Intelligent encryption network security protection system

Through the intelligent encrypted network security protection system, edge devices are used for risk assessment and security protection, the security threat problem when devices access unknown addresses is solved, security monitoring and threat identification of client devices and target addresses are realized, and network security and data communication stability are improved.

CN119996041AInactive Publication Date: 2025-05-13珠海城市职业技术学院
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510270298.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When a device accesses unknown addresses, it faces threats such as malware infection, data breaches, cyber attacks and identity theft, and it is difficult for existing technology to effectively use edge devices for risk assessment.

Method used

Provides an intelligent encrypted network security protection system, and uses edge devices to conduct risk assessment and security protection through the collaborative work of proxy access devices, protective devices and real access devices. The specific steps include: finding and mounting the client device to the edge device, collecting the target address in the application task, setting up a proxy access link, scanning for vulnerabilities in the target address, configuring risk levels and setting up protection policies, triggering the launch of the protection policy and building a real access link, embedding the encryption protocol and generating an access request.

Benefits of technology

Through security monitoring and risk assessment of edge devices, we can identify potential threats, reduce security vulnerabilities and attack risks, improve the stability of data communication, prevent hidden dangers in advance, enhance the threat detection and response capabilities of client devices, and improve the efficiency of network bandwidth usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996041A_ABST
    Figure CN119996041A_ABST
Patent Text Reader

Abstract

The invention is applicable to the technical field of security protection, and particularly relates to an intelligent encryption network security protection system, which comprises proxy access equipment, protection equipment and real access equipment, the proxy access equipment is used for searching client equipment needing to be subjected to security protection, configuring edge equipment, mounting the client equipment into the edge equipment, collecting an application task of the client equipment, reading a target address in the application task, uploading the target address to the edge equipment, and transmitting the target address to the edge equipment; establishing a proxy access link; and the protection equipment is used for scanning the vulnerability in the target address through the proxy access link and based on a scanning result. According to the method, hidden dangers can be prevented in advance by determining the risk level of the target address, threat detection and response capability can be enhanced, intermediate agents and filtering processes can be reduced by determining the real access link, and the use efficiency of network bandwidth is improved while safety risks are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security protection technology, and in particular to an intelligent encrypted network security protection system. Background Art

[0002] Network information security issues have penetrated into various industries and fields and have become the focus of people's attention. When a device accesses an unknown address, it may face many threats including malware infection, data leakage, network attacks and identity theft. After the device directly connects to a malicious website or phishing page, it may be infected with malware such as viruses, worms or ransomware, causing system crashes, data loss or ransomware, and may also expose sensitive information of the device, such as account passwords, geographic location and device identification.

[0003] In real life, security gateways and firewalls are generally deployed to prevent the spread of malware and denial of service attacks; however, this will still cause some malicious programs to bypass the firewall and attack client devices; if an intermediate device can be added between the client device and the target address, and a firewall can be deployed on this intermediate device, all access requests can be centrally managed to reduce potential threats.

[0004] Therefore, “how to use edge devices to perform risk assessment on target addresses” is the technical problem that the present invention needs to solve. Summary of the invention

[0005] The purpose of the present invention is to provide an intelligent encrypted network security protection system to solve the problem of "how to use edge devices to perform risk assessment on target addresses" raised in the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solutions: An intelligent encrypted network security protection system, the system comprising: a proxy access device, a protection device and a real access device; The proxy access device is used to find out the client device that needs security protection, configure the edge device, and mount the client device to the edge device, collect the application tasks of the client device, read the target address in the application task, upload the target address to the edge device, and build a proxy access link; The protection device is used to scan the vulnerabilities in the target address via the proxy access link, and configure the risk level of the target address based on the scanning result, wherein the risk level includes: high, medium and low, and set the protection strategy corresponding to the risk level one by one; The real access device is used to trigger the start of the protection strategy, build a real access link between the client device and the target address, and embed an encryption protocol. Using the client device, an access request is generated, and the access request is imported into the target address via the real access link.

[0007] Further, the proxy access device includes: A search module is used to find client devices that need security protection, configure edge devices, and mount the client devices to the edge devices; The proxy link module is used to collect application tasks of client devices, read the target address in the application tasks, upload the target address to the edge device, and build a proxy access link.

[0008] Furthermore, the protective equipment includes: A configuration module, configured to scan for vulnerabilities in the target address via the proxy access link, and configure a risk level of the target address based on the scan result, wherein the risk level includes: high, medium and low; The setting module is used to set protection strategies corresponding to the risk levels.

