Satellite network multi-dimensional threat simulation method and system based on isolated forest detection

By applying isolated forest detection algorithms and multi-dimensional threat simulation methods in satellite networks, the shortcomings of the existing technology in real-time data processing and immediate threat response are solved, and efficient identification and response to multi-dimensional threats are achieved, which significantly improves the security and stability of the network.

CN120050067AActive Publication Date: 2025-05-27XINGCHEN XUANJI (BEIJING) MEASUREMENT & CONTROL TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510078653.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-27
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The prior art has shortcomings in real-time data processing and immediate threat response, and cannot effectively intercept or mitigate new or variant threats, resulting in insufficient protection of network systems in the face of multi-dimensional threats, affecting the stability and reliability of the overall network.

Method used

A multi-dimensional threat simulation method for satellite networks based on isolated forest detection is adopted. Through the extraction and analysis of real-time traffic data, an isolated forest algorithm is used to identify abnormal patterns, evaluate threat risks, adjust defense configurations, and conduct multi-dimensional threat simulation tests in a virtual environment.

Benefits of technology

Real-time threat awareness and evaluation of satellite networks are realized, the response speed and effectiveness to multi-dimensional threats are improved, and the overall security of the network and the adaptability of defense configurations are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050067A_ABST
    Figure CN120050067A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a satellite network multi-dimensional threat simulation method and system based on isolated forest detection. The method comprises the following steps of: loading real-time traffic data of a satellite network through a data interface, extracting key indexes, recording traffic size, time delay and packet loss probability, and establishing an initialized traffic characteristic framework; according to the method, through accurate identification of the abnormal modes and comparison with known threat features, judgment of potential threats is more accurate, resource waste caused by misinformation is avoided, evaluation of multi-dimensional threat degrees and specific analysis of threat risks provide more comprehensive safety evaluation, defense measures are more targeted and efficient, and the method is suitable for popularization and application. And the defense configuration is adjusted, and the defense scheme is tested in the virtual environment, so that the effectiveness of the adjustment measure is further verified, the resistance of the satellite network to actual threats is ensured, and the adaptability of the defense configuration and the overall security of the network are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a multi-dimensional threat simulation method and system for satellite networks based on isolated forest detection. Background Art

[0002] The field of network security technology involves protecting computer networks from unauthorized access and threats, including various practices and technical strategies for protecting the integrity, confidentiality, and availability of networks and network-accessible resources. Network security measures aim to defend against various network threats, data breaches, malware propagation, etc. against enterprise and individual users. This technical field is often used in combination with encryption technology, intrusion detection systems, firewalls, and the latest artificial intelligence technology, etc., to improve the efficiency of detecting and responding to network threats.

[0003] Among them, the multi-dimensional threat simulation method for satellite networks based on isolated forest detection refers to using the isolated forest algorithm to identify and evaluate abnormal and threatening behaviors that occur in satellite networks. This method is applied in the security management of satellite communication networks and can simulate and predict various threat scenarios, such as network intrusion, data tampering, and denial-of-service threats, etc. Through this simulation, the impact and intrusion path can be predicted before an actual threat occurs, effectively enhancing the security and resistance of satellite networks. The main use of this technology is to provide an efficient and feasible security assessment tool for satellite networks, so as to timely discover potential security problems and take corresponding protection measures.

[0004] Although the prior art provides basic network security protection, there are obvious deficiencies in real-time data processing and immediate threat response. The prior art relies on static defense mechanisms and threat identification systems with large delays, resulting in a long response time when facing rapidly evolving threats and being unable to effectively intercept or mitigate new or variant threats. For example, traditional intrusion detection systems cannot timely identify and process unknown threat patterns, so they are slow to react in the face of new malware propagation or complex data tampering threats, which may lead to the leakage or loss of important information. Due to the lack of effective real-time risk assessment, the prior art is difficult to accurately adjust defense strategies, making the protection of network systems against multi-dimensional threats insufficiently comprehensive and affecting the stability and reliability of the overall network. Summary of the Invention

[0005] To address the significant deficiencies in real-time data processing and immediate threat response in the existing technology. The existing technology relies on static defense mechanisms and threat recognition systems with relatively large delays, resulting in longer response times when facing rapidly evolving threats and being unable to effectively intercept or mitigate new or variant threats. For example, traditional intrusion detection systems cannot promptly identify and process unknown threat patterns, thus showing sluggish responses in the face of the spread of new malware or complex data tampering threats, which may lead to the leakage or loss of important information. Due to the lack of effective real-time risk assessment, it is difficult for the existing technology to accurately adjust defense strategies, making the protection of network systems against multi-dimensional threats insufficiently comprehensive and affecting the stability and reliability of the overall network. Embodiments of the present invention provide a multi-dimensional threat simulation method and system for satellite networks based on isolation forest detection. The technical solutions are as follows:

[0006] On the one hand, a multi-dimensional threat simulation method for satellite networks based on isolation forest detection is provided. The method includes:

[0007] S1: Load the real-time traffic data of the satellite network through a data interface, extract key metrics, record the traffic size, delay, and packet loss rate, and establish an initial traffic characteristic framework;

[0008] S2: Through the initial traffic characteristic framework, use the isolation forest algorithm to identify abnormal patterns in the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and obtain the abnormal pattern recognition result;

[0009] S3: According to the abnormal pattern recognition result, evaluate the multi-dimensional threat level of the abnormal data, identify the risk rating of each threat type by analyzing the harm level and frequency of the threat type, and output the threat risk assessment result;

[0010] S4: Adopt the threat risk assessment result to adjust the satellite network defense configuration, update the rules of intrusion detection and the defense of the firewall, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks, and obtain the defense configuration adjustment plan;

[0011] S5: Conduct multi-dimensional threat simulation in a virtual environment, test the processing speed of the defense configuration adjustment plan for threats, detect the impact of the defense configuration adjustment on the performance of the satellite network, evaluate the implementation effect and impact, and identify the overall security of the satellite network to obtain the multi-dimensional threat simulation test result.

