Novel network information security method and system

By injecting dynamic mutation engines into the bottom layer of the network protocol stack and generating spatiotemporal dynamic device identity identification, combined with chaotic encryption and bait data injection technology, the problem of existing technologies being difficult to deal with advanced threats is solved, and the long-term effectiveness of network security and a continuous evolutionary defense mechanism is achieved.

CN120050092AActive Publication Date: 2025-05-27QINGDAO VIDEOCOM INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510196739.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-27
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

Existing network security protection technologies are difficult to effectively deal with advanced threats such as protocol sniffing, identity forgery and dynamic vulnerability exploitation. Especially when facing zero-day attacks and automatic AI mutation attacks, defense methods are difficult to adapt to new attack modes, resulting in offense and defense asymmetry.

Method used

The dynamic mutation engine is injected into the bottom layer of the network protocol stack, and random mutation factors are generated through quantum noise sources, dynamic distortion of the protocol field length, check bit distribution and handshake timing characteristics to generate the mutation protocol fingerprint. At the same time, based on the variation protocol fingerprint, physical layer hardware noise characteristics and virtualization layer resource call mode, a device identity identifier with spatiotemporal and spatial dynamics is generated, and a transmission channel based on chaotic encryption or bait data injection is dynamically selected. Embed an adaptive bait generator in the camouflage transmission channel to generate false vulnerability features and build a data interaction sequence of logical traps. Through the behavioral analysis probe, the attacker's behavioral characteristics are captured and the attack fingerprint is extracted. The adversarial defense strategy generator is input to synchronously update the distortion parameters of the dynamic mutation engine.

Benefits of technology

Through dynamic mutation engines and space-time dynamic identity authentication, the robustness of protocol layer protection is enhanced to avoid attackers using fixed modes. Dynamically select transmission channels and generate false vulnerability features, improve the confidentiality and integrity of data transmission, enhance the security of device identity authentication, realize a continuously evolving defense mechanism, and improve the long-term effectiveness of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050092A_ABST
    Figure CN120050092A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network information security, in particular to a novel network information security method and system, and the method comprises the following steps: injecting a dynamic variation engine into the bottom layer of a network protocol stack, and generating a variation protocol fingerprint; generating an equipment identity label with space-time dynamic property; selecting a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on bait data injection, wherein the protocol encapsulation channel encrypts or obfuscates an original protocol; a self-adaptive bait generator is embedded in the camouflage transmission channel; extracting attack fingerprints; and inputting the attack fingerprint into the antagonistic defense strategy generator, and synchronously updating the distortion parameter of the dynamic variation engine. According to the invention, the distortion parameter of the dynamic variation engine and the adaptive adjustment mechanism based on the attack fingerprint ensure that the defense strategy always dynamically confronts the attack behavior, and the robustness of the protocol layer protection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network information security, and in particular to a novel network information security method and system. Background Art

[0002] With the continuous evolution of network attack methods, traditional network security protection technology faces severe challenges. The existing security mechanism mainly relies on static encryption, rule-based access control, feature matching intrusion detection and other methods, but there are still many shortcomings in dealing with advanced threats such as protocol sniffing, identity forgery, and dynamic vulnerability exploitation. First, the structure of the existing communication protocol is relatively fixed. Attackers can extract protocol features through traffic analysis and pattern matching technology to implement protocol deception, replay attacks or traffic injection attacks. In addition, device identity authentication mostly relies on static identifiers such as MAC addresses, IP addresses or public key certificates, which are easy to be forged or tampered with. Especially in virtualization and cloud computing environments, attackers can steal identity information through virtual machine escape, side channel attacks and other means to bypass security detection mechanisms.

[0003] More importantly, existing defense strategies are usually based on predefined rules or known attack feature libraries, and are difficult to adapt to new attack patterns, especially zero-day attacks and attacks based on AI automatic mutation. As a result, attackers can constantly adjust their strategies and circumvent existing defense measures, creating an asymmetric offense and defense situation. Summary of the invention

[0004] The invention provides a novel network information security method and system.

[0005] A novel network information security method comprises the following steps:

[0006] S1. Inject a dynamic mutation engine into the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, generate random mutation factors through quantum noise sources, dynamically distort the protocol field length, check bit distribution and handshake timing characteristics, and generate mutation protocol fingerprints;

[0007] S2. Based on the variant protocol fingerprint, the physical layer hardware noise characteristics and the virtualization layer resource call mode are integrated to form a three-dimensional feature vector, and a device identity with spatiotemporal dynamics is generated based on the three-dimensional feature vector;

[0008] S3. Deploy a heterogeneous protocol mapper in the protocol conversion gateway, and dynamically select a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on bait data injection according to the confidence level of the device identity, wherein the protocol encapsulation channel encrypts or obfuscates the original protocol;

[0009] S4, embedding an adaptive decoy generator in the disguised transmission channel, generating a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructing a data interaction sequence with logic traps;

[0010] S5. Capturing the triggering behavior characteristics of the attacker on the logic trap by deploying a behavior analysis probe between the physical network card and the virtual switching layer, and extracting attack fingerprints including memory modification mode and instruction execution path offset;

[0011] S6. Input the attack fingerprint into the adversarial defense strategy generator, and synchronously update the distortion parameters of the dynamic mutation engine.

[0012] Optionally, the S1 specifically includes:

[0013] S11, between the data link layer and the network layer of the network protocol stack, by real-time analysis and modification of the transmitted data packets, the characteristic fingerprint F of the communication protocol is collected, including the protocol field length, check bit distribution and handshake timing characteristics;

[0014] S12, generating a random mutation factor through a quantum noise source, where the random mutation factor includes a random number and a noise signal, and is used to perform a distortion operation on a communication protocol field;

[0015] S13, the distortion operation includes dynamically adjusting the protocol field length, check bit distribution and handshake timing characteristics, disrupting the original fixed pattern in the protocol, and generating a variant protocol fingerprint F' with a variant property, and the variant protocol fingerprint is used to describe the data packet characteristics of the modified protocol.

