A new network information security defense method and system
By injecting a dynamic mutation engine and behavioral analysis probes into the underlying network protocol stack, combined with quantum noise and chaotic encryption technology, the protocol structure and transmission channels are dynamically adjusted to construct logical traps. This solves the problem that existing technologies are unable to cope with advanced threats, and achieves dynamic defense and long-term effectiveness of network security.
Patent Information
- Application Number
- CN202510196739.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-02-21
AI Technical Summary
Existing cybersecurity technologies are ill-equipped to deal with advanced threats such as protocol sniffing, identity forgery, and zero-day attacks. In particular, in virtualization and cloud computing environments, attackers can steal identity information through virtual machine escape and side-channel attacks, leading to an asymmetry between offense and defense.
A dynamic mutation engine is injected into the bottom layer of the network protocol stack. Random mutation factors are generated by quantum noise sources to distort protocol fields. A three-dimensional feature vector is generated by combining physical layer hardware noise and virtualization layer resource call patterns. Chaotic encryption or decoy data transmission channels are dynamically selected. An adaptive decoy generator is embedded to construct a logical trap. Attacker behavior is captured by behavioral analysis probes, and defense strategies are updated in real time.
It improves the robustness of protocol layer protection, enhances the security of device authentication, ensures the confidentiality and integrity of data transmission, dynamically adjusts defense strategies to cope with different attack modes, and improves the long-term effectiveness of network security.
Smart Images

Figure CN120050092B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network information security, and in particular to a novel network information security defense method and system. BACKGROUND
[0002] With the continuous evolution of network attack means, traditional network security protection technology is facing severe challenges. The existing security mechanism mainly relies on static encryption, rule-based access control, feature matching intrusion detection and the like. However, in response to protocol sniffing, identity forgery, dynamic vulnerability exploitation and other advanced threats, there are still many deficiencies. First, the structure of the existing communication protocol is relatively fixed. Attackers can extract protocol features through traffic analysis and pattern matching technology, thereby implementing protocol deception, replay attacks or traffic injection attacks. In addition, device identity authentication is mainly dependent on static identifiers such as MAC addresses, IP addresses or public key certificates, which are easy to be forged or tampered with. Especially in the virtualization and cloud computing environment, attackers can steal identity information through virtual machine escape, side channel attacks and other means to bypass security detection mechanisms.
[0003] More importantly, the existing defense strategy is usually based on predefined rules or known attack feature libraries, which is difficult to adapt to new attack patterns, especially zero-day attacks and AI-based automatic mutation attacks, so that attackers can continuously adjust strategies to evade existing defense means, forming an asymmetric situation between attack and defense. SUMMARY
[0004] The application provides a novel network information security defense method and system.
[0005] A novel network information security defense method, comprising the following steps:
[0006] S1, injecting a dynamic mutation engine at the bottom layer of a network protocol stack, collecting communication protocol feature fingerprints in real time, generating random mutation factors through a quantum noise source, dynamically distorting protocol field length, check bit distribution and handshake timing characteristics, and generating a mutated protocol fingerprint;
[0007] S2, based on the mutated protocol fingerprint, simultaneously fusing physical layer hardware noise characteristics and virtualization layer resource calling modes to form a three-dimensional feature vector, and generating a device identity identifier with spatiotemporal dynamics based on the three-dimensional feature vector;
[0008] S3, deploying a heterogeneous protocol mapper at a protocol conversion gateway, dynamically selecting a protocol encapsulation channel based on chaotic encryption or a pseudo transmission channel based on decoy data injection according to the confidence level of the device identity identifier, and the protocol encapsulation channel encrypting or obfuscating the original protocol;
[0009] S4, embedding an adaptive decoy generator in the camouflage transmission channel, generating protocol payloads including false vulnerability characteristics according to the vulnerability characteristic library of the target device, and constructing a data interaction sequence with a logical trap;
[0010] S5, capturing the triggering behavior characteristics of the attacker on the logical trap through a behavior analysis probe deployed between the physical network card and the virtual switching layer, and extracting attack fingerprints including memory modification patterns and instruction execution path offsets;
[0011] S6, inputting the attack fingerprints into an adversarial defense strategy generator, and synchronously updating the distortion parameters of the dynamic variation engine.
[0012] Optionally, the S1 specifically comprises:
[0013] S11, collecting communication protocol characteristic fingerprints including protocol field length, check bit distribution, and handshake timing characteristics by performing real-time analysis and modification on the transmitted data packets between the data link layer and the network layer of the network protocol stack
[0014] S12, generating random variation factors including random numbers and noise signals through a quantum noise source, which are used for distortion operation on the communication protocol fields;
[0015] S13, the distortion operation includes dynamically adjusting the protocol field length, check bit distribution, and handshake timing characteristics, disrupting the original fixed mode in the protocol, and generating a variation protocol fingerprint with variation properties , the variation protocol fingerprint is used to describe the data packet characteristics of the modified protocol.
