Computer network security data transmission method and device
By employing techniques such as dynamic encryption algorithm switching, path optimization, and virtual node layout, the real-time and integrity issues of computer network security data transmission in existing technologies have been resolved, enabling efficient and secure data transmission in dynamic threat environments.
Patent Information
- Application Number
- CN202510317956.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2045-03-18
AI Technical Summary
Existing technologies struggle to achieve real-time and complete secure computer network data transmission, especially when facing dynamic threat environments and high real-time requirements. Traditional secure transmission mechanisms have significant limitations in terms of encryption strategy flexibility, multi-path collaborative optimization, and data integrity assurance.
By dynamically switching encryption algorithms, optimizing path selection using path performance evaluation models and decision tree algorithms, verifying data integrity using fragmented metadata index tables and hash matching mechanisms, and constructing a distributed link quality evaluation network and a fake network topology generation model using federated learning technology, the frequency of encryption algorithm switching and transmission path selection strategies are dynamically adjusted.
It enables real-time response to changes in threat intelligence in a dynamic threat environment, ensuring the security and integrity of data transmission, improving transmission efficiency, reducing the risk of data loss, and enhancing network security protection capabilities.
Smart Images

Figure CN119922011B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of computer network security and data transmission technology, and in particular to a computer network security data transmission method and device. BACKGROUND
[0002] At present, computer network security data transmission faces the dual challenges of dynamic threat environment and high real-time demand, especially in response to the continuously changing network attack means, the traditional security transmission mechanism has significant limitations in encryption strategy flexibility, multi-path collaborative optimization and data integrity protection, making it difficult to achieve dynamic balance between security protection and transmission efficiency in complex network environment.
[0003] In one prior art, computer network security data transmission mainly uses fixed encryption algorithm and static path selection strategy, and a single encryption algorithm based on predefined security level binds a specific transmission path, resulting in encryption switching response delay and path performance fluctuations that cannot be adapted; at the same time, the dynamic control mechanism for the order of arrival and integrity verification of the fragments is lacking in the fragmentation transmission process, often resulting in fragment loss or failure of reordering due to network path differences. In addition, the generation and update of false network topology rely on periodic manual configuration, making it difficult to respond to real-time attack feature changes, causing defense lag. However, the prior art has the problem of being unable to achieve real-time and complete computer network security data transmission due to rigid encryption switching, lack of coordination between path selection and fragmentation transmission, and insufficient data reassembly verification mechanism.
[0004] In summary, the prior art has the problem of being unable to achieve real-time and complete computer network security data transmission. SUMMARY
[0005] The present application provides a computer network security data transmission method and device to achieve real-time and complete computer network security data transmission.
[0006] In a first aspect, to solve the above technical problems, the present application provides a computer network security data transmission method, comprising:
[0007] Obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, performing dynamic encryption algorithm switching based on the real-time threat intelligence data, and performing fragmentation encryption processing on the data to be transmitted to obtain encrypted fragment data;
[0008] Inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score;
[0009] According to the path performance score, combining a preset screening threshold, and using a decision tree algorithm to prioritize paths that meet the threshold condition to obtain a transmission path set;
[0010] According to the encrypted fragment data and the set of transmission paths, a fragment metadata index table is constructed and a fragment arrival time sequence analysis is performed to establish a buffer queue so as to match a sequence corresponding relationship between received fragments and original fragments;
[0011] The sequence corresponding relationship is subjected to integrity check of a fragment identifier through a hash matching mechanism to generate complete transmission data;
[0012] The real-time threat intelligence data and the real-time transmission performance parameters are extracted and analyzed to attack features, and an anti-attack optimization is performed to obtain a virtual node layout and a link connection strategy;
[0013] According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a global link quality analysis is performed by using a federated learning technology to obtain a transmission link quality score;
[0014] According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, a dynamic adjustment is made on an encryption algorithm switching frequency, a transmission path selection strategy and a virtual node configuration parameter to obtain real-time transmission data.
[0015] In an optional implementation, the real-time threat intelligence data, the real-time packet loss rate, the real-time end-to-end delay, the real-time transmission performance parameters and the to-be-transmitted data are obtained, a dynamic encryption algorithm switching is performed based on the real-time threat intelligence data, and the to-be-transmitted data is subjected to fragment encryption processing to obtain encrypted fragment data, including:
[0016] The real-time threat intelligence data, the real-time packet loss rate, the real-time end-to-end delay, the real-time transmission performance parameters of multiple network paths and the to-be-transmitted data are obtained;
[0017] The real-time transmission performance parameters include real-time transmission speed, real-time traffic characteristics and transmission stability data of multiple network paths;
[0018] According to the real-time threat intelligence data, a time sequence analysis is used to predict a dynamic trend prediction, a threat level change amplitude is calculated and a security level interval is divided to obtain a dynamic security level evaluation parameter;
[0019] According to the dynamic security level evaluation parameter, an encryption algorithm type dynamic matching is performed in combination with a preset encryption algorithm library to obtain an encryption algorithm dynamic selection model;
[0020] According to the encryption algorithm dynamic selection model and the dynamic security level evaluation parameter, an adaptive fragment strategy is used to fragment the to-be-transmitted data, a fragment size is adjusted based on a preset data sensitivity to obtain initial fragment data;
[0021] According to the initial fragment data, a dynamic encryption processing is performed, when a dynamic security level evaluation parameter promotion is detected, an encryption algorithm switching mechanism is triggered in the fragment transmission process, and encryption compatibility of the fragments before and after the switching is maintained, and encrypted fragment data is obtained.
[0022] In an optional implementation, the preset path performance evaluation model training process comprises:
[0023] obtaining historical real-time transmission performance parameters;
[0024] inputting the historical real-time transmission performance parameters into a linear regression model to obtain a historical path performance score;
[0025] when the number of training is greater than or equal to the preset number of training, it is determined that the training is completed, and a trained path performance evaluation model is obtained;
[0026] In an optional implementation, according to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain a transmission path set, comprising:
[0027] According to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain an initial optimal path set;
[0028] According to the initial optimal path set, a dynamic programming algorithm is used to real-time allocate fragment transmission tasks, to detect the arrival time of each fragment, and to obtain a fragment arrival time difference;
[0029] According to the fragment arrival time difference and the real-time transmission performance parameters, in combination with the path performance evaluation model, the path performance is re-evaluated and prioritized to obtain a transmission path set.
[0030] In an optional implementation, according to the encrypted fragment data and the transmission path set, a fragment metadata index table is constructed and fragment arrival time sequence analysis is performed, a buffer queue is established to match the sequence correspondence relationship between the received fragments and the original fragments, comprising:
[0031] According to the encrypted fragment data and the transmission path set, a hash algorithm is used to calculate the hash value of the encrypted fragment data, in combination with the unique identifier and the fragment sequence number in the encrypted fragment data, a fragment metadata index table is constructed;
[0032] According to the fragment metadata index table, fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence relationship between the received fragments and the original fragments.
