Private protocol transmission security management system and method based on one-way communication device

By deploying a protocol parsing engine and feature library in a one-way optical gate, private protocols are identified and verified, solving the problem that the one-way optical gate cannot deeply identify data content. This enables fine-grained parsing and security control of transmitted content, improving the security and reliability of the network environment.

CN121000508AActive Publication Date: 2025-11-21ZHUHAI COASTAL DIGITAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511448668.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2025-11-21
Estimated Expiration
2045-10-11

AI Technical Summary

Technical Problem

Existing one-way optical shutter products cannot perform deep identification of data content, allowing application-layer attacks hidden under compliant protocols to easily penetrate the isolation barrier. They cannot achieve fine-grained analysis and security control of transmitted content while ensuring physical one-wayness.

Method used

The method for secure transmission management of private protocols based on one-way communication devices extracts the communication characteristics of private protocols, constructs a feature library, and deploys a protocol parsing engine on the low-security side of the one-way optical gate for deep detection. After identifying the private protocols, it performs compliance verification and content filtering, monitors protocol behavior and session status in real time, triggers security alarms, and blocks the transmission link.

Benefits of technology

It enables accurate identification and deep detection of private protocols, prevents application layer attacks and data leaks, improves the security and reliability of the network environment, and provides a proactive defense mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000508A_ABST
    Figure CN121000508A_ABST
Patent Text Reader

Abstract

The invention discloses a private protocol transmission security management system and method based on a one-way communication device, and relates to the technical field of network security, and the method comprises the steps: extracting communication features of a private protocol, carrying out the normalization processing, and constructing a private protocol feature library; deploying a protocol analysis engine at a low-security side of the unidirectional optical shutter, performing deep detection on out-of-domain data streams, identifying a private protocol and extracting a current session protocol feature; matching the extracted features with a feature library, and performing compliance verification and content filtering according to a security policy after matching succeeds; the data passing the verification are packaged into a transmission format allowing the data to pass through the one-way optical shutter, and are sent to the high-safety side through the one-way optical shutter; performing recombination and integrity and consistency verification on the received data on the high-security side, recording an audit log after verification is passed, and forwarding the audit log to a target system; protocol behaviors and session states are monitored in real time, a safety alarm is triggered for unknown protocols or abnormal behaviors, and transmission is blocked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of network security, and particularly relates to a private protocol transmission security management system and method based on a one-way communication device. BACKGROUND

[0002] In a highly sensitive network environment, physical isolation is a key means to guarantee the security of core data. As a core device for realizing physical isolation, a one-way optical gate ensures that data can only flow from a low-security domain to a high-security domain in one direction through its physical characteristics, thereby blocking the reverse network attack path from the basic level.

[0003] However, existing one-way optical gate products have a significant security blind spot. They mostly only verify the data bottom layer format, like a "dumb pipe", and allow it to pass as long as the format is compliant. This mechanism cannot deeply identify the data content, resulting in that application layer attacks hidden in compliant protocols can easily penetrate the isolation barrier, posing a serious threat.

[0004] Therefore, the current technology cannot realize fine analysis and security control of transmission content while ensuring physical unidirectionality. This defect has become a prominent pain point in a high-security network environment, and an innovative technical solution is urgently needed to solve this key technical problem. SUMMARY

[0005] The purpose of the present application is to provide a private protocol transmission security management system and method based on a one-way communication device to solve the problems in the prior art.

[0006] To achieve the above purpose, the present application provides the following technical scheme: a private protocol transmission security management method based on a one-way communication device, the management method comprising:

[0007] S1. Extracting the communication characteristics of a private protocol, normalizing the communication characteristics, and storing them in a private protocol feature library;

[0008] S2. Deploying a protocol analysis engine on the low-security side of a one-way optical gate, deeply detecting the out-domain data stream, and judging whether the data stream belongs to a private protocol; if it is identified as a private protocol, extracting the protocol characteristics of the current session;

[0009] S3. Matching the extracted protocol characteristics with the private protocol feature library; if the matching is successful, performing compliance verification and content filtering on the data content according to a preset security policy; if the matching fails, determining it as an unknown protocol and going to S6 for processing;

[0010] S4. Encapsulating the data passing the compliance verification into a transmission format allowed to pass through the one-way optical gate, and sending it to the high-security side through the one-way optical gate;

[0011] S5. Reorganize the received data on the high-security side, and perform data integrity and consistency check; after the check passes, record the audit log and forward to the target system;

[0012] S6. Monitor the protocol behavior and session state in real time, and if unknown protocol, abnormal protocol characteristics or session behavior deviating from the preset mode is detected, trigger a security alarm and block the current transmission link.

[0013] Further, S1 includes:

[0014] The communication features include protocol header structure, payload structure, instruction set, session behavior pattern;

[0015] Collect the header data included in the private protocol sample, denoted as H i =(h i1 ,h i2 ,…,h ik ), where i=1,2,…,N; k is the number of header fields; h i1 ,h i2 ,…,h ik represent the values of the 1st, 2nd, and kth header fields of the ith private protocol sample, respectively;

[0016] Extract the feature parameters of each header field, including field length L ij , value range R ij =[min(h ij ),max(h ij )], and field type T ij ;

[0017] The field type mentioned above is, for example, a field, a length field, a check field, etc.

[0018] Parse the payload data P i =(p i1 ,p i2 ,…,p im ) of each private protocol sample, where m is the number of payload fields; p i1 ,p i2 ,…,p im represent the values of the 1st, 2nd, and mth payload fields of the ith private protocol sample, respectively; obtain the delimiter D i of the payload field, and extract the length M ij , data type S ij , and field meaning description Cij of each payload field.

[0019] The delimiter mentioned above is, for example, a specific byte sequence, a length identifier, etc., and the data type is, for example, an integer, a string, a binary stream, etc.

