Network security detection method and system based on distributed gateway screening
By sending test messages to the gateway of a distributed network, identifying suspicious gateways and tracing the abnormal link of data transmission, the problem of unable to efficiently identify security problem gateways in the existing technology is solved, and efficient and accurate security detection and link adjustment are achieved to ensure stable network operation.
Patent Information
- Application Number
- CN202411442959.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-16
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2044-10-16
AI Technical Summary
The existing gateway troubleshooting methods cannot efficiently and accurately identify gateways with security problems within the distributed network, resulting in unsafe data transmission and the inability to effectively adjust the data transmission link, affecting the overall operation of the network.
By sending test messages to all gateways of the distributed network, identifying suspicious gateways based on forwarding status and data transmission live, subdivided networks for time-sharing data sampling, analyzing data sample sets, trace the abnormal data transmission link, identifying non-secure gateways and resetting the data transmission link.
It realizes efficient, accurate and secure detection of distributed networks and reliable adjustment of data transmission links, maintains the overall normal operation of the network, and reduces the investigation workload.
Smart Images

Figure CN119420511B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a network security detection method and system based on distributed gateway screening. Background Art
[0002] Distributed networks are equipped with numerous gateways, which are key nodes in the data transmission links within the network. Distributed networks require massive amounts of data transmission during their daily operations. Gateways, acting as transit nodes, ensure smooth data transmission within the corresponding data transmission links. However, in practice, distributed networks can be compromised by external factors such as intrusions, leading to the hijacking of some gateways. Once data passes through a hijacked gateway, data loss or tampering may occur, compromising data security and reducing the overall security of the distributed network. Given the large number of gateways within distributed networks and the complex network connections, existing gateway detection methods are unable to accurately identify gateways with security issues within the distributed network, nor can they effectively and precisely adjust the data transmission links within the distributed network. Therefore, efficient and accurate gateway security detection and reliable data transmission link adjustment within the distributed network are crucial to maintaining the normal operation of the distributed network. Summary of the Invention
[0003] In response to the defects of the existing technology, the present invention provides a network security detection method and system based on distributed gateway screening, which sends test messages to all gateways in the distributed network, identifies suspicious gateways based on the gateway's forwarding status of the test message and the actual data transmission, and conducts a preliminary screening of gateways with security problems within the distributed network; based on the location of the suspicious gateway, the distributed network is divided into several sub-networks, and time-sharing data sampling is performed on all sub-networks to obtain several data sample sets, which provide data support for subsequent judgment on whether security abnormalities occur in the sub-networks; through data transmission tracing, the abnormal data transmission link within the sub-network is determined, and the screening of gateways is narrowed to the range of the data transmission link, reducing the screening workload; based on the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, the non-safe gateway is screened and determined, so as to reset the data transmission link of the distributed network, realize efficient and accurate security detection of the gateway and reliable adjustment of the data transmission link, and maintain the normal operation of the network as a whole.
[0004] The present invention provides a network security detection method based on distributed gateway troubleshooting, comprising the following steps:
[0005] Step S1: Based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission status information of each gateway, whether the gateway is a suspicious gateway is determined;
[0006] Step S2: dividing the distributed network into a plurality of sub-networks based on the locations of all suspicious gateways within the distributed network; performing time-sharing data sampling on all sub-networks based on the gateway connection characteristics of each sub-network to obtain a plurality of data sample sets corresponding to each sub-network;
[0007] Step S3: Analyze the data sample set to determine whether a security anomaly event occurs within the sub-network; trace the data transmission within the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network;
[0008] Step S4, obtain the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, check and determine the non-safe gateways included in the abnormal data transmission link; based on the position of the non-safe gateway inside the distributed network, reset the data transmission link of the distributed network.
[0009] In one embodiment disclosed in the present application, in step S1, based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission information of each gateway, whether the gateway is a suspicious gateway is determined, including:
[0010] Determining, based on the available bandwidth of all active data transmission links within the distributed network, a message transmission data volume that can be supported by all active data transmission links; constructing a test message having a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network;
[0011] Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway;
[0012] Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, it is determined that the gateway is a suspicious gateway; if not, it is determined that the gateway is not a suspicious gateway.
[0013] In one embodiment disclosed in the present application, in step S2, the distributed network is divided into several sub-networks based on the locations of all suspicious gateways within the distributed network; and based on the gateway connection characteristics of all sub-networks, time-sharing data sampling is performed on all sub-networks to obtain several data sample sets corresponding to each sub-network, including:
[0014] Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways, thereby dividing all suspicious gateways into a number of gateway clusters; and based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into a number of sub-networks.
[0015] Based on the number and bandwidth of external gateway links of all subnetworks, the data transmission flow rate of all subnetworks is estimated; based on the said data transmission flow rate, the length of time occupied by data extraction of each subnetwork during the time-sharing data sampling process of all subnetworks is determined, so as to obtain several data sample sets corresponding to all subnetworks one by one.
