A method, system and electronic device for identifying satellite Internet threats

Through blockchain and machine learning technology, the node reputation evaluation model and adaptive security strategy of the satellite Internet are built, the data transmission path is optimized, and the links are quickly identified and switched, which solves the real-time and accuracy of threat identification and protection in the satellite Internet, and improves the security and stability of the satellite network.

CN119922026BActive Publication Date: 2025-07-04GOLDEN SHIELD TESTING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510423567.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-04
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

It is difficult for the existing technology to achieve real-time and accurate threat identification and security protection in the satellite Internet, especially in the environment of high latency, dynamic link changes and resource constraints, traditional security protocols are difficult to effectively deal with the risks of inter-satellite link eavesdropping, hijacking and interference.

Method used

The node reputation evaluation model is built through blockchain technology, combined with machine learning algorithms to monitor the topology changes of satellite networks in real time, generate adaptive security strategies, and use hybrid integer linear planning algorithm to optimize data transmission paths, build inter-star link fast switching model and data exception identification model to achieve rapid response and defense against satellite network threats.

Benefits of technology

It realizes full-time dynamic monitoring and intelligent evaluation of satellite network links, improves the response speed and anti-interference ability of abnormal conditions, ensures the security and continuity of data transmission, and enhances the robustness and self-restoration capabilities of satellite Internet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922026B_ABST
    Figure CN119922026B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and specifically to a satellite Internet threat identification method, system, and electronic device. A node reputation evaluation model is constructed through blockchain technology to obtain trusted nodes, and a satellite network is constructed to collect inter-satellite link information in real time; the topology change of the satellite network is obtained in real time, an inter-satellite link security evaluation model is constructed, and an adaptive security policy matching the inter-satellite link security level is generated; through a mixed-integer linear programming algorithm, the data transmission path is dynamically calculated and optimized; an inter-satellite link fast switching model is constructed to analyze the inter-satellite link information, generate inter-satellite link anomaly information, and quickly switch to a standby inter-satellite link according to the adaptive security policy and network topology information; data transmission is carried out according to the inter-satellite link, and the transmission behavior data is monitored and obtained; a data anomaly identification model is constructed to analyze the transmission behavior to obtain a data anomaly response; and the satellite network threat is identified according to the data anomaly response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method, system and electronic device for identifying satellite Internet threats. Background Art

[0002] With the rapid popularization of the global Internet and the development of the information society, satellite Internet has become an important part of connecting the world, covering remote areas and ensuring the communication security of key fields. However, due to the unique characteristics of satellite Internet systems, such as high latency, dynamic link changes, and resource constraints, traditional security protection protocols based on terrestrial networks are difficult to directly apply, exposing many security risks in data transmission and threat identification. Especially in the field of network security protocols, existing technologies mainly focus on encryption, authentication, and data integrity protection in fixed network environments, and there is no perfect technical system for distributed data transmission and collaborative defense through inter-satellite links in satellite Internet.

[0003] In satellite Internet, high-speed data transmission and information sharing are achieved between satellites through inter-satellite links (ISL), which provides the possibility for building a distributed real-time situation awareness system. By using inter-satellite links, not only can secure data transmission between nodes be realized, but also through cross-satellite data fusion, network anomalies, interference attacks, and other security threats can be collaboratively monitored and analyzed. However, since inter-satellite links themselves may also face risks such as eavesdropping, hijacking, and interference, how to design a network security protocol that can ensure data transmission security and achieve real-time threat detection under limited computing and energy consumption resources has become a key technical problem to be solved urgently.

[0004] Therefore, by using inter-satellite links to achieve real-time collection of threat data, distributed data fusion, and collaborative analysis in satellite Internet, and under the limited resources of satellite platforms, a lightweight network security protocol is used to encrypt and authenticate data, so as to achieve rapid, accurate identification and active defense against network threats.

[0005] For this reason, a method, system and electronic device for identifying satellite Internet threats are proposed. Summary of the Invention

[0006] The purpose of the present invention is to provide a satellite Internet threat identification method, system and electronic device, which constructs a node reputation evaluation model through blockchain technology to obtain trusted nodes, constructs a satellite network, and collects inter-satellite link information in real time; obtains the changes in the satellite network topology in real time, constructs an inter-satellite link security evaluation model, and generates an adaptive security policy matching the inter-satellite link security level; dynamically calculates and optimizes the data transmission path through a mixed-integer linear programming algorithm; constructs an inter-satellite link fast switching model to analyze the inter-satellite link information, generates inter-satellite link anomaly information, and quickly switches to a backup inter-satellite link according to the adaptive security policy and network topology information; performs data transmission based on the inter-satellite link, monitors and obtains transmission behavior data; constructs a data anomaly identification model to analyze the transmission behavior and obtains a data anomaly response; and identifies satellite network threats based on the data anomaly response.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A satellite Internet threat identification method includes establishing a node authentication system based on a distributed public key infrastructure, constructing a node reputation evaluation model through blockchain technology to obtain trusted nodes; constructing a satellite network based on the trusted nodes and collecting inter-satellite link information in real time; obtaining the changes in the satellite network topology in real time based on a machine learning algorithm, constructing an inter-satellite link security evaluation model, and generating an adaptive security policy matching the inter-satellite link security level; dynamically calculating and optimizing the data transmission path through a mixed-integer linear programming algorithm based on the adaptive security policy and network topology information; constructing an inter-satellite link fast switching model to analyze the inter-satellite link information, generating inter-satellite link anomaly information, and quickly switching to a backup inter-satellite link according to the adaptive security policy and network topology information; performing data transmission based on the inter-satellite link, monitoring and obtaining transmission behavior data; constructing a data anomaly identification model to analyze the transmission behavior and obtaining a data anomaly response; and identifying and processing satellite network threats based on the data anomaly response.

