A network traffic covert forwarding method based on superimposed phantom paths
By using superimposed phantom path, graph neural network and deep reinforcement learning technology in the secret forwarding method of network traffic, the problems of insufficient privacy protection capabilities and difficulty in dealing with complex network environments in the existing technology are solved, and efficient data privacy protection and secure transmission are achieved.
Patent Information
- Application Number
- CN202510259198.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The existing technology is difficult to effectively deal with advanced traffic analysis attacks, especially in the environment of complex network topology and dynamic traffic, the privacy protection capabilities are insufficient, making it difficult to achieve efficient data recovery and privacy installation.
The secret forwarding method of network traffic based on superimposed phantom paths is adopted, combined with graph neural network (GNN), deep reinforcement learning (Deep RL) and dynamic path adjustment mechanisms, and the secret and security of network data during transmission is ensured through dynamic generation of virtual paths, path overlays, privacy installation and traffic load prediction.
It significantly improves privacy protection and security during data transmission, can adapt to complex network environments in real time, avoid traffic analysis and path restoration attacks, and ensures data integrity and consistency.
Smart Images

Figure CN119743421B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network traffic secret forwarding method based on superimposed phantom paths. Background Art
[0002] With the popularization of the Internet and the development of informatization, the security and privacy protection of network traffic have received increasing attention. Especially in the process of data transmission, how to prevent data leakage and tampering and how to avoid malicious attacks have become important issues in network communications. Traditional security protection methods, such as encrypted communications, virtual private networks (VPNs) and firewalls, have been widely used. These methods improve network security by encrypting transmitted data or by restricting access paths. However, although these methods can effectively prevent data leakage, they are often unable to effectively deal with advanced traffic analysis attacks, especially when facing attacks through traffic pattern recognition, traditional encryption and protection methods seem to be powerless.
[0003] Among existing privacy protection methods, although encryption technology has certain advantages in preventing data leakage, it still faces threats such as traffic analysis attacks (such as traffic fingerprinting) and path analysis attacks. In this case, attackers may restore sensitive data or identify the identities of both parties in communication by monitoring and analyzing data traffic, thereby bypassing encryption protection and obtaining private information. Therefore, simply relying on static path selection and encryption technology is no longer sufficient, and new, more complex and dynamic privacy protection technologies are needed.
[0004] Existing multi-path transmission methods can alleviate the security risks of single-path transmission to a certain extent, but their path selection usually relies on predetermined rules and cannot provide sufficient flexibility and security when dealing with dynamically changing network environments. Existing path selection algorithms, such as the shortest path algorithm or static load balancing algorithm, usually ignore the real-time changes in network traffic and potential attack patterns. In addition, when faced with network traffic analysis, these traditional methods are still easily inferred by attackers through traffic characteristics, thereby exposing the communication content or the identity of the participants.
[0005] In addition, with the development of advanced intelligent algorithms such as graph neural networks (GNNs) and deep reinforcement learning (Deep RL), more and more studies have begun to try to apply these technologies to network traffic optimization and path selection. By monitoring the network status and traffic characteristics in real time, the optimal path is dynamically selected based on the machine learning model, thereby effectively avoiding traffic analysis attacks and improving network performance. However, although these methods have improved the flexibility and intelligence of path selection to a certain extent, they still have the defect of being unable to adapt to complex network environments in real time in terms of privacy protection and data transmission security. Especially in the face of complex network topologies and dynamic traffic environments, existing methods often lack sufficient privacy protection capabilities and it is difficult to achieve sufficiently efficient data recovery and privacy disguise.
[0006] Therefore, how to provide a network traffic covert forwarding method based on overlapping phantom paths is a problem that technical personnel in this field urgently need to solve. Summary of the invention
[0007] One purpose of the present invention is to propose a method for secretly forwarding network traffic based on overlapping phantom paths. The present invention makes full use of graph neural networks (GNNs), deep reinforcement learning (Deep RL) and dynamic path adjustment mechanisms, and describes in detail how to ensure the privacy and security of network data during transmission through technologies such as dynamic generation of virtual paths, path overlap, privacy camouflage and traffic load prediction. The method can intelligently adjust the network path, optimize the traffic forwarding of data packets, and avoid traffic analysis attacks and path analysis attacks. By combining deep learning and intelligent algorithms, the present invention can not only achieve efficient management of network traffic, but also adapt to different security requirements and traffic patterns in real time in a complex and changeable network environment, ensuring the privacy and security of data transmission.
[0008] The advantage of the present invention is that it innovatively uses overlapping phantom paths and intelligent algorithms, making the selection of network paths more flexible and intelligent, greatly improving the ability to protect data privacy. Through privacy camouflage and path overlapping technology, the traffic pattern of the data packet is effectively hidden, enhancing the ability to resist traffic analysis attacks. At the same time, with the help of graph neural networks and deep reinforcement learning algorithms, the present invention can dynamically evaluate the network status and adjust the path selection in real time, making the forwarding of network traffic more efficient and unpredictable. In addition, the present invention restores the correct order and content of the data packet through a reverse mapping algorithm, ensuring the integrity and consistency of data transmission, and has significant security and efficiency.