[0012] Optionally, the initialization traffic characteristic framework includes traffic volume metrics, latency metrics, and packet loss rate metrics. The abnormal pattern recognition results include abnormal fluctuation recognition and potential threat marking. The threat risk assessment results include the analysis of the harm level of each threat type, the calculation of threat frequency, and the corresponding risk rating. The defense configuration adjustment plan includes intrusion detection rule update, firewall defense adjustment, and satellite network device configuration update. The multi-dimensional threat simulation test results include processing speed test, satellite network performance impact assessment, and overall security rating.

[0013] Optionally, the steps of loading the real-time traffic data of the satellite network through the data interface, extracting key metrics, recording the traffic volume, latency, and packet loss rate, and establishing the initialization traffic characteristic framework are specifically as follows:

[0014] S101: Load the real-time traffic data of the satellite network through the data interface, synchronize and receive the traffic data in real time, including the traffic volume, latency, and packet loss rate, perform data quality initialization monitoring, screen out problematic data segments, and obtain a dynamic data set;

[0015] S102: Use the dynamic data set to format the data, adjust the data format, perform data processing, remove invalid and incorrect data records, and perform standardization processing on the processed data to obtain a standardized data set;

[0016] S103: According to the standardized data set, classify the real-time traffic data, group them according to the differential ranges of the traffic volume, latency, and packet loss rate, identify and summarize the target characteristics of each type of data, and establish an initialization traffic characteristic framework.

[0017] Optionally, through the initialization traffic characteristic framework, use the Isolation Forest algorithm to perform abnormal pattern recognition on the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and the steps to obtain the abnormal pattern recognition results are specifically as follows:

[0018] S201: Based on the initialization traffic characteristic framework, perform initialization screening on the real-time traffic data, identify data points with fluctuations, and perform abnormal marking on the data points to obtain an initialization abnormal data marking result;

[0019] S202: Use the initialization abnormal data marking result to analyze the marked data, compare it with a preset abnormal pattern, identify abnormal data that matches the known pattern, and classify the data as potential threats to obtain an abnormal comparison analysis result;

[0020] S203: Use the abnormal comparison analysis result to classify and label the identified abnormal patterns, analyze the types and potential threat levels of each abnormal pattern, and obtain the abnormal pattern recognition result.

[0021] Optionally, according to the abnormal pattern recognition result, the steps of evaluating the multi-dimensional threat degree of abnormal data, identifying the risk rating of each threat type by analyzing the harm level and frequency of the threat type, and outputting the threat risk assessment result are specifically as follows:

[0022] S301: Use the abnormal pattern recognition result to extract the types and frequency information of multiple types of abnormal data, conduct a risk impact analysis on each abnormal type, identify the threat degree of each abnormal, and obtain the abnormal type analysis result;

[0023] S302: According to the abnormal type analysis result, evaluate the harm level and occurrence frequency of each abnormal type, calculate the risk level of the abnormal type, and obtain the threat risk rating record;

[0024] S303: Through the threat risk rating record, integrate the risk levels and potential harms of multiple types of abnormal patterns, identify the influencing factors of potential harms, and output the threat risk assessment result.

[0025] Optionally, the formula for calculating the risk level of the abnormal type is as follows:

[0026]

[0027] Among them, R i represents the risk level of the i-th abnormal type, w j represents the weight coefficient of the j-th evaluation factor, f ij represents the score of the i-th abnormal type on the j-th evaluation factor, C i represents the continuous impact evaluation value of the i-th abnormal type, and n is the number of evaluation factors.

[0028] Optionally, the steps of using the threat risk assessment result to adjust the satellite network defense configuration, update the intrusion detection rules and firewall defenses, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks, and obtain the defense configuration adjustment plan are specifically as follows:

[0029] S401: Use the threat risk assessment result to analyze the risk ratings of different threat types, and according to the risk ratings, adjust the intrusion detection rules and firewall policies for the corresponding more risky attacks to obtain the priority defense adjustment result;

[0030] S402: Update the defense configuration of the satellite network based on the priority defense adjustment result, adjust the security settings of associated satellite network devices, optimize the monitoring and protection of risk areas, and obtain the updated defense measures;

[0031] S403: Implement the updated defense measures, conduct configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, and intercept and mitigate potential multi-dimensional threat attacks to obtain the defense configuration adjustment plan.

