Network security detection method and system

By adopting blockchain platform, decentralized consensus mechanism, distributed network architecture and edge computing technologies in the network security detection system, single point of failure and data tampering problems of traditional centralized detection systems are solved, and more efficient and accurate network security detection is achieved.

CN119561790BActive Publication Date: 2025-05-09SICHUAN COMM RES PLANNING & DESIGNING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510112508.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-09
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

Traditional centralized network security detection systems have problems such as single point of failure risk, data tampering risk and insufficient real-time performance, making it difficult to effectively deal with cyber attacks.

Method used

Data is encrypted, stored and transmitted through the blockchain platform, and a consensus mechanism between decentralized nodes is used to conduct P2P verification and traceability mechanisms under the distributed network architecture, and secondary detection is carried out in combination with smart contracts and edge computing.

Benefits of technology

It significantly improves the overall security and attack resistance of the system, prevents data tampering and node abnormalities, and achieves more efficient and accurate network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561790B_ABST
    Figure CN119561790B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security detection technology, and discloses a network security detection method and system, including: encrypting, storing and transmitting data through a blockchain platform; in the blockchain platform, verifying the data in the block; the verification includes primary detection and secondary detection; when performing the primary detection, performing synchronous detection of network security; and summarizing and generating security detection results based on the results of the three detections. By improving the multi-level security detection method of data, nodes and consensus mechanism, the overall security and anti-attack capability of the system are significantly improved. Blockchain encrypted storage, P2P distributed verification and edge computing verification are adopted to effectively prevent data tampering and node anomalies, and achieve more efficient and accurate network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security detection, and in particular to a network security detection method and system. Background Art

[0002] With the rapid development of Internet technology and information systems, network security has become a key issue faced by various enterprises, institutions and individual users. The frequent occurrence of network security incidents has led to endless problems such as data leakage, system paralysis, and property loss, posing a great threat to the economy and society. Traditional network security detection methods mainly rely on centralized server structures to detect potential security threats by analyzing data packets, log records, and system behaviors. However, with the continuous upgrading of network attack technologies, traditional centralized detection systems have exposed some significant defects and challenges.

[0003] Centralized network security detection systems often rely on a single or a few servers to process all data and security analysis. This architecture has obvious single point failure risks. Once the central server is attacked or goes down, the entire system will be paralyzed, resulting in the failure of network security protection.

[0004] Traditional network security detection methods mainly rely on centralized architecture, which has problems such as single point failure, data tampering, and lack of real-time performance. Node security detection is inefficient, vulnerable to attacks, and difficult to control as a whole. Summary of the invention

[0005] In view of the above-mentioned problems, the present invention is proposed.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: a network security detection method, comprising:

[0007] Encrypt, store and transmit data through blockchain platform;

[0008] In the blockchain platform, the data in the block is verified; the verification includes primary detection and secondary detection;

[0009] When performing the primary detection, performing a synchronous detection of network security;

[0010] Based on the results of the three tests, the security test results are summarized and generated.

[0011] As a preferred solution of the network security detection method described in the present invention, the blockchain platform includes a consensus mechanism for reaching agreement among decentralized nodes; using each node to store a copy of the data; encrypting the data through a cryptographic algorithm; and automatically executing, verifying and enforcing the terms of the contract through smart contracts.

[0012] As a preferred solution of the network security detection method described in the present invention, wherein: the one-time detection includes using a distributed network architecture to perform P2P verification on the data in the block, specifically including: in the distributed network architecture, after a node receives the data in the block, it determines other nodes in the tracing process through a tracing mechanism, and obtains the block information of the other nodes, and verifies it with the block data received by the current node;

[0013] The distributed network architecture is a decentralized network architecture in which data is transmitted between nodes through direct communication, and the operation of the system completely depends on the cooperation of the nodes.

[0014] As a preferred solution of the network security detection method described in the present invention, wherein: the tracing mechanism specifically includes: assuming that the current node is D0, D0 receives the block Q0 in the node D1;

[0015] Record the transcription time t1 of block Q0 in D1, randomly extract nodes outside D0 and D1, and if there is no block consistent with Q0 in the extracted nodes, re-extract until there is a block consistent with Q0 in the extracted nodes, and the transcription time of the block is less than t1; at the same time, record the node as D2, and record the block consistent with Q0 in D2 as Q1;

[0016] Compare the data in Q0 and Q1. If the data is consistent, the data is considered safe.

