Computer network security monitoring system and method
By using quantum encrypted traffic acquisition, biometric feature extraction and blockchain detection traceability analysis modules in the computer network security monitoring system, the problems of identification difficulties and insufficient encryption security in traditional systems when facing complex network attacks are solved, and efficient and reliable network security monitoring and data transmission security are achieved.
Patent Information
- Application Number
- CN202510320756.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-03-18
AI Technical Summary
When traditional computer network monitoring systems face complex and changeable network attacks, it is difficult to accurately identify new DDoS attacks, and there are problems of false alarms or underreports. At the same time, traditional encryption technology faces the development of quantum computing technology, its security is threatened, and there is a risk of stolen or tampering during data transmission.
The quantum encryption traffic acquisition module is adopted to ensure the security of data transmission by using quantum key distribution and encryption transmission technology; the biometric feature extraction module collects and verifys user biometric information to achieve the authenticity and security of identity verification; the blockchain detection traceability analysis module ensures the credibility of abnormal detection data and the accuracy of traceability analysis through distributed ledgers and smart contracts.
It improves the performance and reliability of network security monitoring, can accurately identify abnormal traffic, locate attack sources, ensure the security of data transmission and the authenticity of user identity, and enhances the security compliance of network systems.
Smart Images

Figure CN120090801A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer network security and information technology, and specifically relates to a computer network security monitoring system and method. Background Art
[0002] At present, with the rapid development of information technology, computer networks have become key infrastructure for social operation and are widely used in many fields such as finance, healthcare, education, and government. As the network scale continues to expand, complexity climbs continuously, and network attack means become increasingly diverse, traditional computer network monitoring systems and methods are gradually struggling to cope with new security threats and complex network environments, and it is difficult to meet the requirements for ensuring the secure and stable operation of the network.
[0003] Traditional network monitoring systems mostly rely on simple traffic threshold setting, feature matching, or rule-based detection methods. These methods have obvious limitations when facing complex and changeable network attacks. For example, for a new type of distributed denial of service (DDoS) attack, its attack traffic may disguise as normal business traffic, and traditional threshold-based monitoring methods are difficult to accurately identify, easily leading to false alarms or missed reports. In terms of data transmission, traditional encryption technologies such as symmetric encryption and asymmetric encryption face potential risks to their security with the development of quantum computing technology, and there is a possibility that data is stolen or tampered with during the transmission process.
[0004] In the user authentication link, most use the combination of username and password. This method has many security risks. For example, users may set simple and easy-to-guess passwords, or the passwords are leaked during network transmission or storage, resulting in illegal users being able to easily impersonate legitimate users to access network resources. Moreover, traditional systems are difficult to effectively analyze and monitor the operation behaviors of users in the network and cannot detect abnormal operations in a timely manner after the account is stolen.
[0005] In terms of anomaly detection and traceability analysis, the normal traffic feature distribution space of traditional models is usually stored in a local centralized database, which is easily subject to malicious tampering or damaged due to system failures. This greatly reduces the reliability of anomaly detection results, and traceability analysis is also difficult to carry out in depth due to the lack of reliable historical data support, and it is impossible to accurately trace the attack source and comprehensively understand the attack path.
[0006] In terms of visualization and management, the visualization display of traditional systems often only provides limited real-time information and lacks the ability to effectively integrate and display historical data, which is not conducive to network administrators analyzing the network security situation from a macroscopic and long-term perspective. At the same time, traditional user access control and management mechanisms are relatively single and difficult to cope with complex network usage scenarios and security requirements. Summary of the Invention
[0007] In view of the deficiencies of the prior art, the present invention provides a computer network security monitoring system and method, aiming to improve the performance and reliability of network security monitoring and meet the requirements of modern network security.
[0008] In the first aspect of the embodiments of the present invention, a computer network security monitoring system is provided, including a quantum encryption traffic collection module, a biometric feature extraction module, and a blockchain detection and traceability analysis module. The quantum encryption traffic collection module is connected to the biometric feature extraction module, and the biometric feature extraction module is connected to the blockchain detection and traceability analysis module; It is characterized in that the quantum encryption traffic collection module includes: A quantum key distribution unit for deploying quantum key distribution devices at key network nodes to generate and distribute secure quantum keys for data transmission; an encrypted transmission unit for obtaining the quantum keys distributed by the quantum key distribution unit and using the quantum keys to encrypt the packet information collected by the traffic collection subunit; a traffic collection subunit for capturing the packets flowing through the network gateway node and performing preliminary parsing on the packets to extract key information; a data cache statistical analysis subunit for temporarily storing the encrypted packet information, managing the data cache according to the first-in-first-out principle, and performing statistical analysis on the data in the cache at a preset time interval to generate traffic data segments; The biometric feature extraction module includes: A biometric unit for collecting the biometric information of users and converting it into digital feature vectors, comparing with the legal user biometric data stored in the biometric storage unit to verify the authenticity of the user identity; a feature extraction subunit for receiving the data cache and traffic data segments of the quantum encryption traffic collection module and extracting the multi-dimensional feature vectors of each traffic data segment; a biometric storage unit for storing the biometric information of legal users in an encrypted storage manner; The blockchain detection and traceability analysis module includes: An anomaly detection subunit with an built-in anomaly detection model, comparing the received feature vectors with the normal traffic feature distribution space stored in the blockchain storage unit. When it is found that the feature vectors deviate from the normal distribution by more than a preset threshold, it is determined as abnormal traffic and the corresponding traffic data segments are marked; a traceability analysis subunit, after receiving the abnormal traffic mark, uses network topology information and IP address tracking technology to perform retrospective analysis on the source of the abnormal traffic, determine the possible attack source or faulty node, and generate a traceability analysis report; a blockchain storage unit, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results, and traceability analysis reports.
