Big data network security monitoring system

By designing a big data network security monitoring system, real-time monitoring and intercepting attack signals, and performing multi-level security verification, the problem of difficult to judge and verify the security status during information data transmission in the prior art is solved, and the high security and reliability of information data in network transmission is achieved.

CN119996061APending Publication Date: 2025-05-13SHENZHEN KEFU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510372789.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

It is difficult for the prior art to accurately judge and verify the security status of information data during transmission, resulting in the information data facing security threats such as interception, tampering and forgery during network transmission.

Method used

A big data network security monitoring system is designed, including real-time monitoring module, early warning module, attack signal processing module and data output module. The system monitors attack signals during data transmission in real time, sets early warning thresholds, analyzes and intercepts attack signal data, and conducts multi-level security verification on the data to ensure the security of data transmission.

Benefits of technology

Through real-time monitoring and early warning mechanisms, potential attack signals can be quickly identified and intercepted, ensuring the security and reliability of data transmission. The multi-level security verification mechanism effectively prevents data from being tampered with or forged during transmission, improving the security of information data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996061A_ABST
    Figure CN119996061A_ABST
Patent Text Reader

Abstract

The invention discloses a big data network security monitoring system, and relates to the technical field of digital information security transmission, and the big data network security monitoring system monitors potential attack signals or abnormal data behaviors through a real-time monitoring module in the data sending, transmission and receiving processes, and carries out the early recognition of potential security threats, thereby achieving the security monitoring of the big data network. A basis is provided for early warning and processing; the early warning module sets a threshold value, and when monitoring data exceed the threshold value, an alarm is triggered to remind a system or an administrator to pay attention to potential threats, so that response time is won before attack outbreak; the attack signal processing module deeply analyzes the received attack data, identifies and intercepts the attack type and source, ensures that the attack signal does not influence the subsequent data flow, and continuously optimizes the security policy; and the data output module carries out security verification on the data and only outputs the data which is confirmed to have no attack signal, and if the data is not qualified, the data is returned to the processing module for reprocessing to form a repeated verification mechanism so as to ensure the security of all the output data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information security transmission, and in particular to a big data network security monitoring system. Background Art

[0002] With the rapid development and widespread application of Internet-related technologies, people's daily lives are increasingly interacting with the Internet, making more and more people choose to obtain information through the Internet. Although the popularity of the Internet has brought more convenience to people's work and life, it has also created many network security risks, such as the possibility of being intercepted, tampered with, and forged by network attackers. During the transmission of information, network security threats are faced. Therefore, it is proposed to monitor data transmission through a network security monitoring system, but traditional network security monitoring systems are often difficult to accurately judge and verify the secure transmission of information data.

[0003] Therefore, the present invention designs a network security protocol verification mechanism, which further confirms the security status of the data transmission process through cyclic judgment evaluation and security verification assessment, ensuring that the received information data is more secure and reliable;

[0004] To sum up, how to ensure the secure transmission of information data is an urgent problem to be solved and optimized in the big data network security monitoring system. Summary of the Invention

[0005] The present invention provides a big data network security monitoring system to solve the technical problem of how to ensure the safe transmission of information data in related technologies.

[0006] In order to solve the above technical problems, the present invention provides a big data network security monitoring system, the specific technical solutions are as follows:

[0007] A big data network security monitoring system includes the following steps:

[0008] Real-time monitoring module 201, which is used to monitor the attack signal status during data sending, transmission and receiving in real time to ensure the safe flow of data;

[0009] Warning module 202; it is used to set a warning threshold, when the real-time monitoring module detects attack signal data, trigger the warning threshold to issue an alarm message;

[0010] Attack signal processing module 203; which is used to acquire and further analyze and process the attack signal data monitored by the real-time monitoring module to intercept the attack signal data;

[0011] Data output module 204: It is used to intercept attack signal data based on the attack signal processing module, and perform security verification on the data set after intercepting the attack signal data. When no attack signal data remains after security verification, the data is output. Otherwise, it is returned to the attack signal processing module for further processing until the verification is qualified.

[0012] As a further optimization solution of the present invention, the real-time monitoring module includes:

[0013] When the network engine obtains the information data, it encrypts and verifies the information data before transmission to obtain ciphertext security data;

[0014] The encrypted security data is securely transmitted through a secure transmission protocol, and multiple verification nodes are set to query the status of the encrypted security data in multiple stages;

[0015] When the receiving end sends the verification information or authorization information, the ciphertext security data is analyzed through hierarchical isolation, and then the key is obtained according to the verification information or authorization information to decrypt the ciphertext to obtain the security information data.

[0016] As a further optimization solution of the present invention, the attack signal processing module includes:

[0017] Attack signal response unit, attack signal tracing unit, attack signal feedback unit and attack signal processing unit;

[0018] The attack signal response unit immediately triggers a response action based on the attack signal detected by the real-time monitoring module. The response action includes disconnecting a suspicious data link, transferring the attacked node to an isolated network, or limiting bandwidth to prevent the attack signal from penetrating.

[0019] The attack signal tracing unit promptly responds to the attack signal based on the attack signal response unit, and traces the source and path of the attack signal by checking the transmission path of the data packet to determine the source node and initiation location of the attack data;

[0020] The attack signal feedback unit traces the source of the attack signal based on the attack signal tracing unit and promptly feeds back the attack signal to the attack signal processing unit for interception processing;

[0021] The attack signal processing unit receives the feedback signal from the attack signal feedback unit, and segments the attack signal data, combines the intersection points of the segmented attack signal data slices to obtain an extreme point set, and further cuts, disturbs and removes the extreme point set to disintegrate the attack signal data.

[0022] As a further optimization solution of the present invention, the attack signal tracing unit includes:

[0023] Attack signal recognition subunit and attack signal feature extraction subunit;

[0024] The attack signal recognition subunit collects historical response attack signal data, constructs a training set based on the historical response attack signal data, and obtains a signal recognition model; based on the signal recognition model, inputs the newly acquired information data into the signal recognition model to output a potential attack signal recognition result;

[0025] Based on the recognition results, feature extraction is performed on the identified attack signal to obtain a feature information dataset; the feature information dataset includes the source IP address, target port, and attack type;

[0026] Comparing the characteristic information dataset with a known attack database to confirm the nature of the attack signal; tracing the attack source through network topology and traffic paths based on the confirmed nature of the attack signal; and analyzing traffic records to obtain the attacker's entry point and activity path;

[0027] Correlate the traced information with user behavior and module logs to confirm the nature and scope of the attack, and visualize the attack chain and the impact and consequences of the attack signal.

[0028] Based on the tracing results, interception processing is implemented to ensure the safe transmission of information data.

[0029] As a further optimization solution of the present invention, the attack signal processing unit includes:

[0030] After receiving the feedback information, the attack signal processing unit processes the attack signal data through: ; Segment the data in a string form according to semantics to obtain multiple segmented data segments; where t is the character; d is the current data; D is the data; tf(t,d) is a string representing the result of segmenting the character t in the data D; , where N is the total number of segmented data segments and the denominator is the total number of data containing character t;

[0031] Build each segmented data segment into a definition structure as a node, and insert each definition structure into the node as an attribute, wherein each node is represented by a key value, the key represents the attribute name, and the value represents the attribute value, to obtain a string data structure;

[0032] Obtaining extreme points of the attack signal data according to the string data structure, and cutting, disrupting, and removing the extreme points to obtain a secure information transmission channel.

