Network Partition Control and Terminal Security Maintenance Method and System

By monitoring the data interaction status information of gateway nodes in the network, dividing network sub-regions, and performing global data sampling and attack identification, the problem of network and terminal synchronization security protection in the prior art is solved, and efficient network security maintenance is achieved.

CN119420519BActive Publication Date: 2025-06-27INFORMATION & TELECOMM COMPANY SICHUAN ELECTRIC POWER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411507478.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-28
Publication Date
2025-06-27
Estimated Expiration
2044-10-28

AI Technical Summary

Technical Problem

The existing technology is difficult to synchronize the security protection of the network and terminals, and cannot effectively identify and intercept security risks within the network, resulting in insufficiency of the overall network security and control efficiency.

Method used

By monitoring the data interaction status information of all gateway nodes in the network, determining the data interaction relationship between the gateway nodes and terminals, dividing the network sub-regions, and global sampling is performed based on the link characteristics of the active data transmission channel to obtain the full-path data sample set. Based on the attack data flow attribute information, the attack occurrence information in the terminal and the operation thread that needs to be controlled are identified to carry out security prevention and control operations.

Benefits of technology

It realizes synchronous security maintenance between the network and terminals, can accurately identify and intercept attacks within the network, and improves the overall security and control efficiency of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420519B_ABST
    Figure CN119420519B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security, specifically to a method and system for network partition control and terminal security maintenance. By monitoring the data interaction status information of all gateway nodes in the network, the data interaction relationship between all gateway nodes and all terminals connected to the network is determined, and several network sub-regions are thus divided. Based on the link characteristics of the active data transmission channels within the network sub-regions, global sampling is performed to obtain a full-path data sample set. Based on the attack data stream attribute information within the active data transmission channels, the attack occurrence information of the terminals is determined, and the operation threads that need to be controlled within the terminals are identified, and the terminals are checked and identified at the thread level. Based on the running associated objects of the abnormal operation data streams within the operation threads that need to be controlled in the terminals, security prevention and control operations are performed on the terminals, and attacks on the terminals are identified and intercepted, realizing synchronous security maintenance of the network and the terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and particularly to a method and system for network partition control and terminal security maintenance. Background Art

[0002] As an intermediary for data interaction and transmission between different terminals, the structure of the gateway distribution within the network will affect the data interaction and transmission efficiency between different terminals and the security of each terminal. If a terminal connected to the network is hijacked and becomes an attack source, the attack source will initiate attacks on other terminals connected to it through the network. At the same time, the gateways within the network will also become new attack sources, thus endangering the security of the entire network. Modern networks are large in scale and complex in structure. If only each gateway within the network is checked one by one, it will be impossible to detect security risks within the network in a timely and efficient manner. Instead, it will increase the number of terminals connected to the network being attacked, reducing the overall security and control efficiency of the network. Existing security checking methods such as attack recognition for the network have problems of large workload and low efficiency, and cannot accurately identify and intercept attacks for the entire network and the terminals connected to it, and cannot perform security protection on the network and terminals synchronously. Summary of the Invention

[0003] In view of the defects existing in the prior art, the present invention provides a method and system for network partition control and terminal security maintenance. By listening to obtain the data interaction status information of all gateway nodes in the network, the data interaction relationship between all gateway nodes and all terminals connected to the network is determined, and then several network sub-regions are divided. Network partitioning is performed on the data interaction behavior between gateway nodes and terminals, and the terminals are accurately associated with the network partitions; based on the link characteristics of the active data transmission channels within the network sub-regions, global sampling is performed to obtain a full-path data sample set, and the transit data of all gateway nodes within the active data transmission channels is comprehensively extracted; based on the attack data stream attribute information within the active data transmission channels, the attack occurrence information of the terminals is determined, and the operation threads that need to be controlled within the terminals are identified, and the terminals are checked and identified at the thread level; based on the running association objects of the abnormal operation data streams within the operation threads that need to be controlled within the terminals, security prevention and control operations are performed on the terminals, and attacks on the terminals are identified and intercepted, realizing synchronous security maintenance of the network and terminals.

[0004] The present invention provides a method for network partition control and terminal security maintenance, including the following steps:

[0005] Step S1, monitor all gateway nodes in the network to obtain the data interaction status information of each gateway node; based on the data interaction status information, determine the data interaction relationship between all gateway nodes and all terminals connected to the network; based on the data interaction relationship, divide the network into several network sub-regions;

[0006] Step S2: Based on the access locations of all terminals within the network sub-region, identify the active data transmission channels within the network sub-region; based on the link characteristics of the active data transmission channels, perform global sampling on the active data transmission channels to obtain a full-path data sample set of the active data transmission channels.

[0007] Step S3: Perform time-evolution analysis on the full-path data sample set to obtain attack data flow attribute information within the active data transmission channels; based on the attack data flow attribute information, determine the attack occurrence information of the terminals corresponding to the active data transmission channels; based on the attack occurrence information, identify the operation threads within the terminals that need to be controlled.

[0008] Step S4: Perform operation data analysis on the operation threads that need to be controlled to determine the abnormal operation data flows within the operation threads that need to be controlled; based on the running association objects of the abnormal operation data flows within the terminal, perform security prevention and control operations on the terminal.

[0009] In an embodiment disclosed in the present application, in the step S1, monitor all the gateway nodes in the network to obtain the data interaction status information of each gateway node; based on the data interaction status information, determine the data interaction relationship between all the gateway nodes and all the terminals accessed within the network; based on the data interaction relationship, divide the network into several network sub-regions, including:

[0010] Based on the network distances between all the gateway nodes in the network, obtain the distribution density information of all the gateway nodes within the network; based on the distribution density information, divide all the gateway nodes into several gateway node groups; based on the number of gateway nodes included in each gateway node group, perform cyclic listening on all the gateway nodes included in each gateway node group in turn to obtain the transmission target address change information of the uplink data / downlink data of each gateway node, and use this as the data interaction status information.

[0011] Based on the transmission target address change information of the uplink data / downlink data, determine the data interaction frequency between each gateway node and all the terminals accessed within the network, thereby determining the data interaction occurrence probability information between all the gateway nodes and all the terminals accessed within the network, and use this as the data interaction relationship; based on the data interaction occurrence probability information, divide the network into several network sub-regions; wherein, all the gateway nodes within each network sub-region can interact with the same terminal.

