Data security monitoring method and system based on USB network communication

USB network communication data is collected and preprocessed through the Libpcap class library, and the diagnostic model is used for security monitoring, which solves the problems of missed and false alarms in the existing technology, and achieves efficient and accurate data security monitoring and response.

CN119945763APending Publication Date: 2025-05-06REMO WIRELESS
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510062284.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When facing complex and changing attack methods, existing USB network communication data security monitoring methods have problems such as missed reports and false alarms, which cannot meet the growing security needs.

Method used

The network data packets of networked devices are collected through the Libpcap class library, combined with the communication log data for preprocessing, data frames are encapsulated using preset protocols, and diagnostics are performed through diagnostic models, including dynamic learning and adjustment of the encoder, to determine whether the confidence threshold is met to determine the response.

Benefits of technology

It improves monitoring accuracy, reduces the probability of missed and false alarms, enhances the system's adaptability and response speed, and ensures security during data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945763A_ABST
    Figure CN119945763A_ABST
Patent Text Reader

Abstract

The invention relates to a USB-based network communication data security monitoring method and system, and belongs to the technical field of communication data security monitoring. The method comprises the following steps: acquiring a network data packet of networking equipment through a Libpcap class library, obtaining communication log data of the networking equipment, and calculating through a preprocessing model according to the network communication data and the communication log data to obtain preprocessed data; presetting a specified protocol, packaging the preprocessed data according to the specified protocol to obtain a data frame, and calculating through a diagnosis model according to the data frame to obtain a diagnosis result; presetting a confidence coefficient threshold value, judging whether the diagnosis result is greater than the confidence coefficient threshold value or not, and if so, executing subsequent steps; if not, marking the data frame to obtain a marked data frame, and retraining the encoder according to the marked data frame; presetting a judgment threshold value, judging the diagnosis result according to the judgment threshold value to obtain a judgment result, and making a response by the networking equipment according to the judgment result. And network communication data security monitoring is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of communication data security monitoring, and in particular relates to a USB network communication data security monitoring method and system. Background Art

[0002] With the rapid development of information technology, USB network communication has become one of the main ways of data transmission and exchange. However, the convenience of USB network communication also brings hidden dangers to data security. Malicious attackers may steal, tamper with or destroy sensitive information by counterfeiting USB devices or exploiting loopholes in the data transmission process, posing a serious threat to personal privacy and corporate security.

[0003] Traditional USB network communication data security monitoring methods often rely on a single protection method, such as firewalls, intrusion detection systems, etc., but these methods often have problems such as missed reports and false positives when facing complex and changeable attack methods, and cannot meet the growing security needs. Therefore, it is particularly important to develop an efficient and accurate USB network communication data security monitoring method. Summary of the invention

[0004] In order to solve the above problems existing in the prior art, the present invention provides a method and system for monitoring data security based on USB network communication.

[0005] The purpose of the present invention can be achieved through the following technical solutions:

[0006] S1: Collect network data packets of networked devices through the Libpcap library to obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model according to the network communication data and the communication log data;

[0007] S2: presetting a prescribed protocol, encapsulating the preprocessed data according to the prescribed protocol to obtain a data frame, and calculating a diagnosis result according to the data frame through a diagnosis model; the diagnosis model includes an encoder;

[0008] S3: presetting a confidence threshold, determining whether the diagnosis result is greater than the confidence threshold, if yes, executing step S4; if no, labeling the data frame to obtain a labeled data frame, and retraining the encoder according to the labeled data frame;

[0009] S4: Preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

[0010] Specifically, the networking device is a mobile terminal connected to a multi-function data cable, and the multi-function data cable includes a first connection part, a second connection part, and a chip component part. The first connection part includes a USB male head and a type-c male head, and the second connection part includes but is not limited to a type-c male head. The chip component part includes a cat1 communication chip, a two-way fast charging management chip, and a fast charging chip.

