Satellite network multi-dimensional protection method and system based on graph neural network attack
Through the multi-dimensional protection method based on graph neural network, dynamically analyze the satellite network topology and node interaction mode, predict the attack path and adjust the security configuration, the problem of insufficient flexibility and adaptability of traditional protection methods is solved, and more efficient network security response and protection effects are achieved.
Patent Information
- Application Number
- CN202510124586.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-23
AI Technical Summary
Traditional satellite network protection methods lack flexibility and adaptability when facing complex and changing satellite network environments, and it is difficult to predict and respond to emerging threats in real time and accurately.
The multi-dimensional protection method of satellite network based on graph neural network attack is adopted. By monitoring the connection status of nodes in real time, analyzing the topology structure, identifying key nodes, predicting attack paths, and dynamically adjusting the security configuration of the network layer, monitoring network traffic in real time, detecting abnormal activities, and optimizing the defense mechanism.
It improves the network's adaptability and response speed, can quickly detect and identify abnormal activities and security risk events, optimize defense mechanisms, and ensure the continuity and security of network services.
Smart Images

Figure CN120034368A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a multi-dimensional protection method and system for satellite networks based on graph neural network attacks. Background Art
[0002] The field of network security technology focuses on protecting computer networks and various related components from unauthorized access and malicious attacks, covering multiple aspects from infrastructure defense to data and application protection, including the use of firewalls, encryption technology, intrusion detection systems and data access control to protect network resources, combined with the formulation and implementation of security policies and procedures to manage user behavior, identify and respond to security threats, ensure data confidentiality, integrity, system availability, and enhance security protection capabilities against external threats.
[0003] Among them, the multi-dimensional protection method of satellite networks aims to protect satellite networks from various network threats and attacks, including continuous monitoring, analysis and evaluation of the network, identification and response to various threats, protection of data transmission security and stable operation of the network, and enhancement of the defense capabilities of satellite communication systems. It combats increasingly complex and diverse network attacks, ensures the continuity and security of critical information and services, strengthens the network's ability to resist attacks, ensures information security and stable operation of the network, and effectively improves the security of satellite networks.
[0004] Traditional satellite network protection methods lack sufficient flexibility and adaptability when facing complex and ever-changing satellite network environments. They are inadequate in dealing with dynamically changing network topologies and rapidly evolving attack strategies, and it is difficult to accurately predict and respond to emerging threats in real time. When attackers use unpredicted new strategies or launch attacks through covert channels, traditional security systems are unable to detect and respond in a timely manner, resulting in data leaks or service interruptions. Traditional security technologies respond to security incidents statically and rely on preset rules and response strategies, which limits their effectiveness in the face of unknown threats. In the current rapidly developing field of network security, it is difficult to protect networks from complex attacks. Summary of the invention
[0005] In order to solve the technical problems of insufficient flexibility and adaptability in the prior art, the embodiments of the present invention provide a satellite network multi-dimensional protection method and system based on graph neural network attacks. The technical solution is as follows:
[0006] On the one hand, a multi-dimensional protection method for satellite networks based on graph neural network attacks is provided, and the method includes:
[0007] S1: Based on the communication node status information, by real-time monitoring the connection status of multiple nodes, analyzing the connection data of multiple nodes in the satellite network, identifying the topology of the satellite communication network, and generating topology analysis results;
[0008] S2: Based on the topology analysis result, by analyzing the interaction mode between nodes, identifying the key nodes in the network, and predicting the attack initiation point and attack path of the external threat, generating the attack path prediction result;
[0009] S3: adjusting the security configuration of multiple network layers according to the attack path prediction result, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and generating network defense parameter configuration;
[0010] S4: Based on the network defense parameter configuration, real-time monitoring of network traffic and analysis of data transmission behavior, including identifying abnormal changes in data packet capacity, transmission frequency, and source, detecting abnormal activities, identifying security risk events, and generating real-time intrusion detection results;
[0011] S5: Based on the real-time intrusion detection results, the detected abnormal behavior data is analyzed, and by identifying the attack patterns in multiple security risk events, including attack types, origins, affected nodes, and propagation paths, the security database is updated, the defense mechanism is optimized, and the satellite network protection settings are generated.
[0012] Optionally, the topology structure analysis results include node connection data, node status information, and data flow identification information; the attack path prediction results specifically refer to key node identification results, attack initiation point analysis information, and attack path prediction data; the network defense parameter configuration includes firewall rule update records, access control adjustment results, and data encryption level setting parameters; the real-time intrusion detection results specifically include data packet capacity analysis results, transmission frequency monitoring information, and a security risk identification list; the satellite network protection settings include security database update records, attack pattern recognition results, and attack type information.
