Digital information security transmission system and method based on network protocol analysis

Through a digital information security transmission system based on network protocol analysis, real-time monitoring and processing of network transmission data, identifying and protecting potential security threats and protocol vulnerabilities, the problem of failure to effectively deal with complex network attacks in the existing technology is solved, and comprehensive security guarantees for digital information transmission are achieved.

CN119995996APending Publication Date: 2025-05-13THE SECOND AFFILIATED HOSPITAL OF NANJING MEDICAL UNIV

Patent Information

Application Number
CN202510152077.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing secure transmission methods have not fully identified and fixed the security risks caused by protocol vulnerabilities or improper configuration, and lack the mechanism for dynamic monitoring and threat detection of real-time network traffic, so they cannot effectively deal with complex attack methods in modern networks.

Method used

Through a digital information security transmission system based on network protocol analysis, network transmission data can be monitored and captured in real time, data preprocessing and protocol analysis are carried out, potential security threats and protocol vulnerabilities are identified, and corresponding security protection measures are implemented.

Benefits of technology

Real-time identification and protection of potential security threats and protocol vulnerabilities is achieved, effectively reducing the damage caused by network attacks, ensuring the secure transmission of digital information, and adapting to a variety of network environments and complex transmission needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995996A_ABST
    Figure CN119995996A_ABST
Patent Text Reader

Abstract

The invention discloses a digital information secure transmission system and method based on network protocol analysis, and relates to the technical field of digital information transmission. In order to solve the problems that an existing secure transmission method mainly focuses on encryption and access control, cannot fully identify security risks possibly caused by protocol vulnerabilities or improper configuration, lacks an active identification and repair mechanism for potential vulnerabilities, is relatively single in processing mode of secure transmission and lacks a flexible real-time response mechanism, the invention provides a secure transmission method based on the protocol vulnerabilities. According to the method, potential security threats and vulnerabilities are detected and identified in real time by deeply analyzing a network protocol, and security risks existing in network communication are dynamically protected in combination with a threat detection and vulnerability repair mechanism, so that higher security is provided in the aspects of data encryption and access control, and the security of the network communication is improved. And potential vulnerabilities and attacks on the protocol level are effectively prevented through deep analysis and behavior pattern recognition of the network protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information transmission, and in particular to a digital information security transmission system and method based on network protocol analysis. Background Art

[0002] With the rapid development of the Internet, network communication has become an indispensable part of modern society. However, network communication also faces many security threats, such as data leakage, tampering, forgery, etc. For example, the patent application with publication number: CN103326849A discloses a method for secure transmission of the Internet of Things, which mainly uses network technology, network protocol, encryption algorithm and access control method to design an Internet of Things secure transmission model based on the three-layer structure of the traditional Internet of Things. The encryption technology in this model adopts encryption algorithm logic and a one-time operation mode, so that the encryption process is dynamic, that is: a pair of passwords at both ends of encryption and decryption are only used once and then eliminated and replaced with a new pair of password mechanisms. In addition, its security is guaranteed by adopting different access control permissions for levels of different importance.

[0003] Although the above patent solves the security problems of data encryption and access control in the prior art, the following problems still exist:

[0004] 1. Existing secure transmission methods mainly focus on encryption and access control, fail to fully identify the security risks that may be caused by protocol vulnerabilities or improper configuration, and lack active identification and repair mechanisms for potential vulnerabilities;

[0005] 2. Existing technologies are unable to dynamically monitor and detect threats to real-time network traffic. Single encryption measures and static access control strategies cannot effectively respond to the ever-changing attack methods in modern networks. In addition, the processing method for secure transmission is relatively simple and lacks a flexible real-time response mechanism. Summary of the invention

[0006] The purpose of the present invention is to provide a digital information security transmission system and method based on network protocol analysis. By comprehensively analyzing the network protocol, detecting potential threats and loopholes in real time, and conducting in-depth analysis of existing risk behaviors, it is possible to identify potential security threats in real time, and provide timely warnings and protection before an attack occurs, thereby ensuring the secure transmission of digital information and effectively reducing the damage caused by network attacks, so as to solve the problems raised in the above-mentioned background technology.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] Digital information security transmission system based on network protocol analysis, including:

