A low-orbit satellite adaptive intrusion detection method and system
By building a regional threat judgment model and dynamic detection container switching technology, the problems of untimely detection and resource waste of low-orbit satellites in different threat areas are solved, and efficient and accurate intrusion detection and rapid response are achieved under limited resources.
Patent Information
- Application Number
- CN202510902678.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-01
AI Technical Summary
Existing technologies cannot achieve real-time detection and adjustment of low-orbit satellites in areas with different threat levels, resulting in untimely detection or waste of resources, and hardware acceleration solutions are not suitable for the resource environment of low-orbit satellites.
By obtaining the area that the satellite is about to enter, identifying the network threat level, predicting network traffic, and calling the adapted detection container combination, it combines real-time network traffic for distribution and intrusion risk detection, and uses real-time positioning data and historical regional attack data to build a threat judgment model to achieve dynamic detection container switching.
It realizes the dynamic detection container switching of low-orbit satellites under limited resource conditions, improves the detection response speed, saves resources, ensures full-time accurate monitoring and rapid feedback, and reduces system energy consumption.
Smart Images

Figure CN120415906B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of satellite network security technology, and in particular to a low-orbit satellite adaptive intrusion detection method and system. Background Art
[0002] In order to maintain satellite network security, fixed detection modules are usually used for full-time monitoring. However, this solution cannot make real-time adjustments to low-orbit satellites frequently crossing areas with different threat levels. Therefore, detection may not be timely in high-risk areas, and there will be a waste of resources in low-risk areas.
[0003] Another method uses hardware acceleration combined with software detection for intrusion defense. Although this can improve detection speed, due to the large size and high energy consumption of the hardware equipment, it is not suitable for the limited resource environment of low-orbit satellites. In addition, the system lacks flexibility and cannot meet the needs of satellites frequently entering different areas.
[0004] Patent application CN117014203A discloses a satellite network adaptive security service system and method, and patent application CN119155101A discloses an intrusion detection and response method and system for a satellite Internet target range, neither of which can solve the above-mentioned problems well. Summary of the Invention
[0005] Embodiments of the present invention provide a low-orbit satellite adaptive intrusion detection method and system to solve at least one of the above problems.
[0006] In a first aspect, an embodiment of the present invention provides a low-orbit satellite adaptive intrusion detection method, comprising:
[0007] Get the area the satellite is about to enter;
[0008] Identifying a network threat level of the area based on network traffic characteristics of the area;
[0009] Predicting the network traffic of the satellite after it enters the area based on the real-time network traffic of the satellite and the network traffic characteristics of the area;
[0010] Based on the prediction results and the network threat level, calling an adapted detection container combination;
[0011] In response to the real-time network traffic after the satellite enters the area, the real-time network traffic is distributed within the detection container combination to cooperate in completing the intrusion risk detection.
[0012] In a second aspect, an embodiment of the present invention provides an electronic device, comprising:
[0013] one or more processors;
[0014] a memory for storing one or more programs,
[0015] When the one or more programs are executed by the one or more processors, the one or more processors implement the low-orbit satellite adaptive intrusion detection method described in any embodiment.
[0016] In a third aspect, an embodiment of the present invention further provides a low-orbit satellite adaptive intrusion detection system, comprising:
[0017] Satellite system, used to obtain the area the satellite is about to enter;
[0018] A region identification component, configured to identify a network threat level of the region based on network traffic characteristics of the region;
[0019] a traffic prediction component, configured to predict the network traffic of the satellite after it enters the area based on the real-time network traffic of the satellite and the network traffic characteristics of the area;
[0020] A mode switching component, configured to call an adapted detection container combination based on the prediction result and the network threat level;
[0021] The traffic distribution engine is used to respond to the real-time network traffic after the satellite enters the area, distribute the real-time network traffic within the detection container combination, and cooperate to complete the intrusion risk detection.
[0022] In summary, the present invention provides an adaptive intrusion detection method for low-orbit satellites, which aims to overcome the shortcomings of existing technologies such as fixed detection modes, resource waste, and hardware dependence, and achieve dynamic switching of detection containers when a satellite enters different threat areas. This method can:
[0023] 1. By combining real-time satellite positioning data with historical regional attack data, a regional threat assessment model is constructed to instantly assess network risks in the satellite's area, providing an accurate basis for subsequent container switching detection.
