Feature defense method and system in network transmission process

By intercepting and parsing traffic data in real time during virtual machine migration, extracting multi-dimensional feature vectors, dynamically calculating deviations and performing graded responses, the security and availability issues of virtual machine migration in cloud environments are solved, and efficient abnormal traffic detection and defense are achieved.

CN120614149AInactive Publication Date: 2025-09-09BEIJING YOUANXIN NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510664489.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-09
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies are difficult to adapt to the dynamic changes during the migration of virtual machines in cloud environments, resulting in a high rate of missed reports of unknown attack variants. Traditional methods are also unable to achieve gradient defense, affecting the availability and security of cloud platforms.

Method used

By intercepting the network transmission data flow of the virtual machine migration channel in real time, establishing a two-way traffic mirror pipeline, performing deep protocol analysis and reconstruction, extracting multi-dimensional feature vectors, combining the dynamic time warping algorithm to match normal traffic patterns, calculating dynamic deviations, and executing graded responses based on risk scoring levels.

Benefits of technology

It achieves high-precision detection and graded response to abnormal traffic during virtual machine migration, reduces service interruptions, enhances the security and availability of the cloud computing platform, and builds a cross-node collaborative defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614149A_ABST
    Figure CN120614149A_ABST
Patent Text Reader

Abstract

The invention relates to a feature defense method and system in a network transmission process, and the method comprises the steps: intercepting a network transmission data flow in a migration channel of a virtual machine in real time, and building a bidirectional flow mirror image pipeline; performing deep protocol analysis and recombination on the original transmission message in the mirror image pipeline to obtain a structured traffic log of complete load information and metadata labels; based on a preset traffic feature set, extracting a memory paging transmission time sequence feature and a disk data block check code distribution feature from the structured traffic log, and constructing a first detection sub-vector; according to the invention, a high-precision virtual machine migration security protection system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and system for characteristic defense during network transmission. Background Art

[0002] With the widespread adoption of cloud computing, dynamic virtual machine migration has become a core mechanism for load balancing and fault recovery. However, during the migration process, sensitive information such as memory state and disk data must be transmitted over open networks, exposing them to security threats such as man-in-the-middle attacks, data tampering, and malicious code injection.

[0003] Existing technologies mostly rely on predefined signature libraries or fixed thresholds (such as traffic rate thresholds and checksum matching rules), which are difficult to adapt to the dynamically changing migration traffic patterns in cloud environments, resulting in a high rate of missed reports of unknown attack variants. For example, new attack methods such as protocol fingerprint disguise or fragmentation timing perturbation of encrypted traffic can bypass the detection system based on static rules. Traditional methods rely on decryption operations to detect encrypted migration traffic, but the frequent session key updates and multi-tenant isolation requirements in virtual machine migration scenarios make full traffic decryption less feasible, and there are risks of key management complexity and privacy leakage.

[0004] Most solutions adopt a binary response strategy of blocking or releasing, and are unable to implement gradient defense based on the severity of the attack. For example, low-risk traffic fluctuations triggering process termination will cause frequent interruptions to migration services, affecting the availability of the cloud platform. The existing system lacks the ability to deeply extract and standardize the characteristics of abnormal traffic, resulting in the inability to share attack fingerprints across nodes, making it difficult to form a collaborative defense system. Attackers can exploit this flaw to launch continuous penetration between different physical nodes. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to overcome the deficiencies of the existing technology, provide a feature defense method during network transmission, and realize a high-precision virtual machine migration security protection system.

[0006] In order to solve the above technical problems, the basic concept of the technical solution adopted by the present invention is:

[0007] In a first aspect, a method for defending against signatures during network transmission includes:

[0008] Step S1: intercepting the network transmission data flow in the virtual machine migration channel in real time and establishing a bidirectional traffic mirroring pipeline;

[0009] Step S2: Perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain a structured traffic log with complete payload information and metadata tags;

[0010] Step S3: Based on a preset traffic feature set, extract memory paging transfer timing features and disk data block check code distribution features from the structured traffic log to construct a first detection subvector;

[0011] Step S4: extracting the fingerprint features of the encryption handshake protocol version and the traffic rate mutation threshold, and combining them with the first detection sub-vector to obtain a multi-dimensional detection vector;

[0012] Step S5: Input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline;

[0013] Step S6: When the dynamic deviation exceeds the preset standard deviation threshold, an abnormal behavior alarm is triggered and a risk score level is obtained based on the deviation magnitude;

[0014] Step S7: Calling the adaptive security policy engine according to the risk score level to perform a graded response operation. In the second aspect, a feature defense system in a network transmission process includes:

[0015] Traffic capture module, used to intercept network transmission data streams in virtual machine migration channels in real time and establish a bidirectional traffic mirroring pipeline;

[0016] The reassembly module is used to perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain structured traffic logs with complete payload information and metadata tags;

[0017] A construction module is used to extract memory paging transfer timing characteristics and disk data block checksum distribution characteristics from structured traffic logs based on a preset traffic feature set to construct a first detection sub-vector; extract the encryption handshake protocol version fingerprint characteristics and traffic rate mutation threshold, and combine them with the first detection sub-vector to obtain a multi-dimensional detection vector;

[0018] The calculation module is used to input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline;

[0019] The evaluation module is used to trigger abnormal behavior alarms when the dynamic deviation exceeds the preset standard deviation threshold and obtain a risk score level based on the deviation amplitude; the adaptive security policy engine is called according to the risk score level to perform graded response operations.

[0020] After adopting the above technical solution, the present invention has the following beneficial effects compared with the prior art:

[0021] By intercepting virtual machine migration traffic in real time and building a bidirectional mirror pipeline, combined with deep protocol analysis and reorganization to generate structured traffic logs, we extract multi-dimensional features such as memory paging timing, disk checksum distribution, encryption protocol fingerprints, and traffic rate mutations. Detection vectors are constructed and matched to normal traffic baselines using a dynamic time warping algorithm. This allows for dynamic deviation calculation and risk grading of abnormal traffic. Based on the risk level, graded response strategies such as key rotation, path switching, and process interruption are implemented. Based on defense effectiveness feedback, baseline model parameters are dynamically adjusted and attack fingerprints are extracted to form a cross-node collaborative defense threat intelligence system. This overcomes the limitations of traditional static rule-based detection and achieves high-precision detection of encrypted migration traffic without full traffic decryption. Gradual response reduces service interruptions and uses dynamic baselines to adapt to traffic fluctuations in the cloud environment. Furthermore, through threat intelligence sharing, a clustered active defense system is established to improve the detection accuracy and response efficiency of new threats such as man-in-the-middle attacks and data tampering during virtual machine migration, thereby enhancing the security and availability of cloud computing platforms. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 It is a flow chart of the characteristic defense method during network transmission of the present invention.

[0023] Figure 2 It is a schematic diagram of the characteristic defense system during network transmission of the present invention. DETAILED DESCRIPTION

[0024] The following embodiment of the present application takes the characteristic defense system during network transmission as an example to explain the solution of the present application in detail, but this embodiment does not limit the scope of protection of the present application.

