A network security threat information monitoring and management system and method

Generating dynamic defense strategies through dynamic cellular encryption engine and causal reinforcement learning decision makers has solved the shortcomings of the existing technology in dealing with unknown attacks and encrypted traffic threat detection, and achieved accurate positioning and efficient response to potential threats in the network, improving the overall protection and adaptive defense capabilities of network security.

CN120074958BActive Publication Date: 2025-07-01江苏省科技资源统筹服务中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510541056.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-01
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The prior art has shortcomings in dealing with unknown attacks and detection of encrypted traffic threats, especially inadequate recognition capabilities for emerging or mutated attacks. The accuracy and efficiency of abnormal behavior analysis are limited by the quality of training data and the degree of algorithm optimization, which is prone to false positives or missed reports.

Method used

By capturing the original traffic data in real time and inputting it into the dynamic cell encryption engine, encrypted data packets carrying spatiotemporal chaos characteristics are generated, three-dimensional threat indicators are extracted, causal topology maps are constructed, and a dynamic defense strategy is generated using the causal reinforcement learning decision-maker to achieve accurate positioning and efficient response to potential threats in the network.

Benefits of technology

Effectively respond to threats in unknown attacks and encrypted traffic, improve the overall protection and adaptive defense capabilities of network security, and optimize the effectiveness and targetedness of defense measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074958B_ABST
    Figure CN120074958B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security threat information monitoring and management system and method, which relates to the technical field of computer network security. It includes: capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; performing decryption and restoration on the encrypted data packets using a pre-shared initial cellular state matrix, and extracting three-dimensional threat indicators; based on the three-dimensional threat indicators, constructing a causal topology graph reflecting the node service dependency relationship, and inputting it into a causal reinforcement learning decision maker. By performing counterfactual intervention to simulate and calculate the expected attack suppression ratio of different defense actions, a dynamic defense strategy is generated. The present invention not only improves the overall protection ability of network security, but also significantly enhances the adaptive defense ability in the face of complex and changeable threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network security, and particularly to a network security threat information monitoring and management system and method. Background Art

[0002] Network security threat information monitoring and management, as a key technical field for ensuring network environment security, intrusion detection systems (IDS) and intrusion prevention systems (IPS) are traditional methods widely used to identify and prevent malicious activities. They mainly rely on signature library matching and abnormal behavior analysis to detect potential security threats. Signature library matching locates and responds to known threats quickly by comparing network traffic with a signature library of known attack patterns; while abnormal behavior analysis is based on machine learning algorithms, which establish a model through learning normal network behaviors to identify behaviors deviating from the norm as potential threats.

[0003] However, although intrusion detection systems (IDS) and intrusion prevention systems (IPS) have played an important role in enhancing network security, there are still deficiencies: First, signature library matching highly depends on the update speed of known attack patterns and lacks effective recognition ability for newly emerged or mutated attacks. This means that even the most advanced signature library is difficult to cover all types of threats, resulting in the risk of the network being exposed to unknown attacks. Second, although abnormal behavior analysis can discover new threats to a certain extent, its accuracy and efficiency are limited by the quality of training data and the optimization degree of algorithms, and false alarms or missed detections are likely to occur. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a network security threat information monitoring and management method to solve the deficiencies of the prior art in dealing with unknown attacks and encrypted traffic threat detection.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a method for monitoring and managing network security threat information, which includes: capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets with spatio-temporal chaos characteristics; using a pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets, and extracting three-dimensional threat indicators; based on the three-dimensional threat indicators, constructing a causal topology graph reflecting the service dependency relationship of nodes, and inputting it into a causal reinforcement learning decision maker, calculating the expected attack suppression ratio of different defense actions through counterfactual intervention simulation, and generating a dynamic defense strategy; converting the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane, and incrementally deploying the flow entries to target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.

[0008] As a preferred solution of the method for monitoring and managing network security threat information according to the present invention, wherein: the step of inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets with spatio-temporal chaos characteristics is as follows.

[0009] Input the raw traffic data set with threat labels into the dynamic cellular encryption engine.

[0010] Perform real-time determination of the attack warning level in the input buffer of the dynamic cellular encryption engine.

[0011] Select a cellular evolution rule from a predefined rule library according to the current attack warning level.

[0012] Perform associated encryption on the threat intelligence field in the raw traffic data based on the Moore neighborhood topology of the selected cellular evolution rule to generate encrypted data packets with spatio-temporal chaos characteristics.

[0013] As a preferred solution of the method for monitoring and managing network security threat information according to the present invention, wherein: the step of using a pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets and extract three-dimensional threat indicators is as follows.

[0014] Transmit the encrypted data packets to the central analysis node through a point-to-point secure channel.

[0015] Use the pre-shared initial cellular state matrix to decrypt and restore the encrypted data packets at the central analysis node.

[0016] Extract three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency association degree from the decrypted and restored encrypted data packets.