[0024] 2. Using traffic prediction and mode switching mechanisms, the satellite preloads or adjusts corresponding detection strategies and detection containers before entering different threat zones, ensuring rapid improvement of detection capabilities in high-risk areas while effectively conserving resources in low-risk areas.
[0025] 3. An intelligent traffic distribution engine enables request targeting, ensuring that each detection container receives sufficient detection data. Dynamic traffic distribution and detection mode switching are implemented within limited computing and energy resources, ensuring accurate monitoring at all times.
[0026] 4. Reduce system energy consumption, improve satellite security protection efficiency, and support rapid feedback and timely warning of abnormal information.
[0027] Through the above-mentioned methods, this embodiment not only significantly improves the data processing speed, but also ensures highly accurate intrusion detection under limited energy conditions, and has outstanding technical advantages and practical application promotion value:
[0028] 1. Resource Conservation: Automatically switches detection modes based on the actual regional threat level. High-risk areas use high-precision detection containers, while low-risk areas use lightweight detection methods, greatly optimizing the use of computing resources and energy.
[0029] 2. Improved detection response speed: Pre-loading the detection engine container combined with real-time traffic distribution technology enables rapid activation of high-performance detection mode upon entering high-risk areas, thereby shortening attack detection and early warning response time. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0031] Figure 1 This is a schematic diagram of the architecture of a low-orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention;
[0032] Figure 2 This is a timing flow chart of the coordinated operation of various parts of a low-orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention;
[0033] Figure 3 This is a flow chart of a low-orbit satellite adaptive intrusion detection method provided by an embodiment of the present invention;
[0034] Figure 4 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0035] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention are described clearly and completely below. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.
[0036] In the description of the present invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate and simplify the description of the present invention. They are not intended to indicate or imply that the devices or components referred to must have, be constructed, or operate in a specific orientation, and therefore should not be construed as limitations on the present invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0037] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood broadly. For example, they may refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on the specific circumstances.
[0038] An embodiment of the present invention provides a low-orbit satellite adaptive intrusion detection method. To illustrate the method, a low-orbit satellite adaptive intrusion detection system that supports the implementation of the method is first introduced. Figure 1 FIG. 1 is a schematic diagram of the architecture of a low-orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention. Figure 1 As shown, the system includes a region and prediction module, a detection mode and container scheduling module, a traffic distribution and detection module, and a system management and log module.
[0039] Among them, the regional and prediction module is used to obtain the regional threat value based on the comparison of the current satellite position with historical data, and initiate mode switching according to the traffic prediction results; the detection mode and container scheduling module is responsible for automatically selecting and loading the corresponding detection container according to the prediction results, and synchronizing the update strategy to the configuration manager; after receiving the real-time traffic, the traffic distribution and detection module imports the data into the specific intrusion detection engine container according to the scheduling results for in-depth detection; the system management and log module is responsible for the configuration and management of the entire system parameters, as well as the recording of detection results and reporting of alarm information.
[0040] Figure 2 The following time sequence flow chart illustrates how the various system modules work together when a low-orbit satellite enters a new area, completing the entire process from data capture, processing, distribution, to detection:
[0041] ① The satellite system continuously transmits current position information and preliminary traffic data during flight;
[0042] ② The regional identification component compares the positioning data with the pre-stored regional database to derive a threat rating;
[0043] ③ The traffic prediction component estimates future traffic conditions based on historical data and real-time information, and assists the mode switching component in making response decisions;
[0044] ④The mode switching component notifies the detection container management system to load or update the detection container, and at the same time ensures the consistency of parameters of each module through the configuration manager;
[0045] ⑤ The traffic distribution engine imports real-time data into the designated intrusion detection engine container according to the configuration policy, and the latter performs in-depth data analysis;
[0046] ⑥ The detection results are archived through the log recording module, and the satellite system and ground terminal are quickly notified when an abnormality is found, achieving rapid response and safety protection.
[0047] Based on the above system architecture and basic timing, Figure 3 This is a flow chart of a low-orbit satellite adaptive intrusion detection method provided by an embodiment of the present invention. This method relies on regional prejudgment and dynamic detection container switching technology to achieve a full-link response of data from positioning, prejudgment, detection to alarm. It can be executed by the various parts of the above system or by a separate electronic device. Figure 3 As shown, the method specifically includes:
[0048] S110: Acquire the area that the satellite is about to enter.