[0013] Optionally, based on the communication node status information, by real-time monitoring the connection status of multiple nodes, analyzing the connection data of multiple nodes in the satellite network, identifying the topology of the satellite communication network, and generating the topology analysis result are specifically as follows:
[0014] S101: Based on the communication node status information, collect the status information of multiple nodes in the satellite network, including the activity time and data exchange frequency of the nodes, monitor the connection status between the nodes in real time, and generate node status monitoring data;
[0015] S102: Analyze the connection stability and communication mode of multiple nodes based on the node status monitoring data, identify the data flow direction, and generate a connection stability analysis result;
[0016] S103: Based on the connection stability analysis result, by calculating the connectivity of multiple nodes and combining the connection path information, the topology structure of the satellite communication network is identified and a topology structure analysis result is generated.
[0017] Optionally, based on the topology analysis result, by analyzing the interaction mode between nodes, identifying the key nodes in the network, and predicting the attack initiation point and attack path of the external threat, the step of generating the attack path prediction result is specifically:
[0018] S201: Analyze the data interaction pattern between multiple nodes based on the topology structure analysis result, identify the traffic concentration area in the network by evaluating the direction and strength of the data flow, and generate a data interaction pattern analysis result;
[0019] S202: Based on the data interaction pattern analysis result, by analyzing the distribution of network traffic, calculating the activity of multiple nodes, identifying multiple key nodes in the network, and generating a key node identification result;
[0020] S203: Based on the key node identification result, according to the location and activity of multiple nodes in the network, predict the attack initiation point and attack path of the external threat, and generate an attack path prediction result.
[0021] Optionally, the specific formula for identifying multiple key nodes in the network is:
[0022]
[0023] Among them, K represents the criticality score, which is used to quantify the importance of each node in the network, and f i represents the interaction frequency of node i, w f Represents the weight coefficient of interaction frequency, s i represents the packet size of node i, w s Represents the weight coefficient of the packet size, t i represents the connection duration of node i, w t Represents the weight coefficient of the connection duration, d i represents the flow distribution of node i, w d Represents the weight coefficient of flow distribution, N represents the total number of nodes analyzed, and i represents the index of the node.
[0024] Optionally, according to the attack path prediction result, the security configuration of multiple network layers is adjusted, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and the steps of generating network defense parameter configuration are specifically as follows:
[0025] S301: Based on the attack path prediction result, collect configuration information of multiple network layers, including firewall rules and access control settings, compare with the predicted attack path, identify network security defense settings that need to be adjusted, and generate adjustment demand analysis results;
[0026] S302: Based on the adjustment demand analysis result, adjust the firewall rules and access control settings, and generate a firewall configuration update record;
[0027] S303: Based on the firewall configuration update record, adjust the settings of data encryption and traffic monitoring to generate a network defense parameter configuration.
[0028] Optionally, based on the network defense parameter configuration, the steps of real-time monitoring of network traffic, analyzing data transmission behavior, including identifying abnormal changes in data packet capacity, transmission frequency, and source, detecting abnormal activities, identifying security risk events, and generating real-time intrusion detection results are specifically as follows:
[0029] S401: Based on the network defense parameter configuration, monitor network traffic in real time, record monitoring information of multiple data packets, including capacity, frequency, and source, and generate traffic monitoring data;
[0030] S402: Analyze the data transmission behaviors of multiple nodes based on the traffic monitoring data, identify abnormal transmission behaviors, including abnormal data packet capacity and abnormal data transmission frequency, and generate abnormal behavior detection results;
[0031] S403: Based on the abnormal behavior detection results, analyze the abnormal behavior data, identify and mark security risk events, including DDoS attacks and data leaks, and generate real-time intrusion detection results.
[0032] Optionally, the specific formula for identifying abnormal transmission behavior is:
[0033]
[0034] Among them, E represents the anomaly score, C is the currently observed packet capacity, and μ C is the historical average of the packet capacity, σ C is the historical standard deviation of the packet size, F is the currently observed data transmission frequency, μ F is the historical average of data transmission frequency, σ F is the historical standard deviation of the data transmission frequency.
[0035] Optionally, based on the real-time intrusion detection results, the detected abnormal behavior data is analyzed, and by identifying attack patterns in multiple security risk events, including attack types, origins, affected nodes, and propagation paths, the security database is updated, the defense mechanism is optimized, and the steps of generating satellite network protection settings are specifically as follows:
[0036] S501: Based on the real-time intrusion detection results, analyze the abnormal behavior data in the marked security risk events, including data transmission frequency, data packet capacity, and transmission source, and generate a behavior data extraction record;
[0037] S502: Based on the behavior data extraction record, identify the attack pattern of the attacker in the target security risk event, including the attack type, attack origin, affected nodes, and attack path, and generate an attack pattern identification result;
[0038] S503: According to the attack pattern recognition result, the security database is updated, and the firewall rules and the response settings of the intrusion detection system are optimized, including adjusting the access control and data encryption parameters of the attacked node, and generating the satellite network protection settings.