[0020] Identifying instruction codes I in each private protocol sample i = (i i1 , i2 …i in ), where n is the number of instructions, i i1 , i2 …i in represent the 1st, 2nd, and mth instruction codes of the ith private protocol sample, respectively; recording the corresponding function description F ij , instruction parameter number Q ij , parameter format G ij , and execution response format H ij of each instruction code;

[0021] Collecting session interaction data in each private protocol sample, including request R i1 , response R i2 , data transmission sequence, session closing request C i1 , and response C i2 ;

[0022] Extracting session behavior features, including session establishment time T is , session duration T id , data transmission rate V i , and session interaction times N i ;

[0023] The session duration T id = T ie -T is ; data transmission rate ; where T ie is the session closing time, and D T is the total number of session transmissions;

[0024] Normalizing the collected data;

[0025] The normalization process includes:

[0026] For numerical features such as field length L ij , M ij , session duration T id , and data transmission rate V i , the min-max normalization method is used, with the formula as follows:

[0027] ;

[0028] where X is the original feature value, X min is the minimum value of the feature value in all samples, and X maxX is the maximum value of the feature value in all samples norm is the normalized feature value;

[0029] For field type T ij , data type S ij , instruction function description F ij , and other partition type features, a one-hot encoding method is used for processing; for example, if there are K field types, each field type is represented as a K-dimensional vector, where the corresponding type position is 1 and the remaining positions are 0.

[0030] For separator D i , instruction code I i , and other string type features, they are converted into ASCII code or hexadecimal number sequence, and then standardized to ensure that strings of different lengths have a unified representation.

[0031] The normalized communication features are classified and stored according to the protocol category to construct a private protocol feature library.

[0032] Further, S2 includes:

[0033] Deploying the data collection unit on the low-security side of the one-way optical shutter, real-time collection of the out-domain data stream flowing from the low-security side to the high-security side; the collected data stream is in the form of data packets, each data packet containing packet header information and data payload;

[0034] The packet header information includes but is not limited to source IP address, destination IP address, source port number, destination port number, protocol type, etc.

[0035] Pretreatment of the collected data packets;

[0036] The above-mentioned pretreatment process includes:

[0037] De-duplication processing is performed on the collected data packets to remove duplicate data packets and avoid repeated detection; a hash algorithm is used to calculate the hash value of each data packet, and if the hash values of two data packets are the same, it is determined that they are duplicate data packets, and only one is retained for subsequent processing;

[0038] Fragment reassembly is performed on the data packets; if the data packets are transmitted in fragments, the fragment data is reassembled into complete data packets according to the relevant rules of IP fragmentation;

[0039] The header data of the data packet is extracted and compared with the header structure features of each protocol in the private protocol feature library; the matching degree M h of the header field is calculated, and the formula is as follows:

[0040] ;

[0041] Where hj is the value of the jth header field of the data packet to be detected, ij is the value range of the jth header field of the ith protocol in the private protocol feature library, is an indicator function, if , , otherwise , is the weight of the jth header field;

[0042] The above is set according to the importance of the field, such as the identification field has a higher weight, and the check field has a lower weight;

[0043] If a protocol i makes M h ≥ θ h , the data packet is preliminarily determined to belong to the protocol i;

[0044] The above θ h is a header matching degree threshold value, which is set according to actual conditions;

[0045] For the data packet preliminarily determined to belong to the protocol i, the payload data of the data packet is extracted, and the payload data is parsed according to the payload format feature of the protocol i; whether the delimiter of the payload field is consistent with D i , whether the field length and data type of each payload field meet the requirements of M ij and S ij ;

[0046] The matching degree M p of the payload format is calculated, and the formula is as follows:

[0047] ;

[0048] Wherein, p j is the feature of the jth payload field of the data packet to be detected, P ij is the feature requirement of the jth payload field of the ith protocol in the private protocol feature library, is an indicator function, if p j meets the requirement of P ij , then , otherwise , v j is the weight of the jth payload field;

[0049] If M p ≥ θ p , the data packet to be detected is further determined to belong to the protocol i; wherein, θ p is a payload matching degree threshold value, which is set according to actual conditions;

[0050] The instruction code is extracted from the payload data, and compared with the instruction set I iComparing; detecting whether the instruction code exists in the instruction set I i , and whether the number of instruction parameters and the parameter format meet the requirements of the corresponding instruction Q ij and G ij ;

[0051] Calculating the matching degree M of the instruction set i , the formula is as follows:

[0052] ;

[0053] Where, i j is the instruction code and parameter characteristics in the data packet to be detected, I ij is the characteristic requirement of the jth instruction of the ith protocol in the private protocol characteristic library, is an indicator function, if ij meets the requirement of Iij, then , otherwise , u j is the weight of the jth instruction;

[0054] If M i ≥ θ i , then it is finally determined that the data packet to be detected belongs to protocol i, that is, it is identified as a private protocol; wherein, θ i is the instruction matching degree threshold value, which is set according to the actual situation;

[0055] For the data stream identified as a private protocol, the session process corresponding to the data stream is tracked, and the protocol characteristics of the current session are extracted; including the header structure characteristics, the payload format characteristics, the instruction set characteristics, and the session behavior mode characteristics, and the extracted characteristics are stored as a characteristic vector F=(f1,f2,…,ft), wherein t is the characteristic dimension;

[0056] The above-mentioned header structure characteristics include but are not limited to dynamic identification field, length field, etc., the payload format characteristics include but are not limited to real-time transmission field content, data type change, etc., the instruction set characteristics include but are not limited to instruction sequence used in the session process, parameter value, etc., and the session behavior mode characteristics include but are not limited to session establishment time, data transmission rate change, interaction frequency, etc.

[0057] Further, S3 includes:

[0058] The extracted current session protocol characteristic vector F is compared with the characteristic vector F k =(f k1 ,f k2 ,…,f kt ) of each protocol in the private protocol characteristic library; cosine similarity algorithm is adopted, and the formula is as follows:

[0059] ;

[0060] wherein, f l is the lth feature value of the current session feature vector F, f kl is the lth feature value of the kth protocol feature vector F k in the private protocol feature library, Sim(F, F k ) is the cosine similarity of the two feature vectors, and the value range is [0, 1], and the closer the value is to 1, the higher the similarity is;

[0061] a similarity threshold θ s is preset; if Sim(F, F k ) ≥ θ s , it is determined that the current session protocol matches the protocol k in the private protocol feature library successfully; if Sim(F, F k ) < θ s for all protocols k, it is determined that the matching fails, the current session protocol is an unknown protocol, and the process goes to S6;

[0062] For the session protocol that matches successfully, the data content is checked for compliance according to the preset security policy; the compliance check includes data content check, instruction permission check, and session behavior compliance check.