[0016] Optionally, the S2 specifically comprises:
[0017] S21, obtaining a variation protocol fingerprint ;
[0018] S22, obtaining hardware noise characteristics including electromagnetic interference and thermal noise generated by the device during operation through a physical layer feature acquisition module, which reflect the working state and characteristics of the hardware
[0019] S23, obtaining resource call patterns including CPU load and network bandwidth consumption through monitoring of the virtualization layer, which represent resource allocation and use characteristics of the device in the virtual environment
[0020] S24, based on the variation protocol fingerprint , hardware noise characteristics and virtualization layer resource call patterns The three feature vectors are concatenated in sequence into a long vector, which is then fused into a three-dimensional feature vector. : ;
[0021] S25, based on three-dimensional feature vectors Device identification identifiers with spatiotemporal dynamics are generated through a spatiotemporal dynamic model. The identity identifier Considering the spatiotemporal variation characteristics of the equipment, it dynamically adjusts with changes in time and space to represent the unique identity of the equipment under different time and space conditions.
[0022] Optionally, the identity identifier Based on three-dimensional feature vectors And the spatiotemporal dynamic model is generated, represented as:
[0023] ,in, Indicates time, It is the device in time The three-dimensional feature vector at time t, It is a spatiotemporal dynamic model, including time series analysis. Specifically, it is expressed as follows:
[0024] ,in, express The number of feature dimensions in the data. express The number of feature dimensions in the data. express The number of feature dimensions in the data. Representing three-dimensional feature vectors The Middle One characteristic in time The value of time, It is the weight of that feature. It is a dynamic time bias term used to adjust for the influence of spatiotemporal factors, which changes over time. As time goes by, the three-dimensional feature vector of the equipment Changes will occur, resulting in changes to the device's identity. The dynamic changes.
[0025] Optionally, S3 specifically includes:
[0026] S31, the heterogeneous protocol mapper interacts with the device's protocol stack to obtain the device's identity identifier in real time. and its confidence level ,in This indicates the credibility of the device's identity identifier;
[0027] S32, the isomeric protocol mapper selects a protocol transmission channel according to the confidence level of the device identity
[0028] When the confidence level is higher than a predetermined threshold (0.8), a protocol encapsulation channel based on chaotic encryption is selected, and the protocol is encrypted or obfuscated through a chaotic encryption algorithm to ensure that the data is difficult to be identified, intercepted or tampered with by attackers during transmission;
[0029] When the confidence level is higher than a predetermined threshold (0.8), a camouflage transmission channel based on decoy data injection is selected, and false data is injected during transmission to confuse potential attackers and hide the real communication content through camouflage means.
[0030] Optionally, the S4 specifically includes:
[0031] S41, adaptive decoy generator initialization: deploying an adaptive decoy generator in the camouflage transmission channel, analyzing and mapping the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extracting potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact range;
[0032] S42, generating false vulnerability features: the adaptive decoy generator generates false vulnerability features according to the vulnerability feature library of the target device and the current network environment, the false vulnerability features simulate the actual existing vulnerabilities, but do not exist in the actual system, thereby misleading the attacker and preventing him from launching an attack using real vulnerabilities;
[0033] S43, constructing protocol payload: embedding the generated false vulnerability features into the protocol payload, disguising as normal vulnerability features, and transmitting the protocol payload to the target device through the network, which appears as a set of seemingly effective camouflage vulnerability features in the protocol stack of the target device;
[0034] S44, constructing a data interaction sequence with a logical trap: according to the vulnerability type, attack path, and vulnerability impact range of the target device, designing a data interaction sequence with a logical trap to induce the attacker to trigger false vulnerabilities incorrectly, and the data interaction sequence sends a decoy path with false vulnerability features through the disguised protocol payload to the attacker, inducing him to enter the logical trap.
[0035] Optionally, the S5 specifically includes:
[0036] S51, deployment of behavior analysis probe: deploying a behavior analysis probe between the physical network card and the virtual switch layer to monitor all data packets and data interaction sequences transmitted through the network in real time, the probe is located between the data link layer and the network layer, and can perform deep analysis on the content, protocol characteristics and interaction mode of the data packets;
[0037] S52, capturing the behavior characteristics of the attacker: capturing the behavior of the attacker after receiving the protocol payload containing the false vulnerability characteristics through the behavior analysis probe, the probe can identify the abnormal behavior characteristics of the attacker when attempting to trigger the vulnerability, including memory modification mode and instruction execution path offset:
[0038] S53, extracting attack fingerprints: the behavior analysis probe extracts the behavior fingerprints of the attacker according to the captured memory modification mode and instruction execution path offset, the behavior fingerprints include the exploit skills, attack path and attack payload used by the attacker, and the attack fingerprints are represented as:
[0039] , wherein, is the th attack behavior characteristic, including memory modification mode, instruction execution path offset and malicious payload;
[0040] S54, relationship between logical trap and bait path: the behavior of the attacker captured by the behavior analysis probe is directly derived from the design of the bait path, when the attacker attempts to trigger the false vulnerability through the logical trap, their behavior will be exposed, the false vulnerability is transmitted to the target device through the protocol payload and the bait path , and finally lures the attacker into the wrong attack path;
[0041] S55, updating of behavior fingerprints and dynamic defense strategy: updating the defense strategy in real time through the extracted attack fingerprints .
[0042] Optionally, the memory modification mode includes that the attacker may modify the memory content of the target device when attempting to exploit the vulnerability, including changing the buffer, data structure or stack content, by monitoring the memory operation, the probe captures the behavior mode of memory modification;
[0043] The instruction execution path offset includes that the attacker may change the normal execution path of the program through the vulnerability, and attempt to jump to the address of malicious code, the behavior analysis probe captures the offset of the instruction execution path, i.e. the abnormal jump of the instruction pointer in the execution process, and identifies whether the attacker attempts to trigger buffer overflow or code injection attack means.
