Block chain distributed consensus-based satellite network intelligent defense method and system

By adopting an intelligent defense method based on blockchain distributed consensus in satellite networks, combining long and short-term memory network analysis traffic data and blockchain consensus verification, the problem of high latency and error rates in satellite networks affecting defense efficiency is solved, efficient anomaly detection and instant security policy updates are achieved, and the defense capability and stability of the network are improved.

CN120050068AActive Publication Date: 2025-05-27XINGCHEN XUANJI (BEIJING) MEASUREMENT & CONTROL TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510087090.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-27
Estimated Expiration
2045-01-20

AI Technical Summary

Technical Problem

The prior art is difficult to effectively handle high latency and error rates in satellite networks, resulting in low data protection and abnormal detection efficiency, inability to respond to security threats in a timely manner, affecting the overall defense efficiency of the network and the secure transmission of key data.

Method used

The intelligent defense method based on blockchain distributed consensus is adopted to analyze the time series traffic data of satellite network nodes through long and short-term memory networks, identify abnormal traffic, determine potential intrusion paths, and conduct consensus verification in the blockchain network to ensure the transparency and consistency of data verification, and realize instant security policy updates and defense capability evaluation.

Benefits of technology

It improves the accuracy and speed of abnormal detection, accurately identify potential intrusion paths, enhances the ability to update defense strategies in real time, improves the adaptability and response speed of the entire network, and ensures the continuous and stable operation of the communication network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050068A_ABST
    Figure CN120050068A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network defense, in particular to a satellite network intelligent defense method and system based on block chain distributed consensus. The method comprises the following steps: collecting satellite network node time sequence flow data, carrying out modeling analysis on the data through a long and short term memory network, predicting a data flow of a next time window, comparing a standard communication mode, identifying abnormal flow data, and generating an abnormal communication behavior identification result. According to the invention, the monitoring and analysis of the data stream are optimized by integrating the long-short-term memory network, the future data stream can be accurately predicted, the deviation from the standard mode can be detected in real time, the accuracy and speed of anomaly detection are effectively enhanced, the connection between nodes and the flow direction of the data packet are analyzed, and the potential intrusion path is accurately identified. The transparency and consistency of data verification are ensured through a block chain technology, the instant updating capability of a defense strategy is enhanced, and the adaptability and response speed of the whole network are improved, so that continuous and stable operation of the communication network is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network defense, and particularly to an intelligent defense method and system for satellite networks based on blockchain distributed consensus. Background Art

[0002] The technical field of network defense mainly focuses on protecting computer networks from unauthorized access and attacks. This includes implementing various security measures to prevent intrusion, monitoring network traffic to detect and respond to abnormal behavior, and using encryption technology to protect the integrity and privacy of data transmission. The scope of network defense technology is extensive, ranging from basic firewalls and antivirus software to advanced intrusion detection systems and security information and event management (SIEM) solutions. In the modern network environment, with the development of technology and the increasing complexity of attack means, network defense technology is constantly evolving, including the application of machine learning and artificial intelligence technologies to more intelligently predict and defend against potential network threats.

[0003] Among them, the intelligent defense method for satellite networks involves the development and implementation of security policies for satellite communication networks, aiming to protect the network from various network threats, such as hacking, data theft, or denial-of-service attacks. Due to its wide range of applications and usually high latency and error rate, satellite networks require special defense strategies, including strengthening signal encryption, implementing more stringent access control, mainly to improve the security of satellite networks, ensure the secure transmission of important data, while protecting the network from potential network attacks, and support the stable operation of key fields such as military, communication, and navigation.

[0004] Although existing network defense technologies cover a variety of security measures, in the special environment of satellite networks, high latency and error rate significantly affect their efficiency and real-time performance. Data protection and anomaly detection in existing technologies are usually not applicable to dynamic and distributed satellite network environments and are difficult to handle rapidly changing security threats. In addition, existing solutions have defects in network-wide synchronization and consistent data verification. The common security policy update mechanism responds slowly when applied in satellite networks and cannot promptly reflect new security requirements, affecting the overall defense effectiveness of the network and the secure transmission of key data, and may lead to security vulnerabilities in the practical applications of key fields such as military and communication, increasing potential operational risks. Summary of the Invention

[0005] The purpose of the present invention is to solve the drawbacks existing in the prior art, and to propose an intelligent defense method and system for satellite networks based on blockchain distributed consensus.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions:

[0007] Satellite network intelligent defense method based on blockchain distributed consensus, comprising the following steps:

[0008] S1: Collect time series traffic data of satellite network nodes, perform modeling analysis on the data through a long short-term memory network, predict the data flow of the next time window, compare with the standard communication mode, identify abnormal traffic data, and generate an abnormal communication behavior recognition result;

[0009] S2: According to the abnormal communication behavior recognition result, analyze the connection status of each node in the satellite network with adjacent nodes, trace the data packet flow direction, calculate the abnormal traffic ratio of each connection, determine the potential intrusion path, and generate a potential intrusion path recognition result;

[0010] S3: Based on the potential intrusion path recognition result, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and generate a consensus verification completion record;

[0011] S4: Based on the consensus verification completion record, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file, and generate a security policy synchronization status record;

[0012] S5: According to the security policy synchronization status record, perform a security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the satellite network defense ability meets the standard, and generate a network defense ability evaluation report.