[0009] A method for secretly forwarding network traffic based on overlapping phantom paths according to an embodiment of the present invention includes the following steps:
[0010] S1, collect network traffic data and pre-process it, extract the traffic subset that needs to be forwarded secretly, and build a virtual path based on traffic feature analysis;
[0011] S2. Construct a path superposition strategy based on the generated virtual path, superimpose the virtual path into the physical network, generate superimposed virtual path data packets, and dynamically allocate a virtual path for each data packet;
[0012] S3, performing privacy disguise processing on the superimposed virtual path data packets, including multi-layer encryption, noise injection, timestamp disguise and data packet sequence transformation;
[0013] S4, optimize the selection of virtual paths according to the data packets processed by privacy disguise, and dynamically adjust the path allocation strategy for each data packet based on the real-time network status, traffic load, attack mode and environmental feedback information;
[0014] S5. Based on the generated dynamic path allocation, the virtual path data and the data packets processed by privacy disguise are combined to identify and analyze potential traffic attacks, and the path overlap strategy is adjusted in real time;
[0015] S6. At the receiving end, decrypt and restore the data packets according to the adjusted path overlap strategy, and use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic;
[0016] S7. Perform integrity verification on the recovered data packets to verify the accuracy and consistency of the data, generate a detailed transmission security report, and record the security and data integrity of the entire transmission process.
[0017] Optionally, the S2 specifically includes:
[0018] S21. Analyze the physical network topology and network traffic demand based on the generated virtual path, and determine the virtual path superposition strategy:
[0019] ;
[0020] in, is the selected virtual path, and To adjust the weight, is the path bandwidth, is the path delay, is the physical path, P is the set of physical paths, To find a path in the physical path set P , so that the value of the objective function is minimized;
[0021] S22. Overlay the virtual path onto the physical network and perform load balancing through a multi-path overlay mechanism. Each virtual path is dynamically adjusted based on the real-time load and capacity of the network:
[0022] ;
[0023] in, is the virtual path assigned to the data packet, is the remaining capacity of the path, is the path load, and are the weight coefficients of load and delay respectively, To find a path in the physical path set P , so that the value of the objective function is maximized;
[0024] S23, generate superimposed virtual path data packets, evaluate the matching degree between each data packet and the virtual path, select the optimal path for allocation, consider the path load, delay, bandwidth and data packet transmission characteristics, and generate a comprehensive matching degree through weighted summation:
[0025] ;
[0026] in, is the matching degree between the virtual path and the characteristics of the data packet, is the matching factor between the i-th virtual path and the j-th packet characteristic, and is the weight coefficient of the data packet characteristics, is the delay adjustment factor, n is the number of characteristic types of data packets;
[0027] S24. Based on dynamic load balancing, a real-time path adjustment mechanism is used to optimize the allocation of virtual paths through traffic analysis and network status feedback:
[0028] ;
[0029] in, To optimize the allocation of virtual paths, is the delay adjustment factor;
[0030] S25. According to the selected path and data packet characteristics, a suitable virtual path is allocated to each data packet. The data packet allocation strategy is combined with network traffic patterns, delays, bandwidth and security requirements to dynamically adjust the path selection and optimize the path allocation strategy using real-time feedback data.
[0031] Optionally, the S3 specifically includes:
[0032] S31, perform privacy disguise processing on the generated superimposed virtual path data packet, first use a multi-layer encryption algorithm to encrypt the data packet, generate an encrypted data packet, and use a variable encryption algorithm combined with a dynamic key generation method, each data packet uses a different encryption method:
[0033] ;
[0034] in, For the encrypted data packet, is the original data packet, A dynamic key generated based on a timestamp. is the encryption algorithm type, Encrypt is the encryption operation function;
[0035] S32, inject noise into the encrypted data packet to generate a disguised data packet, and further enhance the disguise effect by combining a multi-dimensional noise source and a dynamic noise intensity control algorithm:
[0036] ;
[0037] in, is the data packet after adding noise, is the noise intensity, is the multidimensional noise generating function, t is the timestamp, is the network state variable;
[0038] S33, add timestamp disguise to the data packet, and insert time disguise using random timestamp generation algorithm:
[0039] ;
[0040] in, is the disguised timestamp, is the original timestamp, is the time offset calculated according to the algorithm, Disguise strength for time, is a random offset based on network traffic and historical timestamps;
[0041] S34, transform the order of data packets by introducing an adaptive order transformation algorithm based on network traffic status:
[0042] ;
[0043] in, is the transformed data packet sequence, is the original data packet order, NetworkState is the real-time network state, RandomSeed is the random seed, and AdaptiveShuffle is the adaptive order transformation algorithm;
[0044] S35, packing the data packets after the above encryption, noise injection, timestamp disguise and sequence transformation processing and preparing to send, and finally generating a privacy disguised data packet.