[0032] Optionally, the steps of performing multi-dimensional threat simulation in a virtual environment, testing the processing speed of the defense configuration adjustment plan against threats, detecting the impact of the defense configuration adjustment on the performance of the satellite network, evaluating the implementation effect and impact, and identifying the overall security of the satellite network to obtain the multi-dimensional threat simulation test results are specifically as follows:

[0033] S501: Use the virtual environment and import the defense configuration adjustment plan to conduct simulation tests on various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, calculate the defense efficiency under different scenarios, and obtain simulation test data;

[0034] S502: According to the simulation test data, monitor and record the impact of the defense configuration on the performance of the satellite network, analyze the network latency, data throughput rate, and resource utilization rate after the implementation of the defense measures, and obtain the performance impact evaluation result;

[0035] S503: Use the performance impact evaluation result to analyze the overall security and implementation effect of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, and conduct a security evaluation of multi-dimensional threats to obtain the multi-dimensional threat simulation test result.

[0036] Optionally, the formula for calculating the defense efficiency under different scenarios is:

[0037]

[0038] where R is the defense efficiency value, N represents the total number of simulated scenarios, T a represents the defense response time of the a-th scenario, T avg represents the average defense response time of the scenarios, and σ represents the standard deviation of the defense response time.

[0039] On the other hand, an electric vehicle status monitoring system is provided. The electric vehicle status monitoring system is used to execute the above-mentioned electric vehicle status monitoring method. The system includes:

[0040] The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including the traffic size, delay, and packet loss rate, to obtain the real-time traffic archive;

[0041] Based on the real-time traffic profile, the traffic characteristics analysis module collects and collates key metrics, analyzes the performance and characteristics of the key metrics, and constructs an initial traffic characteristics framework;

[0042] Based on the initialized traffic characteristics framework, the anomaly recognition module uses the Isolation Forest algorithm to screen the real-time data, detect abnormal fluctuations and potential threats, and obtain the anomaly pattern analysis results;

[0043] Based on the anomaly pattern analysis results, the threat rating module evaluates the multi-dimensional threat level of the abnormal data, and conducts risk rating for each threat type by comparing the harm levels and occurrence frequencies of different threat types, and obtains the threat risk rating results;

[0044] Based on the threat risk rating results, the defense strategy adjustment module updates the defense configuration of the satellite network, adjusts the intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains the defense configuration plan;

[0045] The test and evaluation module uses the defense configuration plan to conduct multi-dimensional threat simulation tests in a virtual environment, evaluates the processing speed of the defense strategy and its impact on the performance of the satellite network, verifies the implementation effect, identifies the overall security of the satellite network, and obtains the multi-dimensional threat simulation test results.

[0046] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:

[0047] Through the extraction and analysis of real-time traffic data, as well as the identification and risk assessment of abnormal patterns, the security of the satellite network is effectively enhanced. By using real-time data monitoring and key metric extraction, the real-time perception ability of the satellite network status is enhanced, abnormal fluctuations and potential threats can be discovered immediately. Through the accurate identification of abnormal patterns and comparison with known threat characteristics, the determination of potential threats is more accurate, avoiding resource waste caused by false alarms. The assessment of multi-dimensional threat levels and the specific analysis of threat risks provide a more comprehensive security assessment, making the defense measures more targeted and efficient. Adjusting the defense configuration and testing the defense plan in a virtual environment further verifies the effectiveness of the adjustment measures, ensures the resistance ability of the satellite network in the face of actual threats, and significantly improves the adaptability of the defense configuration and the overall security of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It is a schematic diagram of the working process of the present invention;

[0049] Figure 2 It is a detailed flowchart of S1 of the present invention;

[0050] Figure 3 It is a detailed flowchart of S2 of the present invention;

[0051] Figure 4 It is the refined flowchart of S3 of the present invention;

[0052] Figure 5 It is the refined flowchart of S4 of the present invention;

[0053] Figure 6 It is the refined flowchart of S5 of the present invention;

[0054] Figure 7 It is the system flowchart of the present invention. Specific embodiments

[0055] Next, in combination with the accompanying drawings, the technical solutions in the present invention will be described.

[0056] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.

[0057] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail in combination with the accompanying drawings and specific embodiments.

[0058] Please refer to Figure 1 As shown, the embodiments of the present invention provide a satellite network multi-dimensional threat simulation method based on isolation forest detection. The processing flow of this method can include the following steps:

[0059] S1: Load the real-time traffic data of the satellite network through the data interface, extract key indicators, record the traffic size, delay and packet loss rate, and establish an initial traffic characteristic framework;

[0060] S2: Through the initial traffic characteristic framework, use the isolation forest algorithm to identify abnormal patterns in the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and obtain the abnormal pattern recognition result;

[0061] S3: According to the abnormal pattern recognition result, evaluate the multi-dimensional threat degree of the abnormal data, identify the risk rating of each threat type by analyzing the harm level and frequency of the threat type, and output the threat risk assessment result;

[0062] S4: Use the threat risk assessment results to adjust the satellite network defense configuration, update the intrusion detection rules and the firewall defense, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan;

[0063] S5: Conduct multi-dimensional threat simulation in a virtual environment, test the threat handling speed of the defense configuration adjustment plan, detect the impact of the defense configuration adjustment on the satellite network performance, evaluate the implementation effect and impact, identify the overall security of the satellite network, and obtain the multi-dimensional threat simulation test results.

[0064] The initialized traffic characteristic framework includes traffic size metrics, delay metrics, and packet loss rate metrics. The abnormal pattern recognition results include abnormal fluctuation recognition and potential threat marking. The threat risk assessment results include the analysis of the harm level for each threat type, the calculation of threat frequency, and the corresponding risk rating. The defense configuration adjustment plan includes the update of intrusion detection rules, the adjustment of firewall defense, and the update of satellite network device configuration. The multi-dimensional threat simulation test results include the processing speed test, the evaluation of the impact on satellite network performance, and the overall security rating.