[0009] In an alternative embodiment, a visualization management module is further included, and the visualization management module is respectively connected to the biometric feature extraction module and the blockchain detection and traceability analysis module; The visualization management module includes: A visualization display subunit, which displays the real-time status of network traffic, the distribution of abnormal traffic, and the traceability analysis results in intuitive charts and graphical interfaces for network administrators to view and analyze; An authentication and access control subunit, which works in cooperation with the biometric unit. When a user logs in and accesses network resources, it verifies the user's biometric information, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user during the operation process.
[0010] In an alternative embodiment, the encrypted transmission unit supports the integration with existing network protocols, enabling the encrypted data packets to be normally transmitted in the network and decrypted at the receiving end to restore the original data; Key information is extracted in the traffic collection subunit, including source IP, destination IP, port number, and protocol type.
[0011] In an alternative embodiment, the biometric devices in the biometric unit include, but are not limited to, fingerprint scanners, facial recognition cameras, and iris recognition devices; The multi-dimensional feature vectors in the feature extraction subunit include, but are not limited to, source IP address distribution features, destination IP address distribution features, port usage frequency features, data packet size distribution features, and protocol type proportion features.
[0012] In an alternative embodiment, the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum-inspired algorithm to enhance the performance and efficiency of feature extraction.
[0013] In an alternative embodiment, the blockchain storage unit adopts the consensus mechanism of the blockchain, and the consensus mechanism includes, but is not limited to, proof of work, proof of stake, or Byzantine fault tolerance algorithm.
[0014] In an alternative embodiment, the blockchain-verified anomaly detection model of the anomaly detection subunit ensures the credibility of the normal traffic feature distribution space update and verification process through a smart contract.
[0015] In an alternative embodiment, the charts and graphical interfaces of the visualization display subunit support the query and display of historical information stored in the blockchain storage unit.
[0016] In an alternative embodiment, the authentication and access control subunit combines the traditional username and password authentication method to achieve multi-factor authentication.
[0017] The second aspect of the embodiments of the present invention provides a computer network security monitoring method, including the following steps: S1: Perform quantum encrypted traffic collection, adopt a dynamic quantum key length adjustment mechanism based on traffic load, and generate a dynamic key sequence in combination with quantum chaotic mapping; Preferably, generating a dynamic key sequence in combination with quantum chaotic mapping specifically includes: S101: Start the quantum key distribution unit, establish a quantum key distribution channel at network key nodes, generate an unpredictable key sequence through quantum chaotic mapping, and distribute the generated key based on the quantum key distribution protocol; S102: The traffic collection subunit captures data packets at network key nodes, and performs preliminary parsing on the data packets to extract key information; S103: The encryption transmission unit encrypts the collected data packet information using the quantum key, and transmits the encrypted data to the data cache statistical analysis subunit; S104: The data cache statistical analysis subunit stores the encrypted data in the cache, statistically analyzes the cache data at preset time intervals, and generates an encrypted traffic data segment.
[0018] S2: Perform biometric feature extraction, use the federated learning method to perform distributed updates on the biometric model, and bind the user's behavioral features using the quantum key; Preferably, performing distributed updates on the biometric model using the federated learning method specifically includes: S201: The biometric unit collects user biometric information when the user accesses the network, converts it into a digital feature vector, and compares it with the legal user biometric data in the biometric storage unit to verify the authenticity of the user's identity; S202: The feature extraction subunit receives the encrypted traffic data segment and extracts a multi-dimensional feature vector using a quantum-inspired convolutional kernel; S203: Use the dynamic quantum key to encrypt the model parameters in federated learning and bind the quantum key to the user's behavioral features.
[0019] S3: Construct a spatio-temporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, and use the historical data and smart contracts stored in the blockchain to locate the attack source and generate a protection strategy; Preferably, it specifically includes: S301: Construct a spatio-temporal dynamic graph A model that can detect traffic anomalies in real time and mark high-risk data segments; among them, is a set of network nodes, is the edge set at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatio-temporal attention matrix, used to quantify the spatio-temporal correlation strength between nodes; S302: Capture the traffic interaction and time correlation between nodes, assign higher attention weights to the edges that interacted in the most recent time stage, that is, use the spatio-temporal attention mechanism to locate abnormal nodes, and calculate scores for the located abnormal nodes; S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit. The traceability analysis subunit conducts retrospective analysis by integrating real-time attention weights and historical frequencies, locates high-probability attack paths, and stores the traceability analysis report in the blockchain storage unit; S304: Synchronously update the smart contract logic. When the node traffic is greater than the set high-risk threshold, automatically execute predefined protection actions on high-risk nodes, that is, block the IP addresses of abnormal nodes and send alarm information to the administrator.