[0033] As a further optimization solution of the present invention, the attack signal data extreme points are obtained according to the string data structure, and the extreme points are cut, disturbed, and removed to obtain a secure information transmission channel, including:

[0034] An attack signal process is defined based on a plurality of string format data structures, and when the plurality of string format data structures have an intersection, the attack signal process is defined by: ; To obtain the extreme point set of the attack signal process; where E represents the extreme point set, which is composed of multiple intersection points; n represents the number of intersection points; S i and S j Represent the i-th and j-th intersection points respectively;

[0035] Based on the extreme points, by: ; Perform cutting, disrupting and removing operations to disintegrate the attack signal data core; clean up the disintegrated attack signal data to obtain a secure information transmission channel;

[0036] Where G processed represents the processed attack signal data, which is the data after cutting, disturbing and removing. This should be a data set without malicious or offensive content. E represents the set of extreme points of the original attack signal data, which can be regarded as a vector or sequence containing all the information elements that need to be processed. i Represents the fragmentation of the extreme value point set of attack signal data; the original data E is cut into multiple subsets {E1, E2, ..., E i}; Indicates that all the cut subsets G i Recombining into a complete set. This step reflects that after the cutting operation, each part can still be regarded as a whole, but is treated independently during the processing; f represents the perturbation function. This function is applied to the entire data set. It can rearrange, encrypt, and obfuscate the data, making the order or content of the data difficult to identify or predict. represents applying a scrambling function to the reassembled attack signal data set to generate scrambled data. g represents a removal function, which is used to identify and remove portions of the data associated with known attack signatures. This can be implemented as pattern matching, keyword filtering, or other methods. T represents an attack signature set, which contains the characteristic patterns used to identify and remove attack signals. This can include specific strings, data patterns, or abnormal behavior signatures.

[0037] As a further optimization solution of the present invention, the data output module includes:

[0038] Safety verification unit and safety determination unit;

[0039] The security verification unit uses a digital front-end and back-end verification mechanism to preliminarily verify the information data based on the information data processed by the attack signal processing module, and shares the front-end and back-end verification data in real time through inter-process communication to obtain preliminary verification information data;

[0040] Based on the preliminary verification information data, incremental verification is performed to verify the changed part of the information data; and the security verification unit is managed through a sleep and wake-up mechanism to obtain the final verification information data;

[0041] After the information data is verified based on the security verification unit, the security determination unit further determines the security evaluation of the information data to obtain secure information data.

[0042] As a further optimization solution of the present invention, a digital front-end and back-end verification mechanism is used to preliminarily verify the information data, and the front-end and back-end verification data are shared in real time through inter-process communication to obtain preliminary verification information data, including:

[0043] The security verification unit receives the initial information data after the attack signal processing through the front end; and performs format verification, logic verification and pre-processing verification on the initial information data to obtain the front-end verification information data;

[0044] Based on the front-end verification information data, a transmission channel is built between the front-end and back-end processes using a message queue so that the front-end verification information data is output from the front-end and sent to the back-end for verification;

[0045] The backend performs deep security verification to verify the potential attack signal residue detection in the front-end verification data; and through hash calibration, to obtain preliminary verification information data;

[0046] The backend transmits the preliminary verification information data as feedback information to the frontend through the inter-process communication mechanism to transmit the verification result; the frontend triggers the auxiliary processing mechanism for the first time based on the backend feedback information.

[0047] As a further optimization solution of the present invention, based on the preliminary verification information data, incremental verification is performed to verify the changed part of the information data; and the security verification unit is managed through a sleep and wake-up mechanism to obtain the final verification information data, including:

[0048] Based on the preliminary verification information data, obtain the changed part of the preliminary verification information data through differential verification, and identify the changed part to obtain identification part data; and perform single verification on the identification part data through incremental verification,

[0049] When the identification partial data is received, the incremental verification unit that wakes up the security verification unit starts the verification process and prepares to verify the identification partial data; when the identification partial data cannot be detected for a long time, the incremental verification unit enters a sleep state.

[0050] The results of the incremental verification are combined with the preliminary verification results to form a complete verification result; and the complete verification feedback is converted into feedback information through the back end, and the verification result is transmitted back to the front end through the inter-process communication mechanism; the front end triggers the auxiliary processing mechanism for the second time based on the back end feedback information.

[0051] As a further optimization solution of the present invention, after the security verification unit verifies the information data, the security determination unit further determines the security assessment of the information data to obtain final security information data, including:

[0052] Based on the information data after verification received by the security determination unit, the security determination unit sets a determination strategy to evaluate the reliability of the verification mechanism; the determination strategy includes performing an attack signal residual search and verification on the verified security information data through hash verification. If there is no residual attack signal, the label is "safe"; otherwise, the information data with residual attack signal is labeled "suspicious";

[0053] Based on the judgment strategy, a threshold value a for the length of information data is set. When the information data length n is less than a, a direct judgment is performed. When the information data length n is greater than or equal to a, a cyclic judgment is performed. The reliability judgment is repeated multiple times to obtain secure information data.

[0054] The present invention has at least the following beneficial effects: The present invention utilizes a real-time monitoring module to monitor potential attack signals or abnormal data behavior during data transmission, transmission, and reception. These signals may include abnormal traffic characteristics, suspicious data packet characteristics, frequent data requests, and so on. Through real-time monitoring, potential security threats can be rapidly detected and identified at an early stage, providing a foundation for subsequent early warning and response. This ensures continuous monitoring of data flows, controls potential risks at the source, and identifies security issues in advance, preventing attack signals from spreading to subsequent data transmission links.

[0055] The early warning module is used to set corresponding warning thresholds (such as the frequency of data anomalies and specific attack patterns). When the data monitored by the real-time monitoring module exceeds the threshold, an alarm is immediately triggered. Once the warning is triggered, an alarm notification can be quickly issued to alert the system or administrator of the potential attack event. This provides a proactive defense method. Through timely reminders, potential threats are discovered before they erupt, buying sufficient response time for the processing module. Especially in the face of complex, multi-layered attacks, the early warning mechanism can detect anomalies early and prevent the attack from spreading further.

[0056] The attack signal processing module is responsible for receiving attack signal data provided by the real-time monitoring module, conducting in-depth analysis of this data, identifying the type and source of the attack, and taking appropriate measures to intercept the attack signal. After analyzing the attack data, the module will take actions such as interception and isolation to ensure that the attack signal data does not enter the data output module, thereby avoiding threats to subsequent data flow. By analyzing and intercepting attack signals, malicious data can be prevented from entering the core components of the system, thereby protecting data integrity and security. At the same time, this attack signal processing can continuously optimize the system's security strategy and gradually enhance defense capabilities by learning different attack characteristics.

[0057] After the attack signal processing module intercepts and processes the data, the data output module performs security verification on the remaining data set. If the security verification passes (i.e., confirms that no attack signals remain), the data is output. If the verification fails (residual attack signals remain), the data is returned to the attack signal processing module for further processing, ensuring that all output data is strictly verified and secure. The data output module provides a final line of defense, preventing residual attack signals from escaping through repeated verification. This repeated verification mechanism significantly improves system security, especially in the face of persistent and persistent attacks, ensuring that only completely secure data is transmitted. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 This is a flow chart of a big data network security monitoring system provided by an embodiment of the present invention;

[0059] Figure 2 The present invention provides a method flow chart of a big data network security monitoring system. DETAILED DESCRIPTION

[0060] The present application is described in further detail below in conjunction with the accompanying drawings. It is necessary to point out that the following specific implementation methods are only used to further illustrate the present application and cannot be understood as limiting the scope of protection of the present application. Technicians in this field can make some non-essential improvements and adjustments to the present application based on the above application content.