[0009] Preferably, the trusted node is a satellite node with a reputation score exceeding a preset threshold in the blockchain reputation evaluation model;

[0010] The construction of the satellite network includes the following steps: constructing a three-dimensional inter-satellite topology structure based on the node geographical locations; dynamically selecting trusted nodes according to the node reputation scores; and establishing an initial security link based on the trusted nodes.

[0011] The inter-satellite link information is collected in real time by an on-board multi-mode sensor array, including carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, routing hop count, bit error rate, signal attenuation exponent, node relative motion vector, space radiation intensity, and link encryption status.

[0012] Preferably, the step of obtaining satellite network topology changes is as follows:

[0013] The machine learning algorithm uses a spatio-temporal graph convolutional neural network model. The input layer receives the inter-satellite link information of the satellite network. The hidden layer contains long short-term memory modules to process time series features and analyze the input data. The output layer generates a topological dynamic probability map. Node disappearance and node addition events are detected through an adaptive sliding window mechanism, and the inter-satellite link information is updated in real time.

[0014] Preferably, the inter-satellite link security assessment model includes a data collection layer, a feature extraction layer, an evaluation calculation layer, and a policy generation layer;

[0015] The data collection layer obtains the carrier-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, bit error rate, and link encryption status in the inter-satellite link information in real time. The feature extraction layer reduces the dimensions of multi-dimensional parameters by using a deep autoencoder to generate a composite security feature vector. The evaluation calculation layer performs weighted calculation on the composite security feature vector through a fuzzy comprehensive evaluation algorithm to generate a standardized security score. The policy generation layer adaptively adjusts the security policy of the inter-satellite link according to the security score.

[0016] Preferably, the step of dynamically calculating and optimizing the data transmission path includes:

[0017] Taking the inter-satellite link information as input parameters according to the adaptive security policy and the topology information of the satellite network. Using a mixed integer linear programming algorithm, constructing an optimization target of minimizing transmission delay, path risk value, and energy consumption, and calculating the optimal data transmission path with link bandwidth, delay, and load capacity as constraints. Combining with the adaptive security policy, dynamically adjusting the path selection to ensure that the optimization of the data transmission path matches the security requirements under different link security levels. Verifying the calculated data transmission path according to the inter-satellite link information obtained in real time.

[0018] Preferably, the inter-satellite link fast switching model includes a data analysis layer, an anomaly recognition layer, a switching decision layer, and an output layer. The data analysis layer processes the inter-satellite link information by using a machine learning algorithm to identify potential link anomaly behaviors. The anomaly recognition layer analyzes the link anomaly behaviors to generate inter-satellite link anomaly information, which includes link performance degradation, link loss, and sudden interference. The switching decision layer generates a switching decision according to the results of real-time analysis, evaluates the reliability and security of the link, and combines the status of the backup link to quickly switch the data stream to the backup inter-satellite link. The output layer confirms the status of the switched link to ensure the smooth transmission of the data stream.

[0019] Preferably, the data anomaly recognition model includes a first input layer, a second feature extraction layer, an anomaly detection layer, and a response decision layer:

[0020] The first input layer obtains transmission behavior data, which includes the transmission time, data size, transmission delay, throughput, and link quality information of data packets; the second feature extraction layer extracts features from the transmission behavior data to generate a transmission behavior feature vector; the anomaly detection layer analyzes the transmission behavior feature vector to identify abnormal transmission behaviors and generate anomaly detection results, which include attacks, data tampering, and transmission failures; the response decision layer generates corresponding data anomaly responses according to the anomaly detection results.

[0021] A satellite Internet threat recognition system includes: a satellite network construction module that establishes a node authentication system based on a distributed public key infrastructure and constructs a node reputation evaluation model through blockchain technology to obtain trusted nodes; constructs a satellite network based on the trusted nodes and collects inter-satellite link information in real time; a security policy generation module that obtains real-time changes in the satellite network topology based on a machine learning algorithm, constructs an inter-satellite link security evaluation model, and generates an adaptive security policy matching the inter-satellite link security level; a data transmission path acquisition module that dynamically calculates and optimizes the data transmission path based on the adaptive security policy and network topology information through a mixed integer linear programming algorithm; a link fast switching module that constructs an inter-satellite link fast switching model to analyze the inter-satellite link information, generates inter-satellite link anomaly information, and quickly switches to a standby inter-satellite link according to the adaptive security policy and network topology information; an anomaly recognition module that monitors and obtains transmission behavior data according to the inter-satellite link; constructs a data anomaly recognition model to analyze the transmission behavior and obtains a data anomaly response; and identifies and processes satellite Internet threats according to the data anomaly response.

[0022] A satellite Internet threat recognition electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the described satellite Internet threat recognition method.