[0012] In an embodiment disclosed in the present application, in the step S2, based on the access locations of all terminals in the network sub-region, identify the active data transmission channels in the network sub-region; based on the link characteristics of the active data transmission channels, perform global sampling on the active data transmission channels to obtain a full-path data sample set of the active data transmission channels, including:

[0013] Based on the access gateway location addresses of all terminals in the network sub-region, determine all channels through which all terminals in all network sub-regions can perform data transmission; based on the data transmission rate change information of each of all channels, identify the active data transmission channels in the network sub-region from all channels;

[0014] Based on the data transfer traffic of each of all gateway nodes subordinate to the active data transmission channels, perform differential sampling on all gateway nodes subordinate to the active data transmission channels to obtain the transfer data samples of each of all gateway nodes subordinate to the active data transmission channels; based on the data transmission order of all gateway nodes subordinate to the active data transmission channels, sort and integrate the transfer data samples of each gateway node to obtain the full-path data sample set of the active data transmission channels.

[0015] In an embodiment disclosed in the present application, in the step S3, perform time-evolution analysis on the full-path data sample set to obtain the attack data flow attribute information in the active data transmission channel; based on the attack data flow attribute information, determine the attack occurrence information of the terminal corresponding to the active data transmission channel; based on the attack occurrence information, identify the operation threads in the terminal that need to be controlled, including:

[0016] Perform time-evolution analysis on the transfer data samples of each of all gateway nodes subordinate to the active data transmission channels included in the full-path data sample set to obtain the attack data flow change information during the transfer data process of each gateway node subordinate to the active data transmission channel, and use this as the attack data flow attribute information in the active data transmission channel;

[0017] Based on the attack data flow change information, determine the occurrence time information and the occurrence thread location information of the terminal corresponding to the active data transmission channel when it is in the attack data volume reception limit state; based on the occurrence time information and the occurrence thread location information, identify the operation threads in the terminal that need to be controlled.

[0018] In an embodiment disclosed in the present application, in the step S4, perform operation data analysis on the operation threads that need to be controlled to determine the abnormal operation data flows in the operation threads that need to be controlled; based on the running association objects of the abnormal operation data flows in the terminal, perform security prevention and control operations on the terminal, including:

[0019] Perform operation data component analysis on the operation threads to be controlled, and determine the operation data code attribute information within the operation threads to be controlled; based on the operation data code attribute information, determine the abnormal operation data streams within the operation threads to be controlled;

[0020] Based on the work tasks associated with the abnormal operation data streams within the terminal, determine all the application programs associated with the running process of the abnormal operation data streams within the terminal, so as to perform attack intrusion isolation or abnormal operation data stream shielding on all the associated application programs.

[0021] The present invention also provides a network partition control and terminal security maintenance system, including:

[0022] A gateway node monitoring module, used to monitor all gateway nodes in the network to obtain the data interaction status information of each gateway node;

[0023] A network partition module, used to determine the data interaction relationships between all gateway nodes and all terminals connected to the network based on the data interaction status information; based on the data interaction relationships, divide the network into several network sub-regions;

[0024] A data transmission channel identification module, used to identify the active data transmission channels within the network sub-regions based on the access positions of all terminals within the network sub-regions;

[0025] A data sampling processing module, used to perform global sampling on the active data transmission channels based on the link characteristics of the active data transmission channels to obtain a full-path data sample set of the active data transmission channels;

[0026] A data sample analysis module, used to perform time-evolution analysis on the full-path data sample set to obtain the attack data stream attribute information within the active data transmission channels;

[0027] An operation thread identification module, used to determine the attack occurrence information of the terminals corresponding to the active data transmission channels based on the attack data stream attribute information; based on the attack occurrence information, identify the operation threads to be controlled within the terminals;

[0028] An abnormal operation data stream determination module, used to perform operation data analysis on the operation threads to be controlled to determine the abnormal operation data streams within the operation threads to be controlled;

[0029] A security prevention and control operation module, used to perform security prevention and control operations on the terminal based on the running associated objects of the abnormal operation data streams within the terminal.

[0030] In an embodiment disclosed in the present application, the gateway node monitoring module is used to monitor all gateway nodes in the network to obtain the data interaction status information of each of all gateway nodes, including:

[0031] Based on the network distances between all gateway nodes in the network, obtain the distribution density information of all gateway nodes in the network; based on the distribution density information, divide all gateway nodes into several gateway node groups; based on the number of gateway nodes included in each gateway node group, perform round-robin monitoring on all gateway nodes included in each gateway node group to obtain the transmission target address change information of the uplink data / downlink data of each of all gateway nodes, and use this as the data interaction status information;

[0032] The network partitioning module is used to determine the data interaction relationship between all gateway nodes and all terminals connected to the network based on the data interaction status information; based on the data interaction relationship, divide the network into several network sub-regions, including:

[0033] Based on the transmission target address change information of the uplink data / downlink data, determine the data interaction frequency between each gateway node and all terminals connected to the network, and thereby determine the data interaction occurrence probability information between all gateway nodes and all terminals connected to the network, and use this as the data interaction relationship; based on the data interaction occurrence probability information, divide the network into several network sub-regions; wherein, all gateway nodes within each network sub-region can perform data interaction with the same terminal.

[0034] In an embodiment disclosed in the present application, the data transmission channel identification module is used to identify the active data transmission channels within the network sub-region based on the access positions of all terminals within the network sub-region, including:

[0035] Based on the access gateway location addresses of all terminals within the network sub-region, determine all channels through which all terminals within all network sub-regions can perform data transmission; based on the data transmission rate change information of each of all channels, identify the active data transmission channels within the network sub-region from all channels;

[0036] The data sampling and processing module is used to perform global sampling on the active data transmission channels based on the link characteristics of the active data transmission channels to obtain the full-path data sample set of the active data transmission channels, including:

[0037] Based on the data transfer traffic of each gateway node under the active data transfer channel, all gateway nodes under the active data transfer channel are distinguished and sampled to obtain the transfer data samples of each gateway node under the active data transfer channel; based on the data transfer order of all gateway nodes under the active data transfer channel, the transfer data samples of each gateway node are sorted and integrated to obtain the full-path data sample set of the active data transfer channel.