[0061] The present invention provides a big data network security monitoring system, the specific implementation of which is as follows:

[0062] like Figure 1 and Figure 2 As shown, a big data network security monitoring system includes:

[0063] Real-time monitoring module, which is used to monitor the attack signal status during data sending, transmission and receiving in real time to ensure the safe flow of data;

[0064] An early warning module; which is used to set an early warning threshold. When the real-time monitoring module detects attack signal data, the early warning threshold is triggered to issue an alarm message;

[0065] An attack signal processing module; used to acquire, further analyze and process the attack signal data monitored by the real-time monitoring module to intercept the attack signal data;

[0066] Data output module: It is used to intercept attack signal data based on the attack signal processing module, and perform security verification on the data set after intercepting the attack signal data. When the security verification shows that there is no attack signal data remaining, the data is output. Otherwise, it is returned to the attack signal processing module for further processing until the verification is qualified.

[0067] In this embodiment of the present invention, the real-time monitoring module monitors every step of the data transmission, transmission, and reception process, focusing on potential attack signals. By applying Deep Packet Inspection (DPI) and Analysis by Anomaly (ABA) to data streams, comprehensive data monitoring is achieved, enabling rapid identification of potential attack signals. The real-time monitoring module ensures that the system can detect attack signals in real time, enabling timely countermeasures to prevent their spread. Furthermore, by detecting attack signals at an early stage, system damage can be reduced.

[0068] The early warning module sets a threshold. When the attack signal detected by the real-time monitoring module reaches or exceeds this threshold, the module automatically triggers and sends an alert to the system or user. The threshold is dynamically adjusted based on historical data, attack signal strength, attack patterns, and other factors. Specifically, the module obtains historical attack signal data characteristics from multiple sources, including attack signal strength and attack patterns. When the transmitted information shows abnormal data strength, a threshold is set at n times the normal data strength. When the traffic exceeds this threshold, an alert is triggered. A threshold is set for two or more consecutive different authorization or authentication attempts within a short period of time (e.g., within one minute). An alert is triggered when the packet loss rate exceeds 1%. To ensure the accuracy of the alert, the early warning module can quickly alert administrators or system automation modules to take protective measures. This allows for a response before attack threats reach a critical level, improving the system's overall security and emergency response capabilities.

[0069] When the real-time monitoring module detects an attack signal, the attack signal processing module receives this data for further analysis and processing. It decodes the attack signal data, performs behavioral analysis, and performs pattern matching to identify the specific attack type and characteristics. After analysis, the module takes appropriate interception measures, such as dropping the packet or blocking the source IP address. The attack signal processing module effectively blocks the attack signal from reaching the core system, preventing further damage to system data. Furthermore, through in-depth analysis of attack signals, the attack source can be more accurately identified, enhancing the system's defense capabilities.

[0070] The data output module performs security verification on data sets that have intercepted attack signals. This verification includes checking for residual attack signals and verifying data integrity. If verification passes, the data output module outputs the safe data. If verification fails, indicating that residual attack signals are present, the data will be returned to the attack signal processing module for reprocessing until it meets security standards. The data output module ensures that only data that has undergone rigorous security verification is output, thereby ensuring the security of data flow. Furthermore, through continuous verification and processing cycles, the system minimizes the risk of attack signal leakage and ensures high credibility of data output.

[0071] The system uses a real-time monitoring module for monitoring, an early warning module for alarming, an attack signal processing module for interception and analysis, and a data output module for verification and output. The interplay of these modules ensures the security of the entire system during data flow.

[0072] Through the collaborative work of various modules, the system can detect, process, and block attack signals at their earliest stages, thereby ensuring the secure flow of data to the greatest extent possible. Furthermore, due to its modular design, the system can be flexibly expanded and upgraded, further enhancing its defense and response capabilities.

[0073] In a preferred embodiment of the present invention, the real-time monitoring module includes:

[0074] When the network engine obtains the information data, it encrypts and verifies the information data before transmission to obtain ciphertext security data;

[0075] The encrypted security data is securely transmitted through a secure transmission protocol, and multiple verification nodes are set to query the status of the encrypted security data in multiple stages;

[0076] When the receiving end sends the verification information or authorization information, the ciphertext security data is analyzed through hierarchical isolation, and then the key is obtained according to the verification information or authorization information to decrypt the ciphertext to obtain the security information data.

[0077] In an embodiment of the present invention, the network engine obtains original information data from the source, which may include text, files, images, etc.; formats and normalizes the information data for subsequent encryption and transmission; encrypts the information data through an encryption algorithm (such as AES, RSA, etc.) to generate ciphertext security data; and uses a security key for encryption to ensure the secure management and storage of the key.

[0078] Generate a checksum (such as MD5, SHA-256) for integrity verification; append the checksum to the ciphertext security data so that the receiver can verify the data integrity; use a secure transmission protocol (such as TLS / SSL) to protect the security of data during transmission.

[0079] The encrypted security data is sent to the receiving end through a secure transmission protocol; an encrypted channel is used during the transmission process to prevent eavesdropping and tampering; multiple verification nodes are set up in the transmission path to monitor and verify the data status; at each verification node, the integrity and validity of the encrypted security data are checked; and the data status at each stage is recorded to facilitate troubleshooting when errors occur.

[0080] After receiving the encrypted security data, the receiver sends verification information (such as a digital signature) or authorization information (such as access credentials); verifies the sender's identity and the integrity of the data; and confirms that the receiver has the authority to access and decrypt the data.

[0081] Isolate and analyze the encrypted security data to ensure that the data has not been tampered with; confirm the legitimacy of decryption based on verification information or authorization information; use pre-shared or securely transmitted keys for decryption to ensure the security of the keys during transmission and storage; decrypt the encrypted security data to obtain the original security information data; and perform integrity verification to ensure that the data has not been damaged; thereby ensuring the security and integrity of information data during network transmission and preventing unauthorized access and data leakage.

[0082] In a preferred embodiment of the present invention, the attack signal processing module includes:

[0083] Attack signal response unit, attack signal tracing unit, attack signal feedback unit and attack signal processing unit;

[0084] The attack signal response unit immediately triggers a response action based on the attack signal detected by the real-time monitoring module. The response action includes disconnecting a suspicious data link, transferring the attacked node to an isolated network, or limiting bandwidth to prevent the attack signal from penetrating.

[0085] The attack signal tracing unit promptly responds to the attack signal based on the attack signal response unit, and traces the source and path of the attack signal by checking the transmission path of the data packet to determine the source node and initiation location of the attack data;

[0086] The attack signal feedback unit traces the source of the attack signal based on the attack signal tracing unit and promptly feeds back the attack signal to the attack signal processing unit for interception processing;

[0087] The attack signal processing unit receives the feedback signal from the attack signal feedback unit, and segments the attack signal data, combines the intersection points of the segmented attack signal data slices to obtain an extreme point set, and further cuts, disturbs and removes the extreme point set to disintegrate the attack signal data.

[0088] In an embodiment of the present invention, when the real-time monitoring module detects an attack signal, the attack signal response unit quickly responds to mitigate the impact of the attack. The response actions include:

[0089] Stop the data link transmitting the attack signal to prevent further spread of the attack; move the attacked node to an isolated network to prevent the attack signal from spreading to other networks; impose bandwidth restrictions on suspicious connections or traffic to slow the propagation of the attack signal. Through rapid response, the propagation path and speed of the attack signal can be controlled immediately, protecting other key nodes in the system. Isolation and bandwidth restriction strategies can effectively mitigate the threat of the attack and provide time for subsequent tracing and resolution.

