A hopping period adjustment system and method based on intrusion detection and electronic equipment

By introducing an intrusion detection-based adaptive hopping cycle adjustment system into a hopping network, and utilizing trusted devices and secure transmission channels, the network address is dynamically adjusted to cope with network attacks. This resolves the performance contradictions caused by unreasonable hopping cycle settings and improves the network's anti-attack capability and transmission performance.

CN116827634BActive Publication Date: 2026-04-07WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-28
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing hopping network technologies struggle to balance attack resistance and network transmission performance when adjusting hopping cycles, and traditional defense technologies are easily cracked by attackers, failing to provide effective network protection.

Method used

An intrusion detection-based jump cycle adjustment system is adopted. By embedding trusted devices in a trusted environment, and combining an intrusion detection module and a high-precision clock synchronization module, the jump cycle is dynamically calculated to adapt to network attacks. Configuration parameters are transmitted through a secure transmission channel to achieve adaptive jump of network addresses.

Benefits of technology

It improves the network's resistance to attacks and transmission performance, ensures the security and unpredictability of the computing process, and enhances the network's adaptability and resistance to attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827634B_ABST
    Figure CN116827634B_ABST
Patent Text Reader

Abstract

This invention discloses a hopping cycle adjustment system, method, and electronic device based on intrusion detection. The system includes several network hopping nodes. The method first sets a hopping cycle configuration parameter file. The control node sends the hopping cycle configuration parameter file, along with a hopping start command or a hopping stop command, to the network hopping nodes via a secure transmission channel. Then, upon receiving the hopping cycle configuration parameter file and the hopping start command, the network hopping nodes complete system parameter initialization. Next, once an intrusion detection module detects an attack, it analyzes and statistically analyzes the attack to obtain the attack strength. Finally, the hopping cycle is dynamically calculated, and the network hopping nodes adjust the hopping cycle according to the hopping cycle configuration parameter file and under the control of a high-precision clock synchronization module. This invention can adaptively adjust the hopping cycle according to the intensity of network attacks, thus improving the adaptability of the hopping network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of information and network security, and relates to a hopping period adjustment system, method and electronic device, in particular to a hopping period adjustment system, method and electronic device based on intrusion detection. BACKGROUND

[0002] To cope with network attacks such as Trojan, worm, virus, Dos, traditional network defense technologies such as signature, access control, security vulnerability scanning, firewall, intrusion detection and the like have been researched one after another. These technologies greatly improve the network defense level and gradually become the standard configuration of network security defense. However, with the continuous updating of network attack means, in the face of various unknown attack means such as Trojan port hopping, proxy attack, protocol conversion attack, DDoS attack and the like, the widely used defense technologies are increasingly unable to meet the needs. In order to change the situation, the mobile target defense idea is put forward, which is committed to building a dynamic, heterogeneous and uncertain network, and through increasing the randomness of the system or reducing the predictability of the system, the purpose of preventing, delaying or blocking network attacks is achieved. The hopping network technology is built on the basis of the mobile target defense idea, which well makes up for the shortcomings of traditional defense technologies, provides good defense ability for resisting uncertain or unknown attacks, and has an important role in high security application scenarios.