[0011] Specifically, the network data packet includes a data payload, a packet header, and a packet trailer. The data payload includes a request URL, a request method, a request body, and file content; the packet header includes but is not limited to a source address, a destination address, a protocol type, and a port number; and the packet trailer includes verification information.

[0012] Specifically, the specific calculation steps of the preprocessing model include:

[0013] Obtain replacement data by replacing a default value and an infinite value with 0 according to the network communication data and the communication log data;

[0014] Obtaining normalized data through min-max normalization calculation according to the replacement data;

[0015] Obtaining standardized data by Z-score standardization calculation according to the normalized data;

[0016] Performing data balancing using the ADASYN algorithm according to the standardized data to obtain balanced data;

[0017] The preprocessed data is obtained by performing dimensionality reduction on the balanced data using a principal component analysis method.

[0018] Specifically, the specific calculation steps of the diagnostic model are:

[0019] Calculate the relevant characteristic data according to the data frame by using the chi-square test method;

[0020] Performing feature clustering according to the relevant feature data by using a hierarchical clustering algorithm to obtain a feature subset;

[0021] The diagnosis result is obtained by calculating the encoder according to the feature subset.

[0022] Specifically, judging the diagnosis result according to the judgment threshold to obtain a judgment result includes:

[0023] Determine whether the diagnosis result is less than the judgment threshold, if yes, output normal access; if no, output abnormal access;

[0024] The judgment result includes normal access and abnormal access.

[0025] Specifically, the networked device responds according to the judgment result including:

[0026] If the judgment result is normal access, the networked device acquires data according to the request URL and the request method to obtain access data, calculates encrypted data according to the access data through an encryption function, and transmits the encrypted data to the access terminal according to the destination address;

[0027] The encryption function expression is:

[0028]

[0029] Wherein, H is the encrypted data, D is the access data, and D n is the ciphertext of the computer network communication data stream, p is the data conversion amount, s is the transmission upper limit, r is the transmission lower limit, and b is the information change amount per unit time;

[0030] If the judgment result is abnormal access, the networked device blocks the access and generates an alarm signal to be transmitted to the human-computer interaction interface.

[0031] A USB network communication data security monitoring system, comprising: a preprocessing module, a diagnosis module, a decision module, and a response module;

[0032] The preprocessing module is used to collect network data packets of networked devices through the Libpcap library, obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model based on the network communication data and the communication log data;

[0033] The diagnostic module is used to preset a prescribed protocol, encapsulate the preprocessed data according to the prescribed protocol to obtain a data frame, and calculate the diagnostic result through a diagnostic model according to the data frame; the diagnostic model includes an encoder;

[0034] The decision module is used to preset a confidence threshold, determine whether the diagnosis result is greater than the confidence threshold, and if yes, execute step S4; if no, label the data frame to obtain a labeled data frame, and retrain the encoder according to the labeled data frame;

[0035] The response module is used to preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

[0036] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the USB network communication data security monitoring as described above is realized.

[0037] A storage medium containing computer executable instructions, wherein the computer executable instructions are used to perform the USB network communication data security monitoring as described above when executed by a computer processor.

[0038] The beneficial effects of the present invention are:

[0039] (1) Improve monitoring accuracy: The present invention collects network data packets of networked devices through the Libpcap library and preprocesses them in combination with communication log data, effectively extracting key information in network communication. By encapsulating preprocessed data through a preset prescribed protocol and using a diagnostic model for diagnosis, potential security threats can be identified more accurately, reducing the probability of missed reports and false positives.

[0040] (2) Enhanced adaptability: The diagnostic model in the present invention includes an encoder that can dynamically learn and adjust according to the characteristics of the data frame. When the diagnostic result does not meet the confidence threshold, the data frame will be labeled and the encoder will be retrained, thereby improving the model's ability to identify new types of attacks and enhancing the adaptability of the system.

