Satellite network multi-dimensional threat simulation method and system based on isolation forest detection
Through the multi-dimensional threat simulation method of satellite network based on isolated forest detection, real-time traffic data is used to identify abnormal patterns and risk assessment, and the defense configuration is optimized, which solves the problem of insufficient real-time threat response in the existing technology, and improves the security and response speed of the satellite network.
Patent Information
- Application Number
- CN202510078653.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-01-17
AI Technical Summary
The existing technology has shortcomings in real-time data processing and immediate threat response, and it is impossible to effectively identify and intercept new or variant threats, resulting in a long response time for network systems when facing rapidly evolving threats, affecting the stability and reliability of the overall network.
Through a multi-dimensional threat simulation method for satellite networks based on isolated forest detection, real-time traffic data extracts key indicators, abnormal pattern recognition and risk assessment, adjust defense configuration, conduct multi-dimensional threat simulation testing, and optimize defense strategies to enhance network security.
Real-time threat perception and accurate identification of satellite networks are achieved, targeted and efficient defense measures are improved, and the network's resistance is ensured when facing complex threats, and overall security and response speed are improved.
Smart Images

Figure CN120050067B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a satellite network multi-dimensional threat simulation method and system based on isolation forest detection. Background Art
[0002] The field of cybersecurity involves protecting computer networks from unauthorized access and threats. It encompasses various practices and technical strategies designed to safeguard the integrity, confidentiality, and availability of networks and network-accessible resources. Cybersecurity measures are designed to protect against various cyber threats, including data breaches and malware distribution, targeting businesses and individual users. This field is often combined with encryption, intrusion detection systems, firewalls, and the latest artificial intelligence technologies to improve the detection and response to cyber threats.
[0003] The multi-dimensional threat simulation method for satellite networks using isolation forest detection uses the isolation forest algorithm to identify and assess anomalies and threatening behaviors within satellite networks. This method, applied to the security management of satellite communication networks, can simulate and predict various threat scenarios, such as network intrusion, data tampering, and denial of service threats. This simulation can predict the impact and intrusion path before actual threats occur, effectively enhancing the security and resilience of satellite networks. This technology primarily provides an efficient and feasible security assessment tool for satellite networks, enabling the timely identification of potential security issues and the implementation of appropriate protective measures.
[0004] While existing technologies provide basic network security protection, they lack real-time data processing and immediate threat response. Existing technologies rely on static defense mechanisms and threat identification systems with significant latency, resulting in long response times when faced with rapidly evolving threats and an inability to effectively intercept or mitigate new or variant threats. For example, traditional intrusion detection systems are unable to promptly identify and process unknown threat patterns, resulting in a sluggish response to the spread of new malware or complex data tampering threats, potentially leading to the leakage or loss of important information. Due to the lack of effective real-time risk assessment, existing technologies struggle to accurately adjust defense strategies, resulting in incomplete protection for network systems against multi-dimensional threats and impacting the overall stability and reliability of the network. Summary of the Invention
[0005] In order to solve the obvious deficiencies in real-time data processing and immediate threat response in the existing technology. The existing technology relies on static defense mechanisms and threat identification systems with large delays, resulting in long response times when facing rapidly evolving threats, and cannot effectively intercept or mitigate new or variant threats. For example, traditional intrusion detection systems are unable to identify and process unknown threat patterns in a timely manner, and therefore exhibit slow reactions in the face of new malware propagation or complex data tampering threats, which may lead to the leakage or loss of important information. Due to the lack of effective real-time risk assessment, it is difficult for existing technologies to accurately adjust defense strategies, resulting in insufficient protection for network systems when suffering multi-dimensional threats, affecting the stability and reliability of the overall network. The embodiments of the present invention provide a satellite network multi-dimensional threat simulation method and system based on isolation forest detection. The technical solution is as follows:
[0006] On the one hand, a satellite network multi-dimensional threat simulation method based on isolation forest detection is provided, the method comprising:
[0007] S1: Load real-time traffic data from the satellite network through the data interface, extract key indicators, record traffic volume, latency, and packet loss rate, and establish an initial traffic feature framework;
[0008] S2: Using the initialized traffic feature framework, the isolation forest algorithm is used to perform abnormal pattern recognition on the real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat features, mark and classify potential satellite network threats, and obtain abnormal pattern recognition results;
[0009] S3: Based on the abnormal pattern recognition results, evaluate the multi-dimensional threat level of the abnormal data, identify the risk rating of each threat type by analyzing the hazard level and frequency of the threat type, and output the threat risk assessment result;
[0010] S4: Using the threat risk assessment results, adjust the satellite network defense configuration, update intrusion detection rules and firewall defenses, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan;
[0011] S5: Conduct multi-dimensional threat simulation in a virtual environment to test the threat processing speed of the defense configuration adjustment solution, detect the impact of the defense configuration adjustment on the performance of the satellite network, evaluate the implementation effect and impact, identify the overall security of the satellite network, and obtain the multi-dimensional threat simulation test results.
