Method for fusing optimized network service and dynamically generating protection scheme

By obtaining threat intelligence data, evaluating the encryption capabilities of network services, selecting the optimal encryption scheme and transmission path, monitoring the data transmission process in real time, and dynamically updating the protection scheme, it solves the problem of difficult to achieve high security and reliability of data transmission in the existing technology, and realizes an efficient, secure and flexible solution for network data transmission.

CN119945775AActive Publication Date: 2025-05-06JILIN AGRI SCI & TECH COLLEGE

Patent Information

Application Number
CN202510095929.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-06
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

The prior art is difficult to achieve high security and reliability of network data transmission while ensuring data transmission efficiency, especially when facing complex and changing network environments and changing attack patterns.

Method used

By obtaining threat intelligence data, evaluating the encryption capabilities of network services, selecting the optimal encryption scheme and transmission path, and monitoring the data transmission process in real time, dynamically updating protection schemes to deal with changing security threats.

Benefits of technology

It significantly improves the security and reliability of network data transmission, effectively deals with multiple threats in complex network environments, and realizes dynamic encryption and intelligent routing during data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945775A_ABST
    Figure CN119945775A_ABST
Patent Text Reader

Abstract

The invention provides a method for fusing a preferred network service and a dynamic generation protection scheme, and the method comprises the steps: obtaining threat intelligence data, judging whether a current network service supports a preset encryption protocol or not according to the threat intelligence data, determining the current network service as a candidate network service if the current network service supports the preset encryption protocol, and generating a protection scheme according to the candidate network service. If not, screening other network services; extracting an encryption protocol type and an intensity parameter of the candidate network service, and determining a target network service in combination with a threat level in the threat intelligence data; generating an encryption key based on the encryption protocol type and the strength parameter of the target network service; binding the encryption key with a transmission path to form a protection scheme; and monitoring an abnormal behavior in a data transmission process, and if the abnormal behavior is detected, updating the protection scheme.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a method for integrating optimal network services and dynamically generating protection solutions. Background Art

[0002] Network data transmission faces increasingly complex and changeable security threats. Traditional static encryption and fixed routing methods are difficult to cope with this dynamic environment. How to achieve high security and reliability while ensuring data transmission efficiency has become a key challenge. Specifically, there are many potential threats in the network environment, including data eavesdropping, man-in-the-middle attacks, DDoS attacks, etc. The characteristics and means of these threats are constantly evolving. At the same time, the network topology is complex and changeable, and the security levels and encryption capabilities of different nodes are different. In this case, how to accurately identify and evaluate the security threats in the current network environment and select the optimal encryption scheme and transmission path based on this? In addition, even if preliminary security measures are taken, network attackers may still find out the weak links of the system through long-term observation and analysis. Therefore, how to achieve dynamic adjustment and continuous optimization of security policies to cope with the ever-changing attack patterns? These problems involve the integration and innovation of multiple technical fields such as threat intelligence analysis, encryption technology, routing algorithms, and anomaly detection, which constitute a complex technical problem. Solving this problem requires not only considering the advancement of technology, but also taking into account the performance overhead and user experience in actual applications, and finding a balance between security, efficiency and availability. Summary of the invention

[0003] The present invention provides a method for integrating optimal network services and dynamically generating protection solutions, which mainly includes:

[0004] Acquire threat intelligence data, and determine whether the current network service supports a preset encryption protocol based on the threat intelligence data; if so, determine the current network service as a candidate network service; if not, screen other network services; extract the encryption protocol type and strength parameters of the candidate network service, and determine the target network service in combination with the threat level in the threat intelligence data; generate an encryption key based on the encryption protocol type and strength parameters of the target network service; bind the encryption key to the transmission path to form a protection plan; monitor abnormal behavior during data transmission, and update the protection plan if abnormal behavior is detected.

[0005] Furthermore, the acquiring of threat intelligence data and determining whether the current network service supports a preset encryption protocol based on the threat intelligence data include: acquiring multi-source threat intelligence data through an interface, integrating and cleaning the multi-source threat intelligence data, and forming a threat intelligence report in a unified format; parsing the threat intelligence report, extracting network service information, the network service information including at least the address, port, and protocol type of the network service; comparing the network service information with a preset encryption protocol list to determine whether the current network service supports an encryption protocol in the preset encryption protocol list; if the current network service supports at least one encryption protocol in the preset encryption protocol list, then determining that the current network service supports the preset encryption protocol; otherwise determining that the current network service does not support the preset encryption protocol.

[0006] Furthermore, the extraction of encryption protocol types and strength parameters of the candidate network services, combined with the threat level in the threat intelligence data, to determine the target network service includes: traversing the candidate network service list, and for each candidate network service, extracting the encryption protocol types supported by the candidate network service, and the strength parameters corresponding to each encryption protocol; extracting threat level information from the threat intelligence data, and mapping the threat level information into a numerical threat level score according to a preset threat level classification standard; constructing a network service security assessment model according to the encryption protocol type and strength parameters, and using a preset assessment algorithm to calculate the security score of each candidate network service; combining the threat level score and the security score, using a weighted calculation method to obtain a comprehensive security score for each candidate network service, and selecting the candidate network service with the highest comprehensive security score as the target network service.