[0038] In an embodiment disclosed in the present application, the data sample analysis module is used to perform time-evolution analysis on the full-path data sample set to obtain the attack data flow attribute information in the active data transfer channel, including:

[0039] Perform time-evolution analysis on the transfer data samples of each gateway node under the active data transfer channel included in the full-path data sample set to obtain the attack data flow change information during the transfer data process of each gateway node under the active data transfer channel, and use this as the attack data flow attribute information in the active data transfer channel;

[0040] The operation thread identification module is used to determine the attack occurrence information of the terminal corresponding to the active data transfer channel based on the attack data flow attribute information; based on the attack occurrence information, identify the operation threads in the terminal that need to be controlled, including:

[0041] Based on the attack data flow change information, determine the occurrence time information and the occurrence thread position information of the terminal corresponding to the active data transfer channel when it is in the attack data volume reception limit state; based on the occurrence time information and the occurrence thread position information, identify the operation threads in the terminal that need to be controlled.

[0042] In an embodiment disclosed in the present application, the abnormal operation data flow determination module is used to perform operation data analysis on the operation threads that need to be controlled to determine the abnormal operation data flows in the operation threads that need to be controlled, including:

[0043] Perform operation data component analysis on the operation threads that need to be controlled to determine the operation data code attribute information in the operation threads that need to be controlled; based on the operation data code attribute information, determine the abnormal operation data flows in the operation threads that need to be controlled;

[0044] The security prevention and control operation module is used to perform security prevention and control operations on the terminal based on the running association objects of the abnormal operation data flows in the terminal, including:

[0045] Based on the work tasks associated with the abnormal operation data stream within the terminal, determine all the application programs associated with the running process of the abnormal operation data stream within the terminal, so as to isolate the attack and intrusion of the associated application programs or shield the abnormal operation data stream.

[0046] Compared with the prior art, the network partition control and terminal security maintenance method and system monitor the data interaction status information of all gateway nodes in the network, determine the data interaction relationship between all gateway nodes and all terminals connected to the network, and thus divide several network sub-regions, perform network partitioning on the data interaction behavior between the gateway nodes and the terminals, and accurately associate the terminals with the network partitions; based on the link characteristics of the active data transmission channels within the network sub-regions, perform global sampling to obtain a full-path data sample set, and comprehensively extract the transit data of all gateway nodes within the active data transmission channels; based on the attack data stream attribute information within the active data transmission channels, determine the attack occurrence information of the terminals, so as to identify the operation threads that need to be controlled within the terminals, and conduct troubleshooting and identification on the terminals at the thread level; based on the running association objects of the abnormal operation data streams within the operation threads that need to be controlled within the terminals, perform security prevention and control operations on the terminals, identify and intercept attacks on the terminals, and achieve synchronous security maintenance of the network and the terminals.

[0047] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification, claims, and drawings.

[0048] The technical solutions of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0050] Figure 1 It is a flowchart of the network partition control and terminal security maintenance method provided by the present invention.

[0051] Figure 2 It is a framework diagram of the network partition control and terminal security maintenance system provided by the present invention. Detailed Embodiments

[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0053] Refer to Figure 1 , which is a schematic flowchart of the network partition control and terminal security maintenance method provided by the embodiment of the present invention. The network partition control and terminal security maintenance method includes:

[0054] Step S1, monitor all gateway nodes in the network to obtain the data interaction status information of each gateway node; based on the data interaction status information, determine the data interaction relationship between all gateway nodes and all terminals connected to the network; based on the data interaction relationship, divide the network into several network sub-regions;

[0055] Step S2, based on the access locations of all terminals in the network sub-region, identify the active data transmission channels in the network sub-region; based on the link characteristics of the active data transmission channels, perform global sampling on the active data transmission channels to obtain the full-path data sample set of the active data transmission channels;

[0056] Step S3, perform time-evolution analysis on the full-path data sample set to obtain the attack data flow attribute information in the active data transmission channel; based on the attack data flow attribute information, determine the attack occurrence information of the terminal corresponding to the active data transmission channel; based on the attack occurrence information, identify the operation threads in the terminal that need to be controlled;

[0057] Step S4, perform operation data analysis on the operation threads that need to be controlled to determine the abnormal operation data flows in the operation threads that need to be controlled; based on the running association objects of the abnormal operation data flows in the terminal, perform security prevention and control operations on the terminal.

[0058] The beneficial effects of the above technical solution are as follows: the network partition control and terminal security maintenance method monitors and obtains the data interaction status information of all gateway nodes in the network, thereby determining the data interaction relationship between all gateway nodes and all terminals connected to the network, thereby dividing the network into several sub-areas, performing network partitioning based on the data interaction behavior between the gateway nodes and the terminals, and accurately associating the terminals with the network partitions; based on the link characteristics of the active data transmission channels in the network sub-areas, global sampling is performed to obtain a full-path data sample set, and the transit data of all gateway nodes in the active data transmission channels is comprehensively extracted; based on the attack data flow attribute information in the active data transmission channel, the attack occurrence information of the terminal is determined, thereby identifying the operating threads that need to be controlled in the terminal, and checking and identifying the terminals at the thread level; based on the operation-related objects of the abnormal operation data flow in the operation thread that needs to be controlled in the terminal, security prevention and control operations are performed on the terminal, and attacks are identified and intercepted on the terminal, so as to achieve synchronous security maintenance of the network and the terminal.

[0059] Preferably, in step S1, all gateway nodes in the network are monitored to obtain data interaction status information of all gateway nodes; based on the data interaction status information, the data interaction relationship between all gateway nodes and all terminals accessed in the network is determined; based on the data interaction relationship, the network is divided into several network sub-areas, including:

[0060] Based on the network distances between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained; based on the distribution density information, all gateway nodes are divided into several gateway node groups; based on the number of gateway nodes included in each gateway node group, all gateway nodes included in each gateway node group are monitored in turn and cycle to obtain the transmission target address change information of the uplink data / downlink data of all gateway nodes, which is used as the data interaction status information;

[0061] Based on the transmission target address change information of the uplink data / downlink data, the data interaction frequency between each gateway node and all terminals connected to the network is determined, so as to determine the probability information of data interaction between all gateway nodes and all terminals connected to the network, and use this as the data interaction relationship; based on the data interaction probability information, the network is divided into several network sub-areas; wherein all gateway nodes in each network sub-area can interact with the same terminal for data.