[0025] like Figure 1 As shown, the present invention provides a method for characteristic defense during network transmission, comprising:

[0026] Step S1: intercepting the network transmission data flow in the virtual machine migration channel in real time and establishing a bidirectional traffic mirroring pipeline;

[0027] Step S2: Perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain a structured traffic log with complete payload information and metadata tags;

[0028] Step S3: Based on a preset traffic feature set, extract memory paging transfer timing features and disk data block check code distribution features from the structured traffic log to construct a first detection subvector;

[0029] Step S4: extracting the fingerprint features of the encryption handshake protocol version and the traffic rate mutation threshold, and combining them with the first detection sub-vector to obtain a multi-dimensional detection vector;

[0030] Step S5: Input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline;

[0031] Step S6: When the dynamic deviation exceeds the preset standard deviation threshold, an abnormal behavior alarm is triggered and a risk score level is obtained based on the deviation magnitude;

[0032] Step S7: Calling the adaptive security policy engine based on the risk score level to perform a graded response operation. In an embodiment of the present invention, the virtual machine migration traffic is intercepted in real time by the data acquisition module and a bidirectional mirror pipeline is established. After parsing and reorganization, a structured traffic log is generated. Multi-dimensional features such as memory paging timing and disk checksum distribution are extracted from the log to construct a detection vector. The dynamic time warping algorithm is used to match the normal traffic baseline to calculate the dynamic deviation, thereby achieving accurate detection and risk classification of abnormal traffic. Based on the risk level, graded response strategies such as key rotation, path switching, and process interruption are implemented. The baseline model is dynamically optimized through defense effect feedback, and attack fingerprints are extracted to form a cross-node threat intelligence collaboration system. Abnormal behavior in encrypted migration traffic can be efficiently detected without full traffic decryption. The dynamic baseline is adaptive to cloud environment traffic fluctuations, and gradient response is used to reduce service interruptions. Combined with threat intelligence sharing, an active defense network is built to improve the detection accuracy, response flexibility, and clustered defense capabilities of new network attacks during virtual machine migration, thereby enhancing the security and business continuity of the cloud computing platform.

[0033] In a preferred embodiment of the present invention, step S1: intercepting the network transmission data flow in the virtual machine migration channel in real time and establishing a bidirectional traffic mirroring pipeline includes:

[0034] S1.1: Intercept the bidirectional network transmission data flow of the virtual machine migration channel through the virtualized network layer deployed on the source node and the target node;

[0035] S1.2: Perform protocol parsing and reassembly on bidirectional network transmission data streams, stripping redundant control fields, identifying and extracting memory paging data blocks, disk incremental snapshots, and encryption handshake protocol payloads, and establishing a bidirectional traffic mirroring pipeline.

[0036] In a specific embodiment of the present invention, by adopting a bypass monitoring mode at the virtualized network layer of the source node and the target node, only the bidirectional data flow of the virtual machine migration channel is intercepted, thereby significantly improving the pertinence and purity of data capture while avoiding affecting the normal migration business. By stripping redundant fields through deep protocol parsing and reconstruction technology, core migration data such as memory paging data blocks, disk incremental snapshots and encryption handshake protocol payloads are efficiently identified and extracted, effectively solving the problem of low detection efficiency caused by the mixing of migration traffic and irrelevant business traffic in complex network environments, and ensuring the accuracy and real-time performance of subsequent feature extraction and anomaly detection.

[0037] In the specific implementation process of the present invention, the specific process includes:

[0038] Step S1.1: Deploy a traffic capture module in the virtualized network layer (such as vSwitch virtual switch) of the source node (such as host A) and the target node (such as host B) of the virtual machine migration, adopt the bypass monitoring mode (mirror port mode), and replicate the bidirectional network transmission data flow of the virtual machine migration channel (i.e., the traffic from the source node to the target node and the traffic from the target node to the source node) in real time to avoid performance impact on the main path traffic. Based on the five-tuple rule (source IP address, target IP address, source port number, target port number, and transmission protocol type), identify and filter the traffic that is not related to the virtual machine migration (such as user business traffic and management plane traffic), and only retain the data flow related to the migration task (such as VMotion protocol traffic and XenMotion protocol traffic).

[0039] Step S1.2: parse the intercepted original transmission message (such as TCP / UDP message) layer by layer, strip the encapsulation headers of the network layer (IP) and transport layer (TCP / UDP), locate the virtual machine migration protocol layer (such as migration control protocol, memory transmission protocol, disk synchronization protocol), remove the control fields irrelevant to the migration business (such as TCP handshake flag, IP fragment offset and other non-payload data), focus on the payload part, extract the memory status data according to the migration protocol format (such as memory page sequence number, data length), identify the hash chain and differential mark of the disk data block, extract the incremental updated disk data, parse the TLS / SSL handshake message, extract the protocol version, key exchange parameters, certificate information and other encryption-related payloads, and build a dual-channel data stream. Forward pipeline: data from source to target, including memory page transfer, disk synchronization, etc. Reverse pipeline: data from target to source, including confirmation response, error feedback, etc., synchronize the bidirectional data stream through timestamps to ensure timing consistency.

[0040] In a preferred embodiment of the present invention, step S2: performing deep protocol parsing and reassembly on the original transmission message in the mirrored pipeline to obtain a structured traffic log with complete payload information and metadata tags, including:

[0041] S2.1: Based on the predefined VM migration protocol signature library, perform layer-by-layer protocol parsing on the original transmission messages in the image pipeline, stripping off the network layer and transport layer encapsulation headers, and extracting the memory paging transmission protocol payload, disk data block synchronization protocol fields, and encrypted session key exchange messages.

[0042] S2.2: Based on the memory page sequence number tags and the disk data block hash chain, the fragmented data transmitted across messages is reorganized in time sequence, and the complete memory mirror segment and disk incremental snapshot are restored to obtain the reorganized data;

[0043] S2.3: Add transmission direction labels, time window stamps, and session unique identifiers to the reassembled data blocks, and insert protocol compliance tags based on the data block type to generate structured traffic logs with contextual semantics.

[0044] In a specific embodiment of the present invention, the original message is parsed layer by layer through a predefined virtual machine migration protocol feature library, the network layer and transport layer encapsulation are accurately stripped, and the core protocol payloads such as memory paging, disk synchronization and encrypted sessions are efficiently extracted, thereby solving the problem that migration data is difficult to separate under complex network encapsulation; based on the paging sequence number mark and hash chain, the cross-message fragment data is time-sequentially reorganized, and the memory mirror segment and disk incremental snapshot are completely restored to ensure the temporal consistency and business integrity of the traffic data, avoid feature extraction distortion caused by data fragmentation, and generate structured traffic logs with contextual semantics by adding metadata tags such as transmission direction, time window, session identifier and protocol compliance, thereby improving the granularity and accuracy of abnormal traffic detection, and providing structured data support for dynamic baseline model training and threat intelligence extraction, thereby enhancing the system's semantic understanding and in-depth analysis capabilities of the entire virtual machine migration process traffic.