[0003] However, the current hopping network technology is not mature enough, far from the application requirements, mainly due to the performance problem has not been effectively solved, thus seriously restricting its application in practical scenarios. Among the many factors affecting the performance of the hopping network, one of the important factors is the adjustment of the hopping period. Adjusting the hopping period will affect the network's ability to resist attacks and the network's transmission performance. This is because when the hopping period is set short, the network address changes fast enough in unit time, so as to resist network attacks, but also makes the system consume more network resources, thus reducing the network transmission performance; Conversely, when the hopping period is set longer, the enemy will have more time to analyze the network address, thus launching network attacks. Therefore, when adjusting the hopping period, not only the anti-attack ability of the hopping network should be considered, but also the network transmission performance. However, since the network's ability to resist attacks and transmission performance are contradictory, the setting of the hopping period is relatively difficult. How to make the hopping period better balance the anti-network attack ability and network transmission performance is a difficulty faced by the performance optimization of the hopping network. In view of this difficulty, domestic and foreign researchers have carried out in-depth exploration and achieved some good research results. Jafarian J et al. developed a mobile target defense (MTD) software architecture using OpenFlow, and proposed a method of periodic random allocation of host virtual IP based on OpenFlow (document 1). This method uses the OpenFlow controller to allocate a random virtual IP for the host within the preset hopping period, and converts it to the real IP of the host, so that it can resist attacks such as stealth scanning, worm virus propagation, etc. However, this method often presets the hopping period by experience when facing network attacks, and randomly allocates virtual addresses for the host, but the small hopping period will frequently allocate virtual addresses for the host, which will reduce the system's available performance. In view of the problem of Jafarian J et al., Li Wei et al. proposed a terminal address hopping pattern generation method based on quantum key (document 2). After the preset hopping period, the communication parties can make the calculated hopping pattern hop according to the preset hopping period, which makes the third party other than the communication parties unable to know the current network address providing service, thus ensuring the security of the network. However, the setting of the hopping period often relies on the designer's experience and feeling, so it is easy to appear the problem of unreasonable hopping period setting, which affects the network's ability to resist attacks and transmission performance. In view of the problem of Li Wei et al., Cheng Lei et al. proposed an adaptive hopping period adjustment of the end address hopping method (document 3). This method distinguishes the scanning attacks by sensing the enemy's attack strategy, and establishes a satisfactory model theory to guide the periodic hopping of the end address, thus improving the network's ability to resist attacks and transmission performance.However, this method has only local anti-attack ability because it is often used in end hopping scenarios, and does not have anti-attack ability in network environment. In view of this, the defender needs to comprehensively consider various factors such as external attack ability, system availability and network security when setting the hopping period as a network defense technology. Reviewing the defense technology based on network address hopping, most of them only use port and address hopping to resist network attacks. However, these technologies are easy to be cracked by attackers and thus cannot achieve strong protection of the network. Therefore, how to perceive the attack ability of the network and adaptively adjust the hopping period to indirectly change the network address and improve the anti-attack ability of the network has become the research focus at this stage.

[0004] REFERENCES

[0005] [1] Jafarian J, Alshaer E, Duan Q. August). Openflow random host mutation: transparent moving target defense using software defined networking. [C] / / Workshop on Hot Topics in Software Defined Networks. ACM, 2010.

[0006] [2] Li Wei, Lu Gang, A secure communication method, a secure communication system and a communication terminal address hopping pattern generation method, 2020, CN111224775A.

[0007] [3] Lei Chen, Zhang H Q, Ma D H, et al. Network Moving Target Defense Technique Based on Self-Adaptive End-Point Hopping [J]. Arabian Journal for Science and Engineering, 2017, 42(8): 3249-3262. SUMMARY

[0008] In view of how to perceive the capability of network attack and adaptively adjust the hopping period to indirectly change the network address and improve the anti-attack capability of the network, the application provides a hopping period adjustment system and method based on intrusion detection and electronic equipment. The application relies on a trusted environment, the trusted environment contains a trusted device embedded in a normal network node, and a control module for network address change and dynamic configuration is formed in the trusted device to form a network hopping node. The hopping node and the normal network node are connected to the network in a completely compatible manner, and can normally connect and access each other like the normal network node.

[0009] The technical scheme of the system of the application is: a hopping period adjustment system based on intrusion detection, comprising a plurality of network hopping nodes; the network hopping node is a normal network node embedded with a trusted device; the trusted device comprises a trusted computing module, an intrusion detection module and a control module;

[0010] A network hopping node is designated as a control node, the control node is embedded with a hopping control module, and is configured with a hopping start instruction module, a hopping stop instruction module, a high-precision clock synchronization module and a secure transmission channel;

[0011] The network hopping node is connected to the network in a completely compatible manner like the normal network node, and the network hopping nodes are connected by the secure transmission channel.