[0016] In one embodiment disclosed in the present application, in step S3, the data sample set is analyzed to determine whether a security anomaly event occurs within the subnetwork; data transmission within the subnetwork where the security anomaly event occurs is traced to determine an abnormal data transmission link within the subnetwork, including:
[0017] Performing a neural network model analysis on the data sample set to determine whether data packets corresponding to the data sample set have data omissions or illegal data tampering during transmission within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network;
[0018] Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs, and based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
[0019] In one embodiment disclosed in the present application, in step S4, data flow transmission loss characteristic information of all gateways under the abnormal data transmission link is obtained, and based on the data flow transmission loss characteristic information, the non-secure gateway included in the abnormal data transmission link is checked and determined; based on the location of the non-secure gateway within the distributed network, the data transmission link of the distributed network is reset, including:
[0020] Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the amount of data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway;
[0021] Based on the data stream transmission loss characteristic information, the probability of occurrence of data stream transmission errors for all gateways under the data transmission abnormality link is determined; based on the probability of occurrence of data stream transmission errors, the non-secure gateways included in the data transmission abnormality link are checked and determined; based on the position of the non-secure gateway inside the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
[0022] The present invention also provides a network security detection system based on distributed gateway troubleshooting, comprising:
[0023] A test message sending module, configured to send test messages to all gateways of the distributed network based on the bandwidth usage status of the distributed network;
[0024] A suspicious gateway identification module is used to obtain forwarding status information of each gateway for the test message, and determine whether the gateway is a suspicious gateway based on the forwarding status information and the real-time data transmission information of each gateway;
[0025] a subnetwork partitioning module, configured to partition the distributed network into a plurality of subnetworks based on locations of all suspicious gateways within the distributed network;
[0026] The data time-sharing sampling module is used to perform time-sharing data sampling on all sub-networks based on the gateway connection characteristics of each sub-network, and obtain several data sample sets corresponding to each sub-network;
[0027] A security anomaly event judgment module, configured to analyze the data sample set and determine whether a security anomaly event occurs within the sub-network;
[0028] A data transmission abnormal link determination module is used to trace the data transmission inside the sub-network where the security abnormality event occurs and determine the data transmission abnormal link inside the sub-network;
[0029] A non-secure gateway identification module is configured to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link;
[0030] The data transmission link resetting module is used to reset the data transmission link of the distributed network based on the position of the non-secure gateway inside the distributed network.
[0031] In one embodiment disclosed in the present application, the test message sending module is configured to send a test message to all gateways of the distributed network based on the bandwidth usage status of the distributed network, including:
[0032] Determining, based on the available bandwidth of all active data transmission links within the distributed network, a message transmission data volume that can be supported by all active data transmission links; constructing a test message having a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network;
[0033] The suspicious gateway identification module is configured to obtain forwarding status information of each gateway for the test message, and determine whether the gateway is a suspicious gateway based on the forwarding status information and the actual data transmission information of each gateway, including:
[0034] Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway;
[0035] Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, it is determined that the gateway is a suspicious gateway; if not, it is determined that the gateway is not a suspicious gateway.
[0036] In one embodiment disclosed in the present application, the subnetwork division module is configured to divide the distributed network into a plurality of subnetworks based on the locations of all suspicious gateways within the distributed network, including:
[0037] Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways, thereby dividing all suspicious gateways into a number of gateway clusters; and based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into a number of sub-networks.
[0038] The data time-sharing sampling module is used to perform time-sharing data sampling on all sub-networks based on the gateway connection characteristics of each sub-network to obtain several data sample sets corresponding to each sub-network, including:
[0039] Based on the number and bandwidth of external gateway links of all subnetworks, the data transmission flow rate of all subnetworks is estimated; based on the said data transmission flow rate, the length of time occupied by data extraction of each subnetwork during the time-sharing data sampling process of all subnetworks is determined, so as to obtain several data sample sets corresponding to all subnetworks one by one.
[0040] In one embodiment disclosed in the present application, the security anomaly event judgment module is configured to analyze the data sample set to determine whether a security anomaly event occurs within the sub-network, including:
[0041] Performing a neural network model analysis on the data sample set to determine whether data packets corresponding to the data sample set have data omissions or illegal data tampering during transmission within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network;
[0042] The abnormal data transmission link determination module is configured to trace data transmission within the sub-network where the abnormal security event occurs and determine the abnormal data transmission link within the sub-network, including:
[0043] Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs, and based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
[0044] In one embodiment disclosed in the present application, the non-secure gateway identification module is configured to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link, including:
[0045] Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the amount of data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway;
[0046] Based on the data stream transmission loss characteristic information, determine the probability of data stream transmission error time occurrence of all gateways under the abnormal data transmission link; based on the data stream transmission error time occurrence probability, identify the non-secure gateways included in the abnormal data transmission link;
[0047] The data transmission link resetting module is configured to reset the data transmission link of the distributed network based on the location of the non-secure gateway within the distributed network, including:
[0048] Based on the position of the non-secure gateway inside the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
[0049] Compared with the existing technology, the network security detection method and system based on distributed gateway screening sends test messages to all gateways in the distributed network, identifies suspicious gateways based on the gateway's forwarding status of the test message and the actual data transmission, and conducts preliminary screening of gateways with security problems within the distributed network; based on the location of the suspicious gateway, the distributed network is divided into several sub-networks, and time-sharing data sampling is performed on all sub-networks to obtain several data sample sets, which provide data support for subsequent judgment of whether security abnormalities occur in the sub-network; it also determines the abnormal data transmission link within the sub-network through data transmission tracing, narrows the screening of gateways to the scope of the data transmission link, and reduces the screening workload; based on the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, screens and determines non-secure gateways, thereby resetting the data transmission link of the distributed network, realizing efficient and accurate security detection of gateways and reliable adjustment of data transmission links, and maintaining the normal operation of the entire network.
