Automatic defense system for computer network security
Through the combination of quantum random walk edge detection, hyperchaotic timing prediction, quantum key distribution and causal Bayesian network, the real-time detection lag problem of network security systems in the prior art is solved, and rapid response and efficient defense against sudden attacks are achieved.
Patent Information
- Application Number
- CN202510491274.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing computer network security systems have lag when detecting burst attack behaviors in real time, making it difficult to capture and respond to cyber attacks in a timely manner.
The quantum random walk edge real-time detection module, superchaotic timing prediction module, quantum key distribution cross-system collaboration module and dynamic causal reasoning real-time feedback module are used to build a quantum random walk model, superchaotic neural network, quantum key distribution technology and causal Bayesian network to realize real-time threat detection and defense.
It significantly improves the detection efficiency of abnormal transitions in the data flow, infers attack propagation paths in real time, reduces response time, and improves network security defense efficiency.
Smart Images

Figure CN120358057A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network security, and in particular to an automated defense system for computer network security. Background Art
[0002] With the continuous development of computer network technology, the network has become an indispensable part of modern society. However, at the same time, network security issues have become increasingly prominent, and network attack incidents occur frequently, bringing huge losses and risks to individuals, enterprises, and countries. The automated defense system can monitor network traffic in real time, automatically identify and block malicious attacks, thereby greatly improving the efficiency of network security defense. Through advanced algorithms and models, the automated defense system can more accurately identify malicious traffic and normal traffic, reduce the false alarm rate, and reduce unnecessary interference and losses.
[0003] In the automated defense system for computer network security, the weighted moving average (WMA), as a data processing technology, is widely used in fields such as network traffic analysis and anomaly detection. The essence of the weighted moving average (WMA) is the weighted average of past data, so it reflects the trend over a past period of time. This lag may cause sudden attack behaviors to not be captured in time during real-time detection. Therefore, an automated defense system for computer network security is proposed. Summary of the Invention
[0004] The purpose of the present invention is to solve the deficiencies existing in the prior art, and to propose an automated defense system for computer network security.
[0005] In order to achieve the above purpose, the present invention adopts the following technical solutions:
[0006] An automated defense system for computer network security, comprising:
[0007] A quantum random walk edge real-time detection module: responsible for capturing the data stream in the network in real time, and using the quantum random walk model to detect abnormal transitions in the data stream. The data stream captured by the quantum random walk edge real-time detection module will be passed as input to the hyperchaotic time series prediction module;
[0008] A hyperchaotic time series prediction module: using a hyperchaotic neural network to perform time series prediction on the data stream, identifying potential security threats, quantifying the chaos degree of the system through the Lyapunov exponent, dynamically setting the anomaly threshold, and when the prediction result exceeds the threshold, sending out a warning signal and passing the anomaly information to the quantum key distribution cross-system collaboration module, and the quantum key distribution cross-system collaboration module then encrypts the threat intelligence using the anomaly information and passes it to other systems;
[0009] Quantum Key Distribution Cross-System Collaboration Module: Encrypts the exchange of threat intelligence between external systems using quantum key distribution technology. Meanwhile, through the intelligent contract automation mechanism, when specific conditions are met, it automatically triggers a network-wide defense action. The threat intelligence encrypted by the quantum key distribution cross-system collaboration module is transmitted to the Dynamic Causal Inference Real-Time Feedback Module, which uses this information to construct a causal Bayesian network and infer the attack propagation path;
[0010] Dynamic Causal Inference Real-Time Feedback Module: Constructs a causal Bayesian network of processor-network-application, quickly locates and blocks the threat source by inferring the attack propagation path in real time. Meanwhile, uses the reinforcement learning parameter tuning mechanism to dynamically optimize the sensitivity of sensors and the weights of defense strategies. The attack propagation path and defense strategies inferred by the dynamic causal inference real-time feedback module are fed back to the Quantum Random Walk Edge Real-Time Detection Module, which adjusts the detection parameters and strategies based on this information.
[0011] The above technical solution further includes:
[0012] Further, the quantum random walk edge real-time detection module uses the quantum random walk model to detect abnormal transitions in the data stream, including the following steps:
[0013] Initializing the wave function: Initialize the wave function. The components of the wave function represent the probability amplitudes of data packets or segments being at different positions in the network. A network contains three nodes A, B, and C. Initialize the wave function as a three-dimensional vector, where each component represents the probability amplitude of the particle being at node A, B, or C, and thus obtain ψ(0) = [α β γ], where α, β, and γ are complex numbers and satisfy α 2 + β 2 + γ 2 = 1;
[0014] Applying the quantum random walk model: Apply the quantum random walk model to update the wave function. After a discrete time step Δt, the wave function is calculated by the following formula ψ(t + 1) = e -iHΔt ψ(t), where H is the Hamiltonian;
[0015] Detecting abnormal transitions: After each update of the wave function, check whether there are significant abnormal changes in the components of the wave function. The abnormal changes represent abnormal transitions in the data stream, that is, data abnormally transfers from one node to another. Calculate the change rate or difference degree of the wave function components. If the change rate or difference degree exceeds a preset threshold, it is considered that an abnormal transition has occurred and the corresponding warning mechanism is triggered.