[0049] Optionally, satellite regions can be pre-defined. Specifically, the Earth's surface is segmented based on the orbital characteristics of low-orbit satellites. A regional database is then constructed based on historical traffic data and network attack incidents. This database records potential attack characteristics, traffic peak statistics, and descriptions of abnormal behavior in each region. These a priori regional characteristics provide data support for subsequent detection mode selection.
[0050] After the division is completed, the satellite continues to obtain its own position information during operation, and when it detects that it is about to enter a certain area, it starts to execute the method of this embodiment.
[0051] S120: Identify the network threat level of the area according to the network traffic characteristics of the area.
[0052] Combine Figure 2The region identification component determines the network threat level of the region and passes the result to the traffic prediction component. The region identification component uses the geographic information system module to map the current location to a predefined region. It then uses the relevant historical data from the region database to determine the threat level of the current region through a decision-making model. The threat level is categorized as low, medium, or high, and the results directly influence the selection of subsequent intrusion detection strategies.
[0053] Specifically, the above decision model combines historical statistical information with real-time satellite status to accurately and dynamically assess the network risk of the satellite's current area. In one embodiment, the identification of the network threat level includes the following steps:
[0054] Step 1: Feature extraction and quantification. The region recognition component retrieves historical data for the corresponding region from the "region database" and extracts and quantifies the following key features to form a multidimensional feature vector V = [f1, f2, f3, f4, ..., fn], where:
[0055] f1 represents the historical attack frequency, for example, the number / frequency of attack events detected in the area in the past X days, where X is a natural number;
[0056] f2 represents the severity of historical attacks, for example, the average or highest severity score assigned based on the attack type (DDoS, probing, malicious code, etc.). DDoS stands for Distributed Denial of Service.
[0057] f3 represents the degree of abnormality of historical traffic peak, for example, the standard deviation multiple or percentage by which the historical peak traffic exceeds the normal baseline of the area;
[0058] f4 represents known vulnerability indicators, such as vulnerability scores of known network infrastructure or protocols that may be exploited in the region;
[0059] f5 represents the threat transfer factor for the adjacent area, which considers the threat level of the adjacent area that the satellite is about to enter or has just left, and assigns an impact factor based on distance or correlation;
[0060] f6 represents the real-time global threat intelligence correlation, which matches the current regional characteristics with the real-time updated global network threat intelligence library to assess whether there are currently known active attack activities or warnings targeting the area.
[0061] Step 2: Dynamic weight assignment. Assign a weight wi, i = 1, 2, ..., n, to each feature fi in the feature vector V. These weights are not fixed but can be dynamically adjusted based on system strategy or real-time situation. The basis for adjustment may include:
[0062] Satellite mission priority: During high-priority missions, higher weights are assigned to "attack severity" and "real-time intelligence".
[0063] Global security situation: When a specific type of attack (such as a large-scale DDoS) occurs frequently globally, the weight of the corresponding attack feature is increased.
[0064] Model feedback: According to historical prediction accuracy and actual attack events, the weight allocation is optimized regularly through machine learning or reinforcement learning methods to make it more suitable for the current environment.
[0065] Step 3: Weighted fusion calculation. Calculate the weighted comprehensive threat score S:
[0066] S = Σ(wi × fi), where fi is the normalized feature value.
[0067] Step 4: Dynamic threshold determination. Set dynamic thresholds T_low and T_high to map the comprehensive threat score S to the threat level Threat Level (low, medium, high). Among them, the dynamic nature of the thresholds is reflected in: These thresholds can be fine-tuned based on the overall satellite resource status. For example, when the satellite's computing or storage resources are tight, the threshold for entering the "high" threat level may be appropriately increased to avoid resource consumption caused by overly frequent mode switching. Optionally, the thresholds can also be associated with the predicted traffic peak. For example, when a coming traffic peak is predicted, even if the threat score S is the same, it may be more likely to be determined as the "medium" or "high" level to prepare stronger detection capabilities in advance.
[0068] The determination method is:
[0069] If S < T_low, Threat Level = Low (the network threat level is low)
[0070] If T_low ≤ S < T_high, Threat Level = Medium (the network threat level is medium)
[0071] If S ≥ T_high, Threat Level = High (the network threat level is high)
[0072] S130. Predict the network traffic of the satellite after it enters the area based on the real-time network traffic of the satellite and the network traffic characteristics of the area.
[0073] Combined with Figure 2The traffic prediction component uses historical data models to perform short-term deductions on future traffic fluctuation trends and formulate the next detection strategy. This strategy determines the activation mode of the detection container and the resource allocation plan.