[0007] Furthermore, the encryption key is generated based on the encryption protocol type and strength parameter of the target network service, including: selecting a corresponding key generation algorithm according to the encryption protocol type of the target network service, if the encryption protocol type is symmetric encryption, selecting a first key generation algorithm, if the encryption protocol type is asymmetric encryption, selecting a second key generation algorithm; determining a key length according to the encryption protocol strength parameter of the target network service, the key length being positively correlated with the encryption protocol strength parameter; generating an initial random number through a hardware random number generator, and generating an initial key based on the initial random number and the key generation algorithm; performing a complexity check on the initial key to determine whether the initial key meets a preset complexity requirement, and if not, regenerating the initial key until the generated initial key meets the complexity requirement, and using the initial key that meets the complexity requirement as the encryption key.

[0008] Furthermore, the binding of the encryption key to the transmission path to form a protection scheme includes: obtaining network topology information, constructing a network transmission path model based on the network topology information, wherein the network transmission path model includes multiple network nodes and links connecting the network nodes; associating the encryption key with the network nodes and links in the network transmission path model to form a key-path mapping relationship; selecting a corresponding transmission path from the network transmission path model according to different data transmission requests, and assigning the encryption key to the network nodes and links on the transmission path; combining the encryption key, the transmission path and the corresponding security configuration information into a protection scheme, and storing the protection scheme in a configuration database.

[0009] Furthermore, the monitoring of abnormal behavior during data transmission and updating of the protection scheme if abnormal behavior is detected include: obtaining data packets during data transmission by means of bypass listening, parsing the data packets, and extracting data packet feature information; comparing the data packet feature information with a preset abnormal behavior feature library to determine whether there is abnormal behavior, and if there is at least one data packet feature information that matches a feature in the abnormal behavior feature library, then it is determined that abnormal behavior exists; when abnormal behavior is detected, a protection scheme update mechanism is triggered, and a new protection scheme is selected from the protection scheme library according to the type and level of the abnormal behavior; and the new protection scheme is sent to the network device to replace the original protection scheme.

[0010] Furthermore, the selecting a new protection scheme from a protection scheme library according to the type and level of the abnormal behavior includes: determining the urgency of updating the protection scheme according to the type and level of the abnormal behavior; if the level of the abnormal behavior is a high-risk level, selecting a protection scheme with the fastest updating speed; if the level of the abnormal behavior is a medium-risk level, balancing the updating speed and security, and selecting a protection scheme with a faster updating speed and higher security; if the level of the abnormal behavior is a low-risk level, selecting a protection scheme with the highest security; when updating the protection scheme, selecting a protection scheme with a specific protection effect against the type of abnormal behavior according to the type of the abnormal behavior; after updating the protection scheme, verifying the new protection scheme to ensure that it can protect the detected abnormal behavior.

[0011] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:

[0012] The present invention discloses a network data security transmission method based on dynamic encryption and intelligent routing. The method analyzes network security threat intelligence, evaluates the encryption capability of network services, selects the optimal service and generates complex encryption keys. In combination with the network topology, a mapping relationship between keys and transmission paths is established to achieve dynamic encryption and route selection for data transmission. The present invention also includes real-time monitoring of transmission behavior, comparing abnormal features, and automatically updating protection plans based on the type and severity of the abnormality. When a persistent abnormality is detected, the present invention will reacquire threat intelligence and generate a new dynamic protection plan, thereby continuously optimizing data security protection measures. This method significantly improves the security and reliability of network data transmission by integrating threat analysis, dynamic encryption, intelligent routing and adaptive protection, and effectively responds to ever-changing network security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 The present invention is a flow chart of a method for integrating optimal network services and dynamically generating protection solutions. DETAILED DESCRIPTION

[0014] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0015] like Figure 1 In this embodiment, a method for integrating optimal network services and dynamically generating protection solutions may specifically include:

[0016] S101. Obtain a network security threat intelligence analysis report, and determine whether the current network service supports advanced encryption protocols based on the report. If so, add the service to a candidate service list; if not, remove the service from a candidate service list.