[0013] Optionally, the abnormal communication behavior recognition result includes traffic anomaly points, time anomaly points, and pattern deviation analysis records; the potential intrusion path recognition result includes abnormal connection points, abnormal flow directions, and traffic ratios; the consensus verification completion record includes verification marking results, node accuracy records, and data consistency analysis results; the security policy synchronization status record includes configuration update records, security requirement matching results, and configuration file verification results; the network defense ability evaluation report includes security compliance analysis results, defense performance scores, and security standard achievement records.

[0014] Optionally, the specific steps of collecting time series traffic data of satellite network nodes, performing modeling analysis on the data through a long short-term memory network, predicting the data flow of the next time window, comparing with the standard communication mode, and identifying abnormal traffic data to generate an abnormal communication behavior recognition result are as follows:

[0015] S101: Collect time series traffic data of satellite network nodes, set the collection period, synchronize the data timestamps, check the time consistency of the data, and batch transfer the data to the local database to generate an original data set;

[0016] S102: Based on the original data set, conduct a preliminary check on the data, exclude transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, unify the data format, and generate a cleaned data set;

[0017] S103: Based on the cleaned data set, set data splitting parameters to divide the training and test sets, predict the data traffic of the next time window through a long short-term memory network, compare it with the standard communication mode, identify abnormal traffic points, and generate an identification result of abnormal communication behavior.

[0018] Optionally, according to the identification result of abnormal communication behavior, analyze the connection status of each node in the satellite network with adjacent nodes, trace the flow direction of data packets, calculate the abnormal traffic ratio of each connection, determine potential intrusion paths, and the specific steps for generating an identification result of potential intrusion paths are as follows:

[0019] S201: Based on the identification result of abnormal communication behavior, record the connection status between each node and adjacent nodes in the satellite network, monitor the frequency and duration of each connection, and at the same time collect data transmission records to generate a node connection status report;

[0020] S202: Based on the node connection status report, mark the flow direction of each data packet, from the source node to the target node, record the data transmission path between nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report;

[0021] S203: Based on the abnormal traffic analysis report, compare it with a preset traffic threshold, analyze the connection paths with abnormal traffic greater than the preset traffic threshold, and combine the network topology structure to identify key potential intrusion paths and generate an identification result of potential intrusion paths.

[0022] Optionally, the abnormal traffic probability is calculated according to the formula:

[0023]

[0024] It is calculated as follows, where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

[0025] Optionally, based on the identification result of potential intrusion paths, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and the specific steps for generating a consensus verification completion record are as follows:

[0026] S301: Initialize the consensus mechanism in the blockchain network based on the potential intrusion path recognition result, set the time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole-network data consensus process, and generate a consensus request initiation record;

[0027] S302: Based on the consensus request initiation record, conduct intensive verification on the data packets received by each node in the network, check the authenticity and integrity of the data, perform timestamp and content verification on the data of each node, and generate a data packet verification record;

[0028] S303: Based on the data packet verification record, mark the abnormal data packets, record the verification details of the node identifiers and the data packet content, confirm the accuracy of the data through synchronization among nodes, and generate a consensus verification completion record.

[0029] Optionally, based on the consensus verification completion record, the specific steps for instantaneously updating the node security policies in the satellite network, synchronizing the security configurations of each node, matching the latest security requirements, recording and verifying each modification to the configuration file, and generating a security policy synchronization status record are as follows:

[0030] S401: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record;

[0031] S402: Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and content, and generate a configuration modification monitoring record;

[0032] S403: Based on the configuration modification monitoring record, conduct security verification, confirm that the security configuration files of all nodes have been correctly updated, and complete the security policy synchronization within the network, and generate a security policy synchronization status record.

[0033] Optionally, according to the security policy synchronization status record, the specific steps for conducting a security compliance inspection on each node, evaluating the overall defense performance of the network, confirming whether the satellite network defense capability meets the standard, and generating a network defense capability evaluation report are as follows:

[0034] S501: Based on the security policy synchronization status record, initialize the security compliance inspection program, perform a security configuration check for each node, confirm the consistency between the configuration file and the security standard, record the compliance status and inspection time of the node, and generate a node compliance inspection record;

[0035] S502: Analyze the defense performance of the entire satellite network based on the node compliance check records, examine the collaborative defense mechanism between nodes, evaluate the node response time and processing capabilities, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record;

[0036] S503: Based on the network defense performance analysis record, comprehensively evaluate the defense capabilities of the satellite network, check whether the defense performance of each node meets the preset security standards, summarize the evaluation results to confirm the overall defense status of the network, and generate a network defense capability evaluation report.