[0062] The beneficial effects of the above technical solution are as follows: the network contains a large number of gateway nodes, and each gateway node, as a data transfer node, can transfer data to other gateway nodes according to the data transmission target address, so as to realize data transmission along the corresponding path within the network. The distribution of gateway nodes within the network is not uniform, that is, the network distance between any two adjacent gateway nodes is not the same, so that the distribution density of gateway nodes in a certain area within the network is not the same. In order to monitor all gateway nodes within the network equally, based on the network distance between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained, that is, the number of gateway nodes within the unit data transmission distance in the network. Based on the distribution density information, all gateway nodes are divided into several gateway node groups, so that the number of gateway nodes contained in each gateway node group is basically the same, and then based on the number of gateway nodes contained in each gateway node group, all gateway nodes contained in each gateway node group are monitored in turn, that is, all gateway nodes contained in each gateway node group are periodically monitored for an equal period of time, and the transmission target address change information of the uplink data / downlink data of each gateway node under each gateway node group is obtained, that is, the change information of the transmission target address of the uplink data of each gateway node in different time periods during the data relay transmission process and the change information of the transmission target address of the downlink data of each gateway node in different time periods, so as to quantitatively represent the data interaction between each gateway node and different terminals during the data relay transmission process. In addition, based on the transmission target address change information of uplink data / downlink data, the frequency of data interaction between each gateway node and all terminals connected to the network is determined; wherein the data interaction frequency may be, but is not limited to, the number of occurrences of data interaction between each gateway node and each terminal connected to the network within a unit time length, and then the data interaction frequency is converted and processed to obtain the probability information of data interaction between all gateway nodes and all terminals connected to the network, thereby quantitatively representing the frequency of data interaction between different gateway nodes and different terminals, and providing a reliable basis for zoning the network. Based on the probability information of data interaction, the network is divided into several network sub-areas, so that all gateway nodes in each network sub-area can interact with the same terminal, which is convenient for the subsequent centralized data sampling of all gateway nodes that interact with the same terminal, and provides a global data basis for identifying the security of network sub-areas.

[0063] Preferably, in step S2, based on the access locations of all terminals in the network sub-area, an active data transmission channel in the network sub-area is identified; based on the link characteristics of the active data transmission channel, the active data transmission channel is globally sampled to obtain a full path data sample set of the active data transmission channel, including:

[0064] Based on the access gateway location addresses of all terminals within the network sub-region, determine all channels through which all terminals within all network sub-regions can perform data transmission; based on the data transmission rate change information of each of all channels, identify the active data transmission channels within the network sub-region from all channels;

[0065] Based on the data transfer traffic of each of all network gateway nodes subordinate to the active data transmission channel, perform differential sampling on all network gateway nodes subordinate to the active data transmission channel to obtain the transfer data samples of each of all network gateway nodes subordinate to the active data transmission channel; based on the data transmission sequence of all network gateway nodes subordinate to the active data transmission channel, sort and integrate the transfer data samples of each network gateway node to obtain the full-path data sample set of the active data transmission channel.

[0066] The beneficial effects of the above technical solution are as follows: All terminals within the network sub-region basically perform data interaction and transmission through the network gateway nodes within the network sub-region, that is, the network gateway nodes within the network sub-region mainly constitute the data transmission channels of the corresponding terminals. However, not all data transmission channels are commonly used for the actual data transmission of terminals, that is, some data transmission channels are idle for a long time, and only some data transmission channels are active. In order to narrow the scope of sampling and investigation of the data transmission channels within the network sub-region, based on the access gateway location addresses of all terminals within the network sub-region, determine all channels through which all terminals within all network sub-regions can perform data transmission, and based on the data transmission rate change information of each of all channels, determine whether the average data transmission rate of each channel exceeds the preset transmission rate threshold. If so, determine the channel as an active data transmission channel; if not, do not determine the channel as an active data transmission channel, thereby limiting the scope of data sampling within the network sub-region to the active data transmission channels and reducing the workload of data sampling. Also, based on the data transfer traffic of each of all network gateway nodes subordinate to the active data transmission channel, perform differential sampling on all network gateway nodes subordinate to the active data transmission channel to obtain the transfer data samples of each of all network gateway nodes subordinate to the active data transmission channel. When the data transfer traffic of the network gateway nodes subordinate to the active data transmission channel is larger, the data sampling volume for the network gateway node is larger, ensuring that all network gateway nodes can be comprehensively and accurately sampled and processed. Then, based on the data transmission sequence of all network gateway nodes subordinate to the active data transmission channel, sort and integrate the transfer data samples of each network gateway node to obtain the full-path data sample set of the active data transmission channel, so that the full-path data sample set accurately reflects the data transfer situation of all network gateway nodes.

[0067] Preferably, in step S3, perform a time-evolution analysis on the full-path data sample set to obtain the attack data flow attribute information in the active data transmission channel; based on the attack data flow attribute information, determine the attack occurrence information of the terminal corresponding to the active data transmission channel; based on the attack occurrence information, identify the operation threads in the terminal that need to be controlled, including:

[0068] Perform a time-evolution analysis on the transit data samples of all the gateway nodes under the active data transmission channel included in the full-path data sample set to obtain the attack data flow change information during the transit data process of each gateway node under the active data transmission channel, and use this as the attack data flow attribute information in the active data transmission channel;

[0069] Based on the attack data flow change information, determine the occurrence time information and the occurrence thread position information of the terminal corresponding to the active data transmission channel when it is in the attack data volume reception limit state; based on the occurrence time information and the occurrence thread position information, identify the operation threads in the terminal that need to be controlled.

[0070] The beneficial effects of the above technical solution are as follows: Perform a time-evolution analysis on the transit data samples of all the gateway nodes under the active data transmission channel included in the full-path data sample set to obtain the attack data flow change information during the transit data process of each gateway node under the active data transmission channel, that is, the change information of the attack data flow size over time during the transit data process of each gateway node. Also, based on the attack data flow change information, determine the occurrence time information and the occurrence thread position information of the terminal corresponding to the active data transmission channel when it is in the attack data volume reception limit state, and use this to identify the operation threads in the terminal that need to be controlled, so as to accurately locate the operation threads in the terminal that have abnormal conditions due to network security problems.

