A secure encrypted transmission system for game data
Through machine learning models, intelligent evaluation of the network environment and dynamically adjusting the hashing algorithm, solving the problem that fixed hashing algorithms in the existing technology cannot be flexibly adjusted in high-risk environments, and achieving higher communication security and resource optimization.
Patent Information
- Application Number
- CN202510107413.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The prior art uses fixed hashing algorithms in high-risk network environments and cannot be flexibly adjusted to cope with dynamically changing security threats, resulting in the risk of possible data breaches or session interruptions.
Through machine learning models, intelligently evaluate the network environment, identify high-risk environments in real time, and dynamically adjust the hashing algorithms, and select algorithms with higher encryption strength and attack resistance to enhance communication security.
Effectively prevent new threats such as viruses and ransomware, ensure the confidentiality and integrity of data transmission, while maintaining high performance and efficiency in low-risk environments, and avoiding unnecessary waste of resources.
Smart Images

Figure CN119561787B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of game data encryption, and particularly to a secure encrypted transmission system for game data. Background Art
[0002] The secure encrypted transmission of game data means that during the game process, sensitive data of players (such as account information, transaction records, game progress, etc.) is encrypted and then transmitted through the network to ensure that the data will not be stolen, tampered with, or leaked by unauthorized third parties during the transmission process. Encrypted transmission usually uses strong encryption algorithms, such as symmetric encryption (AES) or asymmetric encryption (RSA), to convert the data into ciphertext, so that even if the data is intercepted, it cannot be interpreted or tampered with. In addition, to further ensure security, digital signatures and SSL / TLS protocols are often used in combination to verify the integrity of the data and the security of the transmission, thereby preventing network threats such as man-in-the-middle attacks and replay attacks, and protecting the privacy of players and the stability of the game environment.
[0003] The prior art has the following deficiencies:
[0004] In the prior art, a fixed hash algorithm is selected through a handshake protocol each time a session is established to ensure the independence and security of the session. However, in a high-risk network environment, continuing to use a fixed hash algorithm to ensure security may lead to serious hidden dangers. The threats in a high-risk environment are dynamically changing, and attackers can quickly launch attacks against the weaknesses of a specific hash algorithm. The use of a fixed hash algorithm limits the system's ability to flexibly adjust according to the changing threat situation and cannot cope with new security threats (such as viruses and ransomware). Over time, the fixed hash algorithm may expose more and more security flaws, and attackers can continuously exploit these vulnerabilities. Once the hash algorithm is broken, the security of the entire encrypted communication will be lost, which may lead to data leakage or session interruption, thus seriously threatening the confidentiality and integrity of data transmission.
[0005] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and therefore it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0006] The objective of the present invention is to provide a secure encrypted transmission system for game data. Through the intelligent evaluation of the network environment by a machine learning model, the system can identify high-risk environments in real time and dynamically adjust the hash algorithm according to the evaluation results. In high-risk situations, a stronger encryption algorithm is selected to improve communication security and guard against new threats such as viruses and ransomware. This mechanism can not only effectively address known vulnerabilities but also cope with emerging attacks, ensuring the confidentiality and integrity of data. For low-risk environments, the system continues to use a fixed hash algorithm to maintain high performance and efficiency. In this way, while ensuring security, the system optimizes resource utilization, balances the encryption strength and performance requirements, so as to solve the problems in the above-mentioned background technology.
[0007] To achieve the above objective, the present invention provides the following technical solution: A secure encrypted transmission system for game data, comprising a network environment data collection module, a network risk feature extraction module, a feature analysis and machine learning evaluation module, a network environment classification module, a low-risk network hash algorithm module, and a high-risk network hash algorithm adjustment module:
[0008] The network environment data collection module comprehensively collects various parameter information of the current network environment before the handshake protocol starts;
[0009] The network risk feature extraction module systematically organizes and stores the collected network environment parameters to form a structured analysis set, and extracts key features reflecting that the network environment is in a high-risk state from the analysis set;
[0010] The feature analysis and machine learning evaluation module deeply analyzes the extracted key features within the detection window and inputs the analyzed key features into a pre-trained machine learning model for intelligent evaluation;
[0011] The network environment classification module classifies the current network environment into a high-risk network environment and a low-risk network environment based on the machine learning model evaluation results;
[0012] The low-risk network hash algorithm module continues to use a fixed hash algorithm in a low-risk network environment to ensure the independence and security of the session while maintaining high performance and efficiency;
[0013] The high-risk network hash algorithm adjustment module dynamically adjusts the hash algorithm in a high-risk network environment and selects a hash algorithm with higher encryption strength and anti-attack ability to enhance the security of the session.
[0014] Preferably, key features reflecting that the network environment is in a high-risk state are extracted from the analysis set. The extracted features include the frequency of port scanning in the network and potential abnormal behaviors in encrypted communications. Under the detection window, the extracted key features are analyzed to generate a port scanning behavior index and an encrypted communication anomaly index respectively. The port scanning behavior index quantifies the frequency and abnormality of port scanning activities in the network; the encrypted communication anomaly index quantifies the abnormal behaviors of encrypted communication traffic in the network.
[0015] Preferably, the port scanning behavior index and the encrypted communication anomaly index generated after analyzing the extracted key features are input into a pre-trained machine learning model. The network security coefficient is generated through the machine learning model, and the network security environment is intelligently evaluated through the network security coefficient.
[0016] Preferably, the generated network security coefficient is compared and analyzed with a pre-set network security coefficient reference threshold to classify the current network environment. The specific steps are as follows:
[0017] If the network security coefficient is greater than or equal to the pre-set network security coefficient reference threshold, the current network environment is classified as a high-risk network environment;
[0018] If the network security coefficient is less than the pre-set network security coefficient reference threshold, the current network environment is classified as a low-risk network environment.