[0017] Obtain the threat intelligence analysis report, extract the network service related information, and determine whether each network service supports advanced encryption protocols. If the network service supports advanced encryption protocols, add the service to the candidate service list; if not, remove it from the candidate list. Based on the candidate service list, use the machine learning algorithm to evaluate and score the security of the service to obtain a service security score list. From the service security score list, select the top N network services with the highest scores as candidate services. Conduct in-depth analysis of the candidate services, extract the detailed configuration parameters of the services, and use the expert rule base to determine whether the security configurations of the services meet the standards. According to the security configuration analysis results, combined with the business importance of the service, a weighted calculation is performed to obtain the comprehensive security score of each candidate service. Select the service with the highest comprehensive security score as the final target service, and generate the security reinforcement plan and configuration recommendations for the service. For the target service, extract its encryption protocol type and strength parameters, and determine the optimal encryption scheme through risk matrix calculation based on the threat level in the threat intelligence analysis report. Use the preset encryption algorithm model to dynamically generate new encryption keys based on the parameters of the optimal encryption scheme, and ensure the uniqueness and complexity of the key through key strength assessment. Apply the generated encryption key to the target service, verify the confidentiality, integrity and availability of the service through security testing, form a network service security assessment report, and complete the security reinforcement of the service.

[0018] Specifically, first, 10 network services were extracted from the threat intelligence analysis report. It was found that 6 of them supported advanced encryption protocols such as TLS1.3, and they were added to the candidate list. Then, the random forest algorithm was used to evaluate the security of the candidate services. Considering factors such as the number of vulnerabilities and risk level, the top 3 security scores of services A, B, and C were obtained. Next, the detailed configurations of services A, B, and C, such as key length and encryption algorithm, were extracted, and the expert rule base was used to determine whether they met the FIPS140-2Level 3 standard. The results showed that A and C met the standard, but B did not. Combined with the business importance of the service, a weight of 0.6 was assigned to the security configuration score and a weight of 0.4 was assigned to the business importance. The calculated comprehensive score of service A was the highest, which was 0.85. Therefore, service A was selected as the final target, and security reinforcement suggestions were given, such as using AES-256 and 4096-bit RSA keys. Further analysis revealed that service A used the TLS1.3 protocol with a key strength of 256 bits. Combined with the high risk level in threat intelligence, the risk matrix determined that the optimal encryption scheme was AES-256, SHA-384, DH-4096 and other parameter combinations. Finally, a 48-byte random key was generated using the openssl rand-base6448 command, and its strength was evaluated using the NIST SP 800-22 test suite to ensure key security. The key was applied to service A and a penetration test was performed on it. No security vulnerabilities were found, proving that the service security met the requirements.

[0019] S102. For the network services in the candidate service list, extract the encryption protocol type and strength parameters thereof, combine the threat levels in the threat intelligence analysis report, and use a preset network service security assessment model to determine the optimal network service.

[0020] Obtain a list of candidate network services that support advanced encryption protocols, extract the encryption protocol type used by each network service and its corresponding encryption strength parameters. Extract known threat information related to the candidate network services from the threat intelligence analysis report, and determine the hazard level of each threat. According to the encryption protocol type and strength parameters, establish a network service security assessment model, and use the fuzzy comprehensive evaluation method to calculate the security score of each network service. Perform a weighted calculation on the security score of the network service and its corresponding threat level to obtain a ranking of network services that comprehensively considers security and threat risks. Select the network services that are ranked high and meet business needs as the preferred solution. Before the solution is determined, the technical feasibility of the selected network services needs to be evaluated. Perform penetration tests on the network services involved in the preferred solution to comprehensively evaluate their ability to resist network attacks. If the test results are not ideal, a security reinforcement plan needs to be formulated. Continuously monitor the security status of the selected network services, track the latest threat intelligence, and regularly review the security assessment model to ensure that the preferred solution is effective in the long term. If new security risks are found in the selected network service during the monitoring process, re-execute steps 2-7 until the optimal network service that meets security requirements is found. According to the optimal network service finally determined, its encryption protocol type and strength parameters are extracted as input conditions for the subsequent dynamic generation of encryption keys.

[0021] Specifically, firstly, the encryption protocol type of each service, such as TLS1.2, TLS1.3, etc., and the corresponding encryption strength parameters, such as key length of 128 bits, 256 bits, etc., are extracted from the candidate network service list. Then, the known threats related to the candidate network services are identified from the threat intelligence analysis report, and the threat level is divided into three levels: high, medium, and low according to factors such as the potential impact range of the threat and the success rate of the attack. Then, a network service security assessment model is established, and the security of the encryption protocol type and the difficulty of cracking the key length are comprehensively considered. The security score of each network service is calculated using a fuzzy comprehensive evaluation method, and the score range is 0-100. Then, the security score and the threat level are weighted, with the security score weighted as 0.6 and the threat level weighted as 0.4, to obtain the comprehensive score ranking. The network service with the highest comprehensive score that meets business needs is selected as the preferred solution, and its ability to resist network attacks is evaluated through penetration testing and other methods. If the test finds security risks, a corresponding security reinforcement plan is formulated, such as upgrading the encryption protocol version and increasing the key length. In the subsequent operation process, the security status of the selected network services is continuously monitored, the latest threat intelligence is tracked, and the security assessment model is regularly reviewed based on the monitoring data, and the relevant parameters are dynamically adjusted to ensure that the preferred solution can maintain a high level of security in the long term. Finally, the encryption protocol type and strength parameters of the preferred network service are extracted, such as using the TLS1.3 protocol with a key length of 256 bits, as the input conditions for the subsequent dynamic generation of encryption keys.

