Business internet platform big data security protection system

By optimizing the communication protocol through multi-source data acquisition and behavior prediction models, and adjusting the timing trigger nodes of the protocol sequence in conjunction with real-time threat status, the problem of lagging security protection in industrial internet platforms has been solved, achieving dynamic adaptive security protection and improving the security and stability of data transmission.

CN121000484APending Publication Date: 2025-11-21SHENZHEN DECIMETER DIGITAL TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511281606.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing industrial internet platforms' security protection systems are ill-equipped to cope with dynamically changing network threats. They lack multi-source data collection and attack behavior prediction mechanisms, their communication protocol optimizations are out of touch with actual needs, and their security verification mechanisms cannot respond to changes in the threat landscape in a timely manner, resulting in lagging security protection and vulnerabilities.

Method used

A multi-source security data acquisition module is adopted, and an attack behavior prediction map is generated using a behavior prediction model. The boundary for adjusting security communication protocol parameters is defined, and the communication protocol is optimized in combination with business traffic shaping requirements and real-time threat status. The timing triggering node of the protocol sequence is corrected through security protocol adjustment commands to achieve dynamic adaptive protection.

Benefits of technology

It achieves comprehensive, proactive, and real-time security protection for data transmission on industrial internet platforms, improves the pertinence and foresight of security protection, ensures that the protocol adapts to the security needs of different business scenarios, and reduces security vulnerabilities and data transmission stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000484A_ABST
    Figure CN121000484A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial internet security, and discloses an industrial internet platform big data security protection system. A security data acquisition module of the system acquires multi-source security data such as network flow characteristic parameters and equipment behavior log parameters; the attack behavior prediction module generates an attack behavior prediction map by using a behavior prediction model according to the multi-source security data, defines a security communication protocol parameter adjustment boundary range and generates a security protocol adjustment instruction; the communication protocol optimization module generates an optimized security communication protocol sequence by adopting a protocol encapsulation technology in combination with a service traffic shaping demand and a real-time threat state; the traffic shaping module determines a protocol field adjustment direction and proportion according to the security protocol adjustment instruction, and adjusts a protocol sequence; and the security verification module corrects a protocol sequence time sequence trigger node to realize synchronous self-adaptive protection of data transmission security and threat dynamic change.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial internet security, and particularly to an industrial internet platform big data security protection system. BACKGROUND

[0002] With the rapid development of industrial internet technology, the data flow generated in the industrial production process presents the characteristics of massiveness, multi-source and heterogeneity. These data face increasingly complex security threats in the process of transmission, storage and processing. At present, the industrial internet platform generally adopts traditional security protection means. Such means often focus on passive defense of known attack behaviors, and are difficult to cope with the dynamically changing network threat environment.

[0003] In the data acquisition link, the traditional method usually only collects a single type of security data, and cannot comprehensively obtain multi-source security data such as network traffic feature parameters and device behavior log parameters, resulting in that the subsequent threat analysis lacks complete data support and it is difficult to accurately identify potential security risks. At the same time, the existing technology lacks an effective attack behavior prediction mechanism, and mostly relies on artificial experience to judge security events, which not only has slow response speed, but also cannot predict attack trends in advance, so that the security protection is always in a lagging state.

[0004] In terms of communication protocol optimization, the current technical solution rarely considers the combination of business traffic shaping requirements and real-time threat state. The protocol optimization process is often detached from the actual network operation scene, and the optimized communication protocol is difficult to adapt to the security needs in different business scenarios, which may either affect the data transmission efficiency due to the complexity of the protocol, or may lead to security vulnerabilities due to insufficient protection. In addition, in the traffic shaping process, the existing technology cannot determine the adjustment direction and proportion of the protocol field according to specific security protocol adjustment instructions, and cannot realize accurate adjustment of the protocol sequence, thereby affecting the security and stability of data transmission.

[0005] In the security verification link, the traditional method usually only verifies the integrity or legality of data transmission in a single dimension, ignores the synchronous adaptation of time sequence trigger nodes and threat dynamic changes, and causes the verification mechanism to be unable to respond to changes in threat situation in time. Even if security problems are found, it is also difficult to quickly adjust the protection strategy, and a closed-loop security protection system cannot be formed, so that the data transmission security of the industrial internet platform cannot be effectively guaranteed. SUMMARY

[0006] The present application relates to the technical field of industrial internet security, and particularly to an industrial internet platform big data security protection system.

[0007] To achieve the above-mentioned purpose, the present application provides an industrial internet platform big data security protection system, which comprises:

[0008] a security data collection module configured to collect multi-source security data of an industrial internet platform, wherein the multi-source security data comprises network traffic characteristic parameters and device behavior log parameters;

[0009] an attack behavior prediction module configured to generate an attack behavior prediction graph and define an adjustment boundary range of a security communication protocol parameter based on the multi-source security data by using a behavior prediction model, so as to generate a security protocol adjustment instruction matching the multi-source security data;

[0010] a communication protocol optimization module configured to generate an optimized security communication protocol sequence by using a protocol encapsulation technology based on a traffic shaping requirement and a real-time threat state;

[0011] a traffic shaping module configured to determine an adjustment direction and an adjustment proportion of a protocol field based on the security protocol adjustment instruction, so as to adjust the optimized security communication protocol sequence and obtain a protocol sequence with adjusted field structure;

[0012] a security verification module configured to correct a timing trigger node of the protocol sequence with adjusted field structure by using the security protocol adjustment instruction, so as to realize synchronous adaptive protection of data transmission security and threat dynamic change of the industrial internet platform.

[0013] Preferably, the attack behavior prediction module comprises:

[0014] a security behavior evolution graph is constructed by using a behavior prediction model based on the network traffic characteristic parameters and the device behavior log parameters;

[0015] an attack behavior intensity threshold interval is calculated based on the security behavior evolution graph in a prediction window of the behavior prediction model;

[0016] an adjustment boundary range of a security communication protocol parameter is defined based on the attack behavior intensity threshold interval, and the adjustment boundary range comprises a protocol encryption intensity upper limit, a protocol response delay lower limit and a field step constraint;

[0017] a candidate protocol adjustment parameter set is generated by optimizing the behavior prediction model;

[0018] the candidate protocol adjustment parameter set is continuously verified to generate a target protocol adjustment parameter combination meeting a protocol mutation amplitude limit;

[0019] a target protocol adjustment parameter with the smallest timing interval is extracted from the target protocol adjustment parameter combination to generate the security protocol adjustment instruction.