[0016] Optionally, the S2 specifically includes:

[0017] S21, obtain the variant protocol fingerprint F′;

[0018] S22, obtaining hardware noise features H through a physical layer feature acquisition module, including electromagnetic interference and thermal noise generated by the device during operation. These noise features reflect the working status and characteristics of the hardware;

[0019] S23, obtaining a resource call pattern R through monitoring of the virtualization layer, including CPU load and network bandwidth consumption, which indicates resource allocation and usage characteristics of the device in the virtual environment;

[0020] S24, based on the variant protocol fingerprint F′, the hardware noise feature H and the virtualization layer resource call pattern R, the three feature vectors are sequentially concatenated into a long vector and fused into a three-dimensional feature vector V: V = [F′, H, R];

[0021] S25, based on the three-dimensional feature vector V, generates a device identity ID(t) with spatiotemporal dynamics through a spatiotemporal dynamic model. The identity ID(t) takes into account the spatiotemporal change characteristics of the device, and is dynamically adjusted with the changes in time and space, indicating the unique identity of the device under different time and space conditions.

[0022] Optionally, the identity ID is generated based on the three-dimensional feature vector V and the spatiotemporal dynamic model, and is expressed as:

[0023] ID(t)=f(V(t),t), where t represents time, V(t) is the three-dimensional feature vector of the device at time t, and f(·) is the spatiotemporal dynamic model, including timing analysis. f(V(t),t) is specifically expressed as:

[0024] Among them, e represents the number of feature dimensions in F′, k represents the number of feature dimensions in H, m represents the number of feature dimensions in R, and v p (t) represents the value of the pth feature in the three-dimensional feature vector V(t) at time t, w p is the weight of the feature, β(t) is a dynamic time bias term used to adjust the influence of spatiotemporal factors. As time t passes, the three-dimensional feature vector V(t) of the device will change, resulting in dynamic changes in the device identity ID(t).

[0025] Optionally, the S3 specifically includes:

[0026] S31, the heterogeneous protocol mapper obtains the device identity ID and its confidence level α in real time by interacting with the device's protocol stack, where α∈[0,1] represents the credibility of the device identity;

[0027] S32, the heterogeneous protocol mapper selects a protocol transmission channel according to the confidence level α of the device identity:

[0028] When the confidence level α is higher than the predetermined threshold α thresh When the value is 0.8, a protocol encapsulation channel based on chaotic encryption is selected, and the protocol is encrypted or obfuscated by the chaotic encryption algorithm to ensure that the data is difficult to be identified, intercepted or tampered by attackers during transmission;

[0029] When the confidence level α is higher than the predetermined threshold α thresh When (0.8), a disguised transmission channel based on bait data injection is selected, and false data is injected during the transmission process to confuse potential attackers through disguise means and hide the real communication content.

[0030] Optionally, the S4 specifically includes:

[0031] S41, adaptive decoy generator initialization: deploy an adaptive decoy generator in the disguised transmission channel, analyze and map the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extract the potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact range;

[0032] S42, generating false vulnerability features: the adaptive bait generator generates false vulnerability features according to the vulnerability feature library of the target device and the current network environment. The false vulnerability features simulate actual vulnerabilities but do not exist in the actual system, thereby misleading attackers and preventing them from launching attacks by exploiting real vulnerabilities.

[0033] S43, constructing a protocol payload: embedding the generated false vulnerability features into the protocol payload, disguising them as normal vulnerability features, and transmitting the protocol payload to the target device through the network, and appearing as a set of seemingly effective disguised vulnerability features in the protocol stack of the target device;

[0034] S44, constructing a data interaction sequence of a logic trap: According to the vulnerability type, attack path, and vulnerability impact range of the target device, a data interaction sequence with a logic trap is designed to induce the attacker to mistakenly trigger a false vulnerability. The data interaction sequence sends a bait path with false vulnerability characteristics through a disguised protocol payload to the attacker, thereby inducing him to enter the logic trap.

[0035] Optionally, the S5 specifically includes:

[0036] S51, deployment of behavioral analysis probes: Deploy behavioral analysis probes between the physical network card and the virtual switching layer to monitor all data packets and data interaction sequences transmitted through the network in real time. This probe is located between the data link layer and the network layer and can perform in-depth analysis of the content, protocol characteristics, and interaction patterns of data packets.

[0037] S52, capturing the attacker's behavioral characteristics: Through the behavioral analysis probe, the attacker's behavior after receiving the protocol payload containing false vulnerability characteristics is captured. The probe can identify the abnormal behavior characteristics when the attacker attempts to trigger the vulnerability. The abnormal behavior characteristics include memory modification mode and instruction execution path offset:

[0038] S53, extract attack fingerprint: The behavior analysis probe extracts the attacker's behavior fingerprint based on the captured memory modification pattern and instruction execution path offset. The behavior fingerprint includes the vulnerability exploitation skills, attack path, and attack payload used by the attacker. The attack fingerprint is expressed as:

[0039] F attack ={f 1 ,f 2 ,...,f s}, where fs The sth attack behavior feature includes memory modification mode, instruction execution path offset, and malicious payload;

[0040] S54, the relationship between logic traps and bait paths: The attacker behavior captured by the behavior analysis probe is directly derived from the design of the bait path. When attackers try to trigger false vulnerabilities through logic traps, their behavior will be exposed. The false vulnerabilities are transmitted through the protocol payload P fake and the bait path T trap is delivered to the target device, ultimately tricking the attacker into the wrong attack path;

[0041] S55, Update of behavioral fingerprint and dynamic defense strategy: Through the extracted attack fingerprint F attack , update defense strategies in real time.

