Network security threat information monitoring management system and method
Through the dynamic cellular encryption engine and causal reinforcement learning decision-maker, encrypted data packets carrying spatiotemporal chaos characteristics are generated and expected attack suppression ratios are calculated, which solves the problem of failure to effectively identify unknown attacks and encrypted traffic threats in the existing technology, and realizes efficient security analysis of network traffic and dynamic deployment of defense strategies.
Patent Information
- Application Number
- CN202510541056.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-28
AI Technical Summary
The prior art has shortcomings in dealing with unknown attacks and detection of encrypted traffic threats, especially inadequate recognition capabilities for emerging or mutated attacks. The accuracy and efficiency of abnormal behavior analysis are limited by the quality of training data and the degree of algorithm optimization, which is prone to false positives or missed reports.
By capturing the original traffic data in real time, inputting it into the dynamic cell encryption engine, generating encrypted data packets carrying spatiotemporal chaos characteristics, and decrypting and restoring the data packets using the pre-shared initial cell state matrix to extract three-dimensional threat indicators. The causal topology graph is constructed based on these indicators, and the causal reinforcement learning decision-maker is used to calculate the expected attack suppression ratio of different defense actions, generate dynamic defense strategies, and finally deploy the policy to network devices through the software-defined network control plane.
It realizes highly secure encryption of network traffic and associated encryption of threat intelligence fields, enhances the security and analysis capabilities of data transmission, effectively responds to unknown attacks and threats in encrypted traffic, and realizes accurate positioning and efficient response to potential threats in the network, and optimizes the effectiveness and targeting of defense measures.
Smart Images

Figure CN120074958A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network security, and particularly to a network security threat information monitoring and management system and method. Background Art
[0002] As a key technical field for ensuring network environment security, intrusion detection systems (IDS) and intrusion prevention systems (IPS) are traditional methods widely used to identify and prevent malicious activities. They mainly rely on signature database matching and abnormal behavior analysis to detect potential security threats. Signature database matching quickly locates and responds to known threats by comparing network traffic with a signature database of known attack patterns; while abnormal behavior analysis is based on machine learning algorithms, which establish a model through learning normal network behaviors to identify behaviors deviating from the norm as potential threats.
[0003] However, although intrusion detection systems (IDS) and intrusion prevention systems (IPS) have played an important role in enhancing network security, there are still deficiencies: First, signature database matching highly depends on the update speed of known attack patterns and lacks effective recognition ability for newly emerged or mutated attacks. This means that even the most advanced signature database is difficult to cover all types of threats, resulting in the network being exposed to the risk of unknown attacks. Second, although abnormal behavior analysis can discover new threats to a certain extent, its accuracy and efficiency are limited by the quality of training data and the optimization level of algorithms, and false alarms or missed alarms are likely to occur. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network security threat information monitoring and management method to solve the deficiencies of the prior art in dealing with unknown attacks and encrypted traffic threat detection.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a method for monitoring and managing network security threat information, which includes: capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; using a pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets, and extracting three-dimensional threat indicators; based on the three-dimensional threat indicators, constructing a causal topology graph reflecting the service dependency relationship of nodes, and inputting it into a causal reinforcement learning decision maker, calculating the expected attack suppression ratio of different defense actions through counterfactual intervention simulation, and generating a dynamic defense strategy; converting the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane, and incrementally deploying the flow entries to target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.
[0008] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the step of inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics is as follows.
[0009] Input the raw traffic data set with threat labels into a dynamic cellular encryption engine.
[0010] Perform real-time determination of the attack warning level in the input buffer of the dynamic cellular encryption engine.
[0011] Select a cellular evolution rule from a predefined rule library according to the current attack warning level.
[0012] Perform associated encryption on the threat intelligence fields in the raw traffic data based on the Moore neighborhood topology of the selected cellular evolution rule to generate encrypted data packets carrying spatio-temporal chaos characteristics.
[0013] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the step of using a pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets and extract three-dimensional threat indicators is as follows.
[0014] Transmit the encrypted data packets to a central analysis node through a point-to-point secure channel.
[0015] Use the pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets at the central analysis node.
[0016] Extract three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency association degree from the decrypted and restored encrypted data packets.
[0017] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the step of constructing a causal topology graph reflecting the service dependency relationship of nodes based on the three-dimensional threat indicators is as follows.
[0018] Perform temporal alignment and verification on the three-dimensional threat indicators, and obtain the node threat value through non-linear fusion;
[0019] Based on the node threat value, construct a causal topology graph through directed graph construction and critical attack path identification;
[0020] Mark the critical attack path of the causal topology graph to generate a causal topology graph reflecting the node service dependency relationship.