[0041] (3) Improve response speed: The present invention judges the diagnosis results by presetting the judgment threshold and responds quickly according to the judgment results. For normal access, the networked device will encrypt the transmitted data to ensure the security of the data during the transmission process; for abnormal access, the networked device will immediately block the access and generate an alarm signal, effectively preventing the occurrence of security incidents.

[0042] (4) Support for multi-function data cables: The present invention is particularly suitable for mobile terminals connected to multi-function data cables. The multi-function data cable not only has the data transmission function, but also integrates components such as the cat1 communication chip and the two-way fast charging management chip, which can meet the usage requirements in different scenarios. The monitoring method of the present invention can ensure the security of these devices during the data transmission process.

[0043] (5) Detailed data processing flow: The preprocessing model in the present invention processes the raw data comprehensively and meticulously through steps such as replacing default values, normalization, standardization, data balancing and dimensionality reduction, thereby improving the quality and usability of the data. At the same time, the diagnostic model further extracts key features from the data through algorithms such as the chi-square test and hierarchical clustering, providing strong support for accurate diagnosis. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.

[0045] Figure 1 The present invention is a flow chart of a method for monitoring data security based on USB network communication. DETAILED DESCRIPTION

[0046] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the specific implementation methods, structures, features and effects of the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments.

[0047] See also Figure 1 , a data security monitoring method based on USB network communication;

[0048] S1: Collect network data packets of networked devices through the Libpcap library to obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model according to the network communication data and the communication log data;

[0049] S2: presetting a prescribed protocol, encapsulating the preprocessed data according to the prescribed protocol to obtain a data frame, and calculating a diagnosis result according to the data frame through a diagnosis model; the diagnosis model includes an encoder;

[0050] S3: presetting a confidence threshold, determining whether the diagnosis result is greater than the confidence threshold, if yes, executing step S4; if no, labeling the data frame to obtain a labeled data frame, and retraining the encoder according to the labeled data frame;

[0051] S4: Preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

[0052] Specifically, the networking device is a mobile terminal connected to a multi-function data cable, and the multi-function data cable includes a first connection part, a second connection part, and a chip component part. The first connection part includes a USB male head and a type-c male head, and the second connection part includes but is not limited to a type-c male head. The chip component part includes a cat1 communication chip, a two-way fast charging management chip, and a fast charging chip.

[0053] In this embodiment, the first connection part is used to connect to an adapter, a power bank, etc.; the second connection part is used to connect to a mobile terminal such as a computer; the cat1 communication chip is used to provide a stable Internet access function, the two-way fast charging management chip is used to support data role and power role switching, and the fast charging chip is used to provide a stable fast charging function.

[0054] Specifically, the network data packet includes a data payload, a packet header, and a packet trailer. The data payload includes a request URL, a request method, a request body, and file content; the packet header includes but is not limited to a source address, a destination address, a protocol type, and a port number; and the packet trailer includes verification information.

[0055] Specifically, the communication log data includes system log data, behavior log data, and audit data.

[0056] Specifically, the specific calculation steps of the preprocessing model include:

[0057] Obtain replacement data by replacing a default value and an infinite value with 0 according to the network communication data and the communication log data;

[0058] Obtaining normalized data through min-max normalization calculation according to the replacement data;

[0059] Obtaining standardized data by Z-score standardization calculation according to the normalized data;

[0060] Performing data balancing using the ADASYN algorithm according to the standardized data to obtain balanced data;

[0061] The preprocessed data is obtained by performing dimensionality reduction on the balanced data using a principal component analysis method.

[0062] Specifically, the specific calculation steps of the diagnostic model are:

[0063] Calculate the relevant characteristic data according to the data frame by using the chi-square test method;

[0064] Performing feature clustering according to the relevant feature data by using a hierarchical clustering algorithm to obtain a feature subset;

[0065] The diagnosis result is obtained by calculating the encoder according to the feature subset.

