Satellite Network Intelligent Defense Method and System Based on Blockchain Distributed Consensus

By adopting the combination of blockchain distributed consensus and long and short-term memory networks in satellite networks, the efficiency and real-time problems brought about by high latency and error rates in satellite networks are solved, and the rapid identification of abnormal behaviors and immediate defense strategy updates are achieved, which improves the security and stability of the satellite network.

CN120050068BActive Publication Date: 2025-07-29XINGCHEN XUANJI (BEIJING) MEASUREMENT & CONTROL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510087090.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-07-29
Estimated Expiration
2045-01-20

AI Technical Summary

Technical Problem

The existing network defense technology affects efficiency and real-time performance in satellite networks due to high latency and error rates, making it difficult to deal with security threats in dynamic and distributed environments. The security policy update mechanism is slow to respond and cannot promptly reflect new security needs, resulting in security vulnerabilities and potential operational risks.

Method used

The intelligent defense method of satellite network based on blockchain distributed consensus is adopted to analyze traffic data through long and short-term memory networks, identify abnormal behaviors, track potential intrusion paths, and perform data verification and instant update of security policies in the blockchain network to ensure data consistency and instant response of defense policies.

Benefits of technology

It realizes accurate abnormal detection and rapid response to satellite networks, enhances the transparency of data verification and the ability to update defense strategies in real time, improves the adaptability and response speed of the network, and ensures the continuous and stable operation of the communication network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050068B_ABST
    Figure CN120050068B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network defense technologies, specifically a satellite network intelligent defense method and system based on blockchain distributed consensus. The method includes the following steps: collecting satellite network node time series traffic data, performing modeling and analysis on the data through a long short-term memory network, predicting the data flow in the next time window, comparing with the standard communication mode, identifying abnormal traffic data, and generating an identification result of abnormal communication behavior. In the present invention, by integrating the long short-term memory network, the monitoring and analysis of the data flow are optimized, the future data flow can be accurately predicted, and the deviation from the standard mode can be detected in real time, effectively enhancing the accuracy and speed of abnormal detection, analyzing the connections between nodes and the data packet flow direction, accurately identifying potential intrusion paths, ensuring the transparency and consistency of data verification through blockchain technology, enhancing the instant update ability of defense strategies, improving the adaptability and response speed of the entire network, thereby ensuring the continuous and stable operation of the communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network defense, and particularly to a satellite network intelligent defense method and system based on blockchain distributed consensus. Background Art

[0002] The technical field of network defense mainly focuses on protecting computer networks from unauthorized access and attacks. This includes implementing various security measures to prevent intrusion, monitoring network traffic to detect and respond to abnormal behavior, and using encryption technology to protect the integrity and privacy of data transmission. The scope of network defense technology is extensive, ranging from basic firewalls and antivirus software to advanced intrusion detection systems and security information and event management (SIEM) solutions. In the modern network environment, with the development of technology and the increasing complexity of attack methods, network defense technology is constantly evolving, including the application of machine learning and artificial intelligence technologies to more intelligently predict and defend against potential network threats.

[0003] Among them, the satellite network intelligent defense method involves the development and implementation of security policies for satellite communication networks, aiming to protect the network from various network threats, such as hacking, data theft, or denial-of-service attacks. Due to its wide range of applications and usually high latency and error rate, satellite networks require special defense strategies, including strengthening signal encryption, implementing more stringent access control, mainly to improve the security of satellite networks, ensure the secure transmission of important data, while protecting the network from potential network attacks, and support the stable operation of key fields such as military, communication, and navigation.

[0004] Although existing network defense technologies cover a variety of security measures, in the special environment of satellite networks, high latency and error rate significantly affect their efficiency and real-time performance. Data protection and anomaly detection in existing technologies are usually not applicable to dynamic and distributed satellite network environments and are difficult to handle rapidly changing security threats. In addition, existing solutions have defects in network-wide synchronization and consistent data verification. The common security policy update mechanism responds slowly when applied in satellite networks and cannot timely reflect new security requirements, affecting the overall defense effectiveness of the network and the secure transmission of key data, and may lead to security vulnerabilities in the practical applications of key fields such as military and communication, increasing potential operational risks. Summary of the Invention

[0005] The purpose of the present invention is to solve the disadvantages existing in the prior art, and to propose a satellite network intelligent defense method and system based on blockchain distributed consensus.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions:

[0007] Satellite network intelligent defense method based on blockchain distributed consensus, comprising the following steps:

[0008] S1: Collect time series traffic data of satellite network nodes, perform modeling analysis on the data through a long short-term memory network, predict the data flow in the next time window, compare with the standard communication mode, identify abnormal traffic data, and generate an abnormal communication behavior recognition result;

[0009] S2: According to the abnormal communication behavior recognition result, analyze the connection status of each node in the satellite network with adjacent nodes, track the data packet flow direction, calculate the abnormal traffic ratio of each connection, determine potential intrusion paths, and generate a potential intrusion path recognition result;

[0010] S3: Based on the potential intrusion path recognition result, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and generate a consensus verification completion record;

[0011] S4: Based on the consensus verification completion record, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file, and generate a security policy synchronization status record;

[0012] S5: According to the security policy synchronization status record, perform a security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the satellite network defense ability meets the standard, and generate a network defense ability evaluation report.