[0044] Optionally, the S6 specifically includes:
[0045] S61, Input Attack Fingerprint: Enter the attack fingerprint Input into the adversarial defense strategy generator;
[0046] S62, Adversarial Defense Strategy Generation: Calculating Attack Strength Attack strength As a threat level of an attack, if Exceeding the set threshold ( Within the normalization range [0,1], A value between 0.5 and 0.7 triggers a dynamic defense update. ,in, It is the weight of the attack fingerprint feature, which measures its contribution to the security threat;
[0047] Dynamic defense updates specifically include:
[0048] S63, synchronously updates the distortion parameters of the dynamic mutation engine: adjusts the distortion strategy of the dynamic mutation engine based on the latest attack fingerprint.
[0049] Update the dynamic adjustment rules for protocol fields, including the range of field length variations. And parity bit distortion factor :
[0050] ;
[0051] ;
[0052] in and Calculations based on adversarial defense strategies show that enhancing the randomness of the protocol structure makes it difficult for attackers to establish fixed attack patterns.
[0053] A novel network information security defense system, used to implement the aforementioned novel network information security defense method, includes the following modules:
[0054] The dynamic mutation engine, deployed at the bottom layer of the network protocol stack, is used to collect the feature fingerprints of communication protocols in real time and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutated protocol fingerprints.
[0055] The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the mutation protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and to generate a device identity identifier with spatiotemporal dynamics based on the three-dimensional feature vector.
[0056] The protocol conversion gateway comprises a heterogeneous protocol mapper, a dynamic selection of a protocol encapsulation channel based on chaotic encryption or a camouflage transmission channel based on decoy data injection according to a confidence level of a device identity;
[0057] An adaptive decoy generator is embedded in the camouflage transmission channel, generates a protocol payload comprising false vulnerability features according to a vulnerability feature library of a target device, and constructs a data interaction sequence with a logical trap;
[0058] A behavior analysis probe is deployed between a physical network card and a virtual switching layer, used for capturing triggering behavior features of the logical trap by the attacker, and extracting attack fingerprints, including memory modification patterns and instruction execution path offsets;
[0059] An adversarial defense strategy generator is used for receiving the attack fingerprints and synchronously updating distortion parameters of a dynamic variation engine.
[0060] The present application has the following advantages:
[0061] The present application injects a dynamic variation engine at the bottom layer of a network protocol stack, generates random variation factors based on quantum noise sources, dynamically distorts protocol field lengths, check bit distributions and handshake timing characteristics, changes protocol structures constantly, avoids protocol sniffing, traffic analysis or attacks using specific vulnerabilities by the attacker, synchronously updates distortion parameters of the dynamic variation engine based on an adaptive adjustment mechanism of the attack fingerprints, ensures that the defense strategy is always dynamically opposed to the attack behavior, and improves the robustness of protocol layer protection.
[0062] The present application fuses variation protocol fingerprints, physical layer hardware noise features and virtualization layer resource calling modes, constructs a three-dimensional feature vector, generates a device identity with spatiotemporal dynamics based on the vector, enhances the security of device identity authentication, dynamically selects a protocol encapsulation channel based on chaotic encryption or a camouflage transmission channel based on decoy data injection according to a confidence level of the device identity, ensures the confidentiality and integrity of the data transmission process, updates a key stream of the chaotic encryption algorithm in real time through attack detection, makes the protocol encryption mode unpredictable, and improves the anti-eavesdropping and tamper-proofing capabilities.
[0063] The application embeds an adaptive bait generator in a camouflage transmission channel, generates false vulnerability characteristics according to a vulnerability characteristic library of a target device, constructs a data interaction sequence of a logical trap, and induces an attacker to trigger a non-existent vulnerability. BRIEF DESCRIPTION OF DRAWINGS
[0064] In order to more clearly illustrate the technical solutions in the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only a part of the present application, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.
[0065] Figure 1 The method flowchart of the embodiment of the present application is shown in the figure.
[0066] Figure 2 The system framework diagram of the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0067] The present application will be described in detail below in combination with the drawings and specific embodiments. It should be noted that, in order to make the embodiments more detailed, the following embodiments are the best, preferred embodiments, and other alternative ways can also be used by those skilled in the art to implement them; and the drawings are only used to more specifically describe the embodiments, and are not intended to specifically limit the present application.
[0068] It should be noted that in the specification, "one embodiment", "embodiment", "exemplary embodiment", "some embodiments" and the like indicate that the described embodiments can include specific features, structures or characteristics, but not necessarily every embodiment includes the specific features, structures or characteristics. In addition, when a specific feature, structure or characteristic is described in combination with an embodiment, it should be within the knowledge of those skilled in the related art to realize this feature, structure or characteristic in combination with other embodiments (whether or not explicitly described).
[0069] In general, terms can be understood to be contextually defined. For example, the term "one or more" as used herein, depending on the context, can be used to describe any feature, structure, or characteristic in the singular or can be used to describe combinations of features, structures or characteristics, in the plural, as is consistent with the context. Further, the term "based on" can be understood as not necessarily being confined to factors that are explicitly enumerated, but rather, can also include other factors not explicitly enumerated, as is consistent with the context.