[0037] Optionally, the defense efficiency is calculated according to the formula:

[0038]

[0039] where R represents the efficiency value, T n represents the average value of the node response time, C p represents the average value of the node processing capabilities, D a represents the total data traffic sum between nodes, and P n represents the total number of nodes in the network.

[0040] A satellite network intelligent defense system based on blockchain distributed consensus includes:

[0041] The data collection and prediction module collects the time series traffic data of satellite network nodes, sets the collection period, synchronizes the data timestamps, conducts a preliminary check on the data, unifies the data format, predicts the data traffic of the next time window, compares it with the standard communication mode and identifies abnormal traffic points, and generates an abnormal communication behavior recognition result;

[0042] The abnormal path analysis module, based on the abnormal communication behavior recognition result, records the connection status between each node and its adjacent nodes in the satellite network, marks the flow direction of each data packet, calculates the abnormal traffic probability in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion paths, and generates a potential intrusion path recognition result;

[0043] The consensus mechanism startup module, based on the potential intrusion path recognition result, initializes the consensus mechanism in the blockchain network, starts the whole network data consensus process, intensively verifies the data packets received by each node in the network, marks the abnormal data packets, and generates a consensus verification completion record;

[0044] The security policy update module, based on the consensus verification completion record, starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates a configuration modification monitoring record;

[0045] The compliance check module modifies the monitoring records based on the configuration, performs security verification, confirms that the security configuration files of all nodes have been correctly updated, executes security configuration verification for each node, confirms the consistency between the configuration files and the security standards, and generates node compliance check records;

[0046] Based on the node compliance check records, the defense performance evaluation module analyzes the defense performance of the entire satellite network, calculates the defense efficiency of the overall network, checks whether the defense performance of each node meets the preset security standards, summarizes the evaluation results to confirm the overall defense status of the network, and generates a network defense capability evaluation report.

[0047] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0048] In the present invention, by integrating long short-term memory networks, the monitoring and analysis of data streams are optimized, the future data streams can be accurately predicted and the deviations from the standard patterns can be detected in real time, effectively enhancing the accuracy and speed of anomaly detection, analyzing the connections between nodes and the data packet flows, accurately identifying potential intrusion paths, ensuring the transparency and consistency of data verification through blockchain technology, enhancing the instant update ability of defense strategies, improving the adaptability and response speed of the entire network, thereby ensuring the continuous and stable operation of the communication network. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 is a schematic diagram of the step flow of the present invention;

[0050] Figure 2 is a flowchart of step S1 of the present invention;

[0051] Figure 3 is a flowchart of step S2 of the present invention;

[0052] Figure 4 is a flowchart of step S3 of the present invention;

[0053] Figure 5 is a flowchart of step S4 of the present invention;

[0054] Figure 6 is a flowchart of step S5 of the present invention;

[0055] Figure 7 is a system module diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0057] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.

[0058] Please refer to Figure 1 As shown, the satellite network intelligent defense method based on blockchain distributed consensus includes the following steps:

[0059] S1: Collect the time series traffic data of satellite network nodes, model and analyze the data through a long short-term memory network, predict the data flow in the next time window, compare with the standard communication mode, identify abnormal traffic data, and generate the recognition result of abnormal communication behavior;

[0060] S2: According to the recognition result of abnormal communication behavior, analyze the connection status of each node in the satellite network with adjacent nodes, trace the flow direction of data packets, calculate the abnormal traffic ratio of each connection, determine the potential intrusion path, and generate the recognition result of potential intrusion path;

[0061] S3: Based on the recognition result of potential intrusion path, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and generate a record of the completion of consensus verification;

[0062] S4: Based on the record of the completion of consensus verification, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file, and generate a record of the security policy synchronization status;

[0063] S5: According to the record of the security policy synchronization status, conduct a security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the defense ability of the satellite network meets the standard, and generate a network defense ability evaluation report.

[0064] The recognition results of abnormal communication behaviors include traffic anomaly points, time anomaly points, and pattern deviation analysis records; the recognition results of potential intrusion paths include abnormal connection points, abnormal flow directions, and traffic ratios; the completion records of consensus verification include verification mark results, node accuracy records, and data consistency analysis results; the records of security policy synchronization status include configuration update records, security requirement matching results, and configuration file verification results; the network defense capability assessment report includes security compliance analysis results, defense performance scores, and security standard achievement records.