[0019] Preferably, in a high-risk network environment, the specific steps to dynamically adjust the hash algorithm and select a hash algorithm with higher encryption strength and anti-attack ability to enhance the security of the session are as follows:
[0020] By comparing the network security coefficient NSC with the pre-set network security coefficient reference threshold NSC ref to determine whether to adjust the encryption strength, the method is as follows:
[0021]
[0022] , when the network security coefficient NSC is greater than or equal to the network security coefficient reference threshold NSC ref , it indicates that it is in a high-risk network environment and triggers the hash algorithm adjustment step;
[0023] After confirming that the network environment belongs to a high-risk network environment, a hash algorithm with higher encryption strength and anti-attack ability will be selected according to the value of the network security coefficient NSC. At this time, it is necessary to select a suitable high-strength hash algorithm from the algorithm library. In order to dynamically adjust the hash algorithm, refer to the performance indicators of the hash algorithm and combine the value of the network security coefficient NSC to determine which encryption-level hash algorithm to switch to. The specific steps are as follows:
[0024] Selected hash algorithm = f(NSC, algorithm performance metrics)
[0025] , where f represents the algorithm selection mechanism, and according to the network security coefficient and the performance metrics of the algorithm, a hash algorithm with higher encryption strength is dynamically selected;
[0026] After the hash algorithm adjustment is completed, the new hash algorithm will be applied in the handshake protocol stage. At this time, the new hash algorithm will be passed to both communication parties to ensure that subsequent data encryption and verification processes are all processed based on a high-strength hash algorithm. Before the session starts, according to the security assessment results in a high-risk environment, the default hash algorithm is replaced to ensure that the key exchange, authentication, and data integrity of the session are all provided with stronger security guarantees. The formula is as follows:
[0027] New hash algorithm = Selected hash algorithm(NSC)
[0028] , where the new hash algorithm is the new hash algorithm selected in a high-risk network environment,
[0029] After the handshake protocol is generated and the hash algorithm is applied, the hash algorithm cannot be modified in real time. To ensure the long-term security of network communication, real-time monitoring will be continuously carried out throughout the life cycle of the session, and potential threats will be dynamically evaluated. If during the session, the network security coefficient NSC continues to increase, it means that a new threat has emerged in the network environment. A feedback mechanism will be initiated to notify the administrator for manual intervention and adjustment, and a stronger hash algorithm will be selected for the next session establishment. The formula for this process is as follows:
[0030]
[0031] , even if the hash algorithm cannot be changed in the current session, the network environment can still be monitored to ensure that in the event of a major security risk, the next session can be adjusted in a timely manner, so as to select an algorithm with a high encryption level to protect the confidentiality and integrity of data in future sessions.
[0032] Preferably, under the detection window, the specific steps for analyzing the port scanning frequency in the network and generating the port scanning behavior index are as follows:
[0033] Under the detection window, first, collect the port scanning events in the network. The collected port scanning behavior data is used for analysis and modeling. The expression is as follows:
[0034]
[0035] , where S iis the total number of port scanning events initiated by the source IP address i, I(Scan(t)) is the indicator function of the port scanning event at time point t, and T is the total duration of the detection window;
[0036] After collecting the port scanning events, the next step is to analyze the intensity of the scanning activity. To this end, consider the total number of scanning events of each source IP address within this time window and weight it in combination with the number of ports scanned to reflect the density of the scanning. The calculation expression is as follows:
[0037]
[0038] , where N p (i) is the number of different ports scanned by the source IP address i, α is an intensity adjustment factor, and I s is the port scanning intensity, and N is the total number of source IP addresses participating in the scanning;
[0039] After calculating the port scanning intensity, it is also necessary to identify the abnormality of the scanning behavior and calculate the change rate of the scanning intensity. The calculation expression is as follows:
[0040]
[0041] , where ΔI s is the change rate of the scanning intensity, I s (t) is the port scanning intensity calculated at time point t, and I s (t - 1) is the port scanning intensity calculated at time point t - 1;
[0042] By combining the intensity of the port scanning activity and the change rate of the scanning intensity, a port scanning behavior index is generated. The calculation expression is as follows:
[0043]
[0044] Among them, P s is the port scanning behavior index, I s (i) is the scanning intensity of the source IP address i, 1(ΔI s ≥δ) is the indicator function of the change rate of the scanning intensity, and β is the weighting coefficient of the abnormal behavior on the final index.
[0045] Preferably, under the detection window, the specific steps for analyzing the potential abnormal behavior in encrypted communication and generating an encrypted communication anomaly index are as follows:
[0046] Under the detection window, first extract multiple features from the encrypted communication traffic to capture abnormal behavior. By obtaining encrypted communication data in real time, accurately capture the change in the behavior pattern of the encrypted traffic. The calculation expression is as follows:
[0047]
[0048] , where FAD(t) is the anomaly degree of encrypted communication traffic, i.e., the anomaly degree of encrypted communication traffic at time point t, and I p (t) is the observed value of the p-th type of encrypted communication traffic at time t, and Q p is the median of the historical data of the p-th type of encrypted communication traffic, and E p is the deviation function of the p-th type of encrypted communication traffic, and A p is the weighting coefficient of the characteristics of the p-th type of encrypted communication traffic, and P is the total number of encrypted communication traffic categories;
[0049] Using the extracted feature data, identify the existing encrypted communication anomaly patterns, combine the rule-based detection system and machine learning methods to identify the abnormal patterns in the communication behavior, and the calculation expression is as follows:
[0050]
[0051] , where P j (t) is the observed value of the j-th anomaly pattern index of the encrypted communication traffic at time t, is the normal behavior threshold of the pattern, τ j is the tolerance coefficient of the anomaly pattern, θ j is the weighting coefficient, γ j is the pattern sensitivity index, and API(t) is the anomaly pattern recognition index;
[0052] After identifying the anomaly patterns in the encrypted communication, calculate the ratio of abnormal behaviors in the encrypted communication. By calculating the weighted ratio of the abnormal traffic proportion and the communication duration, accurately evaluate whether the current network is threatened, and the calculation expression is as follows:
[0053]
[0054] p (t) is the anomaly flag, ∈ is a tiny constant to avoid the denominator being zero, and ARI(t) is the encrypted communication anomaly ratio;
[0055] Generate the encrypted communication anomaly index based on the encrypted traffic anomaly degree FAD(t), the anomaly pattern recognition index API(t), and the encrypted communication anomaly ratio ARI(t), and the calculation expression is as follows:
[0056]
[0057] , where ECAI is the encrypted communication anomaly index, and FAD p (t) represents the anomaly degree of the p-th type of encrypted communication traffic at time point t, and ARI p(t) is an exponent indicating whether there is an abnormal pattern in the encrypted communication traffic of the p-th class at time point t, ARI p (t) is used to measure the proportion of abnormal traffic in the encrypted communication traffic of the p-th class within time point t.