[0070] As shown in Figure 1 A new network information security defense method, comprising the following steps:
[0071] S1, injecting a dynamic variation engine at the bottom layer of the network protocol stack, collecting the characteristic fingerprint of the communication protocol in real time, generating random variation factors through a quantum noise source, dynamically distorting the protocol field length, check bit distribution and handshake timing characteristics, and generating a variation protocol fingerprint;
[0072] S2, based on the variation protocol fingerprint, simultaneously fusing the physical layer hardware noise characteristics and the virtualization layer resource calling mode to form a three-dimensional feature vector, and generating a device identity with spatiotemporal dynamics based on the three-dimensional feature vector;
[0073] S3, deploying a heterogeneous protocol mapper in the protocol conversion gateway, dynamically selecting a protocol encapsulation channel based on chaotic encryption or a camouflage transmission channel based on decoy data injection according to the confidence level of the device identity, and the protocol encapsulation channel encrypting or confusing the original protocol, so that the data transmission process is difficult to be recognized, intercepted or tampered by attackers;
[0074] S4, embedding an adaptive decoy generator in the camouflage transmission channel, generating a protocol payload including false vulnerability characteristics according to the vulnerability characteristic library of the target device, and constructing a data interaction sequence with logical traps;
[0075] S5, through the behavior analysis probe deployed between the physical network card and the virtual switching layer, capturing the triggering behavior characteristics of the attacker on the logical trap, and extracting the attack fingerprint including the memory modification mode and the instruction execution path offset;
[0076] S6, inputting the attack fingerprint into the adversarial defense strategy generator, and synchronously updating the distortion parameters of the dynamic variation engine.
[0077] S1 specifically includes:
[0078] S11, between the data link layer and the network layer of the network protocol stack, collecting the characteristic fingerprint of the communication protocol by real-time analysis and modification of the transmitted data packet , including the protocol field length, the check bit distribution and the handshake timing characteristics;
[0079] Extracting protocol feature fingerprints from transmitted data packets, let's say a data packet... ,in Indicates the first in the data packet The acquisition of feature fingerprints for protocol fields is achieved through statistical analysis of these fields in data packets. Typical features include field length, checksum distribution, and handshake timing characteristics. Let:
[0080] Protocol field Length;
[0081] Protocol field The distribution of check bits represents the sequence of check bits for a field;
[0082] Protocol field The handshake timing characteristics represent the timing information of the handshake in the field;
[0083] So, the characteristic fingerprint of a communication protocol Represented as:
[0084] ,in, It is the characteristic fingerprint of the entire data packet, which is a collection of features from all protocol fields.
[0085] S12 generates a random mutation factor through a quantum noise source. This random mutation factor includes random numbers and noise signals, which are used to perform distortion operations on the communication protocol fields.
[0086] Generate a random mutation factor for protocol field distortion, assuming the use of a quantum noise source. To generate random mutation factors The noise provided by the quantum noise source is represented by a probability distribution, and the random factor generated by the quantum noise source is denoted as . Its distribution is represented as: ,in, This indicates that the mean is 0 and the variance is . The protocol field is a Gaussian distribution, and this random factor is used to perform a mutation operation on the protocol field. Let the mutation factor of the protocol field be... Then, the mutation is performed using the following formula: ,in, It is the original protocol field. It is the mutated field.
[0087] S13, the distortion operation includes dynamically adjusting the protocol field length, checksum distribution, and handshake timing characteristics, disrupting the original fixed pattern in the protocol, and generating a mutated protocol fingerprint with mutation properties. The variant protocol fingerprint is used to describe the characteristics of the data packets of the modified protocol.
[0088] 1. Adjusting the length of protocol fields: For each protocol field... According to the random factor The field length has been adjusted, and the adjusted field length is: , represented as: ,in, It is a random increment generated by a quantum noise source, expressed as: ,in, It is a variation factor generated by a quantum noise source for length adjustment;
[0089] 2. Adjustment of checksum distribution: For the checksum of each protocol field... Using noise factor Scramble it to generate a new parity bit distribution : ,in, It is the change based on the random factor adjustment, which can be generated by adding noise or randomization algorithms;
[0090] 3. Adjustment of handshake timing features: For handshake timing features New time series features are generated by randomly perturbing the time series. : ,in, It is the change in time interval after adjustment by quantum noise;
[0091] 4. Generate a mutated protocol fingerprint: the protocol field after distortion operation. This will constitute a new mutation protocol fingerprint. It is represented as:
[0092] ;
[0093] Mutation Protocol Fingerprint It is a collection of protocol field characteristics after mutation operations.
[0094] S2 specifically includes:
[0095] S21, Obtain the mutation protocol fingerprint ;
[0096] S22, acquire hardware noise features through the physical layer feature acquisition module. This includes electromagnetic interference and thermal noise generated during equipment operation; these noise characteristics reflect the working status and characteristics of the hardware.