[0023] Compared with the prior art, the beneficial effects of the present invention are:

[0024] 1. The present invention realizes full-time dynamic monitoring and intelligent evaluation of satellite network links. By using an on-board multi-mode sensor array, key link parameters such as carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, bit error rate, signal attenuation exponent, etc. are collected in real time, and data dimensionality reduction and feature extraction techniques are adopted to construct a comprehensive security feature vector. The link state is quantified through a fuzzy comprehensive evaluation algorithm to timely identify potential anomalies, interference or fault risks, and then realize the adaptive regulation and optimization of link performance. This not only improves the response speed of the satellite network to abnormal conditions, but also significantly enhances the overall anti-interference and self-recovery capabilities, providing a solid security guarantee for data transmission.

[0025] 2. The present invention adopts an adaptive security strategy and a mixed integer linear programming algorithm to realize the dynamic calculation and optimization of data transmission paths. According to the real-time topology information and link security levels of the satellite network, the optimization objectives are matched, and while minimizing transmission delay, path risk value and energy consumption, multiple constraint conditions such as bandwidth, delay, and load are satisfied. The transmission path can be flexibly adjusted to ensure efficient transmission at different security levels, greatly improving data transmission quality and network operation efficiency.

[0026] 3. The present invention constructs an inter-satellite link fast switching model and data anomaly identification to realize the monitoring and response to abnormal situations in the satellite network. Through machine learning algorithms, multi-dimensional link information is analyzed in real time to quickly capture abnormal phenomena such as link performance degradation, loss or sudden interference, and automatically switch to a standby link to ensure uninterrupted data transmission. At the same time, the anomaly detection module mines the transmission behavior data to identify attack, tampering and fault hidden dangers, and triggers response measures in real time to build an all-round threat defense system. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 It is a schematic flow chart of a method for identifying threats to a satellite Internet provided by the present invention;

[0028] Figure 2 It is a schematic structural diagram of a system for identifying threats to a satellite Internet provided by the present invention;

[0029] Figure 3 It is a schematic structural diagram of an inter-satellite link security evaluation model provided by an embodiment of the present invention;

[0030] Figure 4 It is a schematic structural diagram of an inter-satellite link fast switching model provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0031] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0032] Embodiment 1

[0033] Please refer to Figure 1 , the present invention provides a method for identifying satellite Internet threats, and the technical solution is as follows:

[0034] Establish a node authentication system based on a distributed public key infrastructure, construct a node reputation evaluation model through blockchain technology, and obtain trusted nodes; construct a satellite network based on the trusted nodes, and collect inter-satellite link information in real time;

[0035] Furthermore, the trusted nodes are satellite nodes whose reputation scores exceed a preset threshold in the blockchain reputation evaluation model;

[0036] The construction of the satellite network includes the following steps: construct a three-dimensional inter-satellite topological structure based on the node geographical locations; dynamically select trusted nodes according to the node reputation scores; establish an initial secure link based on the trusted nodes;

[0037] The inter-satellite link information is collected in real time through an on-board multi-mode sensor array, including carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, routing hop count, bit error rate, signal attenuation exponent, node relative motion vector, space radiation intensity, and link encryption status.

[0038] In this embodiment, by introducing a node reputation evaluation model based on blockchain, the dynamic identification and precise positioning of the security of each node in the satellite network are realized. First, the blockchain technology is used to perform reputation scoring on each satellite node, so that only nodes with a reputation score exceeding a preset threshold can be selected as trusted nodes, thereby fundamentally preventing malicious nodes or forged nodes from entering the network and significantly improving the security level of the entire satellite Internet. Secondly, for the satellite network constructed based on trusted nodes, a three-dimensional inter-satellite topological structure is constructed by combining the node geographical location information, making the network structure more in line with the actual deployment environment and improving the stability and flexibility of network operation. At the same time, a spaceborne multi-mode sensor array is used to collect multi-dimensional information in real time, including carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, routing hop count, bit error rate, signal attenuation index, relative motion vector of nodes, space radiation intensity, and link encryption status, providing comprehensive data support for network security evaluation and risk warning. Thus, link anomalies and potential threats can be detected earlier and more accurately, and security protection measures can be initiated in a timely manner, effectively ensuring the integrity and reliability of data transmission, and comprehensively improving the anti-attack ability and adaptive regulation level of the satellite Internet.

[0039] Based on the machine learning algorithm, the topological changes of the satellite network are obtained in real time, an inter-satellite link security evaluation model is constructed, and an adaptive security policy matching the inter-satellite link security level is generated;

[0040] Further, the step of obtaining the satellite network topological changes is as follows:

[0041] The machine learning algorithm adopts a spatio-temporal graph convolutional neural network model. The input layer receives the inter-satellite link information of the satellite network; the hidden layer contains a long short-term memory module to process time series features and analyze the input data; the output layer generates a topological dynamic probability map; the node disappearance and node addition events are detected through an adaptive sliding window mechanism, and the inter-satellite link information is updated in real time.

[0042] In this embodiment, by introducing real-time topology monitoring technology based on machine learning algorithms, accurate capture of the dynamic changes in the satellite network structure is achieved. Using a spatio-temporal graph convolutional neural network model and combining long short-term memory modules to deeply process link information, it can not only quickly generate a topological dynamic probability graph, but also timely identify key events such as the addition or disappearance of nodes through an adaptive sliding window mechanism, thereby updating the inter-satellite link information in real time. This technology significantly improves the timeliness and accuracy of network security assessment, automatically generates an adaptive security policy that matches the actual security level according to the latest topological changes, and effectively reduces security risks caused by sudden changes in the network structure. In addition, real-time topological dynamic monitoring provides sufficient data support for subsequent security protection measures, greatly improving the response speed and anti-interference ability of the entire satellite network to abnormal events, ensuring the security and stability of the data transmission process, and enhancing the overall robustness and reliability.