[0039] On the other hand, a satellite network multi-dimensional protection system based on graph neural network attacks is provided, and the system is applied to a satellite network multi-dimensional protection method based on graph neural network attacks, and the system includes:
[0040] The node monitoring module collects the status information of multiple nodes in the satellite communication network based on the communication node status information, monitors the connection status of multiple nodes in real time, analyzes the stability of the connection, and generates node connection status analysis results;
[0041] The topology analysis module identifies the topology structure of the satellite communication network based on the node connection status analysis result and generates a topology structure analysis result;
[0042] The path analysis module analyzes the interaction mode between multiple nodes based on the topological structure analysis result, calculates the activity of multiple nodes and identifies key nodes, predicts the attack path of external threats, and generates attack path prediction results;
[0043] The configuration adjustment module updates the security configuration of multiple network layers based on the attack path prediction results, including adjusting firewall rules, updating access control lists, improving data encryption levels, adjusting network traffic detection parameters, and generating network defense parameter configurations;
[0044] The traffic monitoring module monitors network traffic in real time based on the network defense parameter configuration, analyzes and detects abnormal data transmission behavior, marks security risk events, and generates real-time intrusion detection results;
[0045] Based on the real-time intrusion detection results, the defense optimization module analyzes the attack modes of various security risk events, including attack types, origins, affected nodes and propagation paths, updates the security database and optimizes the defense settings, and generates satellite network protection settings.
[0046] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0047] By identifying the topological structure of the satellite communication network, analyzing the interaction patterns between nodes, identifying key nodes in the network and predicting the attack launch points of external threats, dynamic adjustment of security configurations of multiple network layers can be achieved, so that security policies can flexibly respond to external threats, improve the network's adaptability and response speed, and combine real-time monitoring and behavioral analysis to enable the system to quickly detect and identify abnormal activities and security risk events, optimize defense mechanisms, and ensure the continuity and security of network services. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0049] Figure 1 It is a schematic diagram of the workflow of the present invention;
[0050] Figure 2 This is a detailed flow chart of S1 of the present invention;
[0051] Figure 3 This is a detailed flow chart of S2 of the present invention;
[0052] Figure 4 This is a detailed flow chart of S3 of the present invention;
[0053] Figure 5 This is a detailed flow chart of S4 of the present invention;
[0054] Figure 6 This is a detailed flow chart of S5 of the present invention;
[0055] Figure 7 It is a system flow chart of the present invention. DETAILED DESCRIPTION
[0056] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0057] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "example" in the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present the concept in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or it can be either of the two.
[0058] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same. "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same.
[0059] In the embodiments of the present invention, sometimes the subscripts such as W 1 It may be written in non-subscript form such as W1. When the difference is not emphasized, the meaning is the same.
[0060] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0061] The embodiment of the present invention provides a multi-dimensional protection method for satellite networks based on graph neural network attacks, such as Figure 1 The flowchart of the satellite network multi-dimensional protection method based on graph neural network attack is shown in FIG. The processing flow of the method includes the following steps:
[0062] S1: Based on the communication node status information, by real-time monitoring the connection status of multiple nodes, analyzing the connection data of multiple nodes in the satellite network, identifying the topology of the satellite communication network, and generating topology analysis results;
[0063] S2: Based on the topology analysis results, by analyzing the interaction patterns between nodes, identify the key nodes in the network, predict the attack initiation point and attack path of external threats, and generate attack path prediction results;
[0064] S3: Based on the attack path prediction results, adjust the security configuration of multiple network layers, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and generating network defense parameter configurations;
[0065] S4: Based on the network defense parameter configuration, real-time monitoring of network traffic and analysis of data transmission behavior, including identification of abnormal changes in packet capacity, transmission frequency, and source, detection of abnormal activities, identification of security risk events, and generation of real-time intrusion detection results;
[0066] S5: Based on the real-time intrusion detection results, the detected abnormal behavior data is analyzed, and by identifying the attack patterns in multiple security risk events, including attack type, origin, affected nodes and propagation path, the security database is updated, the defense mechanism is optimized, and the satellite network protection settings are generated.
[0067] The topology analysis results include node connection data, node status information, and data flow identification information. The attack path prediction results specifically refer to key node identification results, attack initiation point analysis information, and attack path prediction data. The network defense parameter configuration includes firewall rule update records, access control adjustment results, and data encryption level setting parameters. The real-time intrusion detection results specifically include data packet capacity analysis results, transmission frequency monitoring information, and security risk identification lists. The satellite network protection settings include security database update records, attack pattern recognition results, and attack type information.
[0068] See also Figure 2 As shown, the steps of analyzing the connection data of multiple nodes in the satellite network based on the communication node status information, identifying the topology of the satellite communication network, and generating the topology analysis result are specifically as follows:
[0069] S101: Based on the communication node status information, collect the status information of multiple nodes in the satellite network, including the activity time and data exchange frequency of the nodes, monitor the connection status between the nodes in real time, and generate node status monitoring data;
[0070] In sub-step S101, SNMP is used to monitor the operating status and performance of network devices in real time, and the number of data transmission packets of each node is recorded in real time, including the number of packets sent and received, and the activity status of the network interface. The target data is collected by network monitoring tools and stored in a central database to form time series data. By analyzing the target time series data, the system evaluates the connection stability of each node, identifies potential network congestion or disconnection problems, and generates detailed node status monitoring data. The target data includes the communication delay data of each node, the packet loss rate and the periodic changes of its communication. The process ensures that network administrators can respond quickly based on real-time data and optimize network performance and reliability.