[0020] S4: Use deep reinforcement learning to adaptively adjust the visualization layout.
[0021] Preferably, it specifically includes: The visualization display subunit displays the real-time status of network traffic, abnormal traffic information, and traceability results in an intuitive chart and graphical interface; the identity authentication and access control subunit verifies the user's biometric information and traditional login credentials during user login and operation, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user's operations at the same time.
[0022] Compared with the prior art, the advantages of the present invention in providing the above method include: In terms of data security, the quantum encryption traffic acquisition module uses quantum key distribution and encrypted transmission to ensure data transmission security and prevent theft and tampering; the biometric storage unit encrypts and stores the user's biometric features to protect user privacy. In terms of identity authentication, multiple identity authentications combining biometric recognition and traditional methods are adopted to increase accuracy and security, and can monitor the user's behavior in real time and give early warnings of abnormal operations. During anomaly detection and traceability analysis, the blockchain storage unit uses the immutable characteristics and smart contracts to ensure the credibility of detection data and the accuracy of results. The traceability analysis subunit can accurately locate the attack source by combining multiple pieces of information. In terms of information display and management, the visualization display subunit presents information in an intuitive interface, supports querying historical information, and improves management efficiency; the identity authentication and access control subunit realizes refined access control, records user operations for easy auditing and traceability, and ensures the security and compliance of the network system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0024] Figure 1 Schematic diagram of the structure of a computer network security monitoring system proposed in an embodiment of the present application; Figure 2 Flowchart of a computer network security monitoring method proposed in an embodiment of the present application. Specific implementation manners
[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0026] Embodiment 1: Please refer to Figure 1 , Figure 1 which is a schematic diagram of the structure of a computer network security monitoring system proposed in Embodiment 1 of the present application. As Figure 1 shown, the computer network security monitoring system includes a quantum encryption traffic collection module, a biometric feature extraction module, and a blockchain detection and traceability analysis module. The quantum encryption traffic collection module is connected to the biometric feature extraction module, and the biometric feature extraction module is connected to the blockchain detection and traceability analysis module; The quantum encryption traffic collection module includes: A quantum key distribution unit for deploying quantum key distribution devices at key network nodes to generate and distribute secure quantum keys for data transmission; an encrypted transmission unit for obtaining the quantum keys distributed by the quantum key distribution unit and using the quantum keys to encrypt the packet information collected by the traffic collection subunit; a traffic collection subunit for capturing the packets flowing through the network node and performing preliminary parsing on the packets to extract key information; a data cache statistical analysis subunit for temporarily storing the encrypted packet information, managing the data cache according to the first-in, first-out principle, and performing statistical analysis on the data in the cache at a preset time interval to generate traffic data segments; The biometric feature extraction module includes: A biometric unit for collecting biometric information of a user, converting it into a digital feature vector, and comparing it with the biometric data of legitimate users stored in the biometric storage unit to verify the authenticity of the user's identity; a feature extraction subunit for receiving the data cache and traffic data segments of the quantum encryption traffic collection module and extracting the multi-dimensional feature vectors of each traffic data segment; a biometric storage unit for storing the biometric information of legitimate users in an encrypted storage manner; The blockchain detection and traceability analysis module includes: An anomaly detection subunit with an built-in anomaly detection model, which compares the received feature vectors with the normal traffic feature distribution space stored in the blockchain storage unit. When it is found that the feature vectors deviate from the normal distribution by more than a preset threshold, it is determined as abnormal traffic, and the corresponding traffic data segments are marked; a traceability analysis subunit, after receiving the abnormal traffic mark, uses network topology information and IP address tracking technology to conduct a retrospective analysis on the source of the abnormal traffic, determine the possible attack source or faulty node, and generate a traceability analysis report; a blockchain storage unit, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results, and traceability analysis reports.
[0027] In this embodiment, the quantum key distribution unit uses the basic principles of quantum mechanics, such as the non-clonability of quantum states and the quantum entanglement property, to generate and distribute highly secure quantum keys for data transmission; for the encryption transmission unit, whether it is the transmission content of the data packet, or its source and destination information, is transmitted under encryption protection to ensure that the data will not be stolen or tampered with during network transmission; the traffic data segments generated by the traffic collection subunit contain various statistical indicators of network traffic, such as the number of data packets, the number of bytes, the traffic rate, etc., providing important data support for subsequent feature extraction and anomaly detection.
[0028] The normal traffic feature distribution space of the anomaly detection subunit is obtained through the learning and analysis of a large amount of normal network traffic data, representing the traffic feature pattern in the normal operation state of the network. The generated traceability analysis report not only contains information about the attack source or faulty node, but also analyzes the propagation path of the abnormal traffic and the possible impacts, providing an important basis for network security administrators to take effective countermeasures.
[0029] Furthermore, it further includes a visualization management module, and the visualization management module is respectively connected to the biometric feature extraction module and the blockchain detection and traceability analysis module; The visualization management module includes: A visualization display subunit for intuitively displaying the real-time state of network traffic, the distribution of abnormal traffic, and the traceability analysis results through charts and graphical interfaces for network administrators to view and analyze; The authentication and access control subunit works in coordination with the biometric unit. When a user logs in and accesses network resources, it verifies the user's biometric information, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user during the operation process.
