Computer network security situation awareness system and method

By using quantum entanglement pairs and antigen-antibody matching algorithms in the network security situation awareness system, the problems of low efficiency and insufficient robustness in the existing technology are solved, real-time perception and dynamic defense of network attacks are realized, and the response speed and adaptability of defense strategies are improved.

CN119995874AInactive Publication Date: 2025-05-13BEIJING MUXUE COMPUTER TECHNOLOGY CO LTD
View PDF 0 Cites 6 Cited by

Patent Information

Application Number
CN202510292541.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network security situational awareness technologies are inefficient in processing large-scale data and high-dimensional threat analysis, which is difficult to meet real-time requirements, and are not robust in multi-source data fusion and dynamic attack detection, making it difficult to accurately capture hidden attack paths.

Method used

The quantum entanglement pairs are allocated to network nodes through the quantum key distribution center, an initial quantum trust vector is generated, and the entanglement entropy changes of the node's quantum states are monitored in real time. A dynamic gene library is generated by combining the antigen-antibody matching algorithm to establish a mapping relationship table between the antigen characteristic vector and the antibody defense strategy, and real-time perception and dynamic defense of network attacks are realized.

Benefits of technology

It improves the response speed and accuracy to potential threats, optimizes the diversity and adaptability of defense strategies, significantly improves the network's ability to fight against unknown attacks, and achieves efficient and accurate network security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995874A_ABST
    Figure CN119995874A_ABST
Patent Text Reader

Abstract

The invention discloses a computer network security situation awareness system and method, and relates to the technical field of computer network security, and the method comprises the steps: generating a dynamic gene pool through an antigen-antibody matching algorithm based on an initial quantum trust vector, and building a mapping relation table of an antigen feature vector and an antibody defense strategy; triggering a quantum alarm according to an entanglement entropy mutation event in the real-time quantum state flow data, matching a biological antibody strategy corresponding to a current network attack feature based on a mapping relation table, and fusing the quantum alarm and the biological alarm to generate an attack path topological graph; the network security situation is perceived by analyzing the quantum state change of the abnormal node ID and combining an attack path topological graph and a dynamic gene pool. Quantum entanglement pairs are distributed to network nodes through the quantum key distribution center, and initial quantum trust vectors are generated, so that the unknown attack resisting capability of the network is remarkably improved, and efficient and accurate network security situation awareness is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network security, and in particular to a computer network security situation awareness system and method. Background Art

[0002] The rapid development of computer networks has promoted the progress of the information society, but network security threats have also intensified, becoming a key issue in the field of technology. Traditional network security technology has evolved from early firewalls and intrusion detection systems to today's situational awareness technology that integrates machine learning and big data. In recent years, the frequent occurrence of complex attacks such as distributed denial of service attacks (DDoS) and advanced persistent threats (APT) has attracted much attention to network security situational awareness, which aims to strengthen defense by real-time monitoring of network status, identifying anomalies and predicting threat trends. The rise of quantum communication technology has injected new vitality into this field. Quantum key distribution (QKD) has shown its potential in communication security based on the principles of quantum mechanics. However, existing research has mostly focused on the underlying quantum communication or the optimization of traditional algorithms, and has failed to fully utilize the combination of quantum characteristics and bio-inspired methods.

[0003] Despite the progress made in network security situational awareness technology, there are still deficiencies in responding to new types of attacks. On the one hand, traditional systems are limited by classical computing capabilities, and are inefficient when processing large-scale data and high-dimensional threat analysis, making it difficult to meet real-time requirements; on the other hand, existing methods are not robust enough in multi-source data fusion and dynamic attack detection, making it difficult to accurately capture hidden attack paths. These shortcomings limit the performance of the system in complex environments. Our invention combines real-time monitoring of quantum entangled states with dynamic response of bio-inspired algorithms, aiming to improve the accuracy and speed of situational awareness and open up new directions for network security technology. Summary of the invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a computer network security situation awareness method to solve the problems of insufficient real-time performance and accurate perception of high-dimensional dynamic attacks.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0007] In the first aspect, the present invention provides a computer network security situation awareness method, which includes allocating quantum entangled pairs to each node in the network through a quantum key distribution center, generating an initial quantum trust vector according to the node quantum state density matrix, and monitoring the entanglement entropy changes of the node quantum state in real time, and outputting real-time quantum state flow data; based on the initial quantum trust vector, a dynamic gene library is generated through an antigen-antibody matching algorithm, and a mapping relationship table between antigen feature vectors and antibody defense strategies is established; a quantum alarm is triggered according to an entanglement entropy mutation event in the real-time quantum state flow data, and the biological antibody strategy corresponding to the current network attack feature is matched based on the mapping relationship table, and the quantum alarm and the biological alarm are integrated to generate an attack path topology map; by analyzing the quantum state changes of abnormal node IDs, combined with the attack path topology map and the dynamic gene library, the network security situation is perceived.