[0013] Optionally, the abnormal communication behavior recognition result includes traffic abnormal points, time abnormal points, and pattern deviation analysis records; the potential intrusion path recognition result includes abnormal connection points, abnormal flow directions, and traffic ratios; the consensus verification completion record includes verification marking results, node accuracy records, and data consistency analysis results; the security policy synchronization status record includes configuration update records, security requirement matching results, and configuration file verification results; the network defense ability evaluation report includes security compliance analysis results, defense performance scores, and security standard achievement records.

[0014] Optionally, the specific steps of collecting time series traffic data of satellite network nodes, performing modeling analysis on the data through a long short-term memory network, predicting the data flow in the next time window, comparing with the standard communication mode, and identifying abnormal traffic data to generate an abnormal communication behavior recognition result are as follows:

[0015] S101: Collect time series traffic data of satellite network nodes, set the collection period, synchronize the data timestamps, check the time consistency of the data, and batch transfer the data to the local database to generate an original data set;

[0016] S102: Based on the original data set, conduct a preliminary check on the data, exclude transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, unify the data format, and generate a cleaned data set;

[0017] S103: Based on the cleaned data set, set data splitting parameters to divide the training and test sets, predict the data traffic of the next time window through a long short-term memory network, compare it with the standard communication mode, identify abnormal traffic points, and generate an identification result of abnormal communication behavior.

[0018] Optionally, according to the identification result of abnormal communication behavior, analyze the connection status of each node in the satellite network with adjacent nodes, trace the flow direction of data packets, calculate the abnormal traffic ratio of each connection, determine potential intrusion paths, and the specific steps for generating an identification result of potential intrusion paths are as follows:

[0019] S201: Based on the identification result of abnormal communication behavior, record the connection status between each node and adjacent nodes in the satellite network, monitor the frequency and duration of each connection, and at the same time collect data transmission records to generate a node connection status report;

[0020] S202: Based on the node connection status report, mark the flow direction of each data packet, from the source node to the target node, record the data transmission path between nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report;

[0021] S203: Based on the abnormal traffic analysis report, compare it with a preset traffic threshold, analyze the connection paths with abnormal traffic greater than the preset traffic threshold, and combine the network topology structure to identify key potential intrusion paths and generate an identification result of potential intrusion paths.

[0022] Optionally, the abnormal traffic probability is calculated according to the formula:

[0023]

[0024] is calculated, where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

[0025] Optionally, based on the identification result of potential intrusion paths, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and the specific steps for generating a consensus verification completion record are as follows:

[0026] S301: Initialize the consensus mechanism in the blockchain network based on the potential intrusion path recognition result, set the time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole network data consensus process, and generate a consensus request initiation record;

[0027] S302: Based on the consensus request initiation record, conduct intensive verification on the data packets received by each node in the network, check the authenticity and integrity of the data, perform timestamp and content verification on the data of each node, and generate a data packet verification record;

[0028] S303: Based on the data packet verification record, mark the abnormal data packets, record the verification details of the node identifier and the data packet content, confirm the accuracy of the data through synchronization among nodes, and generate a consensus verification completion record.

[0029] Optionally, based on the consensus verification completion record, the specific steps for instantaneously updating the node security policies in the satellite network, synchronizing the security configurations of each node, matching the latest security requirements, recording and verifying each modification of the configuration file, and generating a security policy synchronization status record are as follows:

[0030] S401: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record;

[0031] S402: Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and content, and generate a configuration modification monitoring record;

[0032] S403: Based on the configuration modification monitoring record, conduct security verification, confirm that the security configuration files of all nodes have been correctly updated, and complete the security policy synchronization within the network, and generate a security policy synchronization status record.

[0033] Optionally, according to the security policy synchronization status record, the specific steps for conducting a security compliance inspection on each node, evaluating the overall defense performance of the network, and confirming whether the satellite network defense capability meets the standard, and generating a network defense capability evaluation report are as follows:

[0034] S501: Based on the security policy synchronization status record, initialize the security compliance inspection program, execute a security configuration verification for each node, confirm the consistency of the configuration file with the security standard, record the compliance status of the node and the inspection time, and generate a node compliance inspection record;

[0035] S502: Analyze the defense performance of the entire satellite network based on the node compliance check records, examine the collaborative defense mechanism between nodes, evaluate the node response time and processing capabilities, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record;

[0036] S503: Based on the network defense performance analysis record, comprehensively evaluate the defense capabilities of the satellite network, check whether the defense performance of each node meets the preset security standards, summarize the evaluation results to confirm the overall defense status of the network, and generate a network defense capability evaluation report.