[0042] Optionally, the memory modification mode includes: when an attacker attempts to exploit a vulnerability, the attacker may modify the memory content of the target device, including changing the buffer, data structure or stack content, and the probe captures the behavior pattern of the memory modification by monitoring the memory operation;

[0043] The instruction execution path offset includes: an attacker may change the normal execution path of the program through a vulnerability and try to jump to the address of the malicious code. The behavioral analysis probe captures the offset of the instruction execution path, that is, the abnormal jump of the instruction pointer during the execution process, and identifies whether the attacker attempts to trigger a buffer overflow or a code injection attack.

[0044] Optionally, the S6 specifically includes:

[0045] S61, input attack fingerprint: the attack fingerprint F attack ={f 1 ,f 2 ,...,f s} Input to adversarial defense strategy generator;

[0046] S62, adversarial defense strategy generation: Calculate the attack strength γ, which is used as the threat level of the attack behavior. If γ exceeds the set threshold γ thresh (γ is normalized within the range [0,1], γ thresh Value 0.5-0.7) triggers dynamic defense update: Among them, w i is the weight of the attack fingerprint feature, measuring its contribution to the security threat;

[0047] Dynamic defense updates include:

[0048] S63, synchronously update the distortion parameters of the dynamic mutation engine: adjust the distortion strategy of the dynamic mutation engine according to the latest attack fingerprint:

[0049] Update the dynamic adjustment rules of the protocol field, including the field length variation range ΔL′ and the check bit distortion factor ΔC′:

[0050] ΔL′=ΔL+δ L ;

[0051] ΔC′=ΔC+δ C ;

[0052] where δ L and δ C Calculated by the adversarial defense strategy, it enhances the randomness of the protocol structure, making it difficult for attackers to establish fixed-pattern attack methods.

[0053] A novel network information security system, used to implement the above novel network information security method, includes the following modules:

[0054] The dynamic mutation engine is deployed at the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutation protocol fingerprints;

[0055] The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the variant protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and generate a device identity with spatiotemporal dynamics based on the three-dimensional feature vector;

[0056] The protocol conversion gateway, including a heterogeneous protocol mapper, dynamically selects a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection according to the confidence level of the device identity;

[0057] The adaptive decoy generator is embedded in the disguised transmission channel, generates a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructs a data interaction sequence with logic traps;

[0058] Behavioral analysis probes, deployed between the physical network card and the virtual switching layer, are used to capture the attacker's triggering behavior characteristics for logical traps and extract attack fingerprints, including memory modification patterns and instruction execution path offsets;

[0059] The adversarial defense strategy generator is used to receive attack fingerprints and synchronously update the distortion parameters of the dynamic mutation engine.

[0060] Beneficial effects of the present invention:

[0061] The present invention injects a dynamic mutation engine into the bottom layer of the network protocol stack, and dynamically distorts the protocol field length, check bit distribution and handshake timing characteristics based on the random mutation factor generated by the quantum noise source, so that the protocol structure changes continuously, and prevents attackers from using fixed patterns to perform protocol sniffing, traffic analysis or attack using specific vulnerabilities. The distortion parameters of the dynamic mutation engine and the adaptive adjustment mechanism based on the attack fingerprint ensure that the defense strategy always dynamically confronts the attack behavior, thereby improving the robustness of the protocol layer protection.

[0062] The present invention integrates variant protocol fingerprints, physical layer hardware noise characteristics and virtualization layer resource call patterns to construct a three-dimensional feature vector, and generates a device identity with spatiotemporal dynamics based on the vector, thereby enhancing the security of device identity authentication. According to the confidence level of the device identity, the system dynamically selects a protocol encapsulation channel based on chaotic encryption or a camouflaged transmission channel based on bait data injection to ensure the confidentiality and integrity of the data transmission process. The key stream of the chaotic encryption algorithm is updated in real time through attack detection, so that the protocol encryption mode has unpredictability, thereby improving the anti-eavesdropping and tampering capabilities.

[0063] The present invention embeds an adaptive bait generator in the disguised transmission channel, generates false vulnerability features according to the vulnerability feature library of the target device, constructs a data interaction sequence of a logic trap, and induces the attacker to mistakenly trigger a non-existent vulnerability. Through the behavioral analysis probe deployed between the physical network card and the virtual switching layer, the behavioral features of the attacker after triggering the logic trap are captured in real time, including the memory modification mode and the instruction execution path offset, and the attack fingerprint is extracted based on this. The attack fingerprint is input into the adversarial defense strategy generator, and the distortion parameters of the dynamic mutation engine are synchronously updated to form an adaptive evolutionary dynamic defense, ensuring that the system can continuously optimize its own defense capabilities as the attack mode changes, and improve the long-term effectiveness of network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only for the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0065] Figure 1 A schematic diagram of a method flow chart of an embodiment of the present invention;

[0066] Figure 2 Schematic diagram of the system framework of an embodiment of the present invention. DETAILED DESCRIPTION

[0067] The present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. At the same time, it is explained here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments, and those skilled in the art may also adopt other alternatives to implement some known technologies; and the accompanying drawings are only for more specific description of the embodiments, and are not intended to specifically limit the present invention.

[0068] It should be noted that the references to "one embodiment", "an embodiment", "an exemplary embodiment", "some embodiments" and the like in the specification indicate that the embodiments described may include specific features, structures or characteristics, but not every embodiment may include the specific features, structures or characteristics. In addition, when a specific feature, structure or characteristic is described in conjunction with an embodiment, it should be within the knowledge of a person skilled in the art to implement such feature, structure or characteristic in conjunction with other embodiments (whether or not explicitly described).

