Unmanned aerial vehicle cluster network node security isolation and re-access method and system

By building an anomaly detection model and a diagnosis and repair mechanism, the problem of identifying and reconnecting abnormal nodes in the drone cluster network is solved, the robustness and communication security of the drone cluster are improved, and the efficient operation of the network is ensured.

CN120602943APending Publication Date: 2025-09-05SCHOOL OF INFORMATION & COMM TECH NAT UNIV OF DEFENSE TECH OF THE CHINESE PEOPLES LIBERATION ARMY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510814254.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In drone swarm networks, the identification, isolation, repair, and reverification processes of abnormal nodes are subject to misjudgment, communication delays, bandwidth limitations, and incomplete security verification, which affect the robustness and efficiency of the cluster.

Method used

By building an anomaly detection model, we obtain the behavioral deviation attribute data of drone cluster nodes, combine it with the cluster topology structure attributes, calculate the comprehensive behavioral deviation, isolate abnormal nodes, and diagnose and repair their software and hardware status. After dynamically verifying the node status recovery, we adjust its connection relationship and reintegrate it into the cluster topology structure.

Benefits of technology

It achieves rapid identification, accurate diagnosis and efficient repair of abnormal nodes in drone clusters, improves the robustness, security and communication efficiency of the cluster, and realizes safe re-access of nodes under the premise of ensuring network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602943A_ABST
    Figure CN120602943A_ABST
Patent Text Reader

Abstract

The invention discloses an unmanned aerial vehicle cluster network node security isolation and re-access method, and the method comprises the steps: obtaining the behavior deviation attribute data of an unmanned aerial vehicle cluster node, and constructing an anomaly detection model in combination with a cluster topological structure attribute; calculating the comprehensive behavior deviation degree of each node, judging that the node is an abnormal node when the comprehensive behavior deviation degree exceeds a preset threshold value, and performing isolation processing on the abnormal node; behavior data and software and hardware state log data of the abnormal nodes are obtained, and diagnosis and restoration are carried out; obtaining state data of the repaired abnormal node, and dynamically verifying whether the node state of the repaired abnormal node is recovered to be normal or not; and the connection relation of the nodes passing the verification is adjusted according to the centrality of the nodes and the clustering coefficient, and the nodes are re-fused into a cluster topological structure. According to the invention, identification, isolation and repair of abnormal nodes of the unmanned aerial vehicle cluster and re-access to the network after security verification can be realized on the premise of ensuring network security, and the robustness, security and efficiency of the unmanned aerial vehicle cluster are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of drone cluster network security technology, and in particular to a drone cluster network node security isolation and re-access method and system. Background Art

[0002] In a drone cluster network, when a drone node is detected to have abnormal behavior or is attacked maliciously, it needs to be identified and isolated in a timely manner, and then further repaired and re-verified to ensure that it can rejoin the cluster after returning to normal status.

[0003] However, this process currently presents several technical difficulties. First, identifying and locating isolated nodes requires a highly accurate detection mechanism. Due to the dynamic nature of drone swarms and the complex interactions between nodes, traditional static detection methods struggle to accurately identify abnormal nodes and are prone to misjudgments or omissions. This can lead to the incorrect isolation of healthy nodes, impacting the overall operational efficiency of the swarm. Second, drone nodes may experience anomalies due to hardware failures, software vulnerabilities, or malicious attacks. Remediating these anomalies requires specific measures tailored to the cause. For example, software vulnerabilities require timely patch updates, while hardware failures may require remote diagnosis or physical maintenance. However, drone swarms are often deployed in complex or dangerous environments, making physical maintenance challenging. Remote repairs can also face communication delays and bandwidth limitations. Furthermore, after a repaired node rejoins the swarm, its security must be re-verified to ensure it no longer poses a potential threat. This process requires efficient verification algorithms and sufficient computing resources to avoid introducing delays or bottlenecks during the verification process, which could impact the real-time and responsiveness of the swarm. Overly strict isolation and verification mechanisms can lead to excessive node losses, reducing overall cluster utilization. Overly lax mechanisms can expose the swarm to security risks.

[0004] Therefore, how to efficiently and safely identify, isolate, repair, and reconnect abnormal nodes in drone clusters after security verification while ensuring network security, and improve the robustness, communication security, and efficiency of drone clusters, is a key issue currently faced in drone network cluster applications. Summary of the Invention

[0005] In response to the above defects or improvement needs of the prior art, the present invention provides a method for secure isolation and re-access of drone cluster network nodes to at least solve one of the above-mentioned problems.