[0009] Furthermore, the real access device includes: A generation module, used to trigger the start of the protection strategy, build a real access link between the client device and the target address, embed an encryption protocol, and use the client device to generate an access request; The access module is used to import the access request into the target address via the real access link.

[0010] Furthermore, the search module includes: A numbering unit, used to number the edge devices according to a preset numbering rule; The corresponding unit is used to establish a corresponding relationship between the edge device and the client device according to the number.

[0011] Furthermore, the search module also includes: A reading unit, configured to read attribute data of an edge device, wherein the attribute data includes at least: a processor type, memory, and network bandwidth; The intense unit is used to cluster the edge devices into several priorities and create a task allocation mechanism.

[0012] Furthermore, the configuration module includes: A query unit, configured to read out a characteristic value from the scan result, wherein the characteristic value includes at least: the number of vulnerabilities, the severity score, and the difficulty of repair; The obtaining unit is used to query a preset comparison table, wherein the comparison table at least includes: a feature item value and a score item, and the query results are superimposed to obtain a risk score.

[0013] Furthermore, the configuration module also includes: A construction unit, configured to construct a plurality of fluctuation ranges according to the risk score, wherein each fluctuation range corresponds to a risk level; The determination unit is used to identify the influencing factors of the risk level, wherein the influencing factors at least include: historical events and defense capabilities.

[0014] Furthermore, the generation module includes: An embedding unit, configured to embed a timestamp into the client device, record a generation time of the access request, integrate the generation time and the access request, and generate an access log; The encryption unit is used to encrypt the access log using a preset public key.

[0015] Furthermore, the access module includes: An identification unit, configured to identify abnormal traffic in the real access link according to a time series analysis algorithm; The integration unit is used to construct an opening and closing mechanism triggered by the abnormal traffic, and integrate the opening and closing mechanism into the real access link.

[0016] Compared with the prior art, the present invention has the following beneficial effects: By using the edge device as an intermediate layer, security monitoring and risk assessment can be performed between the client device and the target address, the security of the target address can be monitored, potential threats can be identified, and security vulnerabilities and attack risks can be reduced. By building a proxy access link, the data processing burden of the client device can be reduced while improving the stability of data communication. By determining the risk level of the target address, hidden dangers can be prevented in advance and the threat detection and response capabilities of the client device can be enhanced. By determining the real access link, the intermediate proxy and filtering processes can be reduced, thereby improving the efficiency of network bandwidth utilization while avoiding security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A block diagram of the composition of the intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 2 A block diagram of the composition of a proxy access device in an intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 3 A block diagram of the components of the protection device in the intelligent encryption network security protection system provided by the embodiment of the present invention; Figure 4 A block diagram of the composition of a real access device in the intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 5 A block diagram of the composition of a search module in the intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 6 A block diagram of the configuration module in the intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 7 A block diagram of the composition of a generation module in the intelligent encryption network security protection system provided by an embodiment of the present invention; Figure 8 A block diagram of the composition of an access module in the intelligent encryption network security protection system provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0019] Figure 1 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown. The intelligent encryption network security protection system 1 includes: a proxy access device 11, a protection device 12 and a real access device 13; The proxy access device 11 is used to find the client device that needs security protection, configure the edge device, and mount the client device to the edge device, collect the application tasks of the client device, read the target address in the application task, upload the target address to the edge device, and build a proxy access link.

[0020] Identify the client devices that need security protection, where the number of client devices is not limited and can be one or more; find the edge devices according to the geographical location or network topology, and mount the client devices to the edge devices; specifically, if the number of edge devices is one, all client devices are directly mounted to the edge device, and if the number of edge devices is more than one, the mounting relationship should be determined by the user; collect application tasks in the client devices, where the application tasks can be: accessing unfamiliar addresses or target addresses with potential security threats; determine the target address based on the application tasks, and the client device uploads the target address to the edge device, and the edge device establishes a connection with the target address based on the task requirements.

[0021] Using edge devices, a proxy access link is built; in other words, the request of the client device is not sent directly to the target address, but is forwarded through the edge device, thereby building a communication link between the client device, the edge device and the target address, namely, the proxy access link; through this proxy access link, not only the efficiency of data transmission can be improved and latency can be reduced, but also additional security protection can be added at the network level, and the risk level of the target address can be evaluated to effectively identify potential security threats; in this application, the edge device can be an edge server or a gateway device, etc.