[0020] Preferably, the attack behavior prediction module further comprises:

[0021] The attack behavior intensity threshold sub-interval is divided according to the numerical range of the threat evolution rate;

[0022] Based on the upper limit of the protocol encryption strength and the lower limit of the protocol response delay, an initial protocol adjustment parameter set of each sub-interval is generated;

[0023] The initial protocol adjustment parameter set is subjected to parameter expansion and discrete segmentation processing;

[0024] In the prediction window of the behavior prediction model, target protocol adjustment parameters are screened according to the correlation between the threat evolution rate and the attack behavior intensity threshold interval, and the candidate protocol adjustment parameter set is generated.

[0025] Preferably, the communication protocol optimization module comprises:

[0026] According to the traffic shaping requirement, a protocol encapsulation reference parameter is set, and the reference parameter comprises an initial protocol field length and an initial protocol interval period;

[0027] Based on the initial protocol field length and the initial protocol interval period, an initial protocol encapsulation sequence is generated;

[0028] According to the real-time threat state, a field length adjustment amount of each protocol unit in the initial protocol encapsulation sequence is calculated;

[0029] The field length adjustment amount and the initial protocol field length are superimposed to generate a transition protocol sequence;

[0030] The protocol interval period of the transition protocol sequence is subjected to smoothing processing to generate the optimized secure communication protocol sequence.

[0031] Preferably, the security verification module comprises:

[0032] According to the protocol parameter variation amount of the security protocol adjustment instruction, a protocol offset degree is determined;

[0033] Based on the protocol offset degree, the timing consistency of the protocol sequence after the adjustment field structure is verified;

[0034] If the interval between the timing trigger nodes of adjacent protocol units is less than a minimum fault tolerance threshold, the timing trigger nodes are subjected to translation calibration;

[0035] The security communication protocol sequence after timing synchronization calibration is output.

[0036] Preferably, when the attack behavior prediction module generates the security behavior evolution map:

[0037] The threat intensity features and the time distribution features in the historical attack behavior data are extracted;

[0038] According to the threat intensity feature, a multi-dimensional attack correlation matrix is constructed;

[0039] A boundary parameter of an attack behavior intensity threshold interval is calculated through the multi-dimensional attack correlation matrix;

[0040] The boundary parameter is input into the security behavior evolution graph.

[0041] Preferably, the communication protocol optimization module processes the discretization segmentation when:

[0042] According to the field step constraint, the extended protocol parameter set is segmented into discretization protocol parameter segments;

[0043] Based on the real-time change amount of the threat evolution rate, a corresponding discretization protocol parameter segment is matched;

[0044] The matched discretization protocol parameter segment is mapped to the candidate protocol adjustment parameter set.

[0045] Preferably, the traffic shaping module includes:

[0046] The absolute value of the numerical change amount of the security protocol adjustment instruction is taken as a protocol field adjustment ratio;

[0047] According to the protocol field adjustment direction, a protocol field length correction rule is established;

[0048] According to the correction rule, the field length of the optimized security communication protocol sequence is adjusted;

[0049] The protocol units with a field length mutation amplitude exceeding a fault tolerance threshold are smoothly reorganized to generate the protocol sequence after the field structure is adjusted.

[0050] Preferably, when the security verification module corrects the timing trigger node, it:

[0051] The rising edge node and the falling edge node of the protocol parameter fluctuation in the security protocol adjustment instruction are identified;

[0052] The timing offset of each protocol unit in the protocol sequence after the field structure is adjusted is calculated;

[0053] The timing offset and the initial trigger node are superimposed to generate a calibrated protocol unit;

[0054] The timing interval of the calibrated protocol unit is subjected to boundary constraint processing.

[0055] Preferably, the security verification module further includes:

[0056] According to the protocol parameter fluctuation amplitude, a timing offset coefficient is defined;

[0057] An initial timing offset is calculated according to the timing offset coefficient, the initial trigger node and the timing distance of the rising edge node / descending edge node.

[0058] The initial timing offset is subjected to threshold truncation to obtain a final timing offset.

[0059] Compared with the prior art, the present application has the following advantages:

[0060] The industrial internet platform big data security protection system effectively solves many problems existing in the current industrial internet security protection field through the synergistic effect of each module. In the data acquisition layer, the security data acquisition module can comprehensively acquire multi-source security data of the industrial internet platform, covering network flow characteristic parameters and device behavior log parameters, breaking the single limitation of traditional data acquisition methods, providing complete and comprehensive data basis for subsequent attack behavior prediction and security protection, enabling security analysis to be based on richer information, and thus more accurately capturing potential security risks.

[0061] The attack behavior prediction module generates an attack behavior prediction graph based on multi-source security data using a behavior prediction model, defines the adjustment boundary range of the security communication protocol parameter and generates a matching security protocol adjustment instruction, changing the passive situation of traditional technologies relying on artificial experience to judge security events. By generating an attack behavior prediction graph in advance, the attack trend can be actively predicted, enabling security protection to shift from passive response to active prevention, and the generation of the security protocol adjustment instruction also provides a clear direction for subsequent communication protocol optimization and traffic shaping, ensuring that subsequent operations can closely revolve around the actual threat situation, improving the pertinence and foresight of security protection.

[0062] The communication protocol optimization module generates an optimized security communication protocol sequence using protocol encapsulation technology in combination with business traffic shaping requirements and real-time threat states, avoiding the problem of traditional protocol optimization processes being divorced from actual application scenarios. When optimizing the protocol, the module fully considers the actual requirements of business traffic and the threat state in the current network, so that the optimized protocol sequence can meet the data transmission efficiency requirements in different business scenarios and also has the security protection capability to cope with real-time threats, achieving a balance between protocol efficiency and security, enabling the communication protocol to dynamically adapt to changes in the network operating environment.

[0063] The traffic shaping module determines the adjustment direction and adjustment ratio of the protocol field according to the security protocol adjustment instruction, accurately adjusts the optimized security communication protocol sequence, and obtains the protocol sequence after the adjustment of the field structure. This accurate adjustment method overcomes the defect that the adjustment details of the protocol field cannot be accurately controlled in the traditional traffic shaping process, ensures that the adjusted protocol sequence can strictly meet the security protection requirements, further enhances the security of the protocol, reduces the security vulnerabilities caused by unreasonable protocol field design, and protects the stability and security of data in the transmission process.