[0006] According to one aspect of the present invention, a method for securely isolating and re-accessing nodes in a drone cluster network is provided, comprising:

[0007] Obtain the behavioral deviation attribute data of drone cluster nodes and build an anomaly detection model based on the cluster topology attributes;

[0008] Calculate the comprehensive behavior deviation of each node through the anomaly detection model, determine the node as an abnormal node when the comprehensive behavior deviation of the node exceeds a preset threshold, and isolate the abnormal node;

[0009] For the isolated abnormal nodes, obtain their behavior data and software and hardware status log data, diagnose and repair them;

[0010] Acquire the status data of the abnormal node after the repair is completed, the status data including the mutation degree of the fusion node interaction mode and the connection relationship change degree, and dynamically verify whether the node status of the abnormal node has returned to normal after the repair is completed;

[0011] If the node status verification passes, its connection relationship is adjusted according to the node centrality and clustering coefficient, and it is reintegrated into the cluster topology.

[0012] As a preferred technical solution of the present invention, the construction of an anomaly detection model specifically includes:

[0013] Obtain the state change frequency and communication content abnormality of the drone cluster nodes to obtain the state frequency and abnormality data;

[0014] Based on the state frequency and anomaly data, use pre-established rules to determine whether the node has behavioral deviation and generate a behavioral deviation index;

[0015] Get the connectivity and centrality data of cluster nodes and get the connectivity and centrality indicators;

[0016] The behavior deviation index is combined with the connectivity and centrality indexes to construct a cluster topology attribute matrix.

[0017] As a preferred technical solution of the present invention, the state change frequency includes the position and speed change frequency, the communication content abnormality includes the communication frequency abnormality, and the abnormality detection model is specifically:

[0018] Total dev =w v *V dev +w p *P dev +w f *F dev +w central *C dev +w connect *Loss dev

[0019] Among them, w v ,w p ,w f ,w central and w connect are the weights of speed, location, communication frequency, centrality and connectivity, and satisfy w v +w p +w f +w central +w connect =1, C dev is the centrality deviation, Loss dev is the connectivity deviation, V dev is the speed deviation, P dev is the position deviation, F dev is the communication frequency deviation.

[0020] As a preferred technical solution of the present invention, the specific process of diagnosing and repairing includes:

[0021] Obtaining behavior data of the isolated node and determining its abnormality, wherein the behavior data includes resource consumption and response delay, and the abnormality includes resource consumption abnormality and response delay abnormality;

[0022] Based on the abnormality of the above behavioral data and the abnormal values ​​extracted from the software and hardware status log data, a multimodal fusion diagnosis model is obtained to obtain the root cause of the node abnormality and the diagnosis plan;

[0023] According to the root cause of the node abnormality and the diagnosis plan, formulate a corresponding repair plan for repair.

[0024] As a preferred technical solution of the present invention, the dynamic verification of whether the node status has returned to normal specifically includes:

[0025] Obtain the interaction mode mutation degree and connection relationship change degree of the node to be verified;

[0026] Obtaining a node comprehensive deviation based on the interaction pattern mutation degree and the connection relationship change degree;

[0027] If the comprehensive deviation is lower than the preset threshold, the node status is determined to be restored to normal, otherwise it is determined that the status has not been restored.

[0028] As a preferred technical solution of the present invention, the comprehensive deviation is specifically:

[0029]

[0030] Where V t =[IPM t ′,CDC t ′] T is the feature vector, IPMt ′ is the interactive mode mutation degree IPM t Normalized value, CDC t ′ is the connection relationship change degree CDC t The normalized value, μ is the mean value in the normal state, and Σ is the covariance matrix in the normal state.

[0031] As a preferred technical solution of the present invention, adjusting the connection relationship of nodes according to their centrality and clustering coefficient and reintegrating them into the cluster topology structure specifically includes:

[0032] Get real-time status information of all nodes in the drone cluster;

[0033] Calculate the centrality index and clustering coefficient index of the node after verification;

[0034] Generate the connection fitness matrix between the node and other nodes in the cluster based on the centrality index and clustering coefficient index;

[0035] Dynamically adjust the connection weights between a node and other nodes in the cluster based on the connection fitness matrix;

[0036] According to the adjusted connection weights, the node connection relationships in the cluster topology are updated.

