where: θ new is the updated model parameter; θ old are the old model parameters; η is the learning rate; Δθ is the incremental parameter update.

[0114] Specifically, multimodal data input not only relies on network traffic data, but also combines multiple modal inputs such as device behavior logs and user activity data, and uses multimodal learning technology to comprehensively analyze various types of data. By analyzing different data sources, more complex attack patterns and network anomalies can be discovered.

[0115] For example, text mining technology can be used to analyze abnormal behavior patterns in network device logs, and image processing technology can be used to analyze suspicious activities on device screens or video surveillance streams. These different data sources can be combined to enhance the system's protection capabilities.

[0116] The use of incremental learning methods enables the model to quickly adapt to new data and new attack patterns without complete retraining. Incremental learning can effectively improve the real-time responsiveness of the model and ensure that the model is continuously updated as new data is added, thereby improving the accuracy of the system.

[0117] The incremental learning model can maintain the effectiveness of the model through a small update every time new data arrives, avoiding the waste of resources of retraining the full amount of data.

[0118] Based on the real-time feedback of the model, the protection strategy is continuously optimized and adjusted to improve the accuracy and robustness of the system. Through continuous learning and adaptation, the system can respond to changes in the external environment in real time to ensure the efficiency of the protection strategy.

[0119] Step 40, according to the key exchange in the data transmission process based on quantum key distribution encryption, according to the quantum firewall by simulating quantum computing attacks to train the firewall;

[0120] Specifically, quantum key distribution (QKD) uses the principle of quantum entanglement to achieve secure key exchange, ensuring that the key cannot be cracked by quantum computers during data transmission. QKD technology uses quantum physics phenomena such as quantum superposition and quantum entanglement to ensure transmission security. Any attempt to intercept the key will destroy the quantum state and be detected immediately.

[0121] QKD ensures that key exchange during data transmission can be "quantum secure", preventing quantum computers from cracking existing encryption algorithms.

[0122] Quantum firewalls optimize existing firewall policies through quantum algorithms, enabling them to effectively identify and defend against quantum computing breakthroughs in existing encryption technologies. Quantum firewall technology uses quantum computing to simulate attacks and train traditional firewall systems to effectively respond to the challenges of quantum computing.

[0123] The working mechanism of the quantum firewall is similar to that of the traditional firewall, but it adds quantum computing attack simulation, and adaptively optimizes the firewall policy by simulating quantum computing cracking attempts.

[0124] Step 50: Automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to current network traffic status and attack patterns, and dynamically trace back attack patterns and adjust protection strategies through analysis of historical attack behaviors.

[0125] The multi-level protection mechanism automatically responds to attacks and adjusts strategies to deal with different types of attacks, including:

[0126] Collect data sets of different network attack types, including: information D output by network traffic analysis flow 、Information output by IDS system D ids And the output information of log analysis D logs :

[0127] 1) Information D output by the network traffic analysis flow :

[0128] D flow ={d1, d2, ..., d N};

[0129] The d i Includes source IP address, destination IP address, protocol and / or port; N represents the total number;

[0130] 2) Information D output by the IDS system ids :

[0131] D ids ={d1, d2, ..., d m};

[0132] Each of the j represents an intrusion detection record, which includes the intrusion type and / or the detection time; m represents the total number;

[0133] 3) Output information D of the log analysis logs :

[0134] D logs ={d1, d2, ..., d p};

[0135] Each of the k represents a log record, which includes an event description and / or occurrence time; p represents the total number;

[0136] Based on deep reinforcement learning, an intelligent decision engine is determined, which automatically adjusts firewalls, intrusion prevention systems and intrusion detection systems according to different attack types.

[0137] Based on deep reinforcement learning (DRL), an intelligent decision engine is designed, which can automatically adjust network protection components such as firewalls, intrusion prevention systems (IDS) and intrusion detection systems (IPS) according to different attack types. Under different attack modes, the intelligent decision engine can quickly and accurately adjust network security configurations to improve protection capabilities.

[0138] Value update formula in deep reinforcement learning:

[0139]

[0140] Where: Q(s t ,a t ) is state s t Next action a t The value of t is the immediate reward; γ is the discount factor; α is the learning rate.

[0141] Through reinforcement learning algorithms, the system can continuously optimize decision-making strategies and achieve rapid response to complex attack scenarios.

[0142] Combine the current network traffic status and attack mode to adjust the protection strategy in real time. For example, when the system detects a DDoS attack, the intelligent protection system automatically expands the firewall rules and restricts the entry of malicious traffic while keeping legitimate traffic unimpeded. The system can automatically adjust the strategy according to the attack type to improve protection efficiency and system stability.