[0065] Please refer to Figure 2 as shown, the specific steps of S1 are as follows:

[0066] S101: Collect time series traffic data of satellite network nodes, set the collection period, synchronize the data timestamps, check the time consistency of the data, batch transfer the data to the local database, and generate the original data set;

[0067] Collect time series traffic data of satellite network nodes, set a unified collection period, initialize the data collection device according to the protocol standard, including setting the frequency range of the received signal and the data collection format, call the satellite node data interface to obtain high-precision timestamp information, perform time calibration for the timestamp differences collected by multiple nodes, use the time synchronization protocol to unify the time of different nodes to the standard reference time, verify the consistency of the synchronization result to ensure that the error between the data timestamp and the collection period is less than the preset threshold, use the data packaging strategy to transmit the collected time series traffic data to the local database through the encrypted communication channel in batch transmission mode, perform segmented writing operations on the data based on the storage structure design of the database, and attach a check code at the same time to ensure the integrity of data transmission, and generate the original data set that can support subsequent analysis.

[0068] S102: Based on the original data set, conduct a preliminary check on the data, exclude transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, unify the data format, and generate the cleaned data set;

[0069] Based on the original dataset, conduct a preliminary inspection of the collected time - series traffic data. First, perform an integrity review of the data points through a missing - value marking method, screen out the records with missing points and mark them. Subsequently, call the data - cleaning algorithm to interpolate or remove the missing points, use statistical methods to detect and delete the outliers in the traffic data that exceed the normal range, including invalid data with too low or too high traffic. Identify and remove duplicate records through a hash - matching and duplicate - detection mechanism. Use a data - type conversion module to normalize the fields that do not conform to the standard type. For example, uniformly convert floating - point fields to integer or fixed - point types. Standardize the range of all fields according to the predefined numerical range, call the field - mapping rules to re - define the storage format and structure of the data, and finally generate a dataset with a unified format and complete cleaning to provide consistent data input for subsequent processing.

[0070] S103: Based on the cleaned dataset, set the data - splitting parameters to divide the training and test sets. Predict the data traffic of the next time window through a long short - term memory network, compare it with the standard communication mode, identify the abnormal traffic points, and generate the recognition result of abnormal communication behavior.

[0071] Based on the cleaned dataset, set the splitting parameters for data division, including the division ratio of the training set and the test set, and use the stratified sampling method to ensure the consistency of the distribution characteristics of the divided dataset. Import the cleaned dataset into the deep - learning model framework, call the long short - term memory network to predict the traffic of the next time window. The model first extracts the features of the time - series data through multiple layers of networks, and then calculates the predicted value based on the feature vectors. Compare the predicted traffic value with the traffic value in the standard communication mode point by point, identify the abnormal traffic points according to the statistical threshold of the traffic difference, mark and output all the identified abnormal points, and at the same time generate the recognition result of abnormal communication behavior, providing a direct basis and reference for subsequent further security analysis and optimization.

[0072] Please refer to Figure 3 as shown, the specific steps of S2 are as follows:

[0073] S201: Based on the recognition result of abnormal communication behavior, record the connection status between each node and its adjacent nodes in the satellite network, monitor the frequency and duration of each connection, and at the same time collect the data - transmission records to generate a node - connection status report.

[0074] Based on the recognition results of abnormal communication behaviors, record the connection status of each node in the satellite network with its adjacent nodes. By calling the node status query interface, obtain the connection status data in real time, including the connection establishment time, disconnection time, and the number of transmitted data packets. Statistically analyze the communication frequency of each connection, record the transmission time interval of the data packets, and at the same time analyze the duration distribution of the connections. Generate a transmission record table for all data connections, construct a node connection status data set based on parameters such as connection stability, frequency, and transmission volume, and organize the comprehensive status information of each connection into a report form for output, generating a detailed node connection status report to reflect the communication activities between nodes in the satellite network.

[0075] S202: Based on the node connection status report, mark the flow direction of each data packet, from the source node to the target node, record the data transmission path between nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report;

[0076] The abnormal traffic probability is calculated according to the formula:

[0077]

[0078] It is calculated as follows, where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

[0079] P(A) is the prior probability of event A occurring, that is, the probability of event A occurring without any other information. For example, the probability that a network data packet is abnormal traffic. According to historical data analysis, the probability is 0.05.

[0080] P(B|A) is the conditional probability of event B occurring given that event A has occurred. For example, if a network data packet is abnormal traffic, the probability of being detected as abnormal. Based on the records of the network monitoring system, the probability is 0.9.

[0081] P(B) is the marginal probability of event B, that is, the probability of event B occurring regardless of whether event A has occurred. For example, the probability that any network data packet is detected as abnormal. From the statistical data of the monitoring system, the probability is 0.1.