[0012] Optionally, the initialization traffic characteristic framework includes traffic size indicators, delay indicators, and packet loss rate indicators; the abnormal pattern recognition results include abnormal fluctuation identification and potential threat marking; the threat risk assessment results include hazard level analysis of each threat type, threat frequency calculation, and corresponding risk rating; the defense configuration adjustment plan includes intrusion detection rule updates, firewall defense adjustments, and satellite network equipment configuration updates; the multi-dimensional threat simulation test results include processing speed tests, satellite network performance impact assessments, and overall security ratings.
[0013] Optionally, the steps for loading real-time traffic data of the satellite network through the data interface, extracting key indicators, recording traffic volume, delay and packet loss rate, and establishing an initialization traffic characteristic framework are as follows:
[0014] S101: Loading real-time traffic data from the satellite network through the data interface, synchronously and in real time receiving traffic data, including traffic volume, latency, and packet loss rate, performing initial data quality monitoring, screening problematic data segments, and obtaining a dynamic data set;
[0015] S102: using the dynamic data set, formatting the data, adjusting the data format, processing the data, removing invalid and erroneous data records, and standardizing the processed data to obtain a standardized data set;
[0016] S103: Based on the standardized data set, the real-time traffic data is classified and grouped according to the differentiated ranges of traffic size, delay and packet loss rate, the target characteristics of each type of data are identified and summarized, and an initialization traffic characteristic framework is established.
[0017] Optionally, the steps of performing abnormal pattern recognition on real-time traffic data using the isolation forest algorithm through the initialized traffic characteristic framework to identify abnormal fluctuations and potential threats in the real-time traffic data, comparing the identified abnormal patterns with known threat characteristics, marking and classifying potential satellite network threats, and obtaining abnormal pattern recognition results are specifically as follows:
[0018] S201: Based on the initialization traffic characteristic framework, perform initialization screening on the real-time traffic data, identify data points with fluctuations, and mark the data points as abnormal to obtain an initialization abnormal data marking result;
[0019] S202: Analyze the labeled data using the initial abnormal data labeling result, compare it with a preset abnormal pattern, identify abnormal data that matches the known pattern, classify the data as a potential threat, and obtain an abnormal comparison analysis result;
[0020] S203: using the abnormal comparison and analysis results, classifying and marking the identified abnormal patterns, analyzing the type and potential threat level of each abnormal pattern, and obtaining abnormal pattern recognition results.
[0021] Optionally, the steps of evaluating the multi-dimensional threat level of the abnormal data based on the abnormal pattern recognition result, identifying the risk rating of each threat type by analyzing the hazard level and frequency of the threat type, and outputting the threat risk assessment result are specifically as follows:
[0022] S301: Using the abnormal pattern recognition results, extract the type and frequency information of multiple types of abnormal data, perform risk impact analysis on each abnormal type, identify the threat level of each abnormality, and obtain abnormal type analysis results;
[0023] S302: Based on the anomaly type analysis results, evaluate the hazard level and occurrence frequency of each anomaly type, calculate the risk level of the anomaly type, and obtain a threat risk rating record;
[0024] S303: Integrate the risk levels and potential hazards of multiple types of abnormal patterns through the threat risk rating records, identify the influencing factors of potential hazards, and output the threat risk assessment results.
[0025] Optionally, the formula for calculating the risk level of the abnormality type is as follows:
[0026] ;
[0027] in, Representative The risk level of each abnormal type, Representative The weight coefficient of each evaluation factor, Representative The exception type is The scores on the evaluation factors, Representative The continuity impact assessment value of the abnormal type, is the number of evaluation factors.
[0028] Optionally, the steps of using the threat risk assessment results to adjust the satellite network defense configuration, update intrusion detection rules and firewall defenses, adjust satellite network device configurations, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan are specifically as follows:
[0029] S401: Analyze risk ratings of differentiated threat types using the threat risk assessment results, and adjust intrusion detection rules and firewall policies corresponding to higher-risk attacks based on the risk ratings to obtain a priority defense adjustment result;
[0030] S402: Based on the priority defense adjustment result, update the defense configuration of the satellite network, adjust the security settings of the associated satellite network devices, optimize the monitoring and protection of the risk area, and obtain updated defense measures;
[0031] S403: Implement the updated defense measures, perform configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, intercept and mitigate potential multi-dimensional threat attacks, and obtain a defense configuration adjustment plan.
[0032] Optionally, a multi-dimensional threat simulation is performed in a virtual environment to test the speed at which the defense configuration adjustment solution processes threats, detect the impact of the defense configuration adjustment on satellite network performance, evaluate the implementation effect and impact, and identify the overall security of the satellite network. The specific steps for obtaining the multi-dimensional threat simulation test results are as follows:
[0033] S501: Using a virtual environment and importing the defense configuration adjustment plan, simulate and test various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, calculate the defense efficiency under different scenarios, and obtain simulation test data;
[0034] S502: Based on the simulation test data, monitor and record the impact of the defense configuration on the satellite network performance, analyze the network delay, data throughput, and resource utilization after the defense measures are implemented, and obtain a performance impact assessment result;
[0035] S503: Using the performance impact assessment results, analyze the overall security and implementation effect of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, conduct a multi-dimensional threat security assessment, and obtain a multi-dimensional threat simulation test result.