[0022] The protection device 12 is used to scan the vulnerabilities in the target address via the proxy access link, and configure the risk level of the target address based on the scanning result, wherein the risk level includes: high, medium and low, and set protection strategies corresponding to the risk levels.

[0023] The edge device uses a proxy access link and a security scanning tool or service (such as Nessus) to scan the target address for vulnerabilities. The specific scanning areas also include: the network port, operating system, application and database of the target address, etc., to find potential security vulnerabilities; the risk level of the target address is determined according to the number and severity of the scanned vulnerabilities. Each risk level corresponds to a different protection strategy. The protection strategy corresponding to the high risk level is: repairing vulnerabilities, enhancing identity authentication, shutting down unnecessary services or ports, and strengthening network monitoring. The protection strategy corresponding to the medium risk level is: patching discovered vulnerabilities, enhancing access control and enabling encrypted communications, etc. The protection strategy corresponding to the low risk level is: scanning the target address for vulnerabilities at a predetermined frequency.

[0024] For example, after a scan is completed, three vulnerabilities A, B and C are found. By querying the comparison table, it is found that the scores corresponding to the three vulnerabilities are 2 points, among which the severity score of vulnerability A is 2.4 points, and the repair difficulty is 1 point. The severity score of vulnerability B is 1.3 points, and the repair difficulty is 1 point. The severity score of vulnerability C is 6.3 points, and the repair difficulty is 3 points. The risk score of A is; adding up all the scores, we get 17 points. By querying the fluctuation range, the risk level corresponding to 17 points is medium, so the protection strategy corresponding to the medium risk level is activated.

[0025] The real access device 13 is used to trigger the start of the protection strategy, build a real access link between the client device and the target address, and embed an encryption protocol, use the client device to generate an access request, and import the access request into the target address via the real access link.

[0026] After the corresponding protection strategy is triggered, an access link between the client device and the target address, namely the real access link, is established; a symmetric encryption algorithm is embedded in the real access link, and used in conjunction with encryption protocols in the prior art (such as SSL / TLS) to achieve encryption of transmitted data; when the client device generates an access request, which can be for users to access specific services, request data, or perform certain operations, the access request is sent to the target address in an encrypted form through the real access link.

[0027] Figure 2 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the proxy access device 11 includes: The search module 111 is used to find the client device that needs security protection, configure the edge device, and mount the client device to the edge device.

[0028] According to the geographical location or network topology, the edge device is determined and the client device is connected to the edge device.

[0029] The proxy link module 112 is used to collect application tasks of client devices, read out the target addresses in the application tasks, upload the target addresses to the edge devices, and build a proxy access link.

[0030] Collect application tasks in client devices, including smartphones, computers, and IoT devices, read out remote servers or services that the client devices need to access, and determine the target address, where the target address is presented in the form of IP address, domain name, and port number; send the target address to the edge device, and use the client device, edge device, and target address to build a proxy access link.

[0031] Figure 3 The following is a structural block diagram of the intelligent encryption network security protection system provided by an embodiment of the present invention. The protection device 12 includes: The configuration module 121 is used to scan the vulnerabilities in the target address via the proxy access link, and configure the risk level of the target address based on the scanning result, wherein the risk level includes: high, medium and low.

[0032] Use security scanning tools or services to scan the target address for vulnerabilities and detect whether there are known security vulnerabilities, such as unpatched software, open ports, and weak passwords. Determine the risk level corresponding to each target address based on the number, severity, and difficulty of repair of the scanned vulnerabilities.

[0033] The setting module 122 is used to set protection strategies corresponding to the risk levels.

[0034] Each risk level corresponds to a protection strategy.

[0035] Figure 4 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the real access device 13 includes: The generation module 131 is used to trigger the start of the protection strategy, build a real access link between the client device and the target address, embed an encryption protocol, and use the client device to generate an access request.

[0036] After determining the risk level of the target address, the corresponding protection strategy is triggered to establish a communication link between the client device and the target address to obtain a real access link; using the encryption protocol, the access request is encrypted to ensure that the data in the access request will not be read or tampered with by a third party during transmission.

[0037] The access module 132 is used to import the access request into the target address via the real access link.

[0038] The access request is sent to the target address via the real access link.

[0039] Figure 5 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the search module 111 includes: The numbering unit 1111 is used to number the edge devices according to a preset numbering rule.

[0040] Configure a unique identifier for each edge device to facilitate management and tracking during data transmission. Numbering rules are formulated by professionals and can be numbered according to the geographical location of the device, or according to the deployment order or network topology.

[0041] The corresponding unit 1112 is used to establish a corresponding relationship between the edge device and the client device according to the number.