[0069] In general, a term can be understood, at least in part, from its use in context. For example, depending, at least in part, on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in the singular sense, or can be used to describe a combination of features, structures, or characteristics in the plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey an exclusive set of factors, but can instead, depending, at least in part, on the context, allow for the presence of other factors that are not necessarily explicitly described.

[0070] like Figure 1 As shown, a new network information security method includes the following steps:

[0071] S1. Inject a dynamic mutation engine into the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, generate random mutation factors through quantum noise sources, dynamically distort the protocol field length, check bit distribution and handshake timing characteristics, and generate mutation protocol fingerprints;

[0072] S2. Based on the variant protocol fingerprint, the physical layer hardware noise characteristics and the virtualization layer resource call mode are integrated to form a three-dimensional feature vector, and a device identity with spatiotemporal dynamics is generated based on the three-dimensional feature vector;

[0073] S3. Deploy a heterogeneous protocol mapper in the protocol conversion gateway. According to the confidence level of the device identity, dynamically select a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on bait data injection. The protocol encapsulation channel encrypts or obfuscates the original protocol, making it difficult for attackers to identify, intercept or tamper with the data transmission process.

[0074] S4, embedding an adaptive decoy generator in the disguised transmission channel, generating a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructing a data interaction sequence with logic traps;

[0075] S5. By deploying a behavioral analysis probe between the physical network card and the virtual switching layer, the attacker's triggering behavior characteristics for the logic trap are captured, and the attack fingerprint including the memory modification mode and the instruction execution path offset is extracted;

[0076] S6. Input the attack fingerprint into the adversarial defense strategy generator and synchronously update the distortion parameters of the dynamic mutation engine.

[0077] S1 specifically includes:

[0078] S11, between the data link layer and the network layer of the network protocol stack, by real-time analysis and modification of the transmitted data packets, the characteristic fingerprint F of the communication protocol is collected, including the protocol field length, check bit distribution and handshake timing characteristics;

[0079] Extract the protocol feature fingerprint from the transmitted data packet. Suppose a data packet P = {f 1 ,f 2 ,...,f i}, where f i Represents the i-th protocol field in the data packet. The collection of feature fingerprints is achieved by statistically analyzing the protocol fields in the data packet. Typical features include field length, check bit distribution, and handshake timing characteristics. Assume:

[0080] L(P i ) is the protocol field f i Length;

[0081] C(P i ) is the protocol field f i The check bit distribution of the field indicates the check bit sequence of the field;

[0082] T(P i ) is the protocol field f i The handshake timing characteristics indicate the timing information of the handshake in the field;

[0083] Then, the characteristic fingerprint F of the communication protocol is expressed as:

[0084] F={L(P 1 ),L(P 2 ),...,L(P i ),C(P 1 ),C(P 2 ),...,C(P i ),T(P 1 ),T(P2 ),...,T(P i )}, where F is the characteristic fingerprint of the entire data packet, which is the collection of all protocol field features.

[0085] S12, generating a random mutation factor through a quantum noise source, where the random mutation factor includes a random number and a noise signal, and is used to perform a distortion operation on a communication protocol field;

[0086] Generate a random mutation factor for protocol field distortion. Suppose a quantum noise source Q is used to generate a random mutation factor r. The noise provided by the quantum noise source is represented by a probability distribution. Suppose the random factor generated by the quantum noise source is r, and its distribution is expressed as: in, Indicates that the mean is 0 and the variance is σ 2 The random factor is used to mutate the protocol field. Let the mutation factor of the protocol field be Δf i , then the variation is performed by the following formula: Δf i =f i +r, where f i is the original protocol field, Δf i It is the mutated field.

[0087] S13, the distortion operation includes dynamically adjusting the protocol field length, check bit distribution and handshake timing characteristics, disrupting the original fixed pattern in the protocol, and generating a variant protocol fingerprint F′ with a variant property. The variant protocol fingerprint is used to describe the data packet characteristics of the modified protocol.

[0088] 1. Adjustment of protocol field length: For each protocol field f i , the field length is adjusted according to the random factor r, and the adjusted field length is L′, which is expressed as: L′(P i )=L(P i )+ΔL i , where ΔL i is a random increment generated by a quantum noise source, expressed as: ΔL i =r 1 , where r 1 is the variation factor generated by the quantum noise source for length adjustment;

[0089] 2. Adjustment of parity bit distribution: For each protocol field, the parity bit C(P i ), scramble it with the noise factor r to generate a new check bit distribution C′(P i ): C′(P i )=C(P i )+ΔC i , where ΔC iIt is the amount of change adjusted based on a random factor, which can be generated by adding noise or a randomization algorithm;

[0090] 3. Adjustment of handshake timing characteristics: For the handshake timing characteristics T(P i ), by randomly perturbing the time series to generate a new time series feature T′(P i ):T′(P i )=T(P i )+ΔT i , where ΔT i is the amount of change in the time interval adjusted by quantum noise;

[0091] 4. Generate variant protocol fingerprint: the protocol field f after the distortion operation i ′ will constitute a new variant protocol fingerprint F′, which is expressed as:

[0092] F′={L′(P 1 ), L′(P 2 ), ..., L′(P n ), C′(P 1 ), C′(P 2 ), ..., C′(P n ), T′(P 1 ), T′(P 2 ), ..., T′(P n )}; The mutation protocol fingerprint F′ is the set of protocol field features after the mutation operation.