[0045] Optionally, the S4 specifically includes:
[0046] S41. Based on the data packets processed by privacy disguise, the graph neural network algorithm is used to optimize the selection of each virtual path. Combined with the real-time status of the network, traffic load, attack mode and path characteristics, the multi-dimensional optimization score of each path is calculated:
[0047] ;
[0048] in, For virtual path The optimization score of is the throughput of the path, is the path delay, Score the safety of the path, is the stability score of the path, and is the weight coefficient;
[0049] S42. Combined with the path optimization score, a dynamic path adjustment strategy based on deep reinforcement learning is used to consider path load, latency, bandwidth, and real-time network status to select the optimal path for packet forwarding:
[0050] ;
[0051] in, is the selected virtual path, and are the weights of load and delay in path selection, is the weight of the path score, is the path load, is the path delay, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths;
[0052] S43. According to the selected path, a feedback mechanism based on path stability is adopted to adjust the path selection rules in real time:
[0053] ;
[0054] in, is the selected path, StabilityFactor is the feedback factor of path stability, TrafficDemand is the real-time traffic demand, and Feedback() is the dynamic path adjustment mechanism function;
[0055] S44. Use the graph neural network algorithm to dynamically identify and predict potential risks in the path, and adjust the path overlap strategy based on network load and attack mode:
[0056] ;
[0057] in, For path risk assessment, is the k-pair path of nodes in the graph neural network The influence of is the probability of the path being attacked, and is the adjustment coefficient, m is the number of nodes;
[0058] S45. Adjust the path allocation strategy in real time according to the path risk assessment and network status.
[0059] Optionally, the S5 specifically includes:
[0060] S51. Based on the generated dynamic path allocation, combined with the generated virtual path data and the data packets processed by privacy disguise, a risk assessment is performed on each virtual path through a multi-dimensional attack detection algorithm and traffic pattern analysis:
[0061] ;
[0062] in, For path The risk value, For path Correlation with attack feature k, For path The congestion degree under attack mode k is, For path The delay of MaxDelay is the maximum delay of all paths in the network. , and is the weight coefficient, m is the number of attack modes;
[0063] S52, sorting the virtual paths according to the risk assessment value, and selecting a path that can meet the demand for data packet forwarding in combination with the real-time traffic demand and load;
[0064] S53, based on historical traffic data and real-time network status, combined with deep reinforcement learning algorithms, predict the load and delay of the path, and optimize the traffic distribution of the path in real time:
[0065] ;
[0066] in, For path Traffic load prediction, For path The traffic load at time j is, For path The delay of MaxDelay is the maximum delay of all paths in the network. For path The impact score of the attack encountered, , and is the adjustment coefficient, n is the time step;
[0067] S54. Combine the traffic load prediction result and the path risk assessment value to dynamically adjust the path overlap strategy:
[0068] ;
[0069] in, For the optimized virtual path, and is the adjustment coefficient, To find a path in the physical path set P , so that the value of the objective function is minimized, is the physical path, P is the set of physical paths, For traffic demand;
[0070] S55. Use graph neural networks and deep learning-based dynamic path analysis algorithms to conduct in-depth analysis of network topology and traffic changes, and dynamically adjust path overlap strategies based on path security and traffic demand:
[0071] ;
[0072] in, Analyze the characteristics of the path for the graph neural network, Score the path's abnormal behavior, is the weighting coefficient of abnormal behavior, is the adjustment coefficient of the traffic load, MaxLoad is the maximum load of all paths in the network, The path that is finally selected.
[0073] Optionally, the S6 specifically includes:
[0074] S61. Based on the generated path selection and optimization, by comparing the real-time load and historical traffic data of the path, combined with the graph neural network algorithm, the health status of each virtual path is dynamically monitored and the stability of the path is evaluated:
[0075] ;
[0076] in, Score the path stability, is the load of the path in the kth time period, is the path delay, is the probability of path failure, , and is the weight coefficient, m is the feature dimension;
[0077] S62. Reorder the paths according to the stability scores, and select the path with the highest stability score for traffic forwarding:
[0078] ;
[0079] in, For the selected path, is the bandwidth of the path, is the bandwidth weight coefficient, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths;
[0080] S63, based on real-time network feedback and path health assessment, optimize path load distribution through multi-scale dynamic adjustment algorithm:
[0081] ;
[0082] in, The load optimization value for the path, is the load of the path at time j, is the maximum load of the path, is the path delay, is the maximum delay of the path, and is the adjustment coefficient, n is the time step;
[0083] S64. Based on load optimization, intelligently optimize the traffic distribution of the path and adjust the traffic distribution strategy in real time;
[0084] S65. Use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic, and restore its original sequence and content:
[0085] ;
[0086] in, For the recovered data packet, It is the data packet after privacy disguise processing, InverseMap is the reverse mapping algorithm, PathChanges is the path change record, and NetworkState is the real-time status of the network.
[0087] The beneficial effects of the present invention are:
[0088] The present invention significantly improves the privacy protection and security during data transmission by adopting a network traffic covert forwarding method based on overlapping phantom paths. Through the optimization of dynamic path selection and load balancing, combined with intelligent algorithms such as graph neural networks (GNN) and deep reinforcement learning (Deep RL), the present invention can evaluate changes in network traffic in real time and automatically adjust paths and traffic distribution, thereby effectively avoiding the static and inflexible problems common in traditional path selection methods. Especially when facing complex network environments and various potential attacks, the present invention provides a highly intelligent solution that keeps network traffic highly concealed during transmission, preventing traffic analysis and path restoration attacks.