[0036] Optionally, the formula for calculating the defense efficiency in the differentiated scenario is:
[0037] ;
[0038] in, is the defense efficiency value, Represents the total number of simulated scenarios, Representative Defense response time for each scenario, The average defense response time of the representative scenario, Represents the standard deviation of defense response time.
[0039] In another aspect, a satellite network multi-dimensional threat simulation system based on isolation forest detection is provided. The satellite network multi-dimensional threat simulation system based on isolation forest detection is used to perform the above-mentioned satellite network multi-dimensional threat simulation method based on isolation forest detection. The system includes:
[0040] The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including traffic volume, delay and packet loss rate, to obtain a real-time traffic archive;
[0041] The traffic characteristics analysis module collects and organizes key indicators based on the real-time traffic archive, analyzes the performance and characteristics of the key indicators, and constructs an initial traffic characteristics framework;
[0042] The anomaly identification module uses the isolation forest algorithm based on the initialization traffic characteristic framework to screen real-time data, detect abnormal fluctuations and potential threats, and obtain abnormal pattern analysis results;
[0043] The threat rating module evaluates the multi-dimensional threat level of the abnormal data based on the abnormal pattern analysis results, and performs a risk rating on each threat type by comparing the hazard level and occurrence frequency of differentiated threat types to obtain a threat risk rating result;
[0044] The defense strategy adjustment module updates the defense configuration of the satellite network based on the threat risk rating results, adjusts intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains a defense configuration plan;
[0045] The test and evaluation module uses the defense configuration scheme to perform multi-dimensional threat simulation testing in a virtual environment, evaluates the processing speed of the defense strategy and its impact on satellite network performance, verifies the implementation effect, identifies the overall security of the satellite network, and obtains multi-dimensional threat simulation test results.
[0046] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0047] The security of satellite networks has been effectively enhanced through the extraction and analysis of real-time traffic data, as well as the identification and risk assessment of anomaly patterns. Real-time data monitoring and key indicator extraction enhance real-time awareness of satellite network conditions, enabling the immediate detection of abnormal fluctuations and potential threats. Accurately identifying anomaly patterns and comparing them with known threat signatures allows for more precise identification of potential threats, avoiding the waste of resources caused by false alarms. Multi-dimensional threat level assessments and detailed analysis of threat risks provide a more comprehensive security assessment, making defense measures more targeted and effective. Adjusting defense configurations and testing defense solutions in virtual environments further validates the effectiveness of these adjustments, ensuring the satellite network's resilience to real-world threats and significantly improving the adaptability of defense configurations and the overall security of the network. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a schematic diagram of the workflow of the present invention;
[0049] Figure 2 This is a detailed flow chart of S1 of the present invention;
[0050] Figure 3 This is a detailed flow chart of S2 of the present invention;
[0051] Figure 4 This is a detailed flow chart of S3 of the present invention;
[0052] Figure 5 This is a detailed flow chart of S4 of the present invention;
[0053] Figure 6 This is a detailed flow chart of S5 of the present invention;
[0054] Figure 7 It is a system flow chart of the present invention. DETAILED DESCRIPTION
[0055] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0056] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.
[0057] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0058] See also Figure 1 As shown, an embodiment of the present invention provides a satellite network multi-dimensional threat simulation method based on isolation forest detection. The processing flow of the method may include the following steps:
[0059] S1: Load real-time traffic data from the satellite network through the data interface, extract key indicators, record traffic volume, latency, and packet loss rate, and establish an initial traffic feature framework;
[0060] S2: By initializing the traffic feature framework, the isolation forest algorithm is used to identify abnormal patterns in real-time traffic data, identify abnormal fluctuations and potential threats in real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and obtain abnormal pattern recognition results;
[0061] S3: Based on the abnormal pattern recognition results, evaluate the multi-dimensional threat level of the abnormal data. By analyzing the hazard level and frequency of the threat type, identify the risk rating of each threat type and output the threat risk assessment results.
[0062] S4: Using the threat risk assessment results, adjust the satellite network defense configuration, update intrusion detection rules and firewall defenses, adjust the satellite network equipment configuration, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan;
[0063] S5: Conduct multi-dimensional threat simulation in a virtual environment to test the threat processing speed of the defense configuration adjustment plan, detect the impact of the defense configuration adjustment on the performance of the satellite network, evaluate the implementation effect and impact, identify the overall security of the satellite network, and obtain multi-dimensional threat simulation test results.
[0064] The initialization traffic characteristic framework includes traffic size indicators, latency indicators, and packet loss rate indicators. The abnormal pattern recognition results include abnormal fluctuation identification and potential threat marking. The threat risk assessment results include hazard level analysis of each threat type, threat frequency calculation, and corresponding risk rating. The defense configuration adjustment plan includes intrusion detection rule updates, firewall defense adjustments, and satellite network equipment configuration updates. The multi-dimensional threat simulation test results include processing speed tests, satellite network performance impact assessments, and overall security ratings.