[0143] Through this process, the adjustment and response of protection strategies can be synchronized with changes in attack patterns to ensure that network security is not breached.

[0144] Embodiment 2

[0145] To solve the above technical problems, based on the first embodiment, another technical solution adopted by the present application is: an intelligent network data security protection method, comprising the following steps:

[0146] Collection of data sets, including information output from network traffic analysis flow 、Information output by IDS system D ids And the output information of log analysis D logs :

[0147] In this embodiment, the information D output by the network traffic analysis flow :The information output by network traffic analysis includes a series of network traffic records, formally expressed as:

[0148] D flow ={d1, d2, ..., d N}

[0149] d i Includes source IP address, destination IP address, protocol and / or port; N represents the total number;

[0150] Among them, each d i The information contained can be expressed as:

[0151] d i = <source IP, destination IP, protocol, port>

[0152] This information can be used to analyze the source, destination, protocol type and port status of network traffic, providing basic information for subsequent tracing of network attacks.

[0153] In this embodiment, the information D output by the IDS system ids :The information output by the IDS system includes a series of intrusion detection records, each record is j Including information such as intrusion type and / or detection time. The formal representation is:

[0154] D ids ={d1, d2, ..., d m}

[0155] d j =<intrusion type, detection time>

[0156] Each d j Indicates an intrusion detection record, which includes the intrusion type and / or detection time; m represents the total number;

[0157] In this embodiment, the output information D of the log analysis logs : The output information of log analysis includes a series of log records:

[0158] D logs ={d1, d2, ..., d p}

[0159] d k = <Event description, time of occurrence>

[0160] Each d k Represents a log record, which includes an event description and / or occurrence time; p represents the total number. This information can be used to understand the various events and corresponding times that occurred on the network, and is helpful for analyzing the time point of the attack and the occurrence of the event.

[0161] In this embodiment, information from network traffic analysis, IDS system output, and log analysis is collected. Each type of information contains multiple records, and each record contains specific key information, such as source IP, target IP, protocol, intrusion type, event description, and occurrence time.

[0162] This information will be used as dataset D flow , D ids and D logs This dataset collection method can provide multi-dimensional information and provide a rich data foundation for tracing and analyzing network attacks.

[0163] The above embodiments only express the implementation methods of the relevant practical applications of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.

[0164] Embodiment three:

[0165] To solve the above technical problems, based on the first embodiment, another technical solution adopted by the present application is: an intelligent network data security protection method, comprising the following steps:

[0166] Step 1: Collect network traffic data, access logs, API call records, etc. from various network nodes (such as firewalls, routers, switches, servers, etc.).

[0167] Use traffic collection equipment (such as NetFlow, sFlow, etc.) to sample network traffic and collect data at the protocol layer, transport layer, and application layer.

[0168] Clean, deduplicate, format, and normalize the collected network traffic data.

[0169] Feature extraction and data enhancement:

[0170] Extract network traffic characteristics from raw data, such as traffic size, transmission delay, IP address distribution, port number, etc.

[0171] Use data augmentation techniques (such as data synthesis, noise injection, etc.) to increase the diversity of training data to improve the generalization ability of the model.

[0172] Step 2: Build a network graph model:

[0173] The nodes (such as hosts, routers, switches, etc.) and data flows (such as TCP, UDP packets, etc.) in the network are modeled as nodes and edges of a graph.

[0174] Graph convolution is performed using graph neural network (GNN) to map network traffic data into a graph structure.

[0175] Graph neural network model formula:

[0176]

[0177] in:

[0178] H (k) is the k-th layer node representation.

[0179] N(v) is the set of neighbor nodes of node v.

[0180] W (k) is the weight matrix of the kth layer.

[0181] σ is the activation function (such as ReLU).

[0182] The model passes information through layers to capture the complex correlation of network behavior.

[0183] Attack pattern recognition and classification:

[0184] Use graph neural network models to analyze network behavior and identify potential attack patterns (such as DDoS, malicious scanning, data leakage, etc.).

[0185] The identified attacks are classified by a classifier (e.g., SVM, random forest) and provide the type and severity score of the attack.

[0186] Step 3: Adaptive Deep Learning Architecture:

[0187] An adaptive deep learning model combining deep convolutional neural network (CNN) and long short-term memory network (LSTM) is used for dynamic learning and updating.

[0188] By regularly feeding new attack samples and network behaviors into the system, and utilizing a small amount of labeled samples and unlabeled data, the model weights are updated through unsupervised learning.