[0089] In addition, through the overlapping phantom path technology, the traffic pattern of the data packet is dynamically disguised and multi-path overlapped, which makes attackers face extremely high complexity when trying to analyze and decode the traffic. Even if the attacker uses advanced traffic analysis technology, it is difficult to restore the real data or identify the real path of the communication. This innovative mechanism effectively avoids the risk of data leakage and identity identification, and improves the privacy protection ability in network communications.
[0090] By combining the reverse mapping algorithm, the present invention can also restore the correct order and content of data packets during multi-path transmission, ensuring the integrity and consistency of the data. This not only enhances the security of the data, but also improves the stability of network traffic, allowing the network to operate stably in complex environments and avoiding transmission errors caused by improper path selection or disordered data packets.
[0091] Therefore, the present invention not only improves the efficiency and security of network traffic forwarding, but also provides strong technical support for data privacy protection, and has significant innovation and practicality. By comprehensively optimizing path selection and data transmission, the present invention solves the challenges of inflexible paths, insufficient privacy protection, and traffic analysis attacks in the prior art, and provides a more secure, efficient, and adaptable method for secretly forwarding network traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0092] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0093] Figure 1 A flowchart of a network traffic covert forwarding method based on overlapping phantom paths proposed by the present invention;
[0094] Figure 2 A schematic diagram of a method for secretly forwarding network traffic based on overlapping phantom paths proposed by the present invention for restoring the order and content of data packets based on a reverse mapping algorithm. DETAILED DESCRIPTION
[0095] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.
[0096] refer to Figure 1 and Figure 2 , a network traffic secret forwarding method based on superimposed phantom paths, comprising the following steps:
[0097] S1, collect network traffic data and pre-process it, extract the traffic subset that needs to be forwarded secretly, and build a virtual path based on traffic feature analysis;
[0098] S2. Construct a path superposition strategy based on the generated virtual path, superimpose the virtual path into the physical network, generate superimposed virtual path data packets, and dynamically allocate a virtual path for each data packet;
[0099] S3, performing privacy disguise processing on the superimposed virtual path data packets, including multi-layer encryption, noise injection, timestamp disguise and data packet sequence transformation;
[0100] S4, optimize the selection of virtual paths according to the data packets processed by privacy disguise, and dynamically adjust the path allocation strategy for each data packet based on the real-time network status, traffic load, attack mode and environmental feedback information;
[0101] S5. Based on the generated dynamic path allocation, the virtual path data and the data packets processed by privacy disguise are combined to identify and analyze potential traffic attacks, and the path overlap strategy is adjusted in real time;
[0102] S6. At the receiving end, decrypt and restore the data packets according to the adjusted path overlap strategy, and use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic;
[0103] S7. Perform integrity verification on the recovered data packets to verify the accuracy and consistency of the data, generate a detailed transmission security report, and record the security and data integrity of the entire transmission process.
[0104] In this implementation, S2 specifically includes:
[0105] S21. Analyze the physical network topology and network traffic demand based on the generated virtual path, and determine the virtual path superposition strategy:
[0106] ;
[0107] in, is the selected virtual path, and To adjust the weight, is the path bandwidth, is the path delay, is the physical path, P is the set of physical paths, To find a path in the physical path set P , so that the value of the objective function is minimized;
[0108] S22. Overlay the virtual path onto the physical network and perform load balancing through a multi-path overlay mechanism. Each virtual path is dynamically adjusted based on the real-time load and capacity of the network:
[0109] ;
[0110] in, is the virtual path assigned to the data packet, is the remaining capacity of the path, is the path load, and are the weight coefficients of load and delay respectively, To find a path in the physical path set P , so that the value of the objective function is maximized;
[0111] S23, generate superimposed virtual path data packets, evaluate the matching degree between each data packet and the virtual path, select the optimal path for allocation, consider the path load, delay, bandwidth and data packet transmission characteristics, and generate a comprehensive matching degree through weighted summation:
[0112] ;
[0113] in, is the matching degree between the virtual path and the characteristics of the data packet, is the matching factor between the i-th virtual path and the j-th packet characteristic, and is the weight coefficient of the data packet characteristics, is the delay adjustment factor, n is the number of characteristic types of data packets;
[0114] S24. Based on dynamic load balancing, a real-time path adjustment mechanism is used to optimize the allocation of virtual paths through traffic analysis and network status feedback:
[0115] ;
[0116] in, To optimize the allocation of virtual paths, is the delay adjustment factor;
[0117] S25. According to the selected path and data packet characteristics, a suitable virtual path is allocated to each data packet. The data packet allocation strategy is combined with network traffic patterns, delays, bandwidth and security requirements to dynamically adjust the path selection and optimize the path allocation strategy using real-time feedback data.