[0016] Furthermore, in the quantum random walk edge real-time detection module, a low-rank tensor decomposition technique is deployed on the edge nodes to compress the data dimension.
[0017] Furthermore, the hyperchaotic time series prediction module uses a hyperchaotic neural network to perform time series prediction on the data stream and identify potential security threats, including the following steps:
[0018] Data preprocessing: Preprocess the data stream captured by the hyperchaotic time series prediction module;
[0019] Construct a hyperchaotic neural network: Construct a neural network model based on hyperchaotic theory to capture the non-linear time series features in the data stream;
[0020] Network training: After constructing the neural network model, historical data is needed for training;
[0021] Time series prediction: Once the network training is completed, use this model to perform time series prediction on the new data stream, and the prediction results are used to identify potential security threats;
[0022] Anomaly detection and warning: According to the prediction results and the set anomaly threshold, determine whether to trigger a warning signal. If the prediction results exceed the threshold range, the system issues a warning signal.
[0023] Furthermore, the specific steps for the hyperchaotic time series prediction module to dynamically set the anomaly threshold by quantifying the chaos degree of the system through Lyapunov exponents:
[0024] Lyapunov exponent calculation: Calculate the Lyapunov exponent of the network traffic data to quantify its chaotic characteristics. Based on the definition of the maximum Lyapunov exponent, estimate it by calculating the exponential divergence rate of adjacent trajectories. The calculation formula is expressed as where \(X(t)\) and \(X_0(t)\) are the states of adjacent trajectories at time \(t\), \(X_0(0)\) and \(X_1(0)\) are the states of adjacent points at the initial time, and \(\lambda\) is the Lyapunov exponent;
[0025] Dynamically set the anomaly threshold: After calculating the Lyapunov exponent, dynamically set the anomaly threshold. The anomaly threshold is used to determine whether the network traffic data deviates from the normal state, thereby triggering a warning signal. By calculating the mean and standard deviation of the Lyapunov exponents in the historical data, and then setting the threshold according to these statistics. The calculation formula is expressed as \(\varphi=\mu + k\delta\), where \(\mu\) is the mean of the Lyapunov exponents in the historical data, \(\delta\) is the standard deviation, and \(k\) is a coefficient used to adjust the sensitivity of the threshold.
[0026] Further, the specific steps for the quantum key distribution cross-system collaboration module to encrypt the threat intelligence exchange between external systems using quantum key distribution technology are as follows:
[0027] Quantum key generation: Use the BB84 protocol to generate quantum keys. The BB84 protocol utilizes the non-clonability of quantum states and the measurement collapse principle to ensure the security of the keys. In the BB84 protocol, the sender uses four possible quantum states to encode key bits. The receiver randomly selects a measurement basis state for measurement and infers the key bits sent by Alice based on the measurement results. The specific expression is quantum state = {∣0>, ∣1>, ∣+>, ∣->}, where ∣0> and ∣1> respectively represent the basis states of photons in the horizontal polarization and vertical polarization directions, and ∣+> and ∣-> respectively represent the basis states of photons in the diagonal polarization and anti-diagonal polarization directions;
[0028] Key distribution and encryption: Once the shared key is generated, Alice and Bob use this key to encrypt and decrypt threat intelligence. The intelligence data is the plaintext M, and the shared key is K. Then the encrypted ciphertext C is expressed as where represents the XOR operation, and the decryption process is the inverse operation of the encryption process, that is
[0029] Cross-system collaboration: Between multiple external systems, use the shared key generated by QKD technology to encrypt the exchange of threat intelligence.