[0093] S2 specifically includes:

[0094] S21, obtain the variant protocol fingerprint F′;

[0095] S22, obtaining hardware noise features H through a physical layer feature acquisition module, including electromagnetic interference and thermal noise generated by the device during operation. These noise features reflect the working status and characteristics of the hardware;

[0096] S23, obtaining a resource call pattern R through monitoring of the virtualization layer, including CPU load and network bandwidth consumption, which indicates resource allocation and usage characteristics of the device in the virtual environment;

[0097] S24, based on the variant protocol fingerprint F′, the hardware noise feature H and the virtualization layer resource call pattern R, the three feature vectors are sequentially concatenated into a long vector and fused into a three-dimensional feature vector V: V = [F′, H, R];

[0098] S25, based on the three-dimensional feature vector V, generates a device identity ID(t) with spatiotemporal dynamics through a spatiotemporal dynamic model. The identity ID(t) takes into account the spatiotemporal change characteristics of the device, and dynamically adjusts with the changes in time and space, indicating the unique identity of the device under different time and space conditions.

[0099] The identity ID is generated based on the three-dimensional feature vector V and the spatiotemporal dynamic model, and is expressed as:

[0100] ID(t)=f(V(t),t), where t represents time, V(t) is the three-dimensional feature vector of the device at time t, and f(·) is a spatiotemporal dynamic model, including time series analysis. Specifically, the device identity is generated by performing spatiotemporal modeling on the three-dimensional feature vector. f(V(t),t) is specifically expressed as:

[0101] Among them, e represents the number of feature dimensions in F′, k represents the number of feature dimensions in H, m represents the number of feature dimensions in R, and v p (t) represents the value of the pth feature in the three-dimensional feature vector V(t) at time t, w p is the weight of the feature, β(t) is the dynamic time bias term, which is used to adjust the influence of spatiotemporal factors. As time t passes, the three-dimensional feature vector V(t) of the device will change, resulting in dynamic changes in the device identity ID(t). This process takes into account the changes of the device at different time points, thereby increasing the spatiotemporal dynamics of the identity.

[0102] S3 specifically includes:

[0103] S31, the heterogeneous protocol mapper obtains the device identity ID and its confidence level α in real time by interacting with the device's protocol stack, where α∈[0,1] represents the credibility of the device identity;

[0104] S32, the heterogeneous protocol mapper selects a protocol transmission channel according to the confidence level α of the device identity:

[0105] When the confidence level α is higher than the predetermined threshold α thresh When the value is 0.8, a protocol encapsulation channel based on chaotic encryption is selected, and the protocol is encrypted or obfuscated by the chaotic encryption algorithm to ensure that the data is difficult to be identified, intercepted or tampered by attackers during transmission;

[0106] First, chaotic encryption generates a random chaotic sequence, usually using a chaotic map of the Logistic map to generate a key stream. These generated values ​​are used as encryption keys. Next, the key stream is encrypted or obfuscated by performing a bit-by-bit XOR operation with the communication protocol data. The encrypted data will be encapsulated in the obfuscated protocol format and transmitted over the network.

[0107] In addition to encrypting the data itself, chaotic encryption can also confuse the structure of the protocol, including adjusting the order and length of the fields, making the structure and transmission process of the protocol more unpredictable and increasing security.

[0108] Finally, the receiver decrypts the encrypted data using the same chaotic algorithm and key stream to restore the original communication data.

[0109] When the confidence level α is higher than the predetermined threshold α thresh When (0.8), a disguised transmission channel based on bait data injection is selected, and false data is injected during the transmission process to confuse potential attackers through disguise means and hide the real communication content.

[0110] In the protocol conversion gateway, the device identity ID is matched with a predefined device feature database, which contains the known feature vectors of the device (three-dimensional feature vector V) and the corresponding identity. The matching process is based on similarity calculation:

[0111] Here, V new Represents the newly acquired device feature vector, V known Represents the feature vector of a known device. The confidence level α is calculated by the similarity of the matching results. The calculated similarity value is sim. The confidence level α is normalized in the following way:

[0112] Thus, the confidence level α ranges from [0,1], where 0 indicates a complete mismatch and 1 indicates a complete match.

[0113] S4 specifically includes:

[0114] S41, adaptive decoy generator initialization: deploy an adaptive decoy generator in the disguised transmission channel, analyze and map the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extract the potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact range;

[0115] S42, generating false vulnerability features: the adaptive bait generator generates false vulnerability features according to the vulnerability feature library of the target device and the current network environment. The false vulnerability features simulate actual vulnerabilities, but do not exist in the actual system, thereby misleading attackers and preventing them from launching attacks by exploiting real vulnerabilities.

[0116] S43, constructing a protocol payload: embedding the generated false vulnerability features into the protocol payload, disguising them as normal vulnerability features, and transmitting the protocol payload to the target device through the network, and appearing as a set of seemingly effective disguised vulnerability features in the protocol stack of the target device;

[0117] S44, constructing a data interaction sequence of a logic trap: According to the vulnerability type, attack path, and vulnerability impact range of the target device, a data interaction sequence with a logic trap is designed to induce the attacker to mistakenly trigger a false vulnerability. The data interaction sequence sends a bait path with false vulnerability characteristics through a disguised protocol payload to the attacker, thereby inducing him to enter the logic trap.

[0118] Behavioral analysis probes monitor the attacker's reaction behavior when these bait paths are triggered, capture features such as memory modification patterns and path offsets, and then generate attack fingerprints. Through the captured attack fingerprints, the system can adjust the defense strategy in real time and continuously enhance security.