[0065] Please refer to Figure 2 As shown, the steps to establish an initialized traffic characteristic framework by loading the real-time traffic data of the satellite network through a data interface, extracting key metrics, recording the traffic size, delay, and packet loss rate are as follows:

[0066] S101: Load the real-time traffic data of the satellite network through a data interface, synchronize and receive the traffic data in real time, including the traffic size, delay, and packet loss rate, conduct initial monitoring of data quality, screen out problematic data segments, and the execution process to obtain a dynamic data set is as follows;

[0067] Load the real-time traffic data of the satellite network through a data interface. The interface provides three items of data: traffic size, delay, and packet loss rate. Monitor the running status of the network in real time through the data items, and conduct an initial evaluation of the data quality. Screen out data segments with abnormal delay or high packet loss rate. The screening of data depends on the real-time feedback of the data interface and the preset quality threshold. The threshold setting is adjusted according to historical data to ensure the accuracy and timeliness of traffic monitoring. Through real-time data monitoring and screening, the system can quickly respond to changes in the network status. Real-time monitoring not only includes data collection but also includes preliminary analysis of the data to provide decision support for network operation and maintenance, and obtain a dynamic data set.

[0068] S102: Use the dynamic data set to format the data, adjust the data format, conduct data processing, remove invalid and incorrect data records, and standardize the processed data. The execution process to obtain a standardized data set is as follows;

[0069] Standardize the data according to the formula:

[0070]

[0071] where D represents the original data value, D min represents the minimum value in the dataset, and D max represents the maximum value in the dataset;

[0072] To perform data standardization, it is necessary to determine the minimum value D min and the maximum value D max in the dataset. The values are calculated in real time through the traffic volume, delay, and packet loss rate data in the dynamic dataset. For example, if the traffic dataset is [50, 200, 150, 100] MB, then D min = 50 MB and D max = 200 MB;

[0073] Set the data point applied to 150 MB, and the calculation process is as follows:

[0074]

[0075] This result value represents the relative position of the original data within the entire data range, which helps to eliminate the influence of data units and scales, making the dataset more suitable for further analysis.

[0076] S103: According to the standardized dataset, classify the real-time traffic data, group it according to the differential ranges of traffic volume, delay, and packet loss rate, identify and summarize the target characteristics of each type of data, and the execution process of establishing the initial traffic characteristic framework is as follows;

[0077] Perform classification processing on the traffic data. This process requires appropriately grouping the data according to different parameters such as traffic volume, delay, and packet loss rate in the dataset. The key to classification processing lies in defining the classification boundaries, which are obtained through historical data analysis. The target characteristics of each type of data are determined by the statistical characteristics in the dataset, such as the average value, standard deviation, etc. The identification of target characteristics helps to understand various traffic behaviors in the network. The established traffic characteristic framework is used to predict and manage network traffic, optimize the allocation and use of network resources, improve the network service quality and user experience, and establish the initial traffic characteristic framework.

[0078] Please refer to Figure 3 as shown. Through the initial traffic characteristic framework, use the Isolation Forest algorithm to identify abnormal patterns in the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and the steps to obtain the abnormal pattern recognition results are specifically as follows:

[0079] S201: Based on the initialized traffic characteristics framework, perform initialization screening on real-time traffic data, identify data points with fluctuations, and mark the data points as abnormal to obtain the execution process of the initialized abnormal data marking result as follows;

[0080] By real-time monitoring data, identify the fluctuation points in the data, and regard the fluctuations as potential anomalies. The process of marking abnormal data points includes comparing the fluctuation amplitude of the data points with the historical normal data, screening out the fluctuations beyond the normal range. This marking helps to detect potential problems early and improve the security and stability of the network. The algorithms used in this process include statistical analysis and fluctuation pattern recognition, which can effectively screen out abnormal points from a batch of data streams to obtain the initialized abnormal data marking result.

[0081] S202: Utilize the initialized abnormal data marking result, analyze the marked data, compare with the preset abnormal patterns, identify the abnormal data that matches the known patterns, and classify the data as potential threats to obtain the execution process of the abnormal comparison analysis result as follows;

[0082] Analyze the marked data according to the formula:

[0083] P(x) = 1 - e -λx ;

[0084] In the formula, P(x) is the probability that the data point matches the preset abnormal pattern, x represents the abnormal data point, λ represents the average rate of anomaly occurrence, and e is the natural constant;

[0085] When analyzing abnormal data, λ is estimated based on the frequency of anomaly occurrence in historical data. It is set that in the past data, 3 out of every 1000 data points are abnormal, then λ = 0.003;

[0086] Use the formula to calculate the probability that an abnormal data point matches the known pattern, and set x = 1 (i.e., a single data point);

[0087] The calculation process is as follows:

[0088] P(x) = 1 - e -0.003×1 ≈0.003;

[0089] The result indicates that this data point has a 0.3% probability of conforming to the known abnormal pattern. This kind of calculation helps to quantify the abnormal degree of the data point and determine whether it constitutes a potential threat.