[0037] According to another aspect of the present invention, a device for securely isolating and re-accessing nodes in a drone cluster network is provided, characterized in that it includes:

[0038] A model building module is configured to obtain behavioral deviation attribute data of drone cluster nodes and build an anomaly detection model based on cluster topology attributes;

[0039] an isolation module configured to calculate the comprehensive behavior deviation of each node using the anomaly detection model, determine that the node is an abnormal node when the comprehensive behavior deviation of the node exceeds a preset threshold, and isolate the abnormal node;

[0040] A repair module is configured to obtain behavioral data and software and hardware status log data of the isolated abnormal node, perform diagnosis and repair;

[0041] a verification module configured to obtain behavioral data of the abnormal node after repair is completed, the behavioral data including a mutation degree of the fusion node interaction mode and a connection relationship change degree, and dynamically verify whether the node status of the abnormal node has returned to normal after the repair is completed; and

[0042] The re-access module is configured to adjust the connection relationship of a node according to the node centrality and clustering coefficient if the node status verification is passed, and reintegrate the node into the cluster topology.

[0043] According to another aspect of the present invention, a drone cluster network node security isolation and re-access device is provided, which is characterized in that it includes at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the computer program is executed by the processing unit, the processing unit executes the steps of the method.

[0044] According to another aspect of the present invention, a storage medium is provided, which stores a computer program executable by a visit authentication device, and when the computer program is run on the visit authentication device, the visit authentication device executes the steps of the method.

[0045] In general, the above technical solutions conceived by the present invention have the following advantages compared with the prior art:

[0046] Beneficial effects:

[0047] The present invention discloses a method for securely isolating and reconnecting nodes in a drone cluster network. The method comprises obtaining behavioral deviation attribute data of drone cluster nodes, combining the cluster topology attributes to construct an anomaly detection model, calculating the comprehensive behavioral deviation of each node, determining the node as an abnormal node when it exceeds a preset threshold, and isolating the abnormal node. Furthermore, the method diagnoses and repairs the abnormal node by obtaining the behavioral data and software and hardware status log data of the abnormal node. The method obtains the status data of the abnormal node after the repair is completed, and dynamically verifies whether the node status of the abnormal node after the repair is restored to normal. For nodes that pass the verification, the connection relationship is adjusted according to the node centrality and clustering coefficient, and the node is reintegrated into the cluster topology. Through the above steps, the method of the present invention can achieve the identification, isolation, repair, and reconnection of abnormal nodes in the drone cluster to the network after security verification while ensuring network security, thereby improving the robustness, safety, and efficiency of the drone cluster. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 This is a flow chart of a method for securely isolating and re-accessing nodes in a drone cluster network according to one embodiment of the present invention;

[0049] Figure 2 This is a specific flow chart of constructing an anomaly detection model in a method for securely isolating and re-accessing nodes in a drone cluster network according to an embodiment of the present invention;

[0050] Figure 3 A specific flow chart of diagnosis and repair in a method for secure isolation and re-access of a drone cluster network node according to an embodiment of the present invention;

[0051] Figure 4This is a specific flow chart of reintegrating into the cluster topology structure in a method for secure isolation and re-access of drone cluster network nodes in an embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0053] This embodiment provides a method for securely isolating and reconnecting drone cluster network nodes, which is used to quickly identify, accurately diagnose, and efficiently repair abnormal nodes in a drone cluster, and then smoothly reintegrate them into the cluster topology.

[0054] like Figure 1 Specifically, the method for securely isolating and re-accessing drone cluster network nodes in this embodiment may include the following steps:

[0055] Step S101: Obtain the behavior deviation attribute data of the drone cluster nodes, and build a cluster node anomaly detection model based on the cluster topology attributes.

[0056] like Figure 1-2 As shown, this solution obtains behavioral deviation attribute data from drone cluster nodes. This behavior deviation attribute data includes at least the frequency of state changes and the degree of abnormality in communication content, thereby obtaining state frequency and abnormality data. Based on this state frequency and abnormality data, pre-established rules are used to determine whether the node has behavioral deviation and generate a behavior deviation index.

[0057] At the same time, cluster topology attributes are obtained, including at least the connectivity and centrality data of cluster nodes, to obtain connectivity and centrality indices. The aforementioned behavioral deviation index is combined with the connectivity and centrality indices to construct a cluster topology attribute matrix, which serves as a cluster node anomaly detection model.

[0058] In this embodiment, the cluster node anomaly detection model may be trained to improve the recognition accuracy of the detection model.

[0059] Behavioral deviation attribute data includes at least the frequency of state changes and the degree of abnormality in communication content. The frequency of state changes in drone cluster nodes can usually be obtained through the temporal changes in attributes such as node position and speed. For example, when a drone is cruising normally, its position changes by about 5 meters per second. When its position changes abnormally drastically or stagnates for a long time, it can be determined that the state frequency is abnormal. The degree of abnormality in communication content can be measured from two dimensions: the quantity and quality of communication data between nodes. For example, if a node normally sends 10 status messages per minute, and this suddenly increases to 50 per minute or drops to 1 per minute, it is considered an abnormal situation.