[0043] Further, the inter-satellite link security assessment model includes a data acquisition layer, a feature extraction layer, an evaluation calculation layer, and a policy generation layer. Refer to Figure 3 ;

[0044] The data acquisition layer obtains the carrier-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, bit error rate, and link encryption status in the inter-satellite link information in real time; the feature extraction layer reduces the dimensions of multi-dimensional parameters through a deep autoencoder to generate a composite security feature vector; the evaluation calculation layer performs weighted calculation on the composite security feature vector through a fuzzy comprehensive evaluation algorithm to generate a standardized security score; the policy generation layer adaptively adjusts the security policy for the inter-satellite link according to the security score.

[0045] In this embodiment, a multi-level inter-satellite link security assessment model is adopted to achieve comprehensive real-time monitoring and dynamic response to the link status. First, the data acquisition layer can obtain key indicators such as carrier-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, bit error rate, and link encryption status in real time, ensuring the timeliness and accuracy of data in the evaluation process. Secondly, the deep autoencoder is used to reduce the dimensionality of the collected multi-dimensional parameters, effectively extracting and retaining the composite features that have a decisive impact on the security status, reducing data redundancy, and improving the efficiency and accuracy of subsequent processing. Subsequently, the evaluation and calculation layer uses the fuzzy comprehensive evaluation algorithm to perform weighted calculation on the dimensionality-reduced feature vector to generate a standardized security score, providing a quantitative basis for the link security status. Finally, the policy generation layer adaptively adjusts the inter-satellite link security policy according to the security score, enabling the network to quickly respond to environmental changes and potential threats, and ensuring the continuity and security of data transmission. This model greatly improves the security monitoring ability and dynamic regulation level of the satellite network, providing a solid technical guarantee for building an efficient, stable, and anti-interference satellite Internet. In the prior art, threshold detection relies on a single parameter threshold to detect link security, easily ignoring the correlation of multi-dimensional parameters. As shown in Table 1, the present invention reduces the dimensionality of parameters such as carrier-to-noise ratio and bit error rate through a deep autoencoder, generates a composite feature vector, and combines a fuzzy algorithm to quantify the security score, significantly improving the accuracy of link anomaly detection.

[0046] Table 1 Comparison table of the effectiveness of the inter-satellite link security assessment model

[0047] Comparison dimension Threshold detection Deep autoencoder + fuzzy evaluation Effectiveness improvement Feature extraction Single-parameter threshold judgment Multi-dimensional parameter dimensionality reduction and feature fusion False positive rate reduced by 45% Safety score quantification Qualitative grading (high / medium / low) Normalized score (in the range of 0 - 1) Evaluation accuracy improved by 70% Strategy dynamic adjustment Fixed security strategy Adaptive strategy matching security level Response speed increased by 50%

[0048] Through the mixed integer linear programming algorithm, based on the adaptive security policy and network topology information, dynamically calculate and optimize the data transmission path;

[0049] Furthermore, the steps of dynamically calculating and optimizing the data transmission path include:

[0050] Taking the inter-satellite link information as input parameters according to the adaptive security policy and the topology information of the satellite network; adopting the mixed integer linear programming algorithm, constructing an optimization target of minimizing transmission delay, path risk value, and energy consumption, and calculating the optimal data transmission path according to link bandwidth, delay, and load capacity as constraints; combining the adaptive security policy, dynamically adjusting the path selection to ensure that under different link security levels, the optimization of the data transmission path matches the security requirements; verifying the calculated data transmission path according to the real-time obtained inter-satellite link information.

[0051] In this embodiment, the dynamic calculation and optimization of the data transmission path are realized by using the mixed-integer linear programming algorithm. Its beneficial effects are mainly reflected in the following aspects: First, based on the adaptive security policy and satellite network topology information, by collecting the inter-satellite link data in real time, an optimization model aiming to minimize the transmission delay, reduce the path risk value, and decrease the energy consumption is constructed. On the basis of strictly constraining the link bandwidth, delay, and load capacity, the optimal data transmission path is calculated, thus significantly improving the transmission efficiency and resource utilization rate. Second, combined with the adaptive security policy, it can flexibly adjust the path selection under different link security levels to ensure that the data transmission not only meets the high-efficiency requirements but also reaches the security standard. Finally, by verifying the inter-satellite link information obtained in real time, this solution can detect and correct the path optimization deviation in a timely manner, improving the overall network stability, robustness, and anti-interference ability of the satellite Internet, and effectively ensuring the continuity and reliability of data transmission.