[0033] In an optional implementation, the hash matching mechanism performs integrity checking on the sequence correspondence by using the shard identifier, and generates complete transmission data, including:
[0034] According to the sequence correspondence, the integrity of the shard identifier is checked in combination with a preset hash verification rule, when a shard loss or identifier mismatch is detected, the shards are logically reorganized in sequence based on the shard metadata index table and a multi-level sorting algorithm, and intermediate reorganization data conforming to the original shard data structure are obtained;
[0035] According to the intermediate reorganization data, the sequence correspondence and the shard metadata index table, a check completion algorithm is used to perform shard boundary checking and overall hash value comparison, detect data integrity and insert intermediate reorganization data for completion, and generate complete transmission data.
[0036] In an optional implementation, the virtual node layout and link connection strategy are obtained by extracting and analyzing attack features based on the real-time threat intelligence data and the real-time transmission performance parameters, including:
[0037] According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack source, attack type and attack target is obtained through multi-dimensional feature correlation analysis;
[0038] According to the three-dimensional attack feature set, a dynamic weight distribution algorithm is used to analyze the threat probability distribution of different attack paths in real time, and an attack behavior analysis report is obtained;
[0039] According to the attack behavior analysis report and the real-time transmission performance parameters, the mapping relationship between the false node deployment density and the link connection strength is analyzed, and a false network topology generation model is obtained;
[0040] According to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameters, the traffic feature similarity between the false nodes and the real nodes is obtained based on the preset network topology concealment evaluation rule;
[0041] According to the traffic feature similarity, the link confusion index is combined to perform anti-attack optimization, and the virtual node layout and link connection strategy are obtained.
[0042] In an optional implementation, the transmission link quality score is obtained by using federated learning technology to perform global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, including:
[0043] According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a differential privacy technology is used to protect inter-node data interaction, data is divided to each edge node for local model training, and a distributed evaluation framework based on federated learning is obtained;
[0044] According to the distributed evaluation framework and the real-time transmission performance parameters, a dynamic trust score model is established, historical transmission success rates and the real-time transmission performance parameters are analyzed, and an initial dynamic trust score is obtained.
[0045] According to the distributed evaluation framework, a federated aggregation algorithm is used to weight and fuse local model parameters of each edge node, a node trust score weight coefficient is periodically updated, and a real-time updated global link quality evaluation model is obtained.
[0046] The initial dynamic trust score and the real-time transmission performance parameters are input into the global link quality evaluation model, multi-dimensional score calculation is performed, and a transmission link quality score is obtained.
[0047] In an optional implementation, the dynamic adjustment of the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameter according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data comprises:
[0048] According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, threat intelligence change rate and network load fluctuation characteristics are analyzed, and a multi-dimensional optimization space containing security level, transmission efficiency and topology concealment index is constructed.
[0049] According to the multi-dimensional optimization space, an evolutionary algorithm is used for iterative solution, a balance point of security and transmission efficiency is analyzed, and an encryption algorithm switching frequency and a path selection priority coefficient are obtained.
[0050] According to the link connection strategy, real-time changes of false network topology adjustment are analyzed, a virtual node configuration dynamic response mechanism is established, optimization is performed through the inverse relationship between node deployment density and link connection strength, and a resource allocation strategy is obtained.
[0051] According to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, strategy matching verification is performed, and real-time transmission data is obtained.
[0052] In a second aspect, the present application provides a computer network security data transmission device, comprising:
[0053] The data acquisition module is configured to acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameter and to-be-transmitted data, perform dynamic encryption algorithm switching based on the real-time threat intelligence data, and perform fragmentation encryption processing on the to-be-transmitted data to obtain encrypted fragmented data.
[0054] The path evaluation module is configured to input the real-time transmission performance parameter into a preset path performance evaluation model to obtain a path performance score.
[0055] The sorting set module is configured to perform priority sorting on paths meeting a threshold condition by using a decision tree algorithm according to the path performance score and in combination with a preset filtering threshold to obtain a transmission path set.
[0056] The timing analysis module is configured to construct a fragmented metadata index table and perform fragmented arrival time sequence analysis according to the encrypted fragmented data and the transmission path set, and establish a buffer queue to match a sequence corresponding relationship between received fragments and original fragments.
[0057] The data recombination module is configured to perform integrity verification on a fragmented identifier of the sequence corresponding relationship by using a hash matching mechanism to generate complete transmission data.
[0058] The virtual layout module is configured to extract and analyze attack features according to the real-time threat intelligence data and the real-time transmission performance parameter, perform anti-attack optimization, and obtain a virtual node layout and a link connection strategy.
[0059] The link analysis module is configured to perform global link quality analysis by using a federated learning technology according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter to obtain a transmission link quality score.
[0060] The result output module is configured to dynamically adjust encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameter according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0061] In a fourth aspect, the present application further provides a computer readable storage medium, which comprises a stored computer program, wherein the computer program controls a device where the computer readable storage medium is located to perform the computer network security data transmission method in any one of the above aspects when the computer program is running.
[0062] Compared with the prior art, the present application has the following beneficial effects:
[0063] (1) The present application responds to threat intelligence changes in real time through a dynamic encryption algorithm switching mechanism, ensuring that encryption strategies can be quickly adjusted when security threats are detected. This rapid response capability greatly enhances the security of data transmission, reduces the risk of potential data leakage, and maintains efficient data protection in a dynamic threat environment.
[0064] (2) The present application realizes dynamic optimization selection of transmission paths based on a path performance evaluation model and decision tree algorithm. This mechanism can intelligently select the optimal path for data transmission according to network state and threat intelligence changes. This not only improves the efficiency of data transmission, but also reduces the risk of data loss due to network fluctuations or attacks.
[0065] (3) The present application uses a fragmented metadata index table and a hash matching mechanism to realize the integrity verification and intelligent reorganization of fragmented data. This method can automatically repair out-of-order and missing data fragments, ensuring the integrity and accuracy of data during transmission. This provides a reliable foundation for subsequent data processing and analysis.
[0066] (4) The present application combines federated learning technology to build a distributed link quality evaluation network to accurately perceive the global transmission state. Through the collaborative computing of edge nodes, the link quality evaluation is continuously optimized, enabling the system to more accurately monitor and manage the state of the entire network, improving the security and stability of the overall network.
[0067] (5) The present application uses a false network topology generation model to dynamically deploy virtual nodes to confuse attack paths. This defense mechanism can adjust node layout and link connection strategies in real time, effectively resisting attacks on actual network structures. This increases the difficulty for attackers to discover the real network topology, further enhancing the network security protection capability.