[0097] S23, obtain resource call patterns through monitoring of the virtualization layer. This includes CPU load and network bandwidth consumption, representing the resource allocation and usage characteristics of the device in a virtual environment;
[0098] S24, fingerprint based on mutation protocol Hardware noise characteristics and virtualization layer resource allocation mode The three feature vectors are concatenated in sequence into a long vector, which is then fused into a three-dimensional feature vector. : ;
[0099] S25, based on three-dimensional feature vectors Device identification identifiers with spatiotemporal dynamics are generated through a spatiotemporal dynamic model. Identity identifier Considering the spatiotemporal variation characteristics of the equipment, it dynamically adjusts with changes in time and space to represent the unique identity of the equipment under different time and space conditions.
[0100] Identity identifier Based on three-dimensional feature vectors And the spatiotemporal dynamic model is generated, represented as:
[0101] ,in, Indicates time, It is the device in time The three-dimensional feature vector at time t, It is a spatiotemporal dynamic model, including time series analysis. Specifically, device identification is generated by spatiotemporal modeling of three-dimensional feature vectors. Specifically, it is expressed as follows:
[0102] ,in, express The number of feature dimensions in the data. express The number of feature dimensions in the data. express The number of feature dimensions in the data. Representing three-dimensional feature vectors The Middle One characteristic in time The value of time, It is the weight of that feature. It is a dynamic time bias term used to adjust for the influence of spatiotemporal factors, which changes over time. As time goes by, the three-dimensional feature vector of the equipment Changes will occur, resulting in changes to the device's identity. The dynamic changes of the device are taken into account, which increases the spatiotemporal dynamism of the identification.
[0103] S3 specifically includes:
[0104] S31, the heterogeneous protocol mapper interacts with the device's protocol stack to obtain the device's identity identifier in real time. and its confidence level ,in This indicates the credibility of the device's identity identifier;
[0105] S32, the heterogeneous protocol mapper is based on the confidence level of the device identity. Select the protocol transmission channel:
[0106] When confidence level Higher than the predetermined threshold (0.8) When a protocol encapsulation channel based on chaotic encryption is selected, the protocol is encrypted or obfuscated by a chaotic encryption algorithm to ensure that the data is difficult for attackers to identify, intercept or tamper with during transmission.
[0107] First, chaotic encryption generates a random chaotic sequence, typically using a chaotic mapping of the Logistic map to generate a key stream. These generated values are used as the encryption key. Next, the key stream is XORed bit by bit with the communication protocol data to encrypt or obfuscate the data. The encrypted data is then encapsulated in the obfuscated protocol format and transmitted over the network.
[0108] In addition to encrypting the data itself, chaotic encryption can also obfuscate the structure of the protocol, including adjusting the order and length of fields, making the structure and transmission process of the protocol more unpredictable and increasing security.
[0109] Finally, the receiver decrypts the encrypted data using the same chaotic algorithm and key stream to recover the original communication data.
[0110] When confidence level Higher than the predetermined threshold (0.8) Select a disguised transmission channel based on decoy data injection, inject false data during transmission, confuse potential attackers through disguise, and hide the real communication content.
[0111] Device identification in the protocol conversion gateway It will be matched against a predefined device feature database, which contains known feature vectors (three-dimensional feature vectors) of the device. The matching process is based on similarity calculations, and includes the corresponding identity identifier.
[0112] ,here, This represents the newly acquired device feature vector. Represents the feature vector of a known device, with a confidence level. The similarity is calculated based on the similarity of the matching results; the calculated similarity value is... Then the confidence level Normalization is performed in the following manner:
[0113] Thus, the confidence level The range of values is , where 0 indicates no match at all, and 1 indicates a perfect match.
[0114] S4 specifically includes:
[0115] S41, Adaptive decoy generator initialization: Deploy an adaptive decoy generator in the disguised transmission channel, analyze and map the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extract the potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact scope;
[0116] S42, Generate fake vulnerability features: The adaptive decoy generator generates fake vulnerability features based on the vulnerability feature library of the target device and the current network environment. The fake vulnerability features simulate actual vulnerabilities, but do not exist in the actual system, thereby misleading attackers and preventing them from launching attacks using real vulnerabilities.
[0117] S43, Constructing Protocol Payload: Embed the generated fake vulnerability features into the protocol payload, disguise it as normal vulnerability features, and transmit the protocol payload to the target device through the network. In the target device's protocol stack, it appears as a set of seemingly effective fake vulnerability features.
[0118] S44, Construct a data interaction sequence for a logical trap: Based on the vulnerability type, attack path, and vulnerability impact range of the target device, design a data interaction sequence with a logical trap to induce the attacker to mistakenly trigger a fake vulnerability. The data interaction sequence sends a decoy path with fake vulnerability characteristics through a disguised protocol payload to the attacker, inducing them to enter the logical trap.
[0119] Behavioral analysis probes monitor attackers' reactions when these decoy paths are triggered, capturing features such as memory modification patterns and path offsets to generate attack fingerprints. By capturing these attack fingerprints, the system can adjust its defense strategy in real time and continuously enhance security.
[0120] S5 specifically includes:
[0121] S51, Deployment of Behavioral Analysis Probe: Deploy a behavioral analysis probe between the physical network interface card and the virtual switching layer to monitor all data packets and data interaction sequences transmitted through the network in real time. This probe is located between the data link layer and the network layer and can perform in-depth analysis of the content, protocol characteristics and interaction patterns of data packets.
[0122] S52, Capturing Attacker Behavioral Characteristics: Through behavioral analysis probes, the system captures the attacker's actions after receiving a protocol payload containing false vulnerability characteristics. The probes can identify abnormal behavioral characteristics when the attacker attempts to trigger the vulnerability, including memory modification patterns and instruction execution path offsets.