[0060] The generation of node behavior deviation indicators can be combined with existing rules. For example, a speed change threshold of 10 m / s and a communication frequency threshold of 20 messages per minute can be set. When the actual data of a node exceeds the threshold range, different weights are assigned based on the degree of deviation, ultimately resulting in a behavior deviation indicator value.

[0061] Furthermore, node connectivity reflects the degree of communication between a node and its surrounding nodes. For example, if a node normally maintains stable communication with eight surrounding nodes, but can only communicate with, for example, two, this indicates a significant decrease in connectivity. Centrality, on the other hand, reflects the importance of a node within the network. Nodes at the core of the network typically have higher centrality values.

[0062] The topological structure attribute matrix is ​​a model that integrates multiple characteristics of a node, such as behavioral deviation, connectivity, and centrality. It can be characterized by a comprehensive behavioral deviation. In the field of drone cluster node anomaly handling and reconnection, this comprehensive behavioral deviation is a core metric for quantifying drone node behavioral anomalies. It is calculated based on multidimensional data fusion. The comprehensive behavioral deviation is calculated by integrating multiple dimensions, including a node's speed, location, and other behavioral data, as well as its centrality and connectivity within its cluster.

[0063] In this embodiment, the specific formula for the comprehensive behavior deviation can be:

[0064] Total dev =w v *V dev +w p *P dev +w f *F dev +w central *C dev +w connect *Loss dev

[0065] Among them, w v ,w p ,w f ,w central and wconnect are the weights of speed, location, communication frequency, centrality and connectivity, i.e. the weights of the deviation of each behavior and the deviation of centrality and connectivity, and satisfy: w v +w p +w f +w central +w connect =1.

[0066] In the above formula, C dev is the centrality deviation, and where c i is the degree centrality (i.e., the number of neighbors) of node i, C avg is the average degree centrality of the cluster, δ c is the standard deviation of the cluster degree centrality.

[0067] In the above formula, Loss dev is the connectivity deviation, and Loss dev =min(1,max(0,(loss i -loss base )) / loss max -loss base ), where loss i is the packet loss rate of node i (such as the most recent measurement value), loss base is the allowable basic packet loss rate (such as 5%), loss max is the maximum allowed packet loss rate (such as 20%). And when the packet loss rate is less than the basic packet loss rate, loss dev =0, when the packet loss rate exceeds loss max When, Loss dev =1.

[0068] In the above formula, V dev is the speed deviation, that is, the difference between the current speed and the average speed of the cluster or the expected speed. dev =|v i -v base / δ v , where v i is the current speed of node i, v base is the baseline speed (which can be the average speed of the cluster, or the expected speed in mission planning), δ v is the standard deviation of the cluster speed (or the preset allowable fluctuation range).

[0069] In the above formula, P dev is the position deviation, i.e., the Euclidean distance between the current position and the expected position (such as the predetermined trajectory point) or the cluster center position.

[0070] Pdev =min(1,sqrt((x i -x ref ) 2 +(y i -y ref ) 2 +(z i -z ref ) 2 ) / d max ), where (x i ,y i ,z i ) is the current position coordinate of node i, (x ref ,y ref ,z ref ) is the reference position (which can be a predetermined trajectory point or cluster center coordinates), d max The maximum allowable deviation is preset or the threshold is adjusted dynamically according to the task. In this embodiment, min(1,…) is taken to limit the position deviation to between 0 and 1. max It is considered as the maximum deviation (i.e. the value is 1).

[0071] In the above formula, F dev is the communication frequency deviation, that is, the difference between the communication frequency and the preset frequency. dev =min(1,|f i -f base | / Δf max ), where f i is the current communication frequency of node i, f base is the preset standard frequency, Δf max The preset maximum allowable frequency deviation.

[0072] Step S102: Calculate the comprehensive behavior deviation of each node through the above-mentioned anomaly detection model. If the comprehensive behavior deviation of a node exceeds a preset threshold, the node is judged as an abnormal node and isolated.

[0073] The pre-set anomaly detection model is used to obtain the node's comprehensive behavioral deviation and calculate the difference between the comprehensive behavioral deviation and the pre-set threshold. If the comprehensive behavioral deviation of a node exceeds the pre-set threshold, the node is judged to be an abnormal node.