[0118] In this implementation, S3 specifically includes:
[0119] S31, perform privacy disguise processing on the generated superimposed virtual path data packet, first use a multi-layer encryption algorithm to encrypt the data packet, generate an encrypted data packet, and use a variable encryption algorithm combined with a dynamic key generation method, each data packet uses a different encryption method:
[0120] ;
[0121] in, For the encrypted data packet, is the original data packet, A dynamic key generated based on a timestamp. is the encryption algorithm type, Encrypt is the encryption operation function;
[0122] S32, inject noise into the encrypted data packet to generate a disguised data packet, and further enhance the disguise effect by combining a multi-dimensional noise source and a dynamic noise intensity control algorithm:
[0123] ;
[0124] in, is the data packet after adding noise, is the noise intensity, is the multidimensional noise generating function, t is the timestamp, is the network state variable;
[0125] S33, add timestamp disguise to the data packet, and insert time disguise using random timestamp generation algorithm:
[0126] ;
[0127] in, is the disguised timestamp, is the original timestamp, is the time offset calculated according to the algorithm, Disguise strength for time, is a random offset based on network traffic and historical timestamps;
[0128] S34, transform the order of data packets by introducing an adaptive order transformation algorithm based on network traffic status:
[0129] ;
[0130] in, is the transformed data packet sequence, is the original data packet order, NetworkState is the real-time network state, RandomSeed is the random seed, and AdaptiveShuffle is the adaptive order transformation algorithm;
[0131] S35, packing the data packets after the above encryption, noise injection, timestamp disguise and sequence transformation processing and preparing to send, and finally generating a privacy disguised data packet.
[0132] In this implementation, S4 specifically includes:
[0133] S41. Based on the data packets processed by privacy disguise, the graph neural network algorithm is used to optimize the selection of each virtual path. Combined with the real-time status of the network, traffic load, attack mode and path characteristics, the multi-dimensional optimization score of each path is calculated:
[0134] ;
[0135] in, For virtual path The optimization score of is the throughput of the path, is the path delay, Score the safety of the path, is the stability score of the path, and is the weight coefficient;
[0136] S42. Combined with the path optimization score, a dynamic path adjustment strategy based on deep reinforcement learning is used to consider path load, latency, bandwidth, and real-time network status to select the optimal path for packet forwarding:
[0137] ;
[0138] in, is the selected virtual path, and are the weights of load and delay in path selection, is the weight of the path score, is the path load, is the path delay, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths;
[0139] S43. According to the selected path, a feedback mechanism based on path stability is adopted to adjust the path selection rules in real time:
[0140] ;
[0141] in, is the selected path, StabilityFactor is the feedback factor of path stability, TrafficDemand is the real-time traffic demand, and Feedback() is the dynamic path adjustment mechanism function;
[0142] S44. Use the graph neural network algorithm to dynamically identify and predict potential risks in the path, and adjust the path overlap strategy based on network load and attack mode:
[0143] ;
[0144] in, For path risk assessment, is the k-pair path of nodes in the graph neural network The influence of is the probability of the path being attacked, and is the adjustment coefficient, m is the number of nodes;
[0145] S45. Adjust the path allocation strategy in real time according to the path risk assessment and network status.
[0146] In this implementation manner, S5 specifically includes:
[0147] S51. Based on the generated dynamic path allocation, combined with the generated virtual path data and the data packets processed by privacy disguise, a risk assessment is performed on each virtual path through a multi-dimensional attack detection algorithm and traffic pattern analysis:
[0148] ;
[0149] in, For path The risk value, For path Correlation with attack feature k, For path The congestion degree under attack mode k is, For path The delay of MaxDelay is the maximum delay of all paths in the network. , and is the weight coefficient, m is the number of attack modes;
[0150] S52, sorting the virtual paths according to the risk assessment value, and selecting a path that can meet the demand for data packet forwarding in combination with the real-time traffic demand and load;
[0151] S53, based on historical traffic data and real-time network status, combined with deep reinforcement learning algorithms, predict the load and delay of the path, and optimize the traffic distribution of the path in real time:
[0152] ;
[0153] in, For path Traffic load prediction, For path The traffic load at time j is, For path The delay of MaxDelay is the maximum delay of all paths in the network. For path The impact score of the attack encountered, , and is the adjustment coefficient, n is the time step;
[0154] S54. Combine the traffic load prediction result and the path risk assessment value to dynamically adjust the path overlap strategy:
[0155] ;
[0156] in, For the optimized virtual path, and is the adjustment coefficient, To find a path in the physical path set P , so that the value of the objective function is minimized, is the physical path, P is the set of physical paths, For traffic demand;
[0157] S55. Use graph neural networks and deep learning-based dynamic path analysis algorithms to conduct in-depth analysis of network topology and traffic changes, and dynamically adjust path overlap strategies based on path security and traffic demand:
[0158] ;
[0159] in, Analyze the characteristics of the path for the graph neural network, Score the path's abnormal behavior, is the weighting coefficient of abnormal behavior, is the adjustment coefficient of the traffic load, MaxLoad is the maximum load of all paths in the network, The final selected path.