[0090] S203: Adopt the abnormal comparison analysis result, classify and mark the identified abnormal patterns, analyze the type and potential threat level of each abnormal pattern to obtain the execution process of the abnormal pattern recognition result as follows;

[0091] Classify and label the identified abnormal patterns. Key steps in this process include evaluating the types and potential threat levels of different abnormal patterns. By comparing the characteristics of different abnormal data and historical patterns to determine the category and threat level, it helps the system respond and handle potential threats more effectively. The identification of abnormal patterns is based on statistical methods and machine learning techniques, which can learn and extract key information from the data for precise threat assessment to obtain the results of abnormal pattern recognition.

[0092] Please refer to Figure 4 As shown, according to the results of abnormal pattern recognition, evaluate the multi-dimensional threat level of abnormal data. By analyzing the harm level and frequency of threat types, identify the risk rating of each threat type. The specific steps for outputting the threat risk assessment results are as follows:

[0093] S301: Utilize the results of abnormal pattern recognition to extract the type and frequency information of multiple types of abnormal data. Conduct a risk impact analysis for each abnormal type to identify the threat level of each abnormal, and the execution process for obtaining the analysis results of abnormal types is as follows;

[0094] Classify and count various abnormalities that appear in the dataset. Through the data, it can be intuitively seen which abnormal types are the most common and how the frequency changes over time. Conduct a risk impact analysis for each abnormal type. This analysis focuses on the specific threats and potential damages that each abnormal brings to the system, such as data leakage, service interruption, or system performance degradation, etc. Identify the threat level of each abnormal. By evaluating the actual impact of abnormal data on system operation and the threat to business continuity, sort the abnormal types according to the threat level to prioritize handling the abnormal types that cause significant damage, ensuring that resources can be preferentially allocated to counter the most serious threats to obtain the analysis results of abnormal types.

[0095] S302: According to the analysis results of abnormal types, evaluate the harm level and occurrence frequency of each abnormal type, calculate the risk level of the abnormal type, and the execution process for obtaining the threat risk rating record is as follows;

[0096] The formula for calculating the risk level of the abnormal type is as follows:

[0097]

[0098] Among them, R i represents the risk level of the i-th abnormal type, w j represents the weight coefficient of the j-th evaluation factor, f ij represents the score of the i-th abnormal type on the j-th evaluation factor, C i represents the continuous impact evaluation value of the i-th abnormal type, and n is the number of evaluation factors;

[0099] Parameter meanings and set values:

[0100] w j It is the weight coefficient of evaluation factor j. The factors include hazard level and occurrence frequency. The weight coefficient is obtained through a linear regression model based on historical data and expert opinions. The weight of the hazard level is set to 0.6, and the weight of the occurrence frequency is set to 0.4. The weight is adjusted with the optimization of the risk assessment model;

[0101] f ij It is the score of the i-th abnormal type on the j-th evaluation factor. The score is obtained through statistical analysis of historical accident records and risk level data. The hazard level score of a certain abnormal type is set to 85 points, and the occurrence frequency score is set to 30 points;

[0102] C i It is the continuous impact evaluation value of the i-th abnormal type. The continuous impact is comprehensively evaluated by factors such as the chain reaction caused by the accident. This value is obtained through a quantitative analysis model, such as fault tree analysis (FTA). The set range is between 1 and 100, and the continuous impact evaluation value is set to 25;

[0103] Substitute the parameters into the formula for calculation:

[0104] Taking a specific example for calculation, assume that a certain abnormal type (such as type A) involves two evaluation factors: hazard level and occurrence frequency. Using the above parameter values, the weight coefficient w 1 = 0.6, w 2 = 0.4, the score f A1 = 85, f A2 = 30, the continuous impact C A = 25;

[0105] The calculation process is as follows:

[0106]

[0107] The result 12.6 indicates that the abnormal type A has a relatively high risk level. This value is used for further risk management and preventive measure decision-making. The result shows that although the occurrence frequency is low, the high score of the hazard level significantly increases the overall risk level of this abnormal type, highlighting the potential harmfulness, providing a quantitative risk value for decision-makers, and facilitating the formulation of targeted safety improvement strategies.

[0108] S303: The execution process of integrating the risk levels and potential hazards of multiple abnormal patterns through threat risk rating records, identifying the influencing factors of potential hazards, and outputting the threat risk assessment results is as follows;

[0109] Analyze the risk ratings of different anomaly types and associate them with potential hazards in the system to form a comprehensive risk map, including quantifying and ranking various risks, determining which risks require immediate response, and that some risks can be adjusted in subsequent security policy updates, providing decision-makers with a clear view of the current security state, helping to understand the priorities of security investments, and formulating more effective security policies and countermeasures accordingly. Risk assessment also includes a detailed analysis of influencing factors such as external environmental changes, technological evolution, or lack of internal control, which helps to systematically understand and address various factors affecting organizational security, and outputs the threat risk assessment results.

[0110] Please refer to Figure 5 As shown, adopt the threat risk assessment results, adjust the satellite network defense configuration, update the rules of intrusion detection and the defense of the firewall, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks. The steps to obtain the defense configuration adjustment plan are specifically as follows:

[0111] S401: Adopt the threat risk assessment results, analyze the risk ratings of different threat types, and according to the risk ratings, adjust the intrusion detection rules and firewall policies for corresponding relatively high-risk attacks. The execution process to obtain the priority defense adjustment results is as follows;

[0112] Dependent on the risk management framework and threat intelligence database, through tools, the risk rating model can evaluate the potential hazards and occurrence probabilities of different threat types. According to the risk ratings, adjust the intrusion detection rules and firewall policies for corresponding relatively high-risk attacks. This process involves the adjustment of security policy management and the rule engine to adapt to the current threat environment, including a series of protection strategies and intrusion detection parameters adjusted for high-risk threats, ensuring that the satellite network can implement the most effective defense when facing attacks that are most likely to cause significant losses, and obtaining the priority defense adjustment results.