[0008] As a preferred solution of the computer network security situation awareness method of the present invention, wherein: the quantum key distribution center is used to distribute quantum entangled pairs to each node in the network, and the initial quantum trust vector is generated according to the node quantum state density matrix. The specific steps are as follows:

[0009] Using the network topology diagram, we analyze the connection relationship and communication requirements between nodes in the network through graph theory algorithms, and identify node pairs with high frequency communication in combination with routing protocols;

[0010] Entangled photon pairs are generated and distributed to corresponding nodes through quantum light sources, and quantum state tomography technology is used to reconstruct the node quantum state density matrix to calculate the purity value and entanglement entropy of the quantum state of each node in the network;

[0011] The purity value and entanglement entropy of the quantum state of each node in the network are combined to calculate the trust value of each node in the network, and then arranged and combined into an initial quantum trust vector through a vectorization method.

[0012] As a preferred solution of the computer network security situation awareness method of the present invention, wherein: the entanglement entropy change of the node quantum state is monitored in real time, and real-time quantum state flow data is output. The specific steps are as follows:

[0013] Through the sliding window method, the average value and standard deviation of the entanglement entropy of the historical quantum state of each node in the network are calculated within the time window, and the upper limit threshold Θ and the lower limit threshold υ of the quantum state anomaly are set;

[0014] Based on the entanglement entropy E(ρ i ), the security of nodes in the network is evaluated through the quantum state anomaly upper limit threshold Θ and the quantum state anomaly lower limit threshold υ;

[0015] Based on the security assessment results of nodes in the network, quantum state flow data is obtained through data formatting methods and real-time recording.

[0016] As a preferred solution of the computer network security situation awareness method of the present invention, wherein: based on the initial quantum trust vector, a dynamic gene library is generated by an antigen-antibody matching algorithm, and the specific steps are as follows:

[0017] Based on the initial quantum trust vector, combined with network topology information and network attack behavior characteristics, an antigen feature vector is constructed;

[0018] Based on the correspondence between network attack behavior characteristics and defense strategies, a dynamic response strategy for specific attack behaviors is defined to obtain an antibody feature vector;

[0019] The similarity between the antigen feature vector and the antibody feature vector is calculated by using the antigen-antibody matching algorithm to obtain the antigen-antibody similarity value;

[0020] Based on the historical antigen-antibody similarity values, the matching threshold Б is set through machine learning analysis, and the matching degree is evaluated based on the antigen-antibody similarity value. The antibody feature vectors that are successfully matched are collected, and a dynamic gene library is generated through dynamic updating and optimization.

[0021] As a preferred solution of the computer network security situation awareness method of the present invention, wherein: the mapping relationship table between antigen feature vectors and antibody defense strategies is established, and the specific steps are as follows:

[0022] Through the feature vector decoding method, the antibody feature vectors that successfully matched in the dynamic gene library are converted into antibody defense strategies;

[0023] The correspondence between antigen feature vectors and antibody defense strategies is analyzed through feature vector matching and rule mapping methods, and the correspondence between antigen feature vectors and antibody defense strategies is organized into a mapping relationship table through data classification and structuring methods.

[0024] As a preferred solution of the computer network security situation awareness method of the present invention, the specific steps of integrating quantum alarms and biological alarms to generate an attack path topology map are as follows:

[0025] Monitor the real-time quantum state flow data within the time window through a sliding window and calculate the rate of change of entanglement entropy;

[0026] Based on the entanglement entropy change rate ΔE(ρ i ), through the change rate threshold δ, purity anomaly threshold K and trust safety threshold J, the entanglement entropy mutation event in the quantum state flow data is determined, a quantum alarm is generated, and a quantum threat value is obtained;

[0027] Based on quantum alarms, we combine the network attack feature matching biological antibody strategy to generate biological alarms and obtain biological threat values;

[0028] Based on the quantum threat value and the biological threat value, a comprehensive threat value is obtained through a weighted fusion method;

[0029] The quantum threat value, biological threat value and comprehensive threat value are organized into a matrix form, a real-time threat level matrix is ​​constructed, and then analyzed to obtain the abnormal node ID;

[0030] Combining routing protocols and topology information, the Dijkstra algorithm is used in combination with the tracing algorithm to trace back the attack path, mark the target nodes and links in the path, and dynamically generate an attack path topology map.

[0031] As a preferred solution of the computer network security situation awareness method of the present invention, wherein: the network security situation is perceived by analyzing the quantum state changes of the abnormal node ID, combining the attack path topology map and the dynamic gene library, and the specific steps are as follows:

[0032] Through the sliding window method, the entanglement entropy historical data of abnormal nodes is extracted, the mutation frequency and mutation amplitude of the entanglement entropy historical data are calculated, and the attack characteristics of abnormal nodes are analyzed by combining the purity value and trust value of abnormal nodes;

[0033] Through the attack path topology map, analyze the location of abnormal nodes, track the attack path, and obtain the scope and impact of network attacks;

[0034] Based on the attack characteristics of abnormal nodes, combined with the dynamic gene library, the network attack type is perceived, and the comprehensive mapping relationship table, network attack scope and impact are used to gain insight into the network attack intention and overall security situation.

