Cross-domain traffic early warning method based on strategy fingerprint and digital twinning

CN122339990APending Publication Date: 2026-07-03HANGZHOU UNIV OF ELECTRONIC SCI & TECH PINGHU DIGITAL TECH INNOVATION RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU UNIV OF ELECTRONIC SCI & TECH PINGHU DIGITAL TECH INNOVATION RES INST CO LTD
Filing Date
2026-04-23
Publication Date
2026-07-03

Smart Images

  • Figure CN122339990A_ABST
    Figure CN122339990A_ABST
Patent Text Reader

Abstract

This invention discloses a cross-domain traffic early warning method based on policy fingerprints and digital twins, belonging to the field of network traffic monitoring. The method includes: collecting cross-domain multi-source network data from historical periods and real-time runtime; extracting long-term policy features of autonomous systems based on historical data to construct a historical policy fingerprint database and a digital twin; continuously monitoring real-time network behavior based on real-time runtime data, identifying deviations in real-time network behavior relative to historical policy fingerprints, and filtering suspicious drift events using semantic reasoning mechanisms; inputting suspicious drift events into the digital twin for subsequent propagation and evolution simulation, calculating early risk scores; and dynamically correcting the policy fingerprint database and digital twin. This invention effectively alleviates the problems of delayed early warning, high false alarm rates, and difficulty in characterizing abnormal evolution processes, improving the accuracy, stability, and robustness of early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network traffic monitoring, specifically relating to a cross-domain traffic early warning method based on policy fingerprinting and digital twins. Background Technology

[0002] Cross-domain network traffic monitoring is a crucial foundation for ensuring the security of internet operations. Its ability to identify problems such as abnormal propagation, route leakage, and traffic hijacking in advance affects the stability and reliability of network services.

[0003] Existing anomaly detection methods mostly rely on traffic characteristics at a single moment, lacking the ability to characterize the long-term stable behavior patterns of autonomous systems. They are difficult to distinguish between normal strategy adjustments and potential anomaly evolution processes, and are prone to problems such as delayed early warning and high false alarm rates. Summary of the Invention

[0004] The purpose of this invention is to provide a cross-domain traffic early warning method based on policy fingerprinting and digital twins, in order to solve the problems of existing anomaly detection methods lacking the characterization of the long-term stable behavior patterns of autonomous systems, making it difficult to distinguish between normal policy adjustments and potential anomaly evolution processes, and easily resulting in early warning lag and high false alarm rates.

[0005] To achieve the above objectives, the technical solution of the present invention is as follows:

[0006] This invention relates to a cross-domain traffic early warning method based on policy fingerprinting and digital twins, which includes the following steps:

[0007] S1. Collect cross-domain multi-source network data for historical time periods and real-time runtime periods;

[0008] S2. Extract long-term policy features of the autonomous system based on historical data, construct a historical policy fingerprint database based on the long-term policy features, and establish a digital twin that can reflect the real network operation status.

[0009] S3. Based on real-time runtime data, continuously monitor real-time network behavior, identify the deviation of real-time network behavior relative to historical policy fingerprints, filter out policy drift candidate events, and combine semantic reasoning mechanism to eliminate normal operation and maintenance disturbances to form suspicious drift events.

[0010] S4. Input the suspicious drift event into the digital twin, and the digital twin will simulate and extrapolate the subsequent propagation and evolution of the suspicious drift event, and calculate the early risk score by comprehensively considering multiple influencing factors.

[0011] Preferably, the multi-source network data collected in S1 during historical periods and real-time runtime periods includes at least routing control data, traffic observation data, network affiliation data, and data related to network interconnection and switching nodes.

[0012] Preferably, after S1 collects cross-domain multi-source network data from historical time periods and real-time runtime periods, the collected data is further subjected to standardization cleaning, time synchronization, and multi-source correlation processing. The specific steps are as follows:

[0013] S1.1. Perform unified format conversion, field normalization, missing value handling, and outlier cleaning on the collected multi-source data to form a standardized data set with consistent structure and unified semantics;

[0014] S1.2. Time alignment is performed on data from different sources, and cross-source mapping is completed based on autonomous systems, prefixes, links, and organizational identifiers to achieve multi-source association processing and then construct a fused data view.