[0037] Optionally, the defense efficiency is calculated according to the formula:

[0038]

[0039] where R represents the efficiency value, T n represents the average value of the node response time, C p represents the average value of the node processing capabilities, D a represents the total data traffic sum between nodes, P n represents the total number of nodes in the network.

[0040] A satellite network intelligent defense system based on blockchain distributed consensus includes:

[0041] The data collection and prediction module collects the time series traffic data of satellite network nodes, sets the collection period, synchronizes the data timestamps, conducts a preliminary check on the data, unifies the data format, predicts the data traffic of the next time window, compares it with the standard communication mode and identifies abnormal traffic points, and generates an abnormal communication behavior identification result;

[0042] The abnormal path analysis module, based on the abnormal communication behavior identification result, records the connection status between each node and its adjacent nodes in the satellite network, marks the flow direction of each data packet, calculates the abnormal traffic probability in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion paths, and generates a potential intrusion path identification result;

[0043] The consensus mechanism startup module, based on the potential intrusion path identification result, initializes the consensus mechanism in the blockchain network, starts the whole network data consensus process, conducts intensive verification on the data packets received by each node in the network, marks the abnormal data packets, and generates a consensus verification completion record;

[0044] The security policy update module, based on the consensus verification completion record, starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates a configuration modification monitoring record;

[0045] The compliance check module modifies the monitoring records based on the said configuration, conducts security verification, confirms that the security configuration files of all nodes have been correctly updated, performs security configuration verification for each node, confirms the consistency of the configuration files with the security standards, and generates node compliance check records;

[0046] The defense performance evaluation module analyzes the defense performance of the entire satellite network based on the said node compliance check records, calculates the defense efficiency of the overall network, checks whether the defense performance of each node meets the preset security standards, summarizes the evaluation results to confirm the overall defense status of the network, and generates a network defense capability evaluation report.

[0047] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0048] In the present invention, by integrating long short-term memory networks, the monitoring and analysis of data streams are optimized, the future data streams can be accurately predicted and the deviations from the standard patterns can be detected in real time, effectively enhancing the accuracy and speed of anomaly detection, analyzing the connections between nodes and the data packet flows, accurately identifying potential intrusion paths, ensuring the transparency and consistency of data verification through blockchain technology, enhancing the immediate update ability of defense strategies, improving the adaptability and response speed of the entire network, so as to ensure the continuous and stable operation of the communication network. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 It is a schematic diagram of the step flow of the present invention;

[0050] Figure 2 It is a flowchart of the steps of S1 of the present invention;

[0051] Figure 3 It is a flowchart of the steps of S2 of the present invention;

[0052] Figure 4 It is a flowchart of the steps of S3 of the present invention;

[0053] Figure 5 It is a flowchart of the steps of S4 of the present invention;

[0054] Figure 6 It is a flowchart of the steps of S5 of the present invention;

[0055] Figure 7 It is a system module diagram of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0056] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0057] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation on the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.

[0058] Please refer to Figure 1 As shown, a satellite network intelligent defense method based on blockchain distributed consensus includes the following steps:

[0059] S1: Collect the time series traffic data of satellite network nodes, model and analyze the data through a long short-term memory network, predict the data stream in the next time window, compare it with the standard communication mode, identify abnormal traffic data, and generate an abnormal communication behavior recognition result;

[0060] S2: According to the abnormal communication behavior recognition result, analyze the connection status of each node in the satellite network with adjacent nodes, track the flow direction of data packets, calculate the abnormal traffic ratio of each connection, determine the potential intrusion path, and generate a potential intrusion path recognition result;

[0061] S3: Based on the potential intrusion path recognition result, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and generate a consensus verification completion record;

[0062] S4: Based on the consensus verification completion record, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file, and generate a security policy synchronization status record;

[0063] S5: According to the security policy synchronization status record, conduct a security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the satellite network defense ability meets the standard, and generate a network defense ability evaluation report.

[0064] The recognition results of abnormal communication behaviors include traffic anomaly points, time anomaly points, and pattern deviation analysis records; the recognition results of potential intrusion paths include abnormal connection points, abnormal flow directions, and traffic ratios; the completion records of consensus verification include verification marker results, node accuracy records, and data consistency analysis results; the records of security policy synchronization status include configuration update records, security requirement matching results, and configuration file verification results; the network defense capability assessment report includes security compliance analysis results, defense performance scores, and security standard achievement records.