[0009] The network data capture unit is used to monitor the network transmission data in real time, capture the data packets flowing through the network interface in the network transmission data, pre-process the data packets, and extract the key information in the pre-processed data packets;

[0010] The network protocol analysis unit is used to analyze the message structure of the captured data packets and verify the protocol standardization, and at the same time, extract the flow characteristics of the data packets in the network communication;

[0011] The threat detection unit is used to identify and mark potential security threats and protocol vulnerabilities in the data packets according to the analysis results of the protocol analysis unit, determine the correlation between security events, and issue security warnings;

[0012] The secure transmission unit is used to process network transmission data with potential security threats and protocol vulnerabilities based on the detection results of the threat detection unit, and implement corresponding security protection measures.

[0013] Furthermore, the network data capturing unit comprises:

[0014] A data collection module is used to collect data packets of various protocol types in real time from network transmission data based on a network interface;

[0015] The data preprocessing module is used to analyze the protocol type of network traffic in network transmission data in real time, and classify the collected data packets according to preset rules based on the protocol type;

[0016] The data preprocessing module is also used to extract the fields corresponding to the data packets according to the protocol standard, remove the redundant information in the data packets to determine the key information, and arrange the processed data packets and the corresponding key information in the order of timestamps;

[0017] The protocol storage module is used to store the processed data packets in the database and classify and store them by protocol type based on the data packets and corresponding key information.

[0018] Furthermore, the network protocol analysis unit comprises:

[0019] The protocol analysis module is used to analyze the packet message structure based on the protocol type of the packet and analyze the protocol fields of the packet layer by layer based on the analysis rules of the multi-layer protocol stack;

[0020] Traffic analysis module, used to group data packets based on the data source of network transmission data, calculate the communication frequency of each data source, and analyze the timing characteristics of network traffic;

[0021] The traffic analysis module is also used to obtain the size of data packets, identify network traffic patterns, and generate traffic behavior reports based on the timing characteristics of network traffic.

[0022] Furthermore, the network protocol analysis unit also includes corresponding message structure analysis of known network protocols such as TCP / IP protocol, HTTP protocol, and DNS protocol, and decoding in combination with data of each layer in the protocol stack.

[0023] Furthermore, the threat detection unit comprises:

[0024] The abnormal traffic detection module is used to perform real-time analysis based on traffic behavior reports to identify whether there is abnormal behavior. If abnormal patterns are detected in network traffic, potential security threats are marked and security warnings are generated;

[0025] The attack behavior identification module is used to compare the results of the protocol field analysis of the data packet with the traffic behavior report and the attack behavior pattern library to identify potential attack behaviors and network security risk characteristics, and mark potential attack behaviors and network security risks based on the identification results;

[0026] The vulnerability analysis module is used to check whether there are known protocol vulnerabilities and misconfigurations in the data packet, and identify possible protocol vulnerabilities and security risks in combination with the known vulnerability library.

[0027] Furthermore, the threat detection unit further includes:

[0028] The risk identification module is used to classify the output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module based on the classification standard of the risk source and generate a risk report;

[0029] The risk assessment module is used to correlate and analyze potential security threats, attack behaviors, and protocol vulnerabilities of different risk types, evaluate the risk level of each risk event in real time, and provide corresponding security repair solutions;

[0030] The risk alarm module is used to immediately trigger the risk warning mechanism when potential risks are detected, and send corresponding alarm information to system administrators and staff based on the risk type.

[0031] Furthermore, the output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module specifically include: the abnormal pattern recognition results of network traffic, including abnormal traffic patterns, frequent communications and traffic characteristics; the recognition results of potential attack behaviors, including attack behavior types and attack behavior characteristics; the recognition results of known protocol vulnerabilities and misconfigurations, including known vulnerability information and vulnerability types.