[0015] Preferably, the specific steps of S2 are as follows:

[0016] S2.1. For each autonomous system or combination of autonomous system and prefix exit, extract long-term stable routing output pattern and traffic carrying pattern to form a long-term strategy feature set including routing propagation characteristics, prefix diffusion characteristics, path distribution characteristics, temporal behavior characteristics and traffic carrying characteristics;

[0017] S2.2. Based on the long-term policy feature set, extract the statistics of route propagation, prefix diffusion, path distribution, temporal behavior and traffic carrying capacity respectively, normalize and uniformly encode each statistic, and combine them in a set order to form a historical policy fingerprint.

[0018] S2.3. Vectorize and numerically represent the historical strategy fingerprint to obtain the historical strategy fingerprint vector, and extract the corresponding behavioral labels and semantic keywords based on the historical strategy fingerprint vector, and generate the corresponding semantic description template.

[0019] S2.4. A network topology with autonomous systems as nodes and inter-autonomous systems as edges is constructed using a fused data view. Based on the routing propagation direction, path connection characteristics, organizational affiliation information, and interconnection information of exchange nodes, the relationship types and confidence levels between autonomous systems are inferred to obtain the relationship inference results.

[0020] S2.5. Based on the network topology, relationship inference results, prefix exit status, current traffic carrying status, and policy fingerprint, assign status attributes to the corresponding nodes and edges to construct a digital twin of autonomous system relationships; wherein, the current traffic carrying status is obtained by real-time traffic observation data after time alignment, link or autonomous system mapping, and statistical summarization.

[0021] Preferably, the specific steps of S3 are as follows:

[0022] S3.1. For network data during real-time runtime, extract real-time behavioral feature vectors related to route updates and traffic changes, and calculate the policy offset degree of the real-time behavioral feature vectors relative to the corresponding historical policy fingerprints. The formula for calculating the policy offset degree is as follows:

[0023] ,

[0024] in, Indicates the first An object at time The policy offset, For the first An object at time Real-time behavioral feature vectors, Indicates the first The historical strategy fingerprint vector corresponding to each object;

[0025] S3.2. If the policy deviation exceeds a preset threshold, mark it as a policy drift candidate event;

[0026] S3.3. Input the topology information, historical behavior, relational attributes and traffic change information of the policy drift candidate events into the semantic reasoning module to determine whether the cause of the policy drift is normal operation and maintenance disturbance. If so, remove the corresponding policy drift candidate events; if not, determine that there is potential abnormal propagation.

[0027] Preferably, the specific steps of S4 are as follows:

[0028] S4.1. Inject suspicious drift events into the digital twin, and simulate and extrapolate their propagation path, scope of influence, and evolution trend over multiple subsequent time windows. The state evolution process of the digital twin is defined as follows:

[0029] ,

[0030] in, For digital twins at all times state, This refers to the state of the digital twin at the next moment or within the next projected time window. Indicates at time Inputting suspicious drift events into the digital twin. The state evolution function of the digital twin is used to update the state at the next time step based on the current state and input events;

[0031] S4.2. Based on the digital twin simulation results, and taking into account the strategy shift intensity, the scale of the impact prefix, the scope of the affected autonomous system, the traffic capacity, the simulation propagation depth, and the stability of the relationship confidence, an early risk score is calculated for each suspicious event. The early risk score is calculated using the following formula:

[0032] ,

[0033] in, Indicates the first Early risk scoring of suspicious events, Indicates the first The weighting coefficients of each risk factor, Indicates the first The event corresponding to the 1st One normalized risk factor.

[0034] Preferably, S4 is followed by S5: outputting graded early warning results based on risk scores, and dynamically correcting the strategy fingerprint database and digital twin through post-hoc linkage verification.

[0035] Preferably, the specific steps of S5 in dynamically correcting the strategy fingerprint database and digital twin are as follows:

[0036] S5.1. Based on the risk score, output three levels of early warning results: low risk, medium risk, and high risk, and simultaneously output information on abnormal objects, scope, behavioral characteristics, potential abnormal types, scope of impact, and suggested investigation paths;

[0037] S5.2. Perform joint verification for high-risk events, including: verifying the propagation direction, affected prefixes, and scope of the suspicious events based on subsequent routing changes; verifying the path recovery status and prefix exit switching status based on convergence behavior; and verifying the traffic carrying capacity changes of relevant autonomous systems or links based on traffic changes.