[0065] Please refer to Figure 2 as shown, the specific steps of S1 are as follows:

[0066] S101: Collect time series traffic data of satellite network nodes, set the collection period, synchronize the data timestamps, check the time consistency of the data, batch transfer the data to the local database, and generate the original data set;

[0067] Collect time series traffic data of satellite network nodes, set a unified collection period, initialize the data collection device according to the protocol standard, including setting the frequency range of the received signal and the data collection format, call the satellite node data interface to obtain high-precision timestamp information, perform time calibration for the timestamp differences collected by multiple nodes, use the time synchronization protocol to unify the time of different nodes to the standard reference time, verify the consistency of the synchronization result to ensure that the error between the data timestamp and the collection period is less than the preset threshold, use the data packaging strategy to transmit the collected time series traffic data to the local database through the encrypted communication channel in the batch transmission mode, perform segmented writing operations on the data based on the storage structure design of the database, and attach a check code at the same time to ensure the integrity of data transmission, and generate the original data set that can support subsequent analysis.

[0068] S102: Based on the original data set, conduct a preliminary check on the data, exclude transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, unify the data format, and generate the cleaned data set;

[0069] Based on the original dataset, a preliminary check is performed on the collected time - series traffic data. First, the integrity of data points is reviewed through a missing - value marking method, and records with missing points are screened out and marked. Subsequently, a data - cleaning algorithm is called to interpolate or remove the missing points. Statistical methods are used to detect and remove outliers in the traffic data that are outside the normal range, including invalid data with too low or too high traffic. Duplicate records are identified and removed through a hash - matching and duplicate - detection mechanism. A data - type conversion module is used to standardize fields that do not conform to the standard type. For example, floating - point fields are uniformly converted to integer or fixed - point types. All fields are range - standardized according to predefined numerical ranges. The storage format and structure of the data are re - defined by calling field - mapping rules. Finally, a dataset with a unified format and complete cleaning is generated, providing consistent data input for subsequent processing.

[0070] S103: Based on the cleaned dataset, set data - splitting parameters to divide the training and test sets. Predict the data traffic of the next time window through a long short - term memory network, compare it with the standard communication mode, identify abnormal traffic points, and generate an abnormal communication behavior recognition result.

[0071] Based on the cleaned dataset, set the splitting parameters for data division, including the division ratio of the training set and the test set, and use a stratified sampling method to ensure the consistency of the distribution characteristics of the divided dataset. By importing the cleaned dataset into the deep - learning model framework, call the long short - term memory network to predict the traffic of the next time window. The model first extracts features from the time - series data through multiple layers of networks, and then calculates the predicted value based on the feature vectors. The predicted traffic values are compared point - by - point with the traffic values in the standard communication mode. Abnormal traffic points are identified according to the statistical threshold of the traffic difference. All identified abnormal points are marked and output, and at the same time, an abnormal communication behavior recognition result is generated, providing a direct basis and reference for subsequent further security analysis and optimization.

[0072] Please refer to Figure 3 as shown, the specific steps of S2 are as follows:

[0073] S201: Based on the abnormal communication behavior recognition result, record the connection status between each node and its adjacent nodes in the satellite network, monitor the frequency and duration of each connection, and at the same time collect data - transmission records to generate a node - connection status report.

[0074] Based on the recognition results of abnormal communication behaviors, record the connection status of each node in the satellite network with its adjacent nodes. Real-time obtain the connection status data by calling the node status query interface, including the connection establishment time, disconnection time, and the number of transmitted data packets. Statistically analyze the communication frequency of each connection, record the transmission time interval of the data packets, and at the same time analyze the duration distribution of the connections. Generate a transmission record table for all data connections, construct a node connection status data set based on parameters such as connection stability, frequency, and transmission volume, organize the comprehensive status information of each connection into a report form for output, and generate a detailed node connection status report to reflect the communication activities among nodes in the satellite network.

[0075] S202: Based on the node connection status report, mark the flow direction of each data packet, from the source node to the target node, record the data transmission path between nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report;

[0076] The abnormal traffic probability is calculated according to the formula:

[0077]

[0078] Perform the calculation, where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

[0079] P(A) is the prior probability of event A occurring, that is, the probability of event A occurring without any other information. For example, the probability that a network data packet is abnormal traffic. According to historical data analysis, the probability is 0.05.

[0080] P(B|A) is the conditional probability of event B occurring given that event A has occurred. For example, if a network data packet is abnormal traffic, the probability of being detected as abnormal. Based on the records of the network monitoring system, the probability is 0.9.

[0081] P(B) is the marginal probability of event B, that is, the probability of event B occurring regardless of whether event A occurs or not. For example, the probability that any network data packet is detected as abnormal. From the statistical data of the monitoring system, the probability is 0.1.

[0082] Given the above parameters, calculate P(A|B):

[0083]

[0084] The results show that, given that event B has occurred, the probability of event A occurring is higher than its prior probability (1.7889 is greater than 1), which means that if a network packet is detected as abnormal, the likelihood that it is actually abnormal traffic increases significantly, helping network security personnel to more accurately identify and handle network threats.