[0071] Preferably, in step S4, perform an operation data analysis on the operation threads that need to be controlled to determine the abnormal operation data flow in the operation threads that need to be controlled; based on the running associated objects of the abnormal operation data flow in the terminal, perform security prevention and control operations on the terminal, including:

[0072] Perform an operation data component analysis on the operation threads that need to be controlled to determine the operation data code attribute information in the operation threads that need to be controlled; based on the operation data code attribute information, determine the abnormal operation data flow in the operation threads that need to be controlled;

[0073] Based on the work tasks associated with the abnormal operation data flow in the terminal, determine all the application programs associated with the abnormal operation data flow during its running process in the terminal, so as to perform attack intrusion isolation or abnormal operation data flow shielding on all the associated application programs.

[0074] The beneficial effects of the above technical solution are as follows: Analyze the operation data components of the operation thread to be controlled, and determine the operation data code attribute information within the operation thread to be controlled. The operation data code attribute information may include the type information of the operation data code and the proportion information of the garbled data volume. Based on the operation data code attribute information, determine the abnormal operation data stream within the operation thread to be controlled. For example, when the operation data code belongs to a preset type of data code or the proportion of the garbled data volume exceeds the preset proportion threshold, the corresponding operation data stream is determined as the abnormal operation data stream within the operation thread to be controlled. Additionally, based on the work tasks associated with the abnormal operation data stream within the terminal, determine all the application programs associated with the running process of the abnormal operation data stream within the terminal, so as to perform attack intrusion isolation or abnormal operation data stream shielding on all the associated application programs, perform security prevention and control operations on the terminal, identify and intercept attacks on the terminal, and achieve synchronous security maintenance of the network and the terminal, avoiding security problems caused by the mutual influence between the network and the terminals connected thereto.

[0075] See Figure 2 , which is a schematic framework diagram of the network partition control and terminal security maintenance system provided by an embodiment of the present invention. The network partition control and terminal security maintenance system includes:

[0076] A gateway node monitoring module, configured to monitor all gateway nodes in the network to obtain the data interaction status information of each gateway node;

[0077] A network partition module, configured to determine the data interaction relationship between all gateway nodes and all terminals connected to the network based on the data interaction status information; and divide the network into several network sub-regions based on the data interaction relationship;

[0078] A data transmission channel identification module, configured to identify the active data transmission channels within the network sub-region based on the access locations of all terminals within the network sub-region;

[0079] A data sampling and processing module, configured to globally sample the active data transmission channels based on the link characteristics of the active data transmission channels to obtain a full-path data sample set of the active data transmission channels;

[0080] A data sample analysis module, configured to perform time-evolution analysis on the full-path data sample set to obtain the attack data stream attribute information within the active data transmission channels;

[0081] An operation thread identification module, configured to determine the attack occurrence information of the terminal corresponding to the active data transmission channel based on the attack data stream attribute information; and identify the operation threads to be controlled within the terminal based on the attack occurrence information;

[0082] An abnormal operation data flow determination module is used to analyze the operation data of the operation thread that needs to be controlled, and determine the abnormal operation data flow in the operation thread that needs to be controlled;

[0083] The security control operation module is used to perform security control operations on the terminal based on the operation-related objects of the abnormal operation data flow in the terminal.

[0084] The beneficial effects of the above technical solution are as follows: the network partition control and terminal security maintenance system monitors and obtains the data interaction status information of all gateway nodes in the network, thereby determining the data interaction relationship between all gateway nodes and all terminals connected to the network, thereby dividing the network into several sub-areas, performing network partitioning based on the data interaction behavior between the gateway nodes and the terminals, and accurately associating the terminals with the network partitions; based on the link characteristics of the active data transmission channels in the network sub-areas, global sampling is performed to obtain a full-path data sample set, and the transit data of all gateway nodes in the active data transmission channels is comprehensively extracted; based on the attack data flow attribute information in the active data transmission channel, the attack occurrence information of the terminal is determined, thereby identifying the operating threads that need to be controlled in the terminal, and checking and identifying the terminals at the thread level; based on the operation-related objects of the abnormal operation data flow in the operation thread that needs to be controlled in the terminal, security prevention and control operations are performed on the terminal, and attacks are identified and intercepted on the terminal, so as to achieve synchronous security maintenance of the network and the terminal.

[0085] Preferably, the gateway node monitoring module is used to monitor all gateway nodes in the network to obtain data interaction status information of all gateway nodes, including:

[0086] Based on the network distances between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained; based on the distribution density information, all gateway nodes are divided into several gateway node groups; based on the number of gateway nodes included in each gateway node group, all gateway nodes included in each gateway node group are monitored in turn and cycle to obtain the transmission target address change information of the uplink data / downlink data of all gateway nodes, which is used as the data interaction status information;

[0087] The network partitioning module is used to determine the data interaction relationship between all gateway nodes and all terminals accessed in the network based on the data interaction state information; based on the data interaction relationship, the network is divided into a plurality of network sub-areas, including:

[0088] Based on the transmission target address change information of the uplink data / downlink data, determine the data interaction frequency between each gateway node and all terminals accessed within the network, so as to determine the data interaction occurrence probability information between all gateway nodes and all terminals accessed within the network, and use this as the data interaction relationship; based on the data interaction occurrence probability information, divide the network into several network sub-regions; wherein, all gateway nodes within each network sub-region can interact with the same terminal for data.