[0022] S103. Using a preset encryption algorithm model, based on the encryption protocol type and strength parameters of the optimal network service, a random number generator is used to generate a random string of specified length as an initial encryption key, and a complexity judgment is performed on the random string until an encryption key that meets the preset complexity requirement is generated.

[0023] According to the threat intelligence analysis report, determine whether the current network service supports advanced encryption protocols. If it does, extract its encryption protocol type and strength parameters. If it does not, screen other network services. Combined with the threat level in the threat intelligence analysis report, determine the optimal network service and obtain its encryption protocol type and strength parameters. Use the preset encryption algorithm model. If the encryption protocol type is symmetric encryption, use the AES algorithm. If it is asymmetric encryption, use the RSA algorithm. Determine the length of the encryption key based on the strength parameters of the encryption protocol. Generate a random string of specified length as the initial encryption key through a random number generator. Perform a complexity judgment on the initial encryption key and determine whether it meets the complexity requirements based on the preset complexity threshold. If the complexity does not meet the requirements, return to step 5 and regenerate the initial encryption key until the complexity requirements are met. The encryption key that meets the complexity requirements is used as the final dynamic encryption key for data encryption transmission. Bind the generated encryption key to the transmission path to form a new protection scheme, and update it to the network service configuration in real time.

[0024] Specifically, the encryption protocol support of the network service is judged according to the threat intelligence analysis report. If it supports advanced encryption protocols such as TLS1.3, its encryption protocol type (such as AES, RSA, etc.) and strength parameters (such as key length 128 bits, 256 bits, etc.) are extracted. Combined with the threat level (such as high, medium, and low) in the threat intelligence, the optimal network service is determined through a comprehensive scoring model, such as the HTTPS service with the highest score. For the encryption protocol type of the service, if it is symmetric encryption, the AES algorithm is used, and if it is asymmetric encryption, the RSA algorithm is used. According to the protocol strength parameters, the key length is determined, such as 128 bits, 256 bits, etc. A secure random number generator is used to generate a random string consisting of letters, numbers, and special characters as the initial key according to the specified length. The key complexity evaluation function is used to calculate the information entropy of the key to determine whether it meets the preset complexity threshold (such as 3.5). If not, it is returned and regenerated until the requirement is met. The key that meets the complexity is used as the final dynamic encryption key and is bound to the data transmission path (such as source IP, destination IP, port, etc.) to form a new data protection solution. Update the solution to the network service configuration in real time, such as dynamic negotiation during the TLS handshake phase.

[0025] S104, obtaining the topological structure and node information of the network transmission path, constructing a transmission path model according to the logical relationship between nodes and the physical link status, and binding the encryption key with the transmission path model to form a key-path mapping relationship table.

[0026] Obtain the topological structure and node information of the network transmission path, and build a transmission path model based on the logical relationship between nodes and the physical link status. If the logical relationship between nodes is a master-slave relationship, set the master-slave attribute in the model; if the physical link status is interrupted, mark the interruption status in the model. Calculate the security score of each transmission path based on the node attributes and link status in the transmission path model. Use the weighted average algorithm to assign weights to indicators such as node credibility and link stability to obtain a comprehensive security score. Bind the encryption key to the transmission path model to form a key-path mapping relationship table. Use the starting node and the end node of the transmission path as indexes to store the corresponding encryption key and build a mapping relationship. According to the source node and the target node of the data transmission request, query the corresponding encryption key and the optimal transmission path in the key-path mapping relationship table. If the query result is empty, regenerate the key and build a new mapping relationship. During the data transmission process, monitor the network link quality and node status in real time. Use the heartbeat mechanism and anomaly detection algorithm to determine the link interruption and node failure. If the link quality is detected to be degraded or the node status is abnormal, the path switching mechanism is triggered. According to the key-path mapping relationship table, select the optimal backup transmission path and update the routing configuration. Dynamically adjust the key update cycle and path optimization strategy according to changes in the network environment and attack threats. Use machine learning algorithms to obtain the optimal parameter combination through historical data training to achieve adaptive optimization. Synchronize the updated key-path mapping relationship to the network service configuration center and send it to each node. Update the node's routing table and encryption key in real time through the configuration management interface. Continuously monitor the security and efficiency of data transmission, collect network status data and abnormal logs as optimization input. Through big data analysis and visualization technology, realize network security situation awareness and early warning, and continuously improve the overall protection level.