[0030] In this embodiment, for the real-time state of network traffic, the visualization display subunit can not only display the overall traffic trend, such as the fluctuation curve of traffic rate, the real-time change of the number of data packets, etc., but also classify and display different types of network protocol traffic, enabling the administrator to clearly understand the usage of various network applications. For example, by comparing the traffic proportions of protocols such as HTTP, FTP, and TCP through a bar chart, it helps the administrator quickly determine whether the composition of business traffic in the network is normal.
[0031] In the user login stage, it first verifies the user's biometric information, such as fingerprint, facial features, or iris information, etc., and at the same time combines the traditional username and password verification method to achieve multi-factor authentication. When the user accesses network resources, this subunit strictly controls the user's access to various network resources according to the user's identity and pre-set permissions. For example, ordinary users may only be able to access specific files and applications, while administrator users have higher-level permissions and can perform operations such as system configuration and data management. During the user operation process, the authentication and access control subunit continuously monitors and manages. It will record the user's operation behavior in real time, including information such as the time, object, and content of the operation, and analyze these behaviors.
[0032] Furthermore, the encrypted transmission unit supports the integration with existing network protocols, enabling the encrypted data packets to be normally transmitted in the network and decrypted at the receiving end to restore the original data; Key information is extracted in the traffic collection subunit, including source IP, destination IP, port number, and protocol type.
[0033] In this embodiment, the existing network protocol types include TCP, UDP, etc. The TCP protocol is commonly used for reliable, connection-oriented communications, such as file transfer, web browsing, etc.; the UDP protocol is commonly used for applications with relatively high real-time requirements but relatively low requirements for data accuracy, such as video stream and audio stream transmission.
[0034] Furthermore, the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum-inspired algorithm to enhance the performance and efficiency of feature extraction.
[0035] In this embodiment, the weights are updated through quantum rotation gate operations, enabling the model to converge to the vicinity of the global optimal solution more quickly and avoid falling into local optimal solutions. Meanwhile, the quantum-inspired algorithm can also adaptively adjust the search strategy according to the characteristics and changes of network traffic data, improving the flexibility and adaptability of the algorithm.
[0036] Through this combination method, when the feature extraction subunit processes network traffic data, it can more efficiently extract more representative and discriminative multi-dimensional feature vectors from complex traffic data segments. These feature vectors not only include traditional source IP address distribution features, destination IP address distribution features, port usage frequency features, packet size distribution features, and protocol type proportion features, etc., but also can uncover some deep features hidden in the data, such as the co-variation features of different network protocols within a specific time period, the difference features between abnormal traffic and normal traffic on a micro time scale, etc.
[0037] Furthermore, the blockchain storage unit adopts the consensus mechanism of the blockchain, and the consensus mechanism includes but is not limited to proof of work, proof of stake, or Byzantine fault tolerance algorithm.
[0038] In this embodiment, in the blockchain storage unit based on proof of work, each participating node needs to compete for the right to record transactions by calculating complex mathematical problems. The node will continuously try different random numbers, combine them with information such as transaction data for hash operations. Only when the calculated hash value meets specific difficulty requirements can the node obtain the right to record transactions and add the new block to the blockchain.
[0039] Under the proof of stake mechanism, the right of a node to record transactions no longer depends on computing power, but is determined by the amount and holding time of the stake (usually digital currency or tokens) held by the node. Nodes with more stakes have a higher probability of being selected to record transactions. At the same time, these nodes need to pledge a certain amount of stakes as a guarantee during the process of participating in recording transactions. If a node attempts to maliciously tamper with data or conduct illegal operations, the pledged stakes will be deducted.
[0040] The Byzantine fault tolerance algorithm achieves consensus through information interaction and verification among nodes. In the blockchain storage unit of this embodiment, adopting the Byzantine fault tolerance algorithm can ensure that even if some nodes fail or are attacked, the system can still accurately record and store network security monitoring data.
[0041] Furthermore, the anomaly detection model verified by the blockchain of the anomaly detection subunit ensures the credibility of the update and verification process of the normal traffic feature distribution space through smart contracts.
[0042] In this embodiment, the smart contract checks whether the data source is trustworthy, whether the data format is correct, whether the data conforms to the basic characteristics of normal traffic, etc. Only the data verified by the smart contract will be used to update the normal traffic feature distribution space. If it is found that a certain update operation causes misjudgment in the anomaly detection model, the operation log on the blockchain can be checked to accurately identify the problem, whether it is an incorrect data source or a deviation in the verification process. The smart contract can also set corresponding permission management mechanisms. Only authorized devices or algorithms can submit update data, and different users or devices have different permission levels.
[0043] Further, the charts and graphical interfaces of the visualization display subunit support the query and display of historical information stored in the blockchain storage unit.
[0044] In this embodiment, the administrator can filter and retrieve the historical information in the blockchain storage unit according to multiple dimensions, such as time range, network nodes, traffic types, anomaly event types, etc.
[0045] Further, the authentication and access control subunit combines traditional username and password verification methods to implement multi-factor authentication.