[0119] S5 specifically includes:

[0120] S51, deployment of behavioral analysis probes: Deploy behavioral analysis probes between the physical network card and the virtual switching layer to monitor all data packets and data interaction sequences transmitted through the network in real time. This probe is located between the data link layer and the network layer and can perform in-depth analysis of the content, protocol characteristics, and interaction patterns of data packets.

[0121] S52, capturing the attacker's behavioral characteristics: Through the behavioral analysis probe, the attacker's behavior after receiving the protocol payload containing false vulnerability characteristics is captured. The probe can identify the abnormal behavior characteristics when the attacker attempts to trigger the vulnerability. The abnormal behavior characteristics include memory modification mode and instruction execution path offset:

[0122] S53, extract attack fingerprint: The behavior analysis probe extracts the attacker's behavior fingerprint based on the captured memory modification pattern and instruction execution path offset. The behavior fingerprint includes the vulnerability exploitation skills, attack path, and attack payload used by the attacker. The attack fingerprint is expressed as:

[0123] F attack ={f 1 ,f 2 ,...,f s}, where f sThe sth attack behavior feature includes memory modification mode, instruction execution path offset, and malicious payload;

[0124] S54, the relationship between logic traps and bait paths: The attacker behavior captured by the behavior analysis probe is directly derived from the design of the bait path. When attackers try to trigger false vulnerabilities through logic traps, their behavior will be exposed. The false vulnerabilities are transmitted through the protocol payload P fake and the bait path T trap The fake vulnerability features and decoy paths are designed based on the simulation of real vulnerability features. Therefore, the attacker's reaction to these fake vulnerability features (such as memory modification and path deviation) can serve as an early warning signal of real attack behavior, helping the security system identify potential threats.

[0125] S55, Update of behavioral fingerprint and dynamic defense strategy: Through the extracted attack fingerprint F attack ,The defense strategy can be updated in real time.,For example, these fingerprints can be input through the adversarial defense strategy generator,,the distortion parameters of the dynamic mutation engine, the key sequence of the,protocol encapsulation channel, and the decoy data injection strategy,,forming a continuously evolving defense mechanism.

[0126] Memory modification patterns include: When an attacker attempts to exploit a vulnerability, the attacker may modify the memory content of the target device, including changing the buffer, data structure, or stack content. By monitoring memory operations, the probe captures the behavior pattern of memory modification;

[0127] The instruction execution path offset includes: attackers may change the normal execution path of the program through vulnerabilities and try to jump to the address of malicious code. The behavioral analysis probe captures the offset of the instruction execution path, that is, the abnormal jump of the instruction pointer during execution, and identifies whether the attacker attempts to trigger a buffer overflow or code injection attack.

[0128] S6 specifically includes:

[0129] S61, input attack fingerprint: the attack fingerprint F attack ={f 1 ,f 2 ,...,f s} Input to adversarial defense strategy generator;

[0130] S62, adversarial defense strategy generation: Calculate the attack strength γ, which is used as the threat level of the attack behavior. If γ exceeds the set threshold γ thresh (γ is normalized within the range [0,1], γ thresh Value 0.5-0.7) triggers dynamic defense update: Among them, w iis the weight of the attack fingerprint feature, measuring its contribution to the security threat;

[0131] Dynamic defense updates include:

[0132] S63, synchronously update the distortion parameters of the dynamic mutation engine: adjust the distortion strategy of the dynamic mutation engine according to the latest attack fingerprint:

[0133] Update the dynamic adjustment rules of the protocol field, including the field length variation range ΔL′ and the check bit distortion factor ΔC′:

[0134] ΔL′=ΔL+δ L ;

[0135] ΔC′=ΔC+δ C ;

[0136] where δ L and δ C Calculated by adversarial defense strategies, it enhances the randomness of the protocol structure, making it difficult for attackers to establish fixed-pattern attack methods;

[0137] 1. Calculate the protocol field length adjustment increment δ L : Prevent attackers from using fixed protocol structures to perform pattern matching attacks:

[0138] Suppose the protocol field length variation feature recorded in the attack fingerprint is F L ={f L1 ,f L2 ,…,f LG}, where f LG Represents the fixed field length value that the Gth attacker attempts to exploit;

[0139] Calculate the average length of the fields most commonly used by attackers:

[0140] Assume the security adjustment range of the current protocol field is L safe , then adjust the increment δ L The calculation is as follows:

[0141] δ L =k L ·(L safe -L attack ), where k L is the adaptive adjustment coefficient, which is dynamically adjusted according to the historical attack intensity and takes a value of 0.1-0.3. attack Close to L safe The upper limit means that the attacker is attacking the protocol field length and the system needs to increase the distortion amplitude.

[0142] 2. Calculate the check bit distribution adjustment increment δC : Prevent attackers from using the protocol verification mechanism to tamper with data or bypass verification attacks:

[0143] Assume that the distribution characteristics of the check bits recorded in the attack fingerprint are F C ={f C1 ,f C2 ,…,f CG}, where f CG Represents the check digit pattern that the Gth attacker attempts to exploit;

[0144] Calculate the mean of the check digits most commonly used by attackers:

[0145] Assume that the distribution range of the protocol's security check bit is C safe , then adjust the increment δ C , calculated as follows:

[0146] δ C =k C ·(C safe -C attack ), where k C is the adaptive adjustment coefficient, ranging from 0.2 to 0.5, which determines the sensitivity of the check bit adjustment. If an attacker is detected to tamper with a specific check bit, the system increases δ C , disrupting the fixed pattern of the check digit.