[0064] The security verification module corrects the timing trigger node of the protocol sequence after the adjustment of the field structure by using the security protocol adjustment instruction, realizes the synchronous adaptive protection of the security of the industrial internet platform data transmission and the dynamic change of threats. This module changes the limitation of single dimension in traditional security verification, corrects the timing trigger node, so that the verification mechanism can keep synchronization with the dynamic change of threats. When the threat situation changes, the timing trigger node can be adjusted in time to ensure that the verification behavior always adapts to the current security environment, forming a dynamic security verification system. This synchronous adaptive protection mode enables the entire security protection system to respond to threat changes in real time, timely adjust the protection strategy, form a complete security protection closed loop, and comprehensively improve the security protection level of the industrial internet platform data transmission, and adapt to the complex and changeable network security environment. BRIEF DESCRIPTION OF DRAWINGS

[0065] Figure 1 The timing diagram of the industrial internet platform big data security protection system described in the present application;

[0066] Figure 2 The working principle flowchart of the attack behavior prediction module;

[0067] Figure 3 The working principle flowchart of the attack behavior prediction module;

[0068] Figure 4 The working principle flowchart of the communication protocol optimization module. DETAILED DESCRIPTION

[0069] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0070] Please refer to Figure 1The application provides an industrial internet platform big data security protection system, which comprises a security data acquisition module, an attack behavior prediction module, a communication protocol optimization module, a traffic shaping module and a security verification module.

[0071] The security data acquisition module acquires multi-source security data from the industrial internet platform, including network traffic characteristic parameters and device behavior log parameters. The attack behavior prediction module generates an attack behavior prediction graph based on the multi-source security data by using a behavior prediction model, and defines an adjustment boundary range of a security communication protocol parameter, and then generates a security protocol adjustment instruction. The communication protocol optimization module generates an optimized security communication protocol sequence by using a protocol encapsulation technology according to business traffic shaping requirements and a real-time threat state. The traffic shaping module determines a protocol field adjustment direction and a protocol field adjustment proportion according to the security protocol adjustment instruction, adjusts the optimized security communication protocol sequence, and outputs a protocol sequence after the adjustment field structure. The security verification module corrects the time sequence trigger node of the protocol sequence after the adjustment field structure by using the security protocol adjustment instruction, and realizes synchronous adaptive protection of the data transmission security of the industrial internet platform and the dynamic change of threats.

[0072] Embodiment 1: see Figure 2 The operation mechanism of the attack behavior prediction module is described in detail, which works based on the network traffic characteristic parameters and the device behavior log parameters acquired from the security data acquisition module. The network traffic characteristic parameters include but are not limited to quantitative indexes such as data packet transmission rate, connection request frequency, session duration, protocol type distribution and abnormal traffic peak value. The device behavior log parameters cover device access mode, operation instruction sequence, system call record, login exception number and resource occupation fluctuation and other behavior characteristics. After preprocessing, these multi-source security data are input into the behavior prediction model for deep analysis.

[0073] The behavior prediction model adopts a hybrid architecture based on a time series neural network and a graph convolution network, and performs fusion processing on the input security data. The model first performs time series analysis on the network traffic characteristic parameters to extract periodicity and trend characteristics. At the same time, the device behavior log parameters are subjected to behavior pattern mining to identify normal operation baseline and abnormal behavior pattern. Through the correlation analysis of the two types of parameters, the model constructs a security behavior evolution graph. The graph adopts a graph structure, with nodes representing network devices or terminals and edges representing the interaction relationship between devices, and the weight of the edge reflecting the risk degree of the interaction behavior.

[0074] In constructing the security behavior evolution graph, the system extracts key features from historical attack behavior data. Threat intensity features include quantitative indicators such as the number of attack traffic bytes, the number of packets, attack duration, and the number of attack sources. Time distribution features include time stamp, attack interval period, and attack duration distribution. After standardization, these features are used to construct a multi-dimensional attack correlation matrix. The rows of the matrix represent different attack feature dimensions, the columns represent different time windows, and the matrix element values represent the significance of a specific feature in a specific time window. Through the multi-dimensional attack correlation matrix, the system calculates the boundary parameters of the attack behavior intensity threshold interval. The calculation process uses statistical analysis methods to perform singular value decomposition on the matrix rows and columns, and extracts the main feature vectors. According to the distribution range of the feature vectors, the upper and lower bounds of the attack behavior intensity threshold interval are determined. These boundary parameters are injected into the security behavior evolution graph in real time, updating the weight calculation rules of the edges in the graph, so that the graph can dynamically reflect the current threat situation.

[0075] In the prediction window of the behavior prediction model, the system calculates the attack behavior intensity threshold interval based on the updated security behavior evolution graph. The size of the prediction window is dynamically adjusted according to the real-time load of the industrial internet platform, and is usually set as a sliding time window. The calculation process uses a probability-based inference method to consider the latest changes in the correlation strength between nodes and edge weights in the graph, and outputs an intensity threshold interval with upper and lower bounds. Based on the attack behavior intensity threshold interval, the system defines the adjustment boundary range of the security communication protocol parameters. The upper limit of the protocol encryption strength is generated according to the upper bound of the threshold interval, and a linear mapping function is used to convert the attack intensity value into the encryption algorithm strength parameter. The lower limit of the protocol response delay is generated according to the lower bound of the threshold interval, and the attack intensity value is converted into the minimum response time requirement. The field step constraint is dynamically set according to the width of the threshold interval, and the wider the interval, the looser the step constraint, allowing a larger parameter adjustment range.

[0076] The candidate protocol adjustment parameter set is generated by optimizing the behavior prediction model. The optimization process uses a multi-objective optimization algorithm that considers both security and performance indicators. The algorithm searches for parameter combinations that satisfy all adjustment boundary ranges in the parameter space, generating a candidate set containing multiple feasible solutions. Each candidate solution contains a complete set of protocol parameter configurations, including encryption algorithm selection, key length, response timeout, and field step. The candidate protocol adjustment parameter set is subjected to continuity verification to ensure smooth transition of parameter changes. The verification process calculates the difference between adjacent parameter combinations, and if the difference exceeds the protocol mutation amplitude limit, the parameter combination is adjusted or removed. The protocol mutation amplitude limit is pre-set according to the fault tolerance capability of the industrial communication protocol to ensure that parameter adjustment does not cause communication interruption. The parameter combinations that pass the verification form the target protocol adjustment parameter combination set.