[0063] The above-mentioned check process includes:

[0064] Data content check: check whether sensitive information (such as ID number, bank card number, password, etc.) is contained in the data payload; if the regular expression matching is successful, it is determined that sensitive information is contained, and the check fails; check whether the data content meets the business rule requirements, such as data value range, format specification, etc.; for example, for a field representing a quantity, if its value exceeds the preset maximum allowed value or is less than the minimum allowed value, the check fails.

[0065] Instruction permission check: according to the preset instruction permission list, check whether the instruction used in the current session is within the allowed permission range; if a certain instruction is not in the permission list or the current user / device does not have the execution permission of the instruction, the check fails.

[0066] Session behavior compliance check: check whether the behavior mode of the current session conforms to the preset normal mode; for example, whether the session duration exceeds the preset maximum allowed duration, whether the data transmission rate exceeds the preset maximum allowed rate, and if so, the check fails.

[0067] If the data content compliance check fails, perform content filtering operations, including sensitive information filtering, illegal instruction filtering, and abnormal behavior data filtering.

[0068] The above-mentioned filtering operation process includes:

[0069] Sensitive information filtering: for data containing sensitive information, data desensitization technology is adopted for processing;

[0070] Violation instruction filtering: for data containing violation instructions, the data packet is directly discarded, and a filtering log is recorded, including the source IP address, destination IP address, instruction code, filtering time, etc. of the data packet;

[0071] Abnormal behavior data filtering: for data with abnormal session behavior, such as high data transmission rate and long session duration, according to the preset filtering strategy, part of the data packet can be discarded or the current session can be interrupted, and relevant logs are recorded.

[0072] Further, S4 comprises:

[0073] Define the transmission format allowed to pass through the one-way optical gate, including the encapsulation header, data payload and encapsulation tail;

[0074] The transmission format is defined as follows:

[0075] Encapsulation header: contains version number, protocol identifier, data length, check code (used to check the integrity of the encapsulation header) and other fields;

[0076] Data payload: the original data after passing the compliance check;

[0077] Encapsulation tail: contains data integrity check code, encapsulation timestamp and other fields;

[0078] Calculate the CRC32 check code CRC of the original data as the data integrity check code of the encapsulation tail; data

[0079] Use the XOR check algorithm to XOR the bytes of each field in the header to get the check code CRC of the encapsulation header; header

[0080] Combine the encapsulation header, original data and encapsulation tail in order to form the encapsulated data unit Data;

[0081] Select the physical transmission link corresponding to the one-way optical gate, and use the flow control mechanism to control the data sending rate v according to the transmission bandwidth B of the one-way optical gate and the network status, so that v≤B, and the calculation formula of the data sending rate v is:

[0082] ;

[0083] Where, DataSize is the amount of data sent in the time interval T;

[0084] ​​The data units to be sent are numbered and sent in numerical order to ensure that the data is not out of order during transmission.

[0085] Furthermore, S5 includes:

[0086] A data receiving unit is deployed on the high-security side to receive encapsulated data units (Data) transmitted from the unidirectional optical gate in real time.

[0087] Extract the encapsulation header of the data unit and calculate the checksum of the encapsulation header. and the CRC recorded in the header header Perform a comparison; if If the encapsulation head is damaged, the data unit is discarded; if Check whether the version number in the encapsulation header is consistent with the version number supported by the high-security side, whether the protocol identifier is within the preset allowable range, and whether the data length does not exceed the preset maximum data unit length. If there is an abnormality, discard the data unit.

[0088] Extract the end of the data unit's encapsulation to obtain the CRC checksum. data And recalculate the CRC32 checksum on the original data. ;like If the original data is corrupted during transmission, the data unit is discarded; if If so, then data restructuring will be performed;

[0089] Based on the data unit number, the received data units are sorted in ascending order of number; the data payload of each sorted data unit is extracted, and the data payloads are spliced ​​together in order to form a complete original data stream.

[0090] Calculate the hash value of the received original data stream and compare it with the hash value of the original data stream provided by the sender before data transmission; if the hash values ​​before and after reception are consistent, the reassembly is considered successful; otherwise, the reassembly is considered to have failed.

[0091] The reassembled and verified original data stream is forwarded to the target system.

[0092] Furthermore, to better implement the above method, a private protocol transmission security management system based on a one-way communication device is also provided. This private protocol transmission security management system includes: a protocol parsing module, a protocol matching and security verification module, a data encapsulation and transmission module, and a data receiving and reassembly module.

[0093] The protocol parsing module, deployed on the low-security side of the unidirectional optical shutter, is used to perform deep inspection of outbound data streams, identify private protocols, and extract protocol features of the current session.

[0094] The protocol analysis module comprises a data acquisition unit, a data preprocessing unit, a protocol identification unit, and a feature extraction unit.

[0095] The data acquisition unit acquires the out-domain data stream flowing from the low-security side to the high-security side in real time, takes a data packet as a basic unit, and obtains the packet header information and data payload of the data packet.

[0096] The data preprocessing unit performs deduplication processing and fragmentation reorganization on the acquired data packet. The deduplication processing calculates the hash value of the data packet by using a hash algorithm to remove duplicate data packets. The fragmentation reorganization reorganizes fragmented data into complete data packets according to the IP fragmentation rule.

[0097] The protocol identification unit extracts the header data, payload data, and instruction code of the data packet, compares them with the private protocol feature library, calculates the header matching degree, payload matching degree, and instruction matching degree, and determines whether the data stream belongs to the private protocol by using a threshold value.

[0098] The feature extraction unit tracks the session process of the data stream identified as the private protocol, extracts the protocol features of the current session, including the header structure feature, payload format feature, instruction set feature, and session behavior pattern feature, and stores them as a feature vector.

[0099] Further, the protocol matching and security verification module comprises a feature matching unit, a compliance verification unit, and a content filtering unit.

[0100] The protocol matching and security verification module is configured to match the extracted protocol features with the private protocol feature library, and perform compliance verification and content filtering according to the security policy.