[0038] S5.3. Based on the linkage verification results, update the policy fingerprint database. For events verified as normal policy adjustments or temporary load migrations, write their verified behavioral characteristics into the corresponding policy fingerprint database. The update process can be represented as follows:

[0039] ,

[0040] in, Indicates the number before the update The policy fingerprint vector corresponding to each object Indicates the updated number The policy fingerprint vector corresponding to each object Indicates the first The behavior feature vector of an object after linkage verification. This represents the update coefficients, and 0 ≤ ≤1;

[0041] S5.4. Based on the linkage verification results, update the state of the digital twin. For events verified as normal policy adjustments or temporary load migrations, synchronously correct the relevant states in the digital twin. For events verified as abnormal propagation, abnormal transfer, hijacking, or leakage events, retain their abnormal markers and update the risk state and relationship confidence state in the digital twin. The update process of the digital twin state can be expressed as follows:

[0042] ,

[0043] in, This indicates the state of the digital twin before the update. This indicates the updated state of the digital twin. Indicates the first The linkage verification results corresponding to each event This represents an update function that corrects the state of the digital twin based on the results of the linkage verification.

[0044] Compared with the prior art, the technical solution provided by this invention has the following advantages:

[0045] 1. The cross-domain traffic early warning method based on policy fingerprinting and digital twins involved in this invention constructs a long-term stable behavioral fingerprint of an autonomous system and combines it with a digital twin to dynamically deduce the abnormal propagation path, impact range, and evolution trend. Without relying on a single static feature for discrimination, it can achieve early identification and hierarchical early warning of cross-domain network anomalies. It can maintain high early warning accuracy, timeliness, and interpretability in complex network environments. The output results have both risk discrimination capabilities and auxiliary analysis value. It can effectively alleviate the problems of early warning lag, high false alarm rate, and difficulty in characterizing the abnormal evolution process of existing methods, and improve the engineering application capabilities of cross-domain network traffic anomaly monitoring and security protection.

[0046] 2. The cross-domain traffic early warning method based on policy fingerprints and digital twins involved in this invention performs linkage verification for high-risk events after risk assessment. The linkage verification includes comprehensive verification of subsequent routing changes, convergence behavior, traffic changes and active detection results, and updates the policy fingerprint database and digital twin status according to the linkage verification results, thereby further improving the accuracy, stability and robustness of early warning of subsequent cross-domain network traffic anomalies. Attached Figure Description

[0047] Figure 1 This is a flowchart of a cross-domain traffic early warning method based on policy fingerprinting and digital twins. Detailed Implementation

[0048] To further understand the content of the present invention, the present invention will be described in detail with reference to the embodiments. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.

[0049] See attached document Figure 1 As shown, this invention relates to a cross-domain traffic early warning method based on policy fingerprinting and digital twins, which includes the following steps:

[0050] S1. Collect cross-domain, multi-source network data from historical periods and real-time runtime periods, including at least routing control data, traffic observation data, network affiliation data, and data related to network interconnection and switching nodes; and perform standardized cleaning, time synchronization, and multi-source correlation processing on the collected data. The specific steps are as follows:

[0051] S1.1. Perform unified format conversion, field normalization, missing value handling, and outlier cleaning on the collected multi-source data to form a standardized data set with consistent structure and unified semantics, which is a common practice in this field;

[0052] S1.2. Time alignment is performed on data from different sources, and cross-source mapping is completed based on autonomous systems, prefixes, links, and organizational identifiers to achieve multi-source association processing and then construct a fused data view.

[0053] S2. Extract long-term policy features of the autonomous system based on historical data, construct a historical policy fingerprint database based on the long-term policy features, and establish a digital twin that can reflect the real network operation status. The specific steps are as follows:

[0054] S2.1. For each autonomous system or combination of autonomous system and prefix exit, extract long-term stable routing output pattern and traffic carrying pattern to form a long-term strategy feature set including routing propagation characteristics, prefix diffusion characteristics, path distribution characteristics, temporal behavior characteristics and traffic carrying characteristics;

[0055] S2.2. Based on the long-term policy feature set, extract the statistics of route propagation, prefix diffusion, path distribution, temporal behavior and traffic carrying capacity respectively, normalize and uniformly encode each statistic, and combine them in a set order to form a historical policy fingerprint.

[0056] S2.3. Vectorize and numerically represent the historical strategy fingerprint to obtain the historical strategy fingerprint vector, and extract the corresponding behavioral labels and semantic keywords based on the historical strategy fingerprint vector, and generate the corresponding semantic description template.