[0074] The preset threshold value for the comprehensive behavior deviation can be determined based on the actual mission requirements, accuracy, and safety requirements of the drone swarm. In one embodiment, the preset threshold value for the comprehensive behavior deviation is set between 0.6 and 0.8, such as 0.6, 0.7, or 0.8, or other values ​​determined based on the actual mission requirements.

[0075] Further isolation processing is performed on the identified abnormal nodes.

[0076] In this embodiment, it is preferred that the node be isolated based on its abnormal characteristics using, for example, a rule-based isolation algorithm. For example, the isolated nodes can be classified using the K-means clustering algorithm to determine their abnormality types, and different isolation means or methods can be used accordingly. When the K-means clustering algorithm is used to classify the isolated nodes, the abnormality types can be divided into three categories: communication abnormalities, behavioral abnormalities, and performance abnormalities. Communication abnormalities manifest as abnormalities in the frequency or content of data transmission, such as a node frequently sending duplicate data packets. Behavioral abnormalities are reflected in abnormalities in flight posture or path, such as a node deviating from the planned route by more than, for example, 50 meters. Performance abnormalities are reflected in abnormalities in processing power or energy levels, such as a sudden drop in power to, for example, below 20%.

[0077] Optionally, abnormal nodes can be categorized into other dimensions, such as general abnormal nodes, high-risk abnormal nodes, and so on, to facilitate hierarchical classification management. Specifically, the load and signal strength of abnormal nodes can be obtained and compared with preset abnormality thresholds. If the threshold is exceeded, the node is marked as a high-risk node.

[0078] Of course, the classification dimensions of abnormal types can be combined with each other or used separately, and this application solution is not limited to this. In an optional embodiment, the isolation decision can use the following matrix:

[0079] Step S103: For the isolated abnormal node, obtain its behavior data and software and hardware status log data, diagnose and repair it.

[0080] like Figure 3 As shown, first, the behavior data of the isolated node is obtained and its abnormality is determined. Preferably, the abnormality of the behavior data includes the abnormality of resource consumption and the abnormality of response delay.

[0081] Specifically, resource consumption anomalies include changes in a node's processor occupancy rate, memory usage, and storage space. For example, in a drone cluster, the processor occupancy rate of a normal node typically remains around 40%, while that of an abnormal node may suddenly soar to over 90%. Such drastic fluctuations often indicate that the node may be infected by malicious programs. Response delay anomalies reflect the node's response speed to control commands. Under normal circumstances, a node should complete its response within a set time, such as 50ms. If a node continuously experiences a response delay exceeding, for example, 200ms, this indicates that the node has a response delay anomaly.

[0082] Based on the behavior data of the isolated nodes, the behavior data abnormality is obtained, including the resource consumption abnormality RAD and the response delay abnormality LAD.

[0083] Secondly, based on the above behavioral data and combined with the abnormal values ​​extracted from the software and hardware status log data, the node is diagnosed for abnormalities and a repair plan is obtained.

[0084] By analyzing software and hardware status logs, we can extract the behavioral characteristics of nodes. Based on the obtained behavioral data such as resource consumption anomalies and response latency anomalies, combined with the node software and hardware status logs, we can diagnose abnormal node status and determine the specific cause of the node anomaly.

[0085] In one embodiment, the extraction of software and hardware status log data includes the hardware health index (HHI) and the software anomaly index (SAI). The hardware health index is a fusion of health values ​​for hardware devices such as motors, batteries, satellite positioning sensors, and gyroscopes (IMUs). The software health index is a fusion of software health values ​​such as process scheduling anomaly, time invariant violation, and communication anomaly.

[0086] It should be noted that the extraction of the hardware health index HHI and the software anomaly index SAI is a relatively mature technical means in the art, which is not the key to the solution of this application and will not be described in detail here.

[0087] Furthermore, based on behavioral data and outliers, a multimodal fusion diagnosis model is obtained through weighted decision-making and root cause analysis to obtain a diagnostic solution.

[0088] In this embodiment, a weighted fusion strategy is adopted to combine behavior and state features to obtain a multimodal fusion diagnosis model and obtain the diagnosis threshold:

[0089] ASF=α·RAD+β·LAD+γ·(1-HHI)+δ·SAI

[0090] In the above formula, α, β, γ, and δ are weight coefficients, which can be dynamically adjusted through Lasso regression to prioritize the significant features, that is,

[0091]

[0092] Wherein, y is a historical fault label. For example, in a preferred embodiment, motor fault = 1 and software error = 2 can be set.

