A computer network security monitoring system and method

Through the quantum encrypted traffic acquisition, biometrics and blockchain detection traceability analysis modules, the problems of traditional network monitoring systems in identifying complex attacks, data security and user verification are solved, and efficient network security monitoring and management are achieved.

CN120090801BActive Publication Date: 2025-08-05BEIJING YUHONG XINAN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510320756.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-08-05
Estimated Expiration
2045-03-18

AI Technical Summary

Technical Problem

Traditional computer network monitoring systems are difficult to accurately identify when facing complex and changeable network attacks, data transmission security is insufficient, user identity verification is not strict enough, abnormal detection and traceability analysis are poor, and visualization and management capabilities are limited.

Method used

The quantum encryption traffic acquisition module, biometric feature extraction module and blockchain detection traceability analysis module are adopted, combining quantum key distribution, biometric verification and blockchain storage to realize data encryption transmission, multi-factor authentication, trusted anomaly detection and traceability analysis, and provide intuitive visual management.

Benefits of technology

It improves the security and reliability of data transmission of network security monitoring, ensures the accuracy of user identity verification and real-time monitoring, realizes accurate abnormality detection and traceability analysis, and improves the efficiency and security of network management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090801B_ABST
    Figure CN120090801B_ABST
Patent Text Reader

Abstract

The present invention discloses a computer network security monitoring system and method, including a quantum encryption traffic collection module, a biometric feature extraction module, a blockchain detection and traceability analysis module, and a visualization management module. The quantum encryption traffic collection module generates and distributes secure quantum keys through the quantum key distribution unit, encrypts the collected data packets using the encrypted transmission unit, and generates traffic data segments through the traffic collection subunit and the data cache statistical analysis subunit. The biometric feature extraction module verifies the user's identity through the biometric unit and extracts multi-dimensional feature vectors using the feature extraction subunit. The blockchain detection and traceability analysis module detects and performs traceability analysis on abnormal traffic through the anomaly detection subunit and the traceability analysis subunit, and stores the results in the blockchain storage unit. The visualization management module provides an intuitive network status display and user identity authentication function through the visualization display subunit and the identity authentication and access control subunit. The present invention combines quantum encryption, biometric recognition, and blockchain technology, improving the accuracy, security, and traceability of network security monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer network security and information technology. Specifically, it relates to a computer network security monitoring system and method. Background Art

[0002] At present, with the rapid development of information technology, computer networks have become key infrastructure for social operation and are widely used in many fields such as finance, healthcare, education, and government. As the network scale continues to expand, complexity keeps rising, and network attack means become increasingly diverse, traditional computer network monitoring systems and methods are gradually unable to cope with new security threats and complex network environments, and it is difficult to meet the requirements of ensuring the secure and stable operation of the network.

[0003] Traditional network monitoring systems mostly rely on simple traffic threshold setting, feature matching, or rule-based detection methods. In the face of complex and changeable network attacks, these methods have obvious limitations. For example, for a new type of distributed denial-of-service (DDoS) attack, its attack traffic may disguise as normal business traffic, and traditional threshold-based monitoring methods are difficult to accurately identify, easily leading to false alarms or missed alarms. In terms of data transmission, traditional encryption technologies such as symmetric encryption and asymmetric encryption face potential risks to their security with the development of quantum computing technology, and there is a possibility that data is stolen or tampered with during the transmission process.

[0004] In the user authentication link, most use the combination of username and password. This method has many security risks. For example, users may set simple and easy-to-guess passwords, or the passwords are leaked during network transmission or storage, resulting in illegal users being able to easily impersonate legitimate users to access network resources. Moreover, traditional systems are difficult to effectively analyze and monitor the operation behaviors of users in the network and cannot detect abnormal operations after the account is stolen in time.

[0005] In terms of anomaly detection and traceability analysis, the normal traffic feature distribution space of traditional models is usually stored in a local centralized database and is easily subject to malicious tampering or damaged due to system failures. This greatly reduces the reliability of anomaly detection results, and traceability analysis is difficult to conduct in depth due to the lack of reliable historical data support, and it is impossible to accurately track the attack source and comprehensively understand the attack path.