[0189] Adaptive model training formula:

[0190]

[0191] in:

[0192] θ t are the parameters of the current model.

[0193] η is the learning rate.

[0194] L(θ t ,D t ) is the loss function, D t is the current training dataset. Online incremental learning

[0195] The system uses incremental learning methods to continuously update model parameters based on new attack patterns captured in real time, thereby maintaining the timeliness and accuracy of the model.

[0196] Step 4: Homomorphic encryption and data privacy protection:

[0197] During data collection and transmission, homomorphic encryption algorithms are used to encrypt sensitive data to ensure that data privacy is not leaked.

[0198] When training deep learning models, use encrypted data for calculations to avoid directly exposing the data content. Homomorphic encryption formula:

[0199] E(f(D))=f(E(D))

[0200] Among them, E(D) is the encrypted data and f is the calculation function.

[0201] Federated learning architecture:

[0202] Each network node uses local data to train the model, and the model parameters are aggregated and updated through federated learning to ensure that the data does not leave the local area while improving the accuracy of the global model. Federated learning model formula:

[0203]

[0204] in:

[0205] θ global are parameters of the global model.

[0206] θ i is the local model parameter of the ith node.

[0207] Step 5: Explain the decision-making process of the deep learning model through LIME (local interpretable model agnostic explanation method) and SHAP (Shapley value), so that the system can provide the credibility and basis of each decision. LIME model explanation formula:

[0208]

[0209] in, is the prediction result, X is the input data, is the explanation generated by the LIME method.

[0210] Decision-making transparency:

[0211] Provides detailed decision logs and attack analysis reports, and uses blockchain technology to ensure that the logs cannot be tampered with, allowing users to review every security decision of the system and verify its compliance and rationality.

[0212] This solution uses cutting-edge technologies such as adaptive deep learning, graph neural networks, federated learning, and homomorphic encryption to solve key problems in current intelligent network data security protection methods, especially the difficulty in identifying complex attack patterns.

[0213] Significant progress has been achieved through:

[0214] Accurate identification and prediction of attack patterns:

[0215] Graph Neural Networks (GNNs) are used to capture the relationship between nodes and data flows in the network, providing efficient modeling of complex attack patterns and identifying different types of network attacks, such as DDoS, malicious scanning, spyware, etc. Combined with adaptive deep learning (including CNN and LSTM models), the system can automatically train and update as new attack samples are added, continuously improving recognition accuracy, especially when facing unknown attack patterns, the system can self-adjust and optimize.

[0216] Privacy protection and compliance assurance:

[0217] By adopting homomorphic encryption, data is ensured not to be leaked during the processing process. Even during in-depth analysis and testing, sensitive data remains encrypted, thereby effectively protecting user privacy.

[0218] The application of federated learning enables multiple network nodes to collaboratively train models while ensuring privacy, avoiding centralized storage and exchange of data and reducing the risk of privacy leakage.

[0219] Enhanced explainability and transparency:

[0220] Combined with interpretability technologies such as LIME and SHAP, it solves the "black box" problem of deep learning models, provides a transparent and explainable basis for each decision, and enhances users' trust in the system.

[0221] By using blockchain technology to record all security decisions and event logs, the immutability of these records is guaranteed, further improving the transparency of the system and facilitating auditing and traceability.

[0222] Performance optimization and real-time response:

[0223] The adaptive learning mechanism and incremental learning method of this solution can reduce the consumption of computing resources and avoid the real-time bottleneck of traditional deep learning models by intelligently selecting data samples and dynamically adjusting models when facing massive data.

[0224] The real-time adjustment mechanism of the multi-level protection strategy combines the network status and traffic pattern to automatically adjust the firewall, intrusion prevention system and other security mechanisms to cope with various attack scenarios, ensuring the real-time response and flexibility of the system.

[0225] Through the above solution, by introducing a variety of cutting-edge technologies (such as neural networks, adaptive deep learning, federated learning, homomorphic encryption, LIME / SHAP interpretability technology, and blockchain), not only the core problems of inaccurate attack identification, privacy leakage risks, insufficient real-time performance, lack of transparency and interpretability in traditional intelligent network protection methods are solved, but also the system's adaptive ability and protection efficiency are greatly improved. This solution provides a more comprehensive, flexible, and powerful technical framework for intelligent network data security protection, and can cope with increasingly complex and changing network security threats.