[0027] Specifically, when obtaining the network topology, the neighbor table and link status information of the network device can be queried through the SNMP protocol to construct a network topology diagram containing 1000 nodes and 2500 links. According to the OSPF routing calculation results, the master-slave relationship and link interruption status between nodes are determined and marked in the model. Then, the weighted average algorithm is used to calculate the security score of the transmission path, and the node credibility weight is set to 0.6 and the link stability weight is set to 0.4 to obtain the comprehensive score of each path. Then, the 128-bit AES encryption key is bound to the optimal transmission path, and the key-path mapping relationship is stored in the hash table with the source IP address and the destination IP address as the index. During data transmission, the encryption key and routing path are quickly obtained by looking up the table. During the transmission process, a heartbeat packet is sent every 10ms, and the link interruption is judged by the timeout retransmission mechanism; key indicators such as node CPU and memory are collected every 1s, and node failure is judged by the anomaly detection algorithm. Once an anomaly is found, it is immediately switched to the backup path and the node routing table is updated. At the same time, the reinforcement learning algorithm is used to dynamically adjust the key update cycle according to the reward value of the network status, seeking the optimal balance between security and performance. Finally, by configuring the delivery interface, the updated key-path mapping relationship is synchronized to each node to achieve real-time updates of routing and encryption strategies. The system continuously monitors the network operation status, collects data such as traffic and latency, identifies potential threats through cluster analysis algorithms, realizes real-time warning and adaptive optimization, and continuously improves the level of network security protection.

[0028] S105. Dynamically select an optimal transmission path for the data transmission request, obtain a corresponding encryption key from the key-path mapping relationship table, and use the key to encrypt the transmission data.

[0029] Obtain the topological structure and node information of the network transmission path, and build a transmission path model based on the logical relationship between nodes and the physical link status. Generate a set of encryption keys through the key generation algorithm. The key length is determined according to the preset security level, and the initial seed is obtained by a random number generator. Bind the generated encryption key to the transmission path model to form a key-path mapping relationship table, which is stored in a secure database. For different data transmission requests, dynamically select the optimal transmission path and obtain the corresponding encryption key from the key-path mapping relationship table. Use the obtained encryption key to encrypt the transmission data to ensure the confidentiality of the data during transmission. During the data transmission process, monitor the network link quality and node status in real time to determine whether abnormal changes occur. If abnormal changes in the network environment are detected, the path switching and key update mechanism are triggered, and the transmission path and encryption key are dynamically adjusted according to the changes. The network environment changes and attack threats are analyzed through machine learning algorithms, and the key update cycle and path optimization strategy are dynamically adjusted to achieve adaptive optimization. The updated key-path mapping relationship is synchronized to the network service configuration in real time to ensure the efficiency and security of encrypted communication and improve the overall protection level.

[0030] Specifically, the network topology is first obtained, including 50 nodes and 100 links between them. The transmission path model is constructed based on indicators such as the average delay between nodes is less than 10ms and the packet loss rate is less than 0.1%. Then the SHA-256 algorithm is used to generate a 256-bit encryption key, and a 128-bit initial seed is obtained using a hardware random number generator. The key is then bound to the path model to form a hash table containing 1000 mapping relationships and stored. For each data transmission request, the Dijkstra algorithm is used to select the path with the smallest delay in the path model and obtain the corresponding encryption key. The AES-256 algorithm is used to encrypt the transmission data using the selected key. During the transmission process, the link RTT and node CPU utilization are detected every 100ms. If the RTT exceeds 50ms or the CPU utilization is higher than 80%, the path switching is triggered, and the encryption key is updated through the key derivation function. At the same time, the support vector machine algorithm is used to analyze the 100 environmental changes in the last hour, and the key update cycle is dynamically adjusted to 5-60 minutes and the delay weight coefficient in the path selection strategy. Finally, the updated 1,000 key-path mapping relationships are synchronized to the network service configuration, and the average synchronization delay is controlled within 100ms to ensure the real-time and security of encrypted communications.

[0031] S106. Monitor the data transmission process in real time through a preset monitoring module, obtain transmission behavior data, compare it with a preset abnormal behavior feature library, and trigger a protection scheme update mechanism if an abnormality exists.

[0032] The behavior data in the data transmission process is obtained in real time through the preset monitoring module, and the obtained behavior data is compared with the pre-established abnormal behavior feature library to determine whether there is abnormal behavior. If the comparison result shows that there is abnormal behavior, the protection scheme update mechanism is triggered, and the corresponding protection scheme is selected from the preset protection scheme library according to the type and severity of the abnormal behavior. The selected protection scheme is compared with the currently used protection scheme to determine whether it needs to be updated. If it needs to be updated, the selected protection scheme is used as the new current protection scheme to replace the original scheme. According to the updated protection scheme, the monitoring rules and abnormal judgment thresholds of the monitoring module are adjusted to improve the monitoring accuracy and response speed, and the data transmission process is continued to be monitored in real time. If the monitoring results show that the abnormal behavior persists, the latest real-time threat data is obtained from the threat intelligence source through the API interface to update the local threat intelligence library. The newly acquired threat intelligence data is preprocessed, key features are extracted, converted into a format acceptable to the machine learning model, and input into the previously trained model for abnormal behavior detection and risk assessment. According to the abnormal behavior detection results and risk levels output by the model, combined with the preset protection rule library, an optimized new protection scheme is automatically generated and applied to the system to block or restrict suspicious behaviors. Continuously monitor the implementation effect of the new protection plan, dynamically adjust the plan parameters according to the feedback results, and update the adjusted plan to the network service configuration in real time and bind it to the transmission path. Apply the finalized protection plan to the entire life cycle of data transmission and storage, and ensure the continuous optimization of data security through dynamic encryption and real-time monitoring to effectively respond to ever-changing network threats.