[0058] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:
[0059] Through the intelligent evaluation of the network environment by the machine learning model, the system can identify high-risk network environments in real time. In high-risk environments (such as when security threats like viruses and ransomware are active), the system will dynamically adjust the hash algorithm according to the evaluation results and select an algorithm with higher encryption strength and anti-attack ability. This mechanism significantly enhances the encryption strength during communication and the ability to resist potential attacks. For example, when there are frequent port scans in the network or abnormal behaviors occur in encrypted communication, the machine learning model can generate corresponding security coefficients and promptly trigger an upgrade of the hash algorithm, using a more complex and secure hash algorithm for session encryption. This dynamic adjustment of the hash algorithm can not only effectively prevent the exploitation of vulnerabilities in known algorithms but also, when facing emerging attack methods, ensure the confidentiality and integrity of data transmission through flexible selection of encryption algorithms. As the network environment changes in real time, the system can quickly respond and adopt appropriate encryption strategies to avoid potential risks brought by traditional fixed hash algorithms.
[0060] Through the intelligent evaluation of the network environment by the machine learning model, the system can more accurately detect potential security threats and classify the network environment as high-risk or low-risk based on the network security coefficient. This intelligent evaluation helps the system to perform more refined security protection in a dynamically changing network environment. In a low-risk network environment, continuing to use a fixed hash algorithm can maintain high performance and efficiency, avoiding unnecessary resource waste and performance degradation. In a high-risk network environment, based on real-time security evaluation, the system can promptly detect abnormalities and react quickly, selecting a stronger encryption algorithm to effectively deal with new threats such as viruses and ransomware. In this way, the system not only improves the overall security protection ability but also optimizes the use of system resources, avoids performance degradation caused by excessive encryption, and ensures the balance between the efficiency and security of network transmission. Description of the Drawings
[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0062] Figure 1 This is a schematic diagram of the modules of a secure encrypted transmission system for game data of the present invention. Detailed implementation manners
[0063] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these example embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art.
[0064] The present invention provides a secure encrypted transmission system for game data as Figure 1 shown, including a network environment data collection module, a network risk feature extraction module, a feature analysis and machine learning evaluation module, a network environment classification module, a low-risk network hash algorithm module, and a high-risk network hash algorithm adjustment module:
[0065] The network environment data collection module comprehensively collects various parameter information of the current network environment before the handshake protocol starts;
[0066] Comprehensively collecting various parameter information of the current network environment before the handshake protocol starts is mainly to be able to dynamically select and adjust the hash algorithm in a timely manner when the network environment changes. The original intention of the handshake protocol is to establish a secure and reliable communication channel, and the hash algorithm, as an important link therein, determines the guarantee of encryption and data integrity. If there are high-risk threats in the network environment, such as malicious attacks, network congestion, or unstable connections, pre-collecting network parameters can help the system evaluate these potential risks and select a suitable hash algorithm based on the security of the current environment. If a high-risk environment is analyzed in advance, the system can choose a hash algorithm with stronger encryption to enhance security and avoid using a fixed hash algorithm that may have been compromised or is vulnerable to threats. Therefore, through the network environment evaluation before the handshake protocol, the system can flexibly adjust the algorithm according to the real-time risk situation, thereby improving the security and reliability of the entire communication process.
[0067] The network risk feature extraction module systematically organizes and stores the collected network environment parameters to form a structured analysis set, and extracts key features reflecting that the network environment is in a high-risk state from the analysis set;
[0068] The specific steps for systematically organizing and storing the collected network environment parameters to form a structured analysis set include: First, the system classifies and labels various types of network information collected to ensure that each parameter can be mapped to a specific network condition; then, these parameters are organized into a standardized data format according to predetermined rules to make them easy to process and analyze subsequently. Next, this information is stored in a database or memory to ensure efficient access and management of the data. The role of the analysis set is that it provides a comprehensive and systematic view for subsequent risk assessment and decision-making. Through the structured analysis set, the system can quickly extract and identify key features that may lead to security risks, and can make targeted adjustments and optimizations based on these features, so as to take appropriate measures to protect session security in a high-risk network environment.
[0069] The feature analysis and machine learning evaluation module deeply analyzes the extracted key features within the detection window and inputs the analyzed key features into a pre-trained machine learning model for intelligent evaluation;
[0070] Extract key features from the analysis set that reflect the network environment being in a high-risk state. The extracted features include the frequency of port scanning in the network and potential abnormal behaviors in encrypted communications. Under the detection window, analyze the extracted key features to generate a port scanning behavior index and an encrypted communication anomaly index respectively. The port scanning behavior index quantifies the frequency and abnormality of port scanning activities in the network; the encrypted communication anomaly index quantifies the abnormal behaviors of encrypted communication traffic in the network.
[0071] Input the port scanning behavior index and the encrypted communication anomaly index generated after analyzing the extracted key features into the pre-learned machine learning model. Generate a network security coefficient through the machine learning model and conduct intelligent evaluation of the network security environment based on the network security coefficient.
[0072] A pre-trained machine learning model refers to a model that has been fully trained with a large amount of historical data before deployment and can intelligently evaluate the input data features and generate accurate outputs. These models have learned the ability to identify network threats by learning the feature patterns of the network environment, especially the feature manifestations in high-risk and low-risk scenarios. During the training process, the model is provided with a training set containing various network environment data, such as key features like port scan frequency and abnormal behavior of encrypted communication, as well as corresponding labels (such as "high risk" or "low risk"). Through multiple iterations of optimization, the model can extract effective feature relationships from the input data and learn how to map these features to accurate output results. For example, for the Port Scan Behavior Index (PSB I) and the Encrypted Communication Abnormality Index (ECAI), the model can identify specific numerical change patterns and determine whether these changes reflect potential security threats.