[0045] In the specific implementation process of the present invention, the specific process includes:

[0046] Step S2.1: Call the pre-configured virtual machine migration protocol feature library (containing the hierarchical structure rules, field identifiers and payload formats of protocols such as VMotion and XenMotion), strip the IP header, identify the source / destination IP address and protocol type (such as TCP / UDP), further strip the TCP / UDP header, match the migration protocol by port number (such as the default port of VMotion), filter out the target traffic, locate the migration protocol payload according to the protocol feature library, extract memory paging data (such as paging sequence number, data content), disk synchronization fields (such as data block hash, incremental mark) and encrypted handshake messages (such as TLS version, certificate information), remove irrelevant information such as network layer checksum and transport layer control bits, and retain only the payload related to the migration business.

[0047] Step S2.2: Get the memory paging sequence number (used to mark the order of memory pages in the image) and the disk data block hash chain (recording the order of data block updates) from the parsed payload, sort the memory shards across multiple messages according to the paging sequence number, and splice them into a complete memory image segment (such as a set of continuous memory pages) in order. Based on the dependency relationship of the hash chain (from parent block to child block), integrate the disk shards in chronological order, restore the complete incremental snapshot data, and compare the overall hash value of the reorganized data with the protocol specification to ensure that no shards are lost or the order is wrong.

[0048] Step S2.3: Mark the data flow direction (from source node to target node or vice versa), record the start and end time of data block transmission (accurate to milliseconds), generate a unique ID containing source / target node information and migration task time, associate all data in the same session, check whether the data block meets the format requirements (such as page sequence continuity and hash chain integrity) according to the protocol feature library rules, mark compliance, suspicious or abnormal status, integrate the reorganized data and metadata into log entries with contextual semantics, including data type (memory / disk / encrypted), payload content, tag information, etc., and store them in the log system.

[0049] In a preferred embodiment of the present invention, step S3: based on a preset traffic feature set, extracting memory paging transfer timing features and disk data block check code distribution features from the structured traffic log to construct a first detection subvector includes:

[0050] S3.1: Extract the timestamp sequence of memory paging transfers from the structured traffic log. Use a sliding window to calculate the mean square error of the paging transfer intervals and the burst transfer frequency to obtain a dynamic feature vector of memory paging that represents timing anomalies.

[0051] S3.2: Parse the checksum field of the disk data block and, based on predefined data block size classification rules, calculate the distribution dispersion of the checksum hash values ​​of data blocks of different sizes to construct a disk checksum feature vector that reflects the risk of data tampering.

[0052] S3.3: Normalize the memory paging dynamic feature vector and the disk check feature vector, and concatenate them into a first detection sub-vector according to a preset weight coefficient.

[0053] In a specific embodiment of the present invention, by extracting the timestamp sequence of memory paging transmission from the structured traffic log, using the sliding window to count the mean square error and burst frequency of the transmission interval, the abnormal fluctuation characteristics of the memory paging timing are accurately captured, and the transmission rhythm disorder or malicious fragment injection caused by the attack is effectively identified. By parsing the disk data block check code field and counting the hash value distribution discreteness of data blocks of different sizes, a check feature vector reflecting data integrity is constructed, which can sensitively detect threats such as data block tampering and replay. The two types of feature vectors are normalized and spliced ​​into the first detection sub-vector according to the weight, realizing the feature fusion of memory timing and disk check dimensions, avoiding the one-sidedness of single-dimensional detection, and eliminating the interference of feature dimension differences on the detection results through standardization processing, providing a fine-grained and highly robust basic feature set for the subsequent multi-dimensional detection vector generation, and significantly improving the feature characterization capability and early warning accuracy of new threats such as timing perturbation attacks and data tampering attacks during virtual machine migration.

[0054] In the specific implementation process of the present invention, the specific process includes:

[0055] Step S3.1: Filter out data entries of the memory paging type from the structured traffic log, extract the start time of their time window stamps in the transmission order, form a timestamp sequence (such as t1, t2, t3, ..., tn, corresponding to the transmission start time of each page of memory), set a sliding window of fixed length (such as the window covers the transmission time of the last 100 memory pages), slide one page interval each time, calculate the mean square error of the page transmission interval in each window, and obtain the degree of fluctuation of the transmission interval. The larger the mean square error, the more abnormal the timing. Here, n is the total number of memory page timestamps in the sliding window. The number of pages transmitted continuously in a short period of time is detected in the window. The higher the frequency, the more likely there is an abnormal traffic burst. The mean square error value and the burst frequency value of the current window are used as elements to form a memory paging dynamic feature vector.

[0056] Step S3.2: Extract entries of disk data block type from the structured log, parse their checksum fields (such as SHA-256 hash values) and data block size information, and classify disk data blocks into different categories according to predefined size classification rules (such as small data blocks: <4KB, medium data blocks: 4KB-64KB, large data blocks: >64KB). Count the checksum hash values ​​of the data blocks in each category, and calculate the number of disk data blocks in each category. Calculate the distribution dispersion of hash values, where k is the number of different hash values ​​in the current data block category, and p aThe frequency of occurrence of the a-th hash value in this category, H is the information entropy, a is an index variable, and the higher the discreteness, the greater the difference in the checksums of similar data blocks, which may indicate data tampering or illegal replay (under normal circumstances, the hash values ​​of similar data blocks should be concentrated in a similar range). The discreteness values ​​of each data block category are used as elements to form a disk checksum feature vector.

[0057] Step S3.3: Normalize the memory paging dynamic feature vector and the disk check feature vector separately (such as Min-Max scaling or Z-score standardization), eliminate different feature dimensions (such as time unit and dimensionless entropy value), preset weight coefficients for the two types of features according to business needs (such as 60% weight for memory timing features and 40% weight for disk check features), and splice the two normalized feature vectors into the first detection sub-vector according to the weights.

[0058] In a preferred embodiment of the present invention, step S4: extracting the encryption handshake protocol version fingerprint feature and the traffic rate mutation threshold, and combining them with the first detection subvector to generate a multi-dimensional detection vector, includes:

[0059] S4.1: Extract the protocol version identifier, cipher suite list, and certificate signature features from the encrypted handshake protocol message in the structured traffic log. Use the pre-configured compliance policy library to match the legal protocol fingerprint and generate an encryption protocol version feature vector.

[0060] S4.2: Calculate the network transmission rate based on the sliding time window, calculate the rate change gradient of adjacent windows, and dynamically calculate the traffic rate mutation coefficient based on the bandwidth threshold preset for the migration task.

[0061] S4.3: Standardize and encode the encryption protocol version feature vector and the traffic rate mutation coefficient, assign weight factors based on protocol type, and obtain a second detection subvector reflecting encryption behavior and traffic anomalies.