[0012] The technical scheme of the method of the application is: a hopping period adjustment method based on intrusion detection, comprising the following steps:

[0013] Step 1: setting a hopping period configuration parameter file, the control node sends the hopping period configuration parameter file and a hopping start instruction or a hopping stop instruction to the network hopping node through the secure transmission channel;

[0014] Step 2: after the network hopping node receives the hopping period configuration parameter file and the hopping start instruction, the system parameter initialization is completed;

[0015] Step 3: once the intrusion detection module detects an attack, the attack situation is analyzed and counted, the attack strength is obtained, and the attack strength is updated in the hopping period configuration parameter file;

[0016] Step 4: hopping period dynamic calculation, the network hopping node adjusts the hopping period according to the hopping period configuration parameter file and under the control of the high-precision clock synchronization module, and updates the calculation result in the control module.

[0017] As a preferred, the hopping period configuration parameter in step 1 comprises a last hopping period T i-1 , a current hopping period T i , and a next hopping period Ti+1 The system pass rate p0, preference factor σ, adjustment scale μ, intrusion detection error coefficient α, number of attacks λ, ​​success rate of a single attack p, and attack intensity θ.

[0018] As a preferred embodiment, step 3 includes the following sub-steps:

[0019] Step 3.1: The intrusion detection module detects m types of attacks, denoted as S1, S2, S3, S4, ..., S... m The attack types and the number of attacks corresponding to them are λ1, λ2, λ3, λ4, ..., λ m The probabilities of a successful attack and a single attack are p1, p2, p3, p4, ..., p, respectively. m ;

[0020] Step 3.2: Based on the attack strength θ = λp, calculate the attack strengths corresponding to the m attack types as λ1p1, λ2p2, λ3p3, λ4p4, ..., λ m p m Where λ is the number of attacks, p is the success rate of an attack, and θ is the attack intensity;

[0021] Step 3.3: Calculate the average attack strength

[0022] As a preferred embodiment, step 4 includes the following sub-steps:

[0023] Step 4.1: Calculate the attack strength θ = λ·p; where λ is the number of attacks, p is the success rate of an attack, and θ is the attack strength;

[0024] Step 4.2: Calculate the system's defense capability P d (t)=e -p λ t Where t represents the attack interval;

[0025] Step 4.3: Calculate the maximum system revenue Where T is the jump period and σ is the preference factor;

[0026] Step 4.4: Calculate the current transition period T i =T i-1 +μ(T i-1 -argmaxC(t)); where T i-1 For the previous transition period, μ is the adjustment scale, and argmaxC(t) refers to the parameter t corresponding to the maximum system return;

[0027] Step 4.5: Calculate the next jump cycle T i+1 =T i +μ(P d(t)-p0); where p0 is the system pass rate, P d (t) represents the system's defensive capabilities.

[0028] Preferably, step 4.4 includes the following sub-steps:

[0029] Step 4.4.1: Define a two-dimensional array A = [][], a one-dimensional array T_ar = [5, 60], and a variable T i =0;

[0030] Step 4.4.2: Assign the value min(T_ar) to variable i;

[0031] Step 4.4.3: Calculate T i =T i +i / 50, calculate the attack strength θ=λ·p, and calculate the system benefit.

[0032] Step 4.4.4: A(i)(1)=C(T) i ), A(i)(2)=T i ;

[0033] Step 4.4.5: Increment the value of variable i by 1;

[0034] Step 4.4.6: Compare whether the value of i is less than the value of max(T_ar). If yes, go back to step 4.4.3; otherwise, execute step 4.4.7. Here, max() means to get the element with the maximum value in the array.

[0035] Step 4.4.7: T i =argmax(A),T i This is the current transition cycle.

[0036] Preferably, the specific implementation of step 4.4.7 includes the following sub-steps:

[0037] Step 4.4.7.1: Assign the value 1 to variable j;

[0038] Step 4.4.7.2: Determine the relationship between j+1 and length((j)(1)); where length() represents the number of array elements; length((j)(1) represents the number of elements in the first column of the two-dimensional array A;

[0039] If j+1 is less than length((j)(1)), then compare whether the value of A(j)(1) is less than the value of A(j+1)(1). If yes, proceed to step 4.4.7.2; otherwise, proceed to step 4.4.7.3.