[0032] Furthermore, the risk assessment module specifically includes:

[0033] Obtain the identified potential security threats and assess the risk level of each risk event based on at least one risk factor and assessment criteria;

[0034] Among them, the corresponding risk factors are extracted from the identified threat events and attack modes for security assessment, and weighted summary is performed according to the preset weight of each risk factor to determine the comprehensive risk value, where the risk factor of each threat event determines the corresponding weight and value based on the type and severity of the threat event;

[0035] The comprehensive risk value is compared with the preset risk level threshold to determine the risk level of the risk event, and a corresponding security repair plan is generated based on the risk level, wherein the preset risk level threshold is adjusted in real time according to the actual network environment and security event trends.

[0036] Furthermore, the safety repair plan includes: generating corresponding repair measure suggestions according to the risk type and risk level of the risk event, and the risk level includes high-risk events, medium-risk events and low-risk events.

[0037] The present invention provides another technical solution, a digital information secure transmission method based on network protocol analysis, comprising the following steps:

[0038] Step 1: Network data capture and preprocessing: Real-time monitoring of network transmission data, capture and preprocessing of data packets, extraction of key field information, and storage in the database;

[0039] Step 2: Network protocol analysis and traffic analysis: Perform protocol analysis on the captured data packets, analyze the protocol fields of the data packets layer by layer, identify the characteristics of network traffic, and generate a traffic behavior report;

[0040] Step 3: Threat detection and risk assessment: Based on the results of protocol analysis, identify potential security threats, attack behaviors and protocol vulnerabilities, extract risk factors and conduct comprehensive assessments, determine risk levels and generate security repair plans;

[0041] Step 4: Security repair and protection measures execution: Take corresponding protection measures according to the risk level and repair plan to ensure the security of data during transmission;

[0042] Step 5: Risk warning and continuous monitoring: When potential risks are detected, a risk warning is triggered, an alarm is issued to the staff and repair suggestions are provided, network transmission is continuously monitored, and protection strategies are adjusted in real time.

[0043] Compared with the prior art, the present invention has the following beneficial effects:

[0044] By real-time monitoring and capturing of various data packets in network transmission, it can timely identify and prevent potential security threats and protocol loopholes, effectively avoid data leakage, tampering or other network attacks, capture and parse a variety of common network protocols, and efficiently classify and process different types of data packets according to preset rules, so as to achieve rapid capture and analysis of multi-protocol traffic and identify potential abnormal behaviors. By comprehensively analyzing protocol specifications, traffic behaviors and attack patterns, it can detect abnormal traffic, potential attack behaviors and protocol loopholes in real time, and generate security warnings in a timely manner to ensure the security of network transmission. It can adapt to a variety of network environments and complex transmission requirements, flexibly respond to various network security challenges, and provide comprehensive protection for digital information transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a module diagram of the digital information security transmission system based on network protocol analysis of the present invention. DETAILED DESCRIPTION

[0046] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0047] In order to solve the technical problems in existing technologies, such as lack of active identification and repair mechanism for potential vulnerabilities, relatively simple processing methods for secure transmission, and lack of flexible real-time response mechanism, please refer to Figure 1 , this embodiment provides the following technical solutions:

[0048] Digital information security transmission system based on network protocol analysis, including:

[0049] The network data capture unit is used to monitor network transmission data in real time, capture data packets flowing through the network interface in the network transmission data, including data packets of different protocol types such as TCP, UDP, ICMP, etc., and pre-process the data packets to extract key information from the pre-processed data packets, such as source IP address, destination IP address, port number, protocol type, data content, etc., including:

[0050] The data acquisition module is used to collect data packets of various protocol types from network transmission data in real time based on the network interface, including the capture of multiple common protocols such as TCP, UDP, ICMP, etc.

[0051] The data preprocessing module is used to analyze the protocol type of network traffic in network transmission data in real time, and classify the collected data packets according to preset rules (such as source / destination address, port, etc.) based on the protocol type to achieve multi-protocol support and fast data packet capture;

[0052] The data preprocessing module is also used to extract the fields corresponding to the data packet according to the protocol standard, such as IP address, port number, protocol type, sequence number, confirmation number, flag bit, etc., remove the redundant information in the data packet (such as link layer padding bytes, unnecessary network layer and transport layer header information, etc.) to determine the key information, and arrange the processed data packets and the corresponding key information in the order of timestamp;

[0053] The protocol storage module is used to store the processed data packets in the database and classify and store them by protocol type based on the data packets and corresponding key information;

[0054] The network protocol analysis unit is used to analyze the message structure of the captured data packets and verify the protocol compliance. At the same time, it extracts the traffic characteristics of the data packets in the network communication, including communication frequency, data size, connection mode, etc.