[0071] S102: Analyze the connection stability and communication mode of multiple nodes based on the node status monitoring data, identify the data flow direction, and generate a connection stability analysis result;
[0072] In sub-step S102, the network analysis tool Wireshark is used to capture and analyze the data packets in the network in detail. This tool sets specific filters and focuses on data flows related to network stability, such as packet size, sending and receiving intervals, and source addresses. Through target data, the system evaluates the connection stability between each node, including calculating network latency, analyzing packet loss and its transmission path. The analysis results help identify high-risk nodes in the network, that is, nodes with frequent data loss or high latency. The system also analyzes communication patterns between nodes, such as data flow direction and traffic distribution, and identifies the main data transmission paths in the network. The generated connection stability analysis results provide a scientific basis for network optimization, including connection quality reports and network traffic distribution maps between nodes, providing accurate data support for network administrators to adjust network architecture and improve network performance.
[0073] S103: Based on the connection stability analysis result, by calculating the connectivity of multiple nodes and combining the connection path information, the topology structure of the satellite communication network is identified and a topology structure analysis result is generated;
[0074] In sub-step S103, network analysis technology is used to calculate and identify the topological structure of the satellite communication network. The analysis involves calculating the connection stability indicators between nodes, such as transmission delay and packet loss rate, and combining the geographical location information of the nodes to build a connection graph of the network. Graph theory analysis methods, including the shortest path algorithm and the network flow algorithm, are used to evaluate the communication efficiency between nodes and the optimality of the path. The system also considers real-time communication data to verify the dynamic changes of the topological structure to ensure that the topological structure diagram accurately reflects the current state of the network. Through target composite analysis, the generated topological structure analysis results include not only the connection graph between nodes, but also the stability score of each connection and the key communication links, which provides decision support for network management, including providing key information in network expansion and fault recovery.
[0075] See also Figure 3 As shown, the steps of generating attack path prediction results based on the topology structure analysis results, analyzing the interaction patterns between nodes, identifying key nodes in the network, and predicting the attack initiation point and attack path of external threats are specifically as follows:
[0076] S201: Based on the topology analysis result, analyze the data interaction pattern between multiple nodes, identify the traffic concentration area in the network by evaluating the direction and strength of the data flow, and generate the data interaction pattern analysis result;
[0077] In sub-step S201, data flow analysis technologies, such as network packet analysis and traffic monitoring tools, are used to systematically evaluate the direction and strength of data flows between nodes and locate high-traffic nodes and data aggregation areas in the network. The process involves in-depth mining of network traffic data, including frequency analysis, data packet size distribution, and comparison of send and receive timestamps. This analysis helps identify hot spots of data flow. The target areas are often important nodes in the network and may also be potential security risk points. Through the generated data interaction pattern analysis results, network administrators can see detailed distribution maps of network traffic and key interaction nodes. The target results are crucial for the formulation of network traffic management and optimization strategies, helping administrators adjust network resources and optimize network performance.
[0078] S202: Based on the data interaction pattern analysis result, by analyzing the distribution of network traffic, calculating the activity of multiple nodes, identifying multiple key nodes in the network, and generating a key node identification result;
[0079] The specific formula for identifying multiple key nodes in the network is:
[0080]
[0081] Among them, K represents the criticality score, which is used to quantify the importance of each node in the network, and f i represents the interaction frequency of node i, w f Represents the weight coefficient of interaction frequency, s i represents the packet size of node i, w s Represents the weight coefficient of the packet size, t i represents the connection duration of node i, w t Represents the weight coefficient of the connection duration, d i represents the flow distribution of node i, w d Represents the weight coefficient of flow distribution, N represents the total number of nodes analyzed, and i represents the index of the node.
[0082] formula:
[0083]
[0084] Detailed explanation of the formula and the process of formula calculation and derivation:
[0085] The formula is used to calculate the criticality score of each node, identifying the nodes that are most critical to network security and stability;
[0086] Parameter meaning and setting value:
[0087] f i represents the interaction frequency of node i, which is assumed to be 100, reflecting the activity level of the node;
[0088] w f is the weight coefficient of interaction frequency, which is assumed to be 0.3, reflecting the importance of interaction frequency in criticality scoring;
[0089] s i represents the packet size of node i, assuming it is 500 bytes, and represents the amount of data processed by the node;
[0090] w s is the weight coefficient of the packet size, which is assumed to be 0.2, showing the influence of the packet size in the node criticality assessment;
[0091] t i Indicates the connection duration of node i, which is assumed to be 200 seconds, reflecting the connection stability of the node;
[0092] w t is the weight coefficient of connection duration, which is assumed to be 0.25, reflecting the importance of connection time in the scoring system;
[0093] d i represents the flow distribution of node i, quantified as the number of nodes directly connected to the node, assumed to be 5, indicating the connection breadth of the node;
[0094] w d is the weight coefficient of flow distribution, assumed to be 0.25, reflecting the impact of flow distribution on node criticality;
[0095] N is the total number of nodes analyzed, assuming there are 50 nodes in the network;
[0096] Substitute the parameters into the formula for calculation:
[0097]
[0098] K i =3.625;
[0099] The result 3.625 indicates that the comprehensive criticality score of the target node is 3.625, which reflects the criticality of the node in the network.