[0035] In a second aspect, the present invention provides a computer network security situation awareness system, including a quantum state real-time monitoring module, a dynamic gene library construction module, a threat detection module and a security situation awareness module;

[0036] The quantum state real-time monitoring module is used to distribute quantum entangled pairs to each node in the network through the quantum key distribution center, generate the initial quantum trust vector according to the node quantum state density matrix, and monitor the entanglement entropy changes of the node quantum state in real time, and output real-time quantum state flow data;

[0037] Dynamic gene library construction module, which is used to generate a dynamic gene library based on the initial quantum trust vector through the antigen-antibody matching algorithm, and establish a mapping relationship table between the antigen feature vector and the antibody defense strategy;

[0038] The threat detection module is used to trigger quantum alarms based on entanglement entropy mutation events in real-time quantum state flow data, and match the biological antibody strategy corresponding to the current network attack characteristics based on the mapping relationship table, and integrate quantum alarms and biological alarms to generate an attack path topology map;

[0039] The security situation awareness module is used to perceive the network security situation by analyzing the quantum state changes of abnormal node IDs, combining the attack path topology map and dynamic gene library.

[0040] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the computer network security situation awareness method as described in the first aspect of the present invention is implemented.

[0041] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the computer network security situation awareness method as described in the first aspect of the present invention is implemented.

[0042] The beneficial effects of the present invention are as follows: quantum entangled pairs are allocated to network nodes and initial quantum trust vectors are generated through a quantum key distribution center, the entanglement entropy changes of node quantum states are monitored in real time, a dynamic gene library is generated in combination with an antigen-antibody matching algorithm, and a mapping relationship table is established, thereby realizing real-time perception and dynamic defense against network attacks, ensuring the security of network communications through quantum technology, and enhancing the trust basis between nodes; through real-time monitoring and antigen-antibody matching mechanisms, the response speed and accuracy to potential threats are improved; through dynamic gene libraries and mapping relationship tables, the diversity and adaptability of defense strategies are optimized, the ability of the network to resist unknown attacks is significantly improved, and efficient and accurate network security situation awareness is realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0044] Figure 1 This is a flowchart of the computer network security situation awareness method in Example 1.

[0045] Figure 2 This is a schematic diagram of the computer network security situation awareness system in Example 1.

[0046] Figure 3 This is a flow chart for constructing the dynamic gene library in Example 1.

[0047] Figure 4 This is a flow chart of the fusion of quantum alarm and biological alarm in Example 1. DETAILED DESCRIPTION

[0048] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0049] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0050] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0051] Example 1, reference Figure 1 and Figure 2 , which is the first embodiment of the present invention, and provides a computer network security situation awareness method, comprising the following steps:

[0052] S1. Allocate quantum entangled pairs to each node in the network through the quantum key distribution center, and generate an initial quantum trust vector based on the node quantum state density matrix.

[0053] Using the network topology diagram, the connection relationship and communication requirements between nodes in the network are analyzed through graph theory algorithms, and the node pairs with high frequency communication are identified in combination with the routing protocol.

[0054] It should be explained that the connection information (such as IP address, port, link status, etc.) and communication data (such as data packet flow, transmission frequency, etc.) of all nodes in the network are collected, and the network topology diagram is constructed using graph theory methods;

[0055] Through graph theory algorithms (such as Dijkstra algorithm, Floyd-Warshall algorithm or community detection algorithm), the communication paths and traffic distribution between nodes are analyzed, key nodes (such as central nodes or bridge nodes) and high-load links (such as links with frequent communication or high bandwidth occupancy) are identified, and the traffic statistics and routing table data in the routing protocol (such as OSPF or BGP) are combined to screen out node pairs with frequent communication.

[0056] Entangled photon pairs are generated and distributed to corresponding nodes through quantum light sources, and quantum state tomography technology is used to reconstruct the node quantum state density matrix to calculate the purity value and entanglement entropy of the quantum state of each node in the network.

[0057] The details are as follows:

[0058] Entangled photon pairs are generated using quantum light sources, and the photons are transmitted to nodes A and B through optical fiber links for matching, obtaining node quantum states, which are then reconstructed using quantum state tomography technology to generate node quantum state density matrices.

[0059] It should also be explained that the node quantum state density matrix is ​​generated through quantum state tomography reconstruction, specifically:

[0060] Use quantum light sources to distribute entangled photon pairs to network nodes, and use quantum measurement equipment to measure the quantum states of nodes multiple times to obtain projection measurement data. Based on the projection measurement data, use mathematical optimization methods such as maximum likelihood estimation or least squares method to reconstruct the node quantum state density matrix.