[0006] In terms of visualization and management, the visualization display of traditional systems often only provides limited real-time information, lacks the ability to effectively integrate and display historical data, and is not conducive to network administrators analyzing the network security situation from a macroscopic and long-term perspective. At the same time, traditional user access control and management mechanisms are relatively single and difficult to cope with complex network usage scenarios and security requirements. Summary of the Invention

[0007] Aiming at the deficiencies of the prior art, the present invention provides a computer network security monitoring system and method, aiming to improve the performance and reliability of network security monitoring and meet the requirements of modern network security.

[0008] In the first aspect of the embodiment of the present invention, a computer network security monitoring system is provided, including a quantum encryption traffic collection module, a biometric feature extraction module, and a blockchain detection and traceability analysis module. The quantum encryption traffic collection module is connected to the biometric feature extraction module, and the biometric feature extraction module is connected to the blockchain detection and traceability analysis module;

[0009] It is characterized in that the quantum encryption traffic collection module includes:

[0010] A quantum key distribution unit, used to deploy quantum key distribution devices at key network nodes to generate and distribute secure quantum keys for data transmission; an encrypted transmission unit, used to obtain the quantum keys distributed by the quantum key distribution unit and encrypt the packet information collected by the traffic collection subunit using the quantum keys; a traffic collection subunit, used to capture the packets flowing through the network gateway node, perform a preliminary analysis on the packets, and extract key information; a data cache statistical analysis subunit, used to temporarily store the encrypted packet information, manage the data cache according to the first-in-first-out principle, and perform statistical analysis on the data in the cache at a preset time interval to generate traffic data segments;

[0011] The biometric feature extraction module includes:

[0012] A biometric recognition unit, used to collect the biometric feature information of the user, convert it into a digital feature vector, and compare it with the legal user biometric data stored in the biometric feature storage unit to verify the authenticity of the user's identity; a feature extraction subunit, used to receive the data cache and traffic data segments of the quantum encryption traffic collection module and extract the multi-dimensional feature vectors of each traffic data segment; a biometric feature storage unit, used to store the biometric feature information of legal users in an encrypted storage manner;

[0013] The blockchain detection and traceability analysis module includes:

[0014] The anomaly detection subunit has a built-in anomaly detection model and compares the received feature vector with the normal traffic feature distribution space stored in the blockchain storage unit. When it is found that the feature vector deviates from the normal distribution by more than the preset threshold, it is determined to be abnormal traffic and the corresponding traffic data segment is marked; the tracing analysis subunit, after receiving the abnormal traffic mark, uses network topology information and IP address tracking technology to trace back the source of the abnormal traffic, determine the possible attack source or fault node, and generate a tracing analysis report; the blockchain storage unit, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results and tracing analysis report.

[0015] In an optional embodiment, a visualization management module is further included, and the visualization management module is connected to the biometric feature extraction module and the blockchain detection and traceability analysis module respectively;

[0016] The visual management module includes:

[0017] The visualization sub-unit displays the real-time status of network traffic, the distribution of abnormal traffic, and the results of tracing analysis with intuitive charts and graphical interfaces for network administrators to review and analyze;

[0018] The authentication and access control subunit works in conjunction with the biometric recognition unit to verify the user's biometric information when the user logs in and accesses network resources, controls their access to network resources based on their identity and permissions, and monitors and manages the user's operations.

[0019] In an optional embodiment, the encryption transmission unit supports integration with existing network protocols, so that the encrypted data packets can be normally transmitted in the network and decrypted at the receiving end to restore the original data;

[0020] The traffic collection subunit extracts key information, including source IP, destination IP, port number and protocol type.

[0021] In an optional embodiment, the biometric identification device in the biometric identification unit includes but is not limited to a fingerprint reader, a facial recognition camera, and an iris recognition device;

[0022] The multi-dimensional feature vector in the feature extraction subunit includes but is not limited to source IP address distribution features, destination IP address distribution features, port usage frequency features, data packet size distribution features, and protocol type proportion features.