[0082] Given the above parameters, calculate P(A|B):

[0083]

[0084] The results show that, given the occurrence of event B, the probability of event A occurring is higher than its prior probability (1.7889 is greater than 1), which means that if a network data packet is detected as abnormal, the likelihood that it is actually abnormal traffic increases significantly, helping network security personnel to more precisely identify and handle network threats.

[0085] S203: Based on the abnormal traffic analysis report, compare it with a preset traffic threshold, analyze the connection paths where the abnormal traffic is greater than the preset traffic threshold, and combine with the network topology structure to identify key potential intrusion paths, generating the identification results of potential intrusion paths;

[0086] Based on the abnormal traffic analysis report, compare the abnormal traffic values in the paths with the preset traffic threshold one by one, screen the paths where the abnormal traffic is greater than the preset threshold, use a network topology parsing tool to perform topology mapping on the screened paths, analyze the node interaction characteristics and the flow direction of data packets in the paths, and combine with the node importance indicators in the network topology graph, such as the degree centrality and betweenness centrality of nodes, to identify key connection nodes with high abnormal traffic. By comprehensively considering the degree of path traffic abnormality and the potential impact of nodes in the network topology, generate a result list containing paths with potential intrusion risks for subsequent processing of network security events.

[0087] Please refer to Figure 4 as shown, the specific steps of S3 are:

[0088] S301: Based on the identification results of potential intrusion paths, initialize the consensus mechanism in the blockchain network, set the time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole-network data consensus process, and generate a consensus request initiation record;

[0089] Based on the identification results of potential intrusion paths, initialize the consensus mechanism in the blockchain network, set the initial parameters including the type of consensus algorithm, the number of verification nodes, and the time synchronization range, calibrate the time of all participating nodes through a distributed time synchronization protocol to ensure the timeliness of the consensus request, call the network protocol configuration module to update the network communication protocol to ensure that all nodes can receive and respond to the consensus request, detect the network status and availability of each node to exclude faulty nodes, distribute the consensus request data packet to all nodes in the network through a broadcast mechanism, start the distributed consensus calculation process and record the initiation time of the request and the list of broadcast nodes, generating a complete consensus request initiation record.

[0090] S302: Based on the consensus request initiation record, conduct intensive verification on the data packets received by each node in the network, verify the authenticity and integrity of the data, check the timestamp and content of the data of each node, and generate a data packet verification record;

[0091] Based on the consensus request initiation record, perform intensive verification operations on the consensus request data packets received by all nodes in the network. Verify the authenticity of the data by comparing the data packet content with the signature information of the sending node, call to check the integrity identifier of each data packet, calibrate the sending and receiving times of the data packets through the timestamp synchronization mechanism to verify time consistency, perform field-level content matching on the data packets received by each node, analyze the deviation from the expected values in the consensus algorithm, record the verification status of the data of each node and generate a verification report, and generate a data packet verification record after organizing the comprehensive results such as data authenticity, integrity, and timestamp calibration.

[0092] S303: Based on the data packet verification record, mark the abnormal data packets, record the verification details of the node identifier and the data packet content, confirm the accuracy of the data through synchronization between nodes, and generate a consensus verification completion record;

[0093] Based on the data packet verification record, identify and mark all abnormal data packets, determine the source of the abnormality by analyzing the verification details of the node identifier and content recorded in the data packet, call the node synchronization confirmation module to compare the verification status of the abnormal data packets on other nodes in the network, filter out the data packets outside the error range and record the detailed information of all nodes with verification abnormalities, re-perform secondary verification on the abnormal data packets based on the node-to-node synchronization confirmation process to ensure the accuracy of the verification results, classify and count the results of passed and failed verifications and record them, and finally output a consensus verification completion record, completely save the verification status and abnormal marking information of all nodes, and provide a reference basis for the subsequent consensus processing process.

[0094] Please refer to Figure 5 as shown, the specific steps of S4 are:

[0095] S401: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record;

[0096] Based on the consensus verification completion record, start the security policy update program. First, load the updated security protocol for all nodes in the network, extract the key parameter settings in the protocol, and perform a comparison and analysis on the security configuration files of each node to identify the configuration parameter items that need to be adjusted. Gradually update the security configuration parameters of the nodes to ensure that the configuration content is consistent with the security protocol. By performing real-time synchronization on the security configurations between nodes, check the latency and consistency issues during the synchronization process to ensure that the security configuration file statuses of all nodes are consistent. Finally, generate a security configuration update report containing the detailed records of the security configuration updates of all nodes.

[0097] S402: Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and content, and generate a configuration modification monitoring record;

[0098] Based on the security configuration update record, track and record the response of each node to the security policy update, monitor the execution status of the node's security configuration modification instructions in real time, itemize and record the modification content and operation time of the configuration file, and at the same time associate the execution log of the node to verify the correctness of the modification. Sort out the errors or exceptions that occur during the update process of each node, including problems such as modification failure and synchronization delay, record the field adjustment and new entries in the configuration file, ensure that all details are traceable, summarize the modification process and content of all nodes to generate a configuration modification monitoring record, and provide a detailed execution status basis for subsequent security policy verification.