[0101] The feature matching unit calculates the cosine similarity between the current session protocol feature vector and each protocol feature vector in the private protocol feature library, determines whether the matching is successful by using a similarity threshold value, and marks it as an unknown protocol and triggers subsequent processing if the matching fails.

[0102] The compliance verification unit performs data content verification, instruction permission verification, and session behavior compliance verification on the session protocol that has passed the matching. The data content verification matches sensitive information by using a regular expression, checks the data value range and format specification, verifies the legality of the instruction by using a preset instruction permission list, and checks whether the session duration and data transmission rate exceed the preset range.

[0103] The content filtering unit performs filtering operations on the data that has failed the compliance verification, including filtering sensitive information by using data desensitization technology, directly discarding data packets containing illegal instructions, discarding abnormal behavior data or interrupting the session according to the filtering strategy, and recording the filtering log.

[0104] Further, the data encapsulation and transmission module comprises an encapsulation format definition unit, a check code calculation unit, a flow control unit and a data sending unit.

[0105] The data encapsulation and transmission module encapsulates data that passes the compliance check into a transmission format allowed by the unidirectional optical gate and sends the data to the high-security side through the unidirectional optical gate.

[0106] The encapsulation format definition unit defines the transmission format allowed by the unidirectional optical gate, which comprises an encapsulation header, a data payload and an encapsulation tail.

[0107] The check code calculation unit calculates the CRC32 check code of the original data as the data integrity check code and calculates the check code of the encapsulation header by using the exclusive or check algorithm.

[0108] The flow control unit controls the data sending rate according to the transmission bandwidth of the unidirectional optical gate and the network condition.

[0109] The data sending unit numbers the encapsulated data units and sends the data through the physical transmission link of the unidirectional optical gate in the numbered order.

[0110] Further, the data receiving and recombination module comprises a data receiving unit, a header check unit, a data integrity check unit and a data recombination unit.

[0111] The data receiving and recombination module is arranged at the high-security side and is used for receiving, checking and recombining the data transmitted from the unidirectional optical gate and forwarding the data to the target system.

[0112] The data receiving unit receives the encapsulated data units transmitted from the unidirectional optical gate in real time.

[0113] The header check unit extracts the encapsulation header of the data unit, calculates the header check code and compares the header check code with the recorded value, checks whether the version number, the protocol identifier and the data length meet the preset requirements, and discards the data unit if the requirements are not met.

[0114] The data integrity check unit extracts the data integrity check code of the encapsulation tail, recalculates the CRC32 check code of the original data and compares the check codes, and determines that the data is damaged and is discarded if the check codes are inconsistent.

[0115] The data recombination unit sorts the received data units according to the data unit numbers, splices the data payload to form a complete original data stream, compares the hash value with the hash value provided by the sender to verify the data consistency, and forwards the recombined data to the target system.

[0116] Compared with the prior art, the present application has the following beneficial effects:

[0117] 1. By extracting the communication characteristics of private protocols and constructing a feature library, combined with a multi-layer matching mechanism, accurate identification and deep detection of private protocols are realized, avoiding the security blind spot of traditional one-way light gates that only verify the underlying format.

[0118] 2. After successful matching, compliance verification and content filtering are performed to effectively prevent application layer attacks and data leakage, improving overall security.

[0119] 3. Through data encapsulation, checksum calculation, flow control, and high-security side data reorganization and integrity verification, the reliability and consistency of data transmission are ensured, while audit logs are recorded for subsequent tracing and analysis.

[0120] 4. Real-time monitoring of protocol behavior and session state, unknown protocols, abnormal characteristics, or behavior deviating from the preset mode triggers a security alarm and blocks transmission, forming an active defense mechanism to enhance the dynamic security protection capability of the network environment. BRIEF DESCRIPTION OF DRAWINGS

[0121] Figure 1 Method flowchart of the private protocol transmission security management system and method based on one-way communication device of the present application;

[0122] Figure 2 System structure diagram of the private protocol transmission security management system and method based on one-way communication device of the present application. DETAILED DESCRIPTION

[0123] Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.

[0124] Embodiment one: as shown, the present application provides a technical solution, a private protocol transmission security management method based on one-way communication device, which includes: Figure 1 S1. Extract the communication characteristics of private protocols, normalize the communication characteristics, and store them in the private protocol feature library;

[0125] S2. Deploy a protocol analysis engine on the low-security side of the one-way light gate to perform deep detection on the out-domain data stream and determine whether the data stream belongs to a private protocol; if it is identified as a private protocol, extract the protocol characteristics of the current session;

[0126] S3. Match the extracted protocol characteristics with the private protocol feature library; if the match is successful, perform compliance verification and content filtering on the data content according to the preset security policy; if the match fails, determine it as an unknown protocol and go to S6 for processing;

[0127] ​

[0128] S4. Encapsulate the data that has passed the compliance verification into a transmission format that allows it to pass through the one-way optical gate, and send it to the high-security side through the one-way optical gate;

[0129] S5. On the high-security side, the received data is reassembled and its integrity and consistency are verified; after the verification is passed, an audit log is recorded and forwarded to the target system;

[0130] S6. Monitor protocol behavior and session status in real time. If an unknown protocol, abnormal protocol characteristics, or session behavior deviates from the preset mode is detected, a security alarm will be triggered and the current transmission link will be blocked.

[0131] S1 includes:

[0132] The communication features include protocol header structure, payload structure, instruction set, and session behavior pattern;

[0133] Collect the header data included in the private protocol sample, denoted as H. i =(h i1 ,h i2 ,…,h ik ), where i = 1, 2, ..., N; k is the number of header fields; h i1 ,h i2 ,…,h ik These represent the values ​​of the 1st, 2nd, and kth header fields of the i-th private protocol sample, respectively.