[0033] Specifically, the monitoring module obtains the source IP, destination IP, port, protocol and other behavioral data of data transmission every second, extracts the key feature vectors, and calculates the Euclidean distance with thousands of rules in the abnormal behavior feature library. If the minimum distance is less than the preset threshold of 0.1, it is judged as abnormal. Once an abnormality is found, the system immediately selects the best solution from the protection solution library containing 50 candidate solutions based on the type of abnormal behavior and risk score using the decision tree algorithm. The new solution is compared with the current solution item by item. If more than 30% of the parameters are different, an update is triggered and the new solution is issued to replace the original configuration. At the same time, according to the new solution, the parameters such as data sampling frequency, feature extraction algorithm and abnormal judgment threshold in the monitoring module are automatically adjusted to improve the monitoring performance. If the abnormality continues to occur for 3 consecutive cycles, the system obtains external threat intelligence in real time at intervals of 5 seconds through the API interface and updates the local threat library. The newly added intelligence data is standardized and discretized, converted into sparse vectors using One-Hot encoding, and input into the pre-trained LightGBM model for anomaly detection and risk assessment to generate a confidence score. Based on the comprehensive model results and expert rule base, the system automatically makes decisions to generate targeted new protection solutions, such as banning IP addresses, limiting the number of sessions, etc., and deploys them to the protection gateway in real time. The system continuously verifies the effectiveness of the new solution, optimizes online based on the reinforcement learning algorithm, continuously improves the protection performance, and synchronizes with the transmission link in real time. Finally, the optimization solution is applied to the entire data life cycle, including the source, transmission channel, and destination, to build a national secret SM4 dynamic encryption channel, and deploy intelligent security agents for real-time monitoring to provide reliable protection for data security.

[0034] S107. According to the type and severity of the abnormal behavior, a corresponding solution is selected from a preset protection solution library for updating, and the monitoring rules and abnormal judgment threshold of the monitoring module are adjusted.

[0035] The generated steps are as follows: According to the abnormal behavior data obtained by the monitoring module, the type and severity of the abnormal behavior are judged, and a protection scheme matching the abnormal behavior is selected from the preset protection scheme library. The selected protection scheme is compared with the currently used protection scheme, and the difference between the two schemes is determined by the similarity calculation algorithm. If the difference exceeds the preset threshold, the protection scheme update process is triggered. The key parameters in the selected protection scheme are extracted, including encryption algorithm, key length, transmission path, etc., and the updated protection scheme configuration file is generated according to these parameters. The updated protection scheme configuration file is sent to the network service node, and the new protection scheme is parsed by the configuration file parsing module, and loaded into each link of data transmission and storage. According to the updated protection scheme, the monitoring rules of the monitoring module are adjusted, including the judgment conditions of abnormal behavior, data collection frequency, etc., to improve the accuracy and real-time performance of monitoring. The abnormal judgment threshold of the monitoring module is dynamically optimized by using a machine learning algorithm. By analyzing the historical abnormal behavior data, the threshold parameters are automatically learned and adjusted to improve the detection rate of abnormal behavior. During the data transmission process, network behavior data is collected in real time and transmitted to the monitoring module for analysis. The updated monitoring rules and abnormal judgment thresholds are used to quickly identify and respond to abnormal behaviors. If abnormal behaviors are detected to continue to occur, the threat intelligence update mechanism is triggered, and the latest threat data is obtained through the API interface and integrated into the local threat intelligence library to optimize the protection plan. Based on the updated threat intelligence, the effectiveness of the current protection plan is re-evaluated. If blind spots or weaknesses in protection are found, targeted patches are automatically generated to dynamically patch the protection plan to ensure that it can continue to respond to the latest security threats.