[0077] The target protocol adjustment parameter with the smallest timing interval is extracted from the target protocol adjustment parameter combination. The timing interval refers to the response time requirement of parameter adjustment, and the smaller the interval, the faster the parameter adjustment is required. The selection process uses a greedy algorithm to traverse all parameter combinations and selects the combination with the smallest timing interval as the final solution. The parameter combination is encoded as a security protocol adjustment instruction, containing specific parameter adjustment values and adjustment timing information.

[0078] The generation of the security protocol adjustment instruction also includes the serialization and verification of the instruction. The instruction is packaged in a standardized data format, including instruction type, parameter list, effective timestamp, etc. After the instruction is generated, it is verified by digital signature to ensure the integrity and authenticity of the instruction. The final generated instruction is sent to the communication protocol optimization module and the traffic shaping module for execution.

[0079] During the entire implementation process, the system uses a distributed computing architecture for processing. The behavior prediction model is deployed on multiple computing nodes, and parallel computing is used to accelerate the graph construction and parameter optimization process. Data exchange uses a secure communication channel to prevent intermediate results from being tampered with or leaked. The system also establishes a monitoring mechanism to track the running state of the prediction module in real time, ensuring the reliability of the processing process.

[0080] This implementation enables the attack behavior prediction module to dynamically adapt to changes in the security situation of the industrial internet platform. By continuously analyzing multi-source security data, the module can timely predict potential attack behaviors and generate corresponding protocol adjustment instructions. The generation of instructions takes into account various constraints, balancing security and communication performance requirements. The entire processing process is automatically executed, reducing human intervention and improving system response speed.

[0081] Example 2: Referring to Figure 3 , describes in detail the cooperative working mechanism of the attack behavior prediction module and the communication protocol optimization module, which starts with continuous monitoring and analysis of the threat evolution rate. The threat evolution rate is obtained by calculating the change gradient of network traffic feature parameters and device behavior log parameters in real time, specifically the change rate of attack intensity, attack frequency, or the number of abnormal behaviors per unit time. The system establishes a rate monitoring window to sample these security parameters at fixed time intervals and calculates their first-order derivative with respect to time, thereby obtaining a continuous stream of threat evolution rate values.

[0082] According to the historical operation data of the industrial internet platform, the system pre-divides the numerical range of threat evolution rate through cluster analysis. Unsupervised learning algorithm is used to cluster the historical rate data by density, and multiple statistically significant numerical intervals are identified. Each interval represents a typical threat evolution mode, such as low-speed stable evolution, medium-speed fluctuation evolution and high-speed dramatic evolution, etc. These intervals serve as the basis for dividing the attack behavior intensity threshold sub-interval.

[0083] Based on the mapping relationship between the upper limit of protocol encryption strength and the lower limit of protocol response delay, the system generates a corresponding initial protocol adjustment parameter set for each threat evolution rate sub-interval. The upper limit of encryption strength is calculated according to the median rate of the sub-interval by a pre-set conversion rule, usually using a piecewise linear function to map the rate value to the encryption algorithm complexity index. The lower limit of response delay is also calculated based on the median rate, but uses an inverse mapping relationship, i.e. the higher the rate, the stricter the delay requirement. The initial parameter set of each sub-interval contains a complete set of protocol configuration parameters, covering encryption algorithm type, key update period, authentication mechanism strength, etc.

[0084] Parameter expansion processing is performed on the initial protocol adjustment parameter set to enhance the adaptability of the system. The expansion method includes introducing random disturbance based on the original parameters, or using interpolation method to generate intermediate values between parameters. The expanded parameter set presents more abundant parameter combination possibilities, providing more choices for dealing with complex and variable threat scenarios. The expansion degree is dynamically adjusted according to the width of the sub-interval, the wider the interval, the larger the expansion range.

[0085] Discretization segmentation processing divides the continuous parameter space into a finite number of discrete segments, and the processing process is based on field step constraints, which define the minimum granularity of parameter change. Each discrete segment represents a protocol configuration scheme, and the parameter values within the segment remain fixed. The number of segments is determined according to the importance and sensitivity of the parameters, and critical parameters such as encryption strength will be divided more carefully. The discretized protocol parameter segments are stored in a lookup table, and each segment has a unique identifier. In the prediction window of the behavior prediction model, the system calculates the correlation between the threat evolution rate and the attack behavior intensity threshold interval in real time. Correlation analysis uses correlation coefficient calculation to measure the degree of synchronization between rate change and attack intensity change. A high correlation coefficient indicates that the threat evolution rate can effectively predict the attack behavior intensity, and at this time the system selects the matching protocol parameters according to the current rate value. The selection process determines the belonging sub-interval by comparing the real-time rate value with the boundary range of each sub-interval.

[0086] The communication protocol optimization module divides the extended protocol parameter set into discrete protocol parameter segments according to the field step constraint. The division process follows the logical correlation between parameters, dividing functionally related parameters into the same segment. Each parameter segment contains a set of coordinated protocol configurations, such as adjusting encryption strength and response delay simultaneously. The size of the segment is limited by the step constraint, ensuring the gradualness and stability of parameter adjustment.

[0087] Based on the real-time change amount of the threat evolution rate, the system matches the most suitable segment from the discrete protocol parameter segments. The matching algorithm calculates the distance between the current rate change amount and the center value of each parameter segment, and selects the segment with the smallest distance as the matching result. For cases at the interval boundary, a weighted average method is used to consider the influence of adjacent segments. The matching process also considers the historical use effect of the parameter segment, and preferentially selects the segment that performs well in similar scenarios in the past. The matched discrete protocol parameter segment is mapped to the candidate protocol adjustment parameter set. The mapping process includes parameter decoding and format conversion, which converts the abstract parameter values in the segment into specific protocol configuration instructions. The mapped parameters are added to the candidate set as possible protocol adjustment schemes. The candidate set uses a priority queue structure, which is sorted according to the matching score of the parameter segment, with the parameters with high scores at the front of the queue.

[0088] The system performs final screening on the candidate protocol adjustment parameter set to generate the protocol configuration for actual adjustment. The screening criteria include parameter feasibility, performance impact evaluation, and compatibility with the current system state. The screening process uses a multi-level filtering mechanism to gradually eliminate unsuitable parameter combinations. The finally selected parameter combination is encapsulated as a protocol adjustment instruction and sent to the execution module.