[0061] It should also be explained that the purity value and entanglement entropy of the quantum state of each node in the calculation network are as follows:

[0062] Based on the node quantum state density matrix, the purity value of the quantum state of each node in the network is calculated, and the expression is:

[0063]

[0064] Among them, P i is the purity value of the quantum state of the ith node, H is the trace of the node quantum state density matrix, ρ i is the quantum state density matrix of the i-th node, i is the index variable of the node quantum state;

[0065] Based on the node quantum state density matrix, the entanglement entropy of the quantum state of each node in the network is calculated, and the expression is:

[0066] E(ρ i )=-H(ρ i logρ i );

[0067] Among them, E(ρ i ) is the entanglement entropy of the quantum state of the i-th node.

[0068] The purity value and entanglement entropy of the quantum state of each node in the network are combined to calculate the trust value of each node in the network, and then arranged and combined into an initial quantum trust vector through a vectorization method.

[0069] The details are as follows:

[0070] Calculate the trust value of each node in the network, the expression is:

[0071] T j =P i ·exp(-λ·E(ρ i ));

[0072] Among them, Ti is the trust value of the jth node, λ is the adjustment parameter that controls the influence of entanglement entropy on the trust value, and j is the index variable of the node;

[0073] It should also be explained that the initial quantum trust vector is arranged and combined in sequence through the vectorization method, specifically:

[0074] All nodes in the network are sorted according to their identifiers (such as IP addresses or numbers), and the trust values ​​of each node are extracted in turn. The trust values ​​are arranged into a numerical sequence according to the order of the nodes, and the sequence is encapsulated into a vector form to generate an initial quantum trust vector F = [F1, F2, ..., F n ].

[0075] S2, and monitor the entanglement entropy changes of the node quantum state in real time, and output real-time quantum state flow data.

[0076] Through the sliding window method, the average value and standard deviation of the entanglement entropy of the historical quantum state of each node in the network are calculated within the time window, and the upper limit threshold Θ and the lower limit threshold υ of the quantum state anomaly are set.

[0077] Based on the entanglement entropy E(ρ i ), the security of nodes in the network is evaluated through the quantum state anomaly upper limit threshold Θ and the quantum state anomaly lower limit threshold υ.

[0078] The details are as follows:

[0079] When E(ρ i )>Θ and E(ρ i )<υ, it means that the node in the network is attacked;

[0080] When υ≤E(ρ i )≤Θ, indicating that the nodes in the network are safe.

[0081] Based on the security assessment results of nodes in the network, real-time quantum state flow data is obtained through data formatting methods and real-time recording.

[0082] It should be explained that the node security assessment results are formatted to ensure that the data fields are unified and easy to parse. Secondly, the time point of each assessment result is marked with a timestamp and associated with a node identifier (such as an IP address or number). Finally, the formatted data is recorded in real time into the data stream to generate real-time quantum state stream data containing node status, time information and assessment results.

[0083] S3. Based on the initial quantum trust vector, a dynamic gene library is generated through the antigen-antibody matching algorithm.

[0084] Based on the initial quantum trust vector, the antigen feature vector is constructed by combining the network topology information and network attack behavior characteristics.

[0085] It should be stated that graph theory algorithms (such as the shortest path algorithm, community detection algorithm, etc.) are used to analyze the connection relationship and communication path between nodes in the network, and the traffic statistics information in the routing protocol (such as OSPF, BGP, etc.) is combined to identify node pairs with high-frequency communication. At the same time, the network topology information is extracted by constructing a network topology diagram, marking the connection weights (such as bandwidth, delay) and communication frequency between nodes;

[0086] Using the sliding window method, the historical data of the entanglement entropy, purity value and trust value of the node quantum state are counted within the time window, and the average value, standard deviation and change rate are calculated. By analyzing the changing trends of these indicators, abnormal behaviors (such as sudden changes in entanglement entropy, sudden drops in purity value or large fluctuations in trust value) are identified, and combined with known attack patterns, network attack behavior characteristics are extracted;

[0087] The trust value of each node is extracted from the initial quantum trust vector, and the characteristic dimension of the antigen is defined by combining the network topology information (such as node connection relationship, communication path, etc.) and known network attack behavior characteristics (such as attack type, attack mode, etc.). Secondly, the trust value, topological attributes (such as node degree, centrality, etc.) and attack behavior characteristics (such as attack frequency, attack intensity, etc.) of each node are numerically processed and arranged in a predefined order. Finally, the processed data is encapsulated into a multidimensional vector form to generate an antigen feature vector.

[0088] Based on the correspondence between network attack behavior characteristics and defense strategies, a dynamic response strategy for specific attack behaviors is defined to obtain the antibody feature vector.

[0089] The similarity between the antigen feature vector and the antibody feature vector is calculated through the antigen-antibody matching algorithm to obtain the antigen-antibody similarity value.

[0090] The details are as follows:

[0091]

[0092] Among them, S(Z y ,V u ) is the similarity value between the y-th antigen feature vector and the u-th antibody feature vector, Z y is the y-th antigen feature vector, V u is the u-th antibody feature vector, y is the index variable of the antigen feature vector, and u is the index variable of the antibody feature vector.