[0023] In an optional embodiment, the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum heuristic algorithm to enhance the performance and efficiency of feature extraction.

[0024] In an optional embodiment, the blockchain storage unit adopts the consensus mechanism of the blockchain, and the consensus mechanism includes, but is not limited to, proof of work, proof of stake or Byzantine fault tolerance algorithm.

[0025] In an optional embodiment, the anomaly detection model verified by the blockchain of the anomaly detection sub-unit ensures the credibility of the update and verification process of the normal traffic feature distribution space through a smart contract.

[0026] In an optional embodiment, the charts and graphical interfaces of the visualization display sub-unit support querying and displaying the historical information stored in the blockchain storage unit.

[0027] In an optional embodiment, the authentication and access control sub-unit combines traditional username and password verification methods to implement multi-factor authentication.

[0028] The second aspect of the embodiment of the present invention provides a computer network security monitoring method, including the following steps:

[0029] S1: Perform quantum encrypted traffic collection, adopt a dynamic quantum key length adjustment mechanism based on traffic load, and generate a dynamic key sequence in combination with quantum chaotic mapping;

[0030] Preferably, generating a dynamic key sequence in combination with quantum chaotic mapping specifically includes:

[0031] S101: Start the quantum key distribution unit, establish a quantum key distribution channel at the network key nodes, generate an unpredictable key sequence through quantum chaotic mapping, and distribute the generated key based on the quantum key distribution protocol;

[0032] S102: The traffic collection sub-unit captures data packets at the network key nodes, and performs preliminary parsing on the data packets to extract key information;

[0033] S103: The encryption transmission unit encrypts the collected data packet information using the quantum key, and transmits the encrypted data to the data cache statistical analysis sub-unit;

[0034] S104: The data cache statistical analysis sub-unit stores the encrypted data in the cache, statistically analyzes the cache data at a preset time interval, and generates an encrypted traffic data segment.

[0035] S2: Perform biometric feature extraction, use the federated learning method to perform distributed updates on the biometric model, and bind the user's behavior features using the quantum key;

[0036] Preferably, performing distributed updates on the biometric model using the federated learning method specifically includes:

[0037] S201: When a user accesses the network, the biometric recognition unit collects the user's biometric information, converts it into a digital feature vector, and compares it with the biometric data of legitimate users in the biometric storage unit to verify the authenticity of the user's identity;

[0038] S202: The feature extraction subunit receives the encrypted traffic data segment and extracts a multi-dimensional feature vector using a quantum-inspired convolutional kernel;

[0039] S203: Use a dynamic quantum key to encrypt the model parameters in federated learning and bind the quantum key to the user's behavioral characteristics.

[0040] S3: Construct a spatio-temporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, and use the historical data and smart contracts stored in the blockchain to locate the attack source and generate protection strategies;

[0041] Preferably, it specifically includes:

[0042] S301: Construct a spatio-temporal dynamic graph model to detect traffic anomalies in real time and mark high-risk data segments; where is the set of network nodes, is the set of edges at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatio-temporal attention matrix, used to quantify the spatio-temporal correlation strength between nodes;

[0043] S302: Capture the traffic interaction and time correlation between nodes, assign higher attention weights to the edges that interacted in the most recent time stage, that is, use the spatio-temporal attention mechanism to locate abnormal nodes and calculate scores for the located abnormal nodes;

[0044] S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit, and the traceability analysis subunit conducts retrospective analysis by integrating real-time attention weights and historical frequencies, locates the high-probability attack path, and stores the traceability analysis report in the blockchain storage unit;

[0045] S304: Synchronously update the smart contract logic. When the node traffic is greater than the set high-risk threshold, automatically execute predefined protection actions on high-risk nodes, that is, block the IP address of the abnormal node and send an alarm message to the administrator.

[0046] S4: Use deep reinforcement learning to adaptively adjust the visualization layout.

[0047] Preferably, it specifically includes: a visualization display subunit that displays the real-time status of network traffic, abnormal traffic information, and traceability results in intuitive charts and graphical interfaces; an identity authentication and access control subunit that verifies the user's biometric information and traditional login credentials during user login and operation, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user's operations at the same time.