[0052] Construct an inter-satellite link fast-switching model to analyze the inter-satellite link information, generate inter-satellite link abnormal information, and quickly switch to the standby inter-satellite link according to the adaptive security policy and network topology information;

[0053] Furthermore, the inter-satellite link fast-switching model includes a data analysis layer, an anomaly recognition layer, a switching decision layer, and an output layer. For details, refer to Figure 4 ; The data analysis layer processes the inter-satellite link information by using machine learning algorithms to identify potential link abnormal behaviors; the anomaly recognition layer generates inter-satellite link abnormal information by analyzing the link abnormal behaviors. The inter-satellite link abnormal information includes link performance degradation, link loss, and sudden interference; the switching decision layer generates a switching decision according to the results of real-time analysis, by evaluating the reliability and security of the link and combining the status of the standby link, and quickly switches the data flow to the standby inter-satellite link; the output layer confirms the link status after switching to ensure the smooth transmission of the data flow.

[0054] In this embodiment, by adopting the inter-satellite link fast-switching model, the satellite link information is monitored and analyzed in real time; through machine learning algorithms, the link abnormal behaviors (such as link performance degradation, loss, or sudden interference) are quickly identified, and the abnormal information is generated. Based on the real-time analysis results and the status of the standby link, the switching decision layer can quickly switch the data flow to the stable standby link to ensure that the transmission is not interrupted. The output layer confirms the status after switching to ensure the stable transmission of the data flow. This solution significantly improves the fault tolerance and anti-interference level of the satellite network, reduces the risk of data transmission delay and interruption caused by link anomalies, and thus enhances the overall security and operation reliability of the satellite Internet.

[0055] Perform data transmission according to the inter-satellite link, monitor and obtain transmission behavior data; construct a data anomaly recognition model to analyze the transmission behavior and obtain a data anomaly response.

[0056] Further, the data anomaly recognition model includes a first input layer, a second feature extraction layer, an anomaly detection layer, and a response decision layer:

[0057] The first input layer obtains transmission behavior data, which includes the transmission time, data size, transmission delay, throughput, and link quality information of data packets; the second feature extraction layer extracts features from the transmission behavior data to generate a transmission behavior feature vector; the anomaly detection layer analyzes the transmission behavior feature vector to identify abnormal transmission behaviors and generate anomaly detection results, where the anomaly detection results include attacks, data tampering, and transmission failures; the response decision layer generates corresponding data anomaly responses according to the anomaly detection results.

[0058] In this embodiment, by constructing a data anomaly recognition model, real-time monitoring and feature extraction are performed on the inter-satellite link transmission behavior data (such as data packet transmission time, data size, transmission delay, throughput, and link quality information) to capture abnormal transmission behaviors. The anomaly detection layer uses feature vector analysis to identify possible problems such as attacks, data tampering, and transmission failures. The response decision layer quickly generates corresponding data anomaly response measures according to the detection results, effectively preventing and mitigating potential risks. This model not only improves the detection sensitivity of abnormal situations but also achieves fast response, ensuring the continuity and security of data transmission, and at the same time providing strong data support for the dynamic adjustment of network security policies.

[0059] Identify and process satellite network threats according to the data anomaly response.

[0060] The present invention comprehensively applies advanced technologies such as blockchain, machine learning, and mixed-integer linear programming to construct an all-round and dynamically regulated satellite Internet threat identification and protection model. First, a blockchain is used to construct a node reputation evaluation model to effectively identify trusted nodes with a reputation exceeding a preset threshold, and a secure satellite network is constructed based on a three-dimensional geographical topology structure. Key link parameters such as carrier-to-noise ratio, Doppler shift, propagation delay, and throughput fluctuation are collected in real time to ensure the authenticity and reliability of network basic data. At the same time, through a spatio-temporal graph convolutional neural network combined with a long short-term memory module, the topological changes of the satellite network are accurately monitored, and an adaptive security policy matching the link security level is automatically generated, effectively reducing the security risks brought by sudden changes in the network structure. The mixed-integer linear programming algorithm is used to optimize the data transmission path to achieve multiple balances of transmission delay, path risk, and energy consumption; when a link anomaly or interference occurs, it can quickly switch to a backup link, and an attack, data tampering, or transmission failure can be promptly responded to through a data anomaly identification model, thereby significantly improving the anti-attack ability, operation stability, and adaptive regulation level of the satellite Internet, and effectively ensuring the continuity and security of data transmission.

[0061] Embodiment 2

[0062] Please refer to Figure 2 , the present invention provides a satellite Internet threat identification method applied to a satellite Internet threat identification system and an electronic device, and the technical solution is as follows:

[0063] A satellite network construction module establishes a node authentication system based on a distributed public key infrastructure, constructs a node reputation evaluation model through blockchain technology, and obtains trusted nodes; constructs a satellite network based on the trusted nodes and collects inter-satellite link information in real time;

[0064] The node authentication system adopts the principle of traditional public key cryptography and combines distributed storage technology to ensure information transparency and immutability. The implementation steps include:

[0065] Each satellite node generates a pair of keys where is the public key, is the private key. The node submits application data including , the unique node identifier and the timestamp to the authentication center;

[0066] The authentication center uses its own private key to digitally sign the node information to form a certificate

[0067] When other nodes receive a communication request, by extracting , and , verify the digital signature using the public key of the certification center to confirm the identity of the node;

[0068] Ensure that all participating nodes pass trusted authentication, prevent malicious nodes from forging identities, and form a trusted foundation.