[0093] The diagnostic solution is determined based on the diagnostic threshold and the pre-set root cause location matrix. For example, in an optional embodiment, the abnormality type and diagnosis based on the threshold setting can be expressed as follows:

[0094]

[0095] Based on behavioral data and combined with software and hardware log information, the root cause of the node abnormality and the diagnosis plan are obtained, and then a corresponding repair plan is formulated to carry out the repair.

[0096] Preferably, a machine learning algorithm model can be used to develop a corresponding repair plan, and repairs can be performed based on the repair plan. Different diagnostic plans correspond to different repair strategies. For example, anomaly types can be categorized into three categories: hardware anomalies, software anomalies, and communication anomalies. Based on the fault type, a machine learning algorithm model is used to learn and obtain a repair plan for the fault. Furthermore, node degree distribution information and fault level labels can be combined to prioritize repairs into three levels: urgent, important, and general. Repair plans are then developed based on the different levels.

[0097] In a preferred embodiment, if the diagnosis scheme determines that the root cause of the abnormality is a software vulnerability, the update patch with the smallest degree of change in the node software configuration can be matched from the pre-established patch library, and the patch push path can be optimized through the edge weight data of the abnormal node. In this embodiment, after first obtaining the software vulnerability information of the abnormal node, all relevant patch information is extracted from the pre-established patch library. The degree of change of each patch and the node software configuration is calculated, wherein the above-mentioned degree of change is determined by calculating the ratio of the number of files modified by the patch to the number of node software configuration files. After screening out the update patch with the smallest degree of change, the edge weight data of the abnormal node is obtained, and a patch push path optimization model is constructed based on the edge weight data. The shortest path algorithm is used to calculate the transmission path between nodes to determine the optimal patch push path. Among them, the above-mentioned edge weight data is determined by analyzing the communication frequency and delay between nodes.

[0098] The acquisition of software vulnerability information involves a crucial aspect of system security protection. By extracting node system logs, network traffic records, and application layer data, a complete vulnerability signature library can be constructed. For example, if a node experiences a memory overflow exception and the system log indicates a stack overflow, analysis can determine that the cause is a buffer vulnerability. Simultaneously, a large number of abnormal connection requests are discovered in conjunction with network traffic records, indicating that the vulnerability has been exploited. Patch library management is key to remediating vulnerabilities, and a complete patch version control mechanism must be established. Generally, patch libraries typically include three categories: system upgrade packages, security patches, and functional fixes. For discovered buffer vulnerabilities, relevant security patches can be filtered out from the patch library, including vulnerability repair code and configuration files.

[0099] Optionally, you can also diagnose the root cause of the anomaly and establish a corresponding repair strategy library. The following is a typical example of an optional partial repair strategy library.

[0100]

[0101]

[0102] Step S104: After the abnormal node is repaired, the state data of the node, such as the mutation degree of the fusion node interaction mode and the connection relationship change degree, is obtained to dynamically verify whether the node state has returned to normal.

[0103] In this embodiment, the interaction mode mutation degree IPM and the connection relationship change degree CDC of the repaired node are obtained as state data input, and feature extraction is performed on the input state data to obtain dynamic behavior features. The deviation of the node state value from the preset normal value is calculated based on the dynamic behavior features. If the node deviation is lower than the preset threshold, it is judged that the node state has returned to normal, otherwise the node state has not returned to normal.

[0104] Interaction Pattern Change (IPM) reflects changes in communication behavior between a repaired node and other nodes. During normal operation, the communication frequency and data flow between nodes maintain a relatively stable pattern. Connection Change (CDC) reflects changes in the topological structure between a node and other network members. For example, in a distributed sensor network, each node typically maintains stable connections with three to five neighboring nodes. If a repaired node frequently changes its connection partners, this unstable connection pattern is considered abnormal.

[0105] In this scheme, we first collect the interaction data of the repair nodes in real time, such as the communication message type, frequency, and direction, and the connection relationship data, such as the neighbor node list and connection stability, and extract dynamic behavior characteristics.

[0106] The Interaction Pattern Mutation (IPM) reflects abnormal changes in node communication behavior and can be quantified by analyzing the magnitude and rate of change of the node's communication eigenvector. The Connection Change (CDC) value is used to assess the stability of the connection between a node and its neighbors and can be measured by graph structure similarity.

[0107] Specifically, the interactive mode mutation degree IPM can be achieved through the following steps:

[0108] (1) Extract the communication feature vector F within the time window T, F = [f1, f2, f3] T , where f1 is the message entropy (communication content diversity), f2 is the communication intensity (number of message interactions per unit time), and f3 is the direction balance. δ 2 is the variance of the communication frequency of neighboring nodes, which indicates whether the communication direction is concentrated.