[0099] S403: Based on the configuration modification monitoring record, perform security verification, confirm that the security configuration files of all nodes have been correctly updated, and complete the security policy synchronization within the network, and generate a security policy synchronization status record;

[0100] Based on the configuration modification monitoring record, verify each item of the security configuration files of all nodes, confirm the accuracy of the update by comparing the latest security policy standard and the actual configuration status of the nodes, detect the security protocol adaptability of the nodes, confirm the synchronization status between nodes and the consistency of the overall network, identify the nodes with incomplete updates or incorrect parameter configurations and output warning records, classify and sort out the verification results, ensure that the security configurations of all nodes are consistent with the updated security policy, generate a complete security policy synchronization status record, and provide real-time feedback support for the overall security status of the network.

[0101] Please refer to Figure 6 as shown, the specific steps of S5 are as follows:

[0102] S501: Based on the security policy synchronization status record, initialize the security compliance inspection program, perform a security configuration verification for each node, confirm the consistency between the configuration file and the security standard, record the compliance status and inspection time of the node, and generate a node compliance inspection record;

[0103] Based on the security policy synchronization status record, start the security compliance inspection program, check each item of the security configuration file for each node one by one, verify the integrity and consistency of the parameter settings by calling the compliance check to compare the security configuration content of the node with the preset security standards, and at the same time record the details during the inspection process, including the verification status of each configuration and the matching result of the parameter values, detect whether there are omissions or abnormalities in the configuration file of the node, judge the overall compliance status of the node according to the predefined compliance standards, accurately record the time of each verification, sort out the compliance inspection results of all nodes, and generate a node compliance inspection record to comprehensively reflect the security configuration status of the current network nodes.

[0104] S502: Based on the node compliance inspection record, analyze the defense performance of the entire satellite network, check the collaborative defense mechanism between nodes, evaluate the node response time and processing ability, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record;

[0105] The defense efficiency is calculated according to the formula:

[0106]

[0107] is calculated, where R represents the efficiency value, T n represents the average value of the node response time, indicating the average time required for each node to respond to a threat from detecting the threat, C p represents the average value of the node processing ability, indicating the ability of each node to process data, D a represents the total data traffic between nodes, indicating the total amount of data exchanged between all nodes, P n represents the total number of nodes in the network, indicating the number of nodes participating in the network defense mechanism.

[0108] T n represents the average value of the node response time, and the time data of the node's response to threats can be obtained from the real-time monitoring system. In a certain period, the data of the response time of a group of nodes is {200ms, 250ms, 180ms, 220ms}, then T n is the average value of the time:

[0109]

[0110] C p represents the average value of the node processing ability. This parameter reflects the ability of the node to process data and is usually obtained from the performance test of the node. For example, if the test results of the processing ability of a group of nodes are {1000, 1200, 1100, 900} with the unit of operations / second, then C p is:

[0111]

[0112] D a represents the total data traffic between nodes, which is the total amount of data measured by a network monitoring tool. For example, if the monitored data traffic is 5TB within a certain period of time, then D a = 5000GB.

[0113] P n represents the total number of nodes in the network, which is directly obtained from the network configuration management database. For example, if there are 50 nodes in the network, then P n = 50.

[0114] Substitute the above parameters into the formula, and the calculation process is as follows:

[0115]

[0116] The result shows that the defense efficiency is 1.363. The efficiency value reflects the network's response and handling ability to threats under the current configuration and performance conditions. The higher the defense efficiency value, the stronger the overall defense performance of the network. It can evaluate the impact of different network configurations on the defense performance, and then optimize the network structure and resource allocation.

[0117] S503: Based on the network defense performance analysis record, comprehensively evaluate the defense ability of the satellite network, check whether the defense performance of each node meets the preset security standards, summarize the evaluation results to confirm the overall defense status of the network, and generate a network defense ability evaluation report;

[0118] Based on the network defense performance analysis record, comprehensively analyze the defense ability of the satellite network. By checking the defense performance of each node one by one, compare the defense efficiency, collaboration ability, and response time of the nodes with the preset security standards, count the pass rate and non-compliance items of all nodes, and at the same time evaluate the weak links of the overall defense ability based on the network topology structure, mark the key nodes affecting the overall network security, combine the defense ability performance of each node, summarize the evaluation results and confirm whether the defense status of the entire network meets the predetermined requirements, and generate a network defense ability evaluation report containing detailed analysis and evaluation conclusions to provide support for the continuous improvement of network security strategies.