[0050] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.
[0051] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0053] Figure 1 A schematic diagram of the flow of a network security detection method based on distributed gateway troubleshooting provided by the present invention;
[0054] Figure 2 This is a schematic diagram of the framework of the network security detection system based on distributed gateway investigation provided by the present invention. DETAILED DESCRIPTION
[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0056] See Figure 1 , is a flow chart of a network security detection method based on distributed gateway screening provided by an embodiment of the present invention. The network security detection method based on distributed gateway screening includes:
[0057] Step S1: Based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission status information of each gateway, whether the gateway is a suspicious gateway is determined;
[0058] Step S2: Based on the locations of all suspicious gateways within the distributed network, the distributed network is divided into several sub-networks; based on the gateway connection characteristics of all sub-networks, time-sharing data sampling is performed on all sub-networks to obtain several data sample sets corresponding to each sub-network;
[0059] Step S3: Analyze the data sample set to determine whether a security anomaly event occurs within the sub-network; trace the data transmission within the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network;
[0060] Step S4, obtain the data flow transmission loss characteristic information of all gateways under the data transmission abnormality link, and based on the data flow transmission loss characteristic information, identify the non-safe gateways included in the data transmission abnormality link; based on the position of the non-safe gateway within the distributed network, reset the data transmission link of the distributed network.
[0061] This network security detection method based on distributed gateway screening sends test messages to all gateways in the distributed network, identifies suspicious gateways based on the gateway's forwarding status of the test messages and the actual data transmission situation, and conducts a preliminary screening of gateways with security issues within the distributed network; divides the distributed network into several sub-networks based on the location of the suspicious gateways, and performs time-sharing data sampling on all sub-networks to obtain several data sample sets, providing data support for subsequent judgment on whether security anomalies occur in the sub-networks; also determines the abnormal data transmission links within the sub-network through data transmission tracing, narrows the screening of gateways to the range of data transmission links, and reduces the screening workload; based on the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, screens and determines non-secure gateways, thereby resetting the data transmission link of the distributed network, achieving efficient and accurate security detection of gateways and reliable adjustment of data transmission links, and maintaining the normal operation of the entire network.
[0062] Preferably, in step S1, based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission information of each gateway, whether the gateway is a suspicious gateway is determined, including:
[0063] Determining the message transmission data volume that can be supported by all active data transmission links within the distributed network based on the available bandwidth of each link; constructing a test message with a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network;
[0064] Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway;
[0065] Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, the gateway is determined to be a suspicious gateway; if not, the gateway is determined not to be a suspicious gateway.
[0066] In the above technical solution, a large number of gateways are provided within the distributed network, each of which can serve as a data transmission node for a corresponding data transmission link within the distributed network. This means that the data transit transmission performance of the gateway itself directly affects the overall data transmission performance of the data transmission link within which it is located. Given the large number of gateways within the distributed network, checking all gateways one by one would not only require a large amount of manpower and material resources and be inefficient, but would also fail to ensure the normal data transmission operation of the corresponding data transmission link during the checking process. To this end, a test message is sent to all gateways, and the forwarding status of each gateway after receiving the test message is obtained, thereby making a preliminary assessment of the data transmission performance of each gateway. Specifically, the available bandwidth of each active data transmission link within the distributed network is obtained. The active data transmission link may be, but is not limited to, a data transmission link that continuously performs data transmission operations within a preset time interval. The available bandwidth may be, but is not limited to, the remaining available bandwidth value of the active data transmission link. The minimum available bandwidth of each of the available bandwidths of all active data transmission links is determined, and based on the minimum available bandwidth, the message transmission data volume that all active data transmission links can withstand is determined, where the message transmission data volume matches the minimum available bandwidth. Based on the data volume transmitted by the message, a test message with periodic code distribution characteristics is constructed, so that the data volume of the test message is less than or equal to the data volume transmitted by the message, and the code content is periodic. This ensures that the test message is quickly transmitted to each gateway within the distributed network and facilitates the identification of the test message from the code content level.