[0065] See also Figure 2 As shown in the figure, the steps for loading real-time traffic data of the satellite network through the data interface, extracting key indicators, recording traffic volume, delay and packet loss rate, and establishing the initialization traffic feature framework are as follows:
[0066] S101: Loading real-time traffic data from the satellite network through the data interface, synchronously and receiving traffic data in real time, including traffic volume, delay, and packet loss rate, performing initial data quality monitoring, screening problematic data segments, and obtaining a dynamic data set. The execution process is as follows;
[0067] Real-time traffic data of the satellite network is loaded through the data interface. The interface provides three data items: traffic size, delay and packet loss rate. The network's operating status is monitored in real time through the data items, and the data quality is initialized and evaluated. Data segments with abnormal delay or high packet loss rate are screened. Data screening depends on the real-time feedback of the data interface and the preset quality threshold. The threshold setting is adjusted according to historical data to ensure the accuracy and timeliness of traffic monitoring. Through real-time data monitoring and screening, the system can quickly respond to changes in network conditions. Real-time monitoring includes not only data collection, but also preliminary analysis of the data to provide decision support for network operation and maintenance and obtain dynamic data sets.
[0068] S102: Using a dynamic data set, formatting the data, adjusting the data format, processing the data, removing invalid and erroneous data records, and standardizing the processed data to obtain a standardized data set. The execution process is as follows:
[0069] The data is standardized according to the formula:
[0070] ;
[0071] Where, Represents the original data value, Represents the minimum value in the data set. Represents the maximum value in the data set;
[0072] In order to normalize the data, it is necessary to determine the minimum value in the data set. and maximum value , the value is calculated in real time through the traffic size, delay and packet loss rate data in the dynamic data set. For example, if the traffic data set is [50, 200, 150, 100] MB, then MB and MB;
[0073] The setting is applied to 150MB of data points, and the calculation process is:
[0074] ;
[0075] The resulting value represents the relative position of the original data within the entire data range, which helps to eliminate the effects of data units and scales, making the dataset more suitable for further analysis.
[0076] S103: Based on the standardized data set, real-time traffic data is classified and grouped according to the different ranges of traffic volume, latency, and packet loss rate. The target characteristics of each type of data are identified and summarized, and the execution process of establishing the initial traffic characteristics framework is as follows;
[0077] Classify and process traffic data. This process requires grouping the data appropriately based on the different parameters such as traffic size, delay, and packet loss rate in the data set. The key to classification processing is to define the boundaries of the classification. The boundaries are obtained based on historical data analysis. The target characteristics of each type of data are determined by the statistical characteristics of the data set, such as the mean value, standard deviation, etc. The identification of target characteristics helps to understand various traffic behaviors in the network. The established traffic characteristic framework is used to predict and manage network traffic, optimize the allocation and use of network resources, improve the network service quality and user experience, and establish an initialization traffic characteristic framework.
[0078] See also Figure 3As shown in the figure, by initializing the traffic feature framework, using the isolation forest algorithm, anomaly pattern recognition is performed on real-time traffic data, abnormal fluctuations and potential threats in real-time traffic data are identified, the identified anomaly patterns are compared with known threat features, and potential satellite network threats are marked and classified. The specific steps for obtaining anomaly pattern recognition results are as follows:
[0079] S201: Based on the initialization traffic characteristic framework, the real-time traffic data is initially screened to identify data points with fluctuations and mark the data points as abnormal. The execution process of obtaining the initialization abnormal data marking result is as follows;
[0080] By monitoring data in real time, we can identify fluctuation points in the data and regard fluctuations as potential anomalies. The process of marking abnormal data points includes comparing the fluctuation amplitude of the data points with historical normal data and screening out fluctuations that exceed the normal range. This marking helps to detect potential problems early and improve the security and stability of the network. The algorithms used in this process include statistical analysis and fluctuation pattern recognition, which can effectively and quickly screen out anomalies from batch data streams and obtain the initial abnormal data marking results.
[0081] S202: Using the initial abnormal data marking results, analyze the marked data, compare it with the preset abnormal pattern, identify abnormal data that matches the known pattern, and classify the data as potential threats. The execution process of obtaining the abnormal comparison and analysis results is as follows;
[0082] Analyze the marked data according to the formula:
[0083] ;
[0084] Where, The probability that a data point matches a preset anomaly pattern, represents an abnormal data point, represents the average rate of abnormal occurrence, is a natural constant;
[0085] When analyzing abnormal data, It is estimated based on the frequency of anomalies in historical data. Assume that in the past data, 3 out of every 1000 data points are abnormal. ;
[0086] Use the formula to calculate the probability that an abnormal data point matches a known pattern, set (i.e., a single data point);
[0087] The calculation process is:
[0088] ;
[0089] The result indicates that there is a 0.3% probability that the data point conforms to a known abnormal pattern. This calculation helps quantify the degree of abnormality of the data point and determine whether it poses a potential threat.