[0017] As a preferred solution of the method for monitoring and managing network security threat information according to the present invention, wherein: the step of constructing a causal topology graph reflecting the service dependency relationship of nodes based on the three-dimensional threat indicators is as follows.

[0018] Align and verify the three-dimensional threat indicators in time series, and obtain the node threat value through non-linear fusion;

[0019] Based on the node threat value, construct a causal topology graph through directed graph construction and critical attack path identification;

[0020] Mark the critical attack path of the causal topology graph to generate a causal topology graph reflecting the node service dependency relationship.

[0021] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the expected attack suppression ratio of different defense actions is simulated and calculated through counterfactual intervention, and the specific steps are as follows,

[0022] Based on the causal topology graph reflecting the node service dependency relationship, generate a set of candidate defense actions including blocking actions and cleaning actions;

[0023] According to the blocking actions in the set of candidate defense actions, perform virtual blocking simulation through single-node blocking and multi-node joint blocking to generate the node expected attack suppression ratio;

[0024] According to the cleaning actions in the set of candidate defense actions, perform virtual traffic cleaning simulation through unilateral cleaning and multi-lateral joint cleaning to generate the unilateral cleaning utility;

[0025] Fusion the node expected attack suppression ratio and the unilateral cleaning utility with weights to generate the expected attack suppression ratio.

[0026] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the generated dynamic defense strategy includes a target blocking node list and a traffic cleaning weight.

[0027] As a preferred solution of the network security threat information monitoring and management method described in the present invention, wherein: the original traffic data set with threat labels is specifically,

[0028] Fragment the captured original traffic data to obtain data blocks;

[0029] Based on a predefined protocol feature library, identify the protocol features of the data blocks to obtain threat intelligence fields;

[0030] According to the threat intelligence fields, perform dynamic threat label marking to generate an original traffic data set with threat labels.

[0031] In a second aspect, the present invention provides a network security threat information monitoring and management system, including a traffic encryption module for capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; a threat extraction module for decrypting and restoring the encrypted data packets using a pre-shared initial cellular state matrix and extracting three-dimensional threat indicators; a policy generation module for constructing a causal topology graph reflecting the service dependency relationship of nodes based on the three-dimensional threat indicators, inputting it into a causal reinforcement learning decision maker, and generating a dynamic defense policy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention; and a defense deployment module for converting the dynamic defense policy into timestamp-tagged OpenFlow flow entries through a software-defined network control plane and incrementally deploying the flow entries to target network devices based on the time-sensitive queue mechanism of a P4 programmable switch.

[0032] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, it implements any step of the network security threat information monitoring and management method as described in the first aspect of the present invention.

[0033] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, it implements any step of the network security threat information monitoring and management method as described in the first aspect of the present invention.

[0034] The beneficial effects of the present invention are as follows: By inputting raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics, high-security encryption of network traffic and associated encryption of threat intelligence fields are achieved, enhancing the security and analysis capabilities of data transmission and effectively dealing with unknown attacks and threats in encrypted traffic. Then, based on the extracted three-dimensional threat indicators, a causal topology graph reflecting the service dependency relationship of nodes is constructed, and a causal reinforcement learning decision maker is used to calculate the expected attack suppression ratio of different defense actions to generate a dynamic defense policy, achieving precise positioning and efficient response to potential threats in the network and optimizing the effectiveness and pertinence of defense measures. It not only improves the overall protection ability of network security but also significantly enhances the adaptive defense ability in the face of complex and changing threats. Description of the Drawings

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0036] Figure 1 It is a flowchart of a method for monitoring and managing network security threat information.

[0037] Figure 2 It is a flowchart of dynamic cellular encryption.

[0038] Figure 3 It is a flowchart of decryption and three-dimensional threat index extraction.

[0039] Figure 4 It is a flowchart of defense strategy generation.

[0040] Figure 5 It is a flowchart of defense strategy deployment. Detailed implementation manners

[0041] To make the above objects, features and advantages of the present invention more obvious and understandable, the following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings of the specification.

[0042] In the following description, many specific details are set forth to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0043] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" appearing in different places in this specification does not all refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments.

[0044] Referring to Figures 1 to 5 , it is an embodiment of the present invention. This embodiment provides a method for monitoring and managing network security threat information, including the following steps:

[0045] S1: Real-time capture of original network traffic data, input the original traffic data into the dynamic cellular encryption engine to generate encrypted data packets with spatio-temporal chaos characteristics;

[0046] S1.1: Deploy data probes at network edge nodes to real-time capture original traffic data and perform preprocessing;

[0047] S1.1.1: Deploy data probes at network edge nodes to real-time capture original traffic data;

[0048] Furthermore, deploy a dedicated processing unit at the mirror port of the network edge node, configure mirroring rules to capture bidirectional network traffic passing through the specified physical interface, filter non-target protocol data units, and retain the original traffic data containing transport layer and higher layer protocol characteristics.