[0067] After receiving a test message, each gateway forwards it according to its preset destination address. Each gateway decomposes the test message into several message packets, which are then queued to form a message packet queue. All message packets in the message packet queue are then forwarded sequentially. If a gateway has security issues, the gateway's forwarding of all message packets in the message packet queue may be delayed, making it impossible to ensure that all message packets are forwarded within the specified timeframe. Therefore, by monitoring the forwarding process of each gateway after receiving the test message, each gateway obtains forwarding status information for the test message. This forwarding status information is then compared with the transmission progress information corresponding to each gateway's queue of pending data packets, and a time difference is determined. If the time difference is greater than a preset difference threshold, the gateway is determined to have experienced a delay in forwarding the message packet, and the gateway is designated as a suspicious gateway. Otherwise, the gateway is determined to have experienced no delay in forwarding the message packet, facilitating subsequent investigation of suspicious gateways and improving the efficiency of gateway detection within the distributed network.
[0068] Preferably, in step S2, the distributed network is divided into several sub-networks based on the locations of all suspicious gateways within the distributed network; and time-sharing data sampling is performed on all sub-networks based on the gateway connection characteristics of each sub-network to obtain several data sample sets corresponding to each sub-network, including:
[0069] Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways. This is used to divide all suspicious gateways into several gateway clusters. Based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into several subnetworks.
[0070] Based on the number and bandwidth of external links of the gateways of all subnetworks, the data transmission flow rate of all subnetworks is estimated; based on the data transmission flow rate, the length of time occupied by data extraction of each subnetwork during the time-sharing data sampling process of all subnetworks is determined, so as to obtain several data sample sets corresponding to all subnetworks one by one.
[0071] In the above technical solution, a suspicious gateway can negatively impact data transmission within the adjacent network centered on it, potentially causing intrusion or hijacking of other gateways and creating security issues. To conduct a comprehensive gateway inspection within a distributed network, a cluster analysis is performed on all suspicious gateways based on their locations within the distributed network. The probability of data interaction between any two suspicious gateways is estimated. This cluster analysis can be implemented using a deep neural network model, which is not described in detail here. If the probability of data interaction between two suspicious gateways exceeds a preset probability threshold, the two suspicious gateways are assigned to the same gateway cluster. The distributed network is then divided into several subnetworks based on the coverage of each gateway cluster within the distributed network, such that each gateway cluster uniquely corresponds to a subnetwork. Furthermore, based on the number and bandwidth of each subnetwork's gateway external links, the external data transmission rate of each subnetwork is estimated. This external data transmission rate refers to the total data transmission rate of gateways within the subnetwork to gateways outside the subnetwork. The greater the rate of external data transmission of the sub-network, the longer the time taken for data extraction of the sub-network during the time-sharing data sampling of all sub-networks. This ensures balanced and equal data sampling of all sub-networks, so that the collected data sample set can accurately and comprehensively reflect the data forwarding status of the corresponding sub-network, providing a sufficient and reliable data basis for the subsequent identification of security anomalies within the sub-network.
[0072] Preferably, in step S3, the data sample set is analyzed to determine whether a security anomaly event occurs within the sub-network; data transmission within the sub-network where the security anomaly event occurs is traced to determine the abnormal data transmission link within the sub-network, including:
[0073] Performing a neural network model analysis on the data sample set to determine whether there is data omission or illegal data tampering during the transmission of the data packet corresponding to the data sample set within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network;
[0074] Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs. Based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
[0075] In the above technical solution, a convolutional neural network model is used to learn and analyze the data sample set to determine whether the data packet corresponding to the data sample set has data omissions or illegal data tampering during the transmission process within the sub-network, and accurately judge the data transmission security within the sub-network. In addition, the transmission path label of the data packet with data omissions or illegal data tampering within the sub-network where the security anomaly event occurred is obtained. The transmission path label refers to the path address label of the data transmission link within the sub-network through which the data packet with data omissions or illegal data tampering within the sub-network passes; and based on the transmission path label, the data transmission of the sub-network where the security anomaly event occurred is traced to determine the abnormal data transmission link within the sub-network, thereby narrowing the gateway security inspection and detection of the distributed network to the gateway security inspection of the abnormal data transmission link, greatly reducing the scope of the gateway security inspection and reducing the workload of the gateway security inspection.
[0076] Preferably, in step S4, data flow transmission loss characteristic information of all gateways under the abnormal data transmission link is obtained, and based on the data flow transmission loss characteristic information, the non-secure gateway included in the abnormal data transmission link is checked and determined; based on the position of the non-secure gateway in the distributed network, the data transmission link of the distributed network is reset, including:
[0077] Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway;
[0078] Based on the data stream transmission loss characteristic information, the probability of occurrence of data stream transmission errors for all gateways under the data transmission abnormality link is determined; based on the probability of occurrence of data stream transmission errors, the non-secure gateways included in the data transmission abnormality link are checked and determined; based on the position of the non-secure gateway within the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
[0079] In the above technical solution, the characteristic code position changes of the data packets received by all gateways under the abnormal data transmission link are compared. If the abnormal data transmission link includes an insecure gateway, the data packet will lose some data code after being transferred through the insecure gateway. In this case, the characteristic code position within the data packet will also change accordingly. The greater the characteristic code position change within the data packet, the more data code content is lost in the data packet. Therefore, the characteristic code position changes of the data packets received by all gateways under the abnormal data transmission link are compared to determine the amount of data code loss when each gateway receives the same data packet. This determines the data flow transmission loss ratio and the data flow interval where transmission loss occurs for each gateway, thereby quantitatively identifying the data loss situation during data transfer for each gateway. Based on the data flow transmission loss characteristic information, the data flow transmission error time probability of each gateway under the abnormal data transmission link is determined. The data flow transmission error time probability refers to the probability that each gateway will fail to transfer and send the data flow completely within a specified time range during data flow transmission. If the data flow transmission error time probability exceeds a preset probability threshold, the corresponding gateway is determined as an insecure gateway. Based on the location of the non-secure gateway within the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, so that the data transmission link of the distributed network is reset, and reliable adjustment of the data transmission link within the distributed network is achieved to maintain the normal operation of the entire network.