[0055] The threat detection unit is used to identify and mark potential security threats and protocol vulnerabilities in the data packets according to the analysis results of the protocol analysis unit, determine the correlation between security events, and issue security warnings;

[0056] The secure transmission unit is used to process network transmission data with potential security threats and protocol vulnerabilities based on the detection results of the threat detection unit, including data encryption, data isolation, data redirection, etc., and implement corresponding security protection measures to ensure the security of data during transmission and prevent data leakage or tampering.

[0057] In this embodiment, by real-time monitoring and capturing of various types of data packets in network transmission, potential security threats and protocol loopholes are timely identified and prevented, effectively avoiding data leakage, tampering or other network attacks. The capture and analysis of multiple common network protocols can efficiently classify and process different types of data packets according to preset rules, realize rapid capture and analysis of multi-protocol traffic, identify potential abnormal behaviors, and through comprehensive analysis of protocol specifications, traffic behaviors and attack patterns, detect abnormal traffic, potential attack behaviors and protocol loopholes in real time, and generate security warnings in a timely manner to ensure the security of network transmission, adapt to various network environments and complex transmission requirements, flexibly respond to various network security challenges, and provide comprehensive protection for digital information transmission.

[0058] In this embodiment, the network protocol analysis unit includes:

[0059] The protocol parsing module is used to parse the packet message structure based on the protocol type of the packet, and analyze the protocol fields of the packet layer by layer based on the parsing rules of the multi-layer protocol stack to ensure that the field values ​​of each layer of the protocol meet the predetermined protocol specifications;

[0060] Traffic analysis module, used to group data packets based on the data source of network transmission data, calculate the communication frequency of each data source, and analyze the timing characteristics of network traffic;

[0061] The traffic analysis module is also used to obtain the size of the data packet and identify the network traffic pattern, such as whether there is an abnormal large traffic burst or a small but frequent data packet exchange, and generate a traffic behavior report based on the timing characteristics of the network traffic;

[0062] In this embodiment, the network protocol analysis unit also includes performing corresponding message structure analysis on known network protocols such as TCP / IP protocol, HTTP protocol, and DNS protocol, and decoding them in combination with the data of each layer in the protocol stack.

[0063] In this embodiment, through precise protocol parsing and traffic analysis, the security and reliability of network transmission data can be effectively improved. Through special analysis, the accuracy and breadth of protocol analysis can be improved to ensure that when facing complex protocol transmission, data packets can be correctly restored and accurately parsed, thereby enhancing the adaptability and flexibility of network protocols and improving the security and controllability of network data transmission.

[0064] In this embodiment, the threat detection unit includes:

[0065] The abnormal traffic detection module is used to perform real-time analysis based on traffic behavior reports to identify abnormal behaviors such as traffic bursts and frequent communication between abnormal source / destination IP pairs. If abnormal patterns in network traffic are detected, potential security threats are marked and security warnings are generated;

[0066] The attack behavior identification module is used to compare the results of the protocol field analysis of the data packet with the traffic behavior report and the attack behavior pattern library to identify potential attack behaviors and network security risk characteristics, and mark potential attack behaviors and network security risks based on the identification results;

[0067] Vulnerability analysis module, used to check whether there are known protocol vulnerabilities and misconfigurations in the data packet, and identify possible protocol vulnerabilities and security risks in combination with the known vulnerability library;

[0068] The risk identification module is used to classify the output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module based on the classification standard of the risk source and generate a risk report;

[0069] In this embodiment, the output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module specifically include:

[0070] Abnormal pattern recognition results of network traffic, including:

[0071] Abnormal traffic patterns: such as traffic bursts, abnormal traffic fluctuations, etc.