[0036] Specifically, when the monitoring module detects abnormal behavior during data transmission, such as the frequency of data packet transmission suddenly increases to 1,000 per second, far exceeding the normal range, it is determined to be a DDoS attack, and its severity is high. The system automatically selects encryption scheme A for DDoS from the preset protection scheme library, compares it with the currently used scheme B, and calculates the difference between the two through the cosine similarity algorithm to be 0.7, which exceeds the preset update threshold of 0.5, thus triggering the update of the protection scheme. The system extracts the key parameters of scheme A, upgrades the AES encryption algorithm to AES-256, increases the key length to 2048 bits, adjusts the transmission path to a P2P network, generates a new configuration file and sends it to each node. At the same time, the abnormal judgment condition of the monitoring module is adjusted to a packet frequency greater than 500 per second and a duration of more than 5 minutes, and the data collection frequency is increased to once per second. Through the support vector machine SVM algorithm, combined with the abnormal behavior data of the past week, the abnormal judgment threshold is dynamically adjusted to 800 packets per second. During the data transmission process, network behavior data is transmitted to the monitoring module in real time. Through the updated rules and thresholds, DDoS anomalies are identified within 1 second and protective measures are initiated. Since the abnormal behavior continued for 5 minutes, the system obtained the latest DDoS attack fingerprint library through the API interface, integrated it into the local threat intelligence library, re-evaluated the protection plan, and found that the current P2P transmission path is still at risk of attack. Therefore, a path optimization patch is automatically generated to switch the transmission path to the backup VPN dedicated line, further improving the protection capability, and ultimately effectively curbing the impact of DDoS attacks on the business.

[0037] S108. If monitoring finds that abnormal behavior persists, the latest network security threat intelligence is obtained again, and the above steps are repeated to generate a new dynamic protection plan, which is applied to the entire data transmission process to continuously optimize data security protection measures.

[0038] Determine whether there is persistent abnormal behavior based on the monitoring results. If so, trigger the subsequent steps; otherwise, continue monitoring. Obtain the latest real-time threat data from the threat intelligence source through the API interface and update the local threat intelligence library. Preprocess the newly acquired threat intelligence data, extract key features, and convert them into a format acceptable to the model. Input the preprocessed new data into the previously trained machine learning model for abnormal behavior detection and risk assessment. Determine whether a new protection plan needs to be generated based on the abnormal behavior detection results and risk level output by the model. If the protection plan needs to be updated, automatically generate an optimized protection plan based on the abnormal behavior characteristics and risk level, combined with the preset protection rule library. Apply the newly generated protection plan to the system, block or restrict suspicious behavior, and continuously monitor the execution effect of the plan. According to the feedback results of the protection plan execution, dynamically adjust the plan parameters and optimize data security protection measures. Apply the optimized protection plan to the entire life cycle of data transmission and storage to achieve continuous adaptive protection against network threats.

[0039] Specifically, the abnormal behavior in the data transmission process is monitored in real time through the preset monitoring module, and the abnormal detection algorithm based on rules and machine learning is used to compare the behavior data in the data transmission process with the data in the abnormal behavior feature library. If the similarity exceeds the threshold (such as 80%), it is determined to be abnormal behavior. When persistent abnormal behavior is detected, the system automatically obtains the latest threat data such as malware, phishing websites, botnets, etc. from threat intelligence sources such as VirusTotal through the API interface, and updates the local threat intelligence library. Then, the acquired threat data is feature extracted and vectorized, and converted into a format suitable for machine learning model input. The processed new threat data is input into the pre-trained anomaly detection model (such as support vector machine SVM or random forest), and the current network behavior is detected and risk scored. If the abnormal probability exceeds 95% or the risk score is higher than 8 points (out of 10 points), the protection plan update process is triggered. According to the abnormal behavior type and threat level, the system selects the corresponding security protection measures (such as encryption algorithm, key length, transmission protocol, etc.) from the preset protection strategy library, and automatically generates an updated data security protection plan. The new protection scheme is applied to all aspects of data transmission, blocking and isolating suspicious behaviors in real time, and continuously monitoring the implementation effect of the scheme. Based on feedback such as the occurrence of data security incidents and the protection success rate, reinforcement learning algorithms (such as Q-Learning) are used to dynamically optimize and adjust the protection scheme, ultimately forming an adaptive data security protection system that can intelligently respond to ever-changing network security threats.

[0040] It should be noted that the above examples are only some specific embodiments of the present invention. Obviously, the present invention is not limited to the above embodiments, and there are many variations. All variations that can be directly derived or associated with the content disclosed by a person skilled in the art should be considered as the protection scope of the present invention.

Claims

1. A method for integrating optimal network services and dynamically generating protection solutions, characterized in that: include: Acquire threat intelligence data, and determine whether the current network service supports a preset encryption protocol according to the threat intelligence data; if so, determine the current network service as a candidate network service; if not, screen other network services; Extracting the encryption protocol type and strength parameter of the candidate network service, and determining the target network service in combination with the threat level in the threat intelligence data; Generate an encryption key based on the encryption protocol type and strength parameters of the target network service; Binding the encryption key to the transmission path to form a protection scheme; Abnormal behavior during data transmission is monitored, and the protection scheme is updated if abnormal behavior is detected.