[0080] See Figure 2 , is a schematic diagram of the framework of a network security detection system based on distributed gateway troubleshooting provided by an embodiment of the present invention. The network security detection system based on distributed gateway troubleshooting includes:
[0081] A test message sending module is used to send test messages to all gateways of the distributed network based on the bandwidth usage status of the distributed network;
[0082] A suspicious gateway identification module is used to obtain the forwarding status information of each gateway for the test message, and determine whether the gateway is a suspicious gateway based on the forwarding status information and the real-time data transmission information of each gateway;
[0083] a sub-network partitioning module, configured to partition the distributed network into a plurality of sub-networks based on the locations of all suspicious gateways within the distributed network;
[0084] The data time-sharing sampling module is used to perform time-sharing data sampling on all sub-networks based on the gateway connection characteristics of each sub-network, and obtain several data sample sets corresponding to each sub-network;
[0085] A security anomaly event judgment module is used to analyze the data sample set and determine whether a security anomaly event has occurred within the sub-network;
[0086] The abnormal data transmission link determination module is used to trace the data transmission within the sub-network where the security abnormality event occurred and determine the abnormal data transmission link within the sub-network;
[0087] The non-secure gateway identification module is used to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link;
[0088] The data transmission link resetting module is used to reset the data transmission link of the distributed network based on the position of the non-safe gateway inside the distributed network.
[0089] This network security detection system based on distributed gateway screening sends test messages to all gateways in the distributed network, identifies suspicious gateways based on the gateway's forwarding status of the test messages and the actual data transmission situation, and conducts preliminary screening of gateways with security issues within the distributed network; based on the location of the suspicious gateways, the distributed network is divided into several sub-networks, and time-sharing data sampling is performed on all sub-networks to obtain several data sample sets, which provide data support for subsequent judgment on whether security anomalies occur in the sub-networks; it also determines the abnormal data transmission links within the sub-network through data transmission tracing, narrows the screening of gateways to the scope of data transmission links, and reduces the screening workload; based on the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, it screens and determines non-secure gateways, thereby resetting the data transmission link of the distributed network, achieving efficient and accurate security detection of gateways and reliable adjustment of data transmission links, and maintaining the normal operation of the entire network.
[0090] Preferably, the test message sending module is configured to send test messages to all gateways of the distributed network based on the bandwidth usage status of the distributed network, including:
[0091] Determining the message transmission data volume that can be supported by all active data transmission links within the distributed network based on the available bandwidth of each link; constructing a test message with a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network;
[0092] The suspicious gateway identification module is configured to obtain forwarding status information of each gateway for the test message and determine whether the gateway is a suspicious gateway based on the forwarding status information and the actual data transmission status information of each gateway, including:
[0093] Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway;
[0094] Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, the gateway is determined to be a suspicious gateway; if not, the gateway is determined not to be a suspicious gateway.
[0095] In the above technical solution, a large number of gateways are provided within the distributed network, each of which can serve as a data transmission node for a corresponding data transmission link within the distributed network. This means that the data transit transmission performance of the gateway itself directly affects the overall data transmission performance of the data transmission link within which it is located. Given the large number of gateways within the distributed network, checking all gateways one by one would not only require a large amount of manpower and material resources and be inefficient, but would also fail to ensure the normal data transmission operation of the corresponding data transmission link during the checking process. To this end, a test message is sent to all gateways, and the forwarding status of each gateway after receiving the test message is obtained, thereby making a preliminary assessment of the data transmission performance of each gateway. Specifically, the available bandwidth of each active data transmission link within the distributed network is obtained. The active data transmission link may be, but is not limited to, a data transmission link that continuously performs data transmission operations within a preset time interval. The available bandwidth may be, but is not limited to, the remaining available bandwidth value of the active data transmission link. The minimum available bandwidth of each of the available bandwidths of all active data transmission links is determined, and based on the minimum available bandwidth, the message transmission data volume that all active data transmission links can withstand is determined, where the message transmission data volume matches the minimum available bandwidth. Based on the data volume transmitted by the message, a test message with periodic code distribution characteristics is constructed, so that the data volume of the test message is less than or equal to the data volume transmitted by the message, and the code content is periodic. This ensures that the test message is quickly transmitted to each gateway within the distributed network and facilitates the identification of the test message from the code content level.