[0072] Frequent communication: such as abnormal source / destination IP pairs frequently communicating or high-frequency behavior of certain communications;

[0073] Traffic characteristics: including sharp increases in traffic volume, abnormal time distribution patterns, etc.

[0074] Identification results of potential attack behaviors, including:

[0075] Attack behavior type: such as network scanning, brute force cracking, SQL injection, cross-site scripting (XSS), etc.

[0076] Attack behavior characteristics: such as the frequency of malicious requests, abnormal patterns of attack source IP addresses, etc.

[0077] Identification of known protocol vulnerabilities and misconfigurations, including:

[0078] Known vulnerability information: Based on the known vulnerability database, the protocol vulnerabilities and configuration errors in the data packets are marked;

[0079] Vulnerability type: such as protocol layer vulnerabilities (such as SSL / TLS vulnerabilities), application layer vulnerabilities (such as HTTP protocol security vulnerabilities), etc.

[0080] The risk assessment module is used to correlate and analyze potential security threats, attack behaviors and protocol vulnerabilities of different risk types, evaluate the risk level of each risk event in real time, and provide corresponding security repair solutions; the security repair solutions include: generating corresponding repair measures suggestions according to the risk type and risk level of the risk event, and the risk level includes high risk events, medium risk events and low risk events;

[0081] In this embodiment, for high-risk events of abnormal traffic, it is recommended to immediately isolate and analyze the traffic to prevent further spread of the traffic; for potential attacks identified by attack behaviors, it is recommended to block them in combination with historical attack patterns and add firewall rules; for risks of known vulnerabilities, it is recommended to update the protocol version, fix incorrect configurations, or perform encryption protection, etc.

[0082] The risk alarm module is used to immediately trigger the risk warning mechanism when potential risks are detected, and send corresponding alarm information to system administrators and staff based on the risk type. System administrators and staff can take timely response measures according to the security repair plan.

[0083] In this embodiment, the abnormal traffic detection module can quickly identify abnormal behaviors such as traffic bursts and frequent communications, and generate timely warnings to ensure rapid response to potential threats. The attack behavior identification module, combined with the traffic report and attack pattern library, can accurately identify attack behaviors and mark attack characteristics. The vulnerability analysis module checks the known protocol vulnerabilities and configuration errors in the data packet, and by comparing with the vulnerability library, timely discovers and marks security risks. The risk identification module classifies and evaluates various threats, generates risk reports and provides corresponding repair plans. The risk alarm module triggers an early warning when a potential threat is discovered, and sends an alarm message to the administrator so that countermeasures can be taken quickly, effectively improving the security protection capabilities during network transmission and ensuring the security and integrity of data.

[0084] In this embodiment, the risk assessment module specifically includes:

[0085] Obtain the identified potential security threats and assess the risk level of each risk event based on at least one risk factor and assessment criteria;

[0086] Among them, the corresponding risk factors are extracted from the identified threat events and attack modes for security assessment, and weighted summary is performed according to the preset weight of each risk factor to determine the comprehensive risk value, where the risk factor of each threat event determines the corresponding weight and value based on the type and severity of the threat event;

[0087] The comprehensive risk value is compared with the preset risk level threshold to determine the risk level of the risk event, and a corresponding security repair plan is generated based on the risk level, wherein the preset risk level threshold is adjusted in real time according to the actual network environment and security event trends.

[0088] In this embodiment, the corresponding risk factors are extracted from the identified threat events and attack patterns, and weighted and summarized according to preset weights to determine the comprehensive risk value, accurately determine the risk level of the risk event, and generate targeted security repair plans based on this. This not only improves the accuracy of risk assessment, but also optimizes the security repair plan, enhances the system's adaptability, improves security protection efficiency, and ultimately ensures the security of digital information transmission, providing a solid security guarantee for the network environment.