[0147] like Figure 2 As shown, a new network information security system is used to implement the above network information security method, including the following modules:

[0148] The dynamic mutation engine is deployed at the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutation protocol fingerprints;

[0149] The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the variant protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and generate a device identity with spatiotemporal dynamics based on the three-dimensional feature vector;

[0150] The protocol conversion gateway, including a heterogeneous protocol mapper, dynamically selects a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection according to the confidence level of the device identity;

[0151] The adaptive decoy generator is embedded in the disguised transmission channel, generates a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructs a data interaction sequence with logic traps;

[0152] Behavioral analysis probes, deployed between the physical network card and the virtual switching layer, are used to capture the attacker's triggering behavior characteristics for logical traps and extract attack fingerprints, including memory modification patterns and instruction execution path offsets;

[0153] The adversarial defense strategy generator is used to receive attack fingerprints and synchronously update the distortion parameters of the dynamic mutation engine to ensure that the defense strategy can be dynamically adjusted to achieve a continuously evolving security defense mechanism.

[0154] The present invention covers any substitution, modification, equivalent method and scheme made on the essence and scope of the present invention. In order to make the public have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention, but those skilled in the art can fully understand the present invention without the description of these details. In addition, in order to avoid unnecessary confusion about the essence of the present invention, well-known methods, processes, procedures, components and circuits are not described in detail.

[0155] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A new network information security method, characterized in that: The following steps are involved: S1. Inject a dynamic mutation engine into the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, generate random mutation factors through quantum noise sources, dynamically distort the protocol field length, check bit distribution and handshake timing characteristics, and generate mutation protocol fingerprints; S2. Based on the variant protocol fingerprint, the physical layer hardware noise characteristics and the virtualization layer resource call mode are integrated to form a three-dimensional feature vector, and a device identity with spatiotemporal dynamics is generated based on the three-dimensional feature vector; S3. Deploy a heterogeneous protocol mapper in the protocol conversion gateway, and dynamically select a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on bait data injection according to the confidence level of the device identity, wherein the protocol encapsulation channel encrypts or obfuscates the original protocol; S4, embedding an adaptive decoy generator in the disguised transmission channel, generating a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructing a data interaction sequence with logic traps; S5. Capturing the triggering behavior characteristics of the attacker on the logic trap by deploying a behavior analysis probe between the physical network card and the virtual switching layer, and extracting attack fingerprints including memory modification mode and instruction execution path offset; S6. Input the attack fingerprint into the adversarial defense strategy generator, and synchronously update the distortion parameters of the dynamic mutation engine.

2. A novel network information security method according to claim 1, characterized in that: The S1 specifically includes: S11, between the data link layer and the network layer of the network protocol stack, by real-time analysis and modification of the transmitted data packets, the characteristic fingerprint F of the communication protocol is collected, including the protocol field length, check bit distribution and handshake timing characteristics; S12, generating a random mutation factor through a quantum noise source, where the random mutation factor includes a random number and a noise signal, and is used to perform a distortion operation on a communication protocol field; S13, the distortion operation includes dynamically adjusting the protocol field length, check bit distribution and handshake timing characteristics, disrupting the original fixed pattern in the protocol, and generating a variant protocol fingerprint F' with a variant property, and the variant protocol fingerprint is used to describe the data packet characteristics of the modified protocol.

3. A novel network information security method according to claim 2, characterized in that: The S2 specifically includes: S21, obtain the variant protocol fingerprint F′; S22, obtaining hardware noise characteristics H through a physical layer characteristic acquisition module, including electromagnetic interference and thermal noise generated by the device during operation; S23, obtaining resource call pattern R through monitoring of the virtualization layer, including CPU load and network bandwidth consumption; S24, based on the variant protocol fingerprint F′, the hardware noise feature H and the virtualization layer resource call pattern R, they are fused into a three-dimensional feature vector V: V = [F′, H, R]; S25, based on the three-dimensional feature vector V, generates a device identity ID(t) with spatiotemporal dynamics through a spatiotemporal dynamic model. The identity ID(t) takes into account the spatiotemporal change characteristics of the device, and is dynamically adjusted with the changes in time and space, indicating the unique identity of the device under different time and space conditions.

4. A novel network information security method according to claim 3, characterized in that: The identity ID is generated based on the three-dimensional feature vector V and the spatiotemporal dynamic model, and is expressed as: ID(t)=f(V(t), t), where t represents time, V(t) is the three-dimensional feature vector of the device at time t, and f(·) is a spatiotemporal dynamic model, including timing analysis. f(V(t), t) is specifically expressed as: Among them, e represents the number of feature dimensions in F′, k represents the number of feature dimensions in H, m represents the number of feature dimensions in R, and v p (t) represents the value of the pth feature in the three-dimensional feature vector V(t) at time t, w p is the weight of the feature, β(t) is a dynamic time bias term used to adjust the influence of spatiotemporal factors. As time t passes, the three-dimensional feature vector V(t) of the device will change, resulting in dynamic changes in the device identity ID(t).

5. A novel network information security method according to claim 1, characterized in that: The S3 specifically includes: S31, the heterogeneous protocol mapper obtains the device identity ID and its confidence level α in real time by interacting with the device's protocol stack, where α∈[0,1] represents the credibility of the device identity; S32, the heterogeneous protocol mapper selects a protocol transmission channel according to the confidence level α of the device identity: When the confidence level α is higher than the predetermined threshold α thresh When using a chaotic encryption protocol, a chaotic encryption-based protocol encapsulation channel is selected to encrypt or obfuscate the protocol through a chaotic encryption algorithm to ensure that the data is difficult to be identified, intercepted, or tampered with by attackers during transmission. When the confidence level α is higher than the predetermined threshold α thresh When a message is transmitted, a disguised transmission channel based on bait data injection is selected, and false data is injected during the transmission process to confuse potential attackers through disguise and hide the real communication content.