[0049] S1.1.2: Shard the captured original traffic data to obtain data blocks;

[0050] Shard the captured original traffic data according to a fixed time window. The original traffic data captured within each time window is encapsulated into an independent data block, and a time marker field is appended to the head of each data block to record the start and end capture times and the data block sequence number.

[0051] S1.1.3: Identify protocol features of the data blocks based on a predefined protocol feature library;

[0052] Perform parallel scanning on the data blocks based on a predefined protocol feature library to identify data units containing specific protocol header features, extract the transport layer protocol header and the starting part of the payload, and mark the fields containing hypertext transfer protocol request lines, domain name resolution requests, and secure socket layer handshake information as threat intelligence fields.

[0053] S1.1.4: Perform dynamic threat label marking according to the protocol feature identification results;

[0054] According to the protocol feature scanning results, add threat labels to the threat intelligence fields containing structured query language injection features, cross-site scripting attack features, and known malicious domain name requests. The threat labels include attack type identifiers and confidence scores, forming an original traffic data set with threat labels.

[0055] S1.1.5: Preprocess the data blocks after dynamic threat label marking;

[0056] Perform byte alignment operations on the data blocks of the original traffic data set with threat labels, and fill in redundant bytes to meet the minimum data unit requirements for encryption processing, generating standardized original traffic data to provide a uniformly formatted input for subsequent encryption processing.

[0057] It should be noted that the specific requirements for the minimum data unit of encryption processing are as follows: when the data block length of the original traffic data set with threat tags is less than an integer multiple of the encryption algorithm block length (for example, the AES-128 encryption algorithm requires 16-byte alignment), redundant bytes are appended at the end of the data block using the PKCS#7 padding rule (the value of the redundant byte = the number of padding bytes), so that the data block length is extended to the nearest integer multiple of the block length that is not less than the original length (if the original length of the data block is 23 bytes, 1 byte 0x01 is filled to make it 24 bytes); for data blocks whose length already meets an integer multiple of the block length, a complete padding block still needs to be forcibly appended (for example, a data block with a length of 16 bytes needs to append 16 bytes 0x10), and finally, standardized original traffic data is generated to ensure that the length of all data blocks is an integer multiple of the encryption algorithm block length, meeting the unified requirements of the encryption processing for the input data format.

[0058] S1.2: Input the original traffic data into the dynamic cellular encryption engine, and select the cellular evolution rule from the predefined rule library according to the current attack alert level;

[0059] S1.2.1: Input the standardized original traffic data into the dynamic cellular encryption engine;

[0060] Write the standardized original traffic data into the input buffer of the dynamic cellular encryption engine in sequence. The buffer adopts a dual-channel ping-pong structure to ensure continuous and uninterrupted data input;

[0061] Establish an input queue index according to the time stamp field of the data block to maintain the temporal integrity of the data block.

[0062] S1.2.2: Perform real-time determination of the attack alert level in the input buffer of the dynamic cellular encryption engine;

[0063] In the sliding time window, count the proportion of data blocks including SQL injection tags, the continuous occurrence times of data blocks with cross-site scripting attack tags, and the distribution density of data blocks with malicious domain name request tags, and calculate the comprehensive threat index. The expression is:

[0064] ;

[0065] Among them, is the comprehensive threat index, is the proportion of data blocks with SQL injection tags, is the continuous occurrence times of data blocks with cross-site scripting attack tags, is the distribution density of data blocks with malicious domain name request tags, is the cross-site scripting continuity index, is the malicious domain name density gain coefficient, is the malicious domain name suppression factor, is the continuous attack saturation coefficient, the base of the natural logarithm;

[0066] Set the low-risk threshold and medium-risk threshold according to historical data, and perform real-time determination of the attack warning level;

[0067] It should be noted that according to the distribution of the frequency, intensity, and duration indicators of attack events in historical data, the statistical quantile method is used to set the low-risk threshold (for example, taking the 30th percentile value of historical indicators as the low-risk threshold) and the medium-risk threshold (for example, taking the 70th percentile value of historical indicators as the medium-risk threshold); in the process of real-time determination of the attack warning level, if the current attack indicator exceeds the low-risk threshold but does not reach the medium-risk threshold, it is marked as a low-risk warning, and if it exceeds the medium-risk threshold, it is marked as a medium-risk warning; when a single attack event simultaneously triggers multiple indicators to exceed the corresponding medium-risk threshold, it is superimposed and determined as a medium-risk warning, and the determination result is dynamically associated with the latest 30-day historical data through a sliding window mechanism for threshold verification to ensure that the warning level is synchronized with the characteristics of historical data.

[0068] When the comprehensive threat index is less than or equal to the low-risk threshold, it is determined as the low-risk level;

[0069] When the comprehensive threat index is greater than the low-risk threshold and less than or equal to the medium-risk threshold, it is determined as the medium-risk level;

[0070] When the comprehensive threat index is greater than the medium-risk threshold, it is determined as the high-risk level.