[0085] S203: Based on the abnormal traffic analysis report, compare it with the preset traffic threshold, analyze the connection paths where the abnormal traffic is greater than the preset traffic threshold, combine with the network topology structure to identify key potential intrusion paths, and generate the identification results of potential intrusion paths;

[0086] Based on the abnormal traffic analysis report, compare the abnormal traffic values in the paths with the preset traffic threshold one by one, screen the paths where the abnormal traffic is greater than the preset threshold, use the network topology parsing tool to perform topology mapping on the screened paths, analyze the node interaction characteristics and the flow direction of data packets in the paths, and combine with the node importance indicators in the network topology diagram, such as the degree centrality and betweenness centrality of nodes, to identify the key connection nodes with high abnormal traffic. By comprehensively considering the degree of path traffic abnormality and the potential impact of nodes in the network topology, generate a result list containing paths with potential intrusion risks for subsequent processing of network security events.

[0087] Please refer to Figure 4 as shown, the specific steps of S3 are:

[0088] S301: Based on the identification results of potential intrusion paths, initialize the consensus mechanism in the blockchain network, set the time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole-network data consensus process, and generate a record of the initiation of the consensus request;

[0089] Based on the identification results of potential intrusion paths, initialize the consensus mechanism in the blockchain network, set the initial parameters including the type of consensus algorithm, the number of verification nodes, and the time synchronization range, calibrate the time of all participating nodes through the distributed time synchronization protocol to ensure the timeliness of the consensus request, call the network protocol configuration module to update the network communication protocol to ensure that all nodes can receive and respond to the consensus request, detect the network status and availability of each node to exclude faulty nodes, distribute the consensus request data packet to all nodes in the network through the broadcast mechanism, start the distributed consensus calculation process and record the initiation time of the request and the list of broadcast nodes, and generate a complete record of the initiation of the consensus request.

[0090] S302: Based on the record of the initiation of the consensus request, conduct intensive verification on the data packets received by each node in the network, verify the authenticity and integrity of the data, check the timestamp and content of the data of each node, and generate a record of the verification of the data packets;

[0091] Based on the consensus request initiation record, perform intensive verification operations on the consensus request data packets received by all nodes in the network. Verify the authenticity of the data by comparing the content of the data packet with the signature information of the sending node. Invoke the integrity identifier check for each data packet, and calibrate the sending and receiving times of the data packet through the timestamp synchronization mechanism to verify the time consistency. Perform field-level content matching on the data packets received by each node, analyze the deviation from the expected values in the consensus algorithm, record the verification status of each node's data and generate a verification report, and generate a data packet verification record after collating the comprehensive results such as data authenticity, integrity, and timestamp calibration.

[0092] S303: Based on the data packet verification record, mark the abnormal data packets, record the verification details of the node identifier and the data packet content, confirm the accuracy of the data through synchronization between nodes, and generate a consensus verification completion record;

[0093] Based on the data packet verification record, identify and mark all abnormal data packets, determine the source of the abnormality by analyzing the verification details of the node identifier and content recorded in the data packet, invoke the node synchronization confirmation module to compare the verification status of the abnormal data packets on other nodes in the network, filter out the data packets outside the error range and record the detailed information of all nodes with verification abnormalities, re-verify the abnormal data packets based on the node-to-node synchronization confirmation process to ensure the accuracy of the verification results, classify and count the passed and failed verification results and record them, and finally output a consensus verification completion record, completely save the verification status and abnormal marking information of all nodes, and provide a reference basis for the subsequent consensus processing process.

[0094] Please refer to Figure 5 as shown, the specific steps of S4 are as follows:

[0095] S401: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record;

[0096] Based on the consensus verification completion record, start the security policy update program. First, load the updated security protocol for all nodes in the network, extract the key parameter settings in the protocol, and perform a comparison and analysis on the security configuration files of each node to identify the configuration parameter items that need to be adjusted. Gradually update the security configuration parameters of the nodes to ensure that the configuration content is consistent with the security protocol. By performing real-time synchronization of the security configurations between nodes, check the latency and consistency issues during the synchronization process to ensure that the security configuration file status of all nodes is consistent. Finally, generate a security configuration update report containing the detailed records of the security configuration updates of all nodes.

[0097] S402: Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and content, and generate a configuration modification monitoring record;

[0098] Based on the security configuration update record, track and record the response of each node to the updated security policy, monitor the execution status of the node's security configuration modification instructions in real time, itemize and record the modification content and operation time of the configuration file, and at the same time associate the execution log of the node to verify the correctness of the modification. Sort out the errors or exceptions that occur during the update process of each node, including problems such as modification failure and synchronization delay, record the field adjustments and newly added entries in the configuration file to ensure that all details are traceable, summarize the modification process and content of all nodes to generate a configuration modification monitoring record, and provide a detailed execution status basis for subsequent security policy verification.