[0062] S4.4: Align the second detection sub-vector with the first detection sub-vector in time and space, establish an association matrix based on the transmission timestamps of memory paging and disk data blocks, and splice them to obtain a multi-dimensional detection vector containing timing, verification, protocol and traffic characteristics.

[0063] In a specific embodiment of the present invention, by extracting version identifiers, cipher suite lists, and certificate signature features from the encryption handshake protocol and combining them with a pre-set compliance policy library, decryption-free detection of encryption protocol compliance is implemented, effectively identifying threats such as protocol downgrade attacks and illegal certificate use. Based on a sliding time window and rate change gradient calculation, abnormal traffic fluctuations are dynamically captured. The detection threshold is adaptively adjusted based on the characteristics of the migration task to avoid the high false alarm rate of static thresholds. The encryption protocol feature vector and the traffic mutation coefficient are normalized and weighted and fused to form a second detection sub-vector. This is then spatially and temporally aligned with the first detection sub-vector to construct a composite detection vector containing four dimensions: timing, checksum, protocol, and traffic. This achieves full-link anomaly characterization from data content to transmission behavior. A correlation matrix is ​​established between memory paging, disk data blocks, and encrypted traffic using timestamps to capture the spatial and temporal correlation of anomalies in different dimensions, significantly reducing false alarm rates and improving early warning capabilities for advanced persistent threats. The system supports the implementation of a hierarchical response strategy based on a comprehensive assessment of protocol compliance, traffic anomalies, and data integrity, significantly enhancing the security and reliability of the virtual machine migration process.

[0064] In the specific implementation process of the present invention, the specific process includes:

[0065] Step S4.1: Filter encrypted handshake protocol messages (such as TLS ClientHello / ServerHello messages) from structured traffic logs and extract the following features: protocol version identifier (such as TLS1.2 / 1.3), cipher suite list (such as AES-GCM-SHA256), certificate signature features (such as issuing authority, certificate validity period, public key hash), compare the extracted features with the preset compliance policy library (such as the allowed TLS version whitelist, cipher suite priority list), and binary encode each feature (such as compliance is 1, violation is 0) or quantitative score (such as the remaining days of the certificate validity period) and combine them into a vector form.

[0066] Step S4.2: Set a fixed time window (such as 1 second), count the number of network transmission bytes in each window, calculate the transmission rate by the above formula, calculate the rate change gradient of adjacent windows, and calculate the transmission rate by the above formula.

[0067] Combined with the bandwidth threshold preset for the migration task, the mutation coefficient is calculated.

[0068] Step S4.3: Perform Min-Max normalization on the encryption protocol feature vector, scale each dimension to the interval [0, 1], perform logarithmic transformation or Z-score normalization on the traffic rate mutation coefficient to eliminate the dimension effect, assign weights according to the protocol type (for example, sensitive services have a higher weight for TLS versions), and combine the normalized feature vector and the mutation coefficient according to the weight to form the second detection sub-vector. The second sub-vector = [w1×protocol feature 1, w1×protocol feature 2, …, w2×mutation coefficient].

[0069] Step S4.4: Based on the transmission timestamps of memory paging, disk data blocks, and encrypted traffic, a time correlation matrix is ​​established. The first detection sub-vector (memory timing + disk checksum) and the second detection sub-vector (protocol + traffic) are aligned by timestamp and then spliced. Cross-dimensional interaction features (such as the traffic mutation intensity when the protocol is violated) are added to the spliced ​​vector to form the final multi-dimensional detection vector. The second sub-vector = [memory timing features, disk checksum features, protocol features, traffic features, interaction features].

[0070] In a preferred embodiment of the present invention, step S5: inputting the multi-dimensional detection vector into a pre-trained migration traffic baseline model, matching the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculating the dynamic deviation of the current vector from the baseline includes:

[0071] S5.1: Based on the time series characteristics of multi-dimensional detection vectors in the historical normal migration traffic dataset, an unsupervised clustering algorithm is used to obtain a baseline template library representing legitimate traffic patterns. A matching tolerance threshold for Dynamic Time Warping (DTW) is configured for each template.

[0072] S5.2: Based on the matching tolerance threshold, the current multi-dimensional detection vector is divided into subsequence segments according to the time window. Dynamic time warping alignment is performed with the templates of the corresponding protocol type in the baseline template library. The cumulative distance between the sequences is calculated as the initial deviation.

[0073] S5.3: Based on the initial deviation, the initial deviation is normalized and corrected according to the network delay fluctuation rate and data block type weight coefficient of the current migration task to obtain a dynamic deviation indicator adapted to the context environment.

[0074] In a specific embodiment of the present invention, a baseline template is automatically generated through unsupervised clustering based on the multidimensional characteristic time series of historical normal traffic. This method eliminates the need for manually pre-set rules and can adapt to the dynamic characteristics of virtual machine migration traffic in cloud environments. A dynamic time warping algorithm is used to nonlinearly align the current traffic sequence with the baseline template, effectively solving the problem that traditional Euclidean distance cannot handle time axis offsets. The method accurately captures the timing characteristic differences of memory paging and disk data block transmission. The initial deviation is normalized and corrected by combining the current network delay fluctuation rate and data block type weight, eliminating environmental noise interference, making the deviation indicator more suitable for actual migration scenarios and significantly reducing the false alarm rate. The time window and data block identifier corresponding to the dynamic deviation are recorded, providing accurate analysis results with spatiotemporal context for anomaly alarms, supporting rapid tracing of the specific transmission stage and associated data objects of abnormal traffic, and providing a quantitative deviation indicator for subsequent risk scoring and graded response. This enables the system to dynamically adjust defense strategies based on the real-time deviation degree of traffic patterns, building a closed-loop defense system from baseline learning to real-time detection to intelligent response, effectively improving the detection robustness and adaptability of unknown attack variants.

[0075] In the specific implementation process of the present invention, the specific process includes:

[0076] Step S5.1: Collect the multi-dimensional detection vector time series of historical normal migration traffic (such as attack-free migration data for one week). Each sequence contains dimensional features such as timing, verification, protocol, and traffic. Where J is the intra-cluster sum of squares, K is the number of clusters, and C k Represents the set of all sample points belonging to the Kth class in the data set, x z The zth sample point in the data set, μ k is the centroid of the K-th cluster, d(x z ,μ k ) Sample point x z to the centroid μ of the cluster to which it belongs k The distance z is an index. Historical sequences are grouped. Each cluster represents a legitimate traffic pattern (such as memory-first migration pattern and disk-incremental migration pattern). The central sequence of each cluster is averaged or subjected to principal component analysis to generate a corresponding baseline template. The template contains the time series benchmark values ​​of the multidimensional features under this pattern (such as the mean square error of the memory timing at each time point and the mean of the disk check dispersion). A DTW matching tolerance threshold (such as the maximum allowed cumulative distance) is set for each baseline template. This threshold is determined based on the degree of dispersion of the sequence within the cluster.