[0048] Compared with the prior art, the advantages of the present invention in providing the above method include: in terms of data security, the quantum encryption traffic collection module uses quantum key distribution and encrypted transmission to ensure the security of data transmission and prevent theft and tampering; the biometric storage unit encrypts and stores the user's biometric features to protect the user's privacy. In terms of identity authentication, multiple identity authentication combining biometric recognition and traditional methods is adopted to increase accuracy and security, and can monitor the user's behavior in real time and give early warnings of abnormal operations. During abnormal detection and traceability analysis, the blockchain storage unit uses the immutable feature and smart contract to ensure the credibility of the detection data and the accuracy of the results, and the traceability analysis subunit can accurately locate the attack source by combining various information. In terms of information display and management, the visualization display subunit presents information in an intuitive interface, supports query of historical information, and improves management efficiency; the identity authentication and access control subunit realizes refined access control, records the user's operations for easy auditing and traceability, and ensures the security and compliance of the network system. Brief Description of the Drawings

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0050] Figure 1 It is a schematic structural diagram of a computer network security monitoring system proposed in an embodiment of the present application;

[0051] Figure 2 It is a flowchart of a computer network security monitoring method proposed in an embodiment of the present application. Detailed Embodiments

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0053] Embodiment 1:

[0054] Please refer to Figure 1 , Figure 1 which is a schematic structural diagram of a computer network security monitoring system proposed in the first embodiment of this application. As Figure 1 shown, the computer network security monitoring system includes a quantum encryption traffic collection module, a biometric feature extraction module, and a blockchain detection and traceability analysis module. The quantum encryption traffic collection module is connected to the biometric feature extraction module, and the biometric feature extraction module is connected to the blockchain detection and traceability analysis module;

[0055] The quantum encryption traffic collection module includes:

[0056] A quantum key distribution unit, which is used to deploy quantum key distribution devices at key network nodes to generate and distribute secure quantum keys for data transmission; an encrypted transmission unit, which is used to obtain the quantum keys distributed by the quantum key distribution unit and use the quantum keys to encrypt the packet information collected by the traffic collection subunit; a traffic collection subunit, which is used to capture the packets flowing through the network node and perform a preliminary analysis on the packets to extract key information; a data cache statistical analysis subunit, which is used to temporarily store the encrypted packet information, manage the data cache according to the first-in-first-out principle, and perform statistical analysis on the data in the cache at a preset time interval to generate traffic data segments;

[0057] The biometric feature extraction module includes:

[0058] A biometric recognition unit, which is used to collect the biometric feature information of users, convert it into digital feature vectors, and compare it with the legal user biometric data stored in the biometric feature storage unit to verify the authenticity of the user's identity; a feature extraction subunit, which is used to receive the data cache and traffic data segments of the quantum encryption traffic collection module and extract the multi-dimensional feature vectors of each traffic data segment; a biometric feature storage unit, which stores the biometric feature information of legal users in an encrypted storage manner;

[0059] The blockchain detection and traceability analysis module includes:

[0060] An anomaly detection subunit, which has an anomaly detection model built in, compares the received feature vectors with the normal traffic feature distribution space stored in the blockchain storage unit, and when it is found that the feature vectors deviate from the normal distribution by more than a preset threshold, determines it as abnormal traffic and marks the corresponding traffic data segment; a traceability analysis subunit, which, after receiving the abnormal traffic mark, uses network topology information and IP address tracking technology to perform a retrospective analysis on the source of the abnormal traffic, determines possible attack sources or faulty nodes, and generates a traceability analysis report; a blockchain storage unit, which, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results, and traceability analysis reports.

[0061] In this embodiment, the quantum key distribution unit utilizes the basic principles of quantum mechanics, such as the non-clonability of quantum states and the characteristics of quantum entanglement, to generate and distribute quantum keys with high security for data transmission; the encrypted transmission unit transmits both the transmission content of the data packet and its source and destination information under encryption protection, ensuring that the data will not be stolen or tampered with during network transmission; the traffic data segments generated by the traffic collection subunit contain various statistical indicators of network traffic, such as the number of data packets, the number of bytes, the traffic rate, etc., providing important data support for subsequent feature extraction and anomaly detection.