[0021] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the simulation calculation of the expected attack suppression ratio of different defense actions through counterfactual intervention is as follows,
[0022] Based on the causal topology graph reflecting the node service dependency relationship, generate a candidate defense action set including blocking actions and cleaning actions;
[0023] According to the blocking actions in the candidate defense action set, perform virtual blocking simulation through single-node blocking and multi-node joint blocking to generate the node expected attack suppression ratio;
[0024] According to the cleaning actions in the candidate defense action set, perform virtual traffic cleaning simulation through unilateral cleaning and multi-lateral joint cleaning to generate the unilateral cleaning utility;
[0025] Perform weighted fusion on the node expected attack suppression ratio and the unilateral cleaning utility to generate the expected attack suppression ratio.
[0026] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the generation of the dynamic defense strategy includes a target blocking node list and a traffic cleaning weight.
[0027] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the original traffic data set with threat labels is specifically,
[0028] Perform sharding processing on the captured original traffic data to obtain data blocks;
[0029] Based on a predefined protocol feature library, perform protocol feature identification on the data blocks to obtain threat intelligence fields;
[0030] According to the threat intelligence fields, perform dynamic threat label marking to generate an original traffic data set with threat labels.
[0031] In a second aspect, the present invention provides a network security threat information monitoring and management system, including a traffic encryption module for capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; a threat extraction module for decrypting and restoring the encrypted data packets using a pre-shared initial cellular state matrix and extracting three-dimensional threat indicators; a policy generation module for constructing a causal topology graph reflecting the node service dependency relationship based on the three-dimensional threat indicators and inputting it into a causal reinforcement learning decision maker to generate a dynamic defense policy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention; and a defense deployment module for converting the dynamic defense policy into timestamp-tagged OpenFlow flow entries through a software-defined network control plane and incrementally deploying the flow entries to target network devices based on the time-sensitive queue mechanism of a P4 programmable switch.
[0032] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the network security threat information monitoring and management method described in the first aspect of the present invention is implemented.
[0033] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the network security threat information monitoring and management method described in the first aspect of the present invention is implemented.
[0034] The beneficial effects of the present invention are as follows: By inputting raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics, high-security encryption of network traffic and associated encryption of threat intelligence fields are achieved, enhancing the security and analysis ability of data transmission and effectively coping with unknown attacks and threats in encrypted traffic. Then, based on the extracted three-dimensional threat indicators, a causal topology graph reflecting the node service dependency relationship is constructed, and a causal reinforcement learning decision maker is used to calculate the expected attack suppression ratio of different defense actions to generate a dynamic defense policy, realizing the precise positioning and efficient response to potential threats in the network and optimizing the effectiveness and pertinence of defense measures. It not only improves the overall protection ability of network security but also significantly enhances the adaptive defense ability in the face of complex and changing threats. Description of the Drawings
[0035] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0036] Figure 1 It is a flowchart of a method for monitoring and managing network security threat information.
[0037] Figure 2 It is a flowchart of dynamic cellular encryption.
[0038] Figure 3 It is a flowchart of decryption and three-dimensional threat index extraction.
[0039] Figure 4 It is a flowchart of defense strategy generation.
[0040] Figure 5 It is a flowchart of defense strategy deployment. Specific implementation manners
[0041] To make the above objects, features and advantages of the present invention more obvious and understandable, the specific implementation manners of the present invention will be described in detail below with reference to the accompanying drawings of the specification.
[0042] In the following description, many specific details are set forth to facilitate a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein, and those skilled in the art may make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0043] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure or characteristic that may be included in at least one implementation manner of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that exclude each other from other embodiments.
[0044] Referring to Figures 1 to 5 , which is an embodiment of the present invention. This embodiment provides a method for monitoring and managing network security threat information, including the following steps:
[0045] S1: Real-time capture of original network traffic data, input the original traffic data into the dynamic cellular encryption engine to generate encrypted data packets with spatio-temporal chaos characteristics;
[0046] S1.1: Deploy data probes at network edge nodes to real-time capture original traffic data and perform preprocessing;
[0047] S1.1.1: Deploy data probes at network edge nodes to real-time capture original traffic data;
[0048] Furthermore, deploy a dedicated processing unit at the mirror port of the network edge node, configure mirroring rules to capture bidirectional network traffic passing through the specified physical interface, filter non-target protocol data units, and retain the original traffic data containing transport layer and higher layer protocol characteristics.
[0049] S1.1.2: Fragment the captured original traffic data to obtain data blocks;
[0050] Fragment the captured original traffic data according to a fixed time window. The original traffic data captured within each time window is encapsulated into an independent data block, and a time marker field is appended to the head of each data block to record the start and end capture times and the data block sequence number.
[0051] S1.1.3: Identify protocol features of the data blocks based on a predefined protocol feature library;
[0052] Perform a parallel scan of the data blocks based on a predefined protocol feature library to identify data units containing specific protocol header features, extract the transport layer protocol header and the start part of the payload, and mark the fields containing hypertext transfer protocol request lines, domain name resolution requests, and secure socket layer handshake information as threat intelligence fields.