[0042] After determining the number of each edge device, a corresponding relationship between the edge device and the client device is established using the number, where one edge device corresponds to at least one client device.

[0043] Figure 5 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the search module 111 also includes: The reading unit 1113 is used to read the attribute data of the edge device, wherein the attribute data at least includes: processor type, memory and network bandwidth.

[0044] Using hardware detection technology or network construction data, the attribute data of edge devices can be read, including processor type, memory, and network bandwidth.

[0045] The intense unit 1114 is used to cluster the edge devices into several priorities and create a task allocation mechanism.

[0046] According to the attribute data of each edge device, the edge devices are divided into several priorities, among which the priorities are high, medium and low. The edge devices corresponding to the high priority will be given priority to the client devices; the higher the priority, the stronger the data processing capability and the higher the network bandwidth.

[0047] For example, a certain device X needs to be connected to edge devices D, E, and F. If D has a high priority and E and F have medium priorities, X is connected to edge device D.

[0048] Figure 6 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the configuration module 121 includes: The query unit 1211 is used to read out feature values ​​from the scanning results, wherein the feature values ​​at least include: the number of vulnerabilities, severity scores, and repair difficulty.

[0049] The obtaining unit 1212 is used to query a preset comparison table, wherein the comparison table at least includes: feature item values ​​and score items, and superimpose the query results to obtain a risk score.

[0050] From the scan results, select the feature value, use this feature value to query the comparison table, get the corresponding score, add up all the scores, and determine the risk score of the target address. For example, construct the comparison table shown below.

[0051] Once the number of vulnerabilities and the difficulty of repairing them are determined, the corresponding scores can be determined by querying the comparison table. It should be noted that the severity score is determined by the CVSS scoring system, and all scores are added together to obtain the risk score.

[0052] Figure 6 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the configuration module 121 also includes: The construction unit 1213 is used to construct a plurality of fluctuation ranges according to the risk score, wherein each fluctuation range corresponds to a risk level.

[0053] Construct several fluctuation ranges; for example, a risk score of 0-10 corresponds to a low risk level, a risk score of 11-20 corresponds to a medium risk level, and a risk score of other corresponds to a high risk level.

[0054] The determination unit 1214 is configured to identify influencing factors of the risk level, wherein the influencing factors at least include: historical events and defense capabilities.

[0055] In addition to the characteristic values, influencing factors also affect the classification of risk levels, including historical events and defense capabilities. A weighted score is set for each influencing factor. For example, if a security incident has occurred at the target address and the weighted score corresponding to the security incident is 5, 5 points will be added to the risk score.

[0056] Figure 7 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the generation module 131 includes: The embedding unit 1311 is used to embed a timestamp into the client device, record the generation time of the access request, integrate the generation time and the access request, and generate an access log.

[0057] Insert a timestamp into the client device. When an access request is generated, record the generation time, integrate the access request and its corresponding generation time, and obtain the access log.

[0058] Access logs can identify the target address corresponding to the access request, facilitating subsequent security assessments and troubleshooting.

[0059] The encryption unit 1312 is used to encrypt the access log using a preset public key.

[0060] Obtain the public key used for encryption, where the public key is set by the administrator of the client device to ensure that only those who have the corresponding private key can decrypt the log.

[0061] Figure 8 The structure diagram of the intelligent encryption network security protection system provided by the embodiment of the present invention is shown, and the access module 132 includes: The identification unit 1321 is configured to identify abnormal traffic in the real access link according to a time series analysis algorithm.

[0062] Monitor and collect access traffic data of real network links in different time periods, including key features such as access frequency, packet size and request response time. Use time series analysis algorithms to build analysis models to identify regular changes in normal traffic trends and find abnormal traffic that deviates from regular changes, such as sudden traffic peaks, frequent retry requests and abnormal request patterns.

[0063] The integration unit 1322 is used to construct an opening and closing mechanism triggered by the abnormal traffic, and integrate the opening and closing mechanism into the real access link.

[0064] Construct an opening and closing mechanism, where the opening and closing mechanism is: under normal traffic, the real access link remains open to allow traffic to pass freely; once abnormal traffic is identified, some or all of the real access link is temporarily closed to cut off the transmission of abnormal traffic.

[0065] Those skilled in the art will understand that the description of the above service equipment is merely an example and does not constitute a limitation on the terminal equipment. It may include more or fewer components than described above, or a combination of certain components, or different components, for example, it may include input and output devices, network access equipment, buses, etc.