[0057] S2.4. A network topology with autonomous systems as nodes and inter-autonomous systems as edges is constructed using a fused data view. Based on the routing propagation direction, path connection characteristics, organizational affiliation information, and interconnection information of exchange nodes, the relationship types and confidence levels between autonomous systems are inferred to obtain the relationship inference results.

[0058] S2.5. Based on the network topology, relationship inference results, prefix exit status, current traffic carrying status, and policy fingerprint, assign status attributes to the corresponding nodes and edges to construct a digital twin of autonomous system relationships; wherein, the current traffic carrying status is obtained by real-time traffic observation data after time alignment, link or autonomous system mapping, and statistical summarization.

[0059] S3. Based on real-time runtime data, continuously monitor real-time network behavior, identify the deviation of real-time network behavior relative to historical policy fingerprints, filter out policy drift candidate events, and use semantic reasoning mechanisms to eliminate normal operational disturbances, forming suspicious drift events. The specific steps are as follows:

[0060] S3.1. For network data during real-time runtime, extract real-time behavioral feature vectors related to route updates and traffic changes, and calculate the policy offset degree of the real-time behavioral feature vectors relative to the corresponding historical policy fingerprints. The formula for calculating the policy offset degree is as follows:

[0061] ,

[0062] in, Indicates the first An object at time The policy offset, For the first An object at time Real-time behavioral feature vectors, Indicates the first The historical strategy fingerprint vector corresponding to each object;

[0063] S3.2. If the policy deviation exceeds a preset threshold, mark it as a policy drift candidate event;

[0064] S3.3. Input the topology information, historical behavior, relational attributes and traffic change information of the policy drift candidate events into the semantic reasoning module to determine whether the cause of the policy drift is normal operation and maintenance disturbance, such as reasonable policy adjustment or temporary load migration; if so, remove the corresponding policy drift candidate events; if not, it may be suspicious propagation, suspicious abnormal transfer and potential hijacking or leakage precursors, and is determined to be a potential abnormal propagation.

[0065] S4. Input the suspected drift event into the digital twin, which will then simulate and extrapolate the subsequent propagation and evolution of the suspected drift event, and calculate an early risk score by comprehensively considering multiple influencing factors. The specific steps are as follows:

[0066] S4.1. Inject the suspected drift event into the digital twin, and simulate and extrapolate its propagation path, impact range, and evolution trend within multiple subsequent time windows to analyze the subsequent impact of the event on network relationship status, prefix diffusion status, and traffic carrying capacity status. The state evolution process of the digital twin is defined as follows:

[0067] ,

[0068] in, For digital twins at all times state, This refers to the state of the digital twin at the next moment or within the next projected time window. Indicates at time Inputting suspicious drift events into the digital twin. The state evolution function of the digital twin is used to update the state at the next time step based on the current state and input events;

[0069] S4.2. Based on the digital twin simulation results, and taking into account the strategy shift intensity, the scale of the impact prefix, the scope of the affected autonomous system, the traffic capacity, the simulation propagation depth, and the stability of the relationship confidence, an early risk score is calculated for each suspicious event. The early risk score is calculated using the following formula:

[0070] ,

[0071] in, Indicates the first Early risk scoring of suspicious events, Indicates the first The weighting coefficients of each risk factor, Indicates the first The event corresponding to the 1st One normalized risk factor.

[0072] The early risk scores were normalized to make Let the low-risk threshold be... The high-risk threshold is And satisfy Then when When, it is judged as low risk; when When, it is judged as medium risk; when At this point, it is determined to be high-risk. Based on the risk score, a tiered early warning result can be output, including low-risk, medium-risk, and high-risk warnings.

[0073] S5. Dynamically correct the policy fingerprint database and digital twin through post-hoc linkage verification. The specific steps are as follows:

[0074] S5.1. Based on the risk score, output three levels of early warning results: low risk, medium risk, and high risk, and simultaneously output information such as abnormal objects, scope of involvement, behavioral characteristics, potential abnormal types, scope of impact, and suggested investigation paths;

[0075] S5.2. Perform joint verification for high-risk events. The joint verification includes: verifying the propagation direction, affected prefix and scope of the suspicious event based on subsequent routing changes; verifying the path recovery status and prefix exit switching status based on convergence behavior; verifying the traffic carrying capacity changes of relevant autonomous systems or links based on traffic changes; and, when necessary, combining the results of active detection to perform comprehensive verification of the event.