[0093] Based on the historical antigen-antibody similarity values, the matching threshold Б is set through machine learning analysis, and the matching degree is evaluated based on the antigen-antibody similarity value. The antibody feature vectors that are successfully matched are collected, and a dynamic gene library is generated through dynamic updating and optimization.

[0094] The details are as follows:

[0095] Collect historical antigen-antibody similarity values, analyze their distribution patterns using machine learning algorithms (such as cluster analysis or classification models), and dynamically set matching thresholds Б;

[0096] When the antigen-antibody similarity value is greater than or equal to Б, it is considered a successful match, and the successfully matched antibody feature vectors are collected to generate a dynamic gene library through dynamic updating and optimization (such as eliminating inefficient strategies or introducing new strategies).

[0097] S4. Establish a mapping relationship table between antigen feature vectors and antibody defense strategies.

[0098] Through the feature vector decoding method, the antibody feature vectors that successfully matched in the dynamic gene library were converted into antibody defense strategies.

[0099] It should be explained that the data of each dimension of the antibody feature vector is extracted and parsed into specific defense strategy parameters (such as rule sets, execution conditions, etc.), and the parsed parameters are combined into executable defense strategies (such as traffic filtering, key update, etc.) according to the predefined mapping relationship.

[0100] The correspondence between antigen feature vectors and antibody defense strategies is analyzed through feature vector matching and rule mapping methods, and the correspondence between antigen feature vectors and antibody defense strategies is organized into a mapping relationship table through data classification and structuring methods.

[0101] It should be explained that, first, the feature vector matching algorithm is used to calculate the similarity between the antigen feature vector and the antibody feature vector to determine the best matching defense strategy; secondly, the matching results are converted into specific defense rules (such as flow control, key update, etc.) through the rule mapping method; finally, the antigen feature vector and the corresponding defense strategy are classified and structured to generate a mapping relationship table.

[0102] S5. Integrate quantum alarms and biological alarms to generate a real-time threat level matrix and attack path topology map.

[0103] The real-time quantum state flow data within the time window is monitored through a sliding window, and the rate of change of entanglement entropy is calculated.

[0104] The details are as follows:

[0105] The expression for calculating the rate of change of entanglement entropy is:

[0106]

[0107] Among them, ΔE(ρ i ) is the rate of change of entanglement entropy, Δt is the time interval, and t is the index variable of the time point.

[0108] Based on the entanglement entropy change rate ΔE(ρ i ), through the change rate threshold δ, purity anomaly threshold K and trust security threshold J, the entanglement entropy mutation event in the quantum state flow data is determined, a quantum alarm is generated, and the quantum threat value is obtained.

[0109] The details are as follows:

[0110] Based on historical entanglement entropy mutation events, historical purity values, and historical trust values, the change rate threshold δ, purity anomaly threshold K, and trust safety threshold J are set through statistical analysis methods to determine the entanglement entropy mutation events in the quantum state flow data;

[0111]

[0112] Otherwise, it is judged as normal state;

[0113] It should also be explained that the quantum alarm is generated and the quantum threat value is obtained, specifically:

[0114] Determine it as an entanglement entropy mutation event, trigger a quantum alarm, encapsulate the alarm information (such as node ID, mutation time, entanglement entropy change value, etc.) into structured data, and generate a quantum alarm;

[0115] The quantum threat value is calculated based on the quantum alert. The expression is:

[0116]

[0117] Among them, Q is the quantum threat value, min is the minimum function, Θ is the upper limit threshold of quantum state anomaly, and υ is the lower limit threshold of quantum state anomaly.

[0118] Based on quantum alarms, biological alarms are generated by combining the biological antibody strategy with the characteristics of network attacks to obtain the biological threat value.

[0119] The details are as follows:

[0120] Based on quantum alarms, combined with network topology information and historical attack behavior characteristics, the current antigen feature vector is constructed and the attack type is identified to obtain the current network attack characteristics. Through the mapping relationship table, the corresponding antibody defense strategy is matched to obtain the biological antibody strategy and generate a biological alarm.

[0121] According to the type of biological alarm (such as attack mode, attack intensity, etc.) and the response priority of the defense strategy, the urgency level (such as low, medium, and high) is defined; secondly, the urgency of each biological alarm is converted into a corresponding numerical value (such as low = 0.3, medium = 0.6, and high = 0.9) through a predefined rule mapping table; finally, the assigned urgency value is used as the biological threat value.

[0122] Based on the quantum threat value and the biological threat value, the comprehensive threat value is obtained through the weighted fusion method.

[0123] The details are as follows:

[0124] G = α·Q + (1-α)·N;

[0125] Among them, G represents the comprehensive threat value, α represents the contribution ratio of the adjusted quantum threat value and biological threat value in the comprehensive threat value, and N represents the biological threat value.

