An air traffic control network information security protection method based on distributed intrusion tolerance technology

CN116846624BActive Publication Date: 2026-07-21SICHUAN UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SICHUAN UNIV
Filing Date
2023-06-28
Publication Date
2026-07-21

Smart Images

  • Figure CN116846624B_ABST
    Figure CN116846624B_ABST
Patent Text Reader

Abstract

The application discloses an air traffic control network information security protection method based on distributed intrusion tolerance technology, belongs to the technical field of network security information protection, and establishes a basic firewall in a network information system, simultaneously establishes a distributed intrusion tolerance subsystem in the network information system, and deploys an online detection and tracking module based on network node flow monitoring in the main system. In the application, the data of the intrusion is subjected to flow directional induction, and after the data induction, the data of the intrusion can be subjected to active defense by a virtual honeypot interval, so that the data does not affect the data interaction security of the network information system, and meanwhile, the security recovery data record interval can be used to quickly recover the subsystem data when the distributed intrusion tolerance subsystem is damaged by the intrusion, so that the security protection effect is improved, the load of the main system is reduced by the distribution, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security information protection technology, and in particular relates to a method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology. Background Technology

[0002] The 21st century, as the information age centered on the internet, has witnessed rapid advancements in science and technology, driving tremendous progress in human society while simultaneously bringing more challenges to network information security. In recent years, with the expansion of air traffic control networks, network information security issues have come into focus. The demand for network interconnection is increasing, and network applications are becoming more complex. Air traffic control network and information security are crucial projects related to the development of air traffic control informatization in my country, and also represent a very challenging and complex system engineering project. Civil aviation air traffic control network information security is a key sector in national information security work. However, due to the openness of network technology, attacks on civil aviation air traffic control network information systems, leading to the leakage and destruction of important information, are not uncommon.

[0003] Chinese Patent Publication No. CN113472778B discloses an information network security protection trust system that integrates the security protection of satellite communication networks with the security protection of information communication networks. It is deployed in three levels: satellite network access gateway, regional security protection center, and headquarters security protection center, and satellite communication center. This system enables multi-level authentication and authorization of users on the satellite communication network, dynamic access control, access user trust measurement, and risk analysis. Based on the current business management hierarchy of the satellite communication network, a two-level business management architecture of satellite communication center general manager and satellite network access gateway is established. Based on the existing information network security protection system, multi-level security protection is implemented at satellite network access, regional information network security protection, overall information network security protection, and satellite communication center. The system provides the interrelationships and operation methods between each level according to the two specific functions of identity authentication and access control. While this solution protects information network interactions through identity access control of the information network, it still has certain shortcomings in practical use. For example, it lacks analysis of intrusion information; when the attack volume increases, it significantly increases the load on the main system, thus affecting data security; and it is difficult to recover data when it is corrupted. Therefore, there is room for improvement. Summary of the Invention

[0004] The purpose of this invention is to address the problem that, due to the lack of analysis of intrusion information, the load on the main system increases significantly when the attack volume increases, thereby affecting data security and making it difficult to recover data when it is corrupted. Therefore, this invention proposes an information security protection method for air traffic control networks based on distributed intrusion tolerance technology.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: A method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology, specifically including the following steps: S101. By establishing a basic firewall in the network information system, and at the same time establishing a distributed intrusion-tolerant subsystem in the network information system, and deploying an online detection and tracking module based on network node traffic monitoring in the main system, intrusion detection is performed on intrusion attacks. S102. Divide the distributed invasion prevention subsystem into a virtual honeypot area and a secure recovery data recording area; S103. By using the redirection component, the intrusion data is redirected, and the traffic obtained from the intrusion is directed to induce the attack data stream to attack the virtual honeypot area. S104. A distributed database is established in the virtual honeypot area to actively defend against intrusive data streams and to block the transmission of attack stream channels based on distributed files. S105. Distributed virtual environment recovery: After the intrusion data stream obtains false data and stops the intrusion, the security data in the security recovery data record interval is used to recover the false information destroyed in the virtual honeypot interval.

[0006] As a further description of the above technical solution: The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The system matches threat signature information with data in a threat signature database and outputs the corresponding threat level based on the degree of matching of the input threat signature information.

[0007] As a further description of the above technical solution: The intrusion data stream consists of network activity events and subsequent connection nodes, and is guided to the corresponding virtual honeypot range based on different intrusion categories.

[0008] As a further description of the above technical solution: The extraction of threat feature information from the intrusion data stream includes matching by matching a feature pattern library and fast matching of the dataset by constructing a neural network model.