[0073] The pre-training of such models also includes adjusting hyperparameters, selecting appropriate algorithms (such as random forest, neural network, or support vector machine, etc.), and testing the generalization ability of the model to ensure that the model performs equally well on unknown data. The advantage of pre-trained machine learning models is that, through learning historical data, they can quickly adapt to the actual application scenario and efficiently evaluate the input data without retraining during operation. For example, when the input PSB I and ECAI indicate possible abnormal port scan behavior and encrypted traffic in the network, the model can quickly generate a network security coefficient and give a risk assessment result of the network environment.
[0074] The significance of these pre-trained models lies in that they already possess certain decision-making capabilities and can accurately evaluate the network security status by analyzing the current network environment data. The intelligent evaluation function of these models greatly shortens the response time and improves the efficiency and adaptability of the security system. When the model receives input data such as PSB I and ECA I, it can quickly calculate the network security coefficient based on the feature patterns it has mastered during the training stage as a risk score for the current network environment. This evaluation method not only reduces the subjective error of human judgment but also realizes real-time monitoring and dynamic decision-making through the efficient operation of the model, thus significantly improving the network security protection ability and ensuring that targeted countermeasures can be taken in a high-risk environment in a timely manner.
[0075] A sharp increase in the port scanning frequency in a network is usually a strong indication of a network threat, especially in the context of a virus or ransomware attack. Port scanning is a common method used by attackers to find exploitable weaknesses and vulnerabilities in a network. Especially before malware penetrates a network, it often scans open ports to find potential targets for attack. Viruses and ransomware often attack by looking for vulnerable ports, such as open service ports and protocols with vulnerabilities. Therefore, a sharp increase in port scanning frequency indicates that attackers may be actively looking for weak links in the system or network to further execute malicious behaviors, such as implanting malware, conducting a denial-of-service attack (DDoS), stealing sensitive data, or encrypting important files to demand ransom. Therefore, port scanning activities not only represent the activities of attackers but also reflect potential security vulnerabilities in the network. Especially when the scanning frequency increases significantly, it usually means that the network environment is already in a high-risk state and there is a serious threat of being invaded.
[0076] Under the detection window, the specific steps for analyzing the port scanning frequency in a network and generating a port scanning behavior index are as follows:
[0077] Under the detection window, first, collect port scanning events in the network, specifically including all source IP addresses that initiate port scanning, target ports, scanning frequencies, and scanning time information. These data can be obtained through traffic analyzers, IDS / IPS systems, etc., and after preliminary cleaning and filtering, non-scanning network traffic is excluded. The collected port scanning behavior data is used for analysis and modeling, and the expression is as follows:
[0078]
[0079] , where S i is the total number of port scanning events initiated by source IP address i, I(Scan(t)) is the indicator function of the port scanning event at time point t. If a scanning behavior occurs at time point t, it is 1, and if no scanning occurs, it is 0. T is the total duration of the detection window;
[0080] After collecting port scanning events, the next step is to analyze the intensity of the scanning activity, that is, the scanning frequency of a specific source IP address for a target port within a certain time period. For this purpose, consider the total number of scanning events of each source IP address within this time window and combine it with the number of ports scanned for weighting to reflect the density of the scanning. The calculation expression is as follows:
[0081]
[0082] , where N p (i) is the number of different ports scanned by source IP address i, α is an intensity adjustment factor used to enhance or weaken the impact of the scanning frequency on the total intensity, Is is the port scan intensity, which is used to measure the intensity and breadth of port scans in a network environment. N is the total number of source IP addresses participating in the scan;
[0083] This formula measures the scan density of each source IP address and emphasizes the behavior of frequent scans and scanning multiple ports.
[0084] After calculating the port scan intensity, it is also necessary to identify the abnormality of the scan behavior and calculate the change rate of the scan intensity. Abnormal scan behavior usually manifests as a sudden increase in the scan frequency of a certain source IP address or the number of scanned ports far exceeding the normal range. The calculation expression is as follows:
[0085]
[0086] , where ΔI s is the change rate of the scan intensity. The change rate ΔI s can reflect the sharp change in the scan behavior. If the scan intensity of a certain source IP address suddenly increases, ΔI s will increase significantly, thus indicating a possible abnormal behavior. I s (t) is the port scan intensity calculated at time point t, and I s (t - 1) is the port scan intensity calculated at time point t - 1 (i.e., the previous moment);
[0087] By combining the intensity of port scan activities and the change rate of the scan intensity, a port scan behavior index is generated. The calculation expression is as follows:
[0088]
[0089] where P s is the port scan behavior index, I s (i) is the scan intensity of source IP address i, 1(ΔI s ≥δ) is the change rate indicator function of the scan intensity. When the change rate exceeds the threshold δ, it is 1, indicating the existence of abnormal behavior. β is the weighting coefficient of the abnormal behavior on the final index, which is used to control the influence of the abnormal behavior on the index.
[0090] Under the detection window, the larger the port scanning behavior index performance value generated after analyzing the port scanning frequency in the network, the more frequent the port scanning activities encountered by the network during the monitoring window, which usually indicates potential threats in the network environment, especially signs of viruses, ransomware, or other malicious attacks. When an attacker spreads a virus or invades with ransomware, they usually scan open ports to find targets for attack. Therefore, an increase in the port scanning behavior index reflects an increase in the frequency of port scanning and abnormal activities in the network, which is usually direct evidence of the network being threatened or attacked. On the contrary, when the port scanning behavior index is low, it indicates that there are few port scanning activities in the network and no frequent abnormal behaviors are shown, which usually means that the network environment is relatively secure and there are few attack activities.
[0091] An increase in potential abnormal behaviors in encrypted communication does indicate that the current network may be threatened, especially in a high-risk environment where attack methods such as viruses and ransomware are active. When abnormal behaviors occur in encrypted communication traffic, it usually means certain abnormal operations during the data transmission process, such as sudden increases in traffic, changes in traffic patterns, the use of abnormal encryption algorithms, or unauthorized access attempts, etc. These may all be manifestations of malware (such as viruses or ransomware) trying to conceal its activities or steal data. For example, after encrypting files, ransomware may establish connections with remote servers through encrypted communication channels to transmit encrypted data or obtain instructions; while a virus may execute unauthorized commands or download malicious code by exploiting encryption protocols in the network. These abnormal behaviors may be due to malware trying to bypass firewalls and detection mechanisms through encrypted traffic for data transmission or remote control, thus concealing its attack traces. An increase in abnormal behaviors in encrypted communication means there are hidden threat activities in the network, which usually indicates that the current network is in a high-risk state of being attacked and immediate response measures need to be taken to strengthen monitoring and protection. Therefore, timely detection and identification of potential abnormal behaviors in encrypted communication are important links in identifying and preventing network threats such as viruses and ransomware.