[0017] If the data is inconsistent, block Q1 in D2 and block Q0 in D1 are traced again, and the traceability results are Q2 and Q3 respectively;

[0018] Compare the data in Q0, Q1, Q2 and Q3, and use the majority decision method to get the correct data. The blocks with consistent data are regarded as safe blocks, and the other blocks are regarded as abnormal blocks and marked together with the nodes where they are located. If there is no block with consistent data, stop the detection and report an error directly.

[0019] As a preferred solution of the network security detection method described in the present invention, wherein: the synchronous detection includes relying on the traceability mechanism between nodes in the one detection process; while performing the one detection, obtaining the consensus mechanism of the current node and all extracted nodes in the traceability process, and completing the network security detection of the node through the verification of the consensus mechanism;

[0020] During the synchronization detection according to the traceability mechanism, if there is no difference in the consensus mechanism, it is determined that the network security is normal;

[0021] If there is a difference in the consensus mechanism, the network security is judged to be abnormal. The consensus mechanism of n nodes in the randomly selected platform is used to check the consensus mechanism of the two nodes with differences and the randomly selected n nodes. The correct consensus mechanism is obtained by majority decision. When there is more than one unit with abnormal consensus mechanism, a comprehensive warning of network security physical examination is issued; when there is only one unit with abnormal consensus mechanism, the unit with abnormal consensus mechanism is marked;

[0022] Where n is a randomly generated number, which is an integer greater than 1 and less than N-2; N is the number of all nodes.

[0023] As a preferred solution of the network security detection method described in the present invention, wherein: the secondary detection is the detection of data after the nodes in the blockchain complete the data calculation; it includes using the data returned by the edge computing node to recalculate the data in the block to verify the accuracy of the data.

[0024] As a preferred solution of the network security detection method described in the present invention, wherein: the recalculation of the data in the block specifically includes: the nodes in the blockchain complete the data calculation, package the calculated result data in the block, and transcribe the original data of the current calculation as a separate block;

[0025] Let the node that completes data calculation for the first time be the initial node;

[0026] The copied individual blocks are randomly sent to m nodes. In these m nodes, the original data is used to recalculate the data, and the calculation results are returned to the initial node. If the m returned results are consistent with the calculation results of the initial node, the node is judged to be safe;

[0027] If the m returned results are inconsistent with the calculation result of the initial node, the correct node is obtained by majority decision; when there is only one wrong node, the wrong node is marked; when there is more than one wrong node, a comprehensive warning of node safety check is issued;

[0028] Wherein, m is a randomly generated number, and its value is an integer greater than 1 and less than M; M is the maximum number of nodes to be selected, and M<N-2.

[0029] A network security detection system using the method of the present invention is characterized by:

[0030] The transmission unit encrypts, stores and transmits data through the blockchain platform;

[0031] A detection unit, in the blockchain platform, performs a primary detection on the data in the block; while performing the primary detection, performs a synchronous detection of network security; after the primary detection is completed, performs a secondary detection on the data in the node of the blockchain;

[0032] The summary unit summarizes and generates security test results based on the results of the three tests.

[0033] A computer device comprises: a memory and a processor; the memory stores a computer program, wherein: the processor implements the steps of any one of the methods of the present invention when executing the computer program.

[0034] A computer-readable storage medium stores a computer program, wherein: when the computer program is executed by a processor, the steps of any one of the methods of the present invention are implemented.

[0035] Beneficial effects of the invention: The network security detection method provided by the invention significantly improves the overall security and anti-attack capability of the system by improving the multi-level security detection method of data, nodes and consensus mechanism. Blockchain encrypted storage, P2P distributed verification and edge computing verification are adopted to effectively prevent data tampering and node anomalies, and realize more efficient and accurate network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0037] Figure 1 An overall flow chart of a network security detection method provided for the first embodiment of the present invention. DETAILED DESCRIPTION

[0038] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0039] Example 1, reference Figure 1 , as an embodiment of the present invention, provides a network security detection method, comprising:

[0040] S1: Data is encrypted, stored and transmitted through the blockchain platform.

[0041] The blockchain platform includes a consensus mechanism for reaching agreement among decentralized nodes; using each node to store a copy of data; encrypting data through cryptographic algorithms; and automatically executing, verifying and enforcing contract terms through smart contracts.

[0042] The blockchain platform encrypts data through cryptographic algorithms to ensure the privacy and security of data during storage and transmission. Encryption technology prevents unauthorized access and data leakage. It usually adopts a combination of symmetric encryption (such as AES) and asymmetric encryption (such as RSA, ECC). Symmetric encryption is used for efficient encryption of large-scale data, and asymmetric encryption is used for secure key exchange, thereby ensuring the safe and reliable storage and transmission of data in the blockchain.