[0096] After receiving a test message, each gateway forwards it according to its preset destination address. Each gateway decomposes the test message into several message packets, which are then queued to form a message packet queue. All message packets in the message packet queue are then forwarded sequentially. If a gateway has security issues, the gateway's forwarding of all message packets in the message packet queue may be delayed, making it impossible to ensure that all message packets are forwarded within the specified timeframe. Therefore, by monitoring the forwarding process of each gateway after receiving the test message, each gateway obtains forwarding status information for the test message. This forwarding status information is then compared with the transmission progress information corresponding to each gateway's queue of pending data packets, and a time difference is determined. If the time difference is greater than a preset difference threshold, the gateway is determined to have experienced a delay in forwarding the message packet, and the gateway is designated as a suspicious gateway. Otherwise, the gateway is determined to have experienced no delay in forwarding the message packet, facilitating subsequent investigation of suspicious gateways and improving the efficiency of gateway detection within the distributed network.
[0097] Preferably, the subnetwork division module is configured to divide the distributed network into a plurality of subnetworks based on the locations of all suspicious gateways within the distributed network, including:
[0098] Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways. This is used to divide all suspicious gateways into several gateway clusters. Based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into several subnetworks.
[0099] The data time-sharing sampling module is used to perform time-sharing data sampling on all sub-networks based on the gateway connection characteristics of each sub-network, and obtain several data sample sets corresponding to each sub-network, including:
[0100] Based on the number and bandwidth of external links of the gateways of all subnetworks, the data transmission flow rate of all subnetworks is estimated; based on the data transmission flow rate, the length of time occupied by data extraction of each subnetwork during the time-sharing data sampling process of all subnetworks is determined, so as to obtain several data sample sets corresponding to all subnetworks one by one.
[0101] In the above technical solution, a suspicious gateway can negatively impact data transmission within the adjacent network centered on it, potentially causing intrusion or hijacking of other gateways and creating security issues. To conduct a comprehensive gateway inspection within a distributed network, a cluster analysis is performed on all suspicious gateways based on their locations within the distributed network. The probability of data interaction between any two suspicious gateways is estimated. This cluster analysis can be implemented using a deep neural network model, which is not described in detail here. If the probability of data interaction between two suspicious gateways exceeds a preset probability threshold, the two suspicious gateways are assigned to the same gateway cluster. The distributed network is then divided into several subnetworks based on the coverage of each gateway cluster within the distributed network, such that each gateway cluster uniquely corresponds to a subnetwork. Furthermore, based on the number and bandwidth of each subnetwork's gateway external links, the external data transmission rate of each subnetwork is estimated. This external data transmission rate refers to the total data transmission rate of gateways within the subnetwork to gateways outside the subnetwork. The greater the rate of external data transmission of the sub-network, the longer the time taken for data extraction of the sub-network during the time-sharing data sampling of all sub-networks. This ensures balanced and equal data sampling of all sub-networks, so that the collected data sample set can accurately and comprehensively reflect the data forwarding status of the corresponding sub-network, providing a sufficient and reliable data basis for the subsequent identification of security anomalies within the sub-network.
[0102] Preferably, the security abnormality event judgment module is used to analyze the data sample set to determine whether a security abnormality event occurs within the sub-network, including:
[0103] Performing a neural network model analysis on the data sample set to determine whether there is data omission or illegal data tampering during the transmission of the data packet corresponding to the data sample set within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network;
[0104] The abnormal data transmission link determination module is used to trace the data transmission within the sub-network where the abnormal security event occurred and determine the abnormal data transmission link within the sub-network, including:
[0105] Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs. Based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
[0106] In the above technical solution, a convolutional neural network model is used to learn and analyze the data sample set to determine whether the data packet corresponding to the data sample set has data omissions or illegal data tampering during the transmission process within the sub-network, and accurately judge the data transmission security within the sub-network. In addition, the transmission path label of the data packet with data omissions or illegal data tampering within the sub-network where the security anomaly event occurred is obtained. The transmission path label refers to the path address label of the data transmission link within the sub-network through which the data packet with data omissions or illegal data tampering within the sub-network passes; and based on the transmission path label, the data transmission of the sub-network where the security anomaly event occurred is traced to determine the abnormal data transmission link within the sub-network, thereby narrowing the gateway security inspection and detection of the distributed network to the gateway security inspection of the abnormal data transmission link, greatly reducing the scope of the gateway security inspection and reducing the workload of the gateway security inspection.