[0074] Optionally, this model uses a sliding window algorithm, combined with actual satellite traffic data from different regions, to predict potential attack traffic within a certain period of time (e.g., the next 5-15 minutes) and generate an early warning report. This report includes the expected traffic peak, attack probability, and possible abnormal behavior indicators, providing a basis for decision-making in the mode switching component.
[0075] In one specific implementation, a hybrid model of an LSTM (Long Short-Term Memory) network and an ARIMA (Autoregressive Integrated Moving Average) model is used as the core prediction engine. S130 specifically includes the following steps:
[0076] Step 1: Data Preparation and Sliding Window. Obtain real-time satellite traffic data (e.g., total bandwidth, specific protocol traffic, packet rate, etc.) for the most recent period (e.g., the past Y minutes) to form time series data. Simultaneously, obtain historical traffic patterns and known attack signatures for the target area (the area the satellite is about to enter) provided by the "Region Identification and Threat Prediction" module. Then, use a sliding window technique to process the historical time series data, using the most recent window of length W for each prediction.
[0077] Step 2: Use the core forecasting engine to predict network traffic trends for the future. Specifically, the data within the sliding window is fed simultaneously into the LSTM and ARIMA components. The LSTM component leverages its ability to capture complex nonlinear dependencies and long-term patterns in time series to handle periodicity, trends, and complex fluctuations caused by satellite behavior (such as angular adjustments, mission switching) or covert attacks. The ARIMA component leverages its strengths in processing stationary time series (or those that can be made stationary through differencing) to capture linear relationships and autocorrelation in the data. After processing by both components, two future network traffic event sequences are generated. The LSTM and ARIMA forecasts are then weighted and combined or ensembled (for example, using a meta-learner or a simple weighted average) to produce the initial forecast output by the forecasting engine. Weights can be assigned based on cross-validation performance or dynamically adjusted according to current data characteristics (such as volatility), prioritizing predictions from models that perform better in the current scenario.
[0078] Step 3: Use regional characteristics to modify the prediction results. The preliminary prediction results output by the core prediction engine are modified based on the characteristics of the target area. Optionally, if the target area database shows that the area has periodic traffic peaks during specific time periods (such as the daytime peak period for ground users), even if the time series model does not fully capture this, the predicted peak value should be adjusted upward based on historical patterns. If the target area has a history of frequent attacks of a certain type (such as UDP Flood, User Datagram Protocol Flood), and current global intelligence or satellite sensor data shows similar precursors, the model will pay special attention and may increase the predicted value of the corresponding protocol traffic and increase the "attack probability" indicator. If the characteristics of the target area indicate that the network environment is extremely stable and there have been almost no attacks in history, the abnormal peak value predicted by the model based purely on recent fluctuations may be adjusted downward to reduce false positives.
[0079] Step 4: Predict abnormal indicators. Based on the revised traffic predictions and the target area's attack signature database, the model further predicts possible future abnormal behavior indicators. Optionally, a classifier (such as a decision tree, support vector machine, or simple rule engine) can be trained, taking as input the predicted traffic pattern (peak value, protocol distribution change rate, etc.) and regional characteristics, and outputting the probability of the most likely abnormal behavior type (such as DDoS, scanning detection, and abnormal increase in the number of connections).
[0080] Step 5: Generate an early warning report. Integrate the prediction results to generate a structured early warning report. The report content includes: traffic forecast values (bandwidth, packet rate, etc.) for the short term (e.g., per minute), predicted traffic peaks and their occurrence times, estimated attack probability (based on the match between the predicted traffic pattern and historical attacks in the area), and the most likely abnormal behavior indicators or types.
[0081] S140: Call an adapted detection container combination according to the prediction result and the network threat level.
[0082] Combine Figure 2 ,After receiving the prediction result, the mode switching component immediately ,schedules the intrusion detection engine container, and ,loads or activates the corresponding detection engine in advance through ,virtualization technology, ensuring that the detection system can ,respond to the attack traffic in the first time.
[0083] Optionally, this embodiment pre-builds multiple intrusion detection engine containers to meet the protection needs of different regions. Each container has different detection algorithms and policies built in. Containers for high-threat areas use multi-layered detection and in-depth analysis algorithms, while containers for low-threat areas employ lightweight detection to reduce memory and computing resource usage.