[0089] Throughout the implementation process, the system establishes a feedback mechanism to monitor the parameter adjustment effect, and evaluates the effectiveness of parameter selection by comparing the adjusted security state with the expected target. The evaluation results are fed back to the parameter matching process for optimizing future parameter selection strategies. This closed-loop control mechanism enables the system to continuously improve the accuracy of parameter matching. The implementation process also considers the real-time running constraints of the industrial internet platform. The parameter adjustment timing is selected during periods of low communication load to reduce the impact on normal business. The adjustment amplitude is dynamically limited according to the current processing capacity of the platform to avoid system overload due to excessive adjustment. All parameter changes are recorded in the audit log for subsequent analysis and optimization. This implementation method converts the abstract threat evolution rate into specific protocol parameter adjustment through a multi-level processing process. Discrete segmentation processing reduces the complexity of parameter selection, enabling the system to quickly respond to threat changes. The mapping mechanism ensures the rationality of parameter selection, matching the security configuration with the threat level. The entire process is automatically executed to ensure the timeliness and consistency of the response.

[0090] Example 3: see Figure 4, the cooperative working process of the communication protocol optimization module and the traffic shaping module is described in detail. The implementation process starts from the analysis of traffic shaping requirements. The traffic shaping requirements are defined according to the characteristics of the business types running on the industrial internet platform, including real-time control business, batch data transmission business, monitoring business and other different categories. Each type of business has unique traffic mode characteristics. Real-time control business requires low delay and small jitter, batch data transmission business requires high throughput, and monitoring business requires stable bandwidth guarantee. The system establishes a protocol encapsulation benchmark parameter configuration file for each type of business. The initial protocol field length is set according to the business data type and importance. Important control instructions use shorter field length to reduce transmission delay, and batch data uses longer field length to improve transmission efficiency. The initial protocol interval period is set according to the real-time requirements of the business. High real-time business sets a shorter interval period, and low real-time business sets a longer interval period.

[0091] Based on the initial protocol field length and the initial protocol interval period, the system generates an initial protocol encapsulation sequence. The generation process uses a sequence construction algorithm that considers business priority, time constraints and resource allocation. The algorithm first sorts the current business data packets to be transmitted according to the business urgency and allocates transmission time slots. Then, for each time slot, the protocol field length and interval period are allocated to form the initial protocol encapsulation sequence. Each protocol unit in the sequence contains a complete protocol header field, payload data and check information.

[0092] According to the real-time threat state obtained from the attack behavior prediction module, the system calculates the field length adjustment amount of each protocol unit in the initial protocol encapsulation sequence. The real-time threat state includes current attack intensity level, threat type and influence range, etc. The calculation of the field length adjustment amount uses a threat response function, which maps the threat state to the field length change value. For high threat state, the system will increase the protocol field length to enhance data integrity protection; for low threat state, the field length will be appropriately reduced to improve transmission efficiency.

[0093] The calculation of the field length adjustment amount uses the following formula:

[0094]

[0095] Where: ΔL i represents the field length adjustment amount of the i-th protocol unit, α is the threat response coefficient, T current is the current threat state value, T baseline is the benchmark threat state value, T max is the maximum threat state value, T min is the minimum threat state value, L base,iis the initial field length of the ith protocol unit. The threat response coefficient is dynamically adjusted according to the service type, and a larger coefficient value is used for critical services to improve security, and a smaller coefficient value is used for ordinary services to maintain performance.

[0096] The field length adjustment amount is superimposed with the initial protocol field length to generate a transition protocol sequence. The superimposing operation adopts a unit-by-unit processing manner, and the new field length of each protocol unit in the sequence is calculated respectively. The new field length is equal to the initial length plus the adjustment amount, but is limited by the maximum and minimum length constraints specified by the protocol. The transition protocol sequence maintains the timing structure of the original sequence, but the field length of each unit has been adjusted according to the threat state.

[0097] The protocol interval period of the transition protocol sequence is smoothed, and the smoothing processing adopts a timing adjustment algorithm that detects the mutation of the interval period between adjacent protocol units. When the change in the interval period is found to exceed the allowed threshold, the algorithm smooths the interval change by inserting a buffer time slot or adjusting the time slot allocation. The processed protocol interval period presents a gradual change feature, avoiding sudden timing jitter. Finally, an optimized security communication protocol sequence is generated, which takes into account both business requirements and security protection elements.

[0098] The traffic shaping module receives a security protocol adjustment instruction, which contains a protocol field adjustment direction and a protocol field adjustment ratio. The adjustment direction indicates whether the field length needs to be increased or decreased, and the adjustment ratio specifies the degree of change. The module takes the absolute value of the numerical change of the security protocol adjustment instruction as the protocol field adjustment ratio, which reflects the strength of the adjustment required.

[0099] According to the protocol field adjustment direction, a protocol field length correction rule is established, which adopts a conditional judgment structure. When the adjustment direction is increase, the new field length is equal to the current length multiplied by (1 plus the adjustment ratio); when the adjustment direction is decrease, the new field length is equal to the current length multiplied by (1 minus the adjustment ratio). The correction rule also includes boundary checks to ensure that the new field length is within the minimum and maximum values allowed by the protocol. The field length of the optimized security communication protocol sequence is adjusted according to the correction rule. The adjustment process traverses each protocol unit in the sequence, and calculates the new length according to its current field length and adjustment ratio. The calculation process uses floating-point operations to maintain precision, and the final result is rounded to the nearest legal field length value. The adjusted sequence maintains the original protocol unit order and timing relationship.

[0100] The protocol units with a field length mutation amplitude exceeding a fault tolerance threshold are smoothly reorganized. The fault tolerance threshold is set according to the protocol type and service requirements, and is usually set as the maximum allowed percentage of field length change. The smooth reorganization adopts a sliding window processing method to cooperatively adjust the field lengths of multiple protocol units in the window. The reorganization algorithm finds the optimal length allocation scheme to uniformly distribute the length changes across multiple protocol units, avoiding drastic changes in a single unit. Finally, a protocol sequence with adjusted field structure is generated, which not only achieves the required field adjustment, but also maintains good transmission performance characteristics.