[0226] Embodiment 4:

[0227] like Figure 2 As shown, an intelligent network data security protection system includes:

[0228] A data acquisition module is used to acquire network traffic data. The network traffic data is monitored through traffic collection equipment and network monitoring tools, and feature information of data packets is extracted. Preprocessing is performed based on the feature information of data packets. Time series features are captured based on convolutional neural networks and LSTM. Based on graph convolutional neural network modeling, the relationship between devices in the network and the topological structure of data flows are determined;

[0229] The privacy protection and computing module is used for privacy protection and computing sharing based on homomorphic encryption. It performs encrypted computing through the Paillier encryption algorithm, performs summation and multiplication operations on encrypted data, distributes encrypted data on multiple nodes, performs local training based on federated learning technology, and then sends gradient updates to the central node for aggregation;

[0230] Build a data fusion model module to build a multimodal data fusion model, input multimodal data into the model and conduct comprehensive analysis, and provide real-time feedback based on incremental learning technology to update and adjust protection data;

[0231] A quantum computing module for quantum key distribution encryption based on key exchange during data transmission and for training firewalls by simulating quantum computing attacks based on quantum firewalls;

[0232] The dynamic adjustment module is used to automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to the current network traffic status and attack mode, and dynamically trace back attack modes and adjust protection strategies through analysis of historical attack behaviors.

[0233] The foregoing Figure 1The various variations and specific examples of an intelligent network data security protection method in Example 1 are also applicable to an intelligent network data security protection system in this embodiment. Through the above detailed description of an intelligent network data security protection method, those skilled in the art can clearly know the implementation method of an intelligent network data security protection system in this embodiment, so for the sake of brevity of the specification, it will not be described in detail here.

[0234] Embodiment 5

[0235] An embodiment of the present application provides a computer device, which includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by the processor to implement an intelligent network data security protection method provided in the above method embodiment.

[0236] Figure 3 The hardware structure diagram of a device for implementing an intelligent network data security protection method provided in an embodiment of the present application is shown. The device may participate in or include the apparatus or system provided in an embodiment of the present application. Figure 3 As shown, the computer device 10 may include one or more processors 1002 (the processor may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 1004 for storing data, and a transmission device 1006 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 3 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 3 More or fewer components as shown, or with Figure 3 Different configurations are shown.

[0237] It should be noted that the one or more processors and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer device 10 (or mobile device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0238] The memory 1004 can be used to store software programs and modules of application software, such as a program instruction / data storage device corresponding to an intelligent network data security protection method in an embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 1004, that is, implementing the above-mentioned method. The memory 1004 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1004 may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the computer device 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0239] The transmission device 1006 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer device 10. In one example, the transmission device 1006 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 1006 can be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet wirelessly.

[0240] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer device 10 (or mobile device).

[0241] Embodiment 6

[0242] An embodiment of the present application also provides a computer-readable storage medium, which can be set in a server to store at least one instruction or at least one program related to an intelligent network data security protection method in an embodiment of the method. The at least one instruction or the at least one program is loaded and executed by the processor to implement an intelligent network data security protection method provided in the above-mentioned embodiment of the method.

[0243] Optionally, in this embodiment, the storage medium may be located in at least one of the multiple network servers of the computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0244] Embodiment 7

[0245] The embodiment of the present invention also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. The processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes an intelligent network data security protection method provided in the above various optional implementations.

[0246] It should be noted that the above-mentioned sequence of the embodiments of the present application is for description only and does not represent the advantages and disadvantages of the embodiments. The above-mentioned specific embodiments of the present application are described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0247] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device, equipment and storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0248] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.

[0249] Based on the above ideal embodiments of the present invention, the relevant staff can make various changes and modifications without departing from the technical concept of the present invention through the above description. The technical scope of the present invention is not limited to the contents of the specification, and its technical scope must be determined according to the scope of the claims.

[0250] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of various changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. An intelligent network data security protection method, characterized in that: The following steps are involved: Obtain network traffic data, the network traffic data is monitored through traffic collection equipment and network monitoring tools, characteristic information of data packets is extracted, preprocessing is performed based on the characteristic information of data packets, time series characteristics are captured according to convolutional neural networks and LSTM, and the relationship between devices in the network and the topological structure of data flows are determined according to graph convolutional neural network modeling; Privacy protection and computing sharing based on homomorphic encryption, encrypted computing is performed through the Paillier encryption algorithm, summation and multiplication operations are performed on encrypted data, encrypted data is distributed on multiple nodes, local training is performed based on federated learning technology, and gradient updates are sent to the central node for aggregation; Build a multimodal data fusion model, input multimodal data into the model and conduct comprehensive analysis, and provide real-time feedback based on incremental learning technology to update and adjust protection data; According to the key exchange during data transmission based on quantum key distribution encryption, according to the quantum firewall, the firewall is trained by simulating quantum computing attacks; Automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to current network traffic status and attack patterns, and dynamically trace attack patterns and adjust protection strategies through analysis of historical attack behaviors.