[0084] After the traffic prediction component generates a warning, the mode switching component automatically selects the most appropriate intrusion detection container based on the threat level of the satellite's current area. This switching process includes preloading the detection module, initializing the network traffic data cache, and synchronously updating the traffic distribution strategy. The mode switching is seamless, ensuring that no detection data is missed during the switching process and reducing the occurrence of detection blind spots.
[0085] In one specific implementation, the mode switching component selects and activates the most appropriate combination of detection containers based on the "regional threat level" and the "short-term traffic forecast report." This "combination" may include one or more types of detection containers, and may include multiple instances of the same container type. The specific selection and activation process may include the following steps:
[0086] Step 1: Input integration. The mode switching component receives two key inputs:
[0087] Current regional threat level: output by the regional identification component (low, medium, high); and
[0088] Short-term traffic forecast report: Output by the short-term traffic forecast component, including predicted traffic peak, attack probability, possible abnormal behavior indicators, etc.
[0089] Step 2: Perform decision matrix / rule engine matching. Optionally, a predefined decision matrix or rule engine is maintained internally. This engine takes the "threat level" and key indicators in the "forecast report" as input and outputs the "detection container combination" configuration that needs to be activated.
[0090] In a specific implementation, the specific matching logic includes:
[0091] Rule 1 (Low-risk Steady State):
[0092] IF Threat Level = Low AND Predicted Peak <Threshold_Low AND AttackProbability = Low
[0093] THEN Activate Profile = {1 × Lightweight_Container} (activate a lightweight container instance);
[0094] Rule 2 (Low Risk, High Traffic):
[0095] IF Threat Level = Low AND Predicted Peak>Threshold_High AND AttackProbability = Low
[0096] THEN Activate Profile = {N × Lightweight_Container} (activate N lightweight container instances to handle large traffic, N is calculated based on the predicted peak value);
[0097] Rule 3 (Medium Risk):
[0098] IF Threat Level = Medium AND Attack Probability = Low
[0099] THEN Activate Profile = {1 × Standard_Container} (activate a standard profile container);
[0100] Rule 4 (Medium-risk potential attack): IF Threat Level = Medium AND (Predicted Peak>Threshold_Medium OR Attack Probability = Medium)
[0101] THEN Activate Profile = {1 × Standard_Container, 1 × Specialized_Container(type=predicted_anomaly)} (Activate the standard container and, based on the predicted anomaly type, preload a container that specializes in handling that type of attack, such as a DDoS mitigation container).
[0102] Rule 5 (High Risk):
[0103] IF Threat Level = High
[0104] THEN Activate Profile = {1 × Advanced_Container, M × Specialized_Container(type=common_high_risk)} (Activate an advanced multi-level detection container and preload M specialized containers for handling common high-risk attacks);
[0105] Rule 6 (High-risk strong attack warning):
[0106] IF Threat Level = High AND Attack Probability = High AND PredictedPeak>Threshold_VeryHigh
[0107] THEN Activate Profile = {K × Advanced_Container, P × Specialized_Container(type=predicted_attack)} (Maximize resources, activate K advanced containers and P specialized containers).
[0108] Threat Level represents the threat level, Predicted Peak represents the predicted traffic peak, Attack Probability represents the attack probability, and Activate Profile represents the activation policy. The thresholds (Threshold_Low / Medium / High / VeryHigh) and the number of activated containers (N, M, K, P) in the decision matrix / rule engine are configurable and can be adjusted through the Configuration Manager based on the satellite's real-time resource status (CPU, memory), mission priority, or ground commands, enabling more refined adaptive switching.
[0109] Based on the above rules, a combination of detection containers suitable for the area that the satellite is going to enter can be determined.
[0110] Step 3: Container Instantiation and Preloading. Based on the decision, the mode switching component instantiates the required detection container using virtualization technologies (such as Docker, Kubernetes, and other lightweight virtualization technologies). Optionally, for the zone to be entered, the corresponding container image and detection rules / models are preloaded into memory to reduce cold start latency during the switch.
[0111] Step 4: Resource allocation and initialization. Allocate computing resources (CPU cores, memory quota) to the activated container instance; initialize the internal state of the container, such as clearing old caches, loading the latest threat intelligence, and setting up initial network connections.
[0112] Step 5: Synchronize traffic distribution strategies. The traffic distribution engine is notified of the newly activated container combination information (container address, processing capacity, type, etc.), and its routing table or distribution strategy is updated to ensure that traffic is correctly directed to the new container combination.