[0123] S53, Attack Fingerprint Extraction: The behavioral analysis probe extracts the attacker's behavioral fingerprint based on the captured memory modification patterns and instruction execution path offsets. The behavioral fingerprint includes the exploit techniques used by the attacker, the attack path, and the attack payload. The attack fingerprint is represented as follows:
[0124] ,in, For the first The attack behavior characteristics include memory modification patterns, instruction execution path offsets, and malicious payloads;
[0125] S54, The Relationship Between Logic Traps and Decoy Paths: The attacker behavior captured by the behavioral analysis probe originates directly from the design of the decoy path. When attackers attempt to trigger fake vulnerabilities through logic traps, their behavior is exposed. The fake vulnerability is revealed through the protocol payload. and bait path The fake vulnerability features and decoy paths are transmitted to the target device and ultimately lure the attacker into the wrong attack path. Since the design of fake vulnerability features and decoy paths is based on the simulation of real vulnerability features, the attacker's reaction to these fake vulnerability features (such as memory modification and path offset) can serve as an early warning signal of real attack behavior, helping the security system to identify potential threats.
[0126] S55, Updates to Behavioral Fingerprinting and Dynamic Defense Strategies: Through extracted attack fingerprints The defense strategy is updated in real time. For example, these fingerprints can be input into an adversarial defense strategy generator to update the distortion parameters of the dynamic mutation engine, the key sequence of the protocol encapsulation channel, and the decoy data injection strategy, forming a continuously evolving defense mechanism.
[0127] Memory modification patterns include: When an attacker attempts to exploit a vulnerability, they may modify the memory contents of the target device, including changing buffers, data structures, or stack contents. By monitoring memory operations, probes can capture patterns of memory modification behavior.
[0128] Instruction execution path offset includes: attackers may change the normal execution path of a program by exploiting vulnerabilities, attempting to jump to the address of malicious code. Behavioral analysis probes capture the offset of the instruction execution path, that is, the abnormal jump of the instruction pointer during execution, to identify whether the attacker is trying to trigger buffer overflow or code injection attack methods.
[0129] S6 specifically includes:
[0130] S61, Input Attack Fingerprint: Enter the attack fingerprint Input into the adversarial defense strategy generator;
[0131] S62, Adversarial Defense Strategy Generation: Calculating Attack Strength Attack strength As a threat level of an attack, if Exceeding the set threshold ( Within the normalization range [0,1], A value between 0.5 and 0.7 triggers a dynamic defense update. ,in, It is the weight of the attack fingerprint feature, which measures its contribution to the security threat;
[0132] Dynamic defense updates specifically include:
[0133] S63, synchronously updates the distortion parameters of the dynamic mutation engine: adjusts the distortion strategy of the dynamic mutation engine based on the latest attack fingerprint.
[0134] Update the dynamic adjustment rules for protocol fields, including the range of field length variations. And parity bit distortion factor :
[0135] ;
[0136] ;
[0137] in and Calculations based on adversarial defense strategies show that enhancing the randomness of the protocol structure makes it difficult for attackers to establish fixed attack patterns.
[0138] 1. Calculate the incremental adjustment of protocol field length. To prevent attackers from using fixed protocol structures to perform pattern matching attacks:
[0139] Suppose that the protocol field length variation feature recorded in the attack fingerprint is: ,in Representing the A fixed field length value that an attacker attempted to exploit;
[0140] Calculate the average length of the fields most frequently exploited by attackers: ;
[0141] Let the security adjustment range of the current protocol field be... Then adjust the increment. The calculation is as follows:
[0142] ,in, It is an adaptive adjustment coefficient, dynamically adjusted based on historical attack intensity, with a value ranging from 0.1 to 0.3. near The upper limit means that attackers are targeting the length of protocol fields, and the system needs to increase the distortion amplitude.
[0143] 2. Calculate the adjustment increment for the parity bit distribution. To prevent attackers from exploiting protocol verification mechanisms to tamper with data or bypass verification attacks:
[0144] Let the distribution characteristics of the check bits recorded in the attack fingerprint be as follows: ,in Representing the A checksum pattern that an attacker attempted to exploit;
[0145] Calculate the average parity bit most commonly used by attackers: ;
[0146] Assume the security check bit distribution range of the protocol is as follows: Then adjust the increment. The calculation is as follows:
[0147] ,in, This is an adaptive adjustment coefficient, ranging from 0.2 to 0.5, which determines the sensitivity of the check bit adjustment. If an attacker is detected tampering with a specific check bit, the system will increase the sensitivity. Disrupt the fixed pattern of the check bits.
[0148] like Figure 2 As shown, a novel network information security defense system, used to implement the aforementioned network information security defense method, includes the following modules:
[0149] The dynamic mutation engine, deployed at the bottom layer of the network protocol stack, is used to collect the feature fingerprints of communication protocols in real time and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutated protocol fingerprints.
[0150] The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the mutation protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and to generate a device identity identifier with spatiotemporal dynamics based on the three-dimensional feature vector.
[0151] The protocol conversion gateway, including a heterogeneous protocol mapper, dynamically selects either a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection, according to the confidence level of the device identity.