[0040] Step 4.4.7.3: Swap the values ​​of A(j+1)(1) and A(j)(1);

[0041] Step 4.4.7.4: Increment the value of variable j by 1;

[0042] Step 4.4.7.5: Determine if j equals length(A), then sort(A), where sort() is the sorting function, which sorts the elements of the array from smallest to largest. i =A(max(length(A)))(2), and return T. i Otherwise, proceed to step 4.4.7.2.

[0043] The technical solution adopted by the electronic device of the present invention is: an electronic device comprising:

[0044] One or more processors;

[0045] A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the intrusion detection-based jump cycle adjustment method.

[0046] The beneficial effects of this invention include:

[0047] (1) Good confidentiality; This invention selects a reliable and secure channel to transmit system parameters and related parameters involved in this invention. In addition, this invention also uses a trusted device to establish a trusted computing region, so the entire calculation process and the calculation results of this invention are secure and difficult to predict;

[0048] (2) Good adaptability; This invention relies on the intrusion detection system's ability to perceive network attacks and dynamically calculates the jump cycle based on the perceived attack situation to obtain an adaptive jump cycle.

[0049] (3) Strong resistance to attacks; the jump period of the jump period configuration parameter file obtained by the invention is used to make the network address jump periodically according to the jump period setting value, which reduces the risk of exposing or being tracked the network address and has the ability to resist attacks. Attached Figure Description

[0050] The technical solutions described herein are further illustrated below using examples and specific implementation methods. Additionally, accompanying drawings are used in the description of the technical solutions. Those skilled in the art can, without any creative effort, obtain other drawings and the intent of the present invention based on these drawings.

[0051] Figure 1 This is a system architecture diagram of an embodiment of the present invention;

[0052] Figure 2 This is a flowchart of a method according to an embodiment of the present invention;

[0053] Figure 3 This describes the principle of the jump period adjustment in this embodiment of the invention. Detailed Implementation

[0054] To facilitate understanding and implementation of the present invention by those skilled in the art, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0055] Please see Figure 1 The present invention provides a jump cycle adjustment system based on intrusion detection, comprising a plurality of network jump nodes; the network jump nodes are ordinary network nodes with embedded trusted devices; the trusted devices include a trusted computing module, an intrusion detection module, and a control module;

[0056] Designate a network transition node as the control node. The control node has an embedded transition control module and is configured with a transition start command module, a transition stop command module, a high-precision clock synchronization module, and a secure transmission channel.

[0057] Network hopping nodes connect to the network in a fully compatible manner, just like ordinary network nodes, and are connected to each other via secure transmission channels.

[0058] The network jump start instruction module is used to start the network jump node; the network jump stop instruction module is used to stop the network jump node; the intrusion detection module is used to detect the attack strength; the control module is used for the control program of the network jump node; the high-precision clock synchronization module is used to provide high-precision time synchronization function; and the trusted computing module is used for secure and trusted hardware.

[0059] In one implementation, the trusted computing region is selected from a SoC based on TrustZone technology, but is not limited to TrustZone.

[0060] In one implementation, the control node and other nodes are both x86 servers.

[0061] In one implementation, the high-precision clock synchronization module selects NTP service time synchronization to achieve automatic system clock synchronization.

[0062] In one implementation, the secure transmission channel uses VPN transmission encryption technology.

[0063] Please see Figure 2This invention provides a jump cycle adjustment method based on intrusion detection, employing the jump cycle adjustment system based on intrusion detection as described in claim 1; characterized by comprising the following steps:

[0064] Step 1: Set the transition cycle configuration parameter file. The control node sends the transition cycle configuration parameter file, as well as the transition start command or, if necessary, the transition stop command to the network transition node through a secure transmission channel.

[0065] In one implementation, the transition period configuration parameters include the previous transition period T. i-1 The current transition period T i The next jump cycle T i+1 The system pass rate p0, preference factor σ, adjustment scale μ, intrusion detection error coefficient α, number of attacks λ, ​​success rate of a single attack p, and attack intensity θ.