[0068] (6) The present application uses a multi-dimensional optimization space adaptive parameter adjustment mechanism to coordinate encryption strength, path priority, and node configuration parameters. Using evolutionary algorithms to dynamically balance security levels and transmission efficiency, the fragmentation encryption strength is dynamically adapted to threat levels, transmission path allocation is real-time matched with network load state, and virtual node deployment density is adjusted synchronously with attack feature changes. This ensures safe and efficient data transmission in complex and variable network environments. BRIEF DESCRIPTION OF DRAWINGS
[0069] Figure 1 is the flowchart of the computer network security data transmission method provided by the first embodiment of the present application;
[0070] Figure 2 is the structural diagram of the computer network security data transmission device provided by the second embodiment of the present application. DETAILED DESCRIPTION
[0071] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0072] With reference to Figure 1 The first embodiment of the present application provides a computer network security data transmission method, comprising the following steps:
[0073] S11, real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and to-be-transmitted data are obtained, a dynamic encryption algorithm switching is performed based on the real-time threat intelligence data, the to-be-transmitted data is subjected to fragmentation encryption processing, and encrypted fragmented data is obtained;
[0074] S12, the real-time transmission performance parameters are input into a preset path performance evaluation model, and a path performance score is obtained;
[0075] S13, according to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is adopted to perform priority sorting on paths meeting the threshold condition, and a transmission path set is obtained
[0076] S14, according to the encrypted fragmented data and the transmission path set, a fragmented metadata index table is constructed and fragmented arrival time sequence analysis is performed, a buffer queue is established, and a sequence corresponding relationship of received fragments and original fragments is matched;
[0077] S15, the sequence corresponding relationship is subjected to integrity verification of a fragmented identifier through a hash matching mechanism, and complete transmission data is generated;
[0078] S16, according to the real-time threat intelligence data and the real-time transmission performance parameters, attack features are extracted and analyzed, anti-attack optimization is performed, virtual node layout and link connection strategies are obtained;
[0079] S17, according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a federal learning technology is adopted to perform global link quality analysis, and a transmission link quality score is obtained;
[0080] S18, according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, a dynamic adjustment is performed on encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameters, and real-time transmission data is obtained.
[0081] In step S11, real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted are acquired, dynamic encryption algorithm switching is performed based on the real-time threat intelligence data, and the data to be transmitted is subjected to fragmentation encryption processing to obtain encrypted fragmented data.
[0082] In an implementation manner, real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted are acquired, dynamic encryption algorithm switching is performed based on the real-time threat intelligence data, and the data to be transmitted is subjected to fragmentation encryption processing to obtain encrypted fragmented data, including:
[0083] Real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters of multiple network paths and data to be transmitted are acquired; the real-time transmission performance parameters include real-time transmission speed, real-time traffic characteristics and transmission stability data of the multiple network paths; a dynamic trend is predicted by using time series analysis according to the real-time threat intelligence data, a threat level change amplitude is calculated and a security level interval is divided to obtain a dynamic security level evaluation parameter; an encryption algorithm type dynamic matching is performed according to the dynamic security level evaluation parameter and in combination with a preset encryption algorithm library to obtain an encryption algorithm dynamic selection model; an adaptive fragmentation strategy is used to perform fragmentation processing on the data to be transmitted according to the encryption algorithm dynamic selection model and the dynamic security level evaluation parameter, a fragmentation size is adjusted based on a preset data sensitivity to obtain initial fragmented data; and dynamic encryption processing is performed according to the initial fragmented data, an encryption algorithm switching mechanism is triggered in a fragmentation transmission process when a dynamic security level evaluation parameter is improved, and encryption compatibility of fragments before and after the encryption algorithm switching is maintained to obtain encrypted fragmented data.
[0084] It should be noted that the dynamic security level evaluation parameter is a quantitative security index generated by performing time series feature extraction and trend prediction on real-time threat intelligence data. Specifically, the dynamic security level evaluation parameter is a discretized security level value obtained by analyzing time series variation characteristics of network attack frequency, attack type distribution and threat propagation rate, calculating a change gradient of threat intensity in a future period, and mapping the change gradient in combination with a preset security level division rule, and is used for dynamic matching of encryption algorithm strength level. The encrypted fragmented data is fragmented data obtained by performing real-time encryption processing on initial fragmented data by using an encryption algorithm associated with the dynamic security level evaluation parameter. The encrypted fragmented data acquisition process is as follows: by continuously monitoring security level changes, dynamically switching encryption algorithm types in a fragmentation transmission process according to threat situation changes, and by embedding algorithm identifiers and version compatibility information in a fragment header, it is ensured that the receiving end can still correctly decrypt historical fragments when the fragmentation encryption mode is changed, and the encrypted fragmented data that takes into account security and transmission continuity is obtained.
[0085] In step S12, the real-time transmission performance parameter needs to be input into the preset path performance evaluation model to obtain a path performance score.
[0086] In an implementation manner, the preset path performance evaluation model training process comprises:
[0087] The historical real-time transmission performance parameter is obtained.
[0088] The historical real-time transmission performance parameter is input into a linear regression model to obtain a historical path performance score.
[0089] When the training times are greater than or equal to the preset training times, it is determined that the training is completed, and a trained path performance evaluation model is obtained.
[0090] It should be noted that the path performance evaluation model is a prediction model established by linear regression algorithm for correlation analysis of the historical real-time transmission performance parameter and the historical path performance score, which is used to map the real-time transmission performance parameter to a quantifiable path performance index; the path performance score is a path comprehensive performance evaluation value output by the path performance evaluation model, which is obtained by inputting the real-time transmission speed, the packet loss rate and the stability data into the trained regression model for forward calculation, and directly reflects the transmission capacity level of the current path, and is used as a core input parameter of the decision tree algorithm for path priority sorting, and is used to guide the path allocation optimization of the dynamic programming algorithm for the slice transmission task.
[0091] In step S13, according to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to perform priority sorting on paths meeting the threshold condition to obtain a transmission path set.
[0092] In an implementation manner, according to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to perform priority sorting on paths meeting the threshold condition to obtain a transmission path set, which comprises:
[0093] According to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to perform priority sorting on paths meeting the threshold condition to obtain an initial optimal path set; according to the initial optimal path set, a dynamic programming algorithm is used to allocate a slice transmission task in real time, to detect slice arrival times to obtain a slice arrival time difference; according to the slice arrival time difference and the real-time transmission performance parameter, in combination with the path performance evaluation model, the path performance is re-evaluated and priority sorted to obtain a transmission path set.
[0094] It should be noted that the decision tree algorithm is a machine learning method for path priority ranking by feature splitting and rule matching on path performance score, the decision tree algorithm constructs a tree classification structure with transmission delay, bandwidth utilization and packet loss rate as decision nodes according to the real-time score data output by the path performance evaluation model, and then divides the path performance level according to the preset filtering threshold and generates a priority ranking list; the re-evaluation of path performance and the priority ranking is a dynamic path optimization process realized by the feedback mechanism of the difference of the arrival time of the fragments, in which the path performance score is first dynamically corrected according to the difference of the arrival time of the fragments and the real-time transmission performance parameters, and the real-time transmission performance parameters are adjusted, the updated real-time transmission performance parameters are input into the path performance evaluation model to recalculate the path comprehensive score, and then the decision tree algorithm is used to generate a new priority ranking list by feature splitting and rule matching on the corrected score data; the transmission path set is an executable path combination formed after the initial sorting result is verified by the dynamic programming algorithm for fragment task allocation, and the acquisition process of the transmission path set is as follows: first, the decision tree algorithm is used to filter out candidate paths with scores higher than the threshold from all available paths, and then the dynamic programming algorithm is used to simulate the delay difference and load distribution of the fragment transmission task on different paths, the path weight coefficient is dynamically adjusted according to the difference of the arrival time of the fragments, and finally the transmission path set considering the transmission efficiency and stability is formed, which is used to guide the multi-path collaborative transmission of encrypted fragments.