[0046] In this embodiment, the authentication and access control subunit introduces biometric technologies, such as fingerprint recognition, facial recognition, iris recognition, etc. Biometric technologies provide higher accuracy and security for authentication based on the uniqueness and stability of human biological characteristics.
[0047] Embodiment 2: Please refer to Figure 2 , Figure 2 which is a flowchart of a computer network security monitoring method proposed in Embodiment 2 of this application. As Figure 2 shown, a computer network security monitoring method proposed in Embodiment 2 of this application is characterized by including the following steps: S1: Perform quantum encrypted traffic collection, adopt a dynamic quantum key length adjustment mechanism based on traffic load, and generate a dynamic key sequence in combination with quantum chaotic mapping; S101: Start the quantum key distribution unit, establish a quantum key distribution channel at key network nodes, generate an unpredictable key sequence through quantum chaotic mapping, and distribute the generated key based on the quantum key distribution protocol; Exemplarily, generating an unpredictable key sequence through quantum chaotic mapping includes: generating an initial seed value based on a quantum physical entropy source to ensure the randomness of the initial key , and define a chaotic mapping function for initializing the quantum chaotic mapping. Quantize the chaotic output and map it into a binary key stream. After the key stream is generated, it is directly distributed through the quantum key distribution channel. Among them, the chaotic mapping function is: Among them, is the dynamic quantum key of the chaotic output, that is, the dynamic quantum key of the time slice, is the chaotic control parameter, is the secret key value of the previous time period and is the initial input of the chaotic iteration, is used to make the result now in the interval [0, 1), is the quantum state conversion function, is the quantum phase perturbation term generated in real time by the quantum random number generator.
[0048] S102: The traffic collection sub-unit captures data packets at key network nodes, and performs a preliminary analysis on the data packets to extract key information; S103: The encryption transmission unit encrypts the collected data packet information using the quantum key, and transmits the encrypted data to the data cache statistical analysis sub-unit; Exemplarily, encrypting the collected data packet information includes: dynamically adjusting the key length according to the real-time network traffic load, defining load indicators by constructing a traffic load quantization model , , among them, is the rate of the instantaneous traffic, is the maximum broadband of the link, is the weight coefficient, is the number of concurrent connections, is the maximum number of concurrent connections. Select the key length according to the load level. Set that when continuously crosses the set threshold, trigger the key length update. At the same time, fragment the over-long data packets, and each fragment is encrypted with a different key segment. The encryption formula is: , among them, is the quantum secure encryption algorithm, is the key segment corresponding to the fragment; use a short key to reduce the computational overhead when the load is low, and switch to a long key to cope with potential attacks when the load is high, realizing lightweight encryption with load awareness. And the change of the key length will force the encryption protocol to be updated synchronously, further realizing the resistance to the replay attack of the fixed key; each time the key is updated, the key information of the previous time period is destroyed through the quantum erasure technology to ensure that even if the current key is leaked, the historical data is still not decryptable; Furthermore, the encryption transmission unit adopts a hybrid mode of lattice-based post-quantum cryptography PQC and quantum key during data transmission: , even if a quantum computer cracks part of the PQC, it is still necessary to obtain a quantum key to decrypt it, ensuring the absolute security of the data.
[0049] S104: The data cache statistical analysis subunit stores the encrypted data in the cache, statistically analyzes the cache data at preset time intervals, and generates encrypted traffic data segments.
[0050] S2: Perform biometric feature extraction, use the federated learning method to distributively update the biometric model, and use the quantum key to bind the user's behavioral characteristics; S201: The biometric unit collects the user's biometric information when the user accesses the network, converts it into a digital feature vector, and compares it with the legal user's biometric data in the biometric storage unit to verify the authenticity of the user's identity; Exemplarily, verifying the authenticity of the user's identity specifically includes: after collecting the user's biometric information, using the dynamic quantum key output by chaos for encryption: , is the encrypted user biometric, is the encryption function based on quantum chaos mapping, is the quantum noise mask generated in real time by the quantum random number generator, constructs the federated local model, and uses the encrypted user biometric to train the local model at the user side, and synchronously fuse the user's operation behavior analysis features through the loss function: , , where is the overall loss function of federated learning, is the loss of the local biometric model containing Triplet Loss and cross-entropy loss, is the weight coefficient of the behavior analysis loss, is the prediction loss of the user's operation behavior, is the time step of the user's operation behavior sequence, is the LSTM neural network model for constructing the time series of the degree operation behavior sequence, is the user's operation behavior sequence, is the normal behavior pattern label generated by clustering historical data. Finally, bind the local model parameters with the quantum key to the hash value to prevent the model parameters from being tampered with during transmission.
[0051] S202: The feature extraction subunit receives the encrypted traffic data segment and extracts the multi-dimensional feature vector using the quantum-inspired convolution kernel; Exemplarily, define the quantum-inspired convolution kernel , Optimizing parameters using the quantum annealing algorithm can enhance the ability to extract non-linear features of encrypted traffic. The optimization formula based on the quantum annealing algorithm is: , where is to find the parameters that minimize the objective function , is the quantum annealing energy function, is the sparsification coefficient, is the L1 regularization term; each node extracts the encrypted traffic features , , and aggregates the global feature center through the server , , is the total number of nodes participating in the federated aggregation, is the th encrypted traffic feature vector extracted by the node, is the feature mask matrix dynamically generated by the quantum key .