[0009] As a further description of the above technical solution: The virtual honeypot area has the same environment, user information, application services and network status as the main system, and the application layer also sets up corresponding packet processing software to induce data, and the virtual honeypot area does not participate in the interaction of network information.

[0010] As a further description of the above technical solution: The distributed virtual environment awaits recovery during intermittent periods of 1-3 data intrusions, and active recovery is achieved by restoring the periodic nodes. The recovery operation includes system shutdown, duplication, and overlay recovery of data in the recovery data record interval.

[0011] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: 1. In this invention, the designed distributed intrusion-tolerant subsystem can guide the traffic of intruded data. After the data is guided, it can actively defend against the intruded data through virtual honeypot intervals, preventing the data from affecting the data interaction security of the network information system. At the same time, it can quickly restore the subsystem data when the distributed intrusion-tolerant subsystem is damaged by intrusion through the secure recovery data recording interval, which is conducive to improving the security protection effect. The distributed nature helps to reduce the load on the main system and improve data security.

[0012] 2. In this invention, the designed tracking module can detect intrusion data streams, thereby extracting threat feature information. This facilitates matching data feature information using the extracted feature information, and allows for the rapid determination of the corresponding threat level through the matched threshold. Based on the threat level, the degree of threat is determined to assist in security information protection judgment. Attached Figure Description

[0013] Figure 1 This is a schematic diagram of the process structure of an air traffic control network information security protection method based on distributed intrusion tolerance technology proposed in this invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] Please see Figure 1 This invention provides a technical solution: a method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology, specifically including the following steps: S101. By establishing a basic firewall in the network information system, and at the same time establishing a distributed intrusion-tolerant subsystem in the network information system, and deploying an online detection and tracking module based on network node traffic monitoring in the main system, intrusion detection is performed on intrusion attacks. S102. Divide the distributed invasion prevention subsystem into a virtual honeypot area and a secure recovery data recording area; S103. By using the redirection component, the intrusion data is redirected, and the traffic obtained from the intrusion is directed to induce the attack data stream to attack the virtual honeypot area. S104. A distributed database is established in the virtual honeypot area to actively defend against intrusive data streams and to block the transmission of attack stream channels based on distributed files. S105. Distributed virtual environment recovery: After the intrusion data stream stops acquiring false data, the security data in the security recovery data record interval is used to recover the false information destroyed in the virtual honeypot interval. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The extraction of threat feature information from the intrusion data stream includes matching by matching a feature pattern library and fast matching of the dataset by constructing a neural network model; The virtual honeypot area has the same environment, user information, application services and network status as the main system, and the application layer also sets up corresponding packet processing software to induce data, and the virtual honeypot area does not participate in the interaction of network information. The distributed virtual environment awaits recovery during intermittent periods of 1-3 data intrusions, and active recovery is achieved by restoring the periodic nodes. The recovery operation includes system shutdown, duplication, and overlay recovery of data in the recovery data record interval. Example 2

[0016] A method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology, specifically including the following steps: S101. By establishing a basic firewall in the network information system, and at the same time establishing a distributed intrusion-tolerant subsystem in the network information system, and deploying an online detection and tracking module based on network node traffic monitoring in the main system, intrusion detection is performed on intrusion attacks. S102. Divide the distributed invasion prevention subsystem into a virtual honeypot area and a secure recovery data recording area; S103. By using the redirection component, the intrusion data is redirected, and the traffic obtained from the intrusion is directed to induce the attack data stream to attack the virtual honeypot area. S104. A distributed database is established in the virtual honeypot area to actively defend against intrusive data streams and to block the transmission of attack stream channels based on distributed files. S105. Distributed virtual environment recovery: After the intrusion data stream stops acquiring false data, the security data in the security recovery data record interval is used to recover the false information destroyed in the virtual honeypot interval. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The extraction of threat feature information from the intrusion data stream includes matching by matching a feature pattern library and fast matching of the dataset by constructing a neural network model; The virtual honeypot area has the same environment, user information, application services and network status as the main system, and the application layer also sets up corresponding packet processing software to induce data, and the virtual honeypot area does not participate in the interaction of network information. The distributed virtual environment awaits recovery during intermittent periods of 1-3 data intrusions, and active recovery is achieved by restoring the periodic nodes. The recovery operation includes system shutdown, duplication, and overlay recovery of data in the recovery data record interval.