[0092] Under the detection window, the specific steps for generating the encrypted communication anomaly index by analyzing potential abnormal behaviors in encrypted communication are as follows:
[0093] Under the detection window, first extract multiple features from the encrypted communication traffic to capture abnormal behaviors. Common features include sudden increases in encrypted traffic, connection request frequencies, and changes in encryption algorithms. These features should be based on time-domain and frequency-domain analysis. Using high-precision data acquisition devices and network monitoring tools, by obtaining encrypted communication data in real time, accurately capture changes in the behavior patterns of encrypted traffic, especially the parts that deviate significantly from the normal communication pattern. The calculation expressions are as follows:
[0094]
[0095] , where FAD(t) is the anomaly degree of encrypted communication traffic, that is, the anomaly degree of encrypted communication traffic at time point t, which is used to quantify the anomaly degree of encrypted communication traffic at a certain moment and help judge the security of the current network environment, I p (t) is the observed value of the encrypted communication traffic of the pt-th type at time t, Q p is the median of the historical data of the p-th type of encrypted communication traffic. The median refers to the value in the middle after all data are sorted, and is usually used to measure the "typical" value of the data to avoid being affected by extreme values (such as abnormal traffic), E p is the deviation function of the p-th type of encrypted communication traffic, which is used to measure the degree of dispersion or fluctuation amplitude of the traffic, A p is the weighting coefficient of the characteristics of the p-th type of encrypted communication traffic, and P is the total number of encrypted communication traffic categories;
[0096] Using the extracted feature data, identify the existing encrypted communication abnormal patterns. For example, if there are suddenly a large number of connection requests or irregular packet distributions in the encrypted traffic, it may indicate that the network is under attack. This step is a key link in analyzing whether the traffic pattern conforms to malicious behaviors (such as the communication of viruses or ransomware). Combining rule-based detection systems and machine learning methods, identify the abnormal patterns in communication behaviors. The calculation expression is as follows:
[0097]
[0098] , where P j (t) is the observed value of the j-th abnormal pattern index of the encrypted communication traffic at time t, is the normal behavior threshold of the pattern, τ j is the tolerance coefficient of the abnormal pattern, θ j is the weighting coefficient, which is the weighting coefficient assigned to different abnormal patterns, γ j is the pattern sensitivity index, which determines the amplification degree of the index when deviating from the normal pattern value. API(t) is the abnormal pattern recognition index;
[0099] After identifying the abnormal patterns in the encrypted communication, calculate the ratio of abnormal behaviors in the encrypted communication. This step can quantify the proportion of abnormal behaviors relative to the total communication traffic and is an important indicator of the abnormal degree of encrypted communication. By calculating the weighted ratio of the abnormal traffic proportion and the communication duration, accurately evaluate whether the current network is threatened and can reflect whether malicious activities occupy a large proportion of communication resources. The calculation expression is as follows:
[0100]
[0101] , where B p(t) is an anomaly flag, indicating whether the p-th type of encrypted communication traffic is anomalous at time point t (if the traffic is anomalous, it is marked as 1, and if it is normal, it is marked as 0). ∈ is a tiny constant to avoid a zero denominator. ARI(t) is the encrypted communication anomaly ratio;
[0102] The encrypted communication anomaly ratio is used to measure the proportion of anomalous behavior or traffic in the overall communication traffic during encrypted communication. The role of calculating the encrypted communication anomaly ratio is to identify and quantify potential anomalous patterns or security threats in the communication process, such as malware, virus propagation, ransomware attacks, etc. By monitoring and analyzing anomalous behavior in encrypted communication, calculating the encrypted communication anomaly ratio can help the security system detect potential network attacks or system vulnerabilities in a timely manner. When the anomaly ratio exceeds the normal range, the system can trigger a security alert or automatically take protective measures to reduce potential network risks, thereby ensuring the confidentiality, integrity, and reliability of data transmission.
[0103] An encrypted communication anomaly index is generated based on the encrypted traffic anomaly degree FAD(t), the anomaly pattern recognition index API(t), and the encrypted communication anomaly ratio ARI(t). The calculation expression is as follows:
[0104]
[0105] , where ECAI is the encrypted communication anomaly index, FAD p (t) represents the anomaly degree of the p-th type of encrypted communication traffic at time point t, API p (t) is an index used to indicate whether there is an anomalous pattern in the p-th type of encrypted communication traffic at time point t, ARI p (t) is used to measure the proportion of anomalous traffic in the p-th type of encrypted communication traffic at time point t.
[0106] Under the detection window, the larger the value of the encrypted communication anomaly index generated after analyzing potential anomalous behavior in encrypted communication, the more potential anomalous behavior usually exists in the network, meaning the network may be threatened by malware such as viruses and ransomware and is in a high-risk environment. This is because when malware conducts an attack, it often uses the encrypted communication protocol for covert data transmission, remote control, or instruction issuance, resulting in abnormal communication patterns. For example, sudden increases in traffic, unconventional changes in encryption methods, and frequent unauthorized connections may all be manifestations of attack activities. When the value of the encrypted communication anomaly index is relatively high, it usually means that these anomalous behaviors occur frequently within the monitoring window, indicating that the network may have been infected or is under attack. Therefore, the larger the value of this index, the higher the security risk of the network. On the contrary, when the value of the encrypted communication anomaly index is relatively low, it means that the network communication traffic is stable, with few or no anomalous behaviors, and the network security is high and not threatened.
[0107] The machine learning model is not limited herein, and any machine learning model capable of comprehensively analyzing the port scanning behavior index P s and the encrypted communication anomaly index ECAI to generate the network security coefficient NSC can be used. To implement the technical solution of the present invention, a specific implementation manner is provided in the present invention;
[0108] The formula for generating the network security coefficient NSC is as follows:
[0109]
[0110] , where d 1 , d 2 are respectively the preset proportionality coefficients of the port scanning behavior index P s and the encrypted communication anomaly index ECAI, and d 1 , d 2 are both greater than 0.