[0099] S403: Based on the configuration modification monitoring record, conduct security verification to confirm that the security configuration files of all nodes have been correctly updated and the security policy synchronization within the network has been completed, and generate a security policy synchronization status record;

[0100] Based on the configuration modification monitoring record, conduct itemized verification of the security configuration files of all nodes, confirm the accuracy of the update by comparing the latest security policy standard and the actual configuration status of the nodes, detect the security protocol adaptability of the nodes, confirm the synchronization status among the nodes and the consistency of the overall network, identify the nodes with incomplete updates or incorrect parameter configurations and output warning records, classify and sort out the verification results to ensure that the security configurations of all nodes are consistent with the updated security policy, and generate a complete security policy synchronization status record to provide real-time feedback support for the overall security status of the network.

[0101] Please refer to Figure 6 as shown, the specific steps of S5 are as follows:

[0102] S501: Based on the security policy synchronization status record, initialize the security compliance inspection program, perform security configuration verification for each node, confirm the consistency between the configuration file and the security standard, record the compliance status and inspection time of the node, and generate a node compliance inspection record;

[0103] Based on the security policy synchronization status record, start the security compliance inspection program, check each item of the security configuration file for each node one by one, verify the integrity and consistency of the parameter settings by calling the compliance check to compare the security configuration content of the node with the preset security standards, and at the same time record the details during the verification process, including the verification status of each configuration and the matching result of the parameter values, detect whether there are omissions or abnormalities in the configuration file of the node, judge the overall compliance status of the node according to the predefined compliance standards, accurately record the time of each verification, sort out the compliance verification results of all nodes, and generate a node compliance inspection record to comprehensively reflect the security configuration status of the current network nodes.

[0104] S502: Based on the node compliance inspection record, analyze the defense performance of the entire satellite network, check the collaborative defense mechanism between nodes, evaluate the node response time and processing ability, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record;

[0105] The defense efficiency is calculated according to the formula:

[0106]

[0107] is calculated, where R represents the efficiency value, T n represents the average value of the node response time, which represents the average time required for each node to respond to a threat from detecting the threat, C p represents the average value of the node processing ability, which represents the ability of each node to process data, D a represents the total data traffic between nodes, which represents the total amount of data exchanged between all nodes, P n represents the total number of nodes in the network, which represents the number of nodes participating in the network defense mechanism.

[0108] T n represents the average value of the node response time, and the time data of the node's response to threats can be obtained from the real-time monitoring system. During a certain period, the data of the response time of a group of nodes is {200ms, 250ms, 180ms, 220ms}, then T n is the average value of the time:

[0109]

[0110] C p represents the average value of the node processing ability, and this parameter reflects the ability of the node to process data, usually obtained from the performance test of the node. For example, if the test results of the processing ability of a group of nodes are {1000, 1200, 1100, 900} with the unit of operations / second, then C p is:

[0111]

[0112] D a represents the total data traffic sum between nodes, which is the total amount of data measured by a network monitoring tool. For example, if the monitored data traffic is 5TB within a certain period of time, then D a = 5000GB.

[0113] P n represents the total number of nodes in the network, which is directly obtained from the network configuration management database. For example, if there are 50 nodes in the network, then P n = 50.

[0114] Substitute the above parameters into the formula, and the calculation process is as follows:

[0115]

[0116] The result shows that the defense efficiency is 1.363. The efficiency value reflects the network's response and processing capabilities to threats under the current configuration and performance conditions. The higher the defense efficiency value, the stronger the overall defense performance of the network. It can evaluate the impact of different network configurations on the defense performance, and then optimize the network structure and resource allocation.

[0117] S503: Based on the network defense performance analysis record, comprehensively evaluate the defense capabilities of the satellite network, check whether the defense performance of each node meets the preset security standards, summarize the evaluation results to confirm the overall defense status of the network, and generate a network defense capabilities evaluation report;

[0118] Based on the network defense performance analysis record, comprehensively analyze the defense capabilities of the satellite network. By checking the defense performance of each node one by one, compare the defense efficiency, collaboration capabilities, and response time of the nodes with the preset security standards, count the pass rates and non-compliance items of all nodes, and at the same time evaluate the weak links of the overall defense capabilities based on the network topology structure, mark the key nodes affecting the overall network security, combine the defense performance of each node, summarize the evaluation results, and confirm whether the overall defense status of the network meets the predetermined requirements, generate a network defense capabilities evaluation report containing detailed analysis and evaluation conclusions, and provide support for the continuous improvement of network security strategies.