[0077] Step S5.2: Divide the current multi-dimensional detection vector into overlapping subsequence segments according to the time window (e.g., 500ms) (e.g., each segment contains the feature vectors of 10 time points). According to the encryption protocol type of the current traffic (e.g., TLS1.3), select the baseline template of the corresponding protocol type from the baseline template library, allow the time axis to be locally stretched, and find the optimal matching path between the two sequences (e.g., aligning the delayed traffic features by bending the time points). Calculate the sum of the Euclidean distances of the corresponding feature vectors of the two sequences after alignment, where q h,v The v-th dimension eigenvalue of the h-th element of the subsequence Q, c h,v The v-th dimension eigenvalue of the h-th element of the baseline template C, d is the number of dimensions of the feature vector, v is the dimension index of the feature vector, and h is the subsequence segment corresponding to the current detection, and the cumulative distance value is obtained, that is, the initial deviation.

[0078] Step S5.3: Monitor the network delay of the current migration task in real time (such as measuring the round-trip time (RTT) through ICMP echo requests), calculate the volatility (such as standard deviation) of the last N delay values, and call the preset weight coefficient (such as 0.8 for memory paging and 0.2 for disk blocks) based on the proportion of data block types (memory paging / disk blocks) in the current subsequence. The dynamic deviation is equal to the initial deviation multiplied by the data block type weight divided by the network delay volatility plus a minimum constant. If the network delay is high and fluctuates greatly, the corrected deviation will be reduced accordingly (a certain degree of normal fluctuation is allowed). If the delay is stable but the deviation is high, it is judged as abnormal.

[0079] In a preferred embodiment of the present invention, step S6: when the dynamic deviation exceeds a preset standard deviation threshold, triggering an abnormal behavior alarm and obtaining a risk score based on the deviation magnitude includes:

[0080] S6.1: Receive the dynamic deviation indicator and the associated time window identifier, load the corresponding standard deviation threshold from the preset strategy library based on the migration task type, determine whether the dynamic deviation continuously crosses the threshold, and generate a binary anomaly trigger signal;

[0081] S6.2: Using a binary anomaly trigger signal, the risk level value is calculated through a weighted scoring model based on the duration of the dynamic deviation, the peak amplitude, and the type of the associated data block. Based on the risk level value, the risk is divided into three levels: low, medium, and high.

[0082] In a specific embodiment of the present invention, differentiated standard deviation thresholds are loaded based on the migration task type (e.g., full migration / incremental migration), addressing the problem that fixed thresholds are difficult to adapt to different business scenarios. This enables anomaly detection to capture high-frequency risks such as sudden changes in memory paging timing while avoiding false alarms caused by normal fluctuations in disk data blocks. A continuous threshold crossing determination mechanism (rather than a single over-limit alarm) filters transient noise. The duration and peak amplitude of dynamic deviation are combined to effectively distinguish temporary network jitter from persistent attack behavior. Data block type weights are introduced to make risk scoring more aligned with business logic. For example, at the same deviation, the risk level of memory timing anomalies is higher than that of mildly discrete disk checksums, enabling focused protection of core data objects. Risks are categorized into low, medium, and high levels, providing clear decision-making basis for subsequent handling, avoiding response overload caused by one-size-fits-all alarms, and improving security operation efficiency. By associating time windows with data block identifiers, risk scores are tied to specific transmission stages, forming a complete chain of anomaly detection, risk quantification, and precise response. This significantly improves the system's ability to identify and handle complex threats such as timing attacks and data tampering during virtual machine migration in real time and in a graded manner.

[0083] In the specific implementation process of the present invention, the specific process includes:

[0084] Step S6.1: Receive the timestamp-ed dynamic deviation index and the associated time window identifier (such as memory paging ID or disk block hash) from the migration traffic baseline module. According to the current migration task type (such as memory priority migration, disk incremental synchronization), extract the corresponding standard deviation threshold from the preset policy library (such as the threshold for memory migration task is 1.5σ, and the threshold for disk task is 2.0σ). The threshold is pre-configured based on the statistical characteristics of historical normal traffic (such as the standard deviation multiple of the baseline template). Maintain a sliding window (such as the last 5 time points) to determine whether the dynamic deviation exceeds the threshold continuously: if ≥3 points exceed the threshold continuously, generate a binary anomaly trigger signal 1, otherwise generate 0, and bind the anomaly trigger signal to the time window and data block identifier.

[0085] Step S6.2: Collect the data that triggered the anomaly, including the time window from the first crossing of the threshold to the current time (e.g., 500ms), the maximum deviation during the anomaly (e.g., 2.8σ), such as memory paging (weight 0.8), disk block (weight 0.5), and system configuration file (weight 1.0). According to the weighted scoring model, the risk level value is calculated as follows: w1 × duration divided by the benchmark duration + w2

[0086] The peak amplitude primary benchmark amplitude + w3 × data block type weight is used to obtain the risk level value, where w1, w2, and w3 are weight configurations, which are mapped into three-level labels according to the scoring results. Low risk: score ∈ [0, 0.5), such as short-term mild deviation (lasting < 300ms and amplitude < 1.8σ); medium risk: score ∈ [0.5, 0.8), such as medium duration or amplitude abnormality; high risk: score ≥ 0.8, such as long-term large deviation (lasting > 1000ms and amplitude > 2.5σ) or key data block abnormality.

[0087] In a preferred embodiment of the present invention, step S7: calling the adaptive security policy engine according to the risk score level to perform a graded response operation includes:

[0088] S7.1: Load the corresponding response rule set from the preset policy library based on the risk tag type and generate a security operation instruction queue with execution priority;

[0089] S7.2: Initiate a session key rotation mechanism for low-risk tags, including generating a temporary session key pair and distributing the new key to the source and target nodes, triggering the re-encryption of data blocks corresponding to the abnormal time window in the encryption buffer, and sending a resume instruction to the migration process after the key switch is complete.

[0090] S7.3: Dynamically switch transmission paths for medium-risk tags, including selecting a new transmission path from a pool of backup physical links that meets latency constraints, repackaging unconfirmed data blocks in the encryption buffer according to the routing rules of the new path and triggering retransmission, initiating incremental verification of transmitted data blocks, and discarding abnormal fragments that fail verification.

[0091] S7.4: Trigger migration process interruption and integrity verification for high-risk tags, including: sending a migration termination instruction to the source node and freezing the memory image write operation of the target node; extracting suspicious memory pages based on the abnormal fragment index table; calculating their hash values ​​and comparing them with the original image of the source node; if the hash values ​​are inconsistent, restoring the target node memory state from the trusted snapshot in the encrypted buffer.