[0095] In step S14, according to the encrypted fragment data and the transmission path set, a fragment metadata index table is constructed and fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence relationship between the received fragments and the original fragments.
[0096] In one implementation, according to the encrypted fragment data and the transmission path set, a fragment metadata index table is constructed and fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence relationship between the received fragments and the original fragments, including:
[0097] According to the encrypted fragment data and the transmission path set, the hash value of the encrypted fragment data is calculated by using a hash algorithm, the unique identifier and the fragment sequence number in the encrypted fragment data are combined to construct a fragment metadata index table; according to the fragment metadata index table, the fragment arrival time sequence analysis is performed, and the buffer queue is established to match the sequence correspondence relationship between the received fragments and the original fragments.
[0098] It should be noted that the shard metadata index table is a set of encrypted shard data features generated by a hash algorithm, used to record the logical order, encryption features and transmission path mapping relationship of the shard data, and the shard metadata index table is obtained by extracting a shard unique identifier, a shard sequence number and a hash value to construct a multi-dimensional index field; the buffer queue is a temporary storage structure dynamically constructed based on the shard metadata index table, and the shard temporary storage management is realized by recording the shard arrival time sequence and matching the original shard sequence relationship, and the acquisition process of the buffer queue is as follows: the shard metadata index table is analyzed for the actual arrival time sequence of the shard, and the physical storage position of the shard in the queue is dynamically adjusted, when the missing or out-of-order shard is detected, the multi-level sorting algorithm is automatically triggered to rearrange the logical position of the shard, and when the shard is complete and in order, the buffer queue is determined according to the physical storage position of the shard in the current queue; the sequence corresponding relationship is a shard position mapping rule formed by dynamically matching the shard arrival time sequence and the shard metadata index table, and the acquisition process of the sequence corresponding relationship is as follows: first, an original shard logical sequence template is established according to the sequence number field in the shard metadata index table, then the actual arrival time stamp and path transmission delay features of the shard in the buffer queue are analyzed, and the physical position offset of the shard in the recombined sequence is dynamically corrected, and finally the sequence corresponding relationship that can accurately reflect the original order and current transmission state of the shard is formed, which is used to guide the intelligent recombination and integrity check of the multi-level sorting algorithm for out-of-order shards.
[0099] In step S15, the sequence corresponding relationship is checked for integrity by a hash matching mechanism, and complete transmission data is generated.
[0100] In one implementation, the sequence corresponding relationship is checked for integrity by a hash matching mechanism, and complete transmission data is generated, including:
[0101] According to the sequence corresponding relationship, the shard identifier is checked for integrity in combination with a preset hash verification rule, when the missing or identifier mismatch is detected, the multi-level sorting algorithm is used to recombine the logical order of the shard based on the shard metadata index table, and the intermediate recombined data conforming to the original shard data structure is obtained; according to the intermediate recombined data, the sequence corresponding relationship and the shard metadata index table, the check completion algorithm is used to perform shard boundary check and overall hash value comparison, detect data integrity and insert the intermediate recombined data for completion, and generate complete transmission data.
[0102] It should be noted that the logical sequence reorganization when detecting the missing fragments or identifier mismatch is an intelligent repair mechanism realized by the identifier, sequence number and hash value features recorded in the fragment metadata index table. According to the original fragment logical sequence template pre-stored in the fragment metadata index table, a multi-level sorting algorithm is used to dynamically sort the received fragments in sequence according to the fragment sequence priority, path transmission delay compensation value and adjacent fragment correlation degree three dimensions. The logical position offset of the fragment in the reorganization sequence is dynamically corrected by calculating the time deviation of the fragment arrival and the path transmission stability parameter. At the same time, the hash value features stored in the fragment metadata index table are used to mark and isolate the abnormal fragments. Finally, the intermediate reorganization data consistent with the original fragment data structure is generated, which provides the correct fragment sequence benchmark and integrity verification basis for subsequent verification and completion. The complete transmission data is the final available data reconstructed by the hash matching verification and verification completion mechanism. The acquisition process of the complete transmission data is as follows: first, the hash value comparison and identifier verification of the fragments in the buffer queue are performed. After removing the abnormal fragments, the fragment logical sequence is restored according to the metadata index table. Then, the edge data damage caused by network jitter is repaired through the boundary verification algorithm. Finally, the consistency of the reorganized intermediate data and the original overall hash value is verified to ensure that the reorganized data and the source data are completely matched in content integrity and structural consistency, and the complete transmission data is obtained.
[0103] In step S16, according to the real-time threat intelligence data and the real-time transmission performance parameters, attack features are extracted and analyzed, and anti-attack optimization is performed to obtain a virtual node layout and a link connection strategy.
[0104] In an implementation manner, according to the real-time threat intelligence data and the real-time transmission performance parameters, attack features are extracted and analyzed, and anti-attack optimization is performed to obtain a virtual node layout and a link connection strategy, including:
[0105] According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack source, attack type and attack target is obtained through multi-dimensional feature correlation analysis. According to the three-dimensional attack feature set, a dynamic weight distribution algorithm is used to analyze the threat probability distribution of different attack paths in real time to obtain an attack behavior analysis report. According to the attack behavior analysis report and the real-time transmission performance parameters, the mapping relationship between the false node deployment density and the link connection strength is analyzed to obtain a false network topology generation model. According to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameters, analysis is performed based on a preset network topology concealment evaluation rule to obtain the traffic feature similarity between the false nodes and the real nodes. According to the traffic feature similarity, anti-attack optimization is performed in combination with a preset link confusion index to obtain a virtual node layout and a link connection strategy.
[0106] It should be noted that the real-time analysis of the threat probability distribution of different attack paths by using the dynamic weight allocation algorithm is a threat quantitative evaluation process realized by the dynamic association of the three-dimensional attack feature set and the real-time transmission performance parameters. The dynamic weight coefficients are set according to the regional distribution density of the attack source, the damage level of the attack type and the sensitivity of the attack target. The comprehensive threat value of each attack path is calculated in combination with the real-time transmission delay and packet loss rate data of the network path. The threat probability heat map is generated by trend prediction of attack frequency and intensity through the sliding time window mechanism. Finally, the attack behavior analysis report containing attack path features, threat evolution trend and defense priority suggestion is formed, which provides a quantitative basis for defense strategy formulation of the false network topology generation model. The false network topology generation model is a dynamic defense strategy generation framework constructed by correlating and analyzing the three-dimensional attack feature set and the real-time transmission performance parameters. According to the threat probability distribution law revealed by the attack behavior analysis report, in combination with the quantitative relationship between the false node deployment density and the link connection strength, the risk level of different regions under attack is calculated, and then a network structure configuration scheme with deception is automatically generated. The virtual node layout and the link connection strategy are executable deployment schemes optimized according to the topology concealment evaluation rules and the link confusion index. The acquisition process of the virtual node layout and the link connection strategy is as follows: first, analyze the traffic feature similarity of the false nodes and the real nodes to determine the node camouflage effect, then evaluate the misleading ability of the false link to the attacker through the link confusion index, and finally dynamically adjust the node distribution density and the link connection strength ratio in combination with the real-time network load state, to form the virtual node layout and the link connection strategy which can effectively hide the real network topology structure and maintain normal data transmission efficiency. When an attack occurs, decoy nodes are quickly deployed and high-simulation communication links are constructed to divert attack traffic.