[0030] Further, the dynamic causal inference real-time feedback module constructs a causal Bayesian network of processor-network-application, quickly locates and blocks the threat source by inferring the attack propagation path in real time. At the same time, use the reinforcement learning parameter tuning mechanism to dynamically optimize the sensitivity of the sensor and the weight of the defense strategy, including the following steps:
[0031] Construct a causal Bayesian network of processor-network-application: Identify the key components in the system, including the processor, network, and application layer. Based on the interaction relationships between these components, construct a causal Bayesian network. In the Bayesian network, nodes represent components or events, and edges represent the causal relationships between components. Use historical data and expert knowledge to assign a conditional probability table to each node in the Bayesian network to describe the dependence relationship between component states;
[0032] Real-time inference of the attack propagation path: Once the system detects a potential security event, the dynamic causal inference real-time feedback module will use the Bayesian network for real-time inference. By updating the node states in the Bayesian network and calculating the posterior probability, the module infers the attack propagation path and the possible attack source;
[0033] Optimizing Sensor Sensitivity and Defense Strategy Weights Using a Reinforcement Learning Parameter Tuning Mechanism: The dynamic causal inference real-time feedback module integrates a reinforcement learning parameter tuning mechanism for dynamically optimizing the sensitivity of sensors and the weights of defense strategies. The reinforcement learning agent learns the optimal strategy by interacting with the environment. At each time step, the agent observes the state of the system and selects an action according to the current strategy. Then, the agent receives a reward or penalty based on the result of the action and updates the strategy accordingly.
[0034] An automated defense method corresponding to an automated defense system for computer network security, characterized by including the following steps:
[0035] Initialization and Configuration: Deploy in the target network environment, and according to the specific situation and security requirements of the network, initialize the settings of various parameters of the system. Deploy a security policy smart contract on the blockchain, and set the trigger conditions and corresponding defense actions;
[0036] Quantum Random Walk Edge Real-Time Detection: Real-time capture the data stream in the network through sensors deployed on edge nodes, model the data stream using the quantum random walk model, detect abnormal transitions in the data stream, and immediately send out a warning signal when abnormal behavior is detected;
[0037] Hyperchaotic Time Series Prediction: Preprocess the captured data stream, extract key features, and use a hyperchaotic neural network to perform time series prediction on the preprocessed data to identify potential security threats;
[0038] Abnormality Scoring and Warning: Quantify the chaos degree of the system through Lyapunov exponents, dynamically set the abnormality threshold, and send out a warning signal when the prediction result exceeds the threshold;
[0039] Quantum Key Distribution: Generate quantum keys using the BB84 protocol, and use the generated quantum keys to encrypt and transmit threat intelligence between external systems;
[0040] Smart Contract Automation: Real-time detect whether the trigger conditions set in the smart contract are met, and when the conditions are met, the smart contract automatically triggers the corresponding defense actions;
[0041] Causal Graph Model Construction: Construct a causal Bayesian network of processor-network-application to reflect the causal relationships in the network, and use the causal graph model to infer the propagation path of attacks in real time;
[0042] Reinforcement Learning Parameter Tuning: Dynamically adjust the sensitivity of sensors and the weights of defense strategies using the proximal policy optimization algorithm according to the real-time detected network state and attack behavior;
[0043] Defense Measure Execution: Execute corresponding defense measures according to the warning signal and the defense actions triggered by the smart contract;
[0044] Effect evaluation: Evaluate the execution effect of the defense measures. According to the evaluation results, further adjust the defense strategy and optimize the parameters.
[0045] The present invention has the following beneficial effects:
[0046] In the present invention, the data stream is modeled as a quantum state, and the detection efficiency of abnormal transitions in the data stream is significantly improved by detecting abnormal transitions through a random walk model. A causal Bayesian network of processor-network-application is constructed to infer the attack propagation path in real time, improving the response time to new attacks. Description of the Drawings
[0047] Figure 1 It is a system block diagram of an automated defense system for computer network security proposed by the present invention. Detailed Embodiments
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0049] Please refer to Figure 1 As shown, the present invention is an automated defense system for computer network security, including:
[0050] Quantum random walk edge real-time detection module: responsible for capturing the data stream in the network in real time and detecting abnormal transitions in the data stream using the quantum random walk model. The data stream captured by the quantum random walk edge real-time detection module will be passed as input to the hyperchaotic time series prediction module;
[0051] Hyperchaotic time series prediction module: Use a hyperchaotic neural network to perform time series prediction on the data stream, identify potential security threats, quantify the chaos degree of the system through Lyapunov exponents, dynamically set the abnormal threshold, and when the prediction result exceeds the threshold, send a warning signal and pass the abnormal information to the quantum key distribution cross-system collaboration module, which then encrypts the threat intelligence using the abnormal information and passes it to other systems;
[0052] Quantum Key Distribution Cross-System Collaboration Module: Utilize quantum key distribution technology to encrypt the exchange of threat intelligence between external systems, ensuring the security and integrity of intelligence during transmission. Meanwhile, through the intelligent contract automation mechanism, the entire network defense action is automatically triggered when specific conditions are met. The threat intelligence encrypted by the quantum key distribution cross-system collaboration module is transmitted to the Dynamic Causal Inference Real-Time Feedback Module, which then uses this information to construct a causal Bayesian network and infer the attack propagation path.