[0053] S1.1.4: Perform dynamic threat label marking according to the protocol feature identification results;
[0054] According to the protocol feature scan results, add threat labels to the threat intelligence fields containing structured query language injection features, cross-site scripting attack features, and known malicious domain name requests. The threat labels include attack type identifiers and confidence scores, forming an original traffic data set with threat labels.
[0055] S1.1.5: Preprocess the data blocks after dynamic threat label marking;
[0056] Perform a byte alignment operation on the data blocks of the original traffic data set with threat labels, and fill in redundant bytes to meet the minimum data unit requirements for encryption processing, generating standardized original traffic data to provide a uniformly formatted input for subsequent encryption processing.
[0057] It should be noted that the requirements for the minimum data unit of encryption processing are specifically manifested as follows: when the data block length of the original traffic data set with threat tags is not an integer multiple of the encryption algorithm block length (for example, the AES-128 encryption algorithm requires 16-byte alignment), redundant bytes are appended at the end of the data block using the PKCS#7 padding rule (the value of the redundant byte = the number of padding bytes), so that the data block length is extended to the nearest integer multiple of the block length that is not less than the original length (if the original length of the data block is 23 bytes, 1 byte 0x01 is padded to make it 24 bytes); for data blocks whose length already meets the integer multiple of the block length, a complete padding block still needs to be forcibly appended (for example, a 16-byte data block needs to append 16 bytes 0x10), and finally standardized original traffic data is generated to ensure that the length of all data blocks is an integer multiple of the encryption algorithm block length, meeting the unified requirements of the encryption processing for the input data format.
[0058] S1.2: Input the original traffic data into the dynamic cellular encryption engine, and select the cellular evolution rule from the predefined rule library according to the current attack alert level;
[0059] S1.2.1: Input the standardized original traffic data into the dynamic cellular encryption engine;
[0060] Write the standardized original traffic data into the input buffer of the dynamic cellular encryption engine in sequence. The buffer adopts a dual-channel ping-pong structure to ensure continuous and uninterrupted data input;
[0061] Establish an input queue index according to the time stamp field of the data block to maintain the temporal integrity of the data block.
[0062] S1.2.2: Perform real-time determination of the attack alert level in the input buffer of the dynamic cellular encryption engine;
[0063] In the sliding time window, count the proportion of data blocks including SQL injection tags, the continuous occurrence times of data blocks with cross-site scripting attack tags, and the distribution density of data blocks with malicious domain name request tags, and calculate the comprehensive threat index. The expression is:
[0064] ;
[0065] Among them, is the comprehensive threat index, is the proportion of data blocks with SQL injection tags, is the continuous occurrence times of data blocks with cross-site scripting attack tags, is the distribution density of data blocks with malicious domain name request tags, is the cross-site scripting continuity index, is the malicious domain name density gain coefficient, is the malicious domain name suppression factor, is the continuous attack saturation coefficient, the base of the natural logarithm;
[0066] Set the low-risk threshold and medium-risk threshold according to historical data, and perform real-time determination of the attack warning level;
[0067] It should be noted that according to the distribution of the frequency, intensity, and duration indicators of attack events in historical data, the statistical quantile method is used to set the low-risk threshold (for example, taking the 30th percentile value of historical indicators as the low-risk threshold) and the medium-risk threshold (for example, taking the 70th percentile value of historical indicators as the medium-risk threshold); in the process of real-time determination of the attack warning level, if the current attack indicator exceeds the low-risk threshold but does not reach the medium-risk threshold, it is marked as a low-risk warning, and if it exceeds the medium-risk threshold, it is marked as a medium-risk warning; when a single attack event simultaneously triggers multiple indicators to exceed the corresponding medium-risk threshold, it is superimposed and determined as a medium-risk warning, and the determination result is dynamically associated with the latest 30-day historical data through a sliding window mechanism for threshold verification to ensure that the warning level is synchronized with the characteristics of historical data.
[0068] When the comprehensive threat index is less than or equal to the low-risk threshold, it is determined as the low-risk level;
[0069] When the comprehensive threat index is greater than the low-risk threshold and less than or equal to the medium-risk threshold, it is determined as the medium-risk level;
[0070] When the comprehensive threat index is greater than the medium-risk threshold, it is determined as the high-risk level.
[0071] S1.2.3: Select the cellular evolution rule from the predefined rule library according to the current attack warning level;
[0072] The predefined rule library contains three types of evolution rules, corresponding to encryption logic and three attack warning levels respectively;
[0073] Among them, the encryption logic for the high-risk level is multi-round non-linear bit operations and diffusion confusion, the medium-risk level is single-round displacement and exclusive OR mixed operations, and the low-risk level is basic exclusive OR and permutation operations;
[0074] Load the corresponding rule from the rule library to the encryption engine operation unit according to the real-time warning level.