[0092] In a specific embodiment of the present invention, a session key rotation mechanism rapidly refreshes encryption keys without interrupting the migration process, effectively countering low-intensity attacks based on key guessing or traffic analysis. It also re-encrypts abnormal data blocks, achieving dynamic security reinforcement through migration and repair. Dynamic transmission path switching is implemented using a backup physical link pool. Combined with data block retransmission and incremental verification, this not only mitigates attack threats on the current path but also ensures data transmission integrity by discarding abnormal fragments. This significantly improves the system's resilience to medium-risk attacks, such as man-in-the-middle attacks and traffic hijacking. Immediately interrupting the migration process and freezing write operations on the target node prevents the spread of attacks. Combined with memory image hash comparison and trusted snapshot recovery, this allows for precise tracing and rapid rollback of malicious tampering or injection attacks, minimizing data loss. Dynamically loading response rule sets based on risk tags forms an automated closed-loop detection-scoring-response system, avoiding manual intervention delays. Instruction queue priority management ensures the immediacy of high-risk responses. This establishes a multi-layered defense-in-depth system, spanning the key, network, and data layers, significantly enhancing the system's survivability and self-healing capabilities in complex attack environments.

[0093] In the specific implementation process of the present invention, the specific process includes:

[0094] Step S7.1: Receive the risk label (low / medium / high) and associated metadata (such as time window, data block type) output by the risk scoring module, filter the corresponding rule set from the preset policy library according to the label type, parse the operation instructions in the rule set (such as KEY_ROTATION, PATH_SWITCH), extract the execution parameters (such as the backup path delay threshold), sort the instructions according to the preset priority (for example, in high-risk scenarios, TERMINATE_MIGRATION has a higher priority than HASH_VERIFICATION), and generate an instruction queue with timestamp and priority.

[0095] Step S7.2: Call the key management module to generate a temporary session key pair, distribute the new key to the source node and the target node through a secure channel (such as TLS1.3), with a timestamp and key ID, locate the data block corresponding to the abnormal time window in the encryption buffer, use the new key to perform in-place re-encryption on the above data block, update the encryption metadata (such as IV value, authentication tag), verify that the key switch is completed (through two-way ACK confirmation), and send a resume instruction to the migration process, carrying the offset information of the re-encrypted data block.

[0096] Step S7.3: Query the backup physical link pool, screen candidate paths that meet the latency constraints (such as RTT ≤ 50ms) and have sufficient bandwidth (such as ≥ 1Gbps), establish a new path through the SDN controller, allocate virtual private channels (such as VLAN ID, MPLS label), extract unacknowledged data blocks in the encryption buffer (such as through TCP sequence numbers or the ACK mechanism of a custom migration protocol), re-encapsulate the data according to the routing rules of the new path (such as adding the MAC header and IP header of the new path), trigger retransmission, perform incremental verification on the transmitted data blocks (such as calculating the rolling hash value of the data in the sliding window), compare the verification results, discard abnormal fragments with inconsistent hashes, and request retransmission through the NACK mechanism.

[0097] Step S7.4: Send a termination command to the source node to stop generating new data blocks; send a memory write freeze command to the target node to suspend mirror updates, and extract the corresponding memory pages from the source node and target node respectively according to the abnormal fragment index table (such as the suspicious memory page ID Page_1234). SHA-256 (D) = FinalHash(s0, s1, ..., s7), calculate the hash value of the extracted memory page, where D is the binary data of the memory page, and FinalHash represents the final hash value after padding, grouping, and iterative compression. Compare the hash results of the source and target ends. If the hashes are inconsistent, restore the target node state from the most recent trusted snapshot in the encryption buffer (such as a complete memory image from 5 seconds ago). Verify the integrity of the restored memory. If it passes, restart the migration process and continue the transmission from the trusted point.

[0098] In a preferred embodiment of the present invention, step S8: after calling the adaptive security policy engine according to the risk score level and performing the graded response operation, further includes:

[0099] S8.1: Monitor the execution status of hierarchical response operations in real time, collect key rotation response latency, path switching success rate, and memory image recovery consistency indicators, and generate a multi-dimensional defense effectiveness data set;

[0100] S8.2: Based on the correlation between the rate of change of traffic characteristics in the defense effectiveness dataset and the detection accuracy of the baseline model, dynamically adjust the dynamic time warping (DTW) path constraints and cluster center weight coefficients of the baseline template library;

[0101] S8.3: Using path constraints and cluster center weight coefficients, extract protocol field tampering patterns, fragment sequence number jump characteristics, and encryption payload entropy anomaly indicators from abnormal data blocks marked as high-risk, and build a cross-session attack behavior fingerprint feature library;

[0102] S8.4: Correlate and analyze attack behavior fingerprints with associated abnormal time windows and source and target node identifiers to generate standardized threat intelligence messages.

[0103] S8.5: Push threat intelligence messages to all physical nodes and management platforms involved in the migration task through the distributed message bus of the cloud computing platform, and receive collaborative defense feedback data from external nodes to update the local policy library.

[0104] In a specific embodiment of the present invention, based on the correlation analysis between the traffic feature change rate and the detection accuracy after the implementation of defense measures, the DTW path constraints and cluster center weights are adjusted in real time, so that the baseline model can automatically adapt to changes in the network environment, continuously optimize the characterization capability of normal traffic patterns, avoid the degradation of detection accuracy caused by static baselines, extract fine-grained attack features such as protocol field tampering, fragment sequence number jump, and encryption load entropy value anomaly from high-risk abnormal data, build a cross-session attack behavior fingerprint library, realize pattern recognition of unknown attack variants, improve the prediction capability of new timing attacks and data tampering, and connect attack fingerprints with abnormal time windows. , node identification association generates standardized intelligence, which is pushed to all nodes in the multi-cloud environment through the distributed message bus to achieve three-dimensional defense of detection-response-collaboration. It not only supports real-time updates of the local policy library, but also triggers cross-node linkage defense, significantly enhancing the collaborative combat capability of the cloud computing platform in the face of distributed attacks. Through the feedback closed-loop mechanism, the baseline model and security policy are upgraded synchronously with the evolution of attack methods, forming a self-adaptive cycle of detection-response-learning-optimization, effectively responding to dynamically changing security threats in the cloud environment, and ultimately achieving a systematic improvement in detection robustness, attack tracing accuracy and collaborative defense efficiency during virtual machine migration.

[0105] In the specific implementation process of the present invention, the specific process includes:

[0106] Step S8.1: Deploy probes to collect execution indicators of graded response operations: the time difference from the trigger instruction to the completion of the key update of the source / target node (accurate to milliseconds), the ratio of the number of successful establishment of alternative paths to the total number of attempts, the hash matching rate of the memory pages after recovery (such as 99.9% means only 0.1% of the pages are inconsistent), and synchronously collect the change rate of traffic characteristics: such as the standard deviation change rate of the memory paging transfer interval, such as the distribution entropy change of the disk block CRC32 check value, such as the volatility of the TLS handshake packet length, to obtain a multidimensional data set.