[0109] (2) Obtain the change amplitude of the features in adjacent time windows and calculate the IPM value based on the exponentially weighted moving average of the historical windows.

[0110]

[0111] Where λ is the weight coefficient, which controls the decay rate of historical influence, for example, it can be 0.7. t is the amplitude of feature change in adjacent time windows, ΔF t =‖Ft -F t-1 ‖2, where F t is the communication feature vector sequence, EMA(ΔF) t It is an exponentially weighted moving average based on the historical window.

[0112] In this application, the connection relationship change degree CDC value can be achieved by the following steps:

[0113] (1) Determine the neighbor relationship vector. Let the neighbor set of node i at time t be N t (i), its neighbor vector is defined as: N t (i)=[a i1 ,a i2 ,…,a iN ] T , where N is the number of cluster nodes. If node j is a neighbor of node i, a ij =1, otherwise 0.

[0114] (2) Calculate the similarity of neighbor vectors in adjacent time windows. In this embodiment, cosine similarity is used to measure the difference between neighbor vectors in adjacent time windows, specifically:

[0115]

[0116] (3) Obtain the connection relationship change degree CDC, that is, the negative change of continuous similarity:

[0117] CDC t =1-Sim t (n t-1 ,n t )

[0118] Secondly, based on the extracted features, the current interaction mode mutation degree IPM and connection relationship change degree CDC value are calculated to calculate the comprehensive deviation of the overall state of the node.

[0119] Taking the above IPM and CDC as dynamic behavior features, the Mahalanobis distance is used to calculate the comprehensive deviation:

[0120]

[0121] Where: V t =[IPM t ′,CDC t ′] T is the feature vector, IPM t ′ is IPM t Normalized value, CDC t ′ is CDC t The normalized value, μ is the normal state mean (after standardization), and Σ is the covariance matrix under normal state.

[0122] Finally, if the comprehensive deviation is lower than the preset threshold, the node status is determined to be restored to normal, otherwise it is determined that the status has not been restored.

[0123] Step S105: If the node status verification passes, its connection relationship is adjusted according to the node centrality and clustering coefficient, and it is reintegrated into the cluster topology structure.

[0124] like Figure 4 As shown in the figure, the real-time status information of all nodes in the drone cluster is obtained, the centrality index and clustering coefficient index of the node after verification are calculated, and the connection fitness matrix between the node and other nodes in the cluster is generated based on the centrality index and clustering coefficient index.

[0125] The connection fitness matrix describes the rationality of establishing connections between nodes. The connection fitness matrix in this embodiment is expressed as follows:

[0126]

[0127] Where C ij represents the connection fitness between node i and node j, d ik represents the distance from node i to node k, d jk represents the distance from node j to node k, σ represents the standard deviation parameter, α represents the weight coefficient, and n represents the total number of nodes in the cluster.

[0128] Based on the connection fitness matrix, the connection weights between the node and other nodes in the cluster are dynamically adjusted. Specifically:

[0129]

[0130] Where W ij represents the connection weight between node i and node j, d ij represents the distance between two nodes, σ represents the bandwidth parameter of the Gaussian kernel function, and α represents the weight coefficient.

[0131] According to the adjusted connection weights, the node connection relationships in the cluster topology are updated.

[0132] Furthermore, through iterative calculations, the connection relationships between nodes in the cluster topology can be stabilized, and the updated cluster topology information can be output. Iterative optimization of the topology ensures the overall stability of the cluster. For example, during formation flight, some local connections may be overly dense initially. Through multiple rounds of iterative adjustments, the system gradually reduces the weight of redundant connections, ultimately forming a balanced structure in which each drone node maintains a stable connection with other members. This optimized topology ensures the reliability of information transmission while avoiding excessive consumption of communication resources.

[0133] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structures or equivalent process changes made using the contents of the present invention's description and drawings, or directly or indirectly applied to other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A method for securely isolating and re-accessing nodes in a drone cluster network, characterized in that: The method comprises: Obtain the behavioral deviation attribute data of drone cluster nodes and build an anomaly detection model based on the cluster topology attributes; Calculate the comprehensive behavior deviation of each node through the anomaly detection model, determine the node as an abnormal node when the comprehensive behavior deviation of the node exceeds a preset threshold, and isolate the abnormal node; For the isolated abnormal nodes, obtain their behavior data and software and hardware status log data, diagnose and repair them; Acquire the status data of the abnormal node after the repair is completed, the status data including the mutation degree of the fusion node interaction mode and the connection relationship change degree, and dynamically verify whether the node status of the abnormal node has returned to normal after the repair is completed; If the node status verification passes, its connection relationship is adjusted according to the node centrality and clustering coefficient, and it is reintegrated into the cluster topology.