[0075] S1.3: Perform associated encryption on the threat intelligence fields in the original traffic data based on the Moore neighborhood topology of the selected cellular evolution rule to generate encrypted data packets with spatio-temporal chaos characteristics;
[0076] S1.3.1: Through data block matrix conversion and mirror edge filling, perform matrix reconstruction of the threat intelligence fields;
[0077] Extract the data block of threat tags from the standardized original traffic data, and convert the data block into a two-dimensional byte matrix according to the predefined number of rows (determined by the hardware architecture of the dynamic cellular encryption engine);
[0078] Perform a mirror padding operation on the boundary area of the two-dimensional byte matrix, specifically:
[0079] Fill the content of the last row above the first row;
[0080] Fill the content of the first row below the last row;
[0081] Fill the content of the last column to the left of the first column;
[0082] Fill the content of the first column to the right of the last column;
[0083] Ensure that all elements of the two-dimensional byte matrix have a complete Moore neighborhood context.
[0084] S1.3.2: For the reconstructed threat intelligence field, perform rule-driven bit operations on each element in the two-dimensional byte matrix according to the cellular evolution rules, and perform multiple rounds of iterative processing;
[0085] It should be noted that when the attack alarm level is a high-risk level, load the multi-round non-linear bit operations and diffusion confusion rules in the predefined rule library, perform non-linear bit operations on each element in the two-dimensional byte matrix and the byte values of the eight adjacent elements in the Moore neighborhood, and perform diffusion confusion based on the weighted exclusive OR result of the neighborhood values; when the attack alarm level is a medium-risk level, perform a single-round displacement and exclusive OR hybrid operation rule, shift each element in the two-dimensional byte matrix to the right by 3 bits and then perform an exclusive OR operation with the byte value of the element in the center column of the Moore neighborhood; when the attack alarm level is a low-risk level, perform the basic exclusive OR and permutation operation rules, perform an exclusive OR operation on each element in the two-dimensional byte matrix with the predefined mask byte, and perform a cyclic left shift permutation by row; after each evolution rule is executed, use the updated two-dimensional byte matrix as the input for multiple rounds of iterative processing (3 rounds of iteration for high-risk level, 1 round of iteration for medium-risk level, no iteration for low-risk level) until the termination condition defined in the rule library is reached.
[0086] For example, when the attack alarm level is a high-risk level, obtain the byte values of the current element and the Moore neighborhood, perform non-linear bit operations, and append a cyclic shift operation.
[0087] S1.3.3: Perform spatio-temporal chaos feature injection through timestamp perturbation superposition and chaos intensity verification;
[0088] Extract the last byte from the data block time stamp field as the perturbation factor, perform an exclusive OR operation on the specified diagonal elements of the encrypted two-dimensional byte matrix, and calculate the avalanche effect value of the encrypted two-dimensional byte matrix: count the bit change rate of the corresponding bytes before and after encryption. If the bit change rate is lower than the bit change rate threshold, add an additional random perturbation to the matrix central region (random number generator seed = hash value of the time stamp field).
[0089] It should be noted that the last byte is extracted from the data block time stamp field and used as the perturbation factor to perform an exclusive OR operation on the main diagonal elements of the encrypted two-dimensional byte matrix; count the number of bit changes for each byte in the two-dimensional byte matrix before and after encryption, calculate the total bit change rate (total number of changed bits / (number of matrix rows × number of matrix columns × 8)), set the bit rate change threshold according to historical data. If the bit change rate is lower than the bit change rate threshold, add an additional random perturbation to the matrix central region: use a random number generator (the first 32 bits of the SHA-256 hash value of the data block time stamp field as the seed) to generate a random byte sequence, and perform an exclusive OR operation on each element in the central region until the recalculated bit change rate ≥ the change threshold, completing the injection of spatio-temporal chaos characteristics.
[0090] S1.3.4: Encapsulate the encrypted data packet and perform integrity check encapsulation through matrix serialization and recombination to generate an encrypted data packet carrying spatio-temporal chaos characteristics;
[0091] Convert the encrypted two-dimensional byte matrix into a continuous byte stream in column-major order, retain the original protocol header information (source / destination address, port number), and insert an encrypted metadata field at the start position of the payload;
[0092] Calculate the CRC32 checksum of the encrypted data stream and append it to the end of the data packet to form the final output encrypted data packet.