[0089] In order to better demonstrate the implementation process of the digital information security transmission system based on network protocol analysis, the present invention provides a digital information security transmission method based on network protocol analysis, comprising the following steps:

[0090] Step 1: Network data capture and preprocessing: Real-time monitoring of network transmission data, capture and preprocessing of data packets, extraction of key field information, such as source IP, destination IP, port number, protocol type, etc., and storage in the database;

[0091] Step 2: Network protocol analysis and traffic analysis: Perform protocol analysis on the captured data packets, analyze the protocol fields of the data packets layer by layer, identify the characteristics of network traffic, such as communication frequency, data packet size and connection mode, and generate a traffic behavior report;

[0092] Step 3: Threat detection and risk assessment: Based on the results of protocol analysis, identify potential security threats, attack behaviors and protocol vulnerabilities, extract risk factors and conduct comprehensive assessments, determine risk levels and generate security repair plans;

[0093] Step 4: Security repair and protection measures execution: According to the risk level and repair plan, take corresponding protection measures, such as traffic isolation, attack source blocking, vulnerability repair, etc., to ensure the security of data during transmission;

[0094] Step 5: Risk warning and continuous monitoring: When potential risks are detected, a risk warning is triggered, an alarm is issued to the staff and repair suggestions are provided, network transmission is continuously monitored, and protection strategies are adjusted in real time.

[0095] In this embodiment, by real-time monitoring and capturing of network data, data preprocessing is performed and key information is stored, and then in-depth protocol parsing and traffic behavior analysis are performed on the data packets to identify potential threats and generate reports. Then, security repair and protection measures are performed based on the risk assessment results, such as traffic isolation and vulnerability repair, to ensure the security of data transmission, and through risk warning and continuous monitoring, potential risks are responded to in a timely manner, thereby improving the security and traceability of network data transmission, optimizing resource utilization, and enhancing user experience.

[0096] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.

Claims

1. A digital information security transmission system based on network protocol analysis, characterized in that: include: The network data capture unit is used to monitor the network transmission data in real time, capture the data packets flowing through the network interface in the network transmission data, pre-process the data packets, and extract the key information in the pre-processed data packets; The network protocol analysis unit is used to analyze the message structure of the captured data packets and verify the protocol standardization, and at the same time, extract the flow characteristics of the data packets in the network communication; The threat detection unit is used to identify and mark potential security threats and protocol vulnerabilities in the data packets according to the analysis results of the protocol analysis unit, determine the correlation between security events, and issue security warnings; The secure transmission unit is used to process network transmission data with potential security threats and protocol vulnerabilities based on the detection results of the threat detection unit, and implement corresponding security protection measures.

2. The digital information security transmission system based on network protocol analysis as claimed in claim 1, characterized in that: Network data capture unit, comprising: A data collection module is used to collect data packets of various protocol types in real time from network transmission data based on a network interface; The data preprocessing module is used to analyze the protocol type of network traffic in network transmission data in real time, and classify the collected data packets according to preset rules based on the protocol type; The data preprocessing module is also used to extract the fields corresponding to the data packets according to the protocol standard, remove the redundant information in the data packets to determine the key information, and arrange the processed data packets and the corresponding key information in the order of timestamps; The protocol storage module is used to store the processed data packets in the database and classify and store them by protocol type based on the data packets and corresponding key information.

3. The digital information security transmission system based on network protocol analysis as claimed in claim 2, characterized in that: Network protocol analysis unit, including: The protocol analysis module is used to analyze the packet message structure based on the protocol type of the packet and analyze the protocol fields of the packet layer by layer based on the analysis rules of the multi-layer protocol stack; Traffic analysis module, used to group data packets based on the data source of network transmission data, calculate the communication frequency of each data source, and analyze the timing characteristics of network traffic; The traffic analysis module is also used to obtain the size of data packets, identify network traffic patterns, and generate traffic behavior reports based on the timing characteristics of network traffic.

4. The digital information security transmission system based on network protocol analysis as claimed in claim 3, characterized in that: The network protocol analysis unit also includes corresponding message structure analysis of known network protocols such as TCP / IP protocol, HTTP protocol, and DNS protocol, and decoding in combination with the data of each layer in the protocol stack.