[0071] S1.2.3: Select the cellular evolution rule from the predefined rule library according to the current attack warning level;

[0072] The predefined rule library contains three types of evolution rules, corresponding to encryption logic and three attack warning levels respectively;

[0073] Among them, the encryption logic for the high-risk level is multi-round non-linear bit operations and diffusion confusion, the medium-risk level is single-round displacement and exclusive OR mixed operations, and the low-risk level is basic exclusive OR and permutation operations;

[0074] Load the corresponding rule from the rule library to the encryption engine operation unit according to the real-time warning level.

[0075] S1.3: Perform associated encryption on the threat intelligence field in the original traffic data based on the Moore neighborhood topology of the selected cellular evolution rule to generate an encrypted data packet with spatio-temporal chaos characteristics;

[0076] S1.3.1: Reconstruct the threat intelligence field matrix through data block matrix conversion and mirror edge filling;

[0077] Extract the data block of threat tags from the standardized original traffic data, and convert the data block into a two-dimensional byte matrix according to the predefined number of rows (determined by the hardware architecture of the dynamic cellular encryption engine);

[0078] Perform a mirror padding operation on the boundary area of the two-dimensional byte matrix, specifically:

[0079] Fill the content of the last row above the first row;

[0080] Fill the content of the first row below the last row;

[0081] Fill the content of the last column to the left of the first column;

[0082] Fill the content of the first column to the right of the last column;

[0083] Ensure that all elements of the two-dimensional byte matrix have a complete Moore neighborhood context.

[0084] S1.3.2: For the reconstructed threat intelligence field, perform rule-driven bit operations on each element in the two-dimensional byte matrix according to the cellular evolution rules, and perform multiple rounds of iterative processing;

[0085] It should be noted that when the attack alert level is high risk, load the multi-round non-linear bit operations and diffusion confusion rules in the predefined rule library, perform non-linear bit operations on each element in the two-dimensional byte matrix and the byte values of the eight adjacent elements in the Moore neighborhood, and perform diffusion confusion based on the weighted exclusive OR result of the neighborhood values; when the attack alert level is medium risk, perform a single-round displacement and exclusive OR mixed operation rule, shift each element in the two-dimensional byte matrix to the right by 3 bits and then perform an exclusive OR operation with the byte value of the element in the center column of the Moore neighborhood; when the attack alert level is low risk, perform the basic exclusive OR and permutation operation rules, perform an exclusive OR operation on each element in the two-dimensional byte matrix with the predefined mask byte, and perform a cyclic left shift permutation by row; after each evolution rule is executed, use the updated two-dimensional byte matrix as the input for multiple rounds of iterative processing (3 rounds of iteration for high risk level, 1 round of iteration for medium risk level, no iteration for low risk level) until the termination condition defined in the rule library is reached.

[0086] For example, when the attack alert level is high risk, obtain the byte values of the current element and the Moore neighborhood, perform non-linear bit operations, and append cyclic displacement operations.

[0087] S1.3.3: Perform spatio-temporal chaos feature injection through timestamp perturbation superposition and chaos intensity verification;

[0088] Extract the last byte from the data block time stamp field as the perturbation factor, perform an exclusive OR operation on the specified diagonal elements of the encrypted two-dimensional byte matrix, and calculate the avalanche effect value of the encrypted two-dimensional byte matrix: count the bit change rate of the corresponding bytes before and after encryption. If the bit change rate is lower than the bit change rate threshold, add an additional random perturbation to the matrix center area (random number generator seed = hash value of the time stamp field).

[0089] It should be noted that the last byte is extracted from the data block time stamp field and used as the perturbation factor to perform an exclusive OR operation on the main diagonal elements of the encrypted two-dimensional byte matrix; count the number of bit changes for each byte in the two-dimensional byte matrix before and after encryption, calculate the total bit change rate (total number of changed bits / (number of rows × number of columns × 8) of the matrix), set the bit rate change threshold according to historical data. If the bit change rate is lower than the bit change rate threshold, add an additional random perturbation to the matrix center area: use a random number generator (the first 32 bits of the SHA-256 hash value of the data block time stamp field as the seed) to generate a random byte sequence, and perform an exclusive OR operation on each element in the center area until the recalculated bit change rate ≥ the change threshold, completing the injection of spatio-temporal chaos characteristics.

[0090] S1.3.4: Perform encrypted packet encapsulation and integrity check encapsulation through matrix serialization and recombination to generate encrypted packets carrying spatio-temporal chaos characteristics;

[0091] Convert the encrypted two-dimensional byte matrix into a continuous byte stream in column-major order, retain the original protocol header information (source / destination address, port number), and insert an encrypted metadata field at the start position of the payload;

[0092] Calculate the CRC32 checksum of the encrypted data stream and append it to the end of the packet to form the final output encrypted packet.