2. The method according to claim 1, characterized in that The behavior deviation attribute data includes the state change frequency and the abnormality of the communication content, wherein the construction of the abnormality detection model specifically includes: Obtain the state change frequency and communication content abnormality of the drone cluster nodes to obtain the state frequency and abnormality data; Based on the state frequency and anomaly data, use pre-established rules to determine whether the node has behavioral deviation and generate a behavioral deviation index; Get the connectivity and centrality data of cluster nodes and get the connectivity and centrality indicators; The behavior deviation index is combined with the connectivity and centrality indexes to construct a cluster topology attribute matrix.

3. The method according to claim 1 or 2, characterized in that The state change frequency includes the position and speed change frequency, the communication content abnormality includes the communication frequency abnormality, and the abnormality detection model is specifically: Total dev =w v *V dev +w p *P dev +w f *F dev +w central *C dev +w connect *Loss dev Among them, w v ,w p ,w f ,w central and w connect are the weights of speed, location, communication frequency, centrality and connectivity, and satisfy w v +w p +w f +w central +w connect =1, C dev is the centrality deviation, Loss dev is the connectivity deviation, V dev is the speed deviation, P dev is the position deviation, F dev is the communication frequency deviation.

4. The method according to claim 1 or 2, characterized in that The specific process of diagnosing and repairing includes: Obtaining behavior data of the isolated node and determining its abnormality, wherein the behavior data includes resource consumption and response delay, and the abnormality includes resource consumption abnormality and response delay abnormality; Based on the abnormality of the above behavioral data and the abnormal values ​​extracted from the software and hardware status log data, a multimodal fusion diagnosis model is obtained to obtain the root cause of the node abnormality and the diagnosis plan; According to the root cause of the node abnormality and the diagnosis plan, formulate a corresponding repair plan for repair.

5. The method according to claim 4, characterized in that The dynamic verification of whether the node status has returned to normal specifically includes: Obtain the interaction mode mutation degree and connection relationship change degree of the node to be verified; Obtaining a node comprehensive deviation based on the interaction pattern mutation degree and the connection relationship change degree; If the comprehensive deviation is lower than the preset threshold, the node status is determined to be restored to normal, otherwise it is determined that the status has not been restored.

6. The method according to claim 5, characterized in that The comprehensive deviation is specifically: Where V t =[IPM t ′,CDC t ′] T is the feature vector, IPM t ′ is the interactive mode mutation degree IPM t Normalized value, CDC t ′ is the connection relationship change degree CDC t The normalized value, μ is the mean value in the normal state, and Σ is the covariance matrix in the normal state.

7. The method according to claim 1 or 2, characterized in that The method of adjusting the connection relationship of nodes according to the node centrality and clustering coefficient and reintegrating them into the cluster topology structure specifically includes: Get real-time status information of all nodes in the drone cluster; Calculate the centrality index and clustering coefficient index of the node after verification; Generate the connection fitness matrix between the node and other nodes in the cluster based on the centrality index and clustering coefficient index; Dynamically adjust the connection weights between a node and other nodes in the cluster based on the connection fitness matrix; According to the adjusted connection weights, the node connection relationships in the cluster topology are updated.

8. A drone cluster network node security isolation and re-access system, characterized by: include: A model building module is configured to obtain behavioral deviation attribute data of drone cluster nodes and build an anomaly detection model based on cluster topology attributes; an isolation module configured to calculate the comprehensive behavior deviation of each node using the anomaly detection model, determine that the node is an abnormal node when the comprehensive behavior deviation of the node exceeds a preset threshold, and isolate the abnormal node; A repair module is configured to obtain behavioral data and software and hardware status log data of the isolated abnormal node, perform diagnosis and repair; a verification module configured to obtain behavioral data of the abnormal node after repair is completed, the behavioral data including a mutation degree of the fusion node interaction mode and a change degree of the connection relationship, and dynamically verify whether the node status of the abnormal node has returned to normal after the repair is completed; as well as The re-access module is configured to adjust the connection relationship of a node according to the node centrality and clustering coefficient if the node status verification is passed, and reintegrate the node into the cluster topology.

9. A drone cluster network node security isolation and re-access device, characterized by: The method comprises at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the computer program is executed by the processing unit, the processing unit performs the steps of the method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: It stores a computer program executable by an access authentication device. When the computer program runs on the access authentication device, the access authentication device executes the steps of the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Public network unmanned aerial vehicle countering method and device based on base station signal adsorption

    CN121261835A