[0107] Preferably, the non-secure gateway identification module is configured to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link, including:
[0108] Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway;
[0109] Based on the data stream transmission loss characteristic information, determine the probability of data stream transmission error time occurrence of all gateways under the abnormal data transmission link; based on the data stream transmission error time occurrence probability, identify the non-secure gateways included in the abnormal data transmission link;
[0110] The data transmission link resetting module is configured to reset the data transmission link of the distributed network based on the location of the non-secure gateway within the distributed network, including:
[0111] Based on the position of the non-secure gateway inside the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
[0112] In the above technical solution, the characteristic code position changes of the data packets received by all gateways under the abnormal data transmission link are compared. If the abnormal data transmission link includes an insecure gateway, the data packet will lose some data code after being transferred through the insecure gateway. In this case, the characteristic code position within the data packet will also change accordingly. The greater the characteristic code position change within the data packet, the more data code content is lost in the data packet. Therefore, the characteristic code position changes of the data packets received by all gateways under the abnormal data transmission link are compared to determine the amount of data code loss when each gateway receives the same data packet. This determines the data flow transmission loss ratio and the data flow interval where transmission loss occurs for each gateway, thereby quantitatively identifying the data loss situation during data transfer for each gateway. Based on the data flow transmission loss characteristic information, the data flow transmission error time probability of each gateway under the abnormal data transmission link is determined. The data flow transmission error time probability refers to the probability that each gateway will fail to transfer and send the data flow completely within a specified time range during data flow transmission. If the data flow transmission error time probability exceeds a preset probability threshold, the corresponding gateway is determined as an insecure gateway. Based on the location of the non-secure gateway within the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, so that the data transmission link of the distributed network is reset, and reliable adjustment of the data transmission link within the distributed network is achieved to maintain the normal operation of the entire network.
[0113] As can be seen from the contents of the above embodiments, the network security detection method and system based on distributed gateway screening sends test messages to all gateways in the distributed network, identifies suspicious gateways based on the gateway's forwarding status of the test message and the actual data transmission situation, and performs preliminary screening of gateways with security issues within the distributed network; based on the location of the suspicious gateway, the distributed network is divided into several sub-networks, and time-sharing data sampling is performed on all sub-networks to obtain several data sample sets, which provide data support for subsequent judgment on whether security abnormalities occur in the sub-network; through data transmission tracing, the abnormal data transmission link within the sub-network is determined, and the screening of gateways is narrowed to the scope of the data transmission link, reducing the screening workload; based on the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, the non-safe gateway is screened and determined, so as to reset the data transmission link of the distributed network, realize efficient and accurate security detection of the gateway and reliable adjustment of the data transmission link, and maintain the normal operation of the network as a whole.
[0114] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A network security detection method based on distributed gateway inspection is characterized by: It includes the following steps: Step S1: Based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission status information of each gateway, whether the gateway is a suspicious gateway is determined; Step S2: Based on the locations of all suspicious gateways within the distributed network, the distributed network is divided into several sub-networks; based on the gateway connection characteristics of all sub-networks, time-sharing data sampling is performed on all sub-networks to obtain several data sample sets corresponding to each sub-network, which include: Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways, thereby dividing all suspicious gateways into a number of gateway clusters; and based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into a number of sub-networks. Based on the number and bandwidth of external links connected to the gateways of all subnetworks, the data transmission rate of each subnetwork is estimated; based on the data transmission rate, the length of time taken for data extraction from each subnetwork during the time-sharing data sampling process of all subnetworks is determined, thereby obtaining a number of data sample sets corresponding to all subnetworks; Step S3: Analyze the data sample set to determine whether a security anomaly event occurs within the sub-network; trace the data transmission within the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network; Step S4, obtain the data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, check and determine the non-safe gateways included in the abnormal data transmission link; based on the position of the non-safe gateway inside the distributed network, reset the data transmission link of the distributed network.
2. The network security detection method based on distributed gateway screening according to claim 1 is characterized in that: In step S1, based on the bandwidth usage status of the distributed network, a test message is sent to all gateways of the distributed network; forwarding status information of each gateway for the test message is obtained, and based on the forwarding status information and the actual data transmission information of each gateway, whether the gateway is a suspicious gateway is determined, including: Determining, based on the available bandwidth of all active data transmission links within the distributed network, a message transmission data volume that can be supported by all active data transmission links; constructing a test message having a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network; Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway; Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, it is determined that the gateway is a suspicious gateway; if not, it is determined that the gateway is not a suspicious gateway.