[0101] Throughout the implementation process, the system establishes a monitoring mechanism to track the protocol adjustment effect. The monitoring indicators include performance parameters such as transmission delay, throughput, and packet loss rate, as well as security indicators such as security protection level. The monitoring data is used to feedback optimization parameter adjustment strategies to form a closed-loop control system. The system also maintains a protocol adjustment log to record the parameters, reasons, and effects of each adjustment. This implementation method balances business needs and security requirements through fine-grained protocol parameter adjustment. The generation of the protocol encapsulation sequence takes into account the business characteristics, the field length adjustment incorporates the security threat response, and the interval period smoothing processing ensures the transmission quality. The correction rules of the traffic shaping module ensure accurate execution of the adjustment, and the smooth reorganization mechanism prevents excessive protocol fluctuations. The entire process embodies the unification of security protection and performance optimization.

[0102] Embodiment 4: The working mechanism of the security verification module and the cooperative process with the attack behavior prediction module are described in detail. The implementation process starts with the analysis of the security protocol adjustment instruction. The security protocol adjustment instruction contains protocol parameter change amount information, which reflects the adjustment amplitude of key parameters such as encryption strength and response delay. The system calculates the protocol offset degree based on the parameter change amount, and the protocol offset degree is defined as the weighted sum of the parameter change amounts, and the weight coefficients are allocated according to the parameter importance. Based on the protocol offset degree, the system performs timing consistency verification on the protocol sequence after adjusting the field structure. The verification process traverses each protocol unit in the protocol sequence to check whether its timing trigger node meets the pre-interval. The system maintains a timing relationship model that records the standard time interval requirements between protocol units. The verification algorithm calculates the actual trigger time difference of adjacent protocol units and compares it with the standard interval. When the time difference exceeds the allowed tolerance range, it is marked as a timing inconsistency event.

[0103] The timing consistency check uses a sliding window technique, which checks the timing relationship of three consecutive protocol units each time. The window slides on the sequence, and detects whether the interval between the middle unit and its predecessor and successor is balanced. If an unbalanced interval is detected, the system further analyzes the degree of imbalance. When the interval between the timing trigger nodes of adjacent protocol units is less than the minimum fault tolerance threshold, the translation calibration procedure is triggered. The minimum fault tolerance threshold is dynamically configured according to the communication protocol standard and the network environment, and is usually set to a time unit of microseconds.

[0104] The translation calibration process adjusts the trigger node of a specific protocol unit. The calibration algorithm calculates the amount of time that needs to be translated, which is equal to the difference between the standard interval and the actual interval. The calibration direction is determined according to the direction of the timing deviation: when the actual interval is less than the standard interval, it is translated backward, and when it is greater than the standard interval, it is translated forward. The calibration operation modifies the timestamp field of the protocol unit to generate a new trigger time. The calibrated protocol unit is called a calibrated protocol unit, whose time attribute has been updated but the data content remains unchanged.

[0105] The security check module outputs the security communication protocol sequence after timing synchronization calibration, and performs a final verification before outputting, checking whether the timing relationship of all protocol units meets the constraint condition. After verification, the sequence is packaged into a transmission-ready format and sent to the network interface. The entire checking process is performed on a dedicated hardware accelerator to ensure that the processing speed meets the real-time communication requirements.

[0106] When generating the security behavior evolution graph, the attack behavior prediction module obtains historical attack behavior data from the security data acquisition module. The historical data is stored in a distributed database and includes fields such as timestamp, attack type, target device, and attack intensity. The system extracts threat intensity features and time distribution features from the data. Threat intensity features include attack traffic size, attack duration, and number of affected devices. Time distribution features include attack occurrence time, attack interval period, and attack duration distribution. Based on the threat intensity features, the system constructs a multi-dimensional attack correlation matrix. The rows of the matrix represent different attack feature dimensions, and the columns represent different time windows. The matrix element values reflect the activity level of a specific feature in a specific time window. The matrix construction process uses feature engineering methods to standardize, normalize, and reduce the dimensionality of the original data, as shown in Table 1.

[0107] Table 1: Multi-dimensional attack correlation matrix fragment.

[0108] Time window Attack frequency Packet size Source address diversity Attack duration W1 0.85 0.62 0.78 0.91 W2 0.92 0.71 0.85 0.88 W3 0.78 0.66 0.72 0.82 W4 0.95 0.82 0.91 0.96

[0109] The system calculates the boundary parameters of the attack behavior intensity threshold interval by attacking the correlation matrix from multiple dimensions. The principal component analysis method is used to extract the main feature vector of the matrix. According to the distribution range of the feature vector, the statistical boundary of the attack intensity threshold interval is determined. The boundary parameters include the upper and lower bounds of the interval, which correspond to the maximum and minimum expected ranges of attack intensity, respectively. The calculation process considers the time decay factor, and the weight of recent data is higher than that of historical data.

[0110] The boundary parameters are input into the security behavior evolution graph for updating. The graph is stored in a graph database, with nodes representing network devices and edges representing attack propagation paths. The boundary parameters are injected into the edge weight calculation function, affecting the risk propagation probability between nodes. After updating the graph, the threat level and correlation of each node are recalculated. The update cycle is synchronized with the prediction window to ensure that the graph reflects the latest threat situation in real time.

[0111] An abnormal handling mechanism is established during the implementation of the system. When a timing conflict that cannot be calibrated is detected in the protocol sequence, a conflict resolution program is started. The program analyzes the conflict reasons and may adjust the order of protocol units or insert filler units. All calibration operations are recorded in the audit log, including original timing, calibration amount, calibration reason, and other detailed information. The log data is used for subsequent analysis and optimization of the calibration algorithm. A bidirectional communication channel is established between the security verification module and the attack behavior prediction module. The prediction module provides threat prediction information to the verification module to assist in timing calibration decision-making. The verification module feeds back the actual attack protection effect to the prediction module for optimization of the prediction model. This collaborative mechanism enables the system to adapt to the changing network threat environment.

[0112] The processing flow supports parallel execution, and timing verification and graph updating can be performed simultaneously on different computing nodes. System resources are allocated dynamically according to load, with core verification functions being prioritized during peak periods. The implementation process also considers a fault recovery mechanism, with critical states being stored persistently at regular intervals to enable quick recovery of working state after an abnormal interruption. This implementation approach ensures the timing integrity of the protocol sequence through multiple levels of verification processes. The protocol offset degree calculation provides a global adjustment perspective, and the timing consistency verification ensures the micro timing relationship, with translation calibration resolving specific conflict points. The construction of the security behavior evolution graph incorporates historical attack features, and the boundary parameter calculation provides a scientific threat assessment benchmark. The system realizes the collaborative adaptation of protocol timing and security threats.