[0066] Step 2: After receiving the switching cycle configuration parameter file and the switching start command, the network switching node quickly completes the system parameter initialization; after the switching node completes the configuration of the switching cycle configuration parameter file, it sends the configuration success information back to the control node; after receiving the configuration success information from all nodes, the control node sends the switching start command to all switching nodes synchronously, and all switching nodes synchronously enter the switching state.

[0067] In one implementation, the previous transition period T i-1 =60, current transition period T i The next jump cycle T i+1 The default unit for the transition period is seconds, and the default unit for p0 is %.

[0068] In one implementation, the number of attacks is assigned λ = 20, the probability of a successful attack is p = 0.001, the intrusion detection module is snort, and λ and p are taken from the average number of attacks and the probability of a successful attack as counted by the intrusion detection module.

[0069] In one implementation, the attack strength is calculated using λ and p, i.e., θ = λ·p = 20 × 0.001 = 0.02.

[0070] In one implementation, the assignment system pass rate p0 = 0.85, the assignment preference factor σ = 0.2, the assignment adjustment scale μ = 0.01, and the assignment intrusion detection error coefficient α = 0.1.

[0071] Step 3: Once the intrusion detection module detects an attack, it analyzes and statistically analyzes the attack situation, obtains the attack strength, and updates it in the jump cycle configuration parameter file;

[0072] In one implementation, step 3 specifically includes the following sub-steps:

[0073] Step 3.1: The intrusion detection module detects m types of attacks, denoted as S1, S2, S3, S4, ..., S... m The attack types and the number of attacks corresponding to them are λ1, λ2, λ3, λ4, ..., λ m The probabilities of a successful attack and a single attack are p1, p2, p3, p4, ..., p, respectively. m ;

[0074] Step 3.2: Based on the attack strength θ = λp, calculate the attack strengths corresponding to the m attack types as λ1p1, λ2p2, λ3p3, λ4p4, ..., λ m p m Where λ is the number of attacks, p is the success rate of an attack, and θ is the attack intensity;

[0075] Step 3.3: Calculate the average attack strength

[0076] Step 4: Dynamic calculation of the transition period. The network transition node independently adjusts the transition period according to the transition period configuration parameter file and under the control of the high-precision clock synchronization module, and updates the calculation results in the control module.

[0077] Please see Figure 3 In one implementation, step 4 specifically includes the following sub-steps:

[0078] Step 4.1: Calculate the attack strength θ = λ·p; where λ is the number of attacks, p is the success rate of an attack, and θ is the attack strength;

[0079] In one implementation, T i-1 =60, θ=20×0.001=0.02.

[0080] Step 4.2: Calculate the system's defense capability P d (t)=e -pλt (); where t represents the attack interval; in one implementation, λ = 20, p = 0.001, t = 60, P d (t)=e -0.001×20×60 =0.3011.

[0081] Step 4.3: Calculate the maximum system revenue Where T is the jump period and σ is the preference factor;

[0082] In one implementation, P d (t)=0.3011, σ=0.2, T=60,

[0083] Step 4.4: Calculate the current transition period T i =T i-1 +μ(T i-1 -argmaxC(t)); where T i-1 For the previous transition period, μ is the adjustment scale, and argmaxC(t) refers to the parameter t corresponding to the maximum system return;

[0084] In one implementation, T i-1 =60, μ=0.01, argmax(C(t))=0.567, T i =60 + 0.01 × 0.567 = 60.00567.

[0085] In one implementation, step 4.4 specifically includes the following sub-steps:

[0086] Step 4.4.1: Define a two-dimensional array A = [][], a one-dimensional array T_ar = [5, 60], and a variable T i =0;

[0087] Step 4.4.2: Assign the value min(T_ar) to the variable i, where min(A) represents obtaining the minimum value of the elements in array A;

[0088] Step 4.4.3: Calculate T i =T i +i / 50, calculate the attack strength θ=λ·p, and calculate the system benefit.