[0090] Based on the initial isolation performed by the response unit, the attack signal tracing unit begins tracking the source of the attack signal. By examining the packet's transmission path, the unit identifies the attack signal's trajectory, pinpointing the attack source node and the attack's origin. By tracing the packet's path, the tracing unit can precisely determine the attack's origin, providing crucial evidence for attack containment and subsequent analysis. This ability to locate the attack source facilitates targeted measures to prevent similar attacks from recurring.

[0091] After the tracing unit identifies the source of the attack signal, the attack signal feedback unit promptly transmits this information to the attack signal processing unit for processing and interception. The feedback unit's role is to promptly communicate the tracing and processing links, ensuring that attack source information is quickly transmitted to the processing unit, thereby improving the response speed of the entire defense system. This feedback mechanism ensures the coordinated operation of all system units and enhances the overall efficiency of attack defense.

[0092] After receiving the feedback signal, the processing unit performs a series of processing on the attack signal data, including: breaking the attack signal data into multiple small segments to prevent its integrity; combining the segmented attack signal data into a set of extreme points, which are often the key components of the attack data; and further processing the extreme point set by cutting and disrupting the order of the data segments and removing key data to completely destroy the effectiveness of the attack signal. This multi-level data destruction process effectively eliminates the core information of the attack signal, making it difficult for the attack signal to recover and continue to perform malicious actions. This processing method not only improves the reliability of attack signal defense, but also weakens the attacker's intentions, preventing the attack signal from recombining and infiltrating.

[0093] Through the collaboration of units with clear division of labor, the system provides targeted measures at each step, from attack response to tracking, feedback, and processing, effectively enhancing the depth of attack defense; it responds as soon as the attack signal appears, cuts off or isolates the attacked part, and ensures that critical data and networks are not further affected; the tracking mechanism of the tracing unit enables the source of the attack to be quickly located, enhancing the targeted nature of attack analysis and defense measures; by segmenting the attack data and interfering with extreme points, the system can disintegrate the integrity of the attack signal, making it difficult for it to continue to affect the system; the entire attack defense process ensures the high stability of the system in the face of attacks, can effectively prevent data leakage and system crashes, and ensure the security of the network and equipment.

[0094] In a preferred embodiment of the present invention, the attack signal tracing unit includes:

[0095] Attack signal recognition subunit and attack signal feature extraction subunit;

[0096] The attack signal recognition subunit collects historical response attack signal data, constructs a training set based on the historical response attack signal data, and obtains a signal recognition model; based on the signal recognition model, inputs the newly acquired information data into the signal recognition model to output a potential attack signal recognition result;

[0097] Based on the recognition results, feature extraction is performed on the identified attack signal to obtain a feature information dataset; the feature information dataset includes the source IP address, target port, and attack type;

[0098] Comparing the characteristic information dataset with a known attack database to confirm the nature of the attack signal; tracing the attack source through network topology and traffic paths based on the confirmed nature of the attack signal; and analyzing traffic records to obtain the attacker's entry point and activity path;

[0099] Correlate the traced information with user behavior and module logs to confirm the nature and scope of the attack, and visualize the attack chain and the impact and consequences of the attack signal.

[0100] Based on the tracing results, interception processing is implemented to ensure the safe transmission of information data.

[0101] In an embodiment of the present invention, the acquired historical response attack signal data is integrated into an attack signal data set, the attack signal data set is encoded into sequence data, and the sequence data is input into the signal recognition model; the signal recognition model includes an input layer, a first hidden layer, a second hidden layer, a third hidden layer, and an output layer, the intermediate representation data of the hidden layer is transmitted to the output layer, and the output layer output represents a potential attack signal recognition result, specifically as follows:

[0102]

[0103] Among them, W u 、W r 、W c represents the weight parameter, b u 、b r 、b c represents the bias parameter, represents the dot product, u (t) 、r (t) and c (t) Represent the intermediate states of the first, second, and third hidden layers respectively, X (t) represents the tth data item of the attack signal data set, H (t) and H (t-1) They represent the intermediate representation data of the t-th and t-1-th attack signal data sets, n≥t≥1, n represents the total number of input water monitoring data items, and when t=1, H (t-1) =X(t) , tanh is the hyperbolic tangent function, and σ represents the sigmoid function.

[0104] Using the acquired attack signal data set to build a signal recognition model can significantly improve the network security monitoring system's ability to recognize potential attack signals in complex environments.

[0105] The signal recognition model outputs:

[0106]

[0107] Among them, y t represents the output vector of the t-th intermediate period, where the components of the output vector represent the input data item belonging to the i-th state, and h t represents the tth intermediate representation data, W y is the weight parameter, b y is the bias parameter, and σ represents the sigmoid function.

[0108] In summary, the recognition subunit collects past attack signal data and constructs a training set. This historical data contains known attack signal characteristics. Based on this training set, a signal recognition model is trained using machine learning or pattern recognition techniques to identify potential attack signals. Newly acquired network traffic or system data is fed into the trained signal recognition model, which then outputs potential attack signal identification results—data information indicating suspected attacks. By leveraging historical attack data and machine learning models, the system can identify common and variant attack signals, improving attack detection accuracy and response speed. The continuous accumulation of historical data and continuous model optimization give the recognition subunit greater generalization capabilities, enabling timely identification even of new attack patterns.

[0109] Based on the recognition results of the identification sub-unit, the identified attack signal is feature extracted to generate a data set containing key information (feature information data set), which includes key features such as source IP address, target port, and attack type; the feature information data set is compared with the known attack feature database to confirm the nature of the attack signal (such as DDoS attack, SQL injection, Trojan implantation, etc.); once the nature of the attack signal is confirmed, the source of the attack is traced by analyzing the network topology and traffic path, and the entry point and activity path of the attack are further determined.

[0110] Tracing results are correlated with user behavior logs and module logs to accurately determine the attack's scope, target, and potential impact on the system. Graphical displays of the attack chain reveal the impact and potential consequences of attack signals, helping administrators more intuitively understand the attack's path and potential harm. The feature extraction subunit accurately identifies and categorizes different types of attack signals, effectively enhancing the system's threat awareness. A comparison mechanism with the attack database ensures rapid confirmation of known attacks, while topology and traffic analysis provide effective tracing for unknown attacks. Correlation analysis and visualization further help administrators quickly understand the full scope of the attack and take appropriate countermeasures.

[0111] Through historical data training and feature extraction, these two sub-units can effectively separate potential attack signals from normal data and classify and identify different types of attacks, enabling the system to respond quickly. After identifying and extracting attack features, the system can accurately locate the source node of the attack through network topology and traffic path analysis, providing a basis for the precise implementation of defense measures. Attack signals are not limited to detection and tracking, the system also combines them with user behavior and module logs to further analyze the true intent and scope of the attack. This correlation analysis helps identify the specific targets behind the attack and avoids information misjudgment. Visualizing the attack link and impact range helps managers quickly understand the full picture of the attack, improve decision-making efficiency, and facilitate the implementation of accurate interception and isolation measures in the system. Based on the analysis results, the system can implement interception or isolation measures on the source of the attack, thereby ensuring the security of the system's key information and network traffic.