[0107] In step S17, according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a global link quality analysis is performed by using federated learning technology to obtain a transmission link quality score.
[0108] In an implementation manner, according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a global link quality analysis is performed by using federated learning technology to obtain a transmission link quality score, including:
[0109] According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, a differential privacy technology is used to protect the inter-node data interaction, the data is divided to each edge node for local model training, and a distributed evaluation framework based on federated learning is obtained; according to the distributed evaluation framework and the real-time transmission performance parameters, a dynamic trust score model is established, the historical transmission success rate and the real-time transmission performance parameters are analyzed, and an initial dynamic trust score is obtained; according to the distributed evaluation framework, a federated aggregation algorithm is used to weight and fuse the local model parameters of each edge node, the node trust score weight coefficient is periodically updated, and a real-time updated global link quality evaluation model is obtained; the initial dynamic trust score and the real-time transmission performance parameters are input into the global link quality evaluation model, multi-dimensional score calculation is performed, and a transmission link quality score is obtained.
[0110] It should be noted that the distributed evaluation framework is an edge node cooperative computing system constructed by federated learning technology, adopts differential privacy technology to desensitize the link state data exchanged between nodes, and divides the local data set to each edge node for distributed model training, forming a cooperative architecture considering data privacy and global evaluation capability; The differential privacy technology used in the construction process of the distributed evaluation framework is a computing method for realizing privacy protection by adding controllable noise to data or model parameters, applied to the local model training stage of the edge node, through noise disturbance to the gradient information and statistical characteristics interacted between nodes, to ensure that the transmission performance data of a single node cannot be inversely deduced, while maintaining the effectiveness of global model training; The initial dynamic trust score is a node reliability estimate value generated based on historical transmission success rate, delay stability and real-time performance fluctuation characteristics, by analyzing the transmission behavior law and abnormal event frequency of the node within a certain time window, and dynamically updating the score weight combined with the sliding window mechanism; The transmission link quality score is the comprehensive evaluation result output by the global link quality evaluation model after fusion calculation of multi-dimensional network parameters, used to guide the dynamic optimization of encrypted fragmented transmission path and real-time adjustment of virtual topology defense strategy; The federated aggregation algorithm used in the process of obtaining the transmission link quality score is a core mechanism for integrating distributed node model parameters in the federated learning framework, which fuses the local model parameters trained by each edge node through weighted average method, and the weight value is dynamically adjusted according to the dynamic trust score and historical evaluation accuracy of the node, in the link quality evaluation scene of the application, the federated aggregation algorithm periodically collects the local model output of each node based on differential privacy protection, generates a global consensus model by calculating the spatial similarity and contribution index of model parameters, so that each edge node can participate in model training by using local real-time transmission data, and also can obtain link quality evaluation capability beyond local data limitations through the aggregated global model, finally through iterative optimization to obtain transmission link quality score which accurately reflects the state of the whole network and does not leak node privacy.
[0111] In one specific embodiment, differential privacy technology achieves privacy protection in the federated learning framework by injecting controllable noise into the edge node local model training process, which is manifested in that each edge node adds random perturbation to the transmission delay feature distribution and packet loss rate statistical value when calculating the gradient information required for link quality assessment, so that the attacker cannot restore the original transmission performance parameters through reverse engineering, while maintaining the effectiveness of gradient update. For example, when a certain edge node calculates the mean value of the delay features of the local model, it will first add noise that meets the differential privacy requirements to the original delay data before calculating the mean value, ensuring that the output model parameters cannot be associated with the sensitive data of a specific node. The federated aggregation algorithm is responsible for effectively integrating the local models processed by each node, and its working principle is that the central server periodically collects the noise-based model parameters uploaded by each node, dynamically allocates aggregation weights according to the historical assessment accuracy and real-time trust score of the nodes. For example, when the transmission success rate of a certain node is consistently high in the near future and the trust score is stable, its model parameters will have a higher weight proportion in global aggregation. This dynamic weighting mechanism reflects the contribution differences of nodes and avoids interference from low-quality nodes to the global model training results. Finally, through multiple iterations, a global link quality assessment model is generated that can reflect the link state characteristics of the entire network and cannot trace the data details of a single node.
[0112] In step S18, the encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameters need to be dynamically adjusted according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0113] In one implementation, dynamically adjusting the encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data includes:
[0114] According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the threat intelligence change rate and network load fluctuation feature analysis is performed, a multi-dimensional optimization space containing security level, transmission efficiency and topology concealment index is constructed, an evolutionary algorithm is used to iteratively solve the balance point of security and transmission efficiency according to the multi-dimensional optimization space, and the encryption algorithm switching frequency and path selection priority coefficient are obtained. According to the link connection strategy, the real-time changes of false network topology adjustment are analyzed, a virtual node configuration dynamic response mechanism is established, and the resource allocation strategy is obtained by optimizing the inverse relationship between node deployment density and link connection strength. According to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, the strategy matching verification is performed to obtain real-time transmission data.