[0134] Extract the feature parameters of each header field, including the field length L. ij Range of values ​​R ij =[min(h ij ),max(h ij )], Field type T ij ;

[0135] Payload data P for each private protocol sample i =(p i1 ,p i2 ,…,p im The parsing is performed, where m is the number of payload fields; p i1 ,p i2 ,…,p im These represent the values ​​of the 1st, 2nd, and mth payload fields of the i-th private protocol sample, respectively; the delimiter D of the payload field is obtained. i And extract the length M of each load field. ij Data type S ij Field meaning description Cij ;

[0136] Identify the instruction code I in each private protocol samplei = (i i1 , i2 …i in ), where n is the number of instructions, i i1 , i2 …i in represent the 1st, 2nd, mth instruction code of the ith private protocol sample; record the function description F ij , the number of instruction parameters Q ij , the parameter format G ij , and the execution response format H ij corresponding to each instruction code;

[0137] Collect session interaction data in each private protocol sample, including request R i1 , response R i2 , data transmission sequence, session closing request C i1 , response C i2 ;

[0138] Extract session behavior features, including session establishment time T is , session duration T id , data transmission rate V i , and session interaction times N i ;

[0139] Normalize the collected data;

[0140] Store the normalized communication features according to the protocol category, and construct a private protocol feature library;

[0141] Wherein, S2 includes:

[0142] Deploy the data collection unit on the low-security side of the one-way shutter, and collect the out-domain data stream flowing from the low-security side to the high-security side in real time; the collected data stream is in the form of data packets, and each data packet contains packet header information and data payload;

[0143] Preprocess the collected data packets;

[0144] Extract the header data of the data packet, and compare it with the header structure features of each protocol in the private protocol feature library; calculate the matching degree M h of the header field;

[0145] If a protocol i makes M h ≥ θ h , then it is preliminarily determined that the data packet belongs to protocol i;

[0146] For the data packet preliminarily determined to belong to protocol i, extract the payload data of the data packet, and parse it according to the payload format features of protocol i; detect whether the delimiter of the payload field is consistent with Di Consistency: Do the field lengths and data types of each load field conform to M? ij and S ij Requirements;

[0147] Calculate the matching degree M of the load format p If M p ≥θ p Then it is further determined that the data packet to be detected belongs to protocol i;

[0148] Extract the instruction code from the payload data, and match it with the instruction set I of protocol i. i Perform a comparison; check if the instruction code is in instruction set I. i The question arises: do the number and format of the instruction parameters conform to the requirements of the corresponding instruction? ij and G ij ;

[0149] Calculate the matching degree M of the instruction set i If M i ≥θ i If the data packet to be detected is determined to belong to protocol i, it is identified as a private protocol.

[0150] For data streams identified as private protocols, the session process corresponding to the data stream is tracked, and the protocol features of the current session are extracted, including session header structure features, payload format features, instruction set features, and session behavior pattern features. The extracted features are then stored as a feature vector F=(f1,f2,…,f t ), where t is the feature dimension;

[0151] S3 includes:

[0152] The extracted current session protocol feature vector F is compared with the feature vectors F of each protocol in the private protocol feature library. k =(f k1 ,f k2 ,…,f kt Similarity calculation is performed using the cosine similarity algorithm, with the following formula:

[0153] ;

[0154] Among them, f l f is the l-th feature value of the current session feature vector F. kl F is the k-th protocol feature vector in the private protocol feature library. k The l-th eigenvalue, Sim(F,F) k ) represents the cosine similarity between two feature vectors, with a value range of [0,1]. The closer the value is to 1, the higher the similarity.

[0155] Pre-set similarity threshold θs ; if Sim(F, F k ) ≥ θ s , it is determined that the current session protocol matches the protocol k in the private protocol feature library successfully; if Sim(F, F k ) < θ s for all protocols k, it is determined that the matching fails, the current session protocol is an unknown protocol, and the process goes to S6 for processing;

[0156] For the session protocol that matches successfully, the data content is checked for compliance according to a preset security policy; the compliance checking includes data content checking, instruction permission checking, and session behavior compliance checking.

[0157] If the data content compliance checking fails, a content filtering operation is performed, including sensitive information filtering, illegal instruction filtering, and abnormal behavior data filtering.

[0158] S4 includes the following steps:

[0159] A transmission format allowed to pass through the unidirectional optical shutter is defined, including a package header, data payload, and a package trailer.

[0160] A CRC32 check code CRC data of the original data is calculated as a data integrity check code of the package trailer.

[0161] An XOR check algorithm is used to perform XOR operation on the bytes of each field of the header to obtain a check code CRC header of the package header.

[0162] The package header, the original data, and the package trailer are combined in sequence to form a packaged data unit Data.

[0163] A physical transmission link corresponding to the unidirectional optical shutter is selected, a flow control mechanism is used, the data sending rate v is controlled according to the transmission bandwidth B of the unidirectional optical shutter and the network status, so that v ≤ B, and the transmitted data units are numbered and sent in the numbered order.

[0164] S5 includes the following steps:

[0165] A data receiving unit is deployed on the high-security side to receive the packaged data unit Data transmitted from the unidirectional optical shutter in real time.

[0166] The package header of the data unit is extracted, the check code CRC of the package header is calculated, and is compared with the CRC header recorded in the header; if , it is determined that the package header is damaged, and the data unit is discarded; if checking whether the version number in the encapsulation header is consistent with the version number supported by the high-security side, whether the protocol identifier is within the preset allowed range, and whether the data length exceeds the preset maximum data unit length, and discarding the data unit if there is an exception;

[0167] extracting an encapsulation tail of the data unit to obtain a data integrity check code CRC data and recalculating a CRC32 check code for the original data ; if , it is determined that the original data is damaged in the transmission process, and the data unit is discarded; if , data recombination is performed;

[0168] According to the number of the data unit, the received data units are sorted in ascending order of the number; the data payload of each data unit after sorting is extracted, and the data payloads are spliced in order to form a complete original data stream;

[0169] The hash value of the received original data stream is calculated and compared with the hash value of the original data stream provided by the sender before data transmission; if the hash values before and after receiving are consistent, it is determined that the recombination is successful; otherwise, it is determined that the recombination fails;

[0170] The recombined original data stream that passes the verification is forwarded to the target system;

[0171] Embodiment two: as shown in Figure 2 , wherein in order to better implement the above method, a private protocol transmission security management system based on a one-way communication device is also provided, which includes a protocol analysis module, a protocol matching and security check module, a data encapsulation and transmission module, and a data reception and recombination module.

[0172] The protocol analysis module is deployed on the low-security side of the one-way optical gate and is used for deep detection of the out-domain data stream, identification of the private protocol, and extraction of the protocol features of the current session.