[0152] An adaptive decoy generator, embedded in a disguised transmission channel, generates a protocol payload containing fake vulnerability features based on the target device's vulnerability signature library, and constructs a data interaction sequence with logical traps;
[0153] Behavioral analysis probes are deployed between the physical network interface card and the virtual switching layer to capture the attacker's triggering behavior characteristics of logical traps and extract attack fingerprints, including memory modification patterns and instruction execution path offsets.
[0154] An adversarial defense strategy generator is used to receive attack fingerprints and synchronously update the distortion parameters of the dynamic mutation engine to ensure that the defense strategy can be dynamically adjusted and realize a continuously evolving security defense mechanism.
[0155] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0156] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A novel network information security defense method, characterized in that, Includes the following steps: S1. Inject a dynamic mutation engine into the bottom layer of the network protocol stack, collect the characteristic fingerprints of the communication protocol in real time, generate random mutation factors through quantum noise sources, and dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutated protocol fingerprints. S2. Based on the mutation protocol fingerprint, and simultaneously integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, a three-dimensional feature vector is formed, and a device identity identifier with spatiotemporal dynamics is generated based on the three-dimensional feature vector. S3. Deploy a heterogeneous protocol mapper in the protocol conversion gateway, and dynamically select a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection according to the confidence level of the device identity identifier. The protocol encapsulation channel encrypts or obfuscates the original protocol. S4. An adaptive decoy generator is embedded in the disguised transmission channel to generate a protocol payload including fake vulnerability features based on the vulnerability feature library of the target device, and to construct a data interaction sequence with logical traps. S5. By deploying a behavior analysis probe between the physical network card and the virtual switching layer, capture the attacker's triggering behavior characteristics of the logical trap and extract attack fingerprints including memory modification patterns and instruction execution path offsets. S6. Input the attack fingerprint into the adversarial defense strategy generator and update the distortion parameters of the dynamic mutation engine simultaneously.
2. The novel network information security defense method according to claim 1, characterized in that, S1 specifically includes: S11, located between the data link layer and the network layer of the network protocol stack, collects the characteristic fingerprints of the communication protocol by performing real-time analysis and modification of the transmitted data packets. This includes protocol field length, checksum distribution, and handshake timing characteristics; S12 generates a random mutation factor through a quantum noise source. This random mutation factor includes random numbers and noise signals, which are used to perform distortion operations on the communication protocol fields. S13, the distortion operation includes dynamically adjusting the protocol field length, checksum distribution, and handshake timing characteristics, disrupting the original fixed pattern in the protocol, and generating a mutated protocol fingerprint with mutation properties. The variant protocol fingerprint is used to describe the data packet characteristics of the modified protocol.
3. The novel network information security defense method according to claim 2, characterized in that, S2 specifically includes: S21, Obtain the mutation protocol fingerprint ; S22, acquire hardware noise features through the physical layer feature acquisition module. This includes electromagnetic interference and thermal noise generated during equipment operation; S23, obtain resource call patterns through monitoring of the virtualization layer. This includes CPU load and network bandwidth consumption; S24, fingerprint based on mutation protocol Hardware noise characteristics and virtualization layer resource allocation mode fused into a three-dimensional feature vector : ; S25, based on three-dimensional feature vectors Device identification identifiers with spatiotemporal dynamics are generated through a spatiotemporal dynamic model. The identity identifier Considering the spatiotemporal variation characteristics of the equipment, it dynamically adjusts with changes in time and space to represent the unique identity of the equipment under different time and space conditions.
4. A novel network information security defense method according to claim 3, characterized in that, The identity identifier Based on three-dimensional feature vectors And the spatiotemporal dynamic model is generated, represented as: ,in, Indicates time, It is the device in time The three-dimensional feature vector at time t, It is a spatiotemporal dynamic model, including time series analysis. Specifically, it is expressed as follows: ,in, express The number of feature dimensions in the data. express The number of feature dimensions in the data. express The number of feature dimensions in the data. Representing three-dimensional feature vectors The Middle One characteristic in time The value of time, It is the weight of that feature. It is a dynamic time bias term used to adjust for the influence of spatiotemporal factors, which changes over time. As time goes by, the three-dimensional feature vector of the equipment Changes will occur, resulting in changes to the device's identity. The dynamic changes.
5. A novel network information security defense method according to claim 1, characterized in that, S3 specifically includes: S31, the heterogeneous protocol mapper interacts with the device's protocol stack to obtain the device's identity identifier in real time. and its confidence level ,in This indicates the credibility of the device's identity identifier; S32, the heterogeneous protocol mapper is based on the confidence level of the device identity. Select the protocol transmission channel: When confidence level Higher than the predetermined threshold When this is the case, a protocol encapsulation channel based on chaotic encryption is selected. The protocol is encrypted or obfuscated using a chaotic encryption algorithm to ensure that the data is difficult for attackers to identify, intercept or tamper with during transmission. When confidence level Higher than the predetermined threshold At that time, a fake transmission channel based on decoy data injection is selected, and false data is injected during the transmission process to confuse potential attackers and hide the real communication content.