[0062] The normal traffic feature distribution space of the anomaly detection subunit is obtained through the learning and analysis of a large amount of normal network traffic data, representing the traffic feature pattern under normal network operation. The generated traceability analysis report not only contains information about the attack source or faulty node, but also analyzes the propagation path of the abnormal traffic and the possible impacts, providing an important basis for network security administrators to take effective countermeasures.

[0063] Furthermore, it further includes a visualization management module, and the visualization management module is respectively connected to the biometric feature extraction module and the blockchain detection traceability analysis module;

[0064] The visualization management module includes:

[0065] A visualization display subunit, which displays the real-time state of network traffic, the distribution of abnormal traffic, and the traceability analysis results in intuitive charts and graphical interfaces for network administrators to view and analyze;

[0066] An identity authentication and access control subunit, which works in cooperation with the biometric unit to verify the biometric information of users when they log in and access network resources, control their access to network resources according to the user's identity and permissions, and monitor and manage during the user's operation process.

[0067] In this embodiment, for the real-time state of network traffic, the visualization display subunit can not only display the overall traffic trend, such as the fluctuation curve of the traffic rate, the real-time change of the number of data packets, etc., but also classify and display different types of network protocol traffic, enabling the administrator to clearly understand the usage of various network applications. For example, by comparing the traffic proportions of protocols such as HTTP, FTP, and TCP through bar charts, it helps the administrator quickly judge whether the composition of the business traffic in the network is normal.

[0068] In the user login phase, it first verifies the user's biometric information, such as fingerprint, facial features, or iris information, etc., and at the same time combines the traditional username and password verification method to achieve multi-factor authentication. When the user accesses network resources, this subunit strictly controls their access to various network resources according to the user's identity and pre-set permissions. For example, ordinary users may only be able to access specific files and applications, while administrator users have higher-level permissions and can perform operations such as system configuration and data management. During the user's operation, the authentication and access control subunit continuously monitors and manages. It will record the user's operation behavior in real time, including information such as the time, object, and content of the operation, and analyze these behaviors.

[0069] Furthermore, the encryption transmission unit supports the integration with existing network protocols, enabling the encrypted data packets to be transmitted normally in the network and decrypted at the receiving end to restore the original data;

[0070] Extract key information in the traffic collection subunit, including source IP, destination IP, port number, and protocol type.

[0071] In this embodiment, the existing network protocol types include TCP, UDP, etc. The TCP protocol is commonly used for reliable, connection-oriented communications, such as file transfer and web browsing; the UDP protocol is commonly used for applications with high requirements for real-time but relatively low requirements for data accuracy, such as video stream and audio stream transmission.

[0072] Furthermore, the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum-inspired algorithm to enhance the performance and efficiency of feature extraction.

[0073] In this embodiment, the weights are updated through quantum rotation gate operations, enabling the model to converge to near the global optimal solution more quickly and avoid falling into local optimal solutions. At the same time, the quantum-inspired algorithm can also adaptively adjust the search strategy according to the characteristics and changes of network traffic data, improving the flexibility and adaptability of the algorithm.

[0074] Through this combination method, when the feature extraction subunit processes network traffic data, it can more efficiently extract more representative and discriminative multi-dimensional feature vectors from complex traffic data segments. These feature vectors not only include traditional source IP address distribution features, destination IP address distribution features, port usage frequency features, packet size distribution features, and protocol type proportion features, etc., but can also uncover some deep features hidden in the data, such as the co-variation features of different network protocols within a specific time period, and the difference features between abnormal traffic and normal traffic on a tiny time scale.

[0075] Further, the blockchain storage unit adopts the consensus mechanism of the blockchain, and the consensus mechanism includes, but is not limited to, proof of work, proof of stake, or Byzantine fault tolerance algorithm.