[0111] From the network security coefficient, it can be seen that under the detection window, the larger the value of the port scanning behavior index generated after analyzing the port scanning frequency in the network, and the larger the value of the encrypted communication anomaly index generated after analyzing the potential abnormal behavior in the encrypted communication, the larger the value of the network security coefficient generated under the detection window, which indicates that the current network is in a high-risk environment. Conversely, it indicates that the current network has a relatively high security level.
[0112] The preset proportionality coefficients d 1 and d 2 in the figure are the weight settings for the port scanning behavior index P s and the encrypted communication anomaly index ECAI when calculating the network security coefficient NSC. The role of these two coefficients is to weightedly adjust the contributions of the two indices according to the importance of different characteristics in the network environment. For example, if the port scanning behavior has a greater impact on network security in a specific network scenario, then d 1 > d 2 can be set; conversely, if the encrypted communication anomaly can better reflect potential security threats, then d 2 > d 1 can be set. The preset of these proportionality coefficients is usually based on historical data analysis and the risk preference of the specific application scenario. By adjusting the values of d 1 and d 2 , it is possible to more flexibly reflect the comprehensive impact of different characteristics on network security in a specific environment, thereby improving the accuracy and adaptability of model evaluation.
[0113] The network environment classification module classifies the current network environment into a high-risk network environment and a low-risk network environment based on the evaluation results of the machine learning model;
[0114] Compare and analyze the generated network security coefficient with the pre-set network security coefficient reference threshold, and classify the current network environment. The specific steps are as follows:
[0115] If the network security coefficient is greater than or equal to the pre-set network security coefficient reference threshold, then classify the current network environment as a high-risk network environment;
[0116] If the network security coefficient is less than the pre-set network security coefficient reference threshold, then classify the current network environment as a low-risk network environment;
[0117] A high-risk network environment refers to a network state in which there are potential security threats or abnormal behaviors have emerged in the current network; a low-risk network environment refers to a network state where the current network operation is relatively normal and stable, without significant abnormal behaviors or security threats.
[0118] The low-risk network hash algorithm module, in a low-risk network environment, continues to use a fixed hash algorithm to ensure the independence and security of the session, while maintaining high performance and efficiency;
[0119] In a low-risk network environment, the purpose of continuing to use a fixed hash algorithm is to maximize the performance and efficiency of the system while ensuring the security and independence of the session. In a low-risk environment, the network security threats are relatively small, and the fixed hash algorithm is sufficient to cope with potential attack risks. Therefore, there is no need for overly complex encryption processes or high-intensity computational burdens. By using this fixed hash algorithm in the handshake protocol, the system can maintain high processing efficiency and response speed on the basis of ensuring the security of data transmission. This not only reduces the consumption of computing resources and latency, but also reduces the complexity of the system, ensuring that the user's session process is smooth and interference-free in a stable network environment. Therefore, the system will flexibly select an appropriate hash algorithm according to the risk level of the current environment to ensure both sufficient security and stable and efficient session performance.
[0120] The high-risk network hash algorithm adjustment module, in a high-risk network environment, will dynamically adjust the hash algorithm and select a hash algorithm with higher encryption strength and anti-attack ability to enhance the security of the session.
[0121] In a high-risk network environment, the specific steps to dynamically adjust the hash algorithm and select a hash algorithm with higher encryption strength and anti-attack ability to enhance the security of the session are as follows:
[0122] By comparing the network security coefficient NSC with the pre-set network security coefficient reference threshold NSC ref to determine whether to adjust the encryption strength, the method is as follows:
[0123]
[0124] When the network security coefficient NSC is greater than or equal to the network security coefficient reference threshold NSC ref it indicates that the network environment is in a high-risk state, triggering the hash algorithm adjustment step;
[0125] After confirming that the network environment is a high-risk network environment, a hash algorithm with higher encryption strength and anti-attack ability will be selected according to the value of the network security coefficient NSC. At this time, it is necessary to select a suitable high-strength hash algorithm from the algorithm library, such as an enhanced hash function. This algorithm has strong anti-collision ability and higher computational complexity. In order to dynamically adjust the hash algorithm, refer to the performance indicators of the hash algorithm (such as encryption strength, computational load, etc.), and combine the value of the network security coefficient NSC to determine which encryption-level hash algorithm to switch to. The specific steps are as follows:
[0126] Selected hash algorithm = f(NSC, algorithm performance indicators)
[0127] where f represents the algorithm selection mechanism, which dynamically selects a hash algorithm with higher encryption strength according to the network security coefficient and the performance indicators of the algorithm;
[0128] Dynamically select the most suitable hash algorithm for the current network environment according to the network security coefficient NSC of the current network and the performance indicators of different hash algorithms. Specifically, the network security coefficient NSC reflects the security status of the current network. If the network security coefficient NSC is greater than or equal to the network security coefficient reference threshold NSC ref it indicates that the network is in a high-risk environment, and a hash algorithm with higher encryption strength needs to be selected to enhance security; if the network security coefficient NSC is less than the network security coefficient reference threshold NSC ref then an algorithm with lower computational complexity but more efficient performance can be selected to balance security and efficiency. The function f in the formula is a decision-making mechanism used to dynamically output the best choice by combining the network security situation and algorithm performance, so as to ensure that the system can respond flexibly in different risk environments, ensuring both security and optimized performance.
[0129] The algorithm performance indicators refer to the performance characteristics of the hash algorithm itself, including but not limited to encryption strength, computational complexity, anti-collision ability, and anti-attack ability, etc. These indicators can help the system evaluate the effectiveness and efficiency of a certain hash algorithm in practical applications. For example, the stronger the anti-attack ability of the algorithm, usually the more computing resources are required.
[0130] When the network is in a high-risk state, the system will select a strong encryption algorithm, such as SHA-256 or a stronger hashing algorithm, through algorithm performance metrics, rather than using an algorithm with lower computational complexity and easier to crack (such as SHA-1). Conversely, when the network is in a low-risk state (i.e., the network environment is relatively secure), a lighter hashing algorithm (such as SHA-1 or MD5) can be continued to maintain efficiency and performance.