[0112] In a preferred embodiment of the present invention, the attack signal processing unit includes:

[0113] After receiving the feedback information, the attack signal processing unit processes the attack signal data through: ; Segment the data in a string form according to semantics to obtain multiple segmented data segments; where t is the character; d is the current data; D is the data; tf(t,d) is a string representing the result of segmenting the character t in the data D; , where N is the total number of segmented data segments and the denominator is the total number of data containing character t;

[0114] Build each segmented data segment into a definition structure as a node, and insert each definition structure into the node as an attribute, wherein each node is represented by a key value, the key represents the attribute name, and the value represents the attribute value, to obtain a string data structure;

[0115] The attack signal data extreme points are obtained according to the string form data structure, and the extreme points are cut, disturbed and removed to obtain a secure information transmission channel.

[0116] In this embodiment of the present invention, received attack signal data is semantically segmented into character strings. This segmentation is based on a formula: character t and data d are separated to produce multiple data segments. This segmentation method, through semantic segmentation, effectively analyzes the structural information within the data and divides it into smaller segments, laying the foundation for subsequent node construction. This method helps identify and distinguish the different characteristic information of attack signals.

[0117] After segmentation, each segmented data segment is treated as a node, and a structure is defined for each node. Each defined structure consists of attributes, represented as key-value pairs, where the key represents the attribute name and the value represents the attribute value. Ultimately, a data structure is constructed as a string. This node and attribute structure makes attack signal data logically clearer, facilitating subsequent data queries and operations. By segmenting information into small nodes, the semantic information of each data segment can be refined, facilitating targeted processing such as detection, screening, and analysis. This structure also facilitates data management and offers good scalability.

[0118] After constructing the string data structure, the extreme points of the attack signal data are retrieved based on this structure. These extreme points represent key points or significant features in the attack signal. By cutting, disrupting, and removing these extreme points, the attack signal characteristics can be effectively intercepted or eliminated, improving the security and confidentiality of the information data. This helps establish a more secure information transmission channel and enhances the system's anti-attack capabilities.

[0119] Through the aforementioned series of operations, including segmentation, node construction, and extreme point processing, the significant features of the attack signal data are segmented, disrupted, and removed, ultimately forming a concealed and secure information structure. Based on this information structure, a secure information transmission channel is constructed. This secure channel utilizes the reconstruction and characteristics of the anti-attack signal data to encrypt the content of the transmitted data, effectively preventing external interception or analysis. This channel is highly secure and concealed, significantly improving the security level of information transmission.

[0120] The entire process forms a hierarchical and secure structure through multiple steps such as data segmentation, node construction, and extreme point processing. Information transmission under this structure can ensure the confidentiality and anti-attack capabilities of the data, effectively improving the system's security protection capabilities.

[0121] In another preferred embodiment of the present invention, the above-mentioned obtaining the extreme points of the attack signal data according to the string data structure and cutting, disrupting and removing the extreme points to obtain a secure information transmission channel includes:

[0122] An attack signal process is defined based on a plurality of string format data structures, and when the plurality of string format data structures have an intersection, the attack signal process is defined by: ; To obtain the extreme point set of the attack signal process; where E represents the extreme point set, which is composed of multiple intersection points; n represents the number of intersection points; S i and S j Represent the i-th and j-th intersection points respectively;

[0123] Based on the extreme points, by: ; Perform cutting, disrupting and removing operations to disintegrate the attack signal data core; clean up the disintegrated attack signal data to obtain a secure information transmission channel;

[0124] Where G processed represents the processed attack signal data, which is the data after cutting, disturbing and removing. This should be a data set without malicious or offensive content. E represents the set of extreme points of the original attack signal data, which can be regarded as a vector or sequence containing all the information elements that need to be processed. i Represents the fragmentation of the extreme value point set of attack signal data; the original data E is cut into multiple subsets {E1, E2, ..., E i}; Indicates that all the cut subsets G i Recombining into a complete set. This step reflects that after the cutting operation, each part can still be regarded as a whole, but is treated independently during the processing; f represents the perturbation function. This function is applied to the entire data set. It can rearrange, encrypt, and obfuscate the data, making the order or content of the data difficult to identify or predict. represents applying a scrambling function to the reassembled attack signal data set to generate scrambled data. g represents a removal function, which is used to identify and remove portions of the data associated with known attack signatures. This can be implemented as pattern matching, keyword filtering, or other methods. T represents an attack signature set, which contains the characteristic patterns used to identify and remove attack signals. This can include specific strings, data patterns, or abnormal behavior signatures.

[0125] In this embodiment of the present invention, associations are established between multiple string-based data structures, and the attack signal process is defined based on their intersection. "Intersection" here refers to the similarities or overlaps between different data structures. When multiple string-based data structures intersect, these intersections can reveal key common features in the attack signal data. These intersections can be used to determine the extreme point set of the attack signal process.

[0126] By defining the intersections between multiple data structures, key nodes or features in the attack signal data can be identified. These intersections provide a deeper understanding of the attack signal process, aiding subsequent extreme point processing and signal collapse, laying the foundation for further processing.

[0127] After defining the attack signal process and finding the intersection points, the extreme point set E of the attack signal process is obtained based on these intersection points. The extreme point set, composed of multiple intersection points, is a key node in the attack signal data, reflecting the main characteristics of the attack signal in terms of data structure. These extreme points are typically highly correlated or similar parts of the signal data, representing the core characteristics of the attack signal. Obtaining the extreme point set can concentrate the core characteristics of the attack signal data. This aggregation of extreme points helps to focus on important information in the attack signal and improve processing efficiency. Extracting extreme points can simplify subsequent signal processing steps and reduce unnecessary data interference.

[0128] A series of processing operations are performed on the data in the extreme point set, including cutting, perturbing and removing.

[0129] Cutting: Further subdivide the extreme point data, peel off smaller fragments, and extract more fine-grained information.

[0130] Disruption: Disrupt the cut data fragments, change their order or content, and make the data lose its original regularity.

[0131] Removal: This removes extreme point fragments and attack signal fragmentation data, further intercepting and eliminating the core characteristics of the attack signal data. The cutting, scrambling, and removal operations aim to disintegrate the attack signal data core, making it difficult to restore its original structure. This series of operations deprives the attack signal data of its distinctiveness and coherence, increasing data security and preventing external identification or analysis. This data disruption and decomposition mechanism also enhances data concealment to a certain extent.

[0132] By cutting, disrupting, and removing extreme points, the core of the attack signal data is completely disintegrated, weakening or dispersing its structural and characteristic information. Disintegrating the data core is a key step in ensuring the concealment of attack signal data. This process obscures the data's offensive characteristics, making them difficult to identify. The disintegrated data lacks the original attack signature, thus reducing the risk during transmission.

[0133] Cleaning the deconstructed attack signal data removes redundant and residual attack signal data fragments, making the data more concise and secure. The cleaning process further reduces noise in the data, improving data security and transmission efficiency. The cleaned data contains no sensitive attack signatures and can be safely used for information transmission.

[0134] Through a series of processing steps on attack signal data (extraction, segmentation, scrambling, removal, and cleaning of extreme points), a secure information transmission channel is ultimately established; the establishment of a secure information transmission channel is the ultimate goal of this process. This channel utilizes the decomposition and masking of attack signal data, making the transmitted content difficult to identify or analyze. This effectively prevents external eavesdropping and interference, ensuring secure information transmission.