[0076] S5.3. Based on the linkage verification results, update the policy fingerprint database. For events verified as normal policy adjustments or temporary load migrations, write their verified behavioral characteristics into the corresponding policy fingerprint database. The update process can be represented as follows:

[0077] ,

[0078] in, Indicates the number before the update The policy fingerprint vector corresponding to each object Indicates the updated number The policy fingerprint vector corresponding to each object Indicates the first The behavior feature vector of an object after linkage verification. This represents the update coefficients, and 0 ≤ ≤1;

[0079] S5.4. Based on the linkage verification results, update the state of the digital twin. For events verified as normal policy adjustments or temporary load migrations, synchronously correct the relevant states in the digital twin. For events verified as abnormal propagation, abnormal transfer, hijacking, or leakage events, retain their abnormal markers and update the risk state and relationship confidence state in the digital twin. The update process of the digital twin state can be expressed as follows:

[0080] ,

[0081] in, This indicates the state of the digital twin before the update. This indicates the updated state of the digital twin. Indicates the first The linkage verification results corresponding to each event This represents an update function that corrects the state of the digital twin based on the results of the linkage verification.

[0082] The present invention has been described in detail above with reference to the embodiments, but the content described is only a preferred embodiment of the present invention and should not be considered as limiting the scope of the present invention. All equivalent changes and improvements made in accordance with the scope of the present invention should still fall within the patent coverage of the present invention.

Claims

1. A cross-domain traffic early warning method based on policy fingerprinting and digital twins, characterized in that, It includes the following steps: S1. Collect cross-domain multi-source network data for historical time periods and real-time runtime periods; S2. Extract long-term policy features of the autonomous system based on historical data, construct a historical policy fingerprint database based on the long-term policy features, and establish a digital twin that can reflect the real network operation status. S3. Based on real-time runtime data, continuously monitor real-time network behavior, identify the deviation of real-time network behavior relative to historical policy fingerprints, filter out policy drift candidate events, and combine semantic reasoning mechanism to eliminate normal operation and maintenance disturbances to form suspicious drift events. S4. Input the suspicious drift event into the digital twin, and the digital twin will simulate and extrapolate the subsequent propagation and evolution of the suspicious drift event, and calculate the early risk score by comprehensively considering multiple influencing factors.

2. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 1, characterized in that: The multi-source network data collected in S1 during historical periods and real-time runtime periods includes at least routing control data, traffic observation data, network affiliation data, and data related to network interconnection and switching nodes.

3. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 1, characterized in that: After S1 collects cross-domain multi-source network data from historical time periods and real-time runtime periods, it also performs standardized cleaning, time synchronization, and multi-source correlation processing on the collected data. The specific steps are as follows: S1.

1. Perform unified format conversion, field normalization, missing value handling, and outlier cleaning on the collected multi-source data to form a standardized data set with consistent structure and unified semantics; S1.

2. Time alignment is performed on data from different sources, and cross-source mapping is completed based on autonomous systems, prefixes, links, and organizational identifiers to achieve multi-source association processing and then construct a fused data view.

4. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 3, characterized in that: The specific steps of S2 are as follows: S2.

1. For each autonomous system or combination of autonomous system and prefix exit, extract long-term stable routing output pattern and traffic carrying pattern to form a long-term strategy feature set including routing propagation characteristics, prefix diffusion characteristics, path distribution characteristics, temporal behavior characteristics and traffic carrying characteristics; S2.

2. Based on the long-term policy feature set, extract the statistics of route propagation, prefix diffusion, path distribution, temporal behavior and traffic carrying capacity respectively, normalize and uniformly encode each statistic, and combine them in a set order to form a historical policy fingerprint. S2.

3. Vectorize and numerically represent the historical strategy fingerprint to obtain the historical strategy fingerprint vector, and extract the corresponding behavioral labels and semantic keywords based on the historical strategy fingerprint vector, and generate the corresponding semantic description template. S2.

4. A network topology with autonomous systems as nodes and inter-autonomous systems as edges is constructed using a fused data view. Based on the routing propagation direction, path connection characteristics, organizational affiliation information, and interconnection information of exchange nodes, the relationship types and confidence levels between autonomous systems are inferred to obtain the relationship inference results. S2.