[0113] Step 6: Seamless handover execution. At the precise moment the satellite crosses a sector boundary or the predicted conditions meet the handover threshold, the handover operation is completed atomically. This may involve a brief traffic buffer or the use of redundant links / container instances to ensure no packet loss or detection interruption at the instant of handover.
[0114] S150 , in response to the real-time network traffic after the satellite enters the area, distribute the real-time network traffic within the detection container combination to cooperate in completing intrusion risk detection.
[0115] Combine Figure 2 ,The traffic distribution engine distributes the traffic data transmitted in real time by the satellite to each ,detection container based on the latest configuration, and the intrusion detection engine in ,each container performs deep detection and real-time analysis on the data.
[0116] Optionally, when faced with high-density attack traffic, the traffic distribution engine prioritizes all traffic to high-threat containers for in-depth inspection, while processing normal or low-risk traffic in low-risk containers. This allows for dynamic resource allocation and optimal utilization within limited hardware resources. Inter-container scheduling rules set priorities and traffic switching thresholds, ensuring the system automatically adjusts its response strategy based on actual traffic risk.
[0117] In a specific implementation, the following traffic distribution strategy may be adopted:
[0118] Load balancing: If the activated combination contains multiple container instances of the same type (for example, rule 2 activates N lightweight containers), the traffic distribution engine will distribute the traffic evenly (or based on the current load of the container) to these instances to avoid overloading of a single point.
[0119] Content-based routing: The traffic distribution engine performs preliminary, lightweight traffic identification (e.g., based on protocol, port, or traffic rate spikes), then prioritizes specific types of traffic to the most suitable container within the group to handle them. For example, suspected UDP flood traffic is preferentially sent to the group's activated "DDoS-dedicated container"; ordinary web requests are sent to the "standard container" or "advanced container"; and traffic that is not categorized by default or cannot be quickly classified may be distributed according to the load balancing policy.
[0120] Priority and threshold control: Processing priorities can be set for different containers within the group. For example, even if multiple containers are available, the "Advanced Container" may be given the highest priority to handle all the traffic it can handle, and other containers will only be used when it is saturated. Traffic thresholds can also be set. For example, when the traffic rate entering the "Standard Container" or the number of suspicious events detected exceeds a certain threshold, the traffic distribution engine automatically redirects some or all of the subsequent traffic to more capable or specialized containers within the group (such as "Advanced Containers" or "Specific Attack Protection Containers"), even if these containers have not handled much traffic before. This enables real-time response upgrades when an attack occurs, rather than waiting for the next macro mode switch.
[0121] The traffic distribution engine, the hub of the entire system, receives real-time traffic data from satellites and distributes it to the corresponding intrusion detection engine containers based on the current detection mode. This distribution process, based on data labeling, traffic classification, and routing algorithms, ensures seamless data transfer between containers while fully utilizing the computing resources of each detection engine.
[0122] Each intrusion detection engine container has multiple built-in detection algorithms, including rule matching, behavioral baseline models, statistical anomaly detection, and machine learning algorithm fusion strategies. By deeply analyzing the traffic entering the container, the detection engine can quickly identify abnormal traffic and potential attacks.
[0123] Upon detecting abnormal data, the intrusion detection engine immediately transmits this information to the logging and alerting module. This module not only records each detection step but also, depending on the severity of the anomaly, immediately sends an alert to the ground command center or satellite autonomous control system, triggering subsequent security measures. This enables a rapid response.
[0124] Combine Figure 1 The configuration management and logging module includes a configuration manager and a logging mechanism. Specifically, in order to enable each module to maintain consistency under different operating environments, this embodiment adopts a unified configuration manager. The configuration manager is responsible for loading and updating the parameters of each detection container, detection strategy and traffic distribution rules to ensure that each part always operates in accordance with the predetermined strategy. System administrators can update and optimize the detection strategy through the remote configuration management interface to adapt to the ever-changing network attack situation. All data flows, detection results and abnormal alarms in the system need to be stored in the logging module. Logging not only meets the requirements in terms of real-time performance, but also supports offline data aggregation and historical data analysis. This mechanism provides a large amount of reference data for subsequent security policy updates and intrusion detection algorithm training. It can also help system developers to promptly discover system performance or configuration problems, ensuring that the entire solution is always in the best operating state.