[0069] The node reputation evaluation model uses blockchain technology to record the historical behaviors of nodes and identifies trusted nodes through quantitative scoring. The implementation steps are as follows:

[0070] Data collection: Collect the behavioral data of nodes in aspects such as data transmission, fault handling, and security events, such as success rate and failure rate ;

[0071] Define the reputation scoring formula as: where represents the proportion of time the node is active in the network, is the success rate weight, is the failure rate weight, is the weight of the proportion of time the node is active in the network;

[0072] When the defined reputation score is greater than or equal to the set reputation score threshold, that is , at this time the node is recognized as a trusted node.

[0073] Furthermore, the trusted node is a satellite node whose reputation score exceeds the preset threshold in the blockchain reputation evaluation model;

[0074] The construction of the satellite network includes the following steps: constructing a three-dimensional inter-satellite topological structure based on the node geographical locations; dynamically selecting trusted nodes according to the node reputation scores; establishing an initial secure link based on the trusted nodes;

[0075] Construct a three-dimensional inter-satellite topological structure using the geographical location information of the nodes and establish a secure link between the trusted nodes. The specific steps are as follows:

[0076] Geographical data collection: Collect the three-dimensional coordinates of each node ;

[0077] Distance calculation: For any two nodes and , calculate the Euclidean distance : Under the condition that the distance (preset distance threshold), connect the nodes and to form a network where is the set of satellite nodes, is the set of inter-satellite links;

[0078] Dynamically select trusted nodes based on node reputation scores and establish an initial secure link among them.

[0079] The inter-satellite link information is collected in real time through an on-board multi-mode sensor array, including carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, routing hop count, bit error rate, signal attenuation exponent, relative motion vector of nodes, space radiation intensity, and link encryption status.

[0080] A security policy generation module, based on a machine learning algorithm, obtains real-time changes in the satellite network topology, constructs an inter-satellite link security evaluation model, and generates an adaptive security policy matching the inter-satellite link security level;

[0081] Further, the step of obtaining changes in the satellite network topology is as follows:

[0082] The machine learning algorithm uses a spatio-temporal graph convolutional neural network model. The input layer receives the inter-satellite link information of the satellite network; the hidden layer contains a long short-term memory module to process time series features and analyze the input data; the output layer generates a topological dynamic probability graph; node disappearance and node addition events are detected through an adaptive sliding window mechanism, and the inter-satellite link information is updated in real time.

[0083] Further, the inter-satellite link security evaluation model includes a data collection layer, a feature extraction layer, an evaluation calculation layer, and a policy generation layer;

[0084] The data collection layer constitutes an original vector by obtaining in real time the carrier signal-to-noise ratio, Doppler frequency shift, link propagation delay, throughput fluctuation, bit error rate, and link encryption status in the inter-satellite link information , where ; the feature extraction layer performs feature dimensionality reduction on multi-dimensional parameters through a deep autoencoder to generate a composite security feature vector;

[0085] Map to a low-dimensional space through an encoder: where is the encoding weight obtained through training, is the encoding bias obtained through training, is the activation function;

[0086] Hidden output is the composite security feature vector, which is used for subsequent security score calculation.

[0087] The evaluation calculation layer performs weighted calculation on the feature vector through a fuzzy comprehensive evaluation algorithm to generate a standardized security score;

[0088] Use the fuzzy comprehensive evaluation method to perform weighted calculation on the composite security feature vector to form a normalized security score , the specific steps are as follows: Among them, are the minimum and maximum values obtained from historical statistics respectively;

[0089] The weight of each composite security feature vector is obtained by analyzing historical data through machine learning (satisfying ); thus, the security score is calculated based on the feature vector weight and the normalized composite security feature vector. The specific calculation formula is: And the security score is normalized to obtain a standardized security score .

[0090] The policy generation layer adaptively adjusts the security policy of the inter-satellite link according to the security score division.

[0091] Security level division:

[0092] Set two thresholds and (satisfying ), and the scores are divided into three levels:

[0093] When , the link is in a low security level, and high-strength encryption and redundancy measures are taken;

[0094] When , the medium security level is adopted;

[0095] When , the link has a high security level, and the high security level is adopted, and the protection level can be appropriately reduced to improve efficiency.

[0096] Among them, the low security level requires using a high-level encryption algorithm to encrypt data to ensure the confidentiality of data during transmission, increasing data redundancy, and regularly backing up key data to prevent data loss or damage; the medium security level requires using a standard-level encryption algorithm to encrypt data to ensure the basic security of data, regularly conducting security audits, detecting and fixing potential security vulnerabilities; the high security level requires using a basic-level encryption algorithm to ensure the basic data security, while reducing system overhead, reducing data redundancy and backup frequency on the premise of ensuring security to improve system efficiency.

[0097] According to the standardized security score , automatically adjust the policy parameters such as link encryption, access control, and data backup.

[0098] The data transmission path acquisition module dynamically calculates and optimizes the data transmission path through a mixed integer linear programming algorithm based on the adaptive security policy and network topology information;

[0099] Further, the step of dynamically calculating and optimizing the data transmission path includes:

[0100] Taking the inter-satellite link information as an input parameter according to the adaptive security policy and the topology information of the satellite network; adopting a mixed integer linear programming algorithm, constructing an optimization objective of minimizing transmission delay, path risk value, and energy consumption, and calculating the optimal data transmission path according to link bandwidth, delay, and load capacity as constraint conditions; combining the adaptive security policy, dynamically adjusting path selection to ensure that under different link security levels, the optimization of the data transmission path matches the security requirements; verifying the calculated data transmission path according to the real-time obtained inter-satellite link information.