[0043] A smart contract is an automated protocol embedded in the blockchain that automatically executes related operations when preset conditions are met. Smart contracts ensure the automation, reliability and transparency of system operations through coded contract terms. After being published on the blockchain, smart contracts will automatically execute predetermined operations based on specific trigger conditions (such as time, data status, etc.) without the intervention of a third party. Its immutability ensures the transparency and credibility of contract execution, and records all operations on the chain for easy auditing and tracking.

[0044] S2: In the blockchain platform, the data in the block is verified; the verification includes primary detection and secondary detection.

[0045] The one-time detection includes using a distributed network architecture to perform P2P verification of the data in the block, specifically including: in the distributed network architecture, after the node receives the data in the block, it determines the other nodes in the traceability process through the traceability mechanism, and obtains the block information of the other nodes, and verifies it with the block data received by the current node. The distributed network architecture is a decentralized network architecture in which nodes transmit data through direct communication, and the operation of the system completely depends on the cooperation of nodes. The design of multi-node collaboration increases the fault tolerance of the system, so that even if some nodes have problems during the verification process, the system can still maintain normal operation through the data of other nodes.

[0046] The traceability mechanism specifically includes: assuming that the current node is D0, and D0 receives the block Q0 in the node D1.

[0047] Record the transcription time t1 of block Q0 in D1, randomly extract nodes outside D0 and D1, and if there is no block consistent with Q0 in the extracted nodes, re-extract; until there is a block consistent with Q0 in the extracted nodes, and the transcription time of the block is less than t1; at the same time, record the node as D2, and record the block consistent with Q0 in D2 as Q1.

[0048] Compare the data in Q0 and Q1. If the data are consistent, the data is considered safe.

[0049] If the data is inconsistent, block Q1 in D2 and block Q0 in D1 are traced again, and the traceability results are Q2 and Q3 respectively.

[0050] Compare the data in Q0, Q1, Q2 and Q3, and use the majority decision method to get the correct data. The blocks with consistent data are regarded as safe blocks, and the other blocks are regarded as abnormal blocks, and are marked together with the nodes where they are located. If there is no block with consistent data, stop the detection and report an error directly. (The absence of a block with consistent data means that anomalies occurred during multiple transcriptions. At this time, the accuracy of the data is very low, and the credibility of the data is reduced. In this case, there is no need to continue running. At this time, stop the machine and report an error to prevent the spread of abnormal data.)

[0051] It is important to mention that the traceability mechanism can realize multi-layer verification and accuracy check of block data, thus improving data security and consistency. Specifically, by continuously tracing the source nodes of data and comparing multi-node data, data tampering or abnormality can be identified, ensuring the authenticity and integrity of data in the system and preventing malicious nodes from forging or tampering with data.

[0052] Traditional traceability mechanisms are usually based on static data source records, which only verify the direct source of data and cannot deeply detect the data consistency of multiple nodes. This solution verifies the data consistency between multiple nodes by dynamically randomly extracting nodes, which makes the traceability process more flexible and robust. This solution introduces timestamp comparison in the verification process to ensure the time order and version consistency of data. By checking the data transcription time, invalid tracing of abnormal data can be avoided. This solution uses the majority decision method to judge the correctness of the data, that is, to compare the data of multiple nodes and determine the final trusted data based on the data consistency results of the majority of nodes. Conventional traceability methods often rely on a single data source or a fixed verification path. The majority decision method increases the credibility of data verification. Even if the data of a few nodes is maliciously tampered with, it will not affect the overall judgment result, thereby significantly improving the reliability of data security.

[0053] The secondary detection is the detection of data after the nodes in the blockchain complete the data calculation; it includes using the data returned by the edge computing node to recalculate the data in the block and verify the accuracy of the data.

[0054] The recalculation of the data in the block specifically includes: the nodes in the blockchain complete the data calculation, package the calculated result data in the block, and then transcribe the original data of the current calculation as a separate block.

[0055] The node that completes data calculation for the first time is assumed to be the initial node.

[0056] The transcribed individual blocks are randomly sent to m nodes. In these m nodes, the original data is used to recalculate the data, and the calculation results are returned to the initial node. If the m returned results are consistent with the calculation results of the initial node, the node is judged to be safe.