[0115] It should be noted that the construction of the multi-dimensional optimization space is to establish a decision analysis framework by fusing the transmission link quality score, the virtual node layout parameter and the complete transmission data characteristics, to dynamically calculate the correlation between the security level weight, the transmission efficiency coefficient and the topology concealment index based on the threat intelligence change rate and the network load fluctuation characteristics, to form a three-dimensional parameter space that can be quantitatively evaluated; the iterative solution by using the evolutionary algorithm is to explore the optimal combination of the encryption algorithm switching frequency and the path priority coefficient in the optimization space by simulating the selection, crossover and mutation mechanism in the biological evolution process, to filter out a balanced solution set that meets the lowest tolerance value of the security level and maximizes the transmission efficiency through multi-generation population iteration; the encryption algorithm switching frequency is a policy adjustment period determined by analyzing the dynamic correlation between the security level threshold and the transmission link quality score, and the core reasoning process of the encryption algorithm switching frequency is as follows: based on the balance relationship between the security level weight and the transmission efficiency coefficient in the multi-dimensional optimization space, the influence of different encryption intensity switching intervals on network performance is simulated during the evolutionary algorithm iteration solution, and the best frequency parameter that can meet the real-time threat protection requirements and avoid transmission delay caused by frequent switching is selected; the path selection priority coefficient is a quantitative index obtained by comprehensively calculating the path transmission efficiency, the security level adaptation degree and the topology concealment contribution degree in the multi-dimensional parameter space through the evolutionary algorithm, and the reasoning process of the path selection priority coefficient is as follows: first, the basic priority is calculated according to the historical performance data and the real-time load state of each path, and then the path selection priority coefficient reflecting the comprehensive transmission capacity of the path is obtained by combining the weighting correction of the current virtual node layout on the enhancement effect of path concealment, the path selection priority coefficient directly determines the allocation proportion of the fragmented data on different paths, the high-priority path undertakes the key fragment transmission task, and the low-priority path is used for auxiliary transmission and redundancy backup, which ensures that the optimal path combination is always selected in the dynamic network environment, and realizes the optimal balance between security and efficiency; the virtual node configuration dynamic response mechanism is to analyze the real-time change trend of the node deployment density and the link connection strength in the false topology adjustment decision, to construct a dynamic mapping model of resource allocation proportion and attack defense efficiency, and to automatically adjust the ratio of virtual node resource input and real link protection strength according to the inverse relationship; the real-time transmission data is the final available data stream generated after strategy matching verification, and the acquisition process of the real-time transmission data is as follows: based on the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, the effectiveness and stability of the parameter combination in the real network environment are verified, an optimized transmission scheme that meets the requirements of dynamic adaptation of encryption strength, transmission path load balancing and false topology concealment is formed, and thus the real-time transmission data under the current transmission scheme is obtained.
[0116] For the convenience of understanding the present application, some preferred embodiments of the present application will be described further below.
[0117] The working process of the present application will be described below in a more common scenario. Please refer to Figure 2 , which is Figure 1 the working scenario diagram of the method.
[0118] In the high-frequency order transmission scenario of the securities trading system, the present application realizes the safe transmission and complete reorganization of millisecond-level transaction instructions through the whole-link dynamic collaborative control mechanism. When the transaction terminal initiates a high-frequency transaction instruction involving large funds, real-time threat intelligence data is collected through the threat intelligence collection module deployed on the edge node of the exchange, including abnormal login behavior detection, DDoS attack traffic identification, and malicious code propagation feature analysis. The dynamic encryption module based on real-time threat intelligence immediately starts threat level assessment. When it is detected that the frequency of abnormal login attempts in the same period suddenly increases and the attack source IP presents a regular distribution, the system determines that the current threat level is upgraded to level three, and then automatically selects an asymmetric encryption algorithm from the preset encryption algorithm library to encrypt the transaction instruction data. At this time, the data fragmentation module adopts a differentiated fragmentation strategy according to the sensitive attributes of the transaction instruction (such as the amount threshold, account type), and compresses the size of the core transaction parameter (price, quantity) to 50% of the regular fragment, and embeds the dynamically generated encryption algorithm identifier in the fragment header, ensuring that the encryption method can be accurately identified during subsequent reorganization.
[0119] After completing the fragmentation encryption, the path evaluation module calculates the comprehensive performance score of each path based on the real-time transmission performance parameters of the internal private network of the exchange using a linear regression model. When it is detected that a traditional primary path has a delay exceeding the 5-millisecond threshold due to sudden traffic, the decision tree algorithm immediately promotes the priority of the standby low-delay path to the first place, and distributes the key transaction parameter fragments to the path for transmission through the dynamic programming algorithm. At the same time, the false network topology generation mechanism is triggered synchronously during the fragmentation transmission process. According to the current detected attack features (such as port scanning behavior targeting specific transaction servers), the security protection module dynamically deploys virtual nodes outside the real transaction server cluster, generates decoy nodes with the same response characteristics as real servers, and constructs multiple false communication links, making it difficult for attackers to distinguish the real data transmission path.
[0120] When the encrypted fragmented data arrives at the receiving end through the optimized transmission path, the data reorganization module starts the multi-level check mechanism. First, according to the hash identifier embedded in the fragment header, the integrity is verified, and by comparing the hash value of the fragment data with the pre-stored value in the metadata index table, the fragment damaged due to network jitter is quickly identified. For the detected abnormal fragments, the fragment retransmission request is initiated through the backup path, and at the same time, the timestamp information of the received fragments in the buffer queue is used to perform logical reorganization on the out-of-order fragments using a multi-level sorting algorithm. When the core transaction parameter fragments produce a small delay due to path switching, the reorganization algorithm performs intelligent interpolation based on the logical correlation between fragments to ensure that data reorganization is completed within the specified time window without affecting transaction timeliness.
[0121] During the whole data transmission process, the federated learning evaluation network continues to play a role. The local evaluation model deployed on the edge nodes of various exchanges regularly collects link quality data (including delay fluctuation, packet loss event frequency) in the local region, and after desensitization processing of sensitive data through differential privacy technology, uploads the model parameters to the central aggregation server. The federated aggregation algorithm dynamically adjusts the weight coefficient according to the historical evaluation accuracy of each node to generate a global link quality evaluation model. When a certain edge node continuously detects that the packet loss rate of a specific path abnormally rises, the dynamic trust score model immediately reduces the trust level of the path, and adjusts the layout strategy of the virtual node and link in real time, and obtains the virtual node layout and link connection strategy.
[0122] Finally, by integrating link quality scores, virtual topology concealment indicators, and data reorganization success rates, a multi-dimensional decision optimization space is constructed. An improved genetic algorithm is used to dynamically optimize key parameters such as encryption algorithm switching frequency, path selection weight coefficient, and virtual node update period. When detecting a high-frequency trading period with network load surging, the encryption strength of non-critical data is automatically reduced to improve transmission efficiency, while the deployment density of virtual nodes is increased to strengthen security protection. This dynamic balance mechanism enables the system to complete the entire emergency response of encryption strategy switching, path reselection, and false topology reconstruction within 30 milliseconds when encountering sudden network attacks, ensuring that transaction instructions can maintain end-to-end delay stability within 8 milliseconds and data integrity security standards in extreme network environments.
[0123] The whole workflow forms a complete control closed loop, from threat perception driving encryption policy adjustment, to path optimization guaranteeing transmission timeliness, to data verification ensuring information integrity, and finally to global state perception and parameter self-optimization through federated learning. The inherent contradiction between security protection and transmission efficiency in the securities trading scenario is effectively solved. When an APT attack occurs against the trading system, the system can successfully mislead the attack traffic through dynamically increased false nodes, while ensuring the transmission of real transaction data unaffected. When a main trunk line is interrupted due to physical failure, the path evaluation model can switch the traffic to the standby line within 5 milliseconds, and adjust the shard size through an adaptive sharding strategy to adapt to the new network carrying capacity, ensuring the continuous transmission of critical transaction instructions. This dynamic computer network security data transmission method enables the securities trading system to maintain stable operation of the financial market in the face of complex network attacks and sudden network failures.