[0053] Dynamic Causal Inference Real-Time Feedback Module: Construct a causal Bayesian network of processor-network-application, quickly locate and block the threat source by inferring the attack propagation path in real time. Meanwhile, utilize the reinforcement learning parameter tuning mechanism to dynamically optimize the sensitivity of sensors and the weights of defense strategies. The attack propagation path and defense strategies inferred by the dynamic causal inference real-time feedback module are fed back to the Quantum Random Walk Edge Real-Time Detection Module, which then adjusts the detection parameters and strategies based on this information.
[0054] In one embodiment, the quantum random walk edge real-time detection module uses the quantum random walk model to detect abnormal transitions in the data stream, including the following steps:
[0055] Initialize the wave function: Initialize the wave function. The components of the wave function represent the probability amplitudes of data packets or segments at different positions in the network. A network contains three nodes A, B, and C. Initialize the wave function as a three-dimensional vector, where each component represents the probability amplitude of the particle at node A, B, or C, and thus obtain ψ(0) = [α β γ], where α, β, and γ are complex numbers and satisfy α 2 + β 2 + γ 2 = 1;
[0056] Apply the quantum random walk model: Apply the quantum random walk model to update the wave function. After a discrete time step Δt, the wave function is calculated by the formula ψ(t + 1) = e -iHΔt ψ(t), where H is the Hamiltonian, which is a matrix describing the energy and dynamics of the system. H is usually related to the topology of the network and the dynamic characteristics of the data stream.
[0057] Detect abnormal transitions: After each update of the wave function, check whether there are significant abnormal changes in the components of the wave function. The abnormal changes indicate abnormal transitions in the data stream, that is, data abnormally transfers from one node to another. Calculate the change rate or difference degree of the wave function components. If the change rate or difference degree exceeds a preset threshold, it is considered that an abnormal transition has occurred, and the corresponding warning mechanism is triggered.
[0058] In one embodiment, in the quantum random walk edge real-time detection module, low-rank tensor decomposition technology is deployed on edge nodes to compress data dimensions and reduce the computational burden.
[0059] In one embodiment, the hyperchaotic time series prediction module uses a hyperchaotic neural network to perform time series prediction on data streams and identify potential security threats, including the following steps;
[0060] Data preprocessing: Preprocess the data stream captured by the hyperchaotic time series prediction module;
[0061] Suppose a segment of network traffic data is captured, which contains multiple features such as packet size, packet arrival time interval, etc. In the preprocessing stage, invalid or abnormal data points will be removed, and then key features such as average packet size, fluctuation of packet arrival rate, etc. will be extracted as the input of the neural network;
[0062] Construct a hyperchaotic neural network: Construct a neural network model based on hyperchaotic theory to capture the non-linear time series features in the data stream;
[0063] An RNN model driven by the Lorenz system is constructed. The Lorenz system is a typical hyperchaotic system with very complex dynamic behavior, which can generate chaotic signals similar to noise. The state variables of the Lorenz system are used as the input of the hidden layer of the RNN, and through training, the network learns the chaotic features in the data stream;
[0064] Network training: After constructing the neural network model, historical data is needed for training. The purpose of training is to enable the network to accurately predict the future state of the data stream;
[0065] Time series prediction: Once the network training is completed, use this model to perform time series prediction on new data streams, and the prediction results are used to identify potential security threats;
[0066] Anomaly detection and warning: According to the prediction results and the set anomaly threshold, judge whether to trigger a warning signal. If the prediction result exceeds the threshold range, the system issues a warning signal.
[0067] In one embodiment, the hyperchaotic time series prediction module quantifies the chaos degree of the system through Lyapunov exponents and dynamically sets the specific steps of the anomaly threshold:
[0068] Lyapunov exponent calculation: Calculate the Lyapunov exponent of the network traffic data to quantify its chaotic characteristics. Based on the definition of the maximum Lyapunov exponent, it is estimated by calculating the exponential divergence rate of adjacent trajectories. The calculation formula is expressed as Where, X(t) and X0(t) are the states of adjacent trajectories at time t, X0(0) and X1(0) are the states of adjacent points at the initial time, and λ is the Lyapunov exponent;
[0069] Dynamically set the anomaly threshold: After calculating the Lyapunov exponent, dynamically set the anomaly threshold, which is used to determine whether the network traffic data deviates from the normal state, so as to trigger a warning signal. By calculating the average value and standard deviation of the Lyapunov exponent in the historical data, and then setting the threshold according to these statistics, the calculation formula is expressed as φ = μ + kδ, where μ is the average value of the Lyapunov exponent in the historical data, δ is the standard deviation, and k is a coefficient used to adjust the sensitivity of the threshold.