[0066] Specifically, judging the diagnosis result according to the judgment threshold to obtain a judgment result includes:

[0067] Determine whether the diagnosis result is less than the judgment threshold, if yes, output normal access; if no, output abnormal access;

[0068] The judgment result includes normal access and abnormal access.

[0069] Specifically, the networked device responds according to the judgment result, including:

[0070] If the judgment result is normal access, the networked device acquires data according to the request URL and the request method to obtain access data, calculates encrypted data according to the access data through an encryption function, and transmits the encrypted data to the access terminal according to the destination address;

[0071] The encryption function expression is:

[0072]

[0073] Wherein, H is the encrypted data, D is the access data, and D n is the ciphertext of the computer network communication data stream, p is the data conversion amount, s is the transmission upper limit, r is the transmission lower limit, and b is the information change amount per unit time;

[0074] If the judgment result is abnormal access, the networked device blocks the access and generates an alarm signal to be transmitted to the human-computer interaction interface.

[0075] A USB network communication data security monitoring system, comprising: a preprocessing module, a diagnosis module, a decision module, and a response module;

[0076] The preprocessing module is used to collect network data packets of networked devices through the Libpcap library, obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model based on the network communication data and the communication log data;

[0077] The diagnostic module is used to preset a prescribed protocol, encapsulate the preprocessed data according to the prescribed protocol to obtain a data frame, and calculate the diagnostic result through a diagnostic model according to the data frame; the diagnostic model includes an encoder;

[0078] The decision module is used to preset a confidence threshold, determine whether the diagnosis result is greater than the confidence threshold, and if yes, execute step S4; if no, label the data frame to obtain a labeled data frame, and retrain the encoder according to the labeled data frame;

[0079] The response module is used to preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

[0080] In this embodiment, the encoder retraining process is:

[0081] Calculate the true value of the target data frame, calculate the loss function value according to the true value and the diagnosis result, update the weight and bias of the encoder through a back propagation algorithm according to the loss function value, adjust the learning rate of the encoder through an optimization algorithm, preset a convergence interval, and iteratively train the encoder until the loss function value is within the convergence interval.

[0082] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the USB network communication data security monitoring as described above is realized.

[0083] A storage medium containing computer executable instructions, wherein the computer executable instructions are used to perform the USB network communication data security monitoring as described above when executed by a computer processor.

[0084] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device.

[0085] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0086] The program code included on the computer readable medium can be transmitted with any appropriate medium, including but not limited to wireless, electric wire, optical cable, RF, etc., or any suitable combination of the above. The computer program code for performing the operation of the present invention can be written in one or more programming languages ​​or their combinations, and the programming language includes object-oriented programming languages-such as Java, Smalltalk, C++, and also includes conventional procedural programming languages-such as "C" language or similar programming languages. The program code can be executed completely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on the remote computer, or completely on the remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).

[0087] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment as above, it is not used to limit the present invention. Any technical personnel in this field can make some changes or modify the technical contents disclosed above into equivalent embodiments without departing from the scope of the technical solution of the present invention. However, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present invention without departing from the content of the technical solution of the present invention still fall within the scope of the technical solution of the present invention.

Claims

1. A method for monitoring data security based on USB network communication, characterized in that: include: S1: Collect network data packets of networked devices through the Libpcap library to obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model according to the network communication data and the communication log data; S2: presetting a prescribed protocol, encapsulating the preprocessed data according to the prescribed protocol to obtain a data frame, and calculating a diagnosis result according to the data frame through a diagnosis model; the diagnosis model includes an encoder; S3: Preset a confidence threshold, and determine whether the diagnosis result is greater than the confidence threshold. If yes, execute step S4; If no, label the data frame to obtain a labeled data frame, and retrain the encoder according to the labeled data frame; S4: Preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

2. The USB network communication data security monitoring method according to claim 1 is characterized in that: The networking device is a mobile terminal connected to a multi-function data cable, which includes a first connection part, a second connection part, and a chip component part. The first connection part includes a USB male head and a type-c male head, and the second connection part includes but is not limited to a type-c male head. The chip component part includes a cat1 communication chip, a two-way fast charging management chip, and a fast charging chip.