[0135] In a preferred embodiment of the present invention, the data output module includes:

[0136] Safety verification unit and safety determination unit;

[0137] The security verification unit uses a digital front-end and back-end verification mechanism to preliminarily verify the information data based on the information data processed by the attack signal processing module, and shares the front-end and back-end verification data in real time through inter-process communication to obtain preliminary verification information data;

[0138] Based on the preliminary verification information data, incremental verification is performed to verify the changed part of the information data; and the security verification unit is managed through a sleep and wake-up mechanism to obtain the final verification information data;

[0139] After the information data is verified based on the security verification unit, the security determination unit further determines the security evaluation of the information data to obtain secure information data.

[0140] In an embodiment of the present invention, the security verification unit uses a digital front-end and back-end verification mechanism to perform preliminary verification on the processed information data. The specific method includes:

[0141] Front-end validation: Perform preliminary checks on data as it enters the system to filter out content that clearly does not meet requirements;

[0142] Back-end verification: Perform further security checks before data enters the core system for processing.

[0143] Inter-process communication sharing: Through the inter-process communication mechanism, the verification data of the front-end and back-end can be shared in real time, ensuring the consistency and accuracy of the data during transmission.

[0144] The dual verification mechanism of front-end and back-end can effectively improve the reliability of verification and reduce the insecurity factors in data transmission. The real-time data sharing of inter-process communication further improves the response speed and consistency of the system, making the data transmission process more secure.

[0145] Through front-end and back-end verification mechanisms, the system obtains preliminarily verified information data—data that has undergone basic security checks. This stage of verification helps eliminate obvious security risks in the data. Preliminary verification of information data provides the foundation for subsequent incremental verification, filtering out obvious risk data and making subsequent verification more efficient. This process strengthens the system's initial security control capabilities over data.

[0146] Based on the initial verification of information data, the system uses an incremental verification mechanism to verify only the changed parts of the information data, avoiding repeated checks of unchanged data. The system checks the changed parts of the data to ensure data consistency and security. Incremental verification reduces the system's repeated checks of unchanged data, improving system processing efficiency. By verifying only the changed parts of the data, the system can detect anomalies more quickly and reduce resource consumption.

[0147] To save system resources and improve verification efficiency, the security verification unit adopts a sleep and wake-up mechanism.

[0148] Sleep mechanism: When the verification unit is idle, the system puts it into sleep mode to conserve system resources. When new data requires verification, the system quickly wakes the verification unit to perform the verification task. This mechanism effectively reduces system resource consumption and improves system energy efficiency. The introduction of the sleep and wake-up mechanism enables the system to dynamically manage resources, optimizing performance while ensuring verification accuracy.

[0149] After incremental verification and resource management mechanism processing, the system obtains the final verification information data, that is, comprehensive and highly secure data; the final verification information data is the output result of the security verification unit. This data has passed multiple layers of verification to ensure its security and consistency, laying the foundation for further security judgments.

[0150] After completing the data verification, the system passes the data to the security judgment unit for in-depth evaluation.

[0151] The security assessment unit conducts a multi-dimensional analysis of data, including legality, integrity, and reliability, to determine its security level. This security assessment encompasses multiple data characteristics and ultimately provides a security conclusion. This multi-dimensional security assessment further enhances the security and credibility of the data. Through this more comprehensive assessment, the system can more accurately identify potential risks in the data and ensure that the output meets high security standards.

[0152] After multiple processing and assessments by the security verification unit and the security assessment unit, the system ultimately obtains secure information data—data that fully complies with security requirements and is trustworthy. This secure information data is the final product of the entire security verification and assessment process. This data can be securely used for information transmission, ensuring it is immune to external interference and theft in high-security application scenarios.

[0153] In a preferred embodiment of the present invention, the digital front-end and back-end verification mechanism is used to initially verify the information data, and the front-end and back-end verification data are shared in real time through inter-process communication to obtain the preliminary verification information data, including:

[0154] The security verification unit receives the initial information data after the attack signal processing through the front end; and performs format verification, logic verification and pre-processing verification on the initial information data to obtain the front-end verification information data;

[0155] Based on the front-end verification information data, a transmission channel is built between the front-end and back-end processes using a message queue so that the front-end verification information data is output from the front-end and sent to the back-end for verification;

[0156] The backend performs deep security verification to verify the potential attack signal residue detection in the front-end verification data; and through hash calibration, to obtain preliminary verification information data;

[0157] The backend transmits the preliminary verification information data as feedback information to the frontend through the inter-process communication mechanism to transmit the verification result; the frontend triggers the auxiliary processing mechanism for the first time based on the backend feedback information.

[0158] In this embodiment of the present invention, the security verification unit first receives initial information data obtained from attack signal processing at the front end. This initial data contains potential security risks and therefore requires further verification. This mechanism helps to capture potential attack signals early and improve the real-time nature of security protection.

[0159] After receiving the initial data, the front end performs format verification, logic verification and preprocessing to ensure that the data meets the input requirements of subsequent verification. Through preliminary verification and preprocessing, obviously illegal data can be excluded, reducing the burden of subsequent in-depth verification, while improving the efficiency and accuracy of the verification process.

[0160] After the front-end verification data passes format check and logic verification, a data transmission channel is established between the front-end and back-end processes using message queues. Verified data is passed from the front-end to the back-end through this channel for in-depth verification. This distributed message queue mechanism provides stable data transmission, avoids resource competition caused by direct calls, and optimizes data transmission efficiency.

[0161] The backend performs a deeper security verification on the received frontend verification data to detect any remaining potential attack signals. This process includes multi-level security verification of the data to ensure its integrity and authenticity. The backend's in-depth verification can further filter high-risk data, increase the overall security of the system, and supplement and strengthen the frontend verification.

[0162] After deep security verification, the backend performs hash calibration on the data to obtain preliminary verification information. This process ensures that the verification data has not been tampered with during transmission. Hash calibration ensures data consistency, provides a solid foundation for subsequent verification, and prevents security risks caused by intermediate tampering.

[0163] The backend transmits the initial verification information as feedback to the frontend via an inter-process communication mechanism. The frontend then decides whether to trigger the auxiliary processing mechanism based on this feedback. This mechanism allows verification results to be quickly transmitted back to the frontend, ensuring that the frontend can respond to potential attacks in a timely manner, improving the system's emergency response capabilities and security.

[0164] When the front-end receives feedback from the back-end and detects a potential attack risk, it triggers a secondary processing mechanism. This secondary processing mechanism can further confirm and isolate the problem, reducing the spread of risk. Through this secondary processing mechanism, the system can further identify risks and take appropriate security measures, achieving a multi-layered and progressive protection.

[0165] In a preferred embodiment of the present invention, the above-mentioned method is based on the preliminary verification information data, performs incremental verification to verify the changed part of the information data; and manages the security verification unit through a sleep and wake-up mechanism to obtain the final verification information data, including:

[0166] Based on the preliminary verification information data, obtain the changed part of the preliminary verification information data through differential verification, and identify the changed part to obtain identification part data; and perform single verification on the identification part data through incremental verification,

[0167] When the identification partial data is received, the incremental verification unit that wakes up the security verification unit starts the verification process and prepares to verify the identification partial data; when the identification partial data cannot be detected for a long time, the incremental verification unit enters a sleep state.

[0168] The results of the incremental verification are combined with the preliminary verification results to form a complete verification result; and the complete verification feedback is converted into feedback information through the back end, and the verification result is transmitted back to the front end through the inter-process communication mechanism; the front end triggers the auxiliary processing mechanism for the second time based on the back end feedback information.