[0090] S203: Using the anomaly comparison analysis results, classify and mark the identified anomaly patterns, analyze the type and potential threat level of each anomaly pattern, and obtain the anomaly pattern recognition results. The execution process is as follows;
[0091] The identified abnormal patterns are classified and labeled. The key steps in this process include evaluating the types and potential threat levels of different abnormal patterns. By comparing the characteristics and historical patterns of different abnormal data, determining the categories and threat levels, it helps the system respond to and handle potential threats more effectively. The identification of abnormal patterns is based on statistical methods and machine learning technology, which can learn and extract key information from the data, conduct accurate threat assessment, and obtain abnormal pattern recognition results.
[0092] See also Figure 4 As shown in the figure, based on the abnormal pattern recognition results, the multi-dimensional threat level of abnormal data is evaluated. By analyzing the hazard level and frequency of threat types, the risk rating of each threat type is identified. The specific steps for outputting the threat risk assessment results are as follows:
[0093] S301: Using the abnormal pattern recognition results, extract the type and frequency information of multiple types of abnormal data, perform risk impact analysis on each abnormal type, identify the threat level of each abnormality, and obtain the abnormal type analysis results. The execution process is as follows;
[0094] Classify and count various anomalies that appear in the data set. Through the data, you can intuitively see which anomaly types are the most common and how the frequency of occurrence changes over time. Perform a risk impact analysis on each anomaly type. This analysis focuses on the specific threats and potential damages that each anomaly brings to the system, such as data leakage, service interruption, or system performance degradation. Identify the threat level of each anomaly, and by evaluating the actual impact of abnormal data on system operations and the threat to business continuity, sort the anomaly types according to the threat level to prioritize the anomaly types that cause significant damage, ensure that resources can be allocated to combat the most serious threats, and obtain the anomaly type analysis results.
[0095] S302: Based on the anomaly type analysis results, the hazard level and occurrence frequency of each anomaly type are evaluated, the risk level of the anomaly type is calculated, and the execution process of obtaining the threat risk rating record is as follows;
[0096] The formula for calculating the risk level of anomaly types is as follows:
[0097] ;
[0098] in, Representative The risk level of each abnormal type, Representative The weight coefficient of each evaluation factor, Representative The exception type is The scores on the evaluation factors, Representative The continuity impact assessment value of the abnormal type, is the number of evaluation factors;
[0099] Parameter meaning and setting value:
[0100] For evaluation factors The weight coefficients are based on factors including hazard level and occurrence frequency. The weight coefficients are derived through a linear regression model based on historical data and expert opinions. The weight of hazard level is set to 0.6 and the weight of occurrence frequency is set to 0.4. The weights are adjusted as the risk assessment model is optimized.
[0101] For the The exception type is The scores on the evaluation factors are calculated by statistically analyzing historical accident records and risk level data. The hazard level score of a certain abnormality type is set to 85 points, and the frequency score is 30 points.
[0102] For the The continuity impact assessment value of each abnormality type is obtained by comprehensively evaluating factors such as the chain reaction caused by the accident. This value is obtained through a quantitative analysis model, such as fault tree analysis (FTA). The setting range is between 1 and 100. The continuity impact assessment value is set to 25;
[0103] Substitute the parameters into the formula for calculation:
[0104] Taking a specific example, setting a certain anomaly type (such as type A) involves two evaluation factors: hazard level and frequency of occurrence. Using the above parameter values, the weight coefficient , ,score , , continuity impact ;
[0105] The calculation process is as follows:
[0106] ;
[0107] Result 12.6 indicates that anomaly type A has a relatively high risk level. This value is used for further risk management and preventive measures. The results show that despite the low frequency of occurrence, the high hazard level score significantly increases the overall risk level of this anomaly type, highlights the potential harm, and provides decision makers with a quantified risk value, facilitating the development of targeted safety improvement strategies.
[0108] S303: The execution process of integrating the risk levels and potential hazards of multiple types of abnormal patterns through threat risk rating records, identifying the influencing factors of potential hazards, and outputting the threat risk assessment results is as follows;
[0109] Analyze the risk ratings of different anomaly types and associate them with potential hazards in the system to form a comprehensive risk map, including quantifying and ranking various risks, determining risks that require immediate response, and some risks that can be adjusted in subsequent security policy updates. This provides decision-makers with a clear view of the current security status, helps understand the priorities of security investments, and formulates more effective security policies and response measures accordingly. Risk assessment also includes a detailed analysis of influencing factors, such as changes in the external environment, technological evolution, or lack of internal controls. This helps to systematically understand and respond to various factors that affect organizational security and output threat risk assessment results.
[0110] See also Figure 5 As shown in the figure, the steps for using the threat risk assessment results to adjust the satellite network defense configuration, update the intrusion detection rules and firewall defense, adjust the satellite network equipment configuration, intercept and mitigate multi-dimensional threat attacks, and obtain the defense configuration adjustment plan are as follows:
[0111] S401: Using the threat risk assessment results, analyze the risk ratings of differentiated threat types. Based on the risk ratings, adjust the intrusion detection rules and firewall policies corresponding to higher-risk attacks to obtain the priority defense adjustment results. The execution process is as follows;
[0112] Relying on the risk management framework and threat intelligence database, through tools, the risk rating model can evaluate the potential harm and probability of occurrence of different threat types, and adjust the intrusion detection rules and firewall policies corresponding to higher-risk attacks based on the risk rating. This process involves security policy management and rule engine adjustments to adapt to the current threat environment, including a series of protection strategies and intrusion detection parameters adjusted for high-risk threats, ensuring that the satellite network can implement the most effective defense when facing attacks with the highest probability of causing major losses, and obtain priority defense adjustment results.