[0089] Step 4.4.4: A(i)(1)=C(T) i ), A(i)(2)=T i ;

[0090] Step 4.4.5: Increment the value of variable i by 1, i.e., i = i + 1;

[0091] Step 4.4.6: Compare whether the value of i is less than the value of max(T_ar), where max(A) represents the maximum value of the elements in array A. If yes, go back to step 4.4.3; otherwise, go to step 4.4.7.

[0092] Step 4.4.7: T i =argmax(A),T i This is the current transition cycle.

[0093] In one implementation, step 4.4.7 specifically includes the following sub-steps:

[0094] Step 4.4.7.1: Assign the value 1 to variable j; j = 1:length(A(i)(1));

[0095] Step 4.4.7.2: Determine the relationship between j+1 and length((j)(1)); where length() represents the number of array elements; length((j)(1) represents the number of elements in the first column of the two-dimensional array A;

[0096] If j+1 is less than length((j)(1)), then compare whether the value of A(j)(1) is less than the value of A(j+1)(1). If yes, proceed to step 4.4.7.2; otherwise, proceed to step 4.4.7.3.

[0097] Step 4.4.7.3: Swap the values ​​of A(j+1)(1) and A(j)(1);

[0098] Step 4.4.7.4: Increment the value of variable j by 1, i.e., j = j + 1;

[0099] Step 4.4.7.5: Determine if j equals length(A), then sort(A), where sort() is the sorting function, which sorts the elements of the array from smallest to largest. i =A(max(length(A)))(2), and return T. i Otherwise, proceed to step 4.4.7.2.

[0100] Step 4.5: Calculate the next jump cycle T i+1 =T i +μ(P d (t)-p0); where p0 is the system pass rate, P d (t) represents the system's defensive capabilities.

[0101] In one implementation, T i =60.00567, Pd(t)=0.3011, p0=0.85, μ=0.01, T i+1 =60.00567+0.01×(0.3011-0.85)=60.000181.

[0102] Update the jump period in the update configuration file to T. i+1 ;

[0103] Determine if there is a jump abort instruction. If there is, return to step 2 and reset the jump process. If not, return to step 3.

[0104] This invention has the ability to adaptively adjust the transition period according to the intensity of network attacks, thus improving the adaptability of transition networks.

[0105] It should be understood that the above description of the preferred embodiments is quite detailed, but it should not be considered as a limitation on the scope of protection of this invention. Those skilled in the art, under the guidance of this invention, can make substitutions or modifications without departing from the scope of protection of the claims of this invention, and all such substitutions or modifications fall within the scope of protection of this invention. The scope of protection of this invention should be determined by the appended claims.

Claims

1. A method for adjusting the jump period based on intrusion detection, characterized in that, Includes the following steps: Step 1: Set the transition period configuration parameter file. The control node sends the transition period configuration parameter file, as well as the transition start command or transition stop command, to the network transition node through a secure transmission channel. Step 2: After receiving the transition cycle configuration parameter file and transition start command, the network transition node completes system parameter initialization; Step 3: Once the intrusion detection module detects an attack, it analyzes and statistically analyzes the attack situation, obtains the attack strength, and updates it in the jump cycle configuration parameter file; Step 4: Dynamic calculation of the transition period. The network transition node adjusts the transition period according to the transition period configuration parameter file and under the control of the high-precision clock synchronization module, and updates the calculation results in the control module. Step 4 includes the following sub-steps: Step 4.1: Calculate attack strength ;in, λ For the number of attacks, p For the success rate of an attack, θ Attack strength ; Step 4.2: Calculate the system's defense capabilities Where t represents the attack interval; Step 4.3: Calculate the maximum system revenue ;in, T For the jump period, For preference factors; Step 4.4: Calculate the current transition period ;in, T i-1 For the previous jump cycle, μ To adjust the scale, ; Step 4.5: Calculate the next transition cycle ;in, p 0 represents the system pass rate. This indicates the system's defensive capabilities.