[0093] S2: Use the pre-shared initial cellular state matrix to decrypt and restore the encrypted data packet and extract three-dimensional threat indicators;
[0094] S2.1: Transmit the encrypted data packet through a point-to-point secure channel to the central analysis node, and use the pre-shared initial cellular state matrix to decrypt and restore the encrypted data packet at the central analysis node;
[0095] S2.1.1: Transmit the encrypted data packet through a point-to-point secure channel to the central analysis node;
[0096] Use a pre-shared key negotiation protocol to establish a two-way authenticated communication link between the edge node and the central analysis node, and negotiate a session key for encrypted data packet transmission;
[0097] It should be noted that the transmission channel is configured in exclusive mode, and only data packets carrying encrypted metadata fields (rule number, number of iterations, chaos intensity value) are allowed to pass through;
[0098] Write the generated encrypted data packets into the transmission queue in the order of the time stamp field, and send them to the central analysis node through the secure channel;
[0099] Each encrypted data packet is attached with a transmission sequence number and a time stamp hash value to ensure transmission integrity.
[0100] S2.1.2: At the central analysis node, use the pre-shared initial cellular state matrix to perform decryption and restoration on the encrypted data packets;
[0101] The central analysis node loads the pre-shared initial cellular state matrix, which contains a rule number mapping table consistent with that of the edge node and a chaos perturbation factor generation algorithm;
[0102] It should be noted that the pre-shared initial cellular state matrix is generated by the communication parties through the pre-shared key negotiation protocol before establishing a connection. The matrix dimension is fixed at 128x128, and each cellular state value is 0 or 1. The initial state is filled with a chaos sequence generated based on the Logistic map (parameter μ = 3.99); the pre-shared initial cellular state matrix is periodically updated during the communication process following the cellular automaton evolution rule (a state update function combining the von Neumann neighbor mode and XOR logic), and the update period is bound to the modulo operation result of the last 4 bits of the UTC time stamp (for example, when the last bit of the time stamp is 5, an update is triggered); the integrity of the pre-shared initial cellular state matrix is verified by generating a digest through the SHA-256 hash algorithm and performing a bit-by-bit comparison with the MAC value attached to the encrypted data packet to ensure that the pre-shared initial cellular state matrix has not been tampered with during transmission.
[0103] Extract the rule number, number of iterations, and chaos intensity value from the encrypted data packet header;
[0104] Reconstruct the encrypted data packet into a two-dimensional byte matrix in column-major order;
[0105] Perform multiple rounds of decryption according to the inverse operation logic corresponding to the rule number, and remove the time stamp perturbation (perform an XOR operation on the diagonal elements of the matrix);
[0106] Convert the decrypted two-dimensional matrix into a continuous byte stream in row-major order, remove the padding bytes and redundant fields, and restore the original threat intelligence field structure;
[0107] Verify the consistency of the CRC32 value with the packet tail field, and discard the packets that fail the verification.
[0108] S2.2: Extract three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency correlation degree from the restored data;
[0109] Statistically calculate the deviation degree between the protocol header fields in the decrypted data block and the predefined protocol feature library as the protocol type anomaly coefficient;
[0110] Perform autoregressive modeling (AR model) on the request time series in the decrypted data block and calculate the residual variance as the behavior sequence deviation degree;
[0111] Construct a service call graph and calculate the Pearson correlation coefficient between the node betweenness centrality and the threat label as the service dependency correlation degree.
[0112] S3: Based on the three-dimensional threat indicators, construct a causal topology graph reflecting the node service dependency relationship, input it into the causal reinforcement learning decision maker, and generate a dynamic defense strategy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention;
[0113] S3.1: Based on the three-dimensional threat indicators, construct a causal topology graph reflecting the node service dependency relationship;
[0114] S3.1.1: Align and verify the three-dimensional threat indicators in time series, and obtain the node threat value through non-linear fusion;
[0115] Align the protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency correlation degree in time series according to the time stamp field of the data block to ensure that the three indicators of the same node correspond to the same time window;
[0116] Verify the integrity of the three-dimensional threat indicators, discard the data blocks missing any indicator, and record the abnormal node identifiers;
[0117] For each network node, calculate the product of the protocol type anomaly coefficient, the square root of the behavior sequence deviation degree, and the service dependency correlation degree to generate the node threat value.
[0118] S3.1.2: Construct a causal topology graph reflecting the node service dependency relationship;
[0119] Construct a causal topology graph through directed graph construction and critical attack path identification, and perform critical attack path marking to generate a causal topology graph reflecting the node service dependency relationship;
[0120] Specifically, based on protocol features, extract the service call relationships between nodes. All network entities with service call relationships are used as the node set. All service call relationships with weights meeting the standard are used as the edge set. A directed graph is constructed through the node set and the edge set as the causal topology graph. Based on depth-first search traversal of the causal topology graph, key attack paths are marked. In the causal topology graph, service call relationships with a service dependency correlation degree exceeding the service dependency threshold (e.g., service dependency correlation degree ≥ 0.7) are used as the edge set, and combined with the node threat value (the product of the protocol type anomaly coefficient, the square root of the behavior sequence deviation degree, and the service dependency correlation degree) as the node weight. Use depth-first search to traverse the causal topology graph, starting from nodes with a node threat value ≥ high-risk threshold (e.g., the 90th percentile of historical data), and perform path detection along the edges with service dependency correlation degrees meeting the standard. When the sum of the cumulative node threat values of the path exceeds the path threat threshold (e.g., cumulative value ≥ 50) and the path length ≤ the maximum allowed number of hops (e.g., 3 hops), mark this path as a key attack path. The key attack path needs to simultaneously satisfy that the end of the path points to key service nodes (such as database servers, authentication gateways), and edges with service dependency correlation degrees lower than the threshold are dynamically excluded during the traversal process. The finally generated key attack paths are written into the edge attribute field of the causal topology graph.