[0160] In this implementation manner, S6 specifically includes:
[0161] S61. Based on the generated path selection and optimization, by comparing the real-time load and historical traffic data of the path, combined with the graph neural network algorithm, the health status of each virtual path is dynamically monitored and the stability of the path is evaluated:
[0162] ;
[0163] in, Score the path stability, is the load of the path in the kth time period, is the path delay, is the probability of path failure, , and is the weight coefficient, m is the feature dimension;
[0164] S62. Reorder the paths according to the stability scores, and select the path with the highest stability score for traffic forwarding:
[0165] ;
[0166] in, For the selected path, is the bandwidth of the path, is the bandwidth weight coefficient, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths;
[0167] S63, based on real-time network feedback and path health assessment, optimize path load distribution through multi-scale dynamic adjustment algorithm:
[0168] ;
[0169] in, The load optimization value for the path, is the load of the path at time j, is the maximum load of the path, is the path delay, is the maximum delay of the path, and is the adjustment coefficient, n is the time step;
[0170] S64. Based on load optimization, intelligently optimize the traffic distribution of the path and adjust the traffic distribution strategy in real time;
[0171] S65. Use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic, and restore its original sequence and content:
[0172] ;
[0173] in, For the recovered data packet, It is the data packet after privacy disguise processing, InverseMap is the reverse mapping algorithm, PathChanges is the path change record, and NetworkState is the real-time status of the network.
[0174] Embodiment 1:
[0175] In order to verify the feasibility of the present invention in implementation, the present invention is applied to the internal network of a multinational company, which mainly processes important data such as financial data, customer sensitive information and internal communications, so data security and privacy protection are particularly important. With the increasing complexity of the network environment, traditional security protection measures, such as firewalls, encrypted communications and VPNs, can no longer effectively deal with the risks of privacy leakage caused by network traffic analysis attacks and traffic analysis.
[0176] The company has multiple departments, including the Finance Department, Legal Department, R&D Department, and IT Support Department. A large amount of sensitive data is transmitted across departments through the company's internal network every day. For example, the Finance Department regularly transmits sensitive information such as bank transfer records and company financial statements to the Legal Department, while the IT Department transmits maintenance information and security reports of key systems to management. Since this data contains a large amount of commercial secrets, any data leakage may cause huge financial and reputational losses. The company urgently needs an efficient network traffic management method to prevent external attacks while ensuring the privacy and integrity of data.
[0177] In this scenario, the amount of data transmitted over the network is huge, and the data traffic has obvious regularity. For example, the communication traffic between the Finance Department and the Legal Department is usually large and has fixed time characteristics. If an attacker can analyze these traffic patterns, it is possible to infer sensitive information or identify the identities of the communicating parties, thereby conducting further attacks.
[0178] During the implementation process, the company first collected and analyzed network traffic data in real time, and used the technology of the present invention to generate multiple virtual paths. Through graph neural networks and deep reinforcement learning algorithms, the system generates multiple virtual paths in real time according to changes in data traffic and network topology, and superimposes these virtual paths onto the existing physical network to form complex overlapping phantom paths. The generation and selection of these paths take into account the network's load, latency, and potential attack patterns, making the flow of data packets difficult to predict and track.
[0179] During the data packet transmission process, the network performs privacy disguise on the data, using multi-layer encryption technology and timestamp disguise. Through these technologies, the traffic pattern of the data packet is dynamically disguised, preventing the fixed pattern from being analyzed by attackers to reveal the transmission content. At each moment of data packet transmission, the path selection is dynamically optimized based on the real-time network status. After the data packet arrives at the target node, the system restores the original order and content of the data packet through the reverse mapping algorithm. The reverse mapping algorithm can intelligently restore the privacy-disguised data packet to the correct order according to the dynamic changes in network traffic and path adjustments, thereby ensuring data integrity and transmission reliability.
[0180] Table 1 Comparison of the effects of network traffic secret forwarding methods before and after the experiment
[0181] ;
[0182] According to the analysis of the table data, the experimental results show that the network performance and security have been significantly improved after the application of the network traffic secret forwarding method based on the overlapping phantom path. First, the success rate of traffic analysis attacks was reduced from 75% to 15%, an increase of 60%, indicating that privacy protection and path selection effectively prevent traffic analysis attacks. Secondly, the data transmission delay was reduced from 140 milliseconds to 120 milliseconds, an increase of 14.29%, indicating that the network delay was optimized while improving privacy protection. The data transmission speed increased by 10.42%, from 48 Mbps to 53 Mbps, indicating that the network performance remains efficient under privacy protection. The correctness of data packet recovery increased from 90% to 100%, ensuring data integrity and accuracy. Finally, although the system resource consumption increased slightly (3%), compared with other performance improvements, the increase was acceptable and did not have a significant impact on the overall system efficiency. Overall, the present invention improves the security, efficiency and reliability of data transmission and solves the shortcomings of the prior art.