[0089] The beneficial effects of the above technical solution are as follows: the network contains a large number of gateway nodes, and each gateway node, as a data transfer node, can transfer data to other gateway nodes according to the data transmission target address, so as to realize data transmission along the corresponding path within the network. The distribution of gateway nodes within the network is not uniform, that is, the network distance between any two adjacent gateway nodes is not the same, so that the distribution density of gateway nodes in a certain area within the network is not the same. In order to monitor all gateway nodes within the network equally, based on the network distance between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained, that is, the number of gateway nodes within the unit data transmission distance in the network. Based on the distribution density information, all gateway nodes are divided into several gateway node groups, so that the number of gateway nodes contained in each gateway node group is basically the same, and then based on the number of gateway nodes contained in each gateway node group, all gateway nodes contained in each gateway node group are monitored in turn, that is, all gateway nodes contained in each gateway node group are periodically monitored for an equal period of time, and the transmission target address change information of the uplink data / downlink data of each gateway node under each gateway node group is obtained, that is, the change information of the transmission target address of the uplink data of each gateway node in different time periods during the data relay transmission process and the change information of the transmission target address of the downlink data of each gateway node in different time periods, so as to quantitatively represent the data interaction between each gateway node and different terminals during the data relay transmission process. In addition, based on the transmission target address change information of uplink data / downlink data, the frequency of data interaction between each gateway node and all terminals connected to the network is determined; wherein the data interaction frequency may be, but is not limited to, the number of occurrences of data interaction between each gateway node and each terminal connected to the network within a unit time length, and then the data interaction frequency is converted and processed to obtain the probability information of data interaction between all gateway nodes and all terminals connected to the network, thereby quantitatively representing the frequency of data interaction between different gateway nodes and different terminals, and providing a reliable basis for zoning the network. Based on the probability information of data interaction, the network is divided into several network sub-areas, so that all gateway nodes in each network sub-area can interact with the same terminal, which is convenient for the subsequent centralized data sampling of all gateway nodes that interact with the same terminal, and provides a global data basis for identifying the security of network sub-areas.

[0090] Preferably, the data transmission channel identification module is used to identify active data transmission channels in the network sub-area based on access locations of all terminals in the network sub-area, including:

[0091] Based on the access gateway location addresses of all terminals in the network sub-region, determine all channels through which all terminals in all network sub-regions can perform data transmission; based on the data transmission rate change information of each of all channels, identify the active data transmission channels in the network sub-region from all channels.

[0092] The data sampling processing module is used to perform global sampling on the active data transmission channel based on the link characteristics of the active data transmission channel to obtain a full-path data sample set of the active data transmission channel, including:

[0093] Based on the data transfer traffic of each of all network gateway nodes subordinate to the active data transmission channel, perform differential sampling on all network gateway nodes subordinate to the active data transmission channel to obtain the transfer data samples of each of all network gateway nodes subordinate to the active data transmission channel; based on the data transmission order of all network gateways subordinate to the active data transmission channel, sort and integrate the transfer data samples of each network gateway node to obtain the full-path data sample set of the active data transmission channel.

[0094] The beneficial effects of the above technical solution are as follows: All terminals within the network sub-region basically perform data interaction and transmission with each other through the gateway nodes within the network sub-region. That is, the gateway nodes within the network sub-region mainly constitute the data transmission channels for the corresponding terminals. However, not all data transmission channels are commonly used for the actual data transmission of the terminals. That is, some data transmission channels are idle for a long time, while only some data transmission channels are in an active state. To narrow the scope of sampling and investigation of the data transmission channels within the network sub-region, based on the access gateway location addresses of all terminals within the network sub-region, all channels through which all terminals within all network sub-regions can perform data transmission are determined. And based on the data transmission rate change information of each channel, it is judged whether the average data transmission rate of each channel exceeds a preset transmission rate threshold. If so, the channel is determined as an active data transmission channel; if not, the channel is not determined as an active data transmission channel. Thus, the scope of data sampling within the network sub-region is limited to the active data transmission channels, reducing the workload of data sampling. Additionally, based on the respective data transfer traffic of all gateway nodes subordinate to the active data transmission channel, all gateway nodes subordinate to the active data transmission channel are sampled separately to obtain the respective transfer data samples of all gateway nodes subordinate to the active data transmission channel. The greater the data transfer traffic of the gateway node subordinate to the active data transmission channel, the greater the amount of data sampling for that gateway node, ensuring that all gateway nodes can be comprehensively and accurately sampled and processed. Then, based on the data transmission sequence of all gateway nodes subordinate to the active data transmission channel, the respective transfer data samples of all gateway nodes are sorted and integrated to obtain the full-path data sample set of the active data transmission channel, enabling the full-path data sample set to accurately reflect the data transfer situation of all gateway nodes.

[0095] Preferably, the data sample analysis module is used to perform time-evolution analysis on the full-path data sample set to obtain the attack data flow attribute information within the active data transmission channel, including:

[0096] Performing time-evolution analysis on the respective transfer data samples of all gateway nodes subordinate to the active data transmission channel included in the full-path data sample set to obtain the attack data flow change information during the transfer data process of each gateway node subordinate to the active data transmission channel, and using this as the attack data flow attribute information within the active data transmission channel;

[0097] The operation thread identification module is used to determine the attack occurrence information of the terminal corresponding to the active data transmission channel based on the attack data flow attribute information; and based on the attack occurrence information, identify the operation threads within the terminal that need to be controlled, including:

[0098] Based on the attack data traffic change information, determine the occurrence time information and the occurrence thread position information when the terminal corresponding to the active data transmission channel is in the attack data volume reception limit state; based on the occurrence time information and the occurrence thread position information, identify the operating threads in the terminal that need to be controlled.

[0099] The beneficial effects of the above technical solution are as follows: Perform time evolution analysis on the transfer data samples of each network gateway node under the active data transmission channel included in the full-path data sample set, and obtain the attack data traffic change information during the transfer data process of each network gateway node under the active data transmission channel, that is, the change information of the attack data traffic size over time during the transfer data process of each network gateway node. Also, based on the attack data traffic change information, determine the occurrence time information and the occurrence thread position information when the terminal corresponding to the active data transmission channel is in the attack data volume reception limit state, so as to identify the operating threads in the terminal that need to be controlled, thereby accurately locating the operating threads with abnormal conditions due to network security problems inside the terminal.

[0100] Preferably, the abnormal operation data stream determination module is used to perform operation data analysis on the operating threads that need to be controlled, and determine the abnormal operation data streams in the operating threads that need to be controlled, including:

[0101] Perform operation data component analysis on the operating threads that need to be controlled, and determine the operation data code attribute information in the operating threads that need to be controlled; based on the operation data code attribute information, determine the abnormal operation data streams in the operating threads that need to be controlled;

[0102] The security prevention and control operation module is used to perform security prevention and control operations on the terminal based on the running associated objects of the abnormal operation data stream in the terminal, including:

[0103] Based on the work tasks associated with the abnormal operation data stream in the terminal, determine all the application programs associated with the abnormal operation data stream during its running process in the terminal, so as to perform attack intrusion isolation or abnormal operation data stream shielding on all the associated application programs.