[0125] Furthermore, the system utilizes a lightweight distributed architecture. Considering the limited hardware resources of low-orbit satellites, each detection module utilizes an independently run containerized design, enabling modular deployment and flexible scheduling. Modules communicate through message queues and data pipelines, ensuring efficient data transmission and processing capabilities even under high concurrency.
[0126] The system also enables dynamic resource scheduling: as real-time traffic and threat levels fluctuate, it automatically starts, stops, and scales intrusion detection containers according to predefined resource scheduling policies. The dynamic resource scheduling module uses its own load metrics to allocate computing resources to the detection containers most in need, maximizing resource utilization. During container switching, traffic data is backed up and restored in real time to ensure uninterrupted detection.
[0127] The configuration manager continuously monitors the status of each module and automatically adjusts parameters or issues alarms when necessary to ensure overall system stability and efficient operation.
[0128] In summary, this embodiment provides an adaptive intrusion detection method for low-orbit satellites, aiming to overcome the shortcomings of existing technologies, such as fixed detection modes, resource waste, and hardware dependence, and to achieve dynamic switching of detection containers when a satellite enters different threat zones. This method can:
[0129] 1. By combining real-time satellite positioning data with historical regional attack data, a regional threat assessment model is constructed to instantly assess network risks in the satellite's area, providing an accurate basis for subsequent container switching detection.
[0130] 2. Using traffic prediction and mode switching mechanisms, the satellite preloads or adjusts corresponding detection strategies and detection containers before entering different threat zones, ensuring rapid improvement of detection capabilities in high-risk areas while effectively conserving resources in low-risk areas.
[0131] 3. An intelligent traffic distribution engine enables request targeting, ensuring that each detection container receives sufficient detection data. Dynamic traffic distribution and detection mode switching are implemented within limited computing and energy resources, ensuring accurate monitoring at all times.
[0132] 4. Reduce system energy consumption, improve satellite security protection efficiency, and support rapid feedback and timely warning of abnormal information.
[0133] Through the above-mentioned methods, this embodiment not only significantly improves the data processing speed, but also ensures highly accurate intrusion detection under limited energy conditions, and has outstanding technical advantages and practical application promotion value:
[0134] 1. Resource Conservation: Automatically switches detection modes based on the actual regional threat level. High-risk areas use high-precision detection containers, while low-risk areas use lightweight detection methods, greatly optimizing the use of computing resources and energy.
[0135] 2. Improved detection response speed: Pre-loading the detection engine container combined with real-time traffic distribution technology enables rapid activation of high-performance detection mode upon entering high-risk areas, thereby shortening attack detection and early warning response time.
[0136] Figure 4 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention is shown in FIG. Figure 4 As shown, the device includes a processor 60, a memory 61, an input device 62 and an output device 63; the number of processors 60 in the device can be one or more. Figure 4 In the embodiment, a processor 60 is used as an example; the processor 60, the memory 61, the input device 62 and the output device 63 in the device can be connected by a bus or other means. Figure 4 The bus connection is taken as an example.
[0137] Memory 61, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the adaptive intrusion detection method for low-orbit satellites in the embodiments of the present invention. Processor 60 executes the software programs, instructions, and modules stored in memory 61 to perform various functional applications and data processing of the device, thereby implementing the adaptive intrusion detection method for low-orbit satellites described above.
[0138] The memory 61 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function; the data storage area may store data generated based on the use of the terminal. Furthermore, the memory 61 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state memory device. In some instances, the memory 61 may further include memory remotely located relative to the processor 60, and these remote memories may be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0139] The input device 62 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the device. The output device 63 may include a display device such as a display screen.
[0140] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the low-orbit satellite adaptive intrusion detection method of any embodiment.
[0141] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device.
[0142] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0143] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0144] Computer program code for performing the operations of the present invention can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as C or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0145] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the technical solutions of the embodiments of the present invention.
Claims
1. A low-orbit satellite adaptive intrusion detection method, characterized in that: include: Get the area the satellite is about to enter; Identifying a network threat level of the area based on network traffic characteristics of the area; Predicting the network traffic of the satellite after it enters the area based on the real-time network traffic of the satellite and the network traffic characteristics of the area; Based on the prediction results and the network threat level, calling an adapted detection container combination; In response to the real-time network traffic after the satellite enters the area, the real-time network traffic is distributed within the detection container combination to cooperate in completing the intrusion risk detection.