[0119] Please refer to Figure 7 as shown, the satellite network intelligent defense system based on blockchain distributed consensus includes:

[0120] The data collection and prediction module collects the time series traffic data of satellite network nodes, sets the collection period, synchronizes the data timestamps, conducts a preliminary check on the data, unifies the data format, predicts the data traffic in the next time window, compares it with the standard communication mode, and identifies abnormal traffic points to generate the identification result of abnormal communication behavior;

[0121] Based on the recognition result of abnormal communication behavior, the abnormal path analysis module records the connection status between each node and its adjacent nodes in the satellite network, marks the flow direction of each data packet, calculates the probability of abnormal traffic in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion paths, and generates the recognition result of potential intrusion paths;

[0122] Based on the recognition result of potential intrusion paths, the consensus mechanism startup module initializes the consensus mechanism in the blockchain network, starts the whole-network data consensus process, intensively verifies the data packets received by each node in the network, marks the abnormal data packets, and generates the record of completed consensus verification;

[0123] Based on the record of completed consensus verification, the security policy update module starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates the configuration modification monitoring record;

[0124] Based on the configuration modification monitoring record, the compliance check module conducts security verification, confirms that the security configuration files of all nodes have been correctly updated, performs security configuration verification for each node, confirms the consistency of the configuration files with the security standards, and generates the node compliance check record;

[0125] Based on the node compliance check record, the defense performance evaluation module analyzes the defense performance of the entire satellite network, calculates the defense efficiency of the overall network, checks whether the defense performance of each node meets the preset security standards, summarizes the evaluation results to confirm the overall defense status of the network, and generates the network defense capability evaluation report.

[0126] The above are only the preferred embodiments of the present invention, and do not impose other forms of limitations on the present invention. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution content of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. A satellite network intelligent defense method based on blockchain distributed consensus, characterized in that: The following steps are involved: Collect satellite network node time series traffic data, model and analyze the data through long short-term memory network, predict the data flow of the next time window, compare with the standard communication mode, identify abnormal traffic data, and generate abnormal communication behavior identification results; According to the abnormal communication behavior identification result, the connection status of each node in the satellite network with the adjacent nodes is analyzed, and the flow of data packets is tracked, the abnormal traffic ratio of each connection is calculated, the potential intrusion path is determined, and the potential intrusion path identification result is generated; Based on the potential intrusion path identification results, a consensus request is initiated in the blockchain network, abnormal data packets received by all nodes are verified, the accuracy of each node data is verified and marked, and a consensus verification completion record is generated; Based on the consensus verification completion record, the node security policy in the satellite network is updated in real time, the security configuration of each node is synchronized to match the latest security requirements, each modification of the configuration file is recorded and verified, and a security policy synchronization status record is generated; According to the security policy synchronization status record, each node is checked for security compliance, the overall defense performance of the network is evaluated, whether the satellite network defense capability meets the standards is confirmed, and a network defense capability evaluation report is generated.

2. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: The abnormal communication behavior identification results include traffic anomaly points, time anomaly points and pattern deviation analysis records; the potential intrusion path identification results include abnormal connection points, abnormal flow directions and traffic ratios; the consensus verification completion records include verification marking results, node accuracy records and data consistency analysis results; the security policy synchronization status records include configuration update records, security requirements matching results and configuration file verification results; the network defense capability assessment report includes security compliance analysis results, defense performance scores and security standard achievement records.

3. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: The specific steps of collecting satellite network node time series traffic data, modeling and analyzing the data through long short-term memory networks, predicting the data flow of the next time window, comparing the standard communication mode, identifying abnormal traffic data, and generating abnormal communication behavior identification results are as follows: Collect time series traffic data of satellite network nodes, set the collection cycle, synchronize data timestamps, verify the time consistency of data, transfer data in batches to the local database, and generate the original data set; Based on the original data set, perform a preliminary check on the data, eliminate transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, unify the data format, and generate a cleaned data set; Based on the cleaned data set, data segmentation parameters are set to divide the training and test sets, and the data traffic of the next time window is predicted through the long short-term memory network. The data is compared with the standard communication mode, abnormal traffic points are identified, and abnormal communication behavior identification results are generated.

4. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: According to the abnormal communication behavior identification result, the connection status of each node in the satellite network with the adjacent nodes is analyzed, and the flow of data packets is tracked, the abnormal traffic ratio of each connection is calculated, and the potential intrusion path is determined. The specific steps of generating the potential intrusion path identification result are: Based on the abnormal communication behavior identification result, record the connection status between each node and the adjacent nodes in the satellite network, monitor the frequency and duration of each connection, collect data transmission records, and generate a node connection status report; Based on the node connection status report, mark the flow direction of each data packet from the source node to the target node, record the data transmission path between the nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report; Based on the abnormal traffic analysis report, the report is compared with the preset traffic threshold, the connection paths where the abnormal traffic is greater than the preset traffic threshold are analyzed, and the key potential intrusion paths are identified in combination with the network topology to generate potential intrusion path identification results.