[0173] The protocol analysis module includes a data acquisition unit, a data preprocessing unit, a protocol identification unit, and a feature extraction unit.

[0174] The data acquisition unit acquires the out-domain data stream flowing from the low-security side to the high-security side in real time, obtains the packet header information and data payload of the data packet as the basic unit, and performs deep detection on the out-domain data stream.

[0175] The data preprocessing unit performs deduplication processing and fragmentation recombination on the collected data packet; wherein the deduplication processing calculates the hash value of the data packet by using a hash algorithm to remove the duplicate data packet; and the fragmentation recombination recombines the fragmented data into a complete data packet according to the IP fragmentation rule.

[0176] The protocol identification unit extracts header data, payload data and instruction code of the data packet, compares with a private protocol feature library, calculates header matching degree, payload matching degree and instruction matching degree, and determines whether the data stream belongs to the private protocol through a threshold value;

[0177] The feature extraction unit tracks a session process of the data stream identified as the private protocol, extracts protocol features of the current session, including header structure features, payload format features, instruction set features and session behavior pattern features, and stores as a feature vector;

[0178] The protocol matching and security verification module includes a feature matching unit, a compliance verification unit and a content filtering unit.

[0179] The protocol matching and security verification module is configured to match the extracted protocol features with the private protocol feature library, and perform compliance verification and content filtering according to a security policy.

[0180] The feature matching unit calculates cosine similarity of the current session protocol feature vector and each protocol feature vector in the private protocol feature library, and determines whether the matching is successful through a similarity threshold value; if the matching fails, the data stream is marked as an unknown protocol and subsequent processing is triggered.

[0181] The compliance verification unit performs data content verification, instruction permission verification and session behavior compliance verification on the matched session protocol; the data content verification matches sensitive information by using a regular expression, and checks data value range and format specification; the instruction permission verification verifies instruction legality by using a preset instruction permission list; and the session behavior compliance verification checks whether the session duration and data transmission rate exceed a preset range.

[0182] The content filtering unit performs filtering operations on the data that fails the compliance verification, including filtering sensitive information by using a data desensitization technology, directly discarding data packets containing illegal instructions, discarding abnormal behavior data or interrupting a session according to a filtering strategy, and recording a filtering log.

[0183] The data encapsulation and transmission module includes an encapsulation format definition unit, a check code calculation unit, a flow control unit and a data sending unit.

[0184] The data encapsulation and transmission module is configured to encapsulate the data that passes the compliance verification into a transmission format allowed to pass through the unidirectional optical gate, and send the data to the high-security side through the unidirectional optical gate.

[0185] The encapsulation format definition unit defines the transmission format allowed to pass through the unidirectional optical gate, including an encapsulation header, data payload and an encapsulation tail.

[0186] A check code calculation unit calculates a CRC32 check code of the original data as a data integrity check code, and calculates a check code of the encapsulation header by using an exclusive or check algorithm;

[0187] A flow control unit controls a data sending rate according to a transmission bandwidth of the unidirectional optical shutter and a network condition;

[0188] A data sending unit numbers the encapsulated data unit, and sends the data through a physical transmission link of the unidirectional optical shutter according to the numbering order;

[0189] The data receiving and recombining module comprises a data receiving unit, a header check unit, a data integrity check unit and a data recombining unit.

[0190] The data receiving and recombining module is arranged on a high security side, and is used for receiving, checking and recombining data transmitted from the unidirectional optical shutter, and forwarding the data to a target system.

[0191] The data receiving unit receives the encapsulated data unit transmitted from the unidirectional optical shutter in real time.

[0192] The header check unit extracts the encapsulation header of the data unit, calculates a header check code and compares the header check code with a recorded value, checks whether a version number, a protocol identifier and a data length meet preset requirements, and discards the data unit if the data unit is abnormal.

[0193] The data integrity check unit extracts a data integrity check code of the encapsulation tail, recalculates a CRC32 check code of the original data, and compares the CRC32 check code with the data integrity check code, and discards the data if the data is damaged.

[0194] The data recombining unit sorts the received data unit according to the data unit number, splices a data payload to form a complete original data stream, calculates a hash value and compares the hash value with a hash value provided by a sending party, verifies data consistency, and forwards the data to the target system after successful recombination.

[0195] In the embodiment of the application, taking a certain power monitoring system as an example, a dispatching control center (low security side) needs to transmit telemetry data adopting a private protocol to a transformer substation production control area (high security side) through a unidirectional optical shutter; the system is arranged on both sides of the unidirectional optical shutter, and the specific implementation is as follows:

[0196] On the low security side, a protocol analysis engine collects a domain data stream in real time, identifies a private protocol session meeting preset characteristics through deep detection, and extracts a protocol feature vector of the private protocol session; the protocol analysis engine confirms that the session is a legal IEC 104 extended protocol by performing cosine similarity matching on the protocol feature vector with a pre-constructed private protocol feature library; then, the system performs compliance checking on data content according to a security policy, and filters out abnormal jump instructions contained in the data; the checked data is encapsulated into a specified format, and is sent through the unidirectional optical shutter;

[0197] On the high security side, the data receiving and reorganizing module performs header check, CRC integrity verification on the received data unit, and reorganizes into complete data stream according to the number; after the verified hash value is consistent, the data is recorded in the audit log and successfully forwarded to the station control system; during the whole process, the system monitors the session behavior in real time, no unknown protocol or abnormal rate appears, and the transmission link remains stable and safe.