[0057] If the m returned results are inconsistent with the calculation result of the initial node, the correct node is obtained by majority voting; when there is only one node with calculation error, the node with calculation error is marked; when there is more than one node with calculation error, a comprehensive warning of node safety check is issued. Among them, m is a randomly generated number, the value is an integer greater than 1 and less than M; M is the maximum number of nodes to be selected, and M<N-2.

[0058] In addition, among the m randomly selected nodes, certain constraints need to be met: the idle computing power among these m nodes can complete the calculation. This avoids the delay caused by data calculation queues.

[0059] For the mark of the calculated error node P1, after correcting the error result, it is actively sent to P2, P3...Pk to implement the remedial correction of the data content. Among them, P2 is the first node to receive the block containing error information transmitted from P1; Pk is the kth node to receive the block containing error information transmitted from P1. The "nodes containing error information blocks" mentioned here include not only those directly transmitted from P1, but also those indirectly transmitted. When a node P0 completes the remedial correction of the data content, from this time point on, the data transmitted by this node is the updated data, and the nodes that receive the block data in P0 later do not need to participate in the remedial correction process.

[0060] The accuracy and consistency of the calculation results of blockchain nodes are verified through a secondary detection mechanism. By recalculating data in multiple nodes, it is detected whether there are errors or malicious tampering when the nodes perform calculations, thereby ensuring the computing power of the nodes and the reliability of data processing. The security and anti-attack capabilities of the nodes in the entire blockchain network are enhanced.

[0061] It should be noted that this solution uses the data of edge computing nodes as the basis for secondary detection. This method not only relies on the traceability mechanism of the blockchain itself, but also combines real-time computing power to re-verify the data. Conventional traceability mechanisms generally only rely on the tracking of historical data on the chain, and do not involve the verification of computing power. This solution recalculates the transcribed block data by randomly distributing it to multiple nodes (m nodes), and returns the results to the initial node for comparison. This multi-node verification method is not common in traditional traceability, which usually relies on predetermined nodes or historical records for one-way verification. The multi-node recalculation mechanism ensures the fairness and randomness of the data verification process. By comparing multiple independent calculation results, it reduces the risk of individual nodes being attacked or maliciously manipulated, and greatly improves the robustness of the system and data reliability.

[0062] Verification by randomly generating a number of nodes (m) increases the security and anti-attack capabilities of the system. Even if an attacker attempts to tamper with a single node, the effect of the attack will be greatly reduced because the verification node is randomly selected, thereby improving the effectiveness of node security detection.

[0063] S3: When performing the primary detection, a synchronous detection of network security is performed.

[0064] Furthermore, relying on the traceability mechanism between nodes in the one-time detection process; while conducting the one-time detection, the consensus mechanism of the current node and all the extracted nodes in the traceability process is obtained, and the network security detection of the node is completed through the verification of the consensus mechanism.

[0065] During the process of performing the synchronization detection according to the traceability mechanism, if there is no difference in the consensus mechanism, it is determined that the network security is normal.

[0066] If there is a difference in the consensus mechanism, the network security is judged to be abnormal. The consensus mechanism of n nodes in the randomly selected platform is used to check the consensus mechanism of the two nodes with differences and the randomly selected n nodes. The correct consensus mechanism is obtained by majority decision. When there is more than one unit with abnormal consensus mechanism, a comprehensive warning of network security physical examination is issued; when there is only one unit with abnormal consensus mechanism, the unit with abnormal consensus mechanism is marked. Among them, n is a randomly generated number, the value is an integer greater than 1 and less than N-2; N is the number of all nodes.

[0067] It should be noted that traditional traceability mechanisms usually only track the source and transmission path of data, focusing mainly on the integrity and correctness of the data itself. In this solution, the traceability mechanism not only traces the data, but also monitors the consensus status between nodes in real time, and verifies the consistency of the current node and other extracted nodes in the consensus mechanism. Conventional traceability mechanisms usually verify preset paths or fixed nodes, while this solution increases the flexibility and security of the traceability and verification process by randomly selecting multiple nodes (n nodes) to participate in the consensus mechanism verification. The randomly selected node mechanism can effectively prevent attacks on specific nodes and reduce the possibility of malicious attackers predicting or manipulating verification nodes. In this way, the system can still maintain a high level of security when facing complex network attacks.