[0119] Please refer to Figure 7 as shown, the satellite network intelligent defense system based on blockchain distributed consensus includes:

[0120] The data collection and prediction module collects the time series traffic data of satellite network nodes, sets the collection period, synchronizes the data timestamps, conducts a preliminary check on the data, unifies the data format, predicts the data traffic of the next time window, compares it with the standard communication mode, and identifies abnormal traffic points, generating an identification result of abnormal communication behaviors;

[0121] Based on the recognition result of abnormal communication behavior, the abnormal path analysis module records the connection status between each node and its adjacent nodes in the satellite network, marks the flow direction of each data packet, calculates the probability of abnormal traffic in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion paths, and generates the recognition result of potential intrusion paths;

[0122] Based on the recognition result of potential intrusion paths, the consensus mechanism startup module initializes the consensus mechanism in the blockchain network, starts the whole-network data consensus process, intensively verifies the data packets received by each node in the network, marks the abnormal data packets, and generates the record of completed consensus verification;

[0123] Based on the record of completed consensus verification, the security policy update module starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates the configuration modification monitoring record;

[0124] Based on the configuration modification monitoring record, the compliance check module conducts security verification, confirms that the security configuration files of all nodes have been correctly updated, performs security configuration verification for each node, confirms the consistency of the configuration files with the security standards, and generates the node compliance check record;

[0125] Based on the node compliance check record, the defense performance evaluation module analyzes the defense performance of the entire satellite network, calculates the defense efficiency of the overall network, checks whether the defense performance of each node meets the preset security standards, summarizes the evaluation results to confirm the overall defense status of the network, and generates the network defense capability evaluation report.

[0126] The above is only the preferred embodiment of the present invention, and it is not intended to limit the present invention in other forms. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. A satellite network intelligent defense method based on blockchain distributed consensus, characterized in that, It includes the following steps: Collect the time series traffic data of satellite network nodes, model and analyze the data through a long short-term memory network, predict the data stream in the next time window, compare with the standard communication mode, identify abnormal traffic data, and generate the identification result of abnormal communication behavior; According to the identification result of abnormal communication behavior, analyze the connection status of each node in the satellite network with adjacent nodes, trace the data packet flow direction, calculate the abnormal traffic ratio of each connection, determine the potential intrusion path, and generate the identification result of potential intrusion path; Based on the identification result of potential intrusion path, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it, and generate a consensus verification completion record; Based on the consensus verification completion record, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file, and generate a security policy synchronization status record; According to the security policy synchronization status record, conduct a security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the defense ability of the satellite network meets the standard, and generate a network defense ability evaluation report.

2. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, wherein The identification result of abnormal communication behavior includes traffic abnormal points, time abnormal points, and pattern deviation analysis records; the identification result of potential intrusion path includes abnormal connection points, abnormal flow directions, and traffic ratios; the consensus verification completion record includes verification marking results, node accuracy records, and data consistency analysis results; the security policy synchronization status record includes configuration update records, security requirement matching results, and configuration file verification results; the network defense ability evaluation report includes security compliance analysis results, defense performance scores, and security standard achievement records.

3. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, characterized in that The specific steps for collecting the time series traffic data of satellite network nodes, modeling and analyzing the data through a long short-term memory network, predicting the data stream in the next time window, comparing with the standard communication mode, identifying abnormal traffic data, and generating the identification result of abnormal communication behavior are as follows: Collect the time series traffic data of satellite network nodes, set the collection period, synchronize the data timestamps, check the time consistency of the data, and batch transfer the data to the local database to generate the original data set; Based on the original data set, conduct a preliminary check on the data, exclude transmission errors and missing data points, delete outliers and duplicate records, perform data type conversion and range standardization, and unify the data format to generate the cleaned data set; Based on the cleaned data set, set data splitting parameters to divide the training and test sets, predict the data traffic in the next time window through a long short-term memory network, compare with the standard communication mode, identify abnormal traffic points, and generate the identification result of abnormal communication behavior.

4. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, wherein, The specific steps for analyzing the connection status of each node in the satellite network with adjacent nodes, tracing the data packet flow direction, calculating the abnormal traffic ratio of each connection, determining the potential intrusion path, and generating the identification result of potential intrusion path according to the identification result of abnormal communication behavior are as follows: Based on the recognition result of the abnormal communication behavior, record the connection status between each node and its adjacent nodes in the satellite network, monitor the frequency and duration of each connection, and simultaneously collect data transmission records to generate a node connection status report; Based on the node connection status report, mark the flow direction of each data packet, from the source node to the target node, record the data transmission path between nodes, quantify the data flow in the path, calculate the abnormal traffic probability in each connection path, and generate an abnormal traffic analysis report; Based on the abnormal traffic analysis report, compare it with the preset traffic threshold, analyze the connection paths where the abnormal traffic is greater than the preset traffic threshold, and combine the network topology structure to identify the key potential intrusion paths, generating a potential intrusion path recognition result.

5. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 4, characterized in that The abnormal traffic probability is calculated according to the formula: where P(A|B) represents the probability of event A occurring given that event B has occurred, P(B|A) represents the probability of event B occurring given that event A has occurred, P(A) represents the prior probability of event A occurring, and P(B) represents the marginal probability of event B occurring.

6. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, characterized in that, Based on the potential intrusion path recognition result, initiate a consensus request in the blockchain network, verify the abnormal data packets received by all nodes, verify the accuracy of each node's data and mark it. The specific steps to generate a consensus verification completion record are as follows: Based on the potential intrusion path recognition result, initialize the consensus mechanism in the blockchain network, set the time synchronization and the number of verification nodes, adjust the network protocol and confirm that all nodes can receive the consensus request, start the whole network data consensus process, and generate a consensus request initiation record; Based on the consensus request initiation record, conduct intensive verification on the data packets received by each node in the network, check the authenticity and integrity of the data, perform timestamp and content verification on the data of each node, and generate a data packet verification record; Based on the data packet verification record, mark the abnormal data packets, record the verification details of the node identifier and the data packet content, and confirm the accuracy of the data through synchronization between nodes to generate a consensus verification completion record.

7. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, characterized in that, Based on the consensus verification completion record, immediately update the node security policies in the satellite network, synchronize the security configurations of each node, match the latest security requirements, record and verify each modification of the configuration file. The specific steps to generate a security policy synchronization status record are as follows: Based on the consensus verification completion record, start the security policy update program, adjust the security configuration parameters of each node to match the updated security protocol, synchronize the security settings of all nodes, and generate a security configuration update record; Based on the security configuration update record, record the response and execution status of each node to the security policy, track and record the modification details of each configuration file, record the modification time and content, and generate a configuration modification monitoring record; Based on the configuration modification monitoring record, conduct security verification, confirm that the security configuration files of all nodes have been correctly updated, and complete the security policy synchronization within the network to generate a security policy synchronization status record.

8. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 1, characterized in that According to the security policy synchronization status record, perform security compliance inspection on each node, evaluate the overall defense performance of the network, confirm whether the satellite network defense capability meets the standard, and the specific steps for generating the network defense capability evaluation report are as follows: Based on the security policy synchronization status record, initialize the security compliance inspection program, perform security configuration verification for each node, confirm the consistency between the configuration file and the security standard, record the compliance status and inspection time of the node, and generate a node compliance inspection record; Based on the node compliance inspection record, analyze the defense performance of the entire satellite network, check the collaborative defense mechanism between nodes, evaluate the node response time and processing ability, calculate the defense efficiency of the overall network, and generate a network defense performance analysis record; Based on the network defense performance analysis record, comprehensively evaluate the defense capability of the satellite network, check whether the defense performance of each node meets the preset security standard, summarize the evaluation results to confirm the overall defense status of the network, and generate a network defense capability evaluation report.

9. The satellite network intelligent defense method based on blockchain distributed consensus according to claim 8, characterized in that, The defense efficiency is calculated according to the formula: Perform calculations, where R represents the efficiency value, T n represents the average value of the node response time, C p represents the average value of the node processing capacity, D a represents the total data traffic between nodes, P n represents the total number of nodes in the network.

10. A satellite network intelligent defense system based on blockchain distributed consensus, characterized in that, For the satellite network intelligent defense method based on blockchain distributed consensus according to any one of claims 1-9, the system includes: The data collection and prediction module collects the time series traffic data of the satellite network nodes, sets the collection period, synchronizes the data timestamp, performs a preliminary check on the data, unifies the data format, predicts the data traffic of the next time window, compares it with the standard communication mode and identifies abnormal traffic points, and generates an abnormal communication behavior identification result; Based on the abnormal communication behavior identification result, the abnormal path analysis module records the connection status between each node and its adjacent nodes in the satellite network, marks the flow direction of each data packet, calculates the abnormal traffic probability in each connection path, compares it with the preset traffic threshold, identifies the key potential intrusion paths, and generates a potential intrusion path identification result; Based on the potential intrusion path identification result, the consensus mechanism startup module initializes the consensus mechanism in the blockchain network, starts the whole network data consensus process, densely verifies the data packets received by each node in the network, marks the abnormal data packets, and generates a consensus verification completion record; Based on the consensus verification completion record, the security policy update module starts the security policy update program, synchronizes the security settings of all nodes, records the response and execution status of each node to the security policy, tracks and records the modification details of each configuration file, and generates a configuration modification monitoring record; Based on the configuration modification monitoring record, the compliance inspection module performs security verification, confirms that the security configuration files of all nodes have been correctly updated, performs security configuration verification for each node, confirms the consistency between the configuration file and the security standard, and generates a node compliance inspection record; Based on the node compliance inspection record, the defense performance evaluation module analyzes the defense performance of the entire satellite network, calculates the defense efficiency of the overall network, checks whether the defense performance of each node meets the preset security standard, summarizes the evaluation results to confirm the overall defense status of the network, and generates a network defense capability evaluation report.

Citation Information

Patent Citations

  • Network intrusion detection method and system

    CN118138368A

  • Dynamic defense system and method of new energy centralized control station network based on dynamic IP

    US20240414183A1