[0198] Finally, it should be noted that: the above only for the preferred embodiments of the present application, and not for the purpose of limiting the present application, although the foregoing embodiments of the present application are described in detail, for those skilled in the art, it still can be modified, or part of the technical features of the equivalent replacement of the technical solutions recorded in the foregoing embodiments. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A security management method for private protocol transmission based on one-way communication device, characterized in that: The private protocol transmission security management method comprises: S1. Extracting communication characteristics of a private protocol, normalizing the communication characteristics, and storing them in a private protocol characteristic library; S2. Deploying a protocol analysis engine on the low-security side of a one-way optical shutter, performing deep detection on the out-domain data stream, and determining whether the data stream belongs to a private protocol; if it is identified as a private protocol, extracting the protocol characteristics of the current session; S3. Matching the extracted protocol characteristics with the private protocol characteristic library; if the matching is successful, performing compliance verification and content filtering on the data content according to a preset security policy; if the matching fails, determining that it is an unknown protocol, and proceeding to S6 for processing; S4. Encapsulating the data that passes the compliance verification into a transmission format allowed to pass through the one-way optical shutter, and sending it to the high-security side through the one-way optical shutter; S5. Reassembling the received data on the high-security side, and performing data integrity and consistency verification; after the verification passes, recording an audit log and forwarding it to the target system; S6. Real-time monitoring of protocol behavior and session state, if an unknown protocol, abnormal protocol characteristics or session behavior deviating from the preset mode are detected, triggering a security alarm and blocking the current transmission link.

2. The private protocol transmission security management method based on the one-way communication device according to claim 1, characterized in that: S1 comprises: The communication characteristics include protocol header structure, payload structure, instruction set, and session behavior mode; Collecting the header data included in the private protocol sample, denoted as H i = (h i1 , h i2 , …, h ik ), where i = 1, 2, …, N; k is the number of header fields; h i1 , h i2 , …, h ik respectively represent the values of the 1st, 2nd, kth header field of the i-th private protocol sample Extract the feature parameters of each header field, including field length L ij , value range R ij = [min(h ij ), max(h ij )], field type T ij ; Parsing the payload data P of each private protocol sample i = (p i1 ,p i2 ,…,p im ) where m is the number of payload fields; p i1 ,p i2 ,…,p im represent the 1st, 2nd, mth payload field value of the i-th private protocol sample respectively; obtaining the delimiter D i of the payload field, and extracting the length M ij , data type S ij , field meaning description Cij of each payload field; Identify instruction code I in each private protocol sample i = (i i1 , i2 …i in ) where n is the number of instructions, i i1 , i2 …i in is the 1st, 2nd, mth instruction code of the ith private protocol sample respectively; record the corresponding function description F ij , instruction parameter number Q ij , parameter format G ij , execution response format H ij ; Collecting session interaction data in each private protocol sample, including a setup request R i1 , a response R i2 , a data transfer sequence, a session close request C i1 , a response C i2 ; Extract the session behavior features, including session establishment time T is , session duration T id , data transmission rate V i , session interaction times N i ; The collected data is normalized; The normalized communication characteristics are classified and stored according to protocol categories, and a private protocol characteristic library is constructed.

3. The private protocol transmission security management method based on the one-way communication device according to claim 1, characterized in that: S2 comprises: Deploying a data collection unit on the low-security side of the one-way optical shutter, and collecting the out-domain data stream flowing from the low-security side to the high-security side in real time; The collected data stream is in the form of data packets, each data packet containing packet header information and data payload; The collected data packets are preprocessed; The header data of the data packets are extracted, and compared with the header structure characteristics of each protocol in the private protocol characteristic library; Calculating the match degree M of the header field h ; If a protocol i makes M h ≥ θ h then the packet is preliminarily determined to belong to protocol i; For data packets preliminarily determined to belong to protocol i, the payload data of the data packets are extracted, and parsed according to the payload format characteristics of protocol i; whether the delimiter of the payload field is consistent with D i whether the field length and data type of each payload field are consistent with the requirements of M ij and S ij ; the matching degree M of the computed load format p ; if M p ≥ θ p , then it is further determined that the data packet to be detected belongs to protocol i; Extracting instruction code from the load data, with the instruction set I of protocol i i Carrying out a comparison; detecting whether the instruction code exists in the instruction set I i , whether the number of instruction parameters and the parameter format meet the requirements Q of the corresponding instruction ij and G ij ; The matching degree M of the instruction set is calculated i If M i ≥ θ i , then the final determination is that the data packet to be detected belongs to protocol i, that is, it is identified as a private protocol; For data streams identified as private protocols, the protocol characteristics of the current session are extracted by tracking the session process corresponding to the data stream; The session includes a header structure feature, a payload format feature, an instruction set feature, a session behavior pattern feature, and the extracted features are stored as a feature vector F = (f1, f2, …, ft), where t is a feature dimension. t ) 4. The private protocol transmission security management method based on the one-way communication device according to claim 1, characterized in that: S3 comprises: The extracted current session protocol feature vector F is compared with the feature vectors F of various protocols in the private protocol feature library k =(f k1 ,f k2 ,…,f kt ) for similarity calculation; the cosine similarity algorithm is adopted, and the formula is as follows: ; wherein f l is the lth eigenvalue of the current session feature vector F, f kl is the lth eigenvalue of the kth protocol feature vector F k in the private protocol feature library, Sim(F, F k ) is the cosine similarity of the two feature vectors, with a value range of [0, 1], and the closer the value is to 1, the higher the similarity is. Pre-set similarity threshold θ s ; if Sim(F, F k ) ≥ θ s , it is determined that the current session protocol matches the protocol k in the private protocol feature library successfully; if Sim(F, F k ) < θ s for all protocols k, it is determined that the matching fails, the current session protocol is an unknown protocol, and the process goes to S6. For the matched session protocol, the data content is verified for compliance according to a preset security policy; the compliance verification includes data content verification, instruction authority verification, and session behavior compliance verification; If the data content compliance verification fails, a content filtering operation is performed, including sensitive information filtering, illegal instruction filtering, and abnormal behavior data filtering.

5. The private protocol transmission security management method based on the one-way communication device according to claim 1, characterized in that: S4 comprises: Defining a transmission format allowed to pass through the one-way optical shutter, including an encapsulation header, data payload, and an encapsulation trailer; calculating a CRC32 check code CRC of the original data data as a data integrity check code of the encapsulation tail The XOR check algorithm is used to perform XOR operation on the bytes of each field of the header to obtain the check code CRC of the encapsulation header header ; Combining the encapsulation header, the original data, and the encapsulation trailer in sequence to form an encapsulated data unit Data; Selecting a physical transmission link corresponding to the one-way optical shutter, using a flow control mechanism, controlling the data sending rate v according to the transmission bandwidth B of the one-way optical shutter and the network status, so that v≤B, and numbering the sent data units and sending them in the order of the numbers.