[0124] In summary, the computer network security data transmission method disclosed in the present application comprises the following steps: obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted; performing dynamic encryption algorithm switching based on the real-time threat intelligence data; performing sharding and encryption processing on the data to be transmitted to obtain encrypted sharding data; inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; according to the path performance score, combining a preset screening threshold, and using a decision tree algorithm to prioritize the paths that meet the threshold condition to obtain a transmission path set; according to the encrypted sharding data and the transmission path set, constructing a sharding metadata index table and performing sharding arrival time sequence analysis to establish a buffer queue and match the sequence corresponding relationship of the received sharding and the original sharding; according to the sequence corresponding relationship, performing integrity verification on the sequence corresponding relationship through a hash matching mechanism to generate complete transmission data; according to the real-time threat intelligence data and the real-time transmission performance parameters, extracting and analyzing attack features to perform anti-attack optimization to obtain a virtual node layout and a link connection strategy; according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, using federated learning technology to perform global link quality analysis to obtain a transmission link quality score; according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, dynamically adjusting the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters to obtain real-time transmission data.
[0125] The application responds to threat intelligence changes in real time through a dynamic encryption algorithm switching mechanism, dynamically optimizes transmission path selection in combination with a path performance evaluation model based on linear regression and decision tree algorithms, uses hash identification and buffer queue to realize integrity verification and sequential reorganization of fragmented data, and constructs a distributed link quality evaluation network to accurately perceive transmission status through federated learning technology, dynamically generates false network topology based on attack feature analysis to enhance defense capability, and finally adjusts the encryption strength, path selection and topology concealment through the adaptive parameter adjustment mechanism of the multi-dimensional optimization space, so that the fragmented encryption processing, multi-path collaborative transmission and data integrity protection form a closed-loop control, realizing millisecond-level response of encryption strategy switching and transmission path optimization in a dynamic threat environment, and ensuring the complete and orderly reorganization of fragmented data under network path performance fluctuations and attack interference. Therefore, the application realizes real-time and complete computer network security data transmission.
[0126] Reference Figure 2 The second embodiment of the application provides a computer network security data transmission device, comprising:
[0127] A data acquisition module is configured to acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, perform dynamic encryption algorithm switching based on the real-time threat intelligence data, perform fragmented encryption processing on the data to be transmitted, and obtain encrypted fragmented data.
[0128] A path evaluation module is configured to input the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score.
[0129] An ordering collection module is configured to perform priority ordering on paths meeting threshold conditions by using a decision tree algorithm based on the path performance score and a preset filtering threshold, and obtain a transmission path set.
[0130] A time sequence analysis module is configured to construct a fragmented metadata index table and perform fragmented arrival time sequence analysis based on the encrypted fragmented data and the transmission path set, and establish a buffer queue to match a sequence corresponding relationship between received fragments and original fragments.
[0131] A data reorganization module is configured to perform integrity verification on fragmented identifiers of the sequence corresponding relationship by using a hash matching mechanism, and generate complete transmission data.
[0132] A virtual layout module is configured to extract and analyze attack features based on the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain a virtual node layout and a link connection strategy.
[0133] a link analysis module, configured to perform global link quality analysis by using a federated learning technique according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, and obtain a transmission link quality score;
[0134] a result output module, configured to dynamically adjust an encryption algorithm switching frequency, a transmission path selection strategy and a virtual node configuration parameter according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, and obtain real-time transmission data.
[0135] It should be noted that the computer network security data transmission device provided by the embodiment of the present application is used to execute all process steps of the computer network security data transmission method provided by the above-mentioned embodiment, and the working principles and beneficial effects of the two are one-to-one correspondence, thus not being described in detail.
[0136] The embodiment of the present application further provides an electronic device. The electronic device comprises a processor, a memory and a computer program, such as a computer network security data transmission program, stored in the memory and executable on the processor. The processor implements the steps in each of the above computer network security data transmission method embodiments when executing the computer program, for example Figure 1 the step S11 shown. Alternatively, the processor implements the functions of each module / unit in each of the above device embodiments when executing the computer program, for example a virtual layout module.
[0137] For example, the computer program can be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the electronic device.
[0138] The electronic device can be a desktop computer, a notebook, a palm computer and a smart tablet computer, etc. The electronic device can include, but is not limited to, a processor, a memory. Those skilled in the art can understand that the above components are only examples of the electronic device, and do not constitute a limitation on the electronic device, and can include more or fewer components than the above, or combine certain components, or different components, for example, the electronic device can also include an input / output device, a network access device, a bus, etc.
[0139] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The processor is a control center of the electronic device, and connects various parts of the electronic device through various interfaces and lines.
[0140] The memory can be used to store the computer program and / or modules, and the processor realizes various functions of the electronic device by running or executing the computer program and / or modules stored in the memory, and calling data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc.; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a nonvolatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory device.
[0141] The modules / units integrated in the electronic device, if realized in the form of software function units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can implement the steps of each method embodiment when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate forms, etc. The computer readable medium can include any entity or device, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. that can carry the computer program code. It should be noted that the contents included in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0142] It should be noted that the above-described device embodiments are only schematic, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the connection relationship between the modules in the device embodiment provided by the present application indicates that there is a communication connection between them, which can be realized as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.
[0143] The above-described specific embodiments further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above-described specific embodiments are only for the specific embodiments of the present application and are not used to limit the protection scope of the present application. It is particularly pointed out that any modification, equivalent replacement, improvement, etc. made by those skilled in the art within the spirit and principles of the present application should be included in the protection scope of the present application.
Claims
1. A computer network security data transmission method, characterized by, The method comprises the following steps: obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, performing dynamic encryption algorithm switching based on the real-time threat intelligence data, performing fragmentation encryption processing on the data to be transmitted to obtain encrypted fragmented data; inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; according to the path performance score, combining a preset screening threshold, and using a decision tree algorithm to prioritize paths that meet the threshold condition to obtain a transmission path set; according to the encrypted fragmented data and the transmission path set, constructing a fragmented metadata index table and performing fragmented arrival time sequence analysis to establish a buffer queue and match the sequence correspondence relationship between the received fragments and the original fragments; performing integrity checking on the sequence correspondence relationship by a hash matching mechanism to generate complete transmission data; according to the real-time threat intelligence data and the real-time transmission performance parameters, extracting and analyzing attack features, performing anti-attack optimization, obtaining a virtual node layout and a link connection strategy; according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, using federated learning technology to perform global link quality analysis to obtain a transmission link quality score; according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, dynamically adjusting the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters to obtain real-time transmission data.