3. The USB network communication data security monitoring method according to claim 1 is characterized in that: The network data packet includes a data payload, a packet header, and a packet trailer. The data payload includes a request URL, a request method, a request body, and file content; the packet header includes but is not limited to a source address, a destination address, a protocol type, and a port number; and the packet trailer includes verification information.

4. The method for monitoring data security based on USB network communication according to claim 1, characterized in that: The specific calculation steps of the preprocessing model include: Obtain replacement data by replacing a default value and an infinite value with 0 according to the network communication data and the communication log data; Obtaining normalized data through min-max normalization calculation according to the replacement data; Obtaining standardized data by Z-score standardization calculation according to the normalized data; Performing data balancing using the ADASYN algorithm according to the standardized data to obtain balanced data; The preprocessed data is obtained by performing dimensionality reduction on the balanced data using a principal component analysis method.

5. The USB network communication data security monitoring method according to claim 1 is characterized in that: The specific calculation steps of the diagnostic model are: Calculate the relevant characteristic data according to the data frame by using the chi-square test method; Performing feature clustering according to the relevant feature data by using a hierarchical clustering algorithm to obtain a feature subset; The diagnosis result is obtained by calculating the encoder according to the feature subset.

6. The method for monitoring data security based on USB network communication according to claim 1, characterized in that: The step of determining the diagnosis result according to the determination threshold to obtain the determination result comprises: Determine whether the diagnosis result is less than the judgment threshold, if yes, output normal access; if no, output abnormal access; The judgment result includes normal access and abnormal access.

7. The USB network communication data security monitoring method according to claim 1, characterized in that: Specifically, the networked device responds according to the judgment result, including: If the judgment result is normal access, the networked device acquires data according to the request URL and the request method to obtain access data, calculates encrypted data according to the access data through an encryption function, and transmits the encrypted data to the access terminal according to the destination address; The encryption function expression is: Wherein, H is the encrypted data, D is the access data, and D n is the ciphertext of the computer network communication data stream, p is the data conversion amount, s is the transmission upper limit, r is the transmission lower limit, and b is the information change amount per unit time; If the judgment result is abnormal access, the networked device blocks the access and generates an alarm signal to be transmitted to the human-computer interaction interface.

8. A USB network communication data security monitoring system, characterized in that: include: Preprocessing module, diagnosis module, decision module, response module; The preprocessing module is used to collect network data packets of networked devices through the Libpcap library, obtain communication log data of the networked devices, and calculate preprocessing data through a preprocessing model based on the network communication data and the communication log data; The diagnostic module is used to preset a prescribed protocol, encapsulate the preprocessed data according to the prescribed protocol to obtain a data frame, and calculate the diagnostic result through a diagnostic model according to the data frame; the diagnostic model includes an encoder; The decision module is used to preset a confidence threshold and determine whether the diagnosis result is greater than the confidence threshold. If yes, execute step S4; If no, label the data frame to obtain a labeled data frame, and retrain the encoder according to the labeled data frame; The response module is used to preset a judgment threshold, judge the diagnosis result according to the judgment threshold to obtain a judgment result, and the networked device responds according to the judgment result.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the USB network communication data security monitoring as described in any one of claims 1-7 is implemented.

10. A storage medium containing computer executable instructions, characterized in that: The computer executable instructions are used to perform USB network communication data security monitoring as described in any one of claims 1-7 when executed by a computer processor.

Citation Information

Patent Citations

  • Web anomaly detection method and system based on SMOTETomek and LightGBM

    CN110138786A

  • Method and system for safely accessing database

    CN118555104A

  • Security server system implementation method, medium, security system and device

    CN119011177A

  • Building low-carbon operation management method based on data analysis

    CN119273235A

  • Sub-cluster extraction apparatus, sub-cluster extraction method, and program

    JP2023006500A