[0068] When the consensus mechanism of multiple nodes is abnormal, the system will immediately issue a comprehensive network security checkup warning to remind the system administrator to conduct in-depth investigation and countermeasures. If only one node is abnormal, the node will be marked. This design enables the system to isolate potential threats at the first time and maintain the overall stability and security of the network. In addition, it should be noted that if the consensus mechanism is abnormal in multiple nodes, it means that the system may be invaded on a large scale, so network security needs to be checked at this time.

[0069] S4: Based on the results of the three tests, a security test result is generated.

[0070] The system will collect all the results of primary detection, synchronous detection and secondary detection, including the data consistency of each node, the consensus mechanism verification status and the accuracy of the calculation results.

[0071] If the three test results are consistent, the system will generate a "safe" test report to confirm that there are no abnormalities in the network at the data, node and consensus mechanism levels. If there are abnormal markings or warnings, the method and content of each warning and marking will be summarized. Based on the comprehensive summary of the test results, the network security status will be evaluated and divided into "safe", "warning" or "dangerous" levels.

[0072] When certain nodes or data are marked as abnormal, corresponding security alerts are triggered based on the number and severity of the abnormalities, and specific response suggestions are given.

[0073] All detection results are summarized to generate a detailed security detection report, which lists all marked abnormal nodes, details of abnormal data and possible security threats so that system administrators can take appropriate measures.

[0074] Embodiment 2 is an embodiment of the present invention, which provides a network security detection system, including:

[0075] The transmission unit encrypts, stores and transmits data through the blockchain platform.

[0076] The detection unit performs a detection on the data in the block in the blockchain platform; while performing the detection, a synchronous detection of network security is performed; after the detection is completed, a secondary detection is performed on the data in the node of the blockchain.

[0077] The summary unit summarizes and generates security test results based on the results of the three tests.

[0078] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program code.

[0079] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0080] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0081] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0082] Example 3 is an embodiment of the present invention, which provides a network security detection method. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0083] This experiment is divided into two groups: the experimental group uses the detection method of the present invention, and the comparison group uses the traditional centralized detection method. Both the experimental group and the comparison group are run in the same blockchain environment to ensure the fairness and comparability of the experimental results.

[0084] 100 nodes were set up in the environment, distributed in a decentralized network, of which 20 nodes were used as edge computing nodes. The same abnormal conditions were added to the experimental environments of the two groups, and the abnormalities were identified through the two experimental processes until the technicians made corrections based on the detected problems. After the corrections were completed, the two methods were run again, with randomly selected samples 1 to 6 as the main experimental objects, and the performance of each sample in data integrity, consensus mechanism consistency, and edge computing node verification was analyzed. The data records are shown in Table 1.

[0085] Table 1 Experimental data record table

[0086] ,

[0087] By comparing the above experimental data, the advantages of the present invention in data integrity, node consensus mechanism consistency verification and edge computing error rate control are clearly demonstrated. The average accuracy of the present invention in data integrity detection reached 99.7%, which is significantly higher than the 95% of the traditional method. This shows that the present invention effectively improves data consistency and integrity and reduces the possibility of data tampering through a distributed P2P verification and traceability mechanism. The traditional method has a bottleneck effect in centralized single-node verification, and data integrity is limited by the processing power and network status of the central server. The present invention overcomes this limitation and achieves higher data reliability through multi-node collaboration.

[0088] The method of the present invention showed an average consistency rate of 98.7%, while the traditional method of the comparison group was only 92%. This shows that the synchronous detection mechanism of the present invention can more effectively prevent the consensus mechanism from breaking down and quickly reach consensus with the participation of multiple nodes. The traditional method relies on a single server for consensus processing and is susceptible to distributed denial of service attacks (DDoS), resulting in poor consistency. The present invention reduces the damage to the consistency of the system by attacks through decentralization and majority decision strategies, thereby improving the robustness of the network.

[0089] The error rate of the edge computing node of the present invention is only 0.5%, which is much lower than the 3.2% error rate of the traditional method on the central computing node. This shows that the use of edge computing nodes for secondary verification effectively reduces the errors in data processing and improves the accuracy of the system's control over node data. The traditional method is limited by the computing power and delay of the central node, and the error rate is relatively high; the distributed computing mode of the present invention can process data nearby, reducing the errors caused by data transmission.

[0090] In summary, the innovation of the present invention is reflected in its multi-level detection and traceability mechanism, which significantly improves the security and stability of the network through systematic and distributed security detection. Compared with traditional methods, the present invention shows higher accuracy and reliability in dealing with data integrity, consensus consistency and calculation errors, proving that it has strong practical application value in the field of network security detection.