[0107] Step S8.2: Dynamic Adjustment of Baseline Model Parameters Defense Effectiveness Data Collection Collect traffic data after defense measures are executed, including: traffic feature change rate: such as the fluctuation rate of memory paging transfer intervals, the change in disk check entropy value, the baseline model's classification accuracy for known normal / abnormal traffic, and the correlation between the traffic feature change rate and detection accuracy: If the change rate of a feature is negatively correlated with the accuracy (such as the accuracy decreases when the protocol version feature change rate increases), it is determined that the corresponding baseline parameters need to be adjusted. The DTW constraints are dynamically modified based on the analysis results: If the normal traffic timing fluctuation increases (such as increased network latency), the time axis scaling window is relaxed. If the abnormal traffic false detection rate increases, the continuity constraint is tightened (such as prohibiting the continuous skipping of more than two time points). Cluster center weight adjustment For the cluster centers of the baseline template library, weights are dynamically assigned according to feature importance: If the change rate of the memory timing feature has the greatest impact on the accuracy, increase the weight of this dimension in the cluster center calculation (such as from 0.3 to 0.5). The weight coefficient is iteratively optimized through the above step S5.1 to minimize the sum of squares within the cluster.

[0108] Step S8.3: Obtain abnormal data blocks marked as high risk from the risk scoring module. The screening criteria include: dynamic deviation ≥ 3σ, risk level "high" and duration ≥ 1 second. Parse the encrypted handshake protocol message (such as the TLS record layer), extract the protocol fields, compare the actual protocol version with the legal version in the baseline template (for example, to detect whether there is a TLS 1.0 downgrade attack), check whether the cipher suite list contains weak encryption algorithms (such as MD5-SHA1), and calculate the sequence number difference of consecutive fragments in the migration protocol data. If the sequence number difference is greater than 1 and there is no retransmission mark, it is determined to be a fragment jump (possibly due to packet drop or reordering due to an attack). The jump amplitude and frequency are recorded. The information entropy of the encrypted data block is calculated according to the above step S3.2. If the entropy value deviates significantly from the baseline (such as above the normal mean + 2σ), it is determined to be a payload anomaly (possibly containing randomized tampered data). The above features are aggregated according to the attack type (such as protocol downgrade attack, fragment reordering attack) to form a cross-session fingerprint template.

[0109] Step S8.4: Feature-metadata association, bind the attack fingerprint feature with the following metadata: abnormal time window, source / destination node identification and defense measure record, and generate a message that complies with the STIX (Structured Threat Information Expression) standard.

[0110] Step S8.5: Push threat intelligence messages in a publish-subscribe mode through the distributed message bus of the cloud computing platform (such as Apache Kafka) to: all physical nodes participating in the migration (such as host machines, storage nodes), cloud computing management platforms (such as OpenStack Neutron, VMware vCenter), receive feedback data from external nodes (such as other data centers detecting the same attack fingerprint), update the local policy library, add new DTW path constraint rules (such as for shard hopping attacks, reduce the maximum allowed jump value from 2 to 1), update the cluster center feature weights (such as increasing the detection weight of the encryption payload entropy value to 0.4), re-cluster the historical abnormal data, generate a new baseline template, and adjust the weighting parameters of the risk scoring module.

[0111] like Figure 2 As shown, an embodiment of the present invention further provides a feature defense system during network transmission, comprising:

[0112] Traffic capture module, used to intercept network transmission data streams in virtual machine migration channels in real time and establish a bidirectional traffic mirroring pipeline;

[0113] The reassembly module is used to perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain structured traffic logs with complete payload information and metadata tags;

[0114] A construction module is used to extract memory paging transfer timing characteristics and disk data block checksum distribution characteristics from structured traffic logs based on a preset traffic feature set to construct a first detection sub-vector; extract the encryption handshake protocol version fingerprint characteristics and traffic rate mutation threshold, and combine them with the first detection sub-vector to obtain a multi-dimensional detection vector;

[0115] The calculation module is used to input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline;

[0116] The evaluation module is used to trigger abnormal behavior alarms when the dynamic deviation exceeds the preset standard deviation threshold and obtain a risk score level based on the deviation amplitude; the adaptive security policy engine is called according to the risk score level to execute graded response operations.

[0117] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for defending against characteristics during network transmission, characterized in that: include: Step S1: intercepting the network transmission data flow in the virtual machine migration channel in real time and establishing a bidirectional traffic mirroring pipeline; Step S2: Perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain a structured traffic log with complete payload information and metadata tags; Step S3: Based on a preset traffic feature set, extract memory paging transfer timing features and disk data block check code distribution features from the structured traffic log to construct a first detection subvector; Step S4: extracting the fingerprint features of the encryption handshake protocol version and the traffic rate mutation threshold, and combining them with the first detection sub-vector to obtain a multi-dimensional detection vector; Step S5: Input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline; Step S6: When the dynamic deviation exceeds the preset standard deviation threshold, an abnormal behavior alarm is triggered and a risk score level is obtained based on the deviation magnitude; Step S7: Call the adaptive security policy engine according to the risk score level and perform graded response operations.

2. The method for defending against characteristics during network transmission according to claim 1, characterized in that: Intercept network transmission data streams in the virtual machine migration channel in real time and establish a bidirectional traffic mirroring pipeline, including: S1.1: Intercept the bidirectional network transmission data flow of the virtual machine migration channel through the virtualized network layer deployed on the source node and the target node; S1.2: Perform protocol parsing and reassembly on bidirectional network transmission data streams, stripping redundant control fields, identifying and extracting memory paging data blocks, disk incremental snapshots, and encryption handshake protocol payloads, and establishing a bidirectional traffic mirroring pipeline.

3. The method for defending against characteristics during network transmission according to claim 2, characterized in that: Perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain structured traffic logs with complete payload information and metadata tags, including: S2.1: Based on the predefined VM migration protocol signature library, the original transmission messages in the image pipeline are parsed layer by layer, stripping the network layer and transport layer encapsulation headers to extract the memory paging protocol payload, disk data block synchronization protocol fields, and encrypted session key exchange messages. S2.2: Based on the memory page sequence number tags and the disk data block hash chain, the fragmented data transmitted across messages is reorganized in time sequence, and the complete memory mirror segment and disk incremental snapshot are restored to obtain the reorganized data; S2.3: Add transmission direction labels, time window stamps, and session unique identifiers to the reassembled data blocks, and insert protocol compliance tags based on the data block type to generate structured traffic logs with contextual semantics.

4. The method for defending against characteristics during network transmission according to claim 3, characterized in that: Based on the preset traffic feature set, the memory paging transfer timing features and disk data block checksum distribution features are extracted from the structured traffic log to construct the first detection sub-vector, including: S3.1: Extract the timestamp sequence of memory paging transfers from the structured traffic log. Use a sliding window to calculate the mean square error of the paging transfer intervals and the burst transfer frequency to obtain a dynamic feature vector of memory paging that represents timing anomalies. S3.2: Parse the checksum field of the disk data block and, based on predefined data block size classification rules, calculate the distribution dispersion of the checksum hash values ​​of data blocks of different sizes to construct a disk checksum feature vector that reflects the risk of data tampering. S3.3: Normalize the memory paging dynamic feature vector and the disk check feature vector, and concatenate them into a first detection sub-vector according to a preset weight coefficient.