[0131] After the hashing algorithm adjustment is completed, the new hashing algorithm will be applied in the handshake protocol phase. At this time, the new hashing algorithm will be passed to both communication parties to ensure that subsequent data encryption and verification processes are all processed based on a high-strength hashing algorithm. Before the session starts, according to the security assessment results in a high-risk environment, the default hashing algorithm is replaced to ensure that the session key exchange, authentication, and data integrity are all provided with stronger security guarantees. The formula is as follows:
[0132] New hashing algorithm = Selected hashing algorithm (NSC)
[0133] , where the new hashing algorithm is the new hashing algorithm selected in a high-risk network environment.
[0134] The new hashing algorithm is the result of dynamically selecting according to the network security coefficient NSC of the current network. The system decides whether to switch or adjust the hashing algorithm by evaluating the value of the network security coefficient NSC. When the network security coefficient NSC reflects that the network is in a high-risk state, the system will select a hashing algorithm with higher encryption strength to enhance security; when the network security coefficient NSC indicates that the network is relatively secure, a more efficient hashing algorithm will be selected to optimize performance. The formula reflects the dynamic selection mechanism to ensure that the hashing algorithm can adapt to the real-time network security situation, thus taking into account both security and efficiency.
[0135] After the handshake protocol is generated and the hashing algorithm is applied, the hashing algorithm cannot be modified in real time because the hashing algorithm has been determined at the session establishment and is used for subsequent communication processes. To ensure the long-term security of network communication, real-time monitoring will be continuously carried out throughout the life cycle of the session, and potential threats will be dynamically evaluated. Specifically, the system will regularly monitor the network security coefficient NSC and compare it with the preset network security coefficient reference threshold NSC ref for comparison to determine whether the current network state still meets the initial assessment criteria. If during the session, the network security coefficient NSC continues to rise, it means that new threats have emerged in the network environment. A feedback mechanism will be initiated to notify the administrator for manual intervention and adjustment, and a stronger hashing algorithm will be selected for the next session establishment. The formula for this process is as follows:
[0136]
[0137] , even if the hash algorithm cannot be changed in the current session, the monitoring of the network environment can still be maintained to ensure that in the event of major security risks, the next session can be adjusted in a timely manner, so as to select an algorithm with a high encryption level to protect the confidentiality and integrity of data in future sessions.
[0138] Through the intelligent evaluation of the network environment by the machine learning model of the present invention, the system can identify high-risk network environments in real time. In high-risk environments (such as when security threats such as viruses and ransomware are active), the system will dynamically adjust the hash algorithm according to the evaluation results and select an algorithm with higher encryption strength and anti-attack ability. This mechanism significantly enhances the encryption strength during communication and the ability to resist potential attacks. For example, when port scanning is frequent in the network or abnormal behavior occurs in encrypted communication, the machine learning model can generate corresponding security coefficients and promptly trigger an upgrade of the hash algorithm, using a more complex and secure hash algorithm for session encryption. This dynamic adjustment of the hash algorithm can not only effectively prevent the exploitation of vulnerabilities in known algorithms but also, in the face of emerging attack methods, ensure the confidentiality and integrity of data transmission through flexible selection of encryption algorithms. As the network environment changes in real time, the system can quickly respond and adopt appropriate encryption strategies, avoiding potential risks brought by traditional fixed hash algorithms.
[0139] Through the intelligent evaluation of the network environment by the machine learning model of the present invention, potential security threats can be detected more precisely, and the network environment can be classified as high-risk or low-risk according to the network security coefficient. This intelligent evaluation can help the system perform more refined security protection in a dynamically changing network environment. In a low-risk network environment, continuing to use a fixed hash algorithm can maintain high performance and efficiency, avoiding unnecessary resource waste and performance degradation. In a high-risk network environment, based on real-time security evaluation, the system can promptly detect anomalies and react quickly, selecting a stronger encryption algorithm to effectively cope with new threats such as viruses and ransomware. In this way, the system not only improves the overall security protection ability but also optimizes the use of system resources, avoids performance degradation caused by excessive encryption, and ensures the balance between the efficiency and security of network transmission.
[0140] Only some exemplary embodiments of the present invention have been described by way of illustration above. Without doubt, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
Claims
1. A secure encryption transmission system for game data, characterized in that: It includes network environment data collection module, network risk feature extraction module, feature analysis and machine learning evaluation module, network environment classification module, low-risk network hash algorithm module and high-risk network hash algorithm adjustment module: The network environment data collection module comprehensively collects various parameter information of the current network environment before the handshake protocol starts; The network risk feature extraction module collects network environment parameters and systematically organizes and stores them to form a structured analysis set, from which key features reflecting that the network environment is in a high-risk state are extracted; The feature analysis and machine learning evaluation module conducts in-depth analysis of the extracted key features within the detection window and inputs the analyzed key features into the pre-trained machine learning model for intelligent evaluation; The network environment classification module classifies the current network environment into high-risk network environment and low-risk network environment based on the evaluation results of the machine learning model; Low-risk network hash algorithm module: In a low-risk network environment, a fixed hash algorithm is continued to be used to ensure the independence and security of sessions while maintaining high performance and efficiency; High-risk network hash algorithm adjustment module, in a high-risk network environment, will dynamically adjust the hash algorithm and select a hash algorithm with higher encryption strength and anti-attack capabilities to enhance the security of the session; Key features that reflect that the network environment is in a high-risk state are extracted from the analysis set. The extracted features include the frequency of port scanning in the network and potential abnormal behaviors in encrypted communications. Under the detection window, the extracted key features are analyzed to generate a port scanning behavior index and an encrypted communication anomaly index respectively. The port scanning behavior index quantifies the frequency and abnormality of port scanning activities in the network; the encrypted communication anomaly index quantifies the abnormal behavior of encrypted communication traffic in the network.
2. A secure encrypted transmission system for game data according to claim 1, characterized in that: The port scanning behavior index and encrypted communication anomaly index generated after analyzing the extracted key features are input into the pre-learned machine learning model, and the network security coefficient is generated by the machine learning model. The network security environment is intelligently evaluated through the network security coefficient.