[0113] Example 5: The security check module corrects the timing trigger nodes in detail. The implementation process starts with a deep analysis of the security protocol adjustment instruction. The security protocol adjustment instruction contains protocol parameter fluctuation information, which involves key communication attributes such as encryption strength, authentication mechanism, and response timeout. The system uses signal processing technology to analyze the parameter fluctuation curve and identify the rising edge node and the falling edge node. The rising edge node refers to the time point at which the parameter value begins to increase significantly, and the falling edge node refers to the time point at which the parameter value begins to decrease significantly. The identification process uses a sliding window difference algorithm to calculate the local change rate of the parameter sequence, and marks it as a feature node when the change rate exceeds the set threshold.

[0114] The system maintains a protocol timing register to record the initial trigger nodes of each protocol unit in the protocol sequence after adjusting the field structure. The initial trigger node is pre-set according to the business scheduling plan and represents the expected execution timestamp of the protocol unit. For each protocol unit, the system calculates its timing offset. The calculation process considers the temporal and spatial relationship between the protocol parameter fluctuation characteristics and the initial trigger node. Specifically, for protocol units close to the rising edge node, the timing offset is proportional to the fluctuation amplitude of the rising edge; for protocol units close to the falling edge node, the timing offset is inversely proportional to the fluctuation amplitude of the falling edge. The closer the protocol unit is to the feature node, the larger the timing offset.

[0115] The calculation of the timing offset is based on the timing offset coefficient defined by the protocol parameter fluctuation amplitude. The timing offset coefficient uses a normalization processing method to convert fluctuation amplitudes of different dimensions into dimensionless coefficients. The coefficient calculation uses a piecewise function, with small amplitude fluctuations corresponding to small coefficient values and large amplitude fluctuations corresponding to large coefficient values. The system calculates the initial timing offset by the timing offset coefficient, the initial trigger node, and the timing distance of the rising edge or falling edge node. The timing distance refers to the time difference between the protocol unit trigger time and the feature node time, measured in microseconds. The initial timing offset is equal to the product of the timing offset coefficient and the timing distance, and the product result has directionality: the rising edge node produces a positive offset, and the falling edge node produces a negative offset.

[0116] The initial timing offset is threshold truncated. The system presets a maximum allowed offset threshold, which is set according to the time fault tolerance capability of the communication protocol. The truncation process uses a limiting function. When the absolute value of the initial offset exceeds the threshold, the extreme value with the same sign as the threshold is taken; otherwise, the original value is retained. The processed result is called the final timing offset, which represents the specific value that the protocol unit trigger time needs to adjust. The final timing offset is superimposed with the initial trigger node to generate a calibrated protocol unit. The superposition operation modifies the timestamp field of the protocol unit, and the new timestamp is equal to the original timestamp plus the offset. The calibration process keeps the data payload of the protocol unit unchanged and only adjusts its timing properties. The system performs boundary constraint processing on the timing interval of the calibrated protocol unit. The boundary constraint checks whether the time interval of adjacent calibrated protocol units meets the minimum interval requirement and the maximum interval limit. When it is detected that the interval exceeds the allowed range, a secondary calibration program is started to fine-tune the timestamp of the related unit until the constraint condition is met.

[0117] The system establishes a calibration effect evaluation mechanism. The evaluation process simulates the execution of the protocol sequence in the actual network environment, predicts the communication delay and conflict probability after timing adjustment. The evaluation results are fed back to the offset calculation module for optimizing the setting rules of the timing offset coefficient. All calibration operations are recorded in the distributed audit log, and the log entries contain complete information such as pre-calibration timestamp, offset, post-calibration timestamp, constraint check results, etc.

[0118] The security verification module adopts a hierarchical processing architecture during implementation. The bottom layer hardware accelerator performs high-precision timestamp operation and fast arithmetic operation, the middle layer handles protocol parsing and calibration logic, and the upper layer manages configuration parameters and policy rules. The layers share data through zero-copy memory to reduce processing delay. The system resource allocation adopts dynamic priority scheduling, and critical protocol units are given priority in obtaining processing resources.

[0119] The monitoring of protocol parameter fluctuation adopts real-time stream processing technology, and the data pipeline continuously receives the security protocol adjustment instruction stream. The window aggregator calculates the parameter change trend according to the time window, and the event detector identifies the fluctuation characteristic node. The processing pipeline adopts a back pressure mechanism, which automatically reduces the sampling frequency when the system load is too high, to ensure the reliability of processing. The definition of the timing offset coefficient considers the particularity of the industrial communication scene. The system configures independent coefficient mapping tables for different service types. The real-time control service adopts a conservative coefficient mapping to limit the maximum offset; the batch data transmission service adopts a loose coefficient mapping to allow larger timing adjustment. The mapping table supports hot updates, which can dynamically adjust according to the network status during runtime. The calculation of the initial timing offset introduces an inertia compensation factor. The compensation factor simulates the inertia characteristics of the physical system to avoid dramatic changes in timing. The calculation process uses an iterative approximation method to gradually converge to the optimal offset in continuous processing periods. The threshold truncation processing increases the smooth transition option, which uses gradual adjustment instead of hard truncation when the offset is close to the threshold. The generation process of the calibrated protocol unit includes integrity verification. The verification checks whether the calibrated protocol unit meets the communication protocol specification, including key attributes such as field check sum, length identifier, and type marker. If the verification fails, an alarm is triggered and a recovery program is started, which falls back to the latest valid protocol sequence snapshot. The boundary constraint processing adopts a multi-objective optimization algorithm. The algorithm considers time interval constraints, resource occupation constraints, and service priority constraints to find the optimal timestamp adjustment scheme that meets all constraint conditions. The optimization process uses historical calibration data for machine learning to improve constraint satisfaction efficiency.

[0120] The calibration processing unit runs in an independent security container, and a single unit failure will not affect the overall function. The system state monitor detects processing abnormalities in real time and triggers a quick restart or switches to a backup computing node. The implementation process also considers time synchronization issues, and all timestamps are based on high-precision network time protocol synchronization to avoid calibration errors caused by clock drift between systems. This implementation enables dynamic adaptation of protocol execution to security requirements through a refined timing adjustment mechanism. Parameter fluctuation feature recognition captures security state changes, timing offset calculation quantifies adjustment requirements, threshold truncation prevents over-adjustment, and boundary constraints ensure communication reliability. The multi-layer processing architecture ensures stable operation of the system in complex industrial environments.