[0121] It should be noted that the service call relationships with weights meeting the standard are generated by calculating the initial dependency strength of the edges and fusing the node threat values to generate the edge weights. The edge weight threshold is set according to historical data. When the edge weight is greater than the edge weight threshold, it is determined that the weight meets the standard. The specific method for setting the edge weight threshold according to historical data is: by statistically analyzing the weight value distribution of all edges in historical data, the edge weight threshold is set to the 90th percentile of the historical edge weights.
[0122] S3.2: Generate a dynamic defense strategy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention;
[0123] S3.2.1: Generate a set of candidate defense actions based on the causal topology graph reflecting the service dependency relationships of nodes;
[0124] The set of candidate defense actions includes blocking actions and cleaning actions. From the list sorted in descending order of node threat values, select the node set with a cumulative threat value proportion exceeding 60% of the total threat value as the candidate blocking target, defined as the blocking action. From the list sorted in descending order of service dependency edge weights, select the edge set with a cumulative weight proportion exceeding 70% of the total weight as the candidate cleaning target, defined as the cleaning action.
[0125] S3.2.2: According to the blocking actions in the set of candidate defense actions, perform virtual blocking simulations through single-node blocking and multi-node joint blocking;
[0126] Further, for each node of the candidate blocking target, generate a new subgraph by temporarily removing the node and its associated edges through single-node blocking;
[0127] Count the number of all critical attack paths in the causal topology graph reflecting the node service dependency relationship, and the number of remaining critical attack paths in the subgraph after single-node blocking;
[0128] Calculate the reduction ratio of the number of critical attack paths as the expected attack suppression ratio of the node for the node blocking action;
[0129] Multi-node combined blocking is to perform a combined removal operation on the three nodes with the highest threat values among all candidate blocking target nodes;
[0130] Based on the subgraph after multi-node combined blocking, calculate the weighted difference between the reduction ratio of critical attack paths and the expected attack suppression ratio of a single node to generate the expected combined blocking suppression ratio of multiple nodes;
[0131] Combined with the cooperative gain coefficient, obtain the gain coefficient to verify the cooperative effect of single-node blocking;
[0132] For example, for node combinations with a cooperative gain > 20%, allocate the expected combined blocking suppression ratio of multiple nodes to each single node in proportion to improve the priority of single nodes;
[0133] For node combinations with a cooperative gain < -10%, prohibit simultaneous blocking in the final strategy to avoid wasting resources.
[0134] S3.2.3: According to the cleaning actions in the candidate defense action set, perform virtual traffic cleaning simulation through unilateral cleaning and multi-lateral combined cleaning;
[0135] Further, in unilateral cleaning, for each edge of the candidate cleaning target, decay the edge weight according to the deviation ratio of the behavior sequence;
[0136] It should be noted that the deviation ratio of the behavior sequence is a parameter used to quantify the attenuation degree of the edge weight of the candidate cleaning target. The deviation ratio of the behavior sequence directly determines the adjustment range of the edge weight in unilateral cleaning and multi-lateral combined cleaning. The behavior sequence deviation is a numerical index obtained by performing autoregressive modeling (AR model) on the request time series in the decrypted data block and calculating its residual variance. The deviation ratio of the behavior sequence is a relative ratio value obtained by normalizing the residual variance value, and the normalization range is based on the linear mapping of the maximum and minimum values of the behavior sequence deviations corresponding to all edges within the same time window.
[0137] Count the total proportion of the node threat values in the critical attack paths passing through the edge before and after unilateral cleaning as the unilateral cleaning utility.
[0138] Multilateral joint cleaning is to decay the weights of the five edges with the highest weights among the edges of all candidate cleaning targets proportionally according to the deviation degree of the behavior sequence;
[0139] Calculate the reduction ratio of the total node threat value of the critical attack path after multilateral joint cleaning, and generate the multilateral joint cleaning utility.
[0140] S3.2.4: Generate dynamic defense strategies including a list of target blocking nodes and traffic cleaning weights;
[0141] Arrange the nodes in descending order of the expected attack suppression ratio of the nodes to generate a list of candidate blocking targets, and accumulate the expected attack suppression ratio of the nodes in turn. Stop when the accumulated value ≥ 80% to form a list of target blocking nodes;
[0142] Set the cleaning utility threshold according to historical data, retain the edges with unilateral cleaning utility greater than the cleaning utility threshold, and combine the weights of the edges of the causal topology graph reflecting the node service dependency relationship to generate traffic cleaning weights.