[0093] S2: Use the pre-shared initial cellular state matrix to perform decryption and restoration on the encrypted packet and extract three-dimensional threat indicators;

[0094] S2.1: Transmit the encrypted packet to the central analysis node through a point-to-point secure channel, and perform decryption and restoration on the encrypted packet at the central analysis node using the pre-shared initial cellular state matrix;

[0095] S2.1.1: Transmit the encrypted packet to the central analysis node through a point-to-point secure channel;

[0096] Use the pre-shared key negotiation protocol to establish a two-way authenticated communication link between the edge node and the central analysis node, and negotiate a session key for encrypted packet transmission;

[0097] It should be noted that the transmission channel is configured in exclusive mode, and only data packets carrying encrypted metadata fields (rule number, number of iterations, chaos intensity value) are allowed to pass through;

[0098] Write the generated encrypted data packets into the transmission queue in the order of the time stamp field, and send them to the central analysis node through the secure channel;

[0099] Each encrypted data packet is attached with a transmission serial number and a time stamp hash value to ensure transmission integrity.

[0100] S2.1.2: At the central analysis node, use the pre-shared initial cellular state matrix to perform decryption and restoration on the encrypted data packets;

[0101] The central analysis node loads the pre-shared initial cellular state matrix, which contains a rule number mapping table consistent with the edge node and a chaos perturbation factor generation algorithm;

[0102] It should be noted that the pre-shared initial cellular state matrix is generated by the communication parties through the pre-shared key negotiation protocol before establishing a connection. The matrix dimension is fixed at 128x128, and each cellular state value is 0 or 1. The initial state is filled with a chaos sequence generated based on the Logistic map (parameter μ = 3.99); the pre-shared initial cellular state matrix is periodically updated during communication following the cellular automaton evolution rule (a state update function combining the von Neumann neighbor mode and XOR logic), and the update period is bound to the modulo operation result of the last 4 bits of the UTC time stamp (for example, when the last bit of the time stamp is 5, an update is triggered); the integrity of the pre-shared initial cellular state matrix is verified by generating a digest through the SHA-256 hash algorithm and performing a bit-by-bit comparison with the MAC value attached to the encrypted data packet to ensure that the pre-shared initial cellular state matrix has not been tampered with during transmission.

[0103] Extract the rule number, number of iterations, and chaos intensity value from the encrypted data packet header;

[0104] Reconstruct the encrypted data packet into a two-dimensional byte matrix in column-major order;

[0105] Perform multiple rounds of decryption according to the inverse operation logic corresponding to the rule number, and remove the time stamp perturbation (perform an XOR operation on the diagonal elements of the matrix);

[0106] Convert the decrypted two-dimensional matrix into a continuous byte stream in row-major order, remove the padding bytes and redundant fields, and restore the original threat intelligence field structure;

[0107] Verify the consistency of the CRC32 value with the packet tail field, and discard the packets that fail the verification.

[0108] S2.2: Extract three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency association degree from the restored data;

[0109] Statistically calculate the deviation degree between the protocol header fields in the decrypted data block and the predefined protocol feature library as the protocol type anomaly coefficient;

[0110] Perform autoregressive modeling (AR model) on the request time series in the decrypted data block and calculate the residual variance as the behavior sequence deviation degree;

[0111] Construct a service call graph and calculate the Pearson correlation coefficient between the node betweenness centrality and the threat label as the service dependency association degree.

[0112] S3: Based on the three-dimensional threat indicators, construct a causal topology graph reflecting the node service dependency relationship, input it into the causal reinforcement learning decision maker, and generate a dynamic defense strategy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention;

[0113] S3.1: Based on the three-dimensional threat indicators, construct a causal topology graph reflecting the node service dependency relationship;

[0114] S3.1.1: Align and verify the three-dimensional threat indicators in time series, and obtain the node threat value through non-linear fusion;

[0115] Align the protocol type anomaly coefficient, behavior sequence deviation degree, and service dependency association degree in time series according to the time stamp field of the data block to ensure that the three indicators of the same node correspond to the same time window;

[0116] Verify the integrity of the three-dimensional threat indicators, discard the data blocks missing any indicator, and record the abnormal node identifiers;

[0117] For each network node, calculate the product of the protocol type anomaly coefficient, the square root of the behavior sequence deviation degree, and the service dependency association degree to generate the node threat value.