[0070] In one embodiment, the specific steps for the quantum key distribution cross-system collaboration module to encrypt the threat intelligence exchange between external systems using quantum key distribution technology are as follows:
[0071] Quantum key generation: Use the BB84 protocol to generate a quantum key. The BB84 protocol uses the unclonable nature of quantum states and the measurement collapse principle to ensure the security of the key. In the BB84 protocol, the sender (Alice) uses four possible quantum states (two basis states corresponding to the two polarization directions of a photon) to encode the key bits. The receiver (Bob) randomly selects a measurement basis state for measurement and infers the key bits sent by Alice based on the measurement results. Due to the measurement collapse principle of quantum states, any third party (Eve) attempting to eavesdrop on the key will introduce detectable errors. The specific expression is quantum state = {∣0>, ∣1>, ∣+>, ∣->}, where ∣0> and ∣1> respectively represent the basis states of a photon in the horizontal polarization and vertical polarization directions, and ∣+> and ∣-> respectively represent the basis states of a photon in the diagonal polarization and anti-diagonal polarization directions;
[0072] In this embodiment, it is assumed that Alice and Bob conduct QKD communication through an optical fiber. Alice uses a laser to emit a series of photons, and each photon randomly occupies one of the above four quantum states. Bob uses a polarizer to randomly select a measurement basis state and records the measurement results. Then, Alice and Bob publicly compare a part of the measurement results (referred to as basis state comparison) through a classical communication channel to detect whether there is an eavesdropping behavior. If the comparison results are consistent, the remaining measurement results can be used as the shared key;
[0073] Key distribution and encryption: Once the shared key is generated, Alice and Bob use this key to encrypt and decrypt the threat intelligence. The intelligence data is the plaintext M, and the shared key is K. Then the encrypted ciphertext C is expressed as Where, Represents the XOR operation. The decryption process is the inverse of the encryption process, i.e.,
[0074] In this embodiment, assume that Alice needs to send a piece of threat intelligence data to Bob. She first generates a shared key K with Bob using the BB84 protocol. Then, she performs an XOR operation on the intelligence data M and the key K to obtain the encrypted ciphertext C. Alice sends the ciphertext C to Bob through an insecure communication channel. After receiving the ciphertext, Bob performs an XOR operation using his own key K to restore the original intelligence data M;
[0075] Cross-system collaboration: Between multiple external systems, use the shared key generated by QKD technology to encrypt the exchange of threat intelligence.
[0076] In one embodiment, the dynamic causal inference real-time feedback module constructs a causal Bayesian network of processor-network-application, quickly locates and blocks the threat source by inferring the attack propagation path in real time. At the same time, it dynamically optimizes the sensitivity of the sensor and the weight of the defense strategy using a reinforcement learning parameter tuning mechanism, including the following steps:
[0077] Construct a causal Bayesian network of processor-network-application: Identify the key components in the system, including the processor, network, and application layer. According to the interaction relationships between these components, construct a causal Bayesian network. In the Bayesian network, nodes represent components or events, and edges represent the causal relationships between components. Use historical data and expert knowledge to assign a conditional probability table (CPT) to each node in the Bayesian network to describe the dependency relationships between component states;
[0078] Suppose there is a computer system that includes a Web server, a database server, and a firewall. The Web server and the database server are connected through an internal network, and the firewall is located between the system and the external network;
[0079] In this system, construct a causal Bayesian network, where the nodes include the Web server state, the database server state, the network state, the firewall state, and the attack event.
[0080] For example, if the Web server is attacked, it may become vulnerable, which in turn increases the risk of the database server being attacked. This causal relationship can be represented by an edge in the Bayesian network.
[0081] Assign conditional probability tables to these nodes to describe the transition probabilities between different states. For example, if the Web server is in a vulnerable state, the probability of the database server being attacked may increase;
[0082] Real-time inference of the attack propagation path: Once the system detects potential security incidents (such as abnormal login attempts, data breaches, etc.), the dynamic causal inference real-time feedback module will use Bayesian networks for real-time inference. By updating the node states in the Bayesian network and calculating the posterior probabilities, the module infers the attack propagation path and the possible attack sources;
[0083] Suppose the system detects an abnormal login attempt on the Web server. The dynamic causal inference module will update the state of the Web server node in the Bayesian network and calculate the posterior probabilities of other nodes (such as the database server, network, firewall).