[0017] The construction and training of the neural network model includes training the neural network using air traffic control network information as the training set, training the network attack information as the hidden layer after inputting the air traffic control network information as the input layer, training the threshold using network attack information as the hidden layer, and training the backpropagation using the attack results as the output layer. After obtaining the threshold information of the hidden layer, the output is judged to obtain the trained network attack information. Example 3

[0018] A method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology, specifically including the following steps: S101. By establishing a basic firewall in the network information system, and at the same time establishing a distributed intrusion-tolerant subsystem in the network information system, and deploying an online detection and tracking module based on network node traffic monitoring in the main system, intrusion detection is performed on intrusion attacks. S102. Divide the distributed invasion prevention subsystem into a virtual honeypot area and a secure recovery data recording area; S103. By using the redirection component, the intrusion data is redirected, and the traffic obtained from the intrusion is directed to induce the attack data stream to attack the virtual honeypot area. S104. A distributed database is established in the virtual honeypot area to actively defend against intrusive data streams and to block the transmission of attack stream channels based on distributed files. S105. Distributed virtual environment recovery: After the intrusion data stream stops acquiring false data, the security data in the security recovery data record interval is used to recover the false information destroyed in the virtual honeypot interval. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The threat signature information is matched with data in the threat signature database, and the corresponding threat level is output based on the matching degree of the input threat signature information. The extraction of threat feature information from the intrusion data stream includes matching by matching a feature pattern library and fast matching of the dataset by constructing a neural network model; The virtual honeypot area has the same environment, user information, application services and network status as the main system, and the application layer also sets up corresponding packet processing software to induce data, and the virtual honeypot area does not participate in the interaction of network information. The distributed virtual environment awaits recovery during intermittent periods of 1-3 data intrusions, and active recovery is achieved by restoring the periodic nodes. The recovery operation includes system shutdown, duplication, and overlay recovery of data in the recovery data record interval.

[0019] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A method for protecting the information security of air traffic control networks based on distributed intrusion tolerance technology, characterized in that, Specifically, the following steps are included: S101. By establishing a basic firewall in the network information system, and at the same time establishing a distributed intrusion-tolerant subsystem in the network information system, and deploying an online detection and tracking module based on network node traffic monitoring in the main system, intrusion detection is performed on intrusion attacks. S102. Divide the distributed invasion prevention subsystem into a virtual honeypot area and a secure recovery data recording area; S103. By using the redirection component, the intrusion data is redirected, and the traffic obtained from the intrusion is directed to induce the attack data stream to attack the virtual honeypot area. S104. A distributed database is established in the virtual honeypot area to actively defend against intrusive data streams and to block the transmission of attack stream channels based on distributed files. S105. Distributed virtual environment recovery: After the intrusion data stream stops acquiring false data, the security data in the security recovery data record interval is used to recover the false information destroyed in the virtual honeypot interval. The distributed virtual environment awaits recovery during intermittent periods of 1-3 data intrusions, and active recovery is achieved by restoring the periodic nodes. The recovery operation includes system shutdown, duplication, and overlay recovery of data in the recovery data record interval.

2. The air traffic control network information security protection method based on distributed intrusion tolerance technology according to claim 1, characterized in that, The method for detecting intrusion data streams by the online detection and tracking module includes: extracting threat feature information from the intrusion data streams; The system matches threat signature information with data in a threat signature database and outputs the corresponding threat level based on the degree of matching of the input threat signature information.

3. The method for protecting air traffic control network information security based on distributed intrusion tolerance technology according to claim 2, characterized in that, The intrusion data stream consists of network activity events and subsequent connection node information, and the intrusion data stream is guided to the corresponding virtual honeypot area according to different intrusion categories.

4. The air traffic control network information security protection method based on distributed intrusion tolerance technology according to claim 2, characterized in that, The extraction of threat feature information from the intrusion data stream includes matching by matching a feature pattern library and fast matching of the dataset by constructing a neural network model.

5. The air traffic control network information security protection method based on distributed intrusion tolerance technology according to claim 1, characterized in that, The virtual honeypot zone shares the same environment, user information, application services, and network status as the main system. Furthermore, the application layer is equipped with corresponding packet processing software to induce data transmission, and the virtual honeypot zone system does not participate in the interaction of network information.

6. The air traffic control network information security protection method based on distributed intrusion tolerance technology according to claim 4, characterized in that, The construction and training of the neural network model includes training the neural network using air traffic control network information as the training set, training the network attack information as the hidden layer after inputting the air traffic control network information as the input layer, training the threshold using network attack information as the hidden layer, and training the backpropagation using the attack results as the output layer. After obtaining the threshold information of the hidden layer, the output is judged to obtain the trained network attack information.

7. A method for protecting air traffic control network information security based on distributed intrusion tolerance technology according to claim 6, characterized in that, The network node traffic monitoring includes data monitoring of intrusion traffic, and the data thresholds for data traffic are updated through the firewall.