[0076] In this embodiment, in the blockchain storage unit based on proof of work, each participating node needs to compete for the bookkeeping right by calculating complex mathematical puzzles. The node will continuously try different random numbers, combine them with information such as transaction data for hash operation. Only when the calculated hash value meets specific difficulty requirements can the node obtain the bookkeeping right and add the new block to the blockchain.

[0077] Under the proof-of-stake mechanism, the bookkeeping right of a node no longer depends on computing power, but is determined by the amount of equity (usually digital currency or tokens) held by the node and the holding time. Nodes with more equity have a higher probability of being selected for bookkeeping. At the same time, these nodes need to pledge a certain amount of equity as a margin during the bookkeeping process. If a node attempts to maliciously tamper with data or conduct illegal operations, the pledged equity will be deducted.

[0078] The Byzantine fault tolerance algorithm achieves consensus through information interaction and verification between nodes. In the blockchain storage unit of this embodiment, adopting the Byzantine fault tolerance algorithm can ensure that even if some nodes fail or are attacked, the system can still accurately record and store network security monitoring data.

[0079] Further, the anomaly detection model of the blockchain verification of the anomaly detection subunit ensures the credibility of the update and verification process of the normal traffic feature distribution space through smart contracts.

[0080] In this embodiment, the smart contract will check whether the data source is credible, whether the data format is correct, whether the data conforms to the basic characteristics of normal traffic, etc. Only the data verified by the smart contract will be used to update the normal traffic feature distribution space. If it is found that a certain update operation causes misjudgment of the anomaly detection model, the problem can be accurately found by checking the operation log on the blockchain, whether it is the data source error or the verification process deviation. The smart contract can also set corresponding permission management mechanisms. Only authorized devices or algorithms can submit update data, and different users or devices have different permission levels.

[0081] Further, the charts and graphical interfaces of the visualization display subunit support the query and display of historical information stored in the blockchain storage unit.

[0082] In this embodiment, the administrator can screen and retrieve the historical information in the blockchain storage unit according to multiple dimensions, such as time range, network nodes, traffic types, anomaly event types, etc.

[0083] Furthermore, the authentication and access control sub-unit combines traditional username and password authentication methods to implement multi-factor authentication.

[0084] In this embodiment, the authentication and access control sub-unit introduces biometric technologies such as fingerprint recognition, facial recognition, iris recognition, etc. Biometric technologies, based on the uniqueness and stability of human biological characteristics, provide higher accuracy and security for authentication.

[0085] Embodiment Two:

[0086] Please refer to Figure 2 , Figure 2 which is a flowchart of a computer network security monitoring method proposed in Embodiment Two of this application. As Figure 2 shown, a computer network security monitoring method proposed in Embodiment Two of this application is characterized by including the following steps:

[0087] S1: Perform quantum encrypted traffic collection, adopt a dynamic quantum key length adjustment mechanism based on traffic load, and generate a dynamic key sequence in combination with quantum chaotic mapping;

[0088] S101: Start the quantum key distribution unit, establish a quantum key distribution channel at key network nodes, generate an unpredictable key sequence through quantum chaotic mapping, and distribute the generated key based on the quantum key distribution protocol;

[0089] Exemplarily, generating an unpredictable key sequence through quantum chaotic mapping includes: generating an initial seed value based on a quantum physical entropy source to ensure the randomness of the initial key , and defining a chaotic mapping function for initializing the quantum chaotic mapping, quantizing the chaotic output and mapping it into a binary key stream. After the key stream is generated, it is directly distributed through the quantum key distribution channel, where the chaotic mapping function is:

[0090]

[0091] where is the dynamic quantum key of the chaotic output, that is, the dynamic quantum key of the th time slice, is the chaotic control parameter, is the secret key value of the previous time period, which is the initial input of the chaotic iteration, is used to make the result currently in the interval [0, 1), is the quantum state conversion function, is the quantum phase perturbation term generated in real time by the quantum random number generator.