[0104] The beneficial effects of the above technical solution are as follows: Analyze the operation data components of the operation thread to be controlled, determine the operation data code attribute information within the operation thread to be controlled, where the operation data code attribute information may include the type information of the operation data code and the proportion information of the garbled data volume, and based on the operation data code attribute information, determine the abnormal operation data stream within the operation thread to be controlled. For example, when the operation data code belongs to a preset type of data code or the proportion of the garbled data volume exceeds a preset proportion threshold, the corresponding operation data stream is determined as the abnormal operation data stream within the operation thread to be controlled. Additionally, based on the work tasks associated with the abnormal operation data stream within the terminal, determine all the application programs associated with the running process of the abnormal operation data stream within the terminal, so as to perform attack intrusion isolation or abnormal operation data stream shielding on all the associated application programs, perform security prevention and control operations on the terminal, identify and intercept attacks on the terminal, and achieve synchronous security maintenance of the network and the terminal, avoiding security problems caused by the mutual influence between the network and the terminals connected to it.

[0105] As can be seen from the content of the above embodiments, the network partition control and terminal security maintenance method and system monitor the data interaction status information of all network gateway nodes in the network, thereby determining the data interaction relationship between all network gateway nodes and all terminals connected to the network, and then dividing several network sub-regions. For the data interaction behavior between the network gateway node and the terminal, network partitioning is performed to accurately associate the terminal with the network partition; based on the link characteristics of the active data transmission channels within the network sub-region, global sampling is performed to obtain a full-path data sample set, and the transit data of all network gateway nodes within the active data transmission channels is comprehensively extracted; based on the attack data stream attribute information within the active data transmission channels, determine the attack occurrence information of the terminal, thereby identifying the operation threads within the terminal that need to be controlled, and performing troubleshooting and identification on the terminal at the thread level; based on the running associated objects of the abnormal operation data stream within the operation thread that needs to be controlled within the terminal, perform security prevention and control operations on the terminal, identify and intercept attacks on the terminal, and achieve synchronous security maintenance of the network and the terminal.

[0106] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A network partition control and terminal security maintenance method, characterized in that: It includes the following steps: Step S1, monitoring all gateway nodes in the network to obtain data interaction status information of all gateway nodes; based on the data interaction status information, determining the data interaction relationship between all gateway nodes and all terminals accessed in the network; based on the data interaction relationship, dividing the network into a plurality of network sub-areas; Step S2, identifying active data transmission channels in the network sub-area based on access locations of all terminals in the network sub-area; Based on the link characteristics of the active data transmission channel, globally sampling the active data transmission channel to obtain a full path data sample set of the active data transmission channel; Step S3, performing time evolution analysis on the full path data sample set to obtain the attack data flow attribute information in the active data transmission channel; Based on the attack data flow attribute information, determining the attack occurrence information of the terminal corresponding to the active data transmission channel; Based on the attack occurrence information, identifying an operation thread in the terminal that needs to be controlled; Step S4, analyzing the operation data of the operation thread that needs to be controlled, and determining the abnormal operation data flow in the operation thread that needs to be controlled; Based on the operation-related object of the abnormal operation data flow in the terminal, a security prevention and control operation is performed on the terminal.

2. The network partition control and terminal security maintenance method according to claim 1, characterized in that: In the step S1, all gateway nodes in the network are monitored to obtain data interaction status information of all gateway nodes; based on the data interaction status information, the data interaction relationship between all gateway nodes and all terminals accessed in the network is determined; Based on the data interaction relationship, the network is divided into several network sub-areas, including: Based on the network distances between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained; based on the distribution density information, all gateway nodes are divided into a number of gateway node groups; based on the number of gateway nodes included in each gateway node group, all gateway nodes included in each gateway node group are monitored in turn and cycle to obtain the transmission target address change information of the uplink data / downlink data of all gateway nodes, which is used as the data interaction state information; Based on the transmission target address change information of the uplink data / downlink data, the data interaction frequency between each gateway node and all terminals connected to the network is determined, so as to determine the data interaction occurrence probability information between all gateway nodes and all terminals connected to the network, and use this as the data interaction relationship; based on the data interaction occurrence probability information, the network is divided into several network sub-areas; wherein all gateway nodes in each network sub-area can interact with the same terminal for data.

3. The network partition control and terminal security maintenance method according to claim 1, characterized in that: In the step S2, based on the access locations of all terminals in the network sub-area, an active data transmission channel in the network sub-area is identified; Based on the link characteristics of the active data transmission channel, globally sampling the active data transmission channel to obtain a full path data sample set of the active data transmission channel, including: Based on the respective access gateway location addresses of all the terminals in the network sub-area, all channels through which all the terminals in all the network sub-areas can perform data transmission are determined; based on the respective data transmission rate change information of all the channels, active data transmission channels in the network sub-area are identified from all the channels; Based on the data transfer traffic of all gateway nodes under the active data transmission channel, differentiated sampling is performed on all gateway nodes under the active data transmission channel to obtain respective transfer data samples of all gateway nodes under the active data transmission channel; based on the data transmission order of all gateway nodes under the active data transmission channel, the respective transfer data samples of all gateway nodes are sorted and integrated to obtain a full-path data sample set of the active data transmission channel.

4. The network partition control and terminal security maintenance method according to claim 1, characterized in that: In the step S3, the full path data sample set is subjected to a time evolution analysis to obtain the attack data flow attribute information in the active data transmission channel; based on the attack data flow attribute information, the attack occurrence information of the terminal corresponding to the active data transmission channel is determined; Based on the attack occurrence information, identifying an operation thread in the terminal that needs to be controlled, including: Performing time evolution analysis on the transfer data samples of all gateway nodes under the active data transmission channel contained in the full path data sample set, obtaining the attack data flow change information during the data transfer process of each gateway node under the active data transmission channel, and using this as the attack data flow attribute information in the active data transmission channel; Based on the attack data flow change information, determine the occurrence time information and the occurrence thread position information when the terminal corresponding to the active data transmission channel is in the attack data volume receiving limit state; based on the occurrence time information and the occurrence thread position information, identify the operation thread that needs to be controlled in the terminal.