2. The method according to claim 1, characterized in that: The federated learning technology includes: each participating node trains a model and shares model parameters to a central server for aggregation to form a global model.

3. The method according to claim 2, characterized in that: The Paillier encryption algorithm and decryption formula: E(m)=g m ·r n mod N 2 ; Where m is the plaintext data; r is a random number; g is the generator; N is the modulus; E(m) is the encrypted data; c is the ciphertext; λ is the Cardano exponent; μ is the auxiliary parameter for calculating decryption; D(c) is the decrypted data; The gradient update formula in federated learning is: Where: θ i is the model parameter of the i-th client; K is the number of clients; θ global are global model parameters.

4. The method according to claim 1, characterized in that: The multimodal data includes network traffic data, device behavior log data and user activity data.

5. The method according to claim 1, characterized in that: The incremental learning technology is used to provide real-time feedback, update and adjust the protection data. The specific formula is: i new =θ old +η·Δθ; Where: θ new is the updated model parameter; θ old are the old model parameters; η is the learning rate; Δθ is the incremental parameter update.

6. The method according to claim 1, characterized in that: The multi-level protection mechanism automatically responds to attacks and adjusts strategies to deal with different types of attacks, including: Collect data sets of different network attack types, including: information D output by network traffic analysis flow 、Information output by IDS system D ids And the output information of log analysis D logs : 1) Information D output by the network traffic analysis flow : D flow ={d1,d2,...,d N }; The d i Includes source IP address, destination IP address, protocol and / or port; N represents the total number; 2) Information D output by the IDS system ids : D ids ={d1,d2,...,d m }; Each of the j represents an intrusion detection record, which includes the intrusion type and / or the detection time; m represents the total number; 3) Output information D of the log analysis logs : D logs ={d1,d2,...,d p }; Each of the k represents a log record, which includes an event description and / or occurrence time; p represents the total number; Based on deep reinforcement learning, an intelligent decision engine is determined, which automatically adjusts firewalls, intrusion prevention systems and intrusion detection systems according to different attack types.

7. The method according to claim 1, characterized in that: The characteristic information of the data packet includes flow size, transmission delay, IP address, port number and protocol type, the preprocessing includes denoising, normalization and outlier removal, the flow collection equipment includes NetFlow and sFlow, and the network monitoring tool includes Wireshark.

8. An intelligent network data security protection system, applied to the intelligent network data security protection method according to any one of claims 1 to 7, characterized in that: include: A data acquisition module is used to acquire network traffic data. The network traffic data is monitored through traffic collection equipment and network monitoring tools, and feature information of data packets is extracted. Preprocessing is performed based on the feature information of data packets. Time series features are captured based on convolutional neural networks and LSTM. Based on graph convolutional neural network modeling, the relationship between devices in the network and the topological structure of data flows are determined; The privacy protection and computing module is used for privacy protection and computing sharing based on homomorphic encryption. It performs encrypted computing through the Paillier encryption algorithm, performs summation and multiplication operations on encrypted data, distributes encrypted data on multiple nodes, performs local training based on federated learning technology, and then sends gradient updates to the central node for aggregation; Build a data fusion model module to build a multimodal data fusion model, input multimodal data into the model and conduct comprehensive analysis, and provide real-time feedback based on incremental learning technology to update and adjust protection data; A quantum computing module for quantum key distribution encryption based on key exchange during data transmission and for training firewalls by simulating quantum computing attacks based on quantum firewalls; The dynamic adjustment module is used to automatically respond to attacks through a multi-level protection mechanism, adjust strategies to deal with different types of attacks, adjust protection strategies in real time according to the current network traffic status and attack mode, and dynamically trace back attack modes and adjust protection strategies through analysis of historical attack behaviors.

9. A computer device, characterized in that: include: processor; A memory for storing executable instructions; The processor is used to read the executable instructions from the memory and execute the executable instructions to implement the intelligent network data security protection method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor implements the intelligent network data security protection method as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Intelligent acquisition and analysis method and system for network flow data

    CN120956630A

  • Power monitoring system information network security protection method based on situation awareness

    CN121864498A

  • A power monitoring system information network security protection method based on situation awareness

    CN121864498B

  • Ai-based dynamic cybersecurity policy optimization and adaptive threat mitigation method and system

    KR102948402B1