[0092] S102: The traffic collection subunit captures data packets at key network nodes, performs preliminary parsing on the data packets, and extracts key information;

[0093] S103: The encryption transmission unit encrypts the collected data packet information using a quantum key and transmits the encrypted data to the data cache statistical analysis subunit;

[0094] Exemplarily, encrypting the collected data packet information includes: dynamically adjusting the key length according to the real-time network traffic load, defining load metrics by constructing a traffic load quantization model , , where is the rate of instantaneous traffic, is the maximum link bandwidth, is the weight coefficient, is the number of concurrent connections, is the maximum number of concurrent connections. Select the key length according to the load level. Set that when continuously crosses the set threshold, trigger the key length update. At the same time, fragment the ultra-long data packets, and each fragment is encrypted using a different key segment. The encryption formula is: , where is the quantum secure encryption algorithm, is the key segment corresponding to the fragment; use a short key to reduce the computational overhead when the load is low, and switch to a long key to cope with potential attacks when the load is high, realizing lightweight encryption with load awareness. And the change of the key length will force the encryption protocol to be synchronized and updated, further realizing the resistance to replay attacks with a fixed key; each time the key is updated, the key information of the previous time period is destroyed through quantum erasure technology, ensuring that even if the current key is leaked, the historical data is still not decryptable;

[0095] Further, the encryption transmission unit adopts a hybrid mode of lattice-based post-quantum cryptography PQC and quantum key during data transmission: , even if a quantum computer cracks the PQC part, the quantum key is still required to decrypt, ensuring the absolute security of the data.

[0096] S104: The data cache statistical analysis subunit stores the encrypted data in the cache, statistically analyzes the cached data at a preset time interval, and generates encrypted traffic data segments.

[0097] S2: Perform biometric feature extraction, use the federated learning method to perform distributed updates on the biometric model, and use quantum keys to bind the user's behavioral characteristics;

[0098] S201: When a user accesses the network, the biometric recognition unit collects the user's biometric information, converts it into a digital feature vector, and compares it with the legal user biometric data in the biometric storage unit to verify the authenticity of the user's identity;

[0099] Exemplarily, verifying the authenticity of the user's identity specifically includes: after collecting the user's biometric information, using the dynamic quantum key output by chaos for encryption: , is the encrypted user biometric, is the encryption function based on quantum chaos mapping, is the quantum noise mask generated in real time by the quantum random number generator, constructs a federated local model, and uses the encrypted user biometric to train the local model at the user side, and synchronously fuse the user's operation behavior analysis features through the loss function: , , where is the overall loss function of federated learning, is the loss of the local biometric model including Triplet Loss and cross-entropy loss, is the weight coefficient of the behavior analysis loss, is the prediction loss of the user's operation behavior, is the time step of the user's operation behavior sequence, is the LSTM neural network model for constructing the time sequence of the degree operation behavior sequence, is the user's operation behavior sequence, is the normal behavior pattern label generated by clustering historical data. Finally, bind the local model parameters with the quantum key to the hash value to prevent the model parameters from being tampered with during transmission.

[0100] S(202): The feature extraction sub-unit receives the encrypted traffic data segment and extracts a multi-dimensional feature vector by using a quantum-inspired convolution kernel;

[0101] Exemplarily, define the quantum-inspired convolution kernel , optimize the parameters by using the quantum annealing algorithm, which can enhance the ability to extract the non-linear features of encrypted traffic. The optimization formula based on the quantum annealing algorithm is: , where is to find the parameter that minimizes the objective function , is the quantum annealing energy function, is the sparsification coefficient, is the L1 regularization term; each node extracts the encrypted traffic features , , aggregate the global feature center through the server , , is the total number of nodes participating in the federated aggregation, is the encrypted traffic feature vector extracted by the is the feature mask matrix dynamically generated by the quantum key .