5. According to claim 4, the satellite network intelligent defense method based on blockchain distributed consensus is characterized in that: The abnormal traffic probability is according to the formula: Calculation is performed, where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

6. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: Based on the potential intrusion path identification results, a consensus request is initiated in the blockchain network to verify the abnormal data packets received by all nodes, verify the accuracy of each node data and mark it, and generate the consensus verification completion record in the following specific steps: Based on the potential intrusion path identification results, initialize the consensus mechanism in the blockchain network, set time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole network data consensus process, and generate a consensus request initiation record; Based on the consensus request initiation record, intensive verification is performed on the data packets received by each node in the network to verify the authenticity and integrity of the data, timestamp and content verification is performed on the data of each node, and a data packet verification record is generated; Based on the data packet verification record, abnormal data packets are marked, the verification details of the node identification and data packet content are recorded, the accuracy of the data is confirmed through synchronization between nodes, and a consensus verification completion record is generated.

7. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: Based on the consensus verification completion record, the node security policy in the satellite network is updated in real time, the security configuration of each node is synchronized, the latest security requirements are matched, each modification of the configuration file is recorded and verified, and the specific steps for generating the security policy synchronization status record are as follows: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record; Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and modification content, and generate configuration modification monitoring records; Based on the configuration modification monitoring record, security verification is performed to confirm that the security configuration files of all nodes have been correctly updated, and the network-wide security policy synchronization is completed, and a security policy synchronization status record is generated.

8. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1 is characterized in that: According to the security policy synchronization status record, each node is tested for security compliance, the overall defense performance of the network is evaluated, and the satellite network defense capability is confirmed to be up to standard. The specific steps for generating a network defense capability evaluation report are as follows: Based on the security policy synchronization status record, a security compliance verification program is initialized, a security configuration verification is performed on each node, the consistency of the configuration file with the security standard is confirmed, the compliance status and verification time of the node are recorded, and a node compliance inspection record is generated; Based on the node compliance check record, analyze the defense performance of the entire satellite network, check the collaborative defense mechanism between nodes, evaluate the node reaction time and processing capacity, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record; Based on the network defense performance analysis records, the defense capabilities of the satellite network are comprehensively evaluated, and it is checked whether the defense performance of each node meets the preset security standards. The evaluation results are summarized to confirm the overall defense status of the network and generate a network defense capability evaluation report.

9. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 8 is characterized in that: The defense efficiency is according to the formula: Calculate, where R represents the efficiency value, T n represents the average node response time, C p Represents the average value of node processing capacity, D a Represents the total data traffic between nodes, P n Represents the total number of nodes in the network.

10. Satellite network intelligent defense system based on blockchain distributed consensus, characterized by: According to any one of claims 1 to 9, the satellite network intelligent defense method based on blockchain distributed consensus comprises: The data collection and prediction module collects the time series traffic data of satellite network nodes, sets the collection cycle, synchronizes the data timestamp, performs a preliminary check on the data, unifies the data format, predicts the data traffic of the next time window, compares it with the standard communication mode and identifies abnormal traffic points, and generates abnormal communication behavior identification results; Based on the abnormal communication behavior identification result, the abnormal path analysis module records the connection status between each node and the adjacent node in the satellite network, marks the flow direction of each data packet, calculates the abnormal traffic probability in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion path, and generates the potential intrusion path identification result; The consensus mechanism startup module initializes the consensus mechanism in the blockchain network based on the potential intrusion path identification result, starts the data consensus process of the entire network, performs intensive verification on the data packets received by each node in the network, marks abnormal data packets, and generates a consensus verification completion record; The security policy update module completes the record based on the consensus verification, starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates configuration modification monitoring records; The compliance check module performs security verification based on the configuration modification monitoring record to confirm that the security configuration files of all nodes have been correctly updated, performs security configuration verification on each node to confirm the consistency of the configuration files with the security standards, and generates node compliance check records; The defense performance evaluation module analyzes the defense performance of the entire satellite network based on the node compliance check records, calculates the defense efficiency of the entire network, verifies whether the defense performance of each node meets the preset security standards, summarizes the evaluation results to confirm the overall defense status of the network, and generates a network defense capability evaluation report.

Citation Information

Patent Citations

  • Active defense method, system and equipment based on internet access lock and medium

    CN118054973A

  • Network intrusion detection method and system

    CN118138368A

  • Distributed network security detection method and system based on block chain

    CN119030688A

  • An AI / ML-based system for preventing and recovering from ransomware attacks in the field of cybersecurity in the energy sector.

    DE202024104698U1

  • Dynamic defense system and method of new energy centralized control station network based on dynamic IP

    US20240414183A1