[0091] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A network security detection method, characterized in that: include: Encrypt, store and transmit data through blockchain platform; In the blockchain platform, verifying the data in the block; The verification includes primary testing and secondary testing; When performing the primary detection, performing a synchronous detection of network security; Based on the results of the three tests, the safety test results are summarized and generated; The primary detection includes using a distributed network architecture to perform P2P verification on the data in the block, specifically including: in the distributed network architecture, after a node receives the data in the block, it determines other nodes in the tracing process through a traceability mechanism, obtains the block information of the other nodes, and verifies it with the block data received by the current node; The distributed network architecture is a decentralized network architecture in which data is transmitted between nodes through direct communication, and the operation of the system completely depends on the cooperation of the nodes; The traceability mechanism specifically includes: assuming that the current node is D0, D0 receives the block Q0 in the node D1; Record the transcription time t1 of block Q0 in D1, randomly extract nodes outside D0 and D1, and if there is no block consistent with Q0 in the extracted nodes, re-extract until there is a block consistent with Q0 in the extracted nodes, and the transcription time of the block is less than t1; at the same time, record the node as D2, and record the block consistent with Q0 in D2 as Q1; Compare the data in Q0 and Q1. If the data is consistent, the data is considered safe. If the data is inconsistent, block Q1 in D2 and block Q0 in D1 are traced again, and the traceability results are Q2 and Q3 respectively; Compare the data in Q0, Q1, Q2 and Q3, and use the majority decision method to get the correct data. The blocks with consistent data are regarded as safe blocks, and the other blocks are regarded as abnormal blocks and marked together with the nodes where they are located. If there is no block with consistent data, stop the detection and report an error directly.

2. The network security detection method according to claim 1, characterized in that: The blockchain platform includes a consensus mechanism for reaching agreement among decentralized nodes; using each node to store a copy of data; encrypting data through cryptographic algorithms; and automatically executing, verifying and enforcing contract terms through smart contracts.

3. The network security detection method according to claim 1, characterized in that: The synchronous detection includes relying on the traceability mechanism between nodes in the one-time detection process; while performing the one-time detection, obtaining the consensus mechanism of the current node and all extracted nodes in the traceability process, and completing the detection of the network security of the node through the verification of the consensus mechanism; During the synchronization detection according to the traceability mechanism, if there is no difference in the consensus mechanism, it is determined that the network security is normal; If there is a difference in the consensus mechanism, the network security is judged to be abnormal. The consensus mechanism of n nodes in the randomly selected platform is used to check the consensus mechanism of the two nodes with differences and the randomly selected n nodes. The correct consensus mechanism is obtained by majority decision. When there is more than one unit with abnormal consensus mechanism, a comprehensive warning of network security physical examination is issued; when there is only one unit with abnormal consensus mechanism, the unit with abnormal consensus mechanism is marked; Where n is a randomly generated number, which is an integer greater than 1 and less than N-2; N is the number of all nodes.

4. The network security detection method according to claim 3, characterized in that: The secondary detection is the detection of data after the nodes in the blockchain complete the data calculation; it includes using the data returned by the edge computing node to recalculate the data in the block and verify the accuracy of the data.

5. The network security detection method according to claim 4, characterized in that: The recalculation of the data in the block specifically includes: the nodes in the blockchain complete the data calculation, package the result data of the calculation in the block, and transcribe the original data of the current calculation as a separate block; Let the node that completes data calculation for the first time be the initial node; The copied individual blocks are randomly sent to m nodes. In these m nodes, the original data is used to recalculate the data, and the calculation results are returned to the initial node. If the m returned results are consistent with the calculation results of the initial node, the node is judged to be safe; If the m returned results are inconsistent with the calculation result of the initial node, the correct node is obtained by majority decision; when there is only one wrong node, the wrong node is marked; when there is more than one wrong node, a comprehensive warning of node safety check is issued; Wherein, m is a randomly generated number, and its value is an integer greater than 1 and less than M; M is the maximum number of nodes to be selected, and M<N-2.

6. A network security detection system using the method according to any one of claims 1 to 5, characterized in that: The transmission unit encrypts, stores and transmits data through the blockchain platform; A detection unit, in the blockchain platform, performs a primary detection on the data in the block; while performing the primary detection, performs a synchronous detection of network security; after the primary detection is completed, performs a secondary detection on the data in the node of the blockchain; The summary unit summarizes and generates security test results based on the results of the three tests.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the network security detection method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security detection method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Industrial data detection block chain network architecture based on edge computing and detection method

    CN109302405A