5. Based on the network topology, relationship inference results, prefix exit status, current traffic carrying status, and policy fingerprint, assign status attributes to the corresponding nodes and edges to construct a digital twin of autonomous system relationships; wherein, the current traffic carrying status is obtained by real-time traffic observation data after time alignment, link or autonomous system mapping, and statistical summarization.

5. The cross-domain traffic early warning method based on policy fingerprinting and digital twin as described in claim 1, characterized in that: The specific steps of S3 are as follows: S3.

1. For network data during real-time runtime, extract real-time behavioral feature vectors related to route updates and traffic changes, and calculate the policy offset degree of the real-time behavioral feature vectors relative to the corresponding historical policy fingerprints. The formula for calculating the policy offset degree is as follows: , in, Indicates the first An object at time The policy offset, For the first An object at time Real-time behavioral feature vectors Indicates the first The historical strategy fingerprint vector corresponding to each object; S3.

2. If the policy deviation exceeds a preset threshold, mark it as a policy drift candidate event; S3.

3. Input the topology information, historical behavior, relational attributes and traffic change information of the policy drift candidate events into the semantic reasoning module to determine whether the cause of the policy drift is normal operation and maintenance disturbance. If so, remove the corresponding policy drift candidate events; if not, determine that there is potential abnormal propagation.

6. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 1, characterized in that: The specific steps of S4 are as follows: S4.

1. Inject suspicious drift events into the digital twin, and simulate and extrapolate their propagation path, scope of influence, and evolution trend over multiple subsequent time windows. The state evolution process of the digital twin is defined as follows: , in, For digital twins at all times state, This refers to the state of the digital twin at the next moment or within the next projected time window. Indicates at time Inputting suspicious drift events into the digital twin. The state evolution function of the digital twin is used to update the state at the next time step based on the current state and input events; S4.

2. Based on the digital twin simulation results, and taking into account the strategy shift intensity, the scale of the impact prefix, the scope of the affected autonomous system, the traffic capacity, the simulation propagation depth, and the stability of the relationship confidence, an early risk score is calculated for each suspicious event. The early risk score is calculated using the following formula: , in, Indicates the first Early risk scoring of suspicious events, Indicates the first The weighting coefficients of each risk factor Indicates the first The event corresponding to the th event One normalized risk factor.

7. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 1, characterized in that: The S4 is followed by S5: outputting graded early warning results based on risk scores, and dynamically correcting the strategy fingerprint database and digital twin through post-hoc linkage verification.

8. The cross-domain traffic early warning method based on policy fingerprinting and digital twins according to claim 7, characterized in that: The specific steps of S5 in dynamically correcting the policy fingerprint database and digital twin are as follows: S5.

1. Based on the risk score, output three levels of early warning results: low risk, medium risk, and high risk, and simultaneously output information on abnormal objects, scope, behavioral characteristics, potential abnormal types, scope of impact, and suggested investigation paths; S5.

2. Perform joint verification for high-risk events. The joint verification includes: verifying the propagation direction, affected prefix and scope of the suspicious event based on subsequent routing changes; verifying the path recovery status and prefix exit switching status based on convergence behavior; and verifying the traffic carrying capacity changes of relevant autonomous systems or links based on traffic changes. S5.

3. Based on the linkage verification results, update the policy fingerprint database. For events verified as normal policy adjustments or temporary load migrations, write their verified behavioral characteristics into the corresponding policy fingerprint database. The update process can be represented as follows: , in, Indicates the number before the update The policy fingerprint vector corresponding to each object Indicates the updated number The policy fingerprint vector corresponding to each object Indicates the first The behavior feature vector of an object after linkage verification. This represents the update coefficients, and 0 ≤ ≤1; S5.

4. Based on the linkage verification results, update the state of the digital twin. For events verified as normal policy adjustments or temporary load migrations, synchronously correct the relevant states in the digital twin. For events verified as abnormal propagation, abnormal transfer, hijacking, or leakage events, retain their abnormal markers and update the risk state and relationship confidence state in the digital twin. The update process of the digital twin state can be expressed as follows: , in, This indicates the state of the digital twin before the update. This indicates the updated state of the digital twin. Indicates the first The linkage verification results corresponding to each event This represents an update function that corrects the state of the digital twin based on the results of the linkage verification.