[0183] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A network traffic secret forwarding method based on superimposed phantom paths, characterized in that: The steps include: S1, collect network traffic data and pre-process it, extract the traffic subset that needs to be forwarded secretly, and build a virtual path based on traffic feature analysis; S2. Construct a path superposition strategy based on the generated virtual path, superimpose the virtual path into the physical network, generate superimposed virtual path data packets, and dynamically allocate a virtual path for each data packet; S3, performing privacy disguise processing on the superimposed virtual path data packets, including multi-layer encryption, noise injection, timestamp disguise and data packet sequence transformation; S4, optimize the selection of virtual paths according to the data packets processed by privacy disguise, and dynamically adjust the path allocation strategy for each data packet based on the real-time network status, traffic load, attack mode and environmental feedback information; S5. Based on the generated dynamic path allocation, the virtual path data and the data packets processed by privacy disguise are combined to identify and analyze potential traffic attacks, and the path overlap strategy is adjusted in real time; S6. At the receiving end, decrypt and restore the data packets according to the adjusted path overlap strategy, and use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic; S7. Verify the integrity of the recovered data packets, verify the accuracy and consistency of the data, and generate a detailed transmission security report to record the security and data integrity of the entire transmission process; The S4 specifically includes: S41. Based on the data packets processed by privacy disguise, the graph neural network algorithm is used to optimize the selection of each virtual path. Combined with the real-time status of the network, traffic load, attack mode and path characteristics, the multi-dimensional optimization score of each path is calculated: ; in, For virtual path The optimization score of is the throughput of the path, is the path delay, Score the safety of the path, is the stability score of the path, and is the weight coefficient; S42. Combined with the path optimization score, a dynamic path adjustment strategy based on deep reinforcement learning is used to consider path load, latency, bandwidth, and real-time network status to select the optimal path for packet forwarding: ; in, is the selected virtual path, and are the weights of load and delay in path selection, is the weight of the path score, is the path load, is the path delay, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths; S43. According to the selected path, a feedback mechanism based on path stability is adopted to adjust the path selection rules in real time: ; in, is the selected path, StabilityFactor is the feedback factor of path stability, TrafficDemand is the real-time traffic demand, and Feedback() is the dynamic path adjustment mechanism function; S44. Use the graph neural network algorithm to dynamically identify and predict potential risks in the path, and adjust the path overlap strategy based on network load and attack mode: ; in, For path risk assessment, is the k-pair path of nodes in the graph neural network The influence of is the probability of the path being attacked, and is the adjustment coefficient, m is the number of nodes; S45. Adjust the path allocation strategy in real time according to the path risk assessment and network status.
2. According to claim 1, a network traffic secret forwarding method based on superimposed phantom paths is characterized in that: The S2 specifically includes: S21. Analyze the physical network topology and network traffic demand based on the generated virtual path, and determine the virtual path superposition strategy: ; in, is the selected virtual path, and To adjust the weight, is the path bandwidth, is the path delay, is the physical path, P is the set of physical paths, To find a path in the physical path set P , so that the value of the objective function is minimized; S22. Overlay the virtual path onto the physical network and perform load balancing through a multi-path overlay mechanism. Each virtual path is dynamically adjusted based on the real-time load and capacity of the network: ; in, is the virtual path assigned to the data packet, is the remaining capacity of the path, is the path load, and are the weight coefficients of load and delay respectively, To find a path in the physical path set P , so that the value of the objective function is maximized; S23, generate superimposed virtual path data packets, evaluate the matching degree between each data packet and the virtual path, select the optimal path for allocation, consider the path load, delay, bandwidth and data packet transmission characteristics, and generate a comprehensive matching degree through weighted summation: ; in, is the matching degree between the virtual path and the characteristics of the data packet, is the matching factor between the i-th virtual path and the j-th packet characteristic, and is the weight coefficient of the data packet characteristics, is the delay adjustment factor, n is the number of characteristic types of data packets; S24. Based on dynamic load balancing, a real-time path adjustment mechanism is used to optimize the allocation of virtual paths through traffic analysis and network status feedback: ; in, To optimize the allocation of virtual paths, is the delay adjustment factor; S25. According to the selected path and data packet characteristics, a suitable virtual path is allocated to each data packet. The data packet allocation strategy is combined with network traffic patterns, delays, bandwidth and security requirements to dynamically adjust the path selection and optimize the path allocation strategy using real-time feedback data.
3. According to claim 1, a network traffic secret forwarding method based on superimposed phantom paths is characterized in that: The S3 specifically includes: S31, perform privacy disguise processing on the generated superimposed virtual path data packet, first use a multi-layer encryption algorithm to encrypt the data packet, generate an encrypted data packet, and use a variable encryption algorithm combined with a dynamic key generation method, each data packet uses a different encryption method: ; in, For the encrypted data packet, is the original data packet, A dynamic key generated based on a timestamp. is the encryption algorithm type, Encrypt is the encryption operation function; S32, inject noise into the encrypted data packet to generate a disguised data packet, and further enhance the disguise effect by combining a multi-dimensional noise source and a dynamic noise intensity control algorithm: ; in, is the data packet after adding noise, is the noise intensity, is the multidimensional noise generating function, t is the timestamp, is the network state variable; S33, add timestamp disguise to the data packet, and insert time disguise using random timestamp generation algorithm: ; in, is the disguised timestamp, is the original timestamp, is the time offset calculated according to the algorithm, Disguise strength for time, is a random offset based on network traffic and historical timestamps; S34, transform the order of data packets by introducing an adaptive order transformation algorithm based on network traffic status: ; in, is the transformed data packet sequence, is the original data packet order, NetworkState is the real-time network state, RandomSeed is the random seed, and AdaptiveShuffle is the adaptive order transformation algorithm; S35, packing the data packets after the above encryption, noise injection, timestamp disguise and sequence transformation processing and preparing to send, and finally generating a privacy disguised data packet.