[0126] The quantum threat value, biological threat value and comprehensive threat value are organized into a matrix form, a real-time threat level matrix is ​​constructed, and analysis is performed to obtain the abnormal node ID.

[0127] The details are as follows:

[0128] The quantum threat value, biological threat value and comprehensive threat value are arranged and organized into a matrix form according to the nodes to construct a real-time threat level matrix, in which each row corresponds to a node and each column represents the quantum threat value, biological threat value and comprehensive threat value respectively; secondly, by setting the threat threshold, the nodes with excessive threat values ​​are screened out; finally, the identifiers of these nodes (such as IP addresses or numbers) are extracted to obtain the abnormal node IDs.

[0129] Combining routing protocols and topology information, the Dijkstra algorithm is used in combination with the tracing algorithm to trace back the attack path, mark the target nodes and links in the path, and dynamically generate an attack path topology map.

[0130] The details are as follows:

[0131] Based on routing protocols (such as OSPF, BGP, etc.) and network topology information, the Dijkstra algorithm is used to calculate the shortest path from the abnormal node to the potential attack source; secondly, the traffic data and attack characteristics are analyzed through the tracing algorithm to determine the actual propagation path of the attack; finally, the graph theory tools are used to dynamically draw the target node color and link thickness in the topology diagram to dynamically generate the attack path topology diagram.

[0132] S6. By analyzing the quantum state changes of abnormal node IDs, combined with the attack path topology map and dynamic gene library, the network security situation can be perceived.

[0133] Through the sliding window method, the entanglement entropy historical data of abnormal nodes are extracted, the mutation frequency and mutation amplitude of the entanglement entropy historical data are calculated, and the attack characteristics of the abnormal nodes are analyzed in combination with the purity value and trust value of the abnormal nodes.

[0134] The details are as follows:

[0135] Set a fixed-size time window (such as 1 minute), slide through the time series with a certain step size (such as 10 seconds), extract the entanglement entropy historical data of the abnormal nodes in each window, and then calculate the mutation frequency, that is, count the number of times the entanglement entropy historical data of the abnormal nodes in each window exceeds the threshold (the upper limit threshold Θ of the quantum state anomaly and the lower limit threshold υ of the quantum state anomaly);

[0136] Calculate the mutation amplitude. The specific expression is:

[0137] E′(ρ i )=E(ρ i (t))-E(ρ i (t-Δt));

[0138] Among them, E′(ρ i ) represents the change in the historical data of entanglement entropy;

[0139] Compare the changes in all historical data of entanglement entropy to obtain the maximum change, i.e. the mutation amplitude;

[0140] It should also be explained that the attack characteristics of abnormal nodes are analyzed by combining the purity value and trust value of abnormal nodes;

[0141] The details are as follows:

[0142] First, the mutation frequency and mutation amplitude of the entanglement entropy historical data of the abnormal node are obtained from the previous steps, and then the purity value and trust value of the abnormal node are extracted. Then, a comprehensive analysis is performed. For example, the persistence of the attack is judged by comparing the mutation frequency, and the attack intensity is evaluated by the size of the mutation amplitude. A decrease in purity value indicates quantum state mixing (such as eavesdropping), and a sudden drop in trust value indicates that the node may be compromised. Finally, these features are integrated (such as "high-frequency mutation, trust value decreases by 50%) to form the attack characteristics of the abnormal node.

[0143] Through the attack path topology map, the location of abnormal nodes can be analyzed, the attack path can be traced, and the scope and impact of network attacks can be obtained.

[0144] The details are as follows:

[0145] Extract the topological information of abnormal nodes from the attack path topology map, analyze the position of abnormal nodes in the topology map (such as central nodes, edge nodes or bridge nodes), combine graph theory methods (such as Dijkstra algorithm) to determine its connection relationship with other nodes, trace the attack path, trace back the propagation chain from abnormal nodes to potential attack sources through the tracing algorithm, mark the target nodes and links in the path, count the number of affected nodes as the attack range (such as involving 5 nodes), evaluate whether key nodes (such as servers) are damaged as the degree of impact, and form a quantitative result of the scope and impact of network attacks (such as "scope 5 nodes, affecting key node B").

[0146] Based on the attack characteristics of abnormal nodes, combined with the dynamic gene library, the network attack type is perceived, and the comprehensive mapping relationship table, network attack scope and impact are used to gain insight into the network attack intention and overall security situation.

[0147] The details are as follows:

[0148] First, the attack characteristics of abnormal nodes are obtained from the previous steps (such as changes in entanglement entropy mutation frequency, amplitude, purity value and trust value), and an antigen feature vector is constructed. It is matched with the antibody feature vector in the dynamic gene library and the similarity is calculated. If the similarity is ≥ Б, the attack type (such as DDoS, data theft) is perceived. Combined with the defense strategy corresponding to the antibody in the S4 mapping table (such as "traffic filtering") and the attack range (such as 5 nodes) and impact (such as damage to key node B) of the previous steps, the attack intention (such as "blocking the network") is understood. Finally, the overall security situation (such as "the network is facing DDoS threats, key nodes are damaged, and the situation is serious") is evaluated based on the type, scope and impact of network attacks to achieve comprehensive perception.