5. The method for defending against characteristics during network transmission according to claim 4, characterized in that: Extract the encryption handshake protocol version fingerprint features and traffic rate mutation threshold, and combine them with the first detection sub-vector to generate a multi-dimensional detection vector, including: S4.1: Extract the protocol version identifier, cipher suite list, and certificate signature features from the encrypted handshake protocol message in the structured traffic log. Match the legal protocol fingerprint with the pre-set compliance policy library to obtain the encryption protocol version feature vector. S4.2: Calculate the network transmission rate based on the sliding time window, calculate the rate change gradient of adjacent windows, and dynamically calculate the traffic rate mutation coefficient based on the bandwidth threshold preset for the migration task. S4.3: Standardize and encode the encryption protocol version feature vector and the traffic rate mutation coefficient, assign weight factors based on protocol type, and obtain a second detection subvector reflecting encryption behavior and traffic anomalies. S4.4: Align the second detection sub-vector with the first detection sub-vector in time and space, establish an association matrix based on the transmission timestamps of memory paging and disk data blocks, and splice them to obtain a multi-dimensional detection vector containing timing, verification, protocol and traffic characteristics.

6. The method for defending against characteristics during network transmission according to claim 5, characterized in that: The multi-dimensional detection vector is input into the pre-trained migration traffic baseline model. The dynamic time warping algorithm is used to match the time series characteristics of the normal traffic pattern and calculate the dynamic deviation of the current vector from the baseline, including: S5.1: Based on the time series characteristics of multi-dimensional detection vectors in the historical normal migration traffic dataset, an unsupervised clustering algorithm is used to generate a baseline template library representing legitimate traffic patterns. A matching tolerance threshold for Dynamic Time Warping (DTW) is configured for each template. S5.2: Based on the matching tolerance threshold, the current multi-dimensional detection vector is divided into subsequence segments according to the time window. Dynamic time warping alignment is performed with the templates of the corresponding protocol type in the baseline template library. The cumulative distance between the sequences is calculated as the initial deviation. S5.3: Based on the initial deviation, the initial deviation is normalized and corrected according to the network delay fluctuation rate of the current migration task and the data block type weight coefficient to obtain a dynamic deviation adapted to the context environment.

7. The method for defending against characteristics during network transmission according to claim 6, characterized in that: When the dynamic deviation exceeds the preset standard deviation threshold, an abnormal behavior alarm is triggered and a risk score is generated based on the deviation magnitude, including: S6.1: Receive the dynamic deviation indicator and the associated time window identifier, load the corresponding standard deviation threshold from the preset strategy library based on the migration task type, determine whether the dynamic deviation continuously crosses the threshold, and generate a binary anomaly trigger signal; S6.2: Using a binary anomaly trigger signal, the risk level value is calculated through a weighted scoring model based on the duration of the dynamic deviation, the peak amplitude, and the type of the associated data block. Based on the risk level value, the risk is divided into three levels: low, medium, and high.

8. The method for defending against characteristics during network transmission according to claim 7, characterized in that: The adaptive security policy engine is invoked based on the risk score to perform graded response actions, including: S7.1: Load the corresponding response rule set from the preset policy library based on the risk tag type and generate a security operation instruction queue with execution priority; S7.2: Initiate a session key rotation mechanism for low-risk tags, including generating a temporary session key pair and distributing the new key to the source and target nodes, triggering the re-encryption of data blocks corresponding to the abnormal time window in the encryption buffer, and sending a resume instruction to the migration process after the key switch is complete. S7.3: Dynamically switch transmission paths for medium-risk tags, including selecting a new transmission path from a pool of backup physical links that meets latency constraints, repackaging unconfirmed data blocks in the encryption buffer according to the routing rules of the new path and triggering retransmission, initiating incremental verification of transmitted data blocks, and discarding abnormal fragments that fail verification. S7.4: Trigger migration process interruption and integrity verification for high-risk tags, including: sending a migration termination instruction to the source node and freezing the memory image write operation of the target node; extracting suspicious memory pages based on the abnormal fragment index table; calculating their hash values ​​and comparing them with the original image of the source node; if the hash values ​​are inconsistent, restoring the target node memory state from the trusted snapshot in the encrypted buffer.

9. The method for defending against characteristics during network transmission according to claim 8, characterized in that: After invoking the adaptive security policy engine based on the risk score and executing the graded response actions, it also includes: S8.1: Monitor the execution status of hierarchical response operations in real time, collect key rotation response latency, path switching success rate, and memory image recovery consistency indicators, and generate a multi-dimensional defense effectiveness data set; S8.2: Based on the correlation between the rate of change of traffic characteristics in the defense effectiveness dataset and the detection accuracy of the baseline model, dynamically adjust the dynamic time warping (DTW) path constraints and cluster center weight coefficients of the baseline template library; S8.3: Using path constraints and cluster center weight coefficients, extract protocol field tampering patterns, fragment sequence number jump characteristics, and encryption payload entropy anomaly indicators from abnormal data blocks marked as high-risk, and build a cross-session attack behavior fingerprint feature library; S8.4: Correlate and analyze attack behavior fingerprints with associated abnormal time windows and source and target node identifiers to generate standardized threat intelligence messages. S8.5: Push threat intelligence messages to all physical nodes and management platforms involved in the migration task through the distributed message bus of the cloud computing platform, and receive collaborative defense feedback data from external nodes to update the local policy library.

10. A characteristic defense system during network transmission, characterized in that: The system is used to perform the method according to any one of claims 1 to 9, and the system comprises: Traffic capture module, used to intercept network transmission data streams in virtual machine migration channels in real time and establish a bidirectional traffic mirroring pipeline; The reassembly module is used to perform deep protocol parsing and reassembly on the original transmission messages in the mirror pipeline to obtain structured traffic logs with complete payload information and metadata tags; A construction module is used to extract memory paging transfer timing characteristics and disk data block checksum distribution characteristics from structured traffic logs based on a preset traffic feature set to construct a first detection sub-vector; extract the encryption handshake protocol version fingerprint characteristics and traffic rate mutation threshold, and combine them with the first detection sub-vector to obtain a multi-dimensional detection vector; The calculation module is used to input the multi-dimensional detection vector into the pre-trained migration traffic baseline model, match the time series characteristics of the normal traffic pattern through the dynamic time warping algorithm, and calculate the dynamic deviation of the current vector from the baseline; The evaluation module is used to trigger abnormal behavior alarms when the dynamic deviation exceeds the preset standard deviation threshold and obtain a risk score level based on the deviation amplitude; the adaptive security policy engine is called according to the risk score level to perform graded response operations.

Citation Information

Cited By

  • Highway toll collection system data processing method and system based on cloud architecture

    CN121239507A

  • Data Processing Method and System for Highway Toll Collection System Based on Cloud Architecture

    CN121239507B

  • TCP retransmission positioning method based on ICMP and TCP association analysis

    CN121603579A

  • Network traffic identification method and device based on DPI, and medium

    CN122053416A

  • A DPI-based network traffic identification method, device, and medium

    CN122053416B