[0118] S3.1.2: Construct a causal topology graph reflecting the node service dependency relationship;

[0119] Construct a causal topology graph through directed graph construction and critical attack path identification, and perform critical attack path marking to generate a causal topology graph reflecting the node service dependency relationship;

[0120] Specifically, based on protocol features, extract the service call relationships between nodes. Take all network entities with service call relationships as the node set; take all service call relationships with qualified weights as the edge set; construct a directed graph through the node set and the edge set as the causal topology graph. Traverse the causal topology graph based on depth-first search to mark the critical attack paths. In the causal topology graph, take the service call relationships with a service dependency correlation degree exceeding the service dependency threshold (for example, service dependency correlation degree ≥ 0.7) as the edge set, and combine the node threat value (the product of the protocol type anomaly coefficient, the square root of the behavior sequence deviation degree, and the service dependency correlation degree) as the node weight; use depth-first search to traverse the causal topology graph, starting from the nodes with node threat value ≥ high-risk threshold (for example, the 90th percentile of historical data), and perform path detection along the edges with qualified service dependency correlation degrees; when the sum of the cumulative node threat values of the path exceeds the path threat threshold (for example, cumulative value ≥ 50) and the path length ≤ maximum allowed hops (for example, 3 hops), mark this path as a critical attack path; the critical attack path needs to simultaneously satisfy that the end of the path points to critical service nodes (such as database servers, authentication gateways), and dynamically eliminate the edges with service dependency correlation degrees lower than the threshold during the traversal process. Finally, write the generated critical attack paths into the edge attribute field of the causal topology graph.

[0121] It should be noted that the service call relationships with qualified weights are generated by calculating the initial dependence strength of the edges and fusing the node threat values to generate the weights of the edges. Set the edge weight threshold according to historical data. When the weight of the edge is greater than the edge weight threshold, it is determined that the weight is qualified; the specific method for setting the edge weight threshold according to historical data is: by statistically analyzing the distribution of the weight values of all edges in historical data, set the edge weight threshold to the 90th percentile of the historical edge weight values.

[0122] S3.2: Generate a dynamic defense strategy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention;

[0123] S3.2.1: Generate a candidate defense action set based on the causal topology graph reflecting the service dependency relationships of nodes;

[0124] The candidate defense action set includes blocking actions and cleaning actions. From the list of node threat values sorted in descending order, select the node set with the cumulative threat value accounting for more than 60% of the total threat value as the candidate blocking target, which is defined as the blocking action; from the list of service dependency edge weights sorted in descending order, select the edge set with the cumulative weight accounting for more than 70% of the total weight as the candidate cleaning target, which is defined as the cleaning action.

[0125] S3.2.2: According to the blocking actions in the candidate defense action set, perform virtual blocking simulations through single-node blocking and multi-node joint blocking;

[0126] Further, for each node of the candidate blocking target, through single-node blocking, the node and the associated edges are temporarily removed to generate a new subgraph;

[0127] Count the number of all critical attack paths in the causal topology graph reflecting the node service dependency relationship, and the number of remaining critical attack paths in the subgraph after single-node blocking;

[0128] Calculate the reduction ratio of the number of critical attack paths as the expected attack suppression ratio of the node for the node blocking action;

[0129] Multi-node joint blocking is to perform a joint removal operation on the three nodes with the highest threat values among all candidate blocking target nodes;

[0130] Based on the subgraph after multi-node joint blocking, calculate the weighted difference between the reduction ratio of critical attack paths and the expected attack suppression ratio of a single node to generate the multi-node joint expected blocking suppression ratio;

[0131] Combined with the collaborative gain coefficient, obtain the gain coefficient to verify the collaborative effect of single-node blocking;

[0132] For example, for node combinations with a collaborative gain > 20%, distribute the multi-node joint expected blocking suppression ratio proportionally to each single node to improve the single-node priority;

[0133] For node combinations with a collaborative gain < -10%, simultaneous blocking is prohibited in the final strategy to avoid wasting resources.

[0134] S3.2.3: According to the cleaning actions in the candidate defense action set, perform virtual traffic cleaning simulation through unilateral cleaning and multi-lateral joint cleaning;

[0135] Further, in unilateral cleaning, for each edge of the candidate cleaning target, the edge weight is attenuated according to the deviation ratio of the behavior sequence;

[0136] It should be noted that the deviation ratio of the behavior sequence is a parameter used to quantify the attenuation degree of the edge weight of the candidate cleaning target. The deviation ratio of the behavior sequence directly determines the adjustment range of the edge weight in unilateral cleaning and multi-lateral joint cleaning. The behavior sequence deviation is a numerical index obtained by performing autoregressive modeling (AR model) on the request time series in the decrypted data block and calculating its residual variance. The deviation ratio of the behavior sequence is a relative ratio value obtained by normalizing this residual variance value, and the normalization range is based on the linear mapping of the maximum and minimum values of the behavior sequence deviations corresponding to all edges within the same time window.

[0137] Count the total proportion of the node threat values in the critical attack paths passing through the edge before and after unilateral cleaning as the unilateral cleaning utility.

[0138] Multilateral joint cleaning is to attenuate the weights of the five edges with the highest weights among the edges of all candidate cleaning targets according to the deviation ratio of the behavior sequence;

[0139] Calculate the reduction ratio of the sum of node threat values of the critical attack path after multilateral joint cleaning, and generate the multilateral joint cleaning utility.