5. The network partition control and terminal security maintenance method according to claim 1, characterized in that: In the step S4, the operation data of the operation thread that needs to be controlled is analyzed to determine the abnormal operation data flow in the operation thread that needs to be controlled; Based on the operation-related object of the abnormal operation data flow in the terminal, a security prevention and control operation is performed on the terminal, including: Performing an operation data component analysis on the operation thread that needs to be controlled to determine the operation data code attribute information in the operation thread that needs to be controlled; and determining the abnormal operation data flow in the operation thread that needs to be controlled based on the operation data code attribute information; Based on the work tasks associated with the abnormal operation data flow in the terminal, all the applications associated with the running process of the abnormal operation data flow in the terminal are determined, so as to perform attack and intrusion isolation or abnormal operation data flow shielding on all the associated applications.

6. Network partition management and terminal security maintenance system, characterized by: include: The gateway node monitoring module is used to monitor all gateway nodes in the network and obtain the data interaction status information of all gateway nodes; A network partitioning module, configured to determine the data interaction relationship between all gateway nodes and all terminals accessed within the network based on the data interaction state information; and to divide the network into a plurality of network sub-areas based on the data interaction relationship; A data transmission channel identification module, configured to identify active data transmission channels in the network sub-area based on access locations of all terminals in the network sub-area; A data sampling processing module, configured to perform global sampling on the active data transmission channel based on the link characteristics of the active data transmission channel to obtain a full-path data sample set of the active data transmission channel; A data sample analysis module, used to perform time evolution analysis on the full path data sample set to obtain the attack data flow attribute information in the active data transmission channel; An operation thread identification module, used to determine the attack occurrence information of the terminal corresponding to the active data transmission channel based on the attack data flow attribute information; based on the attack occurrence information, identify the operation thread that needs to be controlled in the terminal; An abnormal operation data flow determination module is used to analyze the operation data of the operation thread that needs to be controlled, and determine the abnormal operation data flow in the operation thread that needs to be controlled; The security control operation module is used to perform security control operations on the terminal based on the operation-related objects of the abnormal operation data flow in the terminal.

7. The network partition management and terminal security maintenance system according to claim 6, characterized in that: The gateway node monitoring module is used to monitor all gateway nodes in the network to obtain data interaction status information of all gateway nodes, including: Based on the network distances between all gateway nodes in the network, the distribution density information of all gateway nodes in the network is obtained; based on the distribution density information, all gateway nodes are divided into a number of gateway node groups; based on the number of gateway nodes included in each gateway node group, all gateway nodes included in each gateway node group are monitored in turn and cycle to obtain the transmission target address change information of the uplink data / downlink data of all gateway nodes, which is used as the data interaction state information; The network partitioning module is used to determine the data interaction relationship between all gateway nodes and all terminals accessed in the network based on the data interaction state information; based on the data interaction relationship, the network is divided into a plurality of network sub-areas, including: Based on the transmission target address change information of the uplink data / downlink data, the data interaction frequency between each gateway node and all terminals connected to the network is determined, so as to determine the data interaction occurrence probability information between all gateway nodes and all terminals connected to the network, and use this as the data interaction relationship; based on the data interaction occurrence probability information, the network is divided into several network sub-areas; wherein all gateway nodes in each network sub-area can interact with the same terminal for data.

8. The network partition management and terminal security maintenance system according to claim 6, characterized in that: The data transmission channel identification module is used to identify active data transmission channels in the network sub-area based on access locations of all terminals in the network sub-area, including: Based on the respective access gateway location addresses of all the terminals in the network sub-area, all channels through which all the terminals in all the network sub-areas can perform data transmission are determined; based on the respective data transmission rate change information of all the channels, active data transmission channels in the network sub-area are identified from all the channels; The data sampling processing module is used to perform global sampling on the active data transmission channel based on the link characteristics of the active data transmission channel to obtain a full path data sample set of the active data transmission channel, including: Based on the data transfer traffic of all gateway nodes under the active data transmission channel, differentiated sampling is performed on all gateway nodes under the active data transmission channel to obtain respective transfer data samples of all gateway nodes under the active data transmission channel; based on the data transmission order of all gateway nodes under the active data transmission channel, the respective transfer data samples of all gateway nodes are sorted and integrated to obtain a full-path data sample set of the active data transmission channel.

9. The network partition management and terminal security maintenance system according to claim 6, characterized in that: The data sample analysis module is used to perform time evolution analysis on the full path data sample set to obtain the attack data flow attribute information in the active data transmission channel, including: Performing time evolution analysis on the transfer data samples of all gateway nodes under the active data transmission channel contained in the full path data sample set, obtaining the attack data flow change information during the data transfer process of each gateway node under the active data transmission channel, and using this as the attack data flow attribute information in the active data transmission channel; The operation thread identification module is used to determine the attack occurrence information of the terminal corresponding to the active data transmission channel based on the attack data flow attribute information; based on the attack occurrence information, identify the operation thread that needs to be controlled in the terminal, including: Based on the attack data flow change information, determine the occurrence time information and the occurrence thread position information when the terminal corresponding to the active data transmission channel is in the attack data volume receiving limit state; based on the occurrence time information and the occurrence thread position information, identify the operation thread that needs to be controlled in the terminal.

10. The network partition management and terminal security maintenance system according to claim 6, characterized in that: The abnormal operation data flow determination module is used to analyze the operation data of the operation thread that needs to be controlled, and determine the abnormal operation data flow in the operation thread that needs to be controlled, including: Performing an operation data component analysis on the operation thread that needs to be controlled to determine the operation data code attribute information in the operation thread that needs to be controlled; and determining the abnormal operation data flow in the operation thread that needs to be controlled based on the operation data code attribute information; The security control operation module is used to perform security control operations on the terminal based on the operation-related object of the abnormal operation data flow in the terminal, including: Based on the work tasks associated with the abnormal operation data flow in the terminal, all the applications associated with the running process of the abnormal operation data flow in the terminal are determined, so as to perform attack and intrusion isolation or abnormal operation data flow shielding on all the associated applications.

Citation Information

Patent Citations

  • Method and device for establishing information communication network system structure, as well as server and router

    CN103338150A

  • Network security control method and system for local area network

    CN116527403A