[0084] If the inference result shows an increased risk of the database server being attacked, the module will trigger a warning signal and take corresponding defense measures (such as strengthening firewall rules, isolating the infected server, etc.);
[0085] Optimizing sensor sensitivity and defense strategy weights using a reinforcement learning parameter tuning mechanism: The dynamic causal inference real-time feedback module integrates a reinforcement learning parameter tuning mechanism for dynamically optimizing the sensitivity of sensors and the weights of defense strategies. The reinforcement learning agent learns the optimal strategy by interacting with the environment (i.e., the network security system). At each time step, the agent observes the state of the system and selects actions (such as adjusting sensor sensitivity, changing defense strategy weights, etc.) according to the current strategy. Then, the agent obtains rewards or punishments based on the results of the actions (i.e., the degree of improvement in system security) and updates the strategy accordingly.
[0086] A method of using an automated defense system for computer network security includes the following steps:
[0087] Initialization and configuration: Deploy in the target network environment, including installing corresponding sensors and processors at edge nodes, core networks, application servers, etc. According to the specific situation and security requirements of the network, initialize the parameters of the system, such as the parameters of the quantum random walk model, the weights of the hyperchaotic neural network, the key length of quantum key distribution, etc. Deploy security policy smart contracts on the blockchain, set trigger conditions and corresponding defense actions to ensure that the defense mechanism can be automatically triggered when detecting specific types of attacks;
[0088] Quantum random walk edge real-time detection: Real-time capture the data flow in the network through sensors deployed at edge nodes, use the quantum random walk model to model the data flow, detect abnormal transitions in the data flow, and immediately issue a warning signal when detecting abnormal behavior;
[0089] Hyperchaotic time series prediction: Preprocess the captured data flow, extract key features, and use the hyperchaotic neural network to perform time series prediction on the preprocessed data to identify potential security threats;
[0090] Abnormal score and early warning: Quantify the chaos degree of the system through Lyapunov exponents, and dynamically set the abnormal threshold. When the prediction result exceeds the threshold, an early warning signal is sent;
[0091] Quantum key distribution: Generate quantum keys using the BB84 protocol to ensure the security and unbreakability of the keys, and use the generated quantum keys to encrypt and transmit threat intelligence between external systems to prevent intelligence leakage or tampering.
[0092] Intelligent contract automation: Real-time detect whether the trigger conditions set in the intelligent contract are met. When the conditions are met, the intelligent contract automatically triggers corresponding defense actions, such as isolating infected devices, cutting off the attack path, etc.;
[0093] Causal graph model construction: Construct a causal Bayesian network of processor-network-application to reflect the causal relationships in the network, and use the causal graph model to infer the propagation path of attacks in real time;
[0094] Reinforcement learning parameter tuning: Use the Proximal Policy Optimization (PPO) algorithm to dynamically adjust the sensitivity of sensors and the weights of defense strategies. According to the real-time detected network status and attack behaviors, continuously learn and adjust parameters to improve the defense effect of the system;
[0095] Defense measure execution: According to the early warning signal and the defense actions triggered by the intelligent contract, execute corresponding defense measures, such as blocking the attack path, isolating infected devices, etc.;
[0096] Effect evaluation: Evaluate the execution effect of the defense measures, including whether the attack is successfully blocked, whether the network resumes normal operation, etc. According to the evaluation results, further adjust the defense strategy and optimize the parameters.
[0097] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made therein without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An automated defense system for computer network security, characterized in that, Including: Quantum Random Walk Edge Real-time Detection Module: Responsible for capturing the data stream in the network in real time and using the quantum random walk model to detect abnormal transitions in the data stream. The data stream captured by the Quantum Random Walk Edge Real-time Detection Module will be passed as input to the Hyperchaotic Time Series Prediction Module; Hyperchaotic Time Series Prediction Module: Uses a hyperchaotic neural network to perform time series prediction on the data stream, identify potential security threats, quantify the chaos degree of the system through Lyapunov exponents, dynamically set the anomaly threshold, and when the prediction result exceeds the threshold, issue a warning signal and pass the anomaly information to the Quantum Key Distribution Cross-system Collaboration Module. The Quantum Key Distribution Cross-system Collaboration Module then encrypts the threat intelligence using the anomaly information and passes it to other systems; Quantum Key Distribution Cross-system Collaboration Module: Uses quantum key distribution technology to encrypt the exchange of threat intelligence between external systems. At the same time, through the intelligent contract automation mechanism, when specific conditions are met, it automatically triggers a full-network defense action. The threat intelligence encrypted by the Quantum Key Distribution Cross-system Collaboration Module will be passed to the Dynamic Causal Inference Real-time Feedback Module, and the Dynamic Causal Inference Real-time Feedback Module will use this information to construct a causal Bayesian network and infer the attack propagation path; Dynamic Causal Inference Real-time Feedback Module: Constructs a causal Bayesian network of processor-network-application, quickly locates and blocks the threat source by inferring the attack propagation path in real time. At the same time, uses the reinforcement learning parameter tuning mechanism to dynamically optimize the sensitivity of the sensor and the weight of the defense strategy. The attack propagation path and defense strategy inferred by the Dynamic Causal Inference Real-time Feedback Module will be fed back to the Quantum Random Walk Edge Real-time Detection Module, and the Quantum Random Walk Edge Real-time Detection Module will adjust the detection parameters and strategies according to this information.