[0100] S203: Based on the key node identification result, according to the location and activity of multiple nodes in the network, predict the attack initiation point and attack path of the external threat, and generate an attack path prediction result;
[0101] In sub-step S203, network analysis technology is used to predict potential attack initiation points and attack paths. The process involves a comprehensive assessment of the geographical location and communication activity of each node in the network, and a path analysis algorithm is used to simulate possible attack scenarios. By evaluating abnormally concentrated areas of data traffic and nodes with abnormally increased communication frequencies, the system can infer the paths that attackers may use, and combine historical security event data with the current security defense status of the network to refine the prediction of the attack path. The generated attack path prediction results include possible attack starting points, key transition nodes, and communication link diagrams to the joint points. The target information is of great significance for strengthening security protection measures in specific areas and deploying defense resources in advance.
[0102] See also Figure 4 As shown, the steps of adjusting the security configuration of multiple network layers according to the attack path prediction results, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and generating network defense parameter configurations are specifically as follows:
[0103] S301: Based on the attack path prediction result, collect configuration information of multiple network layers, including firewall rules and access control settings, compare with the predicted attack path, identify the network security defense settings that need to be adjusted, and generate adjustment demand analysis results;
[0104] In sub-step S301, use configuration management tools, such as Cisco Security Manager, to access and audit existing security settings, compare them with predicted attack paths, systematically analyze the coverage and protection effectiveness of existing security policies, and identify weak links in security configurations, such as outdated firewall rules or insufficient access control measures. Through this comparative analysis, the system generates adjustment needs analysis results, which lists in detail the security settings that need to be updated or strengthened, including recommended changes to firewall rules, strengthened data encryption measures, and new access control policies, aimed at enhancing the overall security of the network, including on predicted attack paths, to ensure that network security defenses can respond to potential threats in a timely manner.
[0105] S302: Based on the adjustment demand analysis result, adjust the firewall rules and access control settings, and generate a firewall configuration update record;
[0106] In sub-step S302, use network security management tools, such as Cisco ASA Firewall Management, to import the current firewall configuration and modify the rules for identified security weaknesses, including adding new access rules, deleting or modifying outdated rules, and updating rule priorities. The process involves recording the specific content of each modification, including the specific changes to the rules, the reasons for the changes, and the expected security enhancement effects. All target modified configurations are not only backed up locally, but also synchronously updated to the firewalls of all network nodes to ensure the consistency of firewall rules for the entire network. Enhanced access control policies are also implemented, including strict restrictions on access to sensitive data. The generated firewall configuration update records reflect all target changes in detail, providing a basis for future security audits.
[0107] S303: Based on the firewall configuration update record, adjust the settings of data encryption and traffic monitoring to generate network defense parameter configuration;
[0108] In sub-step S303, using network security configuration tools such as Juniper Network SecurityManager, the system administrator evaluates the strength and scope of application of the current data encryption protocol, and adjusts the encryption algorithm and key length according to the sensitivity and importance of data transmission in the network. For traffic monitoring, advanced traffic analysis tools such as NetFlow Analyzer are introduced to monitor changes in network traffic in real time, including monitoring data flows through key nodes, and displaying the source, destination, and transmission path of the traffic in a fine-grained manner to help identify unauthorized data access attempts or abnormal data flows. Through target adjustment, the system generates a comprehensive network defense parameter configuration, including updated encryption policies and traffic monitoring policies, ensuring that the network's security performance meets the latest security requirements while enhancing the monitoring and response capabilities to potential network attacks.
[0109] See also Figure 5 As shown, the steps of real-time monitoring of network traffic and analyzing data transmission behavior based on network defense parameter configuration, including identifying abnormal changes in data packet capacity, transmission frequency, and source, detecting abnormal activities, identifying security risk events, and generating real-time intrusion detection results are specifically as follows:
[0110] S401: Based on the network defense parameter configuration, monitor the network traffic in real time, record the monitoring information of multiple data packets, including capacity, frequency, and source, and generate traffic monitoring data;
[0111] In sub-step S401, by deploying network traffic analysis tools such as SolarWinds NetworkPerformance Monitor, detailed information of each data packet passing through the network is continuously tracked and recorded, including the capacity, frequency and source of the data packet, including setting up network traffic capture filters to specifically monitor data flowing out and in from key infrastructure nodes, performing time series analysis on target data, and detecting any unusual changes in network traffic, such as sudden increases in traffic or frequent transmission of small data packets, which may indicate network congestion or scanning activities. The system automatically records all target monitoring data and formats it for storage in a central database for deeper analysis and backtracking. The generated traffic monitoring data includes data flow diagrams and time-stamped event logs, providing the network security team with a real-time view of the network status.