[0052] S203: Encrypt the model parameters in the federated learning using the dynamic quantum key and bind the quantum key to the user's behavior characteristics; Exemplarily, encrypt the model parameters in the federated learning using the dynamic quantum key to achieve double encryption against classical and quantum attacks. The encryption process is: where is the hybrid encryption function, is the algorithm used, is to combine the quantum key with the PQC ciphertext, is the key stream generated based on the dynamic quantum key and synchronized through the quantum key distribution protocol. By embedding the user's operation behavior sequence into the quantum watermark, the quantum key is bound to the user's behavior characteristics. The formula for embedding the quantum watermark is: where is the quantum bit measurement operation, is the hash value of the user operation behavior sequence converted into a binary string. When the user's operation behavior is tampered with, the embedded quantum watermark verification fails and a real-time alarm is triggered.
[0053] S3: Construct a spatio-temporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, and use the historical data and smart contracts stored in the blockchain to locate the attack source and generate protection strategies; S301: Construct a spatio-temporal dynamic graph model to detect traffic anomalies in real time and mark high-risk data segments; where is a set of network nodes, is the edge set at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatio-temporal attention matrix, used to quantify the spatio-temporal correlation strength between nodes; S302: Capture the traffic interaction and time correlation between nodes, assign higher attention weights to the edges that interacted in the most recent time stage, that is, use the spatio-temporal attention mechanism to locate abnormal nodes and calculate scores for the located abnormal nodes; Exemplarily, the spatio-temporal attention mechanism is: where is the spatio-temporal attention weight, is the generated query vector, is the generated key vector, is the time decay function, is node and is the timestamp of the last interaction between S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit, and the traceability analysis subunit conducts retrospective analysis by integrating real-time attention weights and historical frequencies, locates the high-probability attack path, and stores the traceability analysis report in the blockchain storage unit; Exemplarily, the positioning formula for locating the high-probability attack path is: where is the most likely attack propagation path, is the set of paths traced back from the attack target to the potential source node, is the historical interaction frequency statistically obtained from the blockchain traceability records, is node 's total number of interactions. By integrating real-time attention weights and historical frequencies, high-frequency legitimate interaction nodes will not be misjudged as the attack source.
[0054] Exemplarily, in the blockchain detection and traceability analysis step, the smart contract automatically triggers corresponding operations according to preset rules. When high-risk abnormal traffic appears, it notifies the administrator and executes corresponding network protection measures. In the blockchain detection and traceability analysis step, the smart contract automatically triggers corresponding operations according to preset rules. When high-risk abnormal traffic appears, it notifies the administrator and executes corresponding network protection measures; the traceability analysis subunit uses the historical traceability information in the blockchain storage unit to assist in a more comprehensive analysis to discover potential attack patterns or long-term security threats.
[0055] S304: Synchronize by dynamically updating the smart contract logic. When the node traffic is greater than the set high - risk threshold, automatically execute predefined protection actions on high - risk nodes, that is, block the IP addresses of abnormal nodes and send alarm messages to the administrator.
[0056] S4: Use deep reinforcement learning to adaptively adjust the visualization layout.
[0057] S401: The visualization display subunit displays the real - time status of network traffic, abnormal traffic information, and traceability results in an intuitive chart and graphical interface; S402: The authentication and access control subunit verifies the user's biometric information and traditional login credentials during user login and operation, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user's operations at the same time.
[0058] In this embodiment, in the visualization management step, when an illegal access attempt or abnormal user operation behavior is detected, the authentication and access control subunit records the event in the blockchain storage unit for subsequent auditing and traceability.
[0059] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.
[0060] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.
[0061] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.
[0062] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the said element.
[0063] The above has introduced in detail a computer network security monitoring system and method provided by this application. Specific examples are used in this text to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A computer network security monitoring system, comprising a quantum encryption traffic collection module, a biometric feature extraction module and a blockchain detection and traceability analysis module, wherein the quantum encryption traffic collection module is connected to the biometric feature extraction module, and the biometric feature extraction module is connected to the blockchain detection and traceability analysis module; It is characterized in that The quantum encryption traffic collection module includes: The quantum key distribution unit is used to deploy quantum key distribution equipment at key nodes of the network to generate and distribute secure quantum keys for data transmission; the encryption transmission unit is used to obtain the quantum key distributed by the quantum key distribution unit, and use the quantum key to encrypt the data packet information collected by the traffic collection subunit; the traffic collection subunit is used to capture the data packets flowing through the network nodes, and perform preliminary analysis on the data packets to extract key information; the data cache statistical analysis subunit is used to temporarily store the encrypted data packet information, manage the data cache according to the first-in-first-out principle, and perform statistical analysis on the data in the cache at preset time intervals to generate traffic data segments; The biometric feature extraction module comprises: The biometric identification unit is used to collect the user's biometric information and convert it into a digital feature vector, which is compared with the biometric data of the legitimate user stored in the biometric storage unit to verify the authenticity of the user's identity; the feature extraction subunit is used to receive the data cache and flow data segment of the quantum encryption flow acquisition module and extract the multi-dimensional feature vector of each flow data segment; the biometric storage unit uses an encrypted storage method to store the biometric information of the legitimate user; The blockchain detection and traceability analysis module includes: The anomaly detection subunit has a built-in anomaly detection model, which compares the received feature vector with the normal traffic feature distribution space stored in the blockchain storage unit. When it is found that the feature vector deviates from the normal distribution by more than the preset threshold, it is determined to be abnormal traffic and the corresponding traffic data segment is marked; the tracing analysis subunit, after receiving the abnormal traffic mark, uses the network topology information and IP address tracking technology to trace back the source of the abnormal traffic, determine the possible attack source or fault node, and generate a tracing analysis report; the blockchain storage unit, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results and tracing analysis report.