[0101] The link fast switching module constructs an inter-satellite link fast switching model to analyze the inter-satellite link information, generates inter-satellite link abnormal information, and quickly switches to a standby inter-satellite link according to the adaptive security policy and network topology information;

[0102] Further, the inter-satellite link fast switching model includes a data analysis layer, an anomaly identification layer, a switching decision layer, and an output layer; the data analysis layer processes the inter-satellite link information by using a machine learning algorithm to identify potential link abnormal behaviors; the anomaly identification layer analyzes the link abnormal behaviors to generate inter-satellite link abnormal information, and the inter-satellite link abnormal information includes link performance degradation, link loss, and sudden interference; the switching decision layer generates a switching decision according to the real-time analysis results, by evaluating the reliability and security of the link and combining the status of the standby link, and quickly switches the data stream to the standby inter-satellite link; the output layer confirms the status of the switched link to ensure the smooth transmission of the data stream.

[0103] To optimize the data transmission path, an MILP model is constructed, and its objective is to minimize transmission delay, path risk, and energy consumption. The model construction is as follows:

[0104] Objective function:

[0105] Whether to select the link is the link 's transmission delay; is the link 's risk value; is the link 's energy consumption; and are weight coefficients (satisfying );

[0106] Obtained through the objective function and ; and based on the obtained actual link parameters and ; Process the data obtained according to the objective function and the data obtained from the actual link to obtain a deviation and , when the deviation is greater than the tolerance value, trigger re-optimization; regularly update the link status to ensure that the optimal path matches the actual situation of the current network.

[0107] As shown in Table 2, the traditional method relies on adaptive adjustment, resulting in response delay. In contrast, the present invention analyzes link anomalies (such as performance degradation, burst interference) in real time through a machine learning model and automatically switches to a backup link. For example, when a link loss is detected, the switching decision layer completes the path switching within 0.5 seconds to ensure the continuity of data transmission.

[0108] Table 2 Comparison table of inter-satellite link switching response times

[0109] Scenario Adaptive adjustment Machine learning automatic switching Link performance degradation > 5 seconds <1 second Sudden interference > 10 seconds <2 seconds Link loss Manual reconnection required Automatic switching (<0.5 seconds)

[0110] Anomaly recognition module, which performs data transmission based on the inter-satellite link, monitors and obtains transmission behavior data; constructs a data anomaly recognition model to analyze the transmission behavior and obtains a data anomaly response;

[0111] Furthermore, the data anomaly recognition model includes a first input layer, a second feature extraction layer, an anomaly detection layer, and a response decision layer:

[0112] The first input layer obtains transmission behavior data, which includes the transmission time, data size, transmission delay, throughput, and link quality information of data packets; the second feature extraction layer extracts features from the transmission behavior data to generate a transmission behavior feature vector; the anomaly detection layer analyzes the transmission behavior feature vector to identify abnormal transmission behaviors and generates anomaly detection results, which include attacks, data tampering, and transmission failures; the response decision layer generates corresponding data anomaly responses according to the anomaly detection results.

[0113] Calculate an anomaly score based on the data anomaly response: where is the anomaly score, is the transmission time fluctuation, is the data size anomaly, is the delay change, is the link quality change, is the anomaly score calculation function;

[0114] When (preset threshold), perform the following response measures:

[0115] 1) Discard abnormal data packets: If a data packet is determined to be malicious or damaged, discard it in a timely manner;

[0116] 2) Trigger the alarm mechanism: Generate alarm information for abnormal data packets, notify the system administrator or automatically enable security policies for handling;

[0117] 3) Trace the attack source: If an attack behavior is identified, further trace the IP address or link path of the attack source to prevent further damage;

[0118] 4) Switch to a secure link: If the data transmission is unstable due to anomalies, quickly switch to a backup link or implement traffic redirection to ensure the normal progress of data transmission.

[0119] Identify and process satellite network threats according to the data anomaly response.

[0120] The existing rule base is difficult to cover complex attack patterns. As shown in Table 3, the present invention constructs an anomaly score through transmission behavior feature vectors (such as packet size, link quality) , when it automatically triggers a response (such as discarding malicious packets), and the detection accuracy is increased to over 92%.

[0121] Table 3 Comparison table of data anomaly detection accuracy

[0122] Abnormal type Existing technology (rule base matching) The present invention (feature vector analysis) Attack behavior 70% 95% Data tampering 65% 92% Transmission failure 75% 89%