[0112] S402: Analyze the data transmission behaviors of multiple nodes based on the traffic monitoring data, identify abnormal transmission behaviors, including abnormal data packet capacity and abnormal data transmission frequency, and generate abnormal behavior detection results;
[0113] Specific formula for identifying abnormal transmission behavior:
[0114]
[0115] Among them, E represents the anomaly score, C is the currently observed packet capacity, and μ C is the historical average of the packet capacity, σ C is the historical standard deviation of the packet size, F is the currently observed data transmission frequency, μ F is the historical average of data transmission frequency, σ F is the historical standard deviation of the data transmission frequency.
[0116] formula:
[0117]
[0118] Detailed explanation of the formula and the process of formula calculation and derivation:
[0119] The formula is used to calculate the abnormal behavior score, which indicates the degree to which the data transmission behavior deviates from the normal range. The result is used to identify abnormal transmission behavior.
[0120] Parameter meaning and setting value:
[0121] C represents the currently observed packet capacity, assumed to be 500;
[0122] μ C Indicates the historical average value of the packet capacity, assumed to be 450;
[0123] σC represents the historical standard deviation of the packet capacity, assumed to be 50;
[0124] F represents the currently observed data transmission frequency, which is assumed to be 20;
[0125] μ F Indicates the historical average value of data transmission frequency, assumed to be 15;
[0126] σ F represents the historical standard deviation of data transmission frequency, assumed to be 5;
[0127] Substitute the parameters into the formula for calculation:
[0128]
[0129] The result 1.414 shows that the currently observed data transmission behavior is significantly different from the historical data. The result is used to identify abnormal data transmission behavior.
[0130] S403: Based on the abnormal behavior detection results, analyze the abnormal behavior data, identify and mark security risk events, including DDoS attacks and data leaks, and generate real-time intrusion detection results;
[0131] In sub-step S403, the intrusion detection system Snort is used to analyze the collected abnormal behavior data, including unconventional data flows from key nodes and potential signs of security vulnerabilities. By setting specific security event triggering rules, the system can automatically identify and classify various security threats, such as DDoS attacks and data leakage incidents, including applying pattern matching technology to detect known malicious behavior signatures, and using anomaly detection algorithms to identify emerging threat patterns. Records include attack type, starting source IP, affected nodes and their propagation paths. The generated real-time intrusion detection results provide the network operation and maintenance team with immediate security alerts and response guidance, helping them to take quick measures to prevent or mitigate the impact of security incidents.
[0132] See also Figure 6 As shown, the steps of analyzing the detected abnormal behavior data based on the real-time intrusion detection results, updating the security database, optimizing the defense mechanism, and generating the satellite network protection settings are as follows:
[0133] S501: Based on the real-time intrusion detection results, analyze the abnormal behavior data in the marked security risk events, including data transmission frequency, data packet capacity, and transmission source, and generate behavior data extraction records;
[0134] In sub-step S501, a network behavior analysis tool, such as NetWitness, is used to analyze abnormal data transmission frequency, data packet capacity, and transmission source. The system collects detailed data of abnormal events through target tools and uses statistical analysis techniques to evaluate the degree of abnormality of the data, such as a sudden increase in data traffic or atypical large-capacity data packets. Target analysis helps determine the nature of possible security threats and network intrusion behaviors. The generated behavioral data extraction record describes in detail the specific characteristics of each abnormal event, such as frequency peaks, size distribution of abnormal data packets, and source IP addresses, providing basic data for security incident investigations.
[0135] S502: Based on the behavior data extraction records, identify the attack mode of the attacker in the target security risk event, including the attack type, attack origin, affected nodes, and attack path, and generate an attack mode identification result;
[0136] In sub-step S502, machine learning classification algorithms, such as support vector machines, are applied to perform pattern recognition on the data to analyze and classify different types of attack behaviors, such as DDoS attacks and data leaks. Through the target algorithm, the system can extract key features from abnormal behavior data and predict the possible type and origin of the attack. The system also analyzes the affected nodes and attack paths, integrates the target information to generate detailed attack pattern recognition results. The target results clearly indicate the core nodes of the attack, the starting point of the attack, and the path of the attack spread, providing key information for formulating response measures.
[0137] S503: updating the security database, optimizing the firewall rules and the response settings of the intrusion detection system according to the attack pattern identification results, including adjusting the access control and data encryption parameters of the attacked nodes, and generating the satellite network protection settings;
[0138] In sub-step S503, a dynamic security management platform, such as Palo Alto Networks Panorama, is used to update firewall rules in real time and adjust the response parameters of the intrusion detection system to ensure that all security settings are optimized based on the latest threat intelligence and attack trends. The generated satellite network protection settings include updated access control lists, encryption protocols, and security incident response strategies, which enhance the network's ability to combat complex attack patterns.