2. The computer network security data transmission method of claim 1, wherein, The method comprises the following steps: obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, performing dynamic encryption algorithm switching based on the real-time threat intelligence data, performing fragmentation encryption processing on the data to be transmitted to obtain encrypted fragmented data, comprising: obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters of multiple network paths and data to be transmitted; the real-time transmission performance parameters include real-time transmission speed, real-time traffic characteristics and transmission stability data of multiple network paths; according to the real-time threat intelligence data, using time series analysis to predict dynamic trend prediction, calculating the threat level change amplitude and dividing the security level interval to obtain a dynamic security level evaluation parameter; according to the dynamic security level evaluation parameter, combining a preset encryption algorithm library, performing dynamic matching of encryption algorithm types to obtain an encryption algorithm dynamic selection model; according to the encryption algorithm dynamic selection model and the dynamic security level evaluation parameter, using an adaptive fragmentation strategy to perform fragmentation processing on the data to be transmitted, adjusting the fragmentation size based on the preset data sensitivity to obtain initial fragmented data; 3. The computer network security data transmission method of claim 1, wherein, according to the initial fragmented data, performing dynamic encryption processing, when detecting that the dynamic security level evaluation parameter is improved, triggering an encryption algorithm switching mechanism in the fragmentation transmission process, and maintaining the encryption compatibility of the fragments before and after the fragmentation to obtain encrypted fragmented data. The preset path performance evaluation model training process comprises the following steps: obtaining historical real-time transmission performance parameters; Inputting the historical real-time transmission performance parameters into a linear regression model to obtain a historical path performance score; When the number of training times is greater than or equal to the preset number of training times, it is determined that the training is completed, and a trained path performance evaluation model is obtained.
4. The computer network security data transmission method of claim 1, wherein, According to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain a transmission path set, including: According to the path performance score, in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain an initial optimal path set; According to the initial optimal path set, a dynamic programming algorithm is used to allocate real-time transmission tasks, and the arrival time of each fragment is detected to obtain a fragment arrival time difference; According to the fragment arrival time difference and the real-time transmission performance parameters, in combination with the path performance evaluation model, the path performance is re-evaluated and prioritized to obtain a transmission path set.
5. The computer network security data transmission method of claim 1, wherein, According to the encrypted fragment data and the transmission path set, a fragment metadata index table is constructed and fragment arrival time sequence analysis is performed to establish a buffer queue to match the sequence correspondence between the received fragments and the original fragments, including: According to the encrypted fragment data and the transmission path set, a hash algorithm is used to calculate the hash value of the encrypted fragment data, and in combination with the unique identifier and fragment sequence number in the encrypted fragment data, a fragment metadata index table is constructed; According to the fragment metadata index table, fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence between the received fragments and the original fragments.
6. The computer network security data transmission method of claim 1, wherein, The sequence correspondence is verified by a hash matching mechanism to generate complete transmission data, including: According to the sequence correspondence, in combination with a preset hash verification rule, the integrity of the fragment identifier is verified, and when a missing fragment or an unmatched identifier is detected, a multi-level sorting algorithm is used to logically reorder the fragments based on the fragment metadata index table to obtain intermediate reorganized data that conforms to the original fragment data structure; According to the intermediate reorganized data, the sequence correspondence and the fragment metadata index table, a verification completion algorithm is used to perform fragment boundary verification and overall hash value comparison, detect data integrity and insert intermediate reorganized data for completion to generate complete transmission data.
7. The computer network security data transmission method of claim 1, wherein, According to the real-time threat intelligence data and the real-time transmission performance parameters, attack features are extracted and analyzed to optimize anti-attack, obtain a virtual node layout and a link connection strategy, including: According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack source, attack type and attack target is obtained through multi-dimensional feature correlation analysis; According to the three-dimensional attack feature set, a dynamic weight distribution algorithm is used to analyze the threat probability distribution of different attack paths in real time to obtain an attack behavior analysis report; According to the attack behavior analysis report and the real-time transmission performance parameters, the mapping relationship between the false node deployment density and the link connection strength is analyzed to obtain a false network topology generation model; According to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameter, analysis is performed based on a preset network topology concealment evaluation rule to obtain a traffic feature similarity between a false node and a real node; According to the traffic feature similarity, anti-attack optimization is performed in combination with a preset link confusion index to obtain a virtual node layout and a link connection strategy.
8. The computer network security data transmission method of claim 1, wherein, According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, global link quality analysis is performed by using a federated learning technology to obtain a transmission link quality score, including: According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, differential privacy technology is used to protect inter-node data interaction, and data is divided to each edge node for local model training to obtain a distributed evaluation framework based on federated learning; According to the distributed evaluation framework and the real-time transmission performance parameter, a dynamic trust score model is established, historical transmission success rates and the real-time transmission performance parameter are analyzed to obtain an initial dynamic trust score; According to the distributed evaluation framework, federated aggregation algorithm is used to perform weighted fusion on local model parameters of each edge node, and node trust score weight coefficients are periodically updated to obtain a real-time updated global link quality evaluation model; The initial dynamic trust score and the real-time transmission performance parameter are input into the global link quality evaluation model for multi-dimensional score calculation to obtain a transmission link quality score.
9. The computer network security data transmission method of claim 1, wherein, According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, dynamic adjustment is performed on an encryption algorithm switching frequency, a transmission path selection strategy and a virtual node configuration parameter to obtain real-time transmission data, including: According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, threat intelligence change rate and network load fluctuation feature analysis is performed to construct a multi-dimensional optimization space including security level, transmission efficiency and topology concealment index; According to the multi-dimensional optimization space, an evolutionary algorithm is used for iterative solution to analyze a balance point of security and transmission efficiency to obtain an encryption algorithm switching frequency and a path selection priority coefficient; According to the link connection strategy, real-time changes of false network topology adjustment are analyzed to establish a virtual node configuration dynamic response mechanism, and optimization is performed through an inverse relationship between node deployment density and link connection strength to obtain a resource allocation strategy; According to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, strategy matching verification is performed to obtain real-time transmission data.
10. A computer network security data transmission apparatus, characterized by comprising: including: A data acquisition module is configured to acquire real-time threat intelligence data, a real-time packet loss rate, a real-time end-to-end delay, a real-time transmission performance parameter and to-be-transmitted data, perform dynamic encryption algorithm switching based on the real-time threat intelligence data, and perform fragmented encryption processing on the to-be-transmitted data to obtain encrypted fragmented data; A path evaluation module is configured to input the real-time transmission performance parameter into a preset path performance evaluation model to obtain a path performance score; The sorting set module is configured to sort paths meeting threshold conditions in priority according to the path performance score in combination with a preset screening threshold by using a decision tree algorithm, to obtain a transmission path set; The time sequence analysis module is configured to construct a fragment metadata index table and perform fragment arrival time sequence analysis according to the encrypted fragment data and the transmission path set, to establish a buffer queue and thus match a sequence corresponding relationship between received fragments and original fragments; The data recombination module is configured to perform integrity check on a fragment identifier in the sequence corresponding relationship by using a hash matching mechanism, to generate complete transmission data; The virtual layout module is configured to extract and analyze attack features according to the real-time threat intelligence data and the real-time transmission performance parameter, to perform anti-attack optimization, to obtain a virtual node layout and a link connection strategy; The link analysis module is configured to perform global link quality analysis by using a federated learning technology according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, to obtain a transmission link quality score; The result output module is configured to dynamically adjust an encryption algorithm switching frequency, a transmission path selection strategy and a virtual node configuration parameter according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, to obtain real-time transmission data.
Citation Information
Patent Citations
Data transmission and link switching method, electronic equipment and readable storage medium
CN115460662A
Encryption optimization method for data communication
CN118944952A