[0121] It is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting; it is not intended to exclude myriad other embodiments of the present application that other inventors can develop based on the same general inventive concepts embodied by the described embodiments. That is, although the present application is described in terms of particular embodiments and illustrative figures, it should be apparent that the scope of the present application is not limited to these specific embodiments.

[0122] While the embodiments of the application have been shown and described herein, it will be understood by those of ordinary skill in the art that various changes, modifications, alternatives, and variations can be made to the embodiments without departing from the spirit and scope of the application, which is defined by the appended claims and their equivalents.

Claims

1. An industrial internet platform big data security protection system, characterized in that, The method comprises the following steps: a security data acquisition module is used to acquire multi-source security data of an industrial internet platform, wherein the multi-source security data comprises network traffic characteristic parameters and device behavior log parameters; an attack behavior prediction module is used to generate an attack behavior prediction graph and define an adjustment boundary range of a security communication protocol parameter according to the multi-source security data by using a behavior prediction model, so as to generate a security protocol adjustment instruction matched with the multi-source security data; a communication protocol optimization module is used to generate an optimized security communication protocol sequence by using a protocol encapsulation technology according to business traffic shaping requirements and a real-time threat state; a traffic shaping module is used to determine a protocol field adjustment direction and a protocol field adjustment proportion according to the security protocol adjustment instruction, so as to adjust the optimized security communication protocol sequence and obtain a protocol sequence with an adjusted field structure; a security verification module is used to correct a timing trigger node of the protocol sequence with the adjusted field structure by using the security protocol adjustment instruction, so as to realize synchronous adaptive protection of data transmission security and threat dynamic changes of the industrial internet platform.

2. The system of claim 1, wherein, The attack behavior prediction module comprises the following steps: a security behavior evolution graph is constructed by using a behavior prediction model based on the network traffic characteristic parameters and the device behavior log parameters; an attack behavior intensity threshold interval is calculated according to the security behavior evolution graph within a prediction window of the behavior prediction model; an adjustment boundary range of a security communication protocol parameter is defined based on the attack behavior intensity threshold interval, wherein the adjustment boundary range comprises a protocol encryption intensity upper limit, a protocol response delay lower limit and a field step constraint; a candidate protocol adjustment parameter set is generated by optimizing the behavior prediction model; a target protocol adjustment parameter combination conforming to a protocol mutation amplitude limit is generated by performing continuity verification on the candidate protocol adjustment parameter set; a target protocol adjustment parameter with the smallest timing interval is extracted from the target protocol adjustment parameter combination, and the security protocol adjustment instruction is generated.

3. The system of claim 2, wherein, The attack behavior prediction module further comprises the following steps: attack behavior intensity threshold subintervals are divided according to a numerical range of a threat evolution rate; initial protocol adjustment parameter sets of each subinterval are generated based on the protocol encryption intensity upper limit and the protocol response delay lower limit; parameter expansion and discretization segmentation processing are performed on the initial protocol adjustment parameter sets; target protocol adjustment parameters are screened according to the correlation between the threat evolution rate and the attack behavior intensity threshold interval within the prediction window of the behavior prediction model, and the candidate protocol adjustment parameter set is generated.

4. The system of claim 1, wherein, The communication protocol optimization module comprises the following steps: protocol encapsulation reference parameters are set according to business traffic shaping requirements, wherein the reference parameters comprise an initial protocol field length and an initial protocol interval period; an initial protocol encapsulation sequence is generated based on the initial protocol field length and the initial protocol interval period; field length adjustment amounts of each protocol unit in the initial protocol encapsulation sequence are calculated according to a real-time threat state; the field length adjustment amounts and the initial protocol field length are superimposed to generate a transition protocol sequence; the protocol interval period of the transition protocol sequence is smoothed to generate the optimized security communication protocol sequence.

5. The system of claim 1, wherein, The security verification module comprises: According to the protocol parameter variation of the security protocol adjustment instruction, the protocol offset degree is determined; Based on the protocol offset degree, the timing consistency of the protocol sequence after adjusting the field structure is verified; If the timing trigger node interval of adjacent protocol units is less than the minimum fault tolerance threshold, the timing trigger node is translated and calibrated; Output the security communication protocol sequence after timing synchronization calibration.

6. The system of claim 2, wherein, When the attack behavior prediction module generates the security behavior evolution graph: Extract the threat intensity features and time distribution features from the historical attack behavior data; According to the threat intensity features, a multi-dimensional attack correlation matrix is constructed; Through the multi-dimensional attack correlation matrix, the boundary parameters of the attack behavior intensity threshold interval are calculated; The boundary parameters are input into the security behavior evolution graph.

7. The system of claim 3, wherein, When the communication protocol optimization module processes discretization segmentation: According to the field step constraint, the extended protocol parameter set is segmented into discretized protocol parameter segments; Based on the real-time variation of the threat evolution rate, the corresponding discretized protocol parameter segment is matched; The matched discretized protocol parameter segment is mapped to the candidate protocol adjustment parameter set.

8. The system of claim 4, wherein, The traffic shaping module comprises: The absolute value of the numerical variation of the security protocol adjustment instruction is taken as the protocol field adjustment ratio; According to the protocol field adjustment direction, the protocol field length correction rule is established; According to the correction rule, the field length of the optimized security communication protocol sequence is adjusted; The protocol units with field length mutation amplitude exceeding the fault tolerance threshold are smoothly reorganized to generate the protocol sequence after adjusting the field structure.

9. The system of claim 5, wherein, When the security verification module corrects the timing trigger node: Identify the rising edge node and falling edge node of the protocol parameter fluctuation in the security protocol adjustment instruction; Calculate the timing offset of each protocol unit in the protocol sequence after adjusting the field structure; The timing offset and the initial trigger node are superimposed to generate a calibrated protocol unit; Boundary constraint processing is performed on the timing interval of the calibrated protocol unit.

10. The system of claim 9, wherein, The security verification module further comprises: According to the protocol parameter fluctuation amplitude, the timing offset coefficient is defined; Through the timing offset coefficient, the timing distance of the initial trigger node and the rising edge / falling edge node, the initial timing offset is calculated; The initial timing offset is threshold truncated to obtain the final timing offset.

Citation Information

Patent Citations

  • Multi-layer protection method and system for high-performance industrial switch

    CN120200845A

  • Network threat detection method and system under dynamic protocol recombination

    CN120321043A

  • Wireless sensor network environment monitoring system based on Internet of Things and safety protection method

    CN120434621A