[0113] S402: Based on the priority defense adjustment results, update the defense configuration of the satellite network, adjust the security settings of associated satellite network devices, and optimize the monitoring and protection of risk areas. The execution process to obtain the updated defense measures is as follows;

[0114] Update the defense configuration of the satellite network according to the formula:

[0115] C new =C old +α×(T target -C old );

[0116] In the formula, C new represents the updated configuration, C old represents the old configuration, α represents the adjustment coefficient, T targetRepresents the target configuration;

[0117] When updating the defense configuration, the core task is to adjust the old configuration C according to the risk assessment result old , to approach the safer target configuration T target , the adjustment coefficient α represents the sensitivity of the adjustment, which depends on the urgency of the risk and the acceptable speed of configuration update. Set the old configuration to 100 units, the target configuration to 150 units, and the adjustment coefficient to 0.2;

[0118] The calculation process is as follows:

[0119] C new = 100 + 0.2×(150 - 100) = 100 + 0.2×50 = 110;

[0120] The result means that the new configuration will increase by 10 units, enhancing the monitoring and protection of the risk area, enabling the configuration update to more precisely reflect the current security needs, and at the same time avoiding potential new risks brought by excessive adjustment.

[0121] S403: Implement the updated defense measures, conduct configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, and intercept and mitigate potential multi-dimensional threat attacks. The execution process of the defense configuration adjustment plan is as follows;

[0122] Verify the applicability of the modified device configuration and defense rules through simulation testing and field application. During the testing process, closely monitor the system's response and actual performance to ensure the effectiveness and security of the new configuration. Through testing, potential configuration deficiencies or vulnerabilities can be discovered and corresponding adjustments and optimizations can be made to intercept and mitigate potential multi-dimensional threat attacks. This step involves cross-departmental cooperation and coordination, as well as in-depth analysis by security experts. List in detail all successfully implemented defense measures and their contributions to resisting future threats to ensure that the satellite network maintains the highest security and response capabilities in the face of complex and changing threat environments, and obtain the defense configuration adjustment plan.

[0123] Please refer to Figure 6 As shown, conduct multi-dimensional threat simulation in a virtual environment, test the processing speed of the defense configuration adjustment plan for threats, detect the impact of the defense configuration adjustment on the satellite network performance, evaluate the implementation effect and impact, and identify the overall security of the satellite network. The steps to obtain the multi-dimensional threat simulation test results are specifically as follows:

[0124] S501: Utilize the virtual environment and import the defense configuration adjustment plan, conduct simulation testing on various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, calculate the defense efficiency under different scenarios, and the execution process to obtain the simulation test data is as follows;

[0125] The formula for calculating the defense efficiency in the differential scenario is as follows:

[0126]

[0127] Where R is the defense efficiency value, N represents the total number of simulated scenarios, T a represents the defense response time of the a-th scenario, T avg represents the average defense response time of the scenario, and σ represents the standard deviation of the defense response time;

[0128] Meaning and setting values of parameters:

[0129] N is the total number of scenarios, set to 100, which reflects the diversity of scenarios for simulation;

[0130] T a is the response time of the a-th scenario, which is the data point obtained from the actual defense log. Set T 1 = 0.03 seconds, indicating that in the first scenario, the defense configuration responds in 0.03 seconds;

[0131] T avg is the average response time of all scenarios, calculated based on the actual data and set to 0.05 seconds, which reflects the average performance of the defense configuration in all scenarios;

[0132] σ is the standard deviation, calculated based on the distribution of T a and set to 0.01 seconds, indicating the degree of fluctuation of the response time;

[0133] Substitute the parameters into the formula for calculation:

[0134]

[0135] The results show that there is a certain defense efficiency in different scenarios. The relatively low value implies that the defense response time is relatively high in some scenarios, and it is necessary to further optimize the defense configuration to improve the defense efficiency.

[0136] S502: According to the simulation test data, monitor and record the impact of the defense configuration on the satellite network performance, analyze the network latency, data throughput rate, and resource utilization rate after the implementation of the defense measures, and the execution process for obtaining the performance impact assessment results is as follows;

[0137] Careful observation and recording of key performance indicators such as network latency, data throughput rate, and resource utilization rate, analyzing the network performance after the implementation of defense measures to determine the actual effects and side effects of the defense strategy, paying particular attention to configuration changes that have a greater impact on network performance. The analyzed data includes calculating the percentage change in latency after the introduction of defense measures, the increase or decrease in data throughput rate, and the degree of optimization of resource utilization rate. Evaluating the data not only helps to understand the specific impact of defense configurations on performance but also provides guidance for future network optimization. Listing the changes in each performance indicator provides important data support for decision-makers so that while ensuring network security, the overall performance of the network can be maintained or even improved, and the performance impact assessment results are obtained.