2. An automated defense system for computer network security according to claim 1, characterized in that, The Quantum Random Walk Edge Real-time Detection Module uses the quantum random walk model to detect abnormal transitions in the data stream, including the following steps: Initialize the wave function: Initialize the wave function. The components of the wave function represent the probability amplitudes of data packets or segments being at different positions in the network. A network contains three nodes A, B, and C. Initialize the wave function as a three-dimensional vector, where each component represents the probability amplitude of a particle being at node A, B, or C, and thus obtain ψ(0) = [α β γ], where α, β, and γ are complex numbers and satisfy α 2 + β 2 + γ 2 = 1; Apply the quantum random walk model: Apply the quantum random walk model to update the wave function. After a discrete time step Δt, the wave function is calculated by the following formula ψ(t + 1) = e -iHΔt ψ(t), where H is the Hamiltonian; Detecting Abnormal Transitions: After each update of the wave function, check whether there are significant abnormal changes in the components of the wave function. The abnormal changes represent abnormal transitions in the data stream, that is, data abnormally transfers from one node to another node. Calculate the change rate or difference degree of the wave function components. If the change rate or difference degree exceeds a certain preset threshold, it is considered that an abnormal transition has occurred and the corresponding warning mechanism is triggered.
3. An automated defense system for computer network security according to claim 1, characterized in that, In the Quantum Random Walk Edge Real-time Detection Module, low-rank tensor decomposition technology is deployed on the edge nodes to compress the data dimension.
4. An automated defense system for computer network security according to claim 1, wherein, The Hyperchaotic Time Series Prediction Module uses a hyperchaotic neural network to perform time series prediction on the data stream and identify potential security threats, including the following steps; Data Preprocessing: Preprocess the data stream captured by the Hyperchaotic Time Series Prediction Module; Constructing a Hyperchaotic Neural Network: Construct a neural network model based on hyperchaotic theory to capture the non-linear time series features in the data stream; Network Training: After constructing the neural network model, historical data is needed for training; Time Series Prediction: Once the network training is completed, use this model to perform time series prediction on the new data stream, and the prediction results are used to identify potential security threats; Anomaly Detection and Early Warning: Based on the prediction results and the set anomaly threshold, it is determined whether to trigger an early warning signal. If the prediction result exceeds the threshold range, an early warning signal is issued.
5. An automated defense system for computer network security according to claim 4, characterized in that, The specific steps for the hyperchaotic time series prediction module to dynamically set the anomaly threshold by quantifying the chaos degree of the system through Lyapunov exponents are as follows: Lyapunov exponent calculation: Calculate the Lyapunov exponent of network traffic data to quantify its chaotic characteristics. Based on the definition of the maximum Lyapunov exponent, it is estimated by calculating the exponential divergence rate of adjacent trajectories, and the calculation formula is expressed as where X(t) and X0(t) are the states of adjacent trajectories at time t, X0(0) and X1(0) are the states of adjacent points at the initial time, and λ is the Lyapunov exponent; Dynamically Set Anomaly Threshold: After calculating the Lyapunov exponent, the anomaly threshold is dynamically set. The anomaly threshold is used to determine whether the network traffic data deviates from the normal state, thereby triggering an early warning signal. By calculating the mean and standard deviation of the Lyapunov exponents in the historical data, and then setting the threshold based on these statistics, the calculation formula is expressed as φ = μ + kδ, where μ is the mean of the Lyapunov exponents in the historical data, δ is the standard deviation, and k is a coefficient used to adjust the sensitivity of the threshold.