2. The method according to claim 1, characterized in that The acquiring of threat intelligence data and determining whether the current network service supports a preset encryption protocol according to the threat intelligence data include: Acquire multi-source threat intelligence data through an interface, integrate and clean the multi-source threat intelligence data, and form a threat intelligence report in a unified format; Parsing the threat intelligence report to extract network service information, where the network service information includes at least an address, a port, and a protocol type of the network service; The network service information is compared with the preset encryption protocol list to determine whether the current network service supports the encryption protocols in the preset encryption protocol list; if the current network service supports at least one encryption protocol in the preset encryption protocol list, then it is determined that the current network service supports the preset encryption protocol; otherwise, it is determined that the current network service does not support the preset encryption protocol.

3. The method according to claim 1, characterized in that The extracting the encryption protocol type and strength parameter of the candidate network service and determining the target network service in combination with the threat level in the threat intelligence data includes: Traversing the candidate network service list, for each candidate network service, extracting the encryption protocol type supported by the candidate network service and the strength parameter corresponding to each encryption protocol; Extracting threat level information from the threat intelligence data, and mapping the threat level information into a numerical threat level score according to a preset threat level classification standard; According to the encryption protocol type and strength parameters, a network service security assessment model is constructed, and a preset assessment algorithm is used to calculate the security score of each candidate network service; The threat level score and the security score are combined and a weighted calculation method is adopted to obtain a comprehensive security score for each candidate network service, and the candidate network service with the highest comprehensive security score is selected as the target network service.

4. The method according to claim 1, characterized in that The generating of an encryption key based on the encryption protocol type and strength parameter of the target network service includes: According to the encryption protocol type of the target network service, select a corresponding key generation algorithm. If the encryption protocol type is symmetric encryption, select a first key generation algorithm; if the encryption protocol type is asymmetric encryption, select a second key generation algorithm; Determining a key length according to an encryption protocol strength parameter of the target network service, wherein the key length is positively correlated with the encryption protocol strength parameter; Generate an initial random number by using a hardware random number generator, and generate an initial key based on the initial random number and the key generation algorithm; A complexity check is performed on the initial key to determine whether the initial key meets the preset complexity requirement. If not, the initial key is regenerated until the generated initial key meets the complexity requirement. The initial key that meets the complexity requirement is used as the encryption key.

5. The method according to claim 1, characterized in that The step of binding the encryption key to the transmission path to form a protection scheme includes: Acquire network topology information, and construct a network transmission path model according to the network topology information, wherein the network transmission path model includes a plurality of network nodes and links connecting the network nodes; Associating the encryption key with the network nodes and links in the network transmission path model to form a key-path mapping relationship; According to different data transmission requests, select a corresponding transmission path from the network transmission path model, and distribute the encryption key to the network nodes and links on the transmission path; The encryption key, the transmission path, and the corresponding security configuration information are combined into a protection scheme, and the protection scheme is stored in a configuration database.

6. The method according to claim 1, characterized in that The monitoring of abnormal behavior during data transmission and updating the protection scheme if abnormal behavior is detected include: Acquire data packets in the data transmission process by means of bypass interception, parse the data packets, and extract characteristic information of the data packets; Compare the data packet feature information with a preset abnormal behavior feature library to determine whether there is abnormal behavior, and if at least one data packet feature information matches a feature in the abnormal behavior feature library, then determine that there is abnormal behavior; When abnormal behavior is detected, a protection scheme update mechanism is triggered, and a new protection scheme is selected from a protection scheme library according to the type and level of the abnormal behavior; The new protection scheme is sent to the network device to replace the original protection scheme.

7. The method according to claim 6, characterized in that The selecting a new protection scheme from a protection scheme library according to the type and level of the abnormal behavior includes: Determine the urgency of updating the protection scheme according to the type and level of the abnormal behavior; If the level of the abnormal behavior is a high-risk level, then select the protection solution with the fastest update speed; If the level of the abnormal behavior is a medium-risk level, a balance is made between update speed and security, and a protection solution with faster update speed and higher security is selected; If the level of the abnormal behavior is a low-risk level, the most secure protection plan is selected. When updating the protection plan, a protection plan with a specific protection effect for the type of abnormal behavior is selected according to the type of abnormal behavior. After updating the protection plan, the new protection plan is verified to ensure that it can protect the detected abnormal behavior.

Citation Information

Patent Citations

  • Power Internet of Things data security protection method

    CN116827680A

  • Gateway intelligent arrangement method and system based on zero-trust network

    CN117118660A

  • Network information security evaluation test system

    CN117527348A

  • Efficient network security protection method and system and storage medium

    CN118074951A

  • Information processing system and encryption communication method

    JP2017139698A

Cited By

  • Trusted cloud security confidential privacy level product service system and method

    CN120342734A

  • Video conference system network inspection method and device based on multiple protocols

    CN120856884A