[0169] In this embodiment of the present invention, the system first uses a differentiated verification mechanism based on existing preliminary verification information to identify changes in the data. Specifically, the system verifies previously verified data and identifies any changes. These changes are identified by the system, forming "identified data." By identifying data changes, differentiated verification avoids repeated verification of unchanged portions, conserving system resources and improving processing efficiency. After identifying changes, the system can focus on these potential risk areas, thereby improving the relevance and effectiveness of verification.

[0170] For the changed portion of the identification data, the system performs individual verifications through an incremental verification mechanism. This individual verification specifically targets the changed data to ensure compliance with security and integrity requirements. Through this individual verification, the system can quickly rule out or confirm the security of the identification data. Incremental verification avoids the high cost of full verification, provides faster response times, and ensures data accuracy despite changes.

[0171] When new identification partial data is received, the system will wake up the incremental verification unit and start the verification process so that the identification partial data can be verified in time; if the incremental verification unit does not detect new identification partial data within a certain period of time, the system will put it into sleep state to save system resources; this mechanism dynamically manages system resources, activating the incremental verification unit to work when needed, and entering sleep state when idle, reducing unnecessary energy consumption, thereby improving the overall energy efficiency of the system.

[0172] After completing incremental verification of the identified data, the system combines the incremental verification results with the previous preliminary verification results to form a comprehensive, complete verification result. This result reflects the overall security and consistency of the data. The complete verification result incorporates the dual guarantees of preliminary and incremental verification, making data verification more comprehensive and reliable, ensuring that the transmitted data meets security standards in terms of both content and changes.

[0173] After the verification results are complete, the system converts the verification feedback information into feedback data through the backend and transmits this feedback information back to the frontend through an inter-process communication mechanism. Through inter-process communication, the system can quickly pass the verification results to the frontend, ensuring that the frontend obtains the data security status in the shortest possible time. This communication mechanism improves the real-time nature of information flow, enhances the system's responsiveness, and improves the user experience.

[0174] After receiving the complete verification results from the backend, the frontend triggers a second auxiliary processing mechanism based on the feedback. This mechanism further processes the data based on the feedback, such as issuing risk warnings, updating data, or storing it. The auxiliary processing mechanism further manages the data based on the verification feedback, enhancing the frontend's data control capabilities. By re-triggering the processing mechanism, the frontend can quickly respond to different feedback states, thereby improving data security and operational accuracy.

[0175] In a preferred embodiment of the present invention, after the information data is verified by the security verification unit, the security determination unit further determines the security assessment of the information data to obtain final secure information data, including:

[0176] Based on the information data after verification received by the security determination unit, the security determination unit sets a determination strategy to evaluate the reliability of the verification mechanism; the determination strategy includes performing an attack signal residual search and verification on the verified security information data through hash verification. If there is no residual attack signal, the label is "safe"; otherwise, the information data with residual attack signal is labeled "suspicious";

[0177] Based on the judgment strategy, a threshold value a for the length of information data is set. When the information data length n is less than a, a direct judgment is performed. When the information data length n is greater than or equal to a, a cyclic judgment is performed. The reliability judgment is repeated multiple times to obtain secure information data.

[0178] In this embodiment of the present invention, the security assessment unit first receives information data that has been verified by a verification mechanism. This data is typically generated after preliminary data verification and has already undergone initial security verification and incremental verification to ensure it is free of obvious errors or threats. The security assessment unit's task is to perform a final security assessment on this verified data; this ensures that all data to be assessed has undergone a certain level of verification, avoids directly performing security assessments on unverified data, and thus improves the accuracy and reliability of the assessment.

[0179] The security determination unit internally sets a set of determination strategies, which define how to evaluate the security of data. Among them, the key strategy is the residual search of hash checksum attack signals. First, the system uses a hash algorithm (such as SHA-256) to calculate the hash of the verified data, generating the hash value of the data. Then, it detects the residual attack signals in the information data through the hash value. This is achieved by comparing the hash value of the data with known attack signal patterns to check if there are any potential malicious codes or tampering traces remaining in the data. The residual search of hash checksum attack signals provides an effective means of security determination, capable of detecting whether the data has been attacked or if there are potential security risks. This method ensures data integrity and credibility through mathematical verification of the data.

[0180] After the residual search of hash checksum attack signals, if no residual attack signals are detected, the security determination unit marks the information data as "secure". This means that the data has not been attacked or tampered with and meets the expected security standards. Thus, it ensures that data without potential threats is promptly identified and marked as secure, reducing unnecessary false alarms or the pressure of security reviews and improving the efficiency of data processing.

[0181] If the residual search of hash checksum attack signals detects the existence of residual attack signals in the data (i.e., there may be malicious tampering or security vulnerabilities in the data), the security determination unit marks the data as "suspicious". This means that the data may have been attacked or tampered with, and the system needs to further analyze or take corresponding security measures. By promptly marking the "suspicious" data, the system can conduct further investigations on this data or take protective measures to prevent the spread of potential security threats, enhancing the system's defense capabilities.

[0182] The security determination unit sets a threshold aa for the length of information data. It decides whether to perform cyclic evaluation based on the data length. When the data length is less than the threshold (n < a): If the data length is less than the threshold, it can directly perform a single security evaluation. This is usually applicable to the case of a small amount of data, and the system can quickly complete the determination. When the data length is greater than or equal to the threshold (n ≥ a): If the data length is long, the system will perform cyclic evaluation. At this time, the data will be divided into multiple small blocks (usually blocks of a fixed size), and the hash checksum and residual signal detection will be performed separately. Through multiple evaluations, the system can more accurately determine the security of the data. Dynamically adjusting the evaluation method according to the data length ensures the determination efficiency and accuracy for different scales of data. For the rapid determination of small amounts of data, it can improve efficiency; while for the cyclic evaluation of large amounts of data, it can provide a more comprehensive and accurate security assessment.

[0183] When the length of information data exceeds a threshold, the system performs a cyclic evaluation of the data in blocks. On each block, the system performs a hash check and searches for residual attack signals. Multiple evaluation results are then analyzed to arrive at an overall security assessment of the data. This cyclic evaluation allows the system to perform multiple, block-by-block security verifications on large amounts of information, avoiding potential risks in details that might be missed due to the limitations of holistic data verification. This approach enhances the reliability and accuracy of the assessment.

[0184] The purpose of the present invention can also be achieved by running a program or a group of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the purpose of the present invention can also be achieved simply by providing a program product containing program code that implements the method or device. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but do not necessarily need to be performed in chronological order. Certain steps can be performed in parallel or independently of each other.

[0185] The above describes an embodiment of the present invention, but this embodiment is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Ordinary technicians in this field can also make more forms of equivalent embodiments based on the inspiration of this embodiment, all of which are protected by this embodiment.

[0186] The above-described embodiments merely illustrate several implementations of the present invention. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, and all such variations and improvements fall within the scope of protection of the present invention.

Claims

1. A big data network security monitoring system, characterized in that: include: A real-time monitoring module, which is used to monitor the attack signal status during data sending, transmission and receiving in real time; To ensure the safe circulation of data; Early warning module; It is used to set the warning threshold. When the real-time monitoring module detects the attack signal data, the warning threshold is triggered to issue an alarm message. Attack signal processing module; It is used to acquire, further analyze and process the attack signal data monitored by the real-time monitoring module to intercept the attack signal data; Data output module: It is used to intercept attack signal data based on the attack signal processing module, and perform security verification on the data set after intercepting the attack signal data. When there is no attack signal data remaining after security verification, the data is output. Otherwise, it is returned to the attack signal processing module for further processing until the verification is qualified.