[0143] It should be noted that the specific method for setting the cleaning utility threshold according to historical data is as follows: By analyzing the distribution of cleaning utility values in historical cleaning operation records, set the cleaning utility threshold to the 80th percentile of historical cleaning utility values. The cleaning utility threshold is used to determine whether the cleaning operation is effective. When the unilateral cleaning utility or the multilateral joint cleaning utility exceeds the cleaning utility threshold, the cleaning operation is considered effective.
[0144] S4: Convert the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane, and incrementally deploy the flow entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch;
[0145] S4.1: Convert the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane;
[0146] Furthermore, generate the matching fields of the OpenFlow flow entries according to the IP addresses and port numbers of the target blocking node list, set the action field to DROP, and write the Unix millisecond timestamp at the moment when the dynamic defense strategy is generated into the metadata field of the flow entries;
[0147] Generate the matching fields of the OpenFlow flow entries according to the edge set of the traffic cleaning weights, set the action field to SET_QUEUE, map the queue ID to the integer after rounding the cleaning weight value, and synchronously write the same timestamp into the metadata field;
[0148] Generate the matching fields of the OpenFlow flow table entries based on the IP addresses and port numbers in the target blocking node list, and generate the matching fields of the OpenFlow flow table entries based on the edge set of the traffic cleaning weights. Then, generate a set of OpenFlow flow table entries with timestamp markings through merging.
[0149] S4.2: Incrementally deploy the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch;
[0150] Configure the time-sensitive queue parameters in the ingress pipeline of the P4 programmable switch, and define the queue rate and queue buffer depth for each queue ID corresponding to the traffic cleaning weight. By calculating the SHA-256 hash value of the set of OpenFlow flow table entries with timestamp markings, compare the hash value differences with the currently deployed set of flow table entries to identify the newly added flow table entries and expired flow table entries;
[0151] Add the newly added flow table entries to the target P4 programmable switch through the FLOW_MOD command of the OpenFlow protocol, and strictly delete the expired flow table entries according to the timestamp markings through the FLOW_MOD command;
[0152] During the deployment process, sort the flow table entries from high to low according to the flow table entry priority (the blocking rule priority 4000 takes precedence over the cleaning rule priority 3000 + queue ID × 100). Combine the queue rate and queue buffer depth defined in the time-sensitive queue mechanism, and write the flow table entries into the flow table storage unit of the P4 programmable switch in sequence to ensure that the high-priority flow table entries take effect first. At the same time, skip the flow table entries that have been repeatedly deployed within 5 minutes based on the timestamp markings.
[0153] This embodiment also provides a network security threat information monitoring and management system, including: a traffic encryption module for capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; a threat extraction module for decrypting and restoring the encrypted data packets using a pre-shared initial cellular state matrix and extracting three-dimensional threat indicators; a policy generation module for constructing a causal topology graph reflecting the node service dependency relationship based on the three-dimensional threat indicators and inputting it into a causal reinforcement learning decision maker, and generating a dynamic defense policy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention; a defense deployment module for converting the dynamic defense policy into OpenFlow flow table entries with timestamp markings through the software-defined network control plane, and incrementally deploying the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.
[0154] This embodiment also provides a computer device applicable to the scenario of the network security threat information monitoring and management method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network security threat information monitoring and management method as proposed in the above embodiment.
[0155] The computer device can be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, a touchpad, or a mouse, etc.
[0156] This embodiment also provides a storage medium on which a computer program is stored, and when the program is executed by a processor, it implements the network security threat information monitoring and management method as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read-Only Memory (EPROM for short), Programmable Read-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0157] In summary, the present invention realizes highly secure encryption of network traffic and associated encryption of threat intelligence fields by inputting the original traffic data into the dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics, enhancing the security and analysis capabilities of data transmission and effectively coping with unknown attacks and threats in encrypted traffic. Subsequently, a causal topology graph reflecting the service dependency relationship of nodes is constructed based on the extracted three-dimensional threat indicators, and the causal reinforcement learning decision-maker is used to calculate the expected attack suppression ratio of different defense actions to generate a dynamic defense strategy, realizing the precise positioning and efficient response to potential threats in the network and optimizing the effectiveness and pertinence of defense measures. It not only improves the overall protection ability of network security but also significantly enhances the adaptive defense ability in the face of complex and changeable threats.