[0123] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for identifying satellite Internet threats, characterized in that, Including: Establish a node authentication system based on a distributed public key infrastructure, construct a node reputation evaluation model through blockchain technology, and obtain trusted nodes; Construct a satellite network based on trusted nodes and collect inter-satellite link information in real time; obtain real-time changes in the satellite network topology based on machine learning algorithms, construct an inter-satellite link security evaluation model, and generate an adaptive security policy matching the inter-satellite link security level; the inter-satellite link security evaluation model includes a data collection layer, a feature extraction layer, an evaluation calculation layer, and a policy generation layer; the data collection layer obtains the carrier-to-noise ratio, Doppler shift, link propagation delay, throughput fluctuation, bit error rate, and link encryption status in the inter-satellite link information in real time; the feature extraction layer generates a composite security feature vector by using a deep autoencoder to perform feature dimensionality reduction on multi-dimensional parameters; the evaluation calculation layer performs weighted calculation on the composite security feature vector through a fuzzy comprehensive evaluation algorithm to generate a standardized security score; the policy generation layer adaptively adjusts the security policy for the inter-satellite link according to the security score; Based on the adaptive security policy and network topology information, dynamically calculate and optimize the data transmission path through a mixed integer linear programming algorithm; construct an inter-satellite link fast switching model to analyze the inter-satellite link information, generate inter-satellite link anomaly information, and quickly switch to a standby inter-satellite link according to the adaptive security policy and network topology information; the inter-satellite link fast switching model includes a data analysis layer, an anomaly recognition layer, a switching decision layer, and an output layer; the data analysis layer processes the inter-satellite link information by using a machine learning algorithm to identify potential link anomaly behaviors; The anomaly recognition layer generates inter-satellite link anomaly information by analyzing the link anomaly behaviors, and the inter-satellite link anomaly information includes link performance degradation, link loss, and sudden interference; The switching decision layer generates a switching decision according to the results of real-time analysis, quickly switches the data stream to the standby inter-satellite link by evaluating the reliability and security of the link and combining the status of the standby link; the output layer confirms the link status after switching to ensure the smooth transmission of the data stream; Perform data transmission according to the inter-satellite link, monitor and obtain transmission behavior data; construct a data anomaly recognition model to analyze the transmission behavior and obtain a data anomaly response; Identify and process satellite network threats according to the data anomaly response.

2. The method for identifying satellite Internet threats according to claim 1, wherein: The trusted node is a satellite node with a reputation score exceeding a preset threshold in the blockchain reputation evaluation model; The construction of the satellite network includes the following steps: constructing a three-dimensional inter-satellite topology structure based on the node geographical location; dynamically selecting trusted nodes according to the node reputation score; establishing an initial secure link based on the trusted nodes; The inter-satellite link information is collected in real time by an on-board multi-mode sensor array, including carrier-to-noise ratio, Doppler shift, link propagation delay, throughput fluctuation, routing hop count, bit error rate, signal attenuation exponent, node relative motion vector, space radiation intensity, and link encryption status.

3. A satellite Internet threat recognition method according to claim 1, characterized in that: The step of obtaining satellite network topology changes is as follows: The machine learning algorithm uses a spatio-temporal graph convolutional neural network model. The input layer receives the inter-satellite link information of the satellite network; the hidden layer includes a long short-term memory module to process time series features and analyze the input data; the output layer generates a topology dynamic probability map; and the node disappearance and node addition events are detected through an adaptive sliding window mechanism, and the inter-satellite link information is updated in real time.

4. A satellite Internet threat recognition method according to claim 1, characterized in that: The steps of dynamically calculating and optimizing the data transmission path include: Taking the inter-satellite link information as an input parameter according to the adaptive security policy and the topology information of the satellite network; using a mixed integer linear programming algorithm, constructing an optimization objective of minimizing transmission delay, path risk value and energy consumption, and calculating the optimal data transmission path with link bandwidth, delay and load capacity as constraint conditions; combining the adaptive security policy, dynamically adjusting the path selection to ensure that the optimization of the data transmission path matches the security requirements under different link security levels; verifying the calculated data transmission path according to the real-time obtained inter-satellite link information.

5. A satellite Internet threat recognition method according to claim 1, characterized in that: The data anomaly recognition model includes a first input layer, a second feature extraction layer, an anomaly detection layer and a response decision layer: The first input layer obtains transmission behavior data, and the transmission behavior data includes the transmission time, data size, transmission delay, throughput and link quality information of the data packet; the second feature extraction layer extracts features from the transmission behavior data to generate a transmission behavior feature vector; the anomaly detection layer analyzes the transmission behavior feature vector to identify abnormal transmission behaviors and generate anomaly detection results, and the anomaly detection results include attacks, data tampering and transmission failures; the response decision layer generates corresponding data anomaly responses according to the anomaly detection results.

6. A satellite Internet threat identification system, characterized in that, Implement a satellite Internet threat recognition method as described in claim 1, including: a satellite network construction module that establishes a node authentication system based on a distributed public key infrastructure, constructs a node reputation evaluation model through blockchain technology to obtain trusted nodes; constructs a satellite network based on the trusted nodes and collects inter-satellite link information in real time; a security policy generation module that obtains real-time changes in the satellite network topology based on a machine learning algorithm, constructs an inter-satellite link security evaluation model, and generates an adaptive security policy that matches the inter-satellite link security level; a data transmission path acquisition module that dynamically calculates and optimizes the data transmission path based on the adaptive security policy and network topology information through a mixed integer linear programming algorithm; a link fast switching module that constructs an inter-satellite link fast switching model to analyze the inter-satellite link information, generates inter-satellite link anomaly information, and based on the adaptive security policy and network topology information, quickly switches to a backup inter-satellite link; an anomaly recognition module that performs data transmission based on the inter-satellite link, monitors and obtains transmission behavior data; constructs a data anomaly recognition model to analyze the transmission behavior and obtains a data anomaly response; and recognizes and processes satellite network threats based on the data anomaly response.

7. A satellite Internet threat identification electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a satellite Internet threat recognition method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Trusted routing method based on medium earth orbit / low earth orbit network

    CN106685834A

  • Satellite-ground data transmission link secure transmission system and method

    CN117220752A