2. A computer network security monitoring system according to claim 1, characterized in that: It also includes a visualization management module, which is connected to the biometric feature extraction module and the blockchain detection traceability analysis module respectively; the visualization management module includes: a visualization display subunit, which displays the real-time status of network traffic, the distribution of abnormal traffic and the traceability analysis results with intuitive charts and graphical interfaces for network administrators to view and analyze; an identity authentication and access control subunit, which works in conjunction with the biometric unit to verify the user's biometric information when the user logs in and accesses network resources, control their access to network resources according to their identity and permissions, and monitor and manage the user's operation process; the encrypted transmission unit supports integration with existing network protocols, so that the encrypted data packets can be transmitted normally in the network, and the original data can be decrypted and restored at the receiving end; the traffic collection subunit extracts key information, including source IP, destination IP, port number and protocol type; The biometric devices in the biometric unit include but are not limited to fingerprint readers, facial recognition cameras and iris readers; the multidimensional feature vectors in the feature extraction subunit include but are not limited to source IP address distribution features, destination IP address distribution features, port usage frequency features, data packet size distribution features and protocol type proportion features; the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum heuristic algorithm; the blockchain storage unit adopts a blockchain consensus mechanism, and the consensus mechanism includes but is not limited to proof of work, proof of stake or Byzantine fault tolerance algorithm; the blockchain-verified anomaly detection model of the anomaly detection subunit ensures the credibility of the normal traffic feature distribution space update and verification process through smart contracts; the charts and graphical interfaces of the visualization subunit support the query and display of historical information stored in the blockchain storage unit; the identity authentication and access control subunit combines traditional username and password authentication methods to achieve multiple identity authentication.
3. A computer network security monitoring method, characterized in that: The following steps are involved: S1: Collect quantum encryption traffic, use a dynamic quantum key length adjustment mechanism based on traffic load, and combine quantum chaos mapping to generate a dynamic key sequence; S2: Extract biometric features, use federated learning methods to distribute updates to the biometric model, and use quantum keys to bind user behavior features; S3: Build a spatiotemporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, use the historical data and smart contracts stored in the blockchain to locate the attack source and generate a protection strategy; S4: Adaptively adjust visualization layout using deep reinforcement learning.
4. A computer network security monitoring method according to claim 3, characterized in that: The step S1 specifically includes the following steps: S101: Start the quantum key distribution unit, establish a quantum key distribution channel at a key node of the network, generate an unpredictable key sequence through quantum chaos mapping, and distribute the generated key based on the quantum key distribution protocol; S102: The traffic collection subunit captures data packets at key nodes of the network, performs preliminary analysis on the data packets, and extracts key information; S103: The encryption transmission unit encrypts the collected data packet information using the quantum key, and transmits the encrypted data to the data cache statistical analysis subunit.
5. A computer network security monitoring method according to claim 4, characterized in that: The method of generating an unpredictable key sequence by quantum chaos mapping includes: generating an initial seed value for ensuring the randomness of the initial key based on a quantum physical entropy source; , and define the chaos mapping function for initializing the quantum chaos mapping, map the chaotic output into a binary key stream through quantization processing, and distribute the key stream directly through the quantum key distribution channel after it is generated. The chaos mapping function is: in, is the dynamic quantum key of chaotic output, i.e. Dynamic quantum keys for time slices, is the chaos control parameter, is the secret key value of the previous period and the initial input of the chaotic iteration. Used to make the result now in the interval [0,1). is the quantum state conversion function, is the quantum phase perturbation term generated in real time by the quantum random number generator.
6. A computer network security monitoring method according to claim 4, characterized in that: The method of encrypting the collected data packet information by using quantum key includes: dynamically adjusting the key length according to the real-time network traffic load, defining the load index by building a traffic load quantization model, , ,in, is the instantaneous flow rate, is the maximum link bandwidth, is the weight coefficient, is the number of concurrent connections, The maximum number of concurrent connections, select the key length according to the load level, and set the When the set threshold is crossed continuously, the key length is updated. At the same time, the overlong data packet is fragmented, and each fragment is encrypted with a different key segment. The encryption formula is: ,in, For quantum-safe encryption algorithms, For the The key segment corresponding to the shard; Furthermore, the encryption transmission unit adopts a hybrid mode of lattice post-quantum cryptography PQC and quantum key in the data transmission process: Even if a quantum computer cracks the PQC part, it still needs to obtain the quantum key to decrypt it, ensuring the absolute security of the data.