[0140] S3.2.4: Generate dynamic defense strategies including a list of target blocking nodes and traffic cleaning weights;

[0141] Arrange the nodes in descending order of the expected attack suppression ratio of the nodes to generate a list of candidate blocking targets, and accumulate the expected attack suppression ratio of the nodes in turn. Stop when the accumulated value ≥ 80% to form a list of target blocking nodes;

[0142] Set the cleaning utility threshold according to historical data, retain the edges with unilateral cleaning utility greater than the cleaning utility threshold, and combine the weights of the edges of the causal topology graph reflecting the node service dependency relationship to generate traffic cleaning weights.

[0143] It should be noted that the specific method for setting the cleaning utility threshold according to historical data is: by analyzing the distribution of cleaning utility values in historical cleaning operation records, set the cleaning utility threshold to the 80th percentile of historical cleaning utility values. The cleaning utility threshold is used to determine whether the cleaning operation is effective. When the unilateral cleaning utility or the multilateral joint cleaning utility exceeds the cleaning utility threshold, the cleaning operation is considered effective.

[0144] S4: Convert the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane, and incrementally deploy the flow entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch;

[0145] S4.1: Convert the dynamic defense strategy into timestamp-tagged OpenFlow flow entries through the software-defined network control plane;

[0146] Furthermore, generate the matching fields of the OpenFlow flow entries according to the IP addresses and port numbers of the target blocking node list, set the action field to DROP, and write the Unix millisecond timestamp at the moment when the dynamic defense strategy is generated in the metadata field of the flow entries;

[0147] Generate the matching fields of the OpenFlow flow entries according to the edge set of the traffic cleaning weights, set the action field to SET_QUEUE, map the queue ID to the integer after rounding the cleaning weight value, and synchronously write the same timestamp in the metadata field;

[0148] Generate the matching fields of the OpenFlow flow table entries based on the IP addresses and port numbers in the target blocking node list, and generate the matching fields of the OpenFlow flow table entries based on the edge set of the traffic cleaning weights. Then, generate a set of OpenFlow flow table entries with timestamp markings through merging.

[0149] S4.2: Incrementally deploy the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch;

[0150] Configure the time-sensitive queue parameters in the ingress pipeline of the P4 programmable switch, and define the queue rate and queue buffer depth for each queue ID corresponding to the traffic cleaning weight; By calculating the SHA-256 hash value of the set of OpenFlow flow table entries with timestamp markings, compare the hash value differences of the currently deployed flow table entry set to identify new flow table entries and expired flow table entries;

[0151] Add the new flow table entries to the target P4 programmable switch through the FLOW_MOD command of the OpenFlow protocol, and strictly delete the expired flow table entries according to the timestamp markings through the FLOW_MOD command;

[0152] During the deployment process, sort the flow table entries from high to low according to the flow table entry priority (the blocking rule priority 4000 takes precedence over the cleaning rule priority 3000 + queue ID × 100). Combine the queue rate and queue buffer depth defined in the time-sensitive queue mechanism, and write the flow table entries into the flow table storage unit of the P4 programmable switch in sequence to ensure that the high-priority flow table entries take effect first. At the same time, skip the flow table entries that have been repeatedly deployed within 5 minutes based on the timestamp markings.

[0153] This embodiment also provides a network security threat information monitoring and management system, including: a traffic encryption module for capturing raw traffic data in real time, inputting the raw traffic data into a dynamic cellular encryption engine to generate encrypted data packets carrying spatio-temporal chaos characteristics; a threat extraction module for decrypting and restoring the encrypted data packets using a pre-shared initial cellular state matrix and extracting three-dimensional threat indicators; a policy generation module for constructing a causal topology graph reflecting the node service dependency relationship based on the three-dimensional threat indicators, inputting it into a causal reinforcement learning decision maker, and generating a dynamic defense policy by simulating and calculating the expected attack suppression ratio of different defense actions through counterfactual intervention; a defense deployment module for converting the dynamic defense policy into OpenFlow flow table entries with timestamp markings through the software-defined network control plane, and incrementally deploying the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.

[0154] This embodiment also provides a computer device, which is applicable to the scenario of the network security threat information monitoring and management method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network security threat information monitoring and management method as proposed in the above embodiment.

[0155] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0156] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the network security threat information monitoring and management method as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read-Only Memory (EPROM for short), Programmable Read-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0157] In summary, the present invention realizes highly secure encryption of network traffic and associated encryption of threat intelligence fields by inputting original traffic data into a dynamic cellular encryption engine to generate encrypted data packets with spatio-temporal chaos characteristics, enhancing the security and analysis capabilities of data transmission and effectively dealing with unknown attacks and threats in encrypted traffic. Subsequently, a causal topology graph reflecting the service dependency relationship of nodes is constructed based on the extracted three-dimensional threat indicators, and a causal reinforcement learning decision maker is used to calculate the expected attack suppression ratio of different defense actions to generate a dynamic defense strategy, realizing the precise positioning and efficient response to potential threats in the network and optimizing the effectiveness and pertinence of defense measures. It not only improves the overall protection ability of network security but also significantly enhances the adaptive defense ability in the face of complex and changeable threats.