3. The network security detection method based on distributed gateway inspection according to claim 1, characterized in that: In step S3, the data sample set is analyzed to determine whether a security anomaly occurs within the sub-network; Tracing data transmission within the sub-network where the security anomaly occurred to determine the abnormal data transmission link within the sub-network, including: Performing a neural network model analysis on the data sample set to determine whether data packets corresponding to the data sample set have data omissions or illegal data tampering during transmission within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network; Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs, and based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
4. The network security detection method based on distributed gateway screening according to claim 1 is characterized in that: In step S4, data flow transmission loss characteristic information of all gateways under the abnormal data transmission link is obtained, and based on the data flow transmission loss characteristic information, the non-secure gateways included in the abnormal data transmission link are checked and determined; Resetting a data transmission link of the distributed network based on a location of the non-secure gateway within the distributed network includes: Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the amount of data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway; Based on the data stream transmission loss characteristic information, the probability of occurrence of data stream transmission errors for all gateways under the data transmission abnormality link is determined; based on the probability of occurrence of data stream transmission errors, the non-secure gateways included in the data transmission abnormality link are checked and determined; based on the position of the non-secure gateway inside the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
5. A network security detection system based on distributed gateway inspection is characterized by: include: A test message sending module, configured to send test messages to all gateways of the distributed network based on the bandwidth usage status of the distributed network; A suspicious gateway identification module is used to obtain forwarding status information of each gateway for the test message, and determine whether the gateway is a suspicious gateway based on the forwarding status information and the real-time data transmission information of each gateway; A subnetwork partitioning module is configured to partition the distributed network into a plurality of subnetworks based on the locations of all suspicious gateways within the distributed network, comprising: Based on the locations of all suspicious gateways within the distributed network, cluster analysis is performed on all suspicious gateways to estimate the probability of data interaction between any two suspicious gateways, thereby dividing all suspicious gateways into a number of gateway clusters; and based on the coverage of each gateway cluster within the distributed network, the distributed network is divided into a number of sub-networks. The data time-sharing sampling module is used to perform time-sharing data sampling on all sub-networks based on the gateway connection characteristics of all sub-networks, and obtain several data sample sets corresponding to each sub-network, which include: Based on the number and bandwidth of external links connected to the gateways of all subnetworks, the data transmission rate of each subnetwork is estimated; based on the data transmission rate, the length of time taken for data extraction from each subnetwork during the time-sharing data sampling process of all subnetworks is determined, thereby obtaining a number of data sample sets corresponding to all subnetworks; A security anomaly event judgment module, configured to analyze the data sample set and determine whether a security anomaly event occurs within the sub-network; A data transmission abnormal link determination module is used to trace the data transmission inside the sub-network where the security abnormality event occurs and determine the data transmission abnormal link inside the sub-network; A non-secure gateway identification module is configured to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link; The data transmission link resetting module is used to reset the data transmission link of the distributed network based on the position of the non-secure gateway inside the distributed network.
6. The network security detection system based on distributed gateway troubleshooting according to claim 5, characterized in that: The test message sending module is configured to send test messages to all gateways of the distributed network based on the bandwidth usage status of the distributed network, including: Determining, based on the available bandwidth of all active data transmission links within the distributed network, a message transmission data volume that can be supported by all active data transmission links; constructing a test message having a periodic code distribution characteristic based on the message transmission data volume, and sending the test message to all gateways in the distributed network; The suspicious gateway identification module is configured to obtain forwarding status information of each gateway for the test message, and determine whether the gateway is a suspicious gateway based on the forwarding status information and the actual data transmission information of each gateway, including: Monitor the forwarding process of each gateway after receiving the test message to obtain forwarding status information of the test message by each gateway; wherein the forwarding status information includes forwarding progress status information of all message packets after the test message is decomposed into multiple message packets with the same code content at the gateway; Based on the forwarding status information and the transmission live process information corresponding to the queue of data packets to be transmitted of each gateway, it is determined whether the gateway delays forwarding the message subpacket; if so, it is determined that the gateway is a suspicious gateway; if not, it is determined that the gateway is not a suspicious gateway.
7. The network security detection system based on distributed gateway inspection according to claim 5, characterized in that: The security abnormality event judgment module is used to analyze the data sample set to determine whether a security abnormality event occurs within the sub-network, including: Performing a neural network model analysis on the data sample set to determine whether data packets corresponding to the data sample set have data omissions or illegal data tampering during transmission within the sub-network; if so, determining that a security anomaly has occurred within the sub-network; if not, determining that no security anomaly has occurred within the sub-network; The abnormal data transmission link determination module is configured to trace data transmission within the sub-network where the abnormal security event occurs and determine the abnormal data transmission link within the sub-network, including: Obtain the transmission path label of the data packet where data omission or illegal data tampering occurs within the sub-network where the security anomaly event occurs, and based on the transmission path label, trace the data transmission of the sub-network where the security anomaly event occurs to determine the abnormal data transmission link within the sub-network.
8. The network security detection system based on distributed gateway troubleshooting according to claim 5, characterized in that: The non-secure gateway identification module is configured to obtain data flow transmission loss characteristic information of all gateways under the abnormal data transmission link, and based on the data flow transmission loss characteristic information, identify the non-secure gateways included in the abnormal data transmission link, including: Comparing changes in characteristic code positions of data packets received by all gateways under the abnormal data transmission link to determine the amount of data code loss at each gateway when receiving the same data packet; determining data stream transmission loss characteristic information for all gateways based on the amount of data code loss at all gateways; wherein the data stream transmission loss characteristic information includes the data stream transmission loss ratio and the data stream interval where the transmission loss occurs for each gateway; Based on the data stream transmission loss characteristic information, determine the probability of data stream transmission error time occurrence of all gateways under the abnormal data transmission link; based on the data stream transmission error time occurrence probability, identify the non-secure gateways included in the abnormal data transmission link; The data transmission link resetting module is configured to reset the data transmission link of the distributed network based on the location of the non-secure gateway within the distributed network, including: Based on the position of the non-secure gateway inside the distributed network, the shortest data transmission link that bypasses the non-secure gateway to maintain the current normal data transmission operation is determined, thereby resetting the data transmission link of the distributed network.
Citation Information
Patent Citations
Communication security maintenance device based on power edge gateway equipment
CN112464295A
Method and system for safely switching and transmitting data streams of communication network
CN118540154A