[0066] The processor may be a central processing unit, or other general-purpose processors, digital signal processors, application-specific integrated circuits, off-the-shelf programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, and uses various interfaces and lines to connect various parts of the entire user terminal.

[0067] The above-mentioned memory can be used to store computer programs and / or modules. The above-mentioned processor realizes various functions of the above-mentioned terminal device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as an information collection template display function, a product information release function, etc.), etc.; the data storage area can store data created according to the use of the berth status display system (such as product information collection templates corresponding to different product types, product information that different product providers need to release, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0068] If the module / unit integrated in the terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the modules / units in the above-mentioned embodiment system, and can also be completed by instructing the relevant hardware through a computer program. The above-mentioned computer program can be stored in a computer-readable storage medium, and the computer program can realize the functions of the above-mentioned various system embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form, etc. Computer-readable media may include: any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory random access memory, electrical carrier signal, telecommunication signal and software distribution medium, etc.

[0069] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0070] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. Intelligent encryption network security protection system, characterized by: The system comprises: a proxy access device, a protection device and a real access device; The proxy access device is used to find out the client device that needs security protection, configure the edge device, and mount the client device to the edge device, collect the application tasks of the client device, read the target address in the application task, upload the target address to the edge device, and build a proxy access link; The protection device is used to scan the vulnerabilities in the target address via the proxy access link, and configure the risk level of the target address based on the scanning result, wherein the risk level includes: high, medium and low, and set the protection strategy corresponding to the risk level one by one; The real access device is used to trigger the start of the protection strategy, build a real access link between the client device and the target address, and embed an encryption protocol. Using the client device, an access request is generated, and the access request is imported into the target address via the real access link.

2. The intelligent encryption network security protection system according to claim 1 is characterized in that: The proxy access device comprises: A search module is used to find client devices that need security protection, configure edge devices, and mount the client devices to the edge devices; The proxy link module is used to collect application tasks of client devices, read the target address in the application tasks, upload the target address to the edge device, and build a proxy access link.

3. The intelligent encryption network security protection system according to claim 1 is characterized in that: The protective equipment includes: A configuration module, configured to scan for vulnerabilities in the target address via the proxy access link, and configure a risk level of the target address based on the scan result, wherein the risk level includes: high, medium and low; The setting module is used to set protection strategies corresponding to the risk levels.

4. The intelligent encryption network security protection system according to claim 1 is characterized in that: The real access device comprises: A generation module, used to trigger the start of the protection strategy, build a real access link between the client device and the target address, embed an encryption protocol, and use the client device to generate an access request; The access module is used to import the access request into the target address via the real access link.

5. The intelligent encryption network security protection system according to claim 2 is characterized in that: The search module includes: A numbering unit, used to number the edge devices according to a preset numbering rule; The corresponding unit is used to establish a corresponding relationship between the edge device and the client device according to the number.

6. The intelligent encryption network security protection system according to claim 5 is characterized in that: The search module also includes: A reading unit, configured to read attribute data of an edge device, wherein the attribute data includes at least: a processor type, memory, and network bandwidth; The intense unit is used to cluster the edge devices into several priorities and create a task allocation mechanism.

7. The intelligent encryption network security protection system according to claim 3 is characterized in that: The configuration module includes: A query unit, configured to read out a characteristic value from the scan result, wherein the characteristic value includes at least: the number of vulnerabilities, the severity score, and the difficulty of repair; The obtaining unit is used to query a preset comparison table, wherein the comparison table at least includes: a feature item value and a score item, and the query results are superimposed to obtain a risk score.

8. The intelligent encryption network security protection system according to claim 7 is characterized in that: The configuration module also includes: A construction unit, configured to construct a plurality of fluctuation ranges according to the risk score, wherein each fluctuation range corresponds to a risk level; The determination unit is used to identify the influencing factors of the risk level, wherein the influencing factors at least include: historical events and defense capabilities.

9. The intelligent encryption network security protection system according to claim 4 is characterized in that: The generation module comprises: An embedding unit, configured to embed a timestamp into the client device, record a generation time of the access request, integrate the generation time and the access request, and generate an access log; The encryption unit is used to encrypt the access log using a preset public key.

10. The intelligent encryption network security protection system according to claim 4 is characterized in that: The access module comprises: An identification unit, configured to identify abnormal traffic in the real access link according to a time series analysis algorithm; The integration unit is used to construct an opening and closing mechanism triggered by the abnormal traffic, and integrate the opening and closing mechanism into the real access link.