[0139] See also Figure 7 As shown, the satellite network multi-dimensional protection system based on graph neural network attack is used to execute the above-mentioned satellite network multi-dimensional protection method based on graph neural network attack, and the system includes:
[0140] The node monitoring module collects the status information of multiple nodes in the satellite communication network based on the communication node status information, monitors the connection status of multiple nodes in real time, analyzes the stability of the connection, and generates node connection status analysis results;
[0141] The topology analysis module identifies the topology structure of the satellite communication network based on the node connection status analysis results and generates topology structure analysis results;
[0142] The path analysis module analyzes the interaction patterns between multiple nodes based on the topological structure analysis results, calculates the activity of multiple nodes and identifies key nodes, predicts the attack path of external threats, and generates attack path prediction results;
[0143] The configuration adjustment module updates the security configuration of multiple network layers based on the attack path prediction results, including adjusting firewall rules, updating access control lists, improving data encryption levels, adjusting network traffic detection parameters, and generating network defense parameter configurations;
[0144] The traffic monitoring module monitors network traffic in real time based on network defense parameter configuration, analyzes and detects abnormal data transmission behavior, marks security risk events, and generates real-time intrusion detection results;
[0145] Based on real-time intrusion detection results, the defense optimization module analyzes the attack patterns of various security risk events, including attack type, origin, affected nodes and propagation path, updates the security database and optimizes defense settings to generate satellite network protection settings.
[0146] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When a computer instruction or computer program is loaded or executed on a computer, a process or function according to an embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.
[0147] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.
[0148] In the present invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0149] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0150] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0151] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0152] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0153] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0154] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0155] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0156] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A multi-dimensional protection method for satellite networks based on graph neural network attacks, characterized in that: The method comprises: Based on the communication node status information, by real-time monitoring of the connection status of multiple nodes, the connection data of multiple nodes in the satellite network are analyzed, the topology of the satellite communication network is identified, and the topology analysis results are generated; Based on the topology analysis results, by analyzing the interaction patterns between nodes, identifying key nodes in the network, and predicting the attack initiation point and attack path of external threats, generating attack path prediction results; According to the attack path prediction results, adjust the security configuration of multiple network layers, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and generating network defense parameter configurations; Based on the network defense parameter configuration, real-time monitoring of network traffic and analysis of data transmission behavior, including identification of abnormal changes in data packet capacity, transmission frequency, and source, detection of abnormal activities, identification of security risk events, and generation of real-time intrusion detection results; Based on the real-time intrusion detection results, the detected abnormal behavior data is analyzed, and by identifying attack patterns in multiple security risk events, including attack types, origins, affected nodes, and propagation paths, the security database is updated, the defense mechanism is optimized, and the satellite network protection settings are generated.
2. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: The topology structure analysis results include node connection data, node status information, and data flow identification information; the attack path prediction results specifically refer to key node identification results, attack initiation point analysis information, and attack path prediction data; the network defense parameter configuration includes firewall rule update records, access control adjustment results, and data encryption level setting parameters; the real-time intrusion detection results specifically include data packet capacity analysis results, transmission frequency monitoring information, and a security risk identification list; the satellite network protection settings include security database update records, attack pattern recognition results, and attack type information.
3. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: Based on the communication node status information, by real-time monitoring of the connection status of multiple nodes, the connection data of multiple nodes in the satellite network are analyzed to identify the topology of the satellite communication network. The steps for generating the topology analysis results are as follows: Based on the communication node status information, collect the status information of multiple nodes in the satellite network, including the node activity time and data exchange frequency, monitor the connection status between nodes in real time, and generate node status monitoring data; Based on the node status monitoring data, analyzing the connection stability and communication mode of multiple nodes, identifying the data flow direction, and generating a connection stability analysis result; Based on the connection stability analysis result, the topology of the satellite communication network is identified by calculating the connectivity of multiple nodes and combining the connection path information to generate a topology analysis result.
4. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: Based on the topology analysis results, by analyzing the interaction patterns between nodes, identifying key nodes in the network, and predicting the attack initiation point and attack path of external threats, the steps of generating the attack path prediction results are specifically as follows: Based on the topology structure analysis results, the data interaction patterns among multiple nodes are analyzed, and the traffic concentration areas in the network are identified by evaluating the direction and strength of the data flow, thereby generating data interaction pattern analysis results; Based on the data interaction pattern analysis result, by analyzing the distribution of network traffic, calculating the activity of multiple nodes, identifying multiple key nodes in the network, and generating key node identification results; Based on the key node identification results, according to the positions and activities of multiple nodes in the network, the attack initiation point and attack path of the external threat are predicted, and the attack path prediction result is generated.
5. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 4 is characterized in that: The specific formula for identifying multiple key nodes in the network is: Among them, K represents the criticality score, which is used to quantify the importance of each node in the network, and f i represents the interaction frequency of node i, w f Represents the weight coefficient of interaction frequency, s i represents the packet size of node i, w s Represents the weight coefficient of the packet size, t i represents the connection duration of node i, w t Represents the weight coefficient of the connection duration, d i represents the flow distribution of node i, w d Represents the weight coefficient of flow distribution, N represents the total number of nodes analyzed, and i represents the index of the node.
6. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: According to the attack path prediction results, the security configuration of multiple network layers is adjusted, including updating firewall rules and access control lists, adjusting data encryption levels and traffic detection levels, and generating network defense parameter configuration steps as follows: Based on the attack path prediction results, collect configuration information of multiple network layers, including firewall rules and access control settings, compare with the predicted attack path, identify network security defense settings that need to be adjusted, and generate adjustment demand analysis results; Based on the adjustment demand analysis results, adjust firewall rules and access control settings, and generate firewall configuration update records; Based on the firewall configuration update record, the settings for data encryption and traffic monitoring are adjusted to generate a network defense parameter configuration.
7. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: Based on the network defense parameter configuration, the steps of real-time monitoring of network traffic and analyzing data transmission behavior, including identifying abnormal changes in data packet capacity, transmission frequency, and source, detecting abnormal activities, identifying security risk events, and generating real-time intrusion detection results are as follows: Based on the network defense parameter configuration, the network traffic is monitored in real time, the monitoring information of multiple data packets, including capacity, frequency, and source, is recorded, and traffic monitoring data is generated; Based on the traffic monitoring data, the data transmission behaviors of multiple nodes are analyzed to identify abnormal transmission behaviors, including abnormal data packet capacity and abnormal data transmission frequency, and generate abnormal behavior detection results; Based on the abnormal behavior detection results, the abnormal behavior data is analyzed, security risk events, including DDoS attacks and data leaks, are identified and marked, and real-time intrusion detection results are generated.
8. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 7 is characterized in that: The specific formula for identifying abnormal transmission behavior is: Among them, E represents the anomaly score, C is the currently observed packet capacity, and μ C is the historical average of the packet capacity, σ C is the historical standard deviation of the packet size, F is the currently observed data transmission frequency, μ F is the historical average of data transmission frequency, σ F is the historical standard deviation of the data transmission frequency.
9. The satellite network multi-dimensional protection method based on graph neural network attack according to claim 1 is characterized in that: Based on the real-time intrusion detection results, the detected abnormal behavior data is analyzed, and the attack patterns in multiple security risk events are identified, including attack types, origins, affected nodes, and propagation paths, so as to update the security database, optimize the defense mechanism, and generate the satellite network protection settings in the following steps: Based on the real-time intrusion detection results, analyze the abnormal behavior data in the marked security risk events, including data transmission frequency, data packet capacity, and transmission source, and generate behavior data extraction records; Based on the behavior data extraction records, identify the attack pattern of the attacker in the target security risk event, including the attack type, attack origin, affected nodes, and attack path, and generate an attack pattern identification result; According to the attack pattern identification results, the security database is updated, the firewall rules and the response settings of the intrusion detection system are optimized, including adjusting the access control and data encryption parameters of the attacked nodes, and the satellite network protection settings are generated.
10. A satellite network multi-dimensional protection system based on graph neural network attacks, characterized in that: According to any one of claims 1 to 9, the satellite network multi-dimensional protection method based on graph neural network attacks comprises: The node monitoring module collects the status information of multiple nodes in the satellite communication network based on the communication node status information, monitors the connection status of multiple nodes in real time, analyzes the stability of the connection, and generates node connection status analysis results; The topology analysis module identifies the topology structure of the satellite communication network based on the node connection status analysis result and generates a topology structure analysis result; The path analysis module analyzes the interaction mode between multiple nodes based on the topological structure analysis result, calculates the activity of multiple nodes and identifies key nodes, predicts the attack path of external threats, and generates attack path prediction results; The configuration adjustment module updates the security configuration of multiple network layers based on the attack path prediction results, including adjusting firewall rules, updating access control lists, improving data encryption levels, adjusting network traffic detection parameters, and generating network defense parameter configurations; The traffic monitoring module monitors network traffic in real time based on the network defense parameter configuration, analyzes and detects abnormal data transmission behavior, marks security risk events, and generates real-time intrusion detection results; Based on the real-time intrusion detection results, the defense optimization module analyzes the attack modes of various security risk events, including attack types, origins, affected nodes and propagation paths, updates the security database and optimizes the defense settings, and generates satellite network protection settings.
Citation Information
Patent Citations
Security policy management method and device
CN107395617A
Satellite network adaptive security service system and method
CN117014203A
Network security emergency information collection and analysis method and system
CN118316708A
Intrusion detection and response method and system of satellite internet target range
CN119155101A
An integrated ai-driven system for automating it and cybersecurity operations
WO2024145209A1
Cited By
Network situation awareness processing method and system based on large model feature fusion
CN121727631A