2. A big data network security monitoring system according to claim 1, characterized in that: Real-time monitoring module, including: When the network engine obtains information data, it encrypts and verifies the information data before transmission to obtain ciphertext security data; The encrypted security data is securely transmitted through a secure transmission protocol, and multiple verification nodes are set to query the status of the encrypted security data in multiple stages; When the receiving end sends the verification information or authorization information, the ciphertext security data is analyzed through hierarchical isolation, and then the key is obtained according to the verification information or authorization information to decrypt the ciphertext to obtain the security information data.

3. A big data network security monitoring system according to claim 2, characterized in that: Attack signal processing module, including: attack signal response unit, attack signal tracing unit, attack signal feedback unit and attack signal processing unit; The attack signal response unit immediately triggers a response action based on the attack signal detected by the real-time monitoring module, wherein the response action includes cutting off a suspicious data link, transferring the attacked node to an isolated network, or limiting bandwidth to prevent the attack signal from penetrating; The attack signal tracing unit timely responds to the attack signal based on the attack signal response unit, and tracks the source and path of the attack signal by checking the transmission path of the data packet to determine the source node and initiation location of the attack data; The attack signal feedback unit traces the source of the attack signal based on the attack signal tracing unit, and timely feeds back the attack signal to the attack signal processing unit for interception processing; The attack signal processing unit receives the feedback signal from the attack signal feedback unit, and segments the attack signal data, combines the intersection points of the segmented attack signal data slices to obtain an extreme point set, and further cuts, disturbs and removes the extreme point set to disintegrate the attack signal data.

4. A big data network security monitoring system according to claim 3, characterized in that: Attack signal tracing unit, including: Attack signal recognition subunit and attack signal feature extraction subunit; The attack signal recognition subunit collects historical response attack signal data, constructs a training set with the historical response attack signal data, so as to obtain a signal recognition model; based on the signal recognition model, inputs the newly acquired information data into the signal recognition model, so as to output a potential attack signal recognition result; Based on the recognition result, feature extraction is performed on the identified attack signal to obtain a feature information data set; the feature information data set includes a source IP address, a target port, and an attack type; Compare the characteristic information data set with a known attack database to confirm the nature of the attack signal; trace the attack source through the network topology and traffic path according to the confirmed nature of the attack signal; and analyze the traffic records to obtain the attacker's entry point and activity path; Correlate the traced information with user behavior and module logs to confirm the nature and scope of the attack, and visualize the attack link and attack signal impact range and consequences; Based on the tracing results, interception processing is implemented to ensure the safe transmission of information data.

5. A big data network security monitoring system according to claim 4, characterized in that: Attack signal processing unit, including: After receiving the feedback information, the attack signal processing unit processes the attack signal data through: ; Segment according to semantics in the form of a string to obtain multiple segmented data segments; where t is a character; d is the current data; D is the data; tf(t,d) is a string, which represents the result of segmenting character t in data D; , where N is the total number of segmented data segments and the denominator is the total number of data containing character t; ·Construct each segmented data segment as a node into a definition structure, and insert each definition structure into the node as an attribute, wherein each node is represented by a key value, the key represents the attribute name, and the value represents the attribute value, so as to obtain a string form data structure; Obtaining the extreme value points of the attack signal data according to the string form data structure, and cutting, disturbing and removing the extreme value points to obtain a secure information transmission channel.

6. A big data network security monitoring system according to claim 5, characterized in that: Acquiring the extreme value points of the attack signal data according to the string form data structure, and cutting, disturbing and removing the extreme value points to obtain a secure information transmission channel, including: The attack signal process is defined based on the plurality of string format data structures, and when the plurality of string format data structures have an intersection, the attack signal process is defined by: ; to obtain the extreme point set of the attack signal process; where E represents the extreme point set, which is composed of multiple intersection points; n represents the number of intersection points; S i and S j Represent the i-th and j-th intersection points respectively; Based on the extreme points, by: ; Perform cutting, disrupting and removing operations; to disintegrate the attack signal data core; clean up the disintegrated attack signal data to obtain a secure information transmission channel; In the formula, G processed represents the processed attack signal data; E represents the extreme value point set of the original attack signal data; E i Represents the fragmentation of the extreme value point set of the attack signal data; the original data E is cut into multiple subsets {E1, E2, ..., E i }; Indicates that all the cut subsets G i Reassemble into a complete set; f represents the perturbation function; It means that the perturbation function is applied to the reassembled attack signal data set to generate perturbed data; g means the removal function; T means the attack feature set.

7. A big data network security monitoring system according to claim 6, characterized in that: Data output module, including: Safety verification unit and safety determination unit; The security verification unit uses a digital front-end and back-end verification mechanism to preliminarily verify the information data based on the information data processed by the attack signal processing module, and shares the front-end and back-end verification data in real time through inter-process communication to obtain preliminarily verified information data; Based on the preliminary verification information data, incremental verification is performed to verify the changed part of the information data; and the security verification unit is managed through a sleep and wake-up mechanism to obtain the final verification information data; After the information data is verified by the security verification unit, the security determination unit further determines the security evaluation of the information data to obtain secure information data.

8. A big data network security monitoring system according to claim 7, characterized in that: The information data is preliminarily verified by using a digital front-end and back-end verification mechanism, and the front-end and back-end verification data are shared in real time through inter-process communication to obtain preliminary verification information data, including: The security verification unit receives the initial information data after the attack signal processing through the front end; and performs format verification, logic verification and pre-processing verification on the initial information data to obtain the front-end verification information data; Based on the front-end verification information data, a transmission channel is built between the front-end and back-end processes using a message queue, so that the front-end verification information data is sent from the front-end output to the back-end for verification; The backend performs deep security verification to verify the potential attack signal residual detection in the front-end verification data; and obtains preliminary verification information data through hash calibration; The backend transmits the preliminary verification information data as feedback information to the frontend through the inter-process communication mechanism to transmit the verification result; the frontend triggers the auxiliary processing mechanism for the first time based on the feedback information from the backend.

9. A big data network security monitoring system according to claim 8, characterized in that: Based on the preliminary verification information data, verify the changed part of the information data through incremental verification; The security verification unit is managed through a sleep and wake-up mechanism to obtain final verification information data, including: Based on the preliminary verification information data, the changed part of the preliminary verification information data is obtained through differential verification, and the changed part is marked to obtain the marked part data; and the marked part data is individually verified through incremental verification, When the identification part data is received, the incremental verification unit that wakes up the security verification unit starts the verification process and prepares to verify the identification part data; when the identification part data cannot be detected for a long time, the incremental verification unit enters a sleep state; The result of the incremental verification is combined with the preliminary verification result to form a complete verification result; and the complete verification feedback is converted into feedback information through the back end, and the verification result is transmitted back to the front end through the inter-process communication mechanism; the front end triggers the auxiliary processing mechanism for the second time based on the back end feedback information.

10. A big data network security monitoring system according to claim 9, characterized in that: After the information data is verified by the security verification unit, the security determination unit further determines the security assessment of the information data to obtain final security information data, including: Based on the information data after verification received by the security judgment unit, the security judgment unit sets a judgment strategy to judge the reliability of the verification mechanism; the judgment strategy includes performing attack signal residual search verification on the verified security information data through hash verification, and when there is no residual attack signal, the label is "safe"; otherwise, the information data with residual attack signal is labeled as "suspicious"; Based on the judgment strategy, the information data length limit threshold a is set, and when the information data length n<a, direct judgment is performed; when the information data length n≥a, cyclic judgment is performed; and reliability judgment is repeated multiple times to obtain safe information data.