5. The digital information security transmission system based on network protocol analysis as claimed in claim 4, characterized in that: Threat detection unit, including: The abnormal traffic detection module is used to perform real-time analysis based on traffic behavior reports to identify whether there is abnormal behavior. If abnormal patterns are detected in network traffic, potential security threats are marked and security warnings are generated; The attack behavior identification module is used to compare the results of the protocol field analysis of the data packet with the traffic behavior report and the attack behavior pattern library to identify potential attack behaviors and network security risk characteristics, and mark potential attack behaviors and network security risks based on the identification results; The vulnerability analysis module is used to check whether there are known protocol vulnerabilities and misconfigurations in the data packet, and identify possible protocol vulnerabilities and security risks in combination with the known vulnerability library.

6. The digital information security transmission system based on network protocol analysis as claimed in claim 5, characterized in that: The threat detection unit also includes: The risk identification module is used to classify the output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module based on the classification standard of the risk source and generate a risk report; The risk assessment module is used to correlate and analyze potential security threats, attack behaviors, and protocol vulnerabilities of different risk types, evaluate the risk level of each risk event in real time, and provide corresponding security repair solutions; The risk alarm module is used to trigger the risk warning mechanism when potential risks are detected, and send corresponding alarm information to system administrators and staff based on the risk type.

7. The digital information security transmission system based on network protocol analysis as claimed in claim 6, characterized in that: The output results of the abnormal traffic detection module, the attack behavior identification module and the vulnerability analysis module specifically include: the abnormal pattern recognition results of network traffic, including abnormal traffic patterns, frequent communications and traffic characteristics; the recognition results of potential attack behaviors, including attack behavior types and attack behavior characteristics; the recognition results of known protocol vulnerabilities and misconfigurations, including known vulnerability information and vulnerability types.

8. The digital information security transmission system based on network protocol analysis as claimed in claim 7, characterized in that: Risk assessment module, including: Obtain the identified potential security threats and assess the risk level of each risk event based on at least one risk factor and assessment criteria; Among them, the corresponding risk factors are extracted from the identified threat events and attack modes for security assessment, and weighted summary is performed according to the preset weight of each risk factor to determine the comprehensive risk value, where the risk factor of each threat event determines the corresponding weight and value based on the type and severity of the threat event; The comprehensive risk value is compared with the preset risk level threshold to determine the risk level of the risk event, and a corresponding security repair plan is generated based on the risk level, wherein the preset risk level threshold is adjusted in real time according to the actual network environment and security event trends.

9. The digital information security transmission system based on network protocol analysis as claimed in claim 8, characterized in that: The safety repair plan includes: generating corresponding repair measure suggestions according to the risk type and risk level of the risk event, and the risk level includes high risk event, medium risk event and low risk event.

10. The digital information secure transmission method based on network protocol analysis is applied in the digital information secure transmission system based on network protocol analysis as claimed in claim 9, characterized in that: The following steps are involved: Step 1: Network data capture and preprocessing: Real-time monitoring of network transmission data, capture and preprocessing of data packets, extraction of key field information, and storage in the database; Step 2: Network protocol analysis and traffic analysis: Perform protocol analysis on the captured data packets, analyze the protocol fields of the data packets layer by layer, identify the characteristics of network traffic, and generate a traffic behavior report; Step 3: Threat detection and risk assessment: Based on the results of protocol analysis, identify potential security threats, attack behaviors and protocol vulnerabilities, extract risk factors and conduct comprehensive assessments, determine risk levels and generate security repair plans; Step 4: Security repair and protection measures execution: Take corresponding protection measures according to the risk level and repair plan to ensure the security of data during transmission; Step 5: Risk warning and continuous monitoring: When potential risks are detected, a risk warning is triggered, an alarm is issued to the staff and repair suggestions are provided, network transmission is continuously monitored, and protection strategies are adjusted in real time.

Citation Information

Patent Citations

  • Internet of Things secure transmission method

    CN103326849A

Cited By

  • Network security protection method and system based on flow analysis

    CN120321044A

  • Network security vulnerability detection method and system based on artificial intelligence

    CN120389916A

  • Method and system for carrying out potential safety hazard detection on network service

    CN120474834A

  • Network security monitoring method, device, equipment and medium

    CN121037017A