2. The jump period adjustment method based on intrusion detection according to claim 1, characterized in that: The switching cycle configuration parameters mentioned in step 1 include the previous switching cycle. T i-1 Current jump cycle T i The next jump cycle T i+1 System pass rate p 0, preference factor Adjust the scale μ, intrusion detection error coefficient α Number of attacks λ Success rate of a single attack p and attack strength θ.

3. The jump period adjustment method based on intrusion detection according to claim 1, characterized in that: Step 3 includes the following sub-steps: Step 3.1: Intrusion detection module detection m There are several attack types, denoted as S1, S2, S3, S4, ..., S... m The number of attacks corresponding to each attack type are as follows: λ 1, λ 2, λ 3, λ 4, ..., λ m The probabilities of a successful attack and a single attack are p1, p2, p3, p4, ..., p, respectively. m ; Step 3.2: Based on attack strength θ=λp ,calculate m The attack strengths corresponding to the various attack types are as follows: λ 1p1, λ 2p2, λ 3p3, λ 4p4, ..., λ m p m ; in, λ For the number of attacks, p For the success rate of an attack, θ Attack strength ; Step 3.3: Calculate the average attack strength =( λ 1p1+ λ 2p2+ λ 3p3+ λ 4p4+…+ λ m p m ) / m.

4. The jump period adjustment method based on intrusion detection according to claim 1, characterized in that: The specific implementation of step 4.4 includes the following sub-steps: Step 4.4.1: Define a two-dimensional array A = [ ][ ], and a one-dimensional array... T_ar = [5,60], variable T i = 0; Step 4.4.2: Transfer variables i Assign min( T_ar ) ; Step 4.4.3: Calculation T i = T i + i / 50, calculate attack strength Calculate system revenue ; Step 4.4.4: A ( i (1) = C ( T i ), A ( i (2) = T i ; Step 4.4.5: Transfer variables i Increment the value by 1; Step 4.4.6: Comparison Is the value less than max( T_ar If the value of ) is true, then go back to step 4.4.3; otherwise, proceed to step 4.4.7; where max() means to get the element with the maximum value in the array; Step 4.4.7: T i = argmax(A), T i This is the current transition cycle.

5. The jump period adjustment method based on intrusion detection according to claim 4, characterized in that: The specific implementation of step 4.4.7 includes the following sub-steps: Step 4.4.7.1: Transfer variables j Assign the value 1; Step 4.4.7.2: Judgment j +1 and length(( j (1)) is a relation; where length() means to find the number of array elements; length(( j (1)) represents the number of elements in the first column of the two-dimensional array A; like j +1 is less than length(( j (1)), then compare A( j Is the value of (1) less than A( j If the value of +1)(1) is true, proceed to step 4.4.7.2; otherwise, proceed to step 4.4.7.

3. Step 4.4.7.3: Swap A( j +1)(1) and A( j The value of (1); Step 4.4.7.4: Transfer variables j Increment the value by 1; Step 4.4.7.5: Judgment; like j If the array length equals length(A), then sort(A) is called, where sort() is the sorting function that sorts the elements of the array from smallest to largest. T i = A(max(length(A)))(2), and return T i Otherwise, proceed to step 4.4.7.

2.

6. A jump cycle adjustment system based on intrusion detection, used to implement the method according to any one of claims 1-5; characterized in that: It includes several network hopping nodes; the network hopping nodes are ordinary network nodes with embedded trusted devices; the trusted devices include a trusted computing module, an intrusion detection module, and a control module; Designate a network transition node as the control node. The control node has an embedded transition control module and is configured with a transition start command module, a transition stop command module, a high-precision clock synchronization module, and a secure transmission channel. The network jump nodes are connected to the network in a fully compatible manner, just like ordinary network nodes, and are connected to each other via a secure transmission channel.

7. An electronic device, characterized in that, include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the intrusion detection-based jump cycle adjustment method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Internet of Vehicles safety communication method, system and application based on terminal information hopping

    CN111447588A

  • Dynamic atlas network hopping method and system based on chaos and encryption mapping

    CN114003928A