[0158] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A network security threat information monitoring and management method, characterized by: include, Capture raw traffic data in real time, input the raw traffic data into the dynamic cellular encryption engine, and generate encrypted data packets with spatiotemporal chaotic characteristics; Use the pre-shared initial cell state matrix to perform decryption and restoration on the encrypted data packet and extract three-dimensional threat indicators; Based on the three-dimensional threat indicators, a causal topology graph reflecting the node service dependency is constructed and input into the causal reinforcement learning decision maker. The expected attack suppression ratio of different defense actions is calculated through counterfactual intervention simulation to generate a dynamic defense strategy. The dynamic defense strategy is converted into OpenFlow flow table entries with timestamps through the software-defined network control plane, and the flow table entries are incrementally deployed to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.
2. The network security threat information monitoring and management method according to claim 1, characterized in that: The original traffic data is input into the dynamic cellular encryption engine to generate an encrypted data packet carrying spatiotemporal chaos characteristics. The specific steps are as follows: Input the original traffic dataset with threat labels into the dynamic cellular encryption engine; In the input buffer of the dynamic cellular encryption engine, the attack warning level is determined in real time; Selecting cell evolution rules from a predefined rule base according to the current attack alert level; Based on the Moore neighborhood topology of the selected cellular evolution rule, the threat intelligence field in the original traffic data is associated and encrypted to generate encrypted data packets carrying spatiotemporal chaotic characteristics.
3. The network security threat information monitoring and management method according to claim 2, characterized in that: The method uses the pre-shared initial cell state matrix to perform decryption and restoration on the encrypted data packet and extract the three-dimensional threat indicator. The specific steps are as follows: Transmit the encrypted data packets to the central analysis node through a point-to-point secure channel; Decryption and restoration of encrypted data packets are performed at the central analysis node using the pre-shared initial cell state matrix; Three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree and service dependency correlation are extracted from the encrypted data packets after decryption and restoration.
4. The network security threat information monitoring and management method according to claim 3, characterized in that: The causal topology diagram reflecting the node service dependency relationship is constructed based on the three-dimensional threat indicators. The specific steps are as follows: The three-dimensional threat indicators are time-series aligned and verified, and the node threat value is obtained through nonlinear fusion; Based on the node threat value, a causal topology graph is constructed through directed graph construction and key attack path identification; The key attack paths are marked on the causal topology graph to generate a causal topology graph that reflects the node service dependencies.
5. The network security threat information monitoring and management method according to claim 4, characterized in that: The specific steps of calculating the expected attack suppression ratio of different defensive actions through counterfactual intervention simulation are as follows: Based on the causal topology graph reflecting the node service dependency, a candidate defense action set including blocking actions and cleaning actions is generated; According to the blocking actions in the candidate defense action set, virtual blocking simulation is performed through single-node blocking and multi-node joint blocking to generate the node expected attack suppression ratio; According to the cleaning actions in the candidate defense action set, virtual traffic cleaning simulation is performed through unilateral cleaning and multilateral joint cleaning to generate unilateral cleaning utility; The node expected attack suppression ratio and unilateral cleaning utility are weightedly fused to generate the expected attack suppression ratio.
6. The network security threat information monitoring and management method according to claim 5, characterized in that: The generated dynamic defense strategy includes a target blocking node list and a traffic cleaning weight.
7. The network security threat information monitoring and management method according to claim 2, characterized in that: The original traffic dataset with threat labels is specifically: Slice the captured raw traffic data to obtain data blocks; Based on the predefined protocol feature library, the protocol feature of the data block is identified to obtain the threat intelligence field; According to the threat intelligence field, dynamic threat labeling is performed to generate a raw traffic data set with threat labels.
8. A network security threat information monitoring and management system, based on the network security threat information monitoring and management method according to any one of claims 1 to 7, characterized in that: include, Traffic encryption module, used to capture raw traffic data in real time, input the raw traffic data into the dynamic cellular encryption engine, and generate encrypted data packets carrying spatiotemporal chaotic features; A threat extraction module, used to perform decryption and restoration on encrypted data packets using a pre-shared initial cell state matrix and extract three-dimensional threat indicators; The strategy generation module is used to construct a causal topology graph reflecting the node service dependency relationship based on the three-dimensional threat indicators, and input the causal reinforcement learning decision maker to calculate the expected attack suppression ratio of different defense actions through counterfactual intervention simulation to generate a dynamic defense strategy; The defense deployment module is used to convert dynamic defense strategies into OpenFlow flow table entries with timestamps through the software-defined network control plane, and incrementally deploy the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security threat information monitoring and management method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security threat information monitoring and management method described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
A cyber-security system and methods thereof
CN106537406A
Data security access control system and method
CN115758324A
Network security threat detection method based on flow data
CN115842647A
Self-supervised model training method and device for encrypted traffic threat detection
CN117375897A
Network security detection method and system
CN118101250A
Cited By
Network flow restoring and monitoring method
CN120825342A
Hyper-converged Internet of Things gateway
CN120856777A
Intelligent security identification and defense method based on end-side cloud cooperation
CN121151034A
Power information dynamic encryption collaborative protection method and system
CN121309221A
A power information dynamic encryption cooperative protection method and system
CN121309221B