3. A secure encrypted transmission system for game data according to claim 2, characterized in that: The generated network security coefficient is compared and analyzed with the preset network security coefficient reference threshold to classify the current network environment. The specific steps are as follows: If the network security factor is greater than or equal to a preset network security factor reference threshold, the current network environment is classified as a high-risk network environment; If the network security factor is less than a preset network security factor reference threshold, the current network environment is classified as a low-risk network environment.
4. A secure encrypted transmission system for game data according to claim 3, characterized in that: In a high-risk network environment, the hash algorithm will be dynamically adjusted to select a hash algorithm with higher encryption strength and anti-attack capabilities to enhance the security of the session. The specific steps are as follows: By comparing the network security factor NSC with the preset network security factor reference threshold NSC ref Compare and determine whether the encryption strength needs to be adjusted: When the network security factor NSC is greater than or equal to the network security factor reference threshold NSC ref When , it indicates that the network is in a high-risk environment, triggering the hash algorithm adjustment step; After confirming that the network environment is a high-risk network environment, a hash algorithm with higher encryption strength and anti-attack capability will be selected based on the network security coefficient NSC value. At this time, it is necessary to select a suitable high-strength hash algorithm from the algorithm library. In order to dynamically adjust the hash algorithm, refer to the performance indicators of the hash algorithm and combine the value of the network security coefficient NSC to decide which encryption level of the hash algorithm to switch to: After the hash algorithm is adjusted, the new hash algorithm will be applied in the handshake protocol phase. At this time, the new hash algorithm will be passed to both communicating parties to ensure that the subsequent data encryption and verification processes are processed based on high-strength hash algorithms. Before the session starts, the default hash algorithm is replaced based on the security assessment results in a high-risk environment to ensure that the key exchange, identity authentication and data integrity of the session are more secure. After the handshake protocol is generated and the hash algorithm is applied, the hash algorithm cannot be modified in real time. In order to ensure the long-term security of network communications, real-time monitoring will be continuously performed throughout the life cycle of the session, and potential threats will be dynamically evaluated. If the network security coefficient NSC continues to increase during the session, it means that new threats have appeared in the network environment. The feedback mechanism will be activated to notify the administrator to manually intervene and adjust, and select a stronger hash algorithm for the next session establishment.
5. A secure encrypted transmission system for game data according to claim 1, characterized in that: In the detection window, analyze the port scanning frequency in the network and generate the port scanning behavior index in the following specific steps: In the detection window, first, collect the port scanning events in the network. The collected port scanning behavior data is used for analysis and modeling. The expression is as follows: , In the formula, S i is the total number of port scan events initiated by source IP address i, I(Scan(t)) is the indicator function of the port scan event at time point t, and T is the total duration of the detection window; After collecting the port scanning events, the next step is to analyze the intensity of the scanning activity. To this end, the total number of scanning events for each source IP address in the time window is considered and weighted in combination with the number of scanned ports to reflect the intensity of the scan. The calculation expression is as follows: , Where N p (i) is the number of different ports scanned by source IP address i, α is a strength adjustment factor, I s is the port scan intensity, N is the total number of source IP addresses participating in the scan; After calculating the port scan intensity, it is also necessary to identify the abnormality of the scan behavior and calculate the rate of change of the scan intensity. The calculation expression is as follows: , In the formula, ΔI s is the rate of change of the scanning intensity, I s (t) is the port scan intensity calculated at time point t, I s (t-1) is the port scan intensity calculated at time point t-1; The port scan behavior index is generated by combining the port scan activity intensity and the rate of change of the scan intensity. The calculation expression is as follows: , Among them, P s is the port scanning behavior index, I s (i) is the scanning intensity of source IP address i, 1(ΔI s ≥δ) is the rate of change indicator function of the scanning intensity. When the rate of change exceeds the threshold δ, it is 1, indicating the presence of abnormal behavior. β is the weighting coefficient of abnormal behavior on the final index.
6. A secure encrypted transmission system for game data according to claim 1, characterized in that: In the detection window, the specific steps for analyzing potential abnormal behaviors in encrypted communication and generating an encrypted communication anomaly index are as follows: In the detection window, we first extract multiple features from the encrypted communication traffic to capture abnormal behavior. By acquiring encrypted communication data in real time, we can accurately capture the behavior pattern changes of encrypted traffic. The calculation expression is as follows: , Where FAD(t) is the abnormality of encrypted communication traffic, i.e., the abnormality of encrypted communication traffic at time point t, I p (t) is the observed value of the p-th type of encrypted communication traffic at time t, Q p is the median of historical data of the p-th type of encrypted communication traffic, E p is the deviation function of the p-th type of encrypted communication traffic, A p is the weight coefficient of the p-th type of encrypted communication traffic characteristics, P is the total number of encrypted communication traffic categories; Using the extracted feature data, we can identify the abnormal patterns of encrypted communications. By combining the rule-based detection system and machine learning methods, we can identify abnormal patterns in communication behaviors. The calculation expression is as follows: , Where P j (t) is the observed value of the jth abnormal pattern indicator of the encrypted communication traffic at time t, is the normal behavior threshold of the pattern, τ j is the tolerance coefficient of abnormal mode, θ j is the weighting coefficient, γ j is the pattern sensitivity index, API(t) is the abnormal pattern recognition index; After identifying abnormal patterns in encrypted communications, the ratio of abnormal behaviors in encrypted communications is calculated. By calculating the weighted ratio of abnormal traffic proportion and communication duration, it is possible to accurately assess whether the current network is threatened. The calculation expression is as follows: , In the formula, B p (t) is an anomaly label, ∈ is a small constant to avoid the denominator being zero, and ARI(t) is the encryption communication anomaly ratio; The encrypted communication anomaly index is generated based on the encrypted traffic anomaly degree FAD(t), the anomaly pattern identification index API(t) and the encrypted communication anomaly ratio ARI(t). The calculation expression is as follows: , Where ECAI is the encrypted communication anomaly index, FAD p (t) represents the abnormality of the p-th type of encrypted communication traffic at time point t, API p (t) is the abnormal pattern recognition index of the p-th type of encrypted communication traffic at time point t, ARI p (t) is used to measure the encryption communication anomaly ratio of the p-th type of encrypted communication traffic at time point t.
Citation Information
Patent Citations
Intelligent encryption decision-making method and system for big data shared data
CN117692145A
Self-adjusting method of fuzzy network control system in network attack environment
CN118170010A