6. A novel network information security method according to claim 1, characterized in that: The S4 specifically includes: S41, adaptive decoy generator initialization: deploy an adaptive decoy generator in the disguised transmission channel, analyze and map the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extract the potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact range; S42, generating false vulnerability features: the adaptive bait generator generates false vulnerability features according to the vulnerability feature library of the target device and the current network environment, wherein the false vulnerability features simulate actual existing vulnerabilities to mislead attackers and prevent them from launching attacks by exploiting real vulnerabilities; S43, constructing a protocol payload: embedding the generated false vulnerability features into the protocol payload to disguise them as normal vulnerability features. The protocol payload is transmitted to the target device through the network and appears as a set of disguised vulnerability features in the protocol stack of the target device. S44, constructing a data interaction sequence of a logic trap: According to the vulnerability type, attack path, and vulnerability impact range of the target device, a data interaction sequence with a logic trap is designed to induce the attacker to mistakenly trigger a false vulnerability. The data interaction sequence sends a bait path with false vulnerability characteristics through a disguised protocol payload to the attacker, thereby inducing him to enter the logic trap.

7. A novel network information security method according to claim 1, characterized in that: The S5 specifically includes: S51, deployment of behavior analysis probes: deploy behavior analysis probes between the physical network card and the virtual switching layer to monitor all data packets and data interaction sequences transmitted through the network in real time; S52, capturing the attacker's behavioral characteristics: Through the behavioral analysis probe, the attacker's behavior after receiving the protocol payload containing false vulnerability characteristics is captured. The probe can identify the abnormal behavior characteristics when the attacker attempts to trigger the vulnerability. The abnormal behavior characteristics include memory modification mode and instruction execution path offset: S53, extract attack fingerprint: The behavior analysis probe extracts the attacker's behavior fingerprint based on the captured memory modification pattern and instruction execution path offset. The behavior fingerprint includes the vulnerability exploitation skills, attack path, and attack payload used by the attacker. The attack fingerprint is expressed as: F attack ={f1, f2, ..., f s }, where f s The sth attack behavior feature includes memory modification mode, instruction execution path offset, and malicious payload; S54, the relationship between logic traps and bait paths: The attacker behavior captured by the behavior analysis probe is directly derived from the design of the bait path. When the attacker tries to trigger a false vulnerability through a logic trap, the false vulnerability is triggered through the protocol payload P fake and the bait path T trap is delivered to the target device, ultimately tricking the attacker into the wrong attack path; S55, Update of behavioral fingerprint and dynamic defense strategy: Through the extracted attack fingerprint F attack , update defense strategies in real time.

8. A novel network information security method according to claim 7, characterized in that: The memory modification mode includes: when an attacker attempts to exploit a vulnerability, the attacker modifies the memory content of the target device, including changing the buffer, data structure or stack content. By monitoring the memory operation, the probe captures the behavior mode of the memory modification; The instruction execution path offset includes: an attacker changes the normal execution path of the program through a vulnerability and attempts to jump to the address of the malicious code, and the behavior analysis probe captures the offset of the instruction execution path.

9. A novel network information security method according to claim 7, characterized in that: The S6 specifically includes: S61, input attack fingerprint: the attack fingerprint F attack ={f1, f2, ..., f s } Input to adversarial defense strategy generator; S62, adversarial defense strategy generation: Calculate the attack strength γ, which is used as the threat level of the attack behavior. If γ exceeds the set threshold γ thresh , triggering dynamic defense updates; S63, synchronously update the distortion parameters of the dynamic mutation engine: adjust the distortion strategy of the dynamic mutation engine according to the latest attack fingerprint: Update the dynamic adjustment rules of the protocol field, including the field length variation range ΔL′ and the check bit distortion factor ΔC′: ΔL′=ΔL+δ L ; ΔC′=ΔC+δ C ; where δ L and δ C Calculated by the adversarial defense strategy, it enhances the randomness of the protocol structure and makes it difficult for attackers to establish fixed-pattern attack methods.

10. A new network information security system, used to implement a new network information security method as claimed in any one of claims 1 to 9, characterized in that: Includes the following modules: The dynamic mutation engine is deployed at the bottom layer of the network protocol stack to collect the characteristic fingerprint of the communication protocol in real time, and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutation protocol fingerprints; The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the variant protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and generate a device identity with spatiotemporal dynamics based on the three-dimensional feature vector; The protocol conversion gateway, including a heterogeneous protocol mapper, dynamically selects a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection according to the confidence level of the device identity; The adaptive decoy generator is embedded in the disguised transmission channel, generates a protocol payload including false vulnerability features according to the vulnerability feature library of the target device, and constructs a data interaction sequence with logic traps; Behavioral analysis probes, deployed between the physical network card and the virtual switching layer, are used to capture the attacker's triggering behavior characteristics for logical traps and extract attack fingerprints, including memory modification patterns and instruction execution path offsets; The adversarial defense strategy generator is used to receive attack fingerprints and synchronously update the distortion parameters of the dynamic mutation engine.

Citation Information

Patent Citations

  • Network protocol fuzz test method based on classified variation

    CN109347696A

  • Network spoofing defense method and device based on host fingerprint hiding

    CN111628993A

  • Power grid industrial control protocol vulnerability mining system adopting fuzzy test

    CN117640199A

  • Method and system for data stream analysis

    US20240406274A1

Cited By

  • Network traffic audit optimization defense method based on protocol confusion

    CN120614196A

  • Short video active defense encryption system based on device fingerprint and dynamic confusion field

    CN120640040A

  • Dynamic CAN bus protocol confusion system and method based on artificial intelligence

    CN121077710A

  • LED energy-saving lamp internet-of-things control system with edge calculation function

    CN121262693A

  • Data security and privacy protection method for distribution automation system

    CN121441649A