[0149] This embodiment also provides a computer network security situation awareness system, including: a quantum state real-time monitoring module, a dynamic gene library construction module, a threat detection module and a security situation awareness module;

[0150] The quantum state real-time monitoring module is used to distribute quantum entangled pairs to each node in the network through the quantum key distribution center, generate the initial quantum trust vector according to the node quantum state density matrix, and monitor the entanglement entropy changes of the node quantum state in real time, and output real-time quantum state flow data;

[0151] Dynamic gene library construction module, which is used to generate a dynamic gene library based on the initial quantum trust vector through the antigen-antibody matching algorithm, and establish a mapping relationship table between the antigen feature vector and the antibody defense strategy;

[0152] The threat detection module is used to trigger quantum alarms based on entanglement entropy mutation events in real-time quantum state flow data, and match the biological antibody strategy corresponding to the current network attack characteristics based on the mapping relationship table, and integrate quantum alarms and biological alarms to generate an attack path topology map;

[0153] The security situation awareness module is used to perceive the network security situation by analyzing the quantum state changes of abnormal node IDs, combining the attack path topology map and dynamic gene library.

[0154] This embodiment also provides a computer device, which is suitable for the computer network security situation awareness method, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute computer executable instructions to implement the computer network security situation awareness method proposed in the above embodiment.

[0155] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.

[0156] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for realizing computer network security situation awareness as proposed in the above embodiment is implemented; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, referred to as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, referred to as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, referred to as EPROM), programmable read-only memory (Programmable Red-Only Memory, referred to as PROM), read-only memory (Read-Only Memory, referred to as ROM), magnetic storage, flash memory, disk or optical disk.

[0157] In summary, the present invention achieves real-time perception and dynamic defense against network attacks by: the quantum key distribution center distributes quantum entangled pairs to network nodes and generates initial quantum trust vectors, monitors the changes in entanglement entropy of node quantum states in real time, generates a dynamic gene library in combination with an antigen-antibody matching algorithm, and establishes a mapping relationship table. It ensures the security of network communications and enhances the trust basis between nodes through quantum technology; improves the response speed and accuracy to potential threats through real-time monitoring and antigen-antibody matching mechanisms; optimizes the diversity and adaptability of defense strategies through dynamic gene libraries and mapping relationship tables, significantly improves the network's ability to resist unknown attacks, and achieves efficient and accurate network security situation awareness.

[0158] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A computer network security situation awareness method, characterized in that: include, The quantum key distribution center distributes quantum entangled pairs to each node in the network, generates an initial quantum trust vector based on the node quantum state density matrix, monitors the entanglement entropy changes of the node quantum state in real time, and outputs real-time quantum state flow data; Based on the initial quantum trust vector, a dynamic gene library is generated through the antigen-antibody matching algorithm, and a mapping relationship table between the antigen feature vector and the antibody defense strategy is established; The quantum alarm is triggered according to the entanglement entropy mutation event in the real-time quantum state flow data. At the same time, the biological antibody strategy corresponding to the current network attack characteristics is matched based on the mapping relationship table, and the quantum alarm and biological alarm are integrated to generate an attack path topology map; By analyzing the quantum state changes of abnormal node IDs, combined with the attack path topology map and dynamic gene library, the network security situation can be perceived.

2. The computer network security situation awareness method according to claim 1, characterized in that: The quantum key distribution center distributes quantum entangled pairs to each node in the network, and generates an initial quantum trust vector according to the node quantum state density matrix. The specific steps are as follows: Using the network topology diagram, we analyze the connection relationship and communication requirements between nodes in the network through graph theory algorithms, and identify node pairs with high frequency communication in combination with routing protocols; Entangled photon pairs are generated and distributed to corresponding nodes through quantum light sources, and quantum state tomography technology is used to reconstruct the node quantum state density matrix to calculate the purity value and entanglement entropy of the quantum state of each node in the network; The purity value and entanglement entropy of the quantum state of each node in the network are combined to calculate the trust value of each node in the network, and then arranged and combined into an initial quantum trust vector through a vectorization method.

3. The computer network security situation awareness method according to claim 2, characterized in that: The specific steps of monitoring the entanglement entropy change of the node quantum state in real time and outputting real-time quantum state flow data are as follows: Through the sliding window method, the average value and standard deviation of the entanglement entropy of the historical quantum state of each node in the network are calculated within the time window, and the upper limit threshold Θ and the lower limit threshold υ of the quantum state anomaly are set; Based on the entanglement entropy E(ρ i ), the security of nodes in the network is evaluated through the quantum state anomaly upper limit threshold Θ and the quantum state anomaly lower limit threshold υ; Based on the security assessment results of nodes in the network, quantum state flow data is obtained through data formatting methods and real-time recording.