4. According to claim 1, a method for secretly forwarding network traffic based on overlapping phantom paths is characterized in that: The S4 specifically includes: S41. Based on the data packets processed by privacy disguise, the graph neural network algorithm is used to optimize the selection of each virtual path. Combined with the real-time status of the network, traffic load, attack mode and path characteristics, the multi-dimensional optimization score of each path is calculated: ; in, For virtual path The optimization score of is the throughput of the path, is the path delay, Score the safety of the path, is the stability score of the path, and is the weight coefficient; S42. Combined with the path optimization score, a dynamic path adjustment strategy based on deep reinforcement learning is used to consider path load, latency, bandwidth, and real-time network status to select the optimal path for packet forwarding: ; in, is the selected virtual path, and are the weights of load and delay in path selection, is the weight of the path score, is the path load, is the path delay, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths; S43. According to the selected path, a feedback mechanism based on path stability is adopted to adjust the path selection rules in real time: ; in, is the selected path, StabilityFactor is the feedback factor of path stability, TrafficDemand is the real-time traffic demand, and Feedback() is the dynamic path adjustment mechanism function; S44. Use the graph neural network algorithm to dynamically identify and predict potential risks in the path, and adjust the path overlap strategy based on network load and attack mode: ; in, For path risk assessment, is the k-pair path of nodes in the graph neural network The influence of is the probability of the path being attacked, and is the adjustment coefficient, m is the number of nodes; S45. Adjust the path allocation strategy in real time according to the path risk assessment and network status.
5. According to claim 1, a method for secretly forwarding network traffic based on overlapping phantom paths is characterized in that: The S5 specifically includes: S51. Based on the generated dynamic path allocation, combined with the generated virtual path data and the data packets processed by privacy disguise, a risk assessment is performed on each virtual path through a multi-dimensional attack detection algorithm and traffic pattern analysis: ; in, For path The risk value, For path Correlation with attack feature k, For path The congestion degree under attack mode k is, For path The delay of MaxDelay is the maximum delay of all paths in the network. , and is the weight coefficient, m is the number of attack modes; S52, sorting the virtual paths according to the risk assessment value, and selecting a path that can meet the demand for data packet forwarding in combination with the real-time traffic demand and load; S53, based on historical traffic data and real-time network status, combined with deep reinforcement learning algorithms, predict the load and delay of the path, and optimize the traffic distribution of the path in real time: ; in, For path Traffic load prediction, For path The traffic load at time j is, For path The delay of MaxDelay is the maximum delay of all paths in the network. For path The impact score of the attack encountered, , and is the adjustment coefficient, n is the time step; S54. Combine the traffic load prediction result and the path risk assessment value to dynamically adjust the path overlap strategy: ; in, For the optimized virtual path, and is the adjustment coefficient, To find a path in the physical path set P , so that the value of the objective function is minimized, is the physical path, P is the set of physical paths, For traffic demand; S55. Use graph neural networks and deep learning-based dynamic path analysis algorithms to conduct in-depth analysis of network topology and traffic changes, and dynamically adjust path overlap strategies based on path security and traffic demand: ; in, Analyze the characteristics of the path for the graph neural network, Score the path's abnormal behavior, is the weighting coefficient of abnormal behavior, is the adjustment coefficient of the traffic load, MaxLoad is the maximum load of all paths in the network, The path that is finally selected.
6. According to claim 1, a method for secretly forwarding network traffic based on overlapping phantom paths is characterized in that: The S6 specifically includes: S61. Based on the generated path selection and optimization, by comparing the real-time load and historical traffic data of the path, combined with the graph neural network algorithm, the health status of each virtual path is dynamically monitored and the stability of the path is evaluated: ; in, Score the path stability, is the load of the path in the kth time period, is the path delay, is the probability of path failure, , and is the weight coefficient, m is the feature dimension; S62. Reorder the paths according to the stability scores, and select the path with the highest stability score for traffic forwarding: ; in, For the selected path, is the bandwidth of the path, is the bandwidth weight coefficient, To find a path in the physical path set P , so that the value of the objective function is maximized, is the physical path, and P is the set of physical paths; S63, based on real-time network feedback and path health assessment, optimize path load distribution through multi-scale dynamic adjustment algorithm: ; in, The load optimization value for the path, is the load of the path at time j, is the maximum load of the path, is the path delay, is the maximum delay of the path, and is the adjustment coefficient, n is the time step; S64. Based on load optimization, intelligently optimize the traffic distribution of the path and adjust the traffic distribution strategy in real time; S65. Use the reverse mapping algorithm to restore the correct data sequence and content according to the dynamic changes of network traffic, and restore its original sequence and content: ; in, For the recovered data packet, It is the data packet after privacy disguise processing, InverseMap is the reverse mapping algorithm, PathChanges is the path change record, and NetworkState is the real-time status of the network.
Citation Information
Patent Citations
Computing power routing method and system based on deep reinforcement learning and graph neural network
CN117896306A
DRL-GNN-based intent network intelligent routing method
CN118474013A