6. A novel network information security defense method according to claim 1, characterized in that, S4 specifically includes: S41, Adaptive decoy generator initialization: Deploy an adaptive decoy generator in the disguised transmission channel, analyze and map the known vulnerabilities of the target device based on the vulnerability feature library of the target device, and extract the potential vulnerability features of the target device, including vulnerability type, attack path, and vulnerability impact scope; S42, Generate false vulnerability features: The adaptive decoy generator generates false vulnerability features based on the vulnerability feature library of the target device and the current network environment. The false vulnerability features simulate actual vulnerabilities to mislead attackers and prevent them from launching attacks using real vulnerabilities. S43, Construct Protocol Payload: Embed the generated fake vulnerability features into the protocol payload, disguise it as normal vulnerability features, and transmit the protocol payload to the target device through the network. In the target device's protocol stack, it appears as a set of fake vulnerability features. S44, Construct a data interaction sequence for a logical trap: Based on the vulnerability type, attack path, and vulnerability impact range of the target device, design a data interaction sequence with a logical trap to induce the attacker to mistakenly trigger a fake vulnerability. The data interaction sequence sends a decoy path with fake vulnerability characteristics through a disguised protocol payload to the attacker, inducing them to enter the logical trap.
7. A novel network information security defense method according to claim 1, characterized in that, S5 specifically includes: S51, Deployment of Behavioral Analysis Probes: Deploy behavioral analysis probes between the physical network interface card and the virtual switching layer to monitor all data packets and data interaction sequences transmitted through the network in real time; S52, Capturing Attacker Behavioral Characteristics: Through behavioral analysis probes, the attacker's actions after receiving a protocol payload containing false vulnerability characteristics are captured. The probes can identify abnormal behavioral characteristics when the attacker attempts to trigger the vulnerability, including memory modification patterns and instruction execution path offsets. S53, Attack Fingerprint Extraction: The behavioral analysis probe extracts the attacker's behavioral fingerprint based on the captured memory modification patterns and instruction execution path offsets. The behavioral fingerprint includes the exploit techniques used by the attacker, the attack path, and the attack payload. The attack fingerprint is represented as follows: ,in, For the first The attack behavior characteristics include memory modification patterns, instruction execution path offsets, and malicious payloads; S54, The Relationship Between Logic Traps and Decoy Paths: The attacker behavior captured by the behavioral analysis probe directly originates from the design of the decoy path. When an attacker attempts to trigger a false vulnerability through a logic trap, the false vulnerability is triggered via protocol payload. and bait path It is transmitted to the target device, ultimately luring the attacker into the wrong attack path; S55, Updates to Behavioral Fingerprinting and Dynamic Defense Strategies: Through extracted attack fingerprints , and update defense strategies in real time.
8. A novel network information security defense method according to claim 7, characterized in that, The memory modification patterns include: when an attacker attempts to exploit a vulnerability, they will modify the memory content of the target device, including changing the buffer, data structure, or stack content. By monitoring memory operations, the probe can capture the memory modification behavior patterns. The instruction execution path offset includes: attackers can change the normal execution path of the program by exploiting vulnerabilities, attempting to jump to the address of malicious code, and the behavioral analysis probe captures the offset of the instruction execution path.
9. A novel network information security defense method according to claim 7, characterized in that, S6 specifically includes: S61, Input Attack Fingerprint: Enter the attack fingerprint Input into the adversarial defense strategy generator; S62, Adversarial Defense Strategy Generation: Calculating Attack Strength Attack strength As a threat level of an attack, if Exceeding the set threshold This triggers a dynamic defense update; S63, synchronously updates the distortion parameters of the dynamic mutation engine: adjusts the distortion strategy of the dynamic mutation engine based on the latest attack fingerprint. Update the dynamic adjustment rules for protocol fields, including the range of field length variations. And parity bit distortion factor : ; ; in and Calculations based on adversarial defense strategies show that enhancing the randomness of the protocol structure makes it difficult for attackers to establish fixed attack patterns.
10. A novel network information security defense system, used to implement the novel network information security defense method as described in any one of claims 1-9, characterized in that, Includes the following modules: The dynamic mutation engine, deployed at the bottom layer of the network protocol stack, is used to collect the feature fingerprints of communication protocols in real time and generate random mutation factors through quantum noise sources to dynamically distort the protocol field length, check bit distribution and handshake timing characteristics to generate mutated protocol fingerprints. The multimodal device fingerprint generation module is used to form a three-dimensional feature vector based on the mutation protocol fingerprint, while integrating the physical layer hardware noise characteristics and the virtualization layer resource call mode, and to generate a device identity identifier with spatiotemporal dynamics based on the three-dimensional feature vector. The protocol conversion gateway, including a heterogeneous protocol mapper, dynamically selects either a protocol encapsulation channel based on chaotic encryption or a disguised transmission channel based on decoy data injection, according to the confidence level of the device identity. An adaptive decoy generator, embedded in a disguised transmission channel, generates a protocol payload containing fake vulnerability features based on the target device's vulnerability signature library, and constructs a data interaction sequence with logical traps; Behavioral analysis probes are deployed between the physical network interface card and the virtual switching layer to capture the attacker's triggering behavior characteristics of logical traps and extract attack fingerprints, including memory modification patterns and instruction execution path offsets. An adversarial defense strategy generator is used to receive attack fingerprints and synchronously update the distortion parameters of the dynamic mutation engine.
Citation Information
Patent Citations
Power grid industrial control protocol vulnerability mining system adopting fuzzy test
CN117640199A
Method and system for data stream analysis
US20240406274A1