4. The computer network security situation awareness method according to claim 3, characterized in that: The dynamic gene library is generated by antigen-antibody matching algorithm based on the initial quantum trust vector. The specific steps are as follows: Based on the initial quantum trust vector, combined with network topology information and network attack behavior characteristics, an antigen feature vector is constructed; Based on the correspondence between network attack behavior characteristics and defense strategies, a dynamic response strategy for specific attack behaviors is defined to obtain an antibody feature vector; The similarity between the antigen feature vector and the antibody feature vector is calculated by using the antigen-antibody matching algorithm to obtain the antigen-antibody similarity value; Based on the historical antigen-antibody similarity values, the matching threshold Б is set through machine learning analysis, and the matching degree is evaluated based on the antigen-antibody similarity value. The antibody feature vectors that are successfully matched are collected, and a dynamic gene library is generated through dynamic updating and optimization.

5. The computer network security situation awareness method according to claim 4, characterized in that: The mapping relationship table between antigen feature vector and antibody defense strategy is established. The specific steps are as follows: Through the feature vector decoding method, the antibody feature vectors that successfully matched in the dynamic gene library are converted into antibody defense strategies; The correspondence between antigen feature vectors and antibody defense strategies is analyzed through feature vector matching and rule mapping methods, and the correspondence between antigen feature vectors and antibody defense strategies is organized into a mapping relationship table through data classification and structuring methods.

6. The computer network security situation awareness method according to claim 5, characterized in that: The quantum alarm and biological alarm are integrated to generate an attack path topology map. The specific steps are as follows: Monitor the real-time quantum state flow data within the time window through a sliding window and calculate the rate of change of entanglement entropy; Based on the entanglement entropy change rate ΔE(ρ i ), through the change rate threshold δ, purity anomaly threshold K and trust safety threshold J, the entanglement entropy mutation event in the quantum state flow data is determined, a quantum alarm is generated, and a quantum threat value is obtained; Based on quantum alarms, we combine the network attack feature matching biological antibody strategy to generate biological alarms and obtain biological threat values; Based on the quantum threat value and the biological threat value, a comprehensive threat value is obtained through a weighted fusion method; The quantum threat value, biological threat value and comprehensive threat value are organized into a matrix form, a real-time threat level matrix is ​​constructed, and then analyzed to obtain the abnormal node ID; Combining routing protocols and topology information, the Dijkstra algorithm is used in combination with the tracing algorithm to trace back the attack path, mark the target nodes and links in the path, and dynamically generate an attack path topology map.

7. The computer network security situation awareness method according to claim 6, characterized in that: The specific steps of analyzing the quantum state changes of abnormal node IDs, combining the attack path topology map and the dynamic gene library, and perceiving the network security situation are as follows: Through the sliding window method, the entanglement entropy historical data of abnormal nodes is extracted, the mutation frequency and mutation amplitude of the entanglement entropy historical data are calculated, and the attack characteristics of abnormal nodes are analyzed by combining the purity value and trust value of abnormal nodes; Through the attack path topology map, analyze the location of abnormal nodes, track the attack path, and obtain the scope and impact of network attacks; Based on the attack characteristics of abnormal nodes, combined with the dynamic gene library, the network attack type is perceived, and the comprehensive mapping relationship table, network attack scope and impact are used to gain insight into the network attack intention and overall security situation.

8. A computer network security situation awareness system, based on the computer network security situation awareness method according to any one of claims 1 to 7, characterized in that: Including quantum state real-time monitoring module, dynamic gene library construction module, threat detection module and security situation awareness module; The quantum state real-time monitoring module is used to distribute quantum entangled pairs to each node in the network through the quantum key distribution center, generate the initial quantum trust vector according to the node quantum state density matrix, and monitor the entanglement entropy changes of the node quantum state in real time, and output real-time quantum state flow data; Dynamic gene library construction module, which is used to generate a dynamic gene library based on the initial quantum trust vector through the antigen-antibody matching algorithm, and establish a mapping relationship table between the antigen feature vector and the antibody defense strategy; The threat detection module is used to trigger quantum alarms based on entanglement entropy mutation events in real-time quantum state flow data, and match the biological antibody strategy corresponding to the current network attack characteristics based on the mapping relationship table, and integrate quantum alarms and biological alarms to generate an attack path topology map; The security situation awareness module is used to perceive the network security situation by analyzing the quantum state changes of abnormal node IDs, combining the attack path topology map and dynamic gene library.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the computer network security situation awareness method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the computer network security situation awareness method described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Information security defense method and device for automatic fire alarm system

    CN120455000A

  • Multi-modal fusion network situation awareness method and system

    CN120811699A

  • New energy efficient scheduling method and system based on smart power grid

    CN120933973A

  • A new energy efficient dispatching method and system based on smart grid

    CN120933973B

  • Method and system for automatically executing network security policy based on artificial intelligence large model

    CN121056220A