[0138] S503: Adopt the performance impact assessment results, analyze the overall security and implementation effects of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, and conduct a security assessment of multi-dimensional threats. The execution process for obtaining the multi-dimensional threat simulation test results is as follows;

[0139] Deeply explore how defense measures improve network security, identify new or unresolved security vulnerabilities and performance bottlenecks that arise due to configuration changes, and conduct a security assessment of multi-dimensional threats. This includes testing the effectiveness of security measures at all levels of the network, examining the network performance under various threat scenarios, and conducting a comprehensive effectiveness evaluation of defense measures. Pay particular attention to areas that exhibit potential risks in the simulation test. Identifying and recording problems is to address them specifically in subsequent updates and adjustments to ensure the resilience and security of the network. List in detail various test scenarios and the corresponding network responses, providing valuable insights and improvement suggestions for the network security team. The information will be used to guide future security strategy adjustments and network maintenance work, and the multi-dimensional threat simulation test results are obtained.

[0140] Please refer to Figure 7 As shown, on the other hand, an electric vehicle status monitoring system is provided. The electric vehicle status monitoring system is used to execute the above-mentioned electric vehicle status monitoring method. The system includes:

[0141] The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including traffic volume, latency, and packet loss rate, to obtain a real-time traffic archive;

[0142] The traffic characteristic analysis module collects and organizes key indicators based on the real-time traffic archive, analyzes the performance and characteristics of the key indicators, and constructs an initial traffic characteristic framework;

[0143] The anomaly recognition module uses the isolation forest algorithm to screen the real-time data based on the initialized traffic characteristic framework, detect abnormal fluctuations and potential threats, and obtain the anomaly pattern analysis results;

[0144] The threat rating module evaluates the multi-dimensional threat level of abnormal data based on the analysis results of abnormal patterns. By comparing the harm levels and occurrence frequencies of different threat types, it conducts risk rating for each threat type to obtain the threat risk rating results;

[0145] Based on the threat risk rating results, the defense strategy adjustment module updates the defense configuration of the satellite network, adjusts the intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains the defense configuration plan;

[0146] The test evaluation module conducts multi-dimensional threat simulation tests using the defense configuration plan in a virtual environment, evaluates the processing speed of the defense strategy and its impact on the performance of the satellite network, verifies the implementation effect, and identifies the overall security of the satellite network to obtain the multi-dimensional threat simulation test results.

[0147] As mentioned above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A satellite network multi-dimensional threat simulation method based on isolation forest detection, characterized in that: The following steps are involved: Load the real-time traffic data of the satellite network through the data interface, extract key indicators, record the traffic size, delay and packet loss rate, and establish an initialization traffic characteristics framework; By using the initialization traffic characteristic framework, the isolation forest algorithm is used to perform abnormal pattern recognition on the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat features, mark and classify potential satellite network threats, and obtain abnormal pattern recognition results; According to the abnormal pattern recognition results, the multi-dimensional threat level of the abnormal data is evaluated, and the risk rating of each threat type is identified by analyzing the hazard level and frequency of the threat type, and the threat risk assessment result is output; Adopting the threat risk assessment results, adjusting the satellite network defense configuration, updating the intrusion detection rules and firewall defense, adjusting the satellite network equipment configuration, intercepting and mitigating multi-dimensional threat attacks, and obtaining a defense configuration adjustment plan; Multi-dimensional threat simulation is performed in a virtual environment to test the threat processing speed of the defense configuration adjustment scheme, detect the impact of the defense configuration adjustment on the performance of the satellite network, evaluate the implementation effect and impact, identify the overall security of the satellite network, and obtain multi-dimensional threat simulation test results.

2. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The initialization traffic characteristic framework includes traffic size indicators, delay indicators, and packet loss rate indicators. The abnormal pattern recognition results include abnormal fluctuation recognition and potential threat marking. The threat risk assessment results include hazard level analysis, threat frequency calculation, and corresponding risk rating for each threat type. The defense configuration adjustment plan includes intrusion detection rule updates, firewall defense adjustments, and satellite network equipment configuration updates. The multi-dimensional threat simulation test results include processing speed tests, satellite network performance impact assessments, and overall security ratings.

3. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The steps to load the real-time traffic data of the satellite network through the data interface, extract key indicators, record the traffic size, delay and packet loss rate, and establish the initialization traffic characteristics framework are as follows: Load the real-time traffic data of the satellite network through the data interface, synchronously and receive the traffic data in real time, including the traffic volume, delay and packet loss rate, perform initialization monitoring of data quality, filter out problematic data segments, and obtain dynamic data sets; Using the dynamic data set, formatting the data, adjusting the data format, processing the data, removing invalid and erroneous data records, and standardizing the processed data to obtain a standardized data set; According to the standardized data set, the real-time traffic data is classified and processed, grouped according to the differentiated ranges of traffic size, delay and packet loss rate, the target characteristics of each type of data are identified and summarized, and an initialization traffic characteristic framework is established.

4. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: Through the initialization traffic characteristic framework, the isolation forest algorithm is used to identify abnormal patterns of real-time traffic data, identify abnormal fluctuations and potential threats in real-time traffic data, compare the identified abnormal patterns with known threat features, mark and classify potential satellite network threats, and obtain the abnormal pattern recognition results in the following steps: Based on the initialization traffic characteristic framework, the real-time traffic data is initially screened, the data points with fluctuations are identified, and the data points are abnormally marked to obtain the initialization abnormal data marking results; Analyze the labeled data using the initial abnormal data labeling result, compare the preset abnormal pattern, identify the abnormal data matching the known pattern, classify the data as a potential threat, and obtain the abnormal comparison analysis result; The abnormal comparison and analysis results are used to classify and mark the identified abnormal patterns, analyze the type and potential threat level of each abnormal pattern, and obtain the abnormal pattern recognition results.

5. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: According to the abnormal pattern recognition result, the multi-dimensional threat level of the abnormal data is evaluated, and the risk rating of each threat type is identified by analyzing the hazard level and frequency of the threat type. The steps of outputting the threat risk assessment result are specifically as follows: Utilizing the abnormal pattern recognition results, extracting the types and frequency information of multiple types of abnormal data, performing risk impact analysis on each abnormal type, identifying the threat level of each abnormality, and obtaining abnormal type analysis results; According to the anomaly type analysis results, the hazard level and occurrence frequency of each anomaly type are evaluated, the risk level of the anomaly type is calculated, and a threat risk rating record is obtained; Through the threat risk rating record, the risk levels and potential hazards of multiple types of abnormal patterns are integrated, and the influencing factors of potential hazards are identified, and the threat risk assessment results are output.

6. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 5 is characterized in that: The formula for calculating the risk level of the anomaly type is as follows: Among them, R i represents the risk level of the i-th abnormality type, w j represents the weight coefficient of the jth evaluation factor, f ij represents the score of the i-th abnormal type on the j-th evaluation factor, C i represents the continuity impact assessment value of the i-th anomaly type, and n is the number of assessment factors.

7. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The steps of using the threat risk assessment results to adjust the satellite network defense configuration, update the intrusion detection rules and firewall defense, adjust the satellite network equipment configuration, intercept and mitigate multi-dimensional threat attacks, and obtain the defense configuration adjustment plan are as follows: Using the threat risk assessment results, analyzing the risk ratings of differentiated threat types, and adjusting the intrusion detection rules and firewall policies corresponding to higher risk attacks according to the risk ratings to obtain priority defense adjustment results; Based on the priority defense adjustment result, the defense configuration of the satellite network is updated, the security settings of the associated satellite network devices are adjusted, the monitoring and protection of the risk area are optimized, and updated defense measures are obtained; Implement the updated defense measures, perform configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, and intercept and mitigate potential multi-dimensional threat attacks to obtain a defense configuration adjustment plan.

8. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The steps of conducting multi-dimensional threat simulation in a virtual environment, testing the processing speed of the defense configuration adjustment scheme on threats, detecting the impact of the defense configuration adjustment on the performance of the satellite network, evaluating the implementation effect and impact, identifying the overall security of the satellite network, and obtaining the multi-dimensional threat simulation test results are as follows: Using a virtual environment and importing the defense configuration adjustment plan, simulate and test various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, calculate the defense efficiency under differentiated scenarios, and obtain simulation test data; Based on the simulation test data, monitor and record the impact of the defense configuration on the satellite network performance, analyze the network delay, data throughput and resource utilization after the defense measures are implemented, and obtain the performance impact assessment results; The performance impact assessment results are used to analyze the overall security and implementation effect of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, conduct security assessments of multi-dimensional threats, and obtain multi-dimensional threat simulation test results.

9. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 8 is characterized in that: The formula for calculating the defense efficiency in the differentiated scenario is: Among them, R is the defense efficiency value, N represents the total number of simulated scenarios, and T a represents the defense response time of the ath scenario, T avg represents the average defense response time of the scenario, and σ represents the standard deviation of the defense response time.

10. Satellite network multi-dimensional threat simulation system based on isolation forest detection, characterized in that: According to the satellite network multi-dimensional threat simulation method based on isolation forest detection according to any one of claims 1 to 9, the system comprises: The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including traffic size, delay, and packet loss rate, to obtain a real-time traffic archive; The traffic characteristic analysis module collects and organizes key indicators based on the real-time traffic archive, analyzes the performance and characteristics of the key indicators, and constructs an initial traffic characteristic framework; The anomaly identification module uses the isolation forest algorithm based on the initialization traffic characteristic framework to screen the real-time data, detect abnormal fluctuations and potential threats, and obtain abnormal pattern analysis results; The threat rating module evaluates the multi-dimensional threat level of the abnormal data according to the abnormal pattern analysis results, and performs risk rating on each threat type by comparing the hazard level and occurrence frequency of differentiated threat types to obtain a threat risk rating result; The defense strategy adjustment module updates the defense configuration of the satellite network based on the threat risk rating result, adjusts the intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains a defense configuration plan; The test evaluation module uses the defense configuration scheme to perform multi-dimensional threat simulation tests in a virtual environment, evaluates the processing speed of the defense strategy and its impact on satellite network performance, verifies the implementation effect, identifies the overall security of the satellite network, and obtains multi-dimensional threat simulation test results.

Citation Information

Patent Citations

  • Security monitoring model based on security label in satellite network

    CN108234499A

  • Intrusion detection and response method and system of satellite internet target range

    CN119155101A

  • WIFI device compatibility analyzer for satellite networks

    US20220191684A1

  • Method and system for predicting cyber threats using deep artificial intelligence (AI)-driven analytics

    US20230171266A1

Cited By

  • Satellite network threat analysis system based on AI

    CN120358086A

  • An AI-based satellite network threat analysis system

    CN120358086B

  • Low earth orbit satellite adaptive intrusion detection method and system

    CN120415906A