6. An automated defense system for computer network security according to claim 1, characterized in that, The specific steps for the quantum key distribution cross-system collaboration module to encrypt the threat intelligence exchange between external systems using quantum key distribution technology are as follows: Quantum Key Generation: Use the BB84 protocol to generate quantum keys. The BB84 protocol uses the non-clonability of quantum states and the measurement collapse principle to ensure the security of the keys. In the BB84 protocol, the sender uses four possible quantum states to encode the key bits, and the receiver randomly selects the measurement basis states for measurement and infers the key bits sent by Alice based on the measurement results. The specific expression is quantum state = {∣0>, ∣1>, ∣+>, ∣->}, where ∣0> and ∣1> respectively represent the basis states of photons in the horizontal polarization and vertical polarization directions, and ∣+> and ∣-> respectively represent the basis states of photons in the diagonal polarization and anti-diagonal polarization directions; Key Distribution and Encryption: Once the shared key is generated, Alice and Bob use this key to encrypt and decrypt the threat intelligence. The intelligence data is the plaintext M, and the shared key is K. Then the encrypted ciphertext C is expressed as C = M ⊕ K, where ⊕ represents the exclusive OR operation, and the decryption process is the inverse operation of the encryption process, that is, M = C ⊕ K; Cross-System Collaboration: Between multiple external systems, use the shared key generated by QKD technology to encrypt the exchange of threat intelligence.
7. An automated defense system for computer network security according to claim 1, wherein, The specific steps for the dynamic causal inference real-time feedback module to construct a causal Bayesian network of processor-network-application, quickly locate and block the threat source by inferring the attack propagation path in real-time, and at the same time, use the reinforcement learning parameter tuning mechanism to dynamically optimize the sensitivity of the sensor and the weight of the defense strategy are as follows: Construct a Causal Bayesian Network of Processor-Network-Application: Identify the key components in the system, including the processor, network, and application layer. Based on the interaction relationships between these components, construct a causal Bayesian network. In the Bayesian network, nodes represent components or events, and edges represent the causal relationships between components. Use historical data and expert knowledge to assign a conditional probability table to each node in the Bayesian network to describe the dependency relationships between component states; Real-time inference of the attack propagation path: Once the system detects a potential security event, the dynamic causal inference real-time feedback module will use Bayesian networks for real-time inference. By updating the node states in the Bayesian network and calculating the posterior probability, the module infers the attack propagation path and the possible attack sources; Optimizing sensor sensitivity and defense strategy weights using a reinforcement learning tuning mechanism: The dynamic causal inference real-time feedback module integrates a reinforcement learning tuning mechanism for dynamically optimizing the sensitivity of sensors and the weights of defense strategies. The reinforcement learning agent learns the optimal strategy by interacting with the environment. At each time step, the agent observes the state of the system and selects an action according to the current strategy. Then, the agent obtains a reward or punishment based on the result of the action and updates the strategy accordingly.
8. The automated defense method corresponding to the automated defense system for computer network security according to claim 1, characterized in that, It includes the following steps: Initialization and configuration: Deploy in the target network environment. According to the specific situation of the network and security requirements, initialize the settings of various parameters of the system. Deploy a security policy smart contract on the blockchain and set the trigger conditions and corresponding defense actions; Quantum random walk edge real-time detection: Real-time capture the data stream in the network through sensors deployed on edge nodes, model the data stream using the quantum random walk model, and detect abnormal transitions in the data stream. When abnormal behavior is detected, immediately send out a warning signal; Hyperchaotic time series prediction: Preprocess the captured data stream, extract key features, and use a hyperchaotic neural network to perform time series prediction on the preprocessed data to identify potential security threats; Abnormality scoring and warning: Quantify the chaos degree of the system through Lyapunov exponents, dynamically set the abnormality threshold, and send out a warning signal when the prediction result exceeds the threshold; Quantum key distribution: Generate quantum keys using the BB84 protocol and use the generated quantum keys to encrypt and transmit threat intelligence between external systems; Smart contract automation: Real-time detect whether the trigger conditions set in the smart contract are met. When the conditions are met, the smart contract automatically triggers the corresponding defense actions; Causal graph model construction: Construct a causal Bayesian network of processor-network-application to reflect the causal relationships in the network, and use the causal graph model to infer the attack propagation path in real time; Reinforcement learning tuning: Dynamically adjust the sensitivity of sensors and the weights of defense strategies using the proximal policy optimization algorithm according to the real-time detected network state and attack behavior; Defense measure execution: Execute the corresponding defense measures according to the warning signal and the defense actions triggered by the smart contract; Effect evaluation: Evaluate the execution effect of the defense measures. According to the evaluation results, further adjust the defense strategy and optimize the parameters.
Citation Information
Cited By
Power grid network attack chain risk assessment and threat situation awareness blocking method
CN120750651A