[0113] S402: Based on the priority defense adjustment results, the defense configuration of the satellite network is updated, the security settings of the associated satellite network devices are adjusted, and the monitoring and protection of the risk area are optimized. The execution process of the updated defense measures is as follows;
[0114] Update the satellite network's defense configuration according to the formula:
[0115] ;
[0116] Where, Represents the updated configuration, Represents the old configuration, represents the adjustment coefficient, Represents the target configuration;
[0117] When updating the defense configuration, the core task is to adjust the old configuration according to the risk assessment results. , to approach a safer target configuration , adjustment coefficient The sensitivity of the adjustment depends on the urgency of the risk and the acceptable speed of configuration update. The old configuration is set to 100 units, the target configuration is set to 150 units, and the adjustment coefficient is set to 0.2;
[0118] The calculation process is:
[0119] ;
[0120] The result means that the new configuration will increase by 10 units, enhancing monitoring and protection of risk areas, allowing configuration updates to more accurately reflect current security needs while avoiding potential new risks caused by over-adjustment.
[0121] S403: Implement the updated defense measures, perform configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, and intercept and mitigate potential multi-dimensional threat attacks. The execution process of the defense configuration adjustment plan is as follows;
[0122] The applicability of the modified equipment configuration and defense rules is verified through simulation testing and field applications. During the testing process, the system's response and actual performance will be closely monitored to ensure the effectiveness and security of the new configuration. Through testing, potential configuration deficiencies or loopholes can be discovered, and corresponding adjustments and optimizations can be made to intercept and mitigate potential multi-dimensional threat attacks. This step involves cross-departmental cooperation and coordination, as well as in-depth analysis by security experts. A detailed list of all successfully implemented defense measures and their contribution to resisting future threats is listed to ensure that the satellite network maintains the highest security and responsiveness when facing a complex and changing threat environment, and a defense configuration adjustment plan is obtained.
[0123] See also Figure 6 As shown in the figure, the steps for conducting multi-dimensional threat simulation in a virtual environment, testing the threat processing speed of the defense configuration adjustment solution, detecting the impact of the defense configuration adjustment on the performance of the satellite network, evaluating the implementation effect and impact, and identifying the overall security of the satellite network are as follows:
[0124] S501: Using a virtual environment and importing a defense configuration adjustment plan, simulate various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, and calculate the defense efficiency under different scenarios. The execution process for obtaining simulation test data is as follows:
[0125] The formula for calculating defense efficiency in differentiated scenarios is:
[0126] ;
[0127] in, is the defense efficiency value, Represents the total number of simulated scenarios, Representative Defense response time for each scenario, The average defense response time of the representative scenario, represents the standard deviation of defense response time;
[0128] Parameter meaning and setting value:
[0129] is the total number of scenarios, which is set to 100, reflecting the diversity of scenarios simulated;
[0130] For the The response time of each scenario, data points obtained from actual defense logs, set seconds, indicating that in the first scenario, the defense configuration responds in 0.03 seconds;
[0131] is the average response time of all scenarios, calculated based on actual data, and set to seconds, reflecting the average performance of the defense configuration in all scenarios;
[0132] is the standard deviation, based on The distribution of is calculated and set as seconds, showing the degree of fluctuation in response time;
[0133] Substitute the parameters into the formula for calculation:
[0134] ;
[0135] ;
[0136] The results show that the defense efficiency is certain in different scenarios. The low value suggests that the defense response time is too high in some scenarios, and further optimization of the defense configuration is needed to improve the defense efficiency.
[0137] S502: Based on the simulation test data, monitor and record the impact of the defense configuration on the satellite network performance, analyze the network delay, data throughput, and resource utilization after the defense measures are implemented, and obtain the performance impact assessment results. The execution process is as follows;
[0138] Careful observation and recording of key performance indicators such as network latency, data throughput, and resource utilization, and analysis of network performance after the implementation of defense measures to determine the actual effectiveness and side effects of the defense strategy, with particular attention paid to configuration changes that significantly impact network performance. Analytical data includes calculating the percentage change in latency after the introduction of defense measures, the increase or decrease in data throughput, and the degree of optimization of resource utilization. Evaluation data not only helps understand the specific impact of defense configuration on performance but also provides guidance for future network optimization. Listing the changes in various performance indicators provides important data support for decision makers, so that while ensuring network security, they can also maintain or even improve the overall performance of the network and obtain performance impact assessment results.