7. A computer network security monitoring method according to claim 3, characterized in that: The step S2 specifically includes the following steps: S201: The biometric identification unit collects the user's biometric information when the user accesses the network, converts it into a digital feature vector, and compares it with the biometric data of the legitimate user in the biometric storage unit to verify the authenticity of the user's identity; S202: The feature extraction subunit receives the encrypted traffic data segment and extracts a multi-dimensional feature vector using a quantum-inspired convolution kernel; S203: Using dynamic quantum keys Model parameters in federated learning Encryption is performed and the quantum key is bound to the user's behavioral characteristics.
8. A computer network security monitoring method according to claim 7, characterized in that: The authenticity verification of the user identity specifically includes: collecting the user's biometric information and using the dynamic quantum key output by the chaos To encrypt: , For encrypted user biometrics, is the encryption function based on quantum chaos mapping, Build a federated local model for quantum noise masks generated in real time by a quantum random number generator, using encrypted user biometrics Train the local model on the user side and simultaneously integrate the user's operation behavior analysis features through the loss function: , ,in, is the overall loss function of federated learning, is the loss of the local biometric model including Triplet Loss and cross entropy loss, is the weight coefficient of behavior analysis loss, is the predicted loss of user operation behavior, is the time step of the user operation behavior sequence, The LSTM neural network model is used to construct the timing sequence of the operation behavior sequence. It is the sequence of user operation behaviors. is the normal behavior pattern label generated by historical data clustering, and finally the local model parameters are combined with the quantum key Binding hash values prevents model parameters from being tampered with during transmission; The quantum-inspired convolution kernel is ,Using the quantum annealing algorithm to optimize parameters can enhance the ability to extract nonlinear characteristics of encrypted traffic. The optimization formula based on the quantum annealing algorithm is: ,in, To find the parameters that minimize the objective function , is the quantum annealing energy function, is the sparsification coefficient, is the L1 regularization term; each node extracts encrypted traffic features , , aggregated by the server global feature center , , is the total number of nodes participating in the federation aggregation, For the The encrypted traffic feature vector extracted by each node, Quantum Key Dynamically generated feature mask matrix; The use of dynamic quantum key Model parameters in federated learning Encryption specifically includes: using dynamic quantum keys Encrypting model parameters in federated learning , double encryption is achieved to resist classical and quantum attacks. The encryption process is: ,in is a hybrid encryption function, For use algorithm, To combine quantum keys with PQC ciphertext, Based on dynamic quantum key The generated key stream is synchronized through the quantum key distribution protocol, and the user's operation behavior sequence is Embed quantum watermarks to bind quantum keys to user behavior characteristics and embed quantum watermarks The formula is: ,in is the quantum bit measurement operation, Provide user action sequences The hash value is converted into a binary string. When the user's operation behavior is tampered with, the embedded quantum watermark verification fails, triggering a real-time alarm.
9. A computer network security monitoring method according to claim 3, characterized in that: The step S3 specifically comprises the following steps: S301: Constructing a spatiotemporal dynamic graph Model, detects traffic anomalies in real time and marks high-risk data segments; is the set of network nodes, is the edge set at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatiotemporal attention matrix, which is used to quantify the spatiotemporal correlation strength between nodes; S302: Capture the traffic interaction and time association between nodes, and assign higher attention weights to the edges of the recent time stage interactions, that is, use the spatiotemporal attention mechanism to locate abnormal nodes, and calculate scores for the located abnormal nodes; The spatiotemporal attention mechanism is: ,in, is the spatiotemporal attention weight, is the generated query vector, is the generated key vector, is the time decay function, For Node and The timestamp of the last interaction; S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit, and the traceability analysis subunit performs a backtracking analysis based on the real-time attention weight and the historical frequency to locate the high-probability attack path, and stores the traceability analysis report in the blockchain storage unit; the positioning formula for locating the high-probability attack path is: ,in, is the most likely attack propagation path, To attack the target The set of paths back to potential source nodes, To record the historical interaction frequency from the blockchain traceability record, For Node The total number of interactions is calculated by combining the real-time attention weight and the historical frequency, so that high-frequency legitimate interaction nodes will not be misjudged as attack sources; S304: Synchronously and dynamically update the smart contract logic. When the node traffic is greater than the set high-risk threshold, the predefined protection action is automatically executed on the high-risk node, that is, the IP address of the abnormal node is blocked and an alarm message is sent to the administrator.
10. A computer network security monitoring method according to claim 3, characterized in that: The step S4 specifically includes: the visual display subunit displays the real-time status of network traffic, abnormal traffic information and tracing results with intuitive charts and graphic interfaces.
Citation Information
Patent Citations
Data acquisition and signal identification method based on data information encryption method
CN117082502A
Comprehensive network security risk assessment and management system
CN118074904A
Biomarker authentication-based block chain secure transaction method and apparatus
WO2019232880A1
Cited By
Persistent Flink job file loading and displaying method and system
CN120408687A
A method and system for loading and presenting a persisted Flink job file
CN120408687B
Production information tracing system based on quantum encryption technology
CN120408732A
Material batch whole-process traceability system based on production process
CN120688801A
Production process-based material batch whole-process tracing system
CN120688801B