6. The private protocol transmission security management method based on the one-way communication device according to claim 1, characterized in that: S5 comprises: Deploying a data receiving unit on the high-security side to receive the encapsulated data unit Data transmitted from the one-way optical shutter in real time; Extract the encapsulation header of the data unit and calculate the checksum of the encapsulation header. and the CRC recorded in the header header Perform a comparison; if If the encapsulation head is damaged, the data unit is discarded; if Check whether the version number in the encapsulation header is consistent with the version number supported by the high-security side, whether the protocol identifier is within the preset allowable range, and whether the data length does not exceed the preset maximum data unit length. If there is an abnormality, discard the data unit. extracting the encapsulation tail of the data unit, obtaining a data integrity check code CRC data and recalculating a CRC32 check code for the original data ; if , it is determined that the original data is damaged in the transmission process, and the data unit is discarded; if , data reassembly is performed; According to the number of data units, the received data units are sorted in ascending order of the number; the data payload of each data unit after sorting is extracted, and the data payloads are spliced in order to form a complete original data stream; The hash value of the received original data stream is calculated and compared with the hash value of the original data stream provided by the sender before data transmission; If the hash values before and after receiving are consistent, it is determined that the reorganization is successful; otherwise, it is determined that the reorganization fails; The reorganized and verified original data stream is forwarded to the target system.

7. A system for secure management of private protocol transmissions based on unidirectional communication devices for performing the method for secure management of private protocol transmissions based on unidirectional communication devices according to any one of claims 1 to 6, characterized in that: The private protocol transmission management system comprises a protocol analysis module, a protocol matching and security verification module, a data encapsulation and transmission module, and a data reception and reorganization module. The protocol analysis module is deployed on the low-security side of the one-way optical gate and is used for deep detection of the out-domain data stream, identification of the private protocol, and extraction of the protocol features of the current session. The protocol analysis module comprises a data acquisition unit, a data preprocessing unit, a protocol identification unit, and a feature extraction unit. The data acquisition unit acquires the out-domain data stream flowing from the low-security side to the high-security side in real time, takes the data packet as the basic unit, and obtains the packet header information and data payload of the data packet. The data preprocessing unit performs deduplication processing and fragmentation reorganization on the collected data packet; wherein the deduplication processing calculates the hash value of the data packet by using a hash algorithm to remove duplicate data packets; and the fragmentation reorganization reorganizes the fragmented data into a complete data packet according to the IP fragmentation rule. The protocol identification unit extracts the header data, payload data, and instruction code of the data packet, compares them with the private protocol feature library, calculates the header matching degree, payload matching degree, and instruction matching degree, and determines whether the data stream belongs to the private protocol by a threshold value. The feature extraction unit tracks the session process of the data stream identified as the private protocol, extracts the protocol features of the current session, including the header structure feature, payload format feature, instruction set feature, and session behavior pattern feature, and stores them as a feature vector.

8. The private protocol transmission security management system based on one-way communication device according to claim 7, characterized in that: The protocol matching and security verification module comprises a feature matching unit, a compliance verification unit, and a content filtering unit. The protocol matching and security verification module is used for matching the extracted protocol features with the private protocol feature library, and performing compliance verification and content filtering according to the security policy. The feature matching unit calculates the cosine similarity of the current session protocol feature vector and each protocol feature vector in the private protocol feature library, determines whether the matching is successful by a similarity threshold value; if the matching fails, it is marked as an unknown protocol and triggers subsequent processing. The compliance verification unit performs data content verification, instruction permission verification, and session behavior compliance verification on the session protocol matched successfully; wherein the data content verification matches sensitive information by using a regular expression, and checks the data value range and format specification; the instruction permission verification verifies the legality of the instruction by a preset instruction permission list; and the session behavior compliance verification checks whether the session duration and data transmission rate exceed the preset range. The content filtering unit performs filtering operation on data that fails the compliance check, including sensitive information filtering using data desensitization technology, discarding data packets containing illegal instructions directly, discarding abnormal behavior data or interrupting sessions according to filtering strategies, and recording filtering logs.

9. The private protocol transmission security management system based on one-way communication device according to claim 7, characterized in that: The data packaging and transmission module comprises a packaging format definition unit, a check code calculation unit, a flow control unit and a data sending unit. The data packaging and transmission module is configured to package data that passes the compliance check into a transmission format allowed to pass through the unidirectional optical gate, and send the data to the high-security side through the unidirectional optical gate. The packaging format definition unit defines the transmission format allowed to pass through the unidirectional optical gate, including a packaging header, data payload and a packaging tail. The check code calculation unit calculates the CRC32 check code of the original data as the data integrity check code, and calculates the check code of the packaging header using the exclusive or check algorithm. The flow control unit controls the data sending rate according to the transmission bandwidth of the unidirectional optical gate and the network condition. The data sending unit numbers the packaged data units, and sends the data through the physical transmission link of the unidirectional optical gate in the order of the number.

10. The private protocol transmission security management system based on one-way communication device according to claim 7, characterized in that: The data receiving and recombination module comprises a data receiving unit, a header check unit, a data integrity check unit and a data recombination unit. The data receiving and recombination module is deployed at the high-security side, and is configured to receive, check and recombine the data transmitted from the unidirectional optical gate, and forward the data to the target system. The data receiving unit receives the packaged data units transmitted from the unidirectional optical gate in real time. The header check unit extracts the packaging header of the data unit, calculates the header check code and compares it with the recorded value, checks whether the version number, protocol identifier and data length meet the preset requirements, and discards the data unit if abnormal. The data integrity check unit extracts the data integrity check code of the packaging tail, recalculates the CRC32 check code of the original data and compares it, and discards the data if the check codes are inconsistent. The data recombination unit sorts the received data units according to the data unit number, splices the data payload to form a complete original data stream, calculates the hash value and compares it with the hash value provided by the sender to verify the data consistency, and forwards the recombined data to the target system.

Citation Information

Patent Citations

  • Intelligent mine network situation awareness system based on network security management

    CN116896462A

  • Connection gateway for communicating monitoring and control information between a remotely located mobile device and premises devices / appliances on a premises network

    US20190058720A1