[0158] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A network security threat information monitoring and management method, characterized by: include, Capture the original traffic data in real time, input the original traffic data into the dynamic cellular encryption engine, and generate encrypted data packets with spatiotemporal chaos characteristics. The specific steps are as follows: Input the original traffic dataset with threat labels into the dynamic cellular encryption engine; In the input buffer of the dynamic cellular encryption engine, the attack warning level is determined in real time; Selecting cell evolution rules from a predefined rule base according to the current attack alert level; Based on the Moore neighborhood topology of the selected cellular evolution rule, the threat intelligence field in the original traffic data is associated and encrypted to generate encrypted data packets carrying spatiotemporal chaos characteristics. Use the pre-shared initial cell state matrix to perform decryption and restoration on the encrypted data packet and extract three-dimensional threat indicators; Based on the three-dimensional threat indicators, a causal topology graph reflecting the node service dependency is constructed and input into the causal reinforcement learning decision maker. The expected attack suppression ratio of different defense actions is calculated through counterfactual intervention simulation to generate a dynamic defense strategy. The dynamic defense strategy is converted into OpenFlow flow table entries with timestamps through the software-defined network control plane, and the flow table entries are incrementally deployed to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.

2. The network security threat information monitoring and management method according to claim 1, characterized in that: The method uses the pre-shared initial cell state matrix to perform decryption and restoration on the encrypted data packet and extract the three-dimensional threat indicator. The specific steps are as follows: Transmit the encrypted data packets to the central analysis node through a point-to-point secure channel; Decryption and restoration of encrypted data packets are performed at the central analysis node using the pre-shared initial cell state matrix; Three-dimensional threat indicators including protocol type anomaly coefficient, behavior sequence deviation degree and service dependency correlation are extracted from the encrypted data packets after decryption and restoration.

3. The network security threat information monitoring and management method according to claim 2, characterized in that: The causal topology diagram reflecting the node service dependency relationship is constructed based on the three-dimensional threat indicators. The specific steps are as follows: The three-dimensional threat indicators are time-series aligned and verified, and the node threat value is obtained through nonlinear fusion; Based on the node threat value, a causal topology graph is constructed through directed graph construction and key attack path identification; The key attack paths are marked on the causal topology graph to generate a causal topology graph that reflects the node service dependencies.

4. The network security threat information monitoring and management method according to claim 3, characterized in that: The specific steps of calculating the expected attack suppression ratio of different defensive actions through counterfactual intervention simulation are as follows: Based on the causal topology graph reflecting the node service dependency, a candidate defense action set including blocking actions and cleaning actions is generated; According to the blocking actions in the candidate defense action set, virtual blocking simulation is performed through single-node blocking and multi-node joint blocking to generate the node expected attack suppression ratio; According to the cleaning actions in the candidate defense action set, virtual traffic cleaning simulation is performed through unilateral cleaning and multilateral joint cleaning to generate unilateral cleaning utility; The node expected attack suppression ratio and unilateral cleaning utility are weightedly fused to generate the expected attack suppression ratio.

5. The network security threat information monitoring and management method according to claim 4, characterized in that: The generated dynamic defense strategy includes a target blocking node list and a traffic cleaning weight.

6. The network security threat information monitoring and management method according to claim 1, characterized in that: The original traffic dataset with threat labels is specifically: Slice the captured raw traffic data to obtain data blocks; Based on the predefined protocol feature library, the protocol feature of the data block is identified to obtain the threat intelligence field; According to the threat intelligence field, dynamic threat labeling is performed to generate a raw traffic data set with threat labels.

7. A network security threat information monitoring and management system, based on the network security threat information monitoring and management method according to any one of claims 1 to 6, characterized in that: include, Traffic encryption module, used to capture raw traffic data in real time, input the raw traffic data into the dynamic cellular encryption engine, and generate encrypted data packets carrying spatiotemporal chaotic features; A threat extraction module, used to perform decryption and restoration on encrypted data packets using a pre-shared initial cell state matrix and extract three-dimensional threat indicators; The strategy generation module is used to construct a causal topology graph reflecting the node service dependency based on the three-dimensional threat indicators, input the causal reinforcement learning decision maker, calculate the expected attack suppression ratio of different defense actions through counterfactual intervention simulation, and generate a dynamic defense strategy; The defense deployment module is used to convert dynamic defense strategies into OpenFlow flow table entries with timestamps through the software-defined network control plane, and incrementally deploy the flow table entries to the target network devices based on the time-sensitive queue mechanism of the P4 programmable switch.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security threat information monitoring and management method described in any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security threat information monitoring and management method described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • A cyber-security system and methods thereof

    CN106537406A

  • Data security access control system and method

    CN115758324A