[0139] S503: Using the performance impact assessment results, analyze the overall security and implementation effectiveness of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, and conduct a multi-dimensional threat security assessment. The execution process for obtaining the multi-dimensional threat simulation test results is as follows;
[0140] In-depth exploration of how defensive measures can improve network security, identification of new or unresolved security vulnerabilities and performance bottlenecks arising from configuration changes, and multi-dimensional threat security assessments. This includes testing the effectiveness of security measures at all levels of the network, examining network performance under various threat scenarios, and conducting a comprehensive effectiveness evaluation of defensive measures. Special attention is paid to areas showing potential risks in simulation tests. Problems are identified and recorded in order to be addressed in a targeted manner in subsequent updates and adjustments to ensure network resilience and security. Various test scenarios and corresponding network responses are listed in detail, providing valuable insights and improvement suggestions for the network security team. The information will be used to guide future security policy adjustments and network maintenance work, and to obtain multi-dimensional threat simulation test results.
[0141] See also Figure 7 As shown, on the other hand, a satellite network multi-dimensional threat simulation system based on isolation forest detection is provided. The satellite network multi-dimensional threat simulation system based on isolation forest detection is used to execute the above-mentioned satellite network multi-dimensional threat simulation method based on isolation forest detection. The system includes:
[0142] The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including traffic volume, delay and packet loss rate, to obtain a real-time traffic archive;
[0143] The traffic characteristics analysis module collects and organizes key indicators based on real-time traffic archives, analyzes the performance and characteristics of key indicators, and builds an initial traffic characteristics framework;
[0144] The anomaly identification module uses the isolation forest algorithm based on the initialization traffic characteristics framework to screen real-time data, detect abnormal fluctuations and potential threats, and obtain abnormal pattern analysis results;
[0145] The threat rating module evaluates the multi-dimensional threat level of abnormal data based on the abnormal pattern analysis results. By comparing the hazard level and frequency of occurrence of differentiated threat types, it assigns a risk rating to each threat type and obtains the threat risk rating result.
[0146] The defense strategy adjustment module updates the satellite network's defense configuration based on the threat risk rating results, adjusts intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains a defense configuration plan;
[0147] The test and evaluation module uses the defense configuration scheme to conduct multi-dimensional threat simulation tests in a virtual environment, evaluates the processing speed of the defense strategy and its impact on satellite network performance, verifies the implementation effect, identifies the overall security of the satellite network, and obtains multi-dimensional threat simulation test results.
[0148] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A satellite network multi-dimensional threat simulation method based on isolation forest detection, characterized by: The following steps are involved: Load real-time traffic data from the satellite network through the data interface, extract key indicators, record traffic volume, latency, and packet loss rate, and establish an initial traffic feature framework; specifically, Loading real-time traffic data from a satellite network through a data interface, synchronously and in real time receiving the traffic data, including traffic size, latency, and packet loss rate, performing initial data quality monitoring, screening problematic data segments, and obtaining a dynamic data set; using the dynamic data set, formatting the data, adjusting the data format, performing data processing, removing invalid and erroneous data records, and standardizing the processed data to obtain a standardized data set; classifying the real-time traffic data based on the standardized data set, grouping it according to differentiated ranges of traffic size, latency, and packet loss rate, identifying and summarizing target characteristics of each type of data, and establishing an initialization traffic characteristic framework; By using the aforementioned initialized traffic characteristic framework, an isolation forest algorithm is used to perform abnormal pattern recognition on real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, mark and classify potential satellite network threats, and obtain abnormal pattern recognition results; Based on the abnormal pattern recognition results, the multi-dimensional threat level of the abnormal data is evaluated, and by analyzing the hazard level and frequency of the threat type, the risk rating of each threat type is identified, and the threat risk assessment result is output; Using the threat risk assessment results, adjust the satellite network defense configuration, update intrusion detection rules and firewall defenses, adjust the satellite network equipment configuration, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan; Conduct multi-dimensional threat simulation in a virtual environment to test the speed at which the defense configuration adjustment solution handles threats, detect the impact of the defense configuration adjustment on satellite network performance, evaluate the implementation effect and impact, identify the overall security of the satellite network, and obtain multi-dimensional threat simulation test results; Among them, a virtual environment is used and the defense configuration adjustment plan is imported to perform simulation tests on various threat scenarios, analyze the response speed and processing efficiency of the defense configuration, calculate the defense efficiency under differentiated scenarios, and obtain simulation test data.
2. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The initialization traffic characteristic framework includes traffic size indicators, delay indicators, and packet loss rate indicators. The abnormal pattern recognition results include abnormal fluctuation identification and potential threat marking. The threat risk assessment results include hazard level analysis, threat frequency calculation, and corresponding risk rating for each threat type. The defense configuration adjustment plan includes intrusion detection rule updates, firewall defense adjustments, and satellite network equipment configuration updates. The multi-dimensional threat simulation test results include processing speed tests, satellite network performance impact assessments, and overall security ratings.
3. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: By using the aforementioned initialized traffic characteristic framework, the isolation forest algorithm is used to perform abnormal pattern recognition on real-time traffic data, identify abnormal fluctuations and potential threats in the real-time traffic data, compare the identified abnormal patterns with known threat characteristics, and mark and classify potential satellite network threats. The specific steps for obtaining abnormal pattern recognition results are as follows: Based on the initialization traffic characteristic framework, the real-time traffic data is initially screened to identify data points with fluctuations and mark the data points as abnormal, thereby obtaining an initialization abnormal data marking result; Analyze the labeled data using the initial abnormal data labeling results, compare them with preset abnormal patterns, identify abnormal data that matches the known patterns, classify the data as potential threats, and obtain abnormal comparison and analysis results; The abnormal comparison and analysis results are used to classify and mark the identified abnormal patterns, analyze the type and potential threat level of each abnormal pattern, and obtain abnormal pattern recognition results.
4. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: Based on the abnormal pattern recognition results, the multi-dimensional threat level of the abnormal data is evaluated, and by analyzing the hazard level and frequency of the threat type, the risk rating of each threat type is identified, and the steps of outputting the threat risk assessment results are specifically as follows: Utilizing the abnormal pattern recognition results, extracting the type and frequency information of multiple types of abnormal data, performing risk impact analysis on each abnormal type, identifying the threat level of each abnormality, and obtaining abnormal type analysis results; Based on the anomaly type analysis results, the hazard level and occurrence frequency of each anomaly type are evaluated, the risk level of the anomaly type is calculated, and a threat risk rating record is obtained; Through the threat risk rating records, the risk levels and potential hazards of multiple types of abnormal patterns are integrated, and the influencing factors of potential hazards are identified, and the threat risk assessment results are output.
5. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 4 is characterized in that: The formula for calculating the risk level of the anomaly type is as follows: ; in, Representative The risk level of each abnormal type, Representative The weight coefficient of each evaluation factor, Representative The exception type is The scores on the evaluation factors, Representative The continuity impact assessment value of the abnormal type, is the number of evaluation factors.
6. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The steps for using the threat risk assessment results to adjust the satellite network defense configuration, update intrusion detection rules and firewall defenses, adjust the satellite network device configuration, intercept and mitigate multi-dimensional threat attacks, and obtain a defense configuration adjustment plan are as follows: Using the threat risk assessment results, analyzing the risk ratings of differentiated threat types, and adjusting intrusion detection rules and firewall policies corresponding to higher-risk attacks based on the risk ratings to obtain priority defense adjustment results; Based on the priority defense adjustment results, the defense configuration of the satellite network is updated, the security settings of the associated satellite network devices are adjusted, the monitoring and protection of the risk area are optimized, and updated defense measures are obtained; Implement the updated defense measures, conduct configuration testing and optimization, verify the applicability of the modified device configuration and defense rules, intercept and mitigate potential multi-dimensional threat attacks, and obtain a defense configuration adjustment plan.
7. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 1 is characterized in that: The steps for conducting multi-dimensional threat simulation in a virtual environment, testing the threat processing speed of the defense configuration adjustment solution, detecting the impact of the defense configuration adjustment on the performance of the satellite network, evaluating the implementation effect and impact, and identifying the overall security of the satellite network are as follows: Based on the simulation test data, monitor and record the impact of the defense configuration on satellite network performance, analyze network latency, data throughput, and resource utilization after the defense measures are implemented, and obtain performance impact assessment results; The performance impact assessment results are used to analyze the overall security and implementation effect of the adjusted defense configuration, identify and record potential security vulnerabilities and performance bottlenecks, conduct a security assessment of multi-dimensional threats, and obtain multi-dimensional threat simulation test results.
8. The satellite network multi-dimensional threat simulation method based on isolation forest detection according to claim 7 is characterized in that: The formula for calculating the defense efficiency in the differentiated scenario is: ; in, is the defense efficiency value, Represents the total number of simulated scenarios, Representative Defense response time for each scenario, The average defense response time of the representative scenario, Represents the standard deviation of defense response time.
9. Satellite network multi-dimensional threat simulation system based on isolation forest detection, characterized by: The satellite network multi-dimensional threat simulation method based on isolation forest detection according to any one of claims 1 to 8, wherein the system comprises: The data interface loading module receives real-time traffic data from the satellite network, organizes and archives the data, including traffic volume, delay and packet loss rate, to obtain a real-time traffic archive; The traffic characteristics analysis module collects and organizes key indicators based on the real-time traffic archive, analyzes the performance and characteristics of the key indicators, and constructs an initial traffic characteristics framework; The anomaly identification module uses the isolation forest algorithm based on the initialization traffic characteristic framework to screen real-time data, detect abnormal fluctuations and potential threats, and obtain abnormal pattern analysis results; The threat rating module evaluates the multi-dimensional threat level of the abnormal data based on the abnormal pattern analysis results, and performs a risk rating on each threat type by comparing the hazard level and occurrence frequency of differentiated threat types to obtain a threat risk rating result; The defense strategy adjustment module updates the defense configuration of the satellite network based on the threat risk rating results, adjusts intrusion detection rules and firewall settings, intercepts and mitigates multi-dimensional threats, and obtains a defense configuration plan; The test and evaluation module uses the defense configuration scheme to perform multi-dimensional threat simulation testing in a virtual environment, evaluates the processing speed of the defense strategy and its impact on satellite network performance, verifies the implementation effect, identifies the overall security of the satellite network, and obtains multi-dimensional threat simulation test results.
Citation Information
Patent Citations
Security monitoring model based on security label in satellite network
CN108234499A
Intrusion detection and response method and system of satellite internet target range
CN119155101A