2. The method according to claim 1, characterized in that The identifying the network threat level of the area according to the network traffic characteristics of the area includes: Extracting network traffic characteristics of the region from a regional database, the network traffic characteristics including historical attack frequency, historical attack severity, historical traffic peak abnormality, known vulnerability indicators, neighboring region threat transmission factors, and real-time global threat intelligence correlation; Dynamically assign weighted weights to various network traffic characteristics based on satellite mission priorities and global security posture; Perform weighted fusion calculation on each network traffic feature according to the assigned weights; The network threat level of the area is determined based on the fusion result and the dynamic threshold.
3. The method according to claim 2, characterized in that The method dynamically assigns weighted weights to various network traffic characteristics based on satellite mission priorities and global security situation, including: Assign higher weights to historical attack severity and real-time global threat intelligence relevance during high-priority satellite missions; When specific attacks occur frequently around the world, the weight of the global threat situation relevance is increased; During the detection process, the weight distribution is regularly optimized based on historical prediction accuracy and actual attack events.
4. The method according to claim 1, wherein The predicting, based on the real-time network traffic of the satellite and the network traffic characteristics of the area, the network traffic after the satellite enters the area includes: Using a hybrid model of a long short-term memory network and an autoregressive integrated moving average model, the real-time network traffic of the satellite is processed to preliminarily predict the network traffic time series after the satellite enters the area; Based on the network traffic characteristics of the area, the initial predicted time series is revised to adjust the predicted peak value and attack probability; Based on the corrected data and the attack signature library of the area, possible abnormal behavior indicators in the future are predicted.
5. The method according to claim 4, characterized in that The hybrid model of the long short-term memory network and the autoregressive integrated moving average model is used to process the real-time network traffic of the satellite and preliminarily predict the network traffic time series after the satellite enters the area, including: Processing the real-time network traffic of the satellite using a long short-term memory network to obtain a first network traffic sequence; Processing the real-time network traffic of the satellite using an autoregressive integrated moving average model to obtain a second network traffic sequence; The first network traffic sequence and the second network traffic sequence are fused by weighted averaging or ensemble learning to obtain a final prediction result.
6. The method according to claim 4, characterized in that The prediction of possible future abnormal behavior indicators based on the corrected data and the attack signature library of the region includes: The corrected traffic peak value, protocol distribution change rate, and traffic characteristics of the area are input into the trained classifier to predict possible abnormal behavior types in the future.
7. The method according to claim 1, characterized in that The prediction results include traffic peak and attack probability; The calling of an adapted detection container combination according to the prediction result and the network threat level includes: Determining the risk status of the satellite in the area according to the network threat level; When the risk state is a low-risk steady state, activating a lightweight container instance; When the risk state is low risk and high traffic, activate N lightweight container instances to handle the high traffic; In the case where the risk status is medium risk, activating a standard configuration container; When the risk status is a medium-risk potential attack, a standard container is activated, and a dedicated container for processing the predicted anomaly type is preloaded according to the predicted anomaly type; When the risk status is high, activate the advanced multi-level detection container and preload M dedicated containers for processing common high-risk attacks; When the risk status is a high-risk strong attack warning, K advanced containers and P targeted special containers are activated; Among them, N, M, K and P are dynamic configuration parameters.
8. The method according to claim 1, characterized in that The distributing of the real-time network traffic within the detection container combination includes: Distributing the real-time network traffic within the detection container combination based on load balancing and traffic content; Traffic distribution is adjusted based on container priority and traffic threshold.
9. An electronic device, characterized in that: include: one or more processors; a memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the low-orbit satellite adaptive intrusion detection method described in any one of claims 1-8.
10. A low-orbit satellite adaptive intrusion detection system, characterized in that: include: Satellite system, used to obtain the area the satellite is about to enter; A region identification component, configured to identify a network threat level of the region based on network traffic characteristics of the region; a traffic prediction component, configured to predict the network traffic of the satellite after it enters the area based on the real-time network traffic of the satellite and the network traffic characteristics of the area; A mode switching component, configured to call an adapted detection container combination based on the prediction result and the network threat level; The traffic distribution engine is used to respond to the real-time network traffic after the satellite enters the area, distribute the real-time network traffic within the detection container combination, and cooperate to complete the intrusion risk detection.
Citation Information
Patent Citations
Satellite network adaptive security service system and method
CN117014203A
Intrusion detection and response method and system of satellite internet target range
CN119155101A
Satellite network load balancing routing strategy based on flow prediction
CN116760758A
Dynamic capacity expansion and contraction method and device for satellite edge computing service and storage medium
CN117573339A