[0102] S203: Use the dynamic quantum key to encrypt the model parameters in federated learning and bind the quantum key to the user's behavior characteristics;

[0103] Exemplarily, use the dynamic quantum key to encrypt the model parameters in federated learning , to achieve double encryption against classical and quantum attacks. The encryption process is: , where is the hybrid encryption function, is the algorithm used, is to combine the quantum key with the PQC ciphertext, is the key stream generated based on the dynamic quantum key and synchronized through the quantum key distribution protocol. By embedding the user's operation behavior sequence into the quantum watermark, the quantum key is bound to the user's behavior characteristics. The formula for embedding the quantum watermark is: , where is the quantum bit measurement operation, is the user operation behavior sequence 's hash value, which is converted into a binary string. When the user's operation behavior is tampered with, the embedded quantum watermark verification fails and a real-time alarm is triggered.

[0104] S3: Build a spatio-temporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, and use the historical data and smart contracts stored in the blockchain to locate the attack source and generate protection strategies;

[0105] S301: Build a spatio-temporal dynamic graph model to detect traffic anomalies in real time and mark high-risk data segments; where, is the network node set, is the edge set at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatio-temporal attention matrix used to quantify the spatio-temporal correlation strength between nodes;

[0106] S302: Capture the traffic interaction and time correlation between nodes, assign higher attention weights to the edges that interacted in the most recent time stage, that is, use the spatio-temporal attention mechanism to locate abnormal nodes, and calculate the scores of the located abnormal nodes;

[0107] Exemplarily, the spatio-temporal attention mechanism is: , where is the spatio-temporal attention weight, is the generated query vector, is the generated key vector, is the time decay function, is node and is the timestamp of the last interaction between

[0108] S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit. The traceability analysis subunit conducts retrospective analysis by integrating real-time attention weights and historical frequencies, locates high-probability attack paths, and stores the traceability analysis report in the blockchain storage unit;

[0109] Exemplarily, the positioning formula for locating high-probability attack paths is: , where is the most likely attack propagation path, is the set of paths traced back from the attack target to the potential source node, is the historical interaction frequency statistically obtained from the blockchain traceability records, is node 's total number of interactions. By integrating real-time attention weights and historical frequencies, high-frequency legitimate interaction nodes will not be misjudged as the attack source.

[0110] Exemplarily, in the blockchain detection traceability analysis step, the smart contract automatically triggers corresponding operations according to preset rules. When high-risk abnormal traffic appears, it notifies the administrator and executes corresponding network protection measures. In the blockchain detection traceability analysis step, the smart contract automatically triggers corresponding operations according to preset rules. When high-risk abnormal traffic appears, it notifies the administrator and executes corresponding network protection measures; the traceability analysis subunit uses the historical traceability information in the blockchain storage unit to assist in more comprehensive analysis to discover potential attack patterns or long-term security threats.

[0111] S304: Synchronously update the smart contract logic. When the node traffic is greater than the set high-risk threshold, automatically execute predefined protection actions on high-risk nodes, that is, block the IP addresses of abnormal nodes and send warning messages to the administrator.

[0112] S4: Use deep reinforcement learning to adaptively adjust the visualization layout.

[0113] S401: The visualization display subunit displays the real-time status of network traffic, abnormal traffic information, and traceability results in intuitive charts and graphical interfaces;

[0114] S402: During the user login and operation process, the authentication and access control subunit verifies the user's biometric information and traditional login credentials, controls the user's access to network resources according to the user's identity and permissions, and monitors and manages the user's operations at the same time.

[0115] In this embodiment, in the visualization management step, when an illegal access attempt or abnormal user operation behavior is detected, the authentication and access control subunit records the event in the blockchain storage unit for subsequent auditing and traceability.

[0116] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.

[0117] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0118] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.

[0119] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or terminal device including the said element.

[0120] The above has introduced in detail a computer network security monitoring system and method provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A computer network security monitoring system, comprising a quantum encryption traffic collection module, a biometric feature extraction module, and a blockchain detection and traceability analysis module. The quantum encryption traffic collection module is connected to the biometric feature extraction module, which is in turn connected to the blockchain detection and traceability analysis module. It is characterized by: The quantum encryption traffic collection module includes: The quantum key distribution unit is used to deploy quantum key distribution equipment at key network nodes to generate and distribute secure quantum keys for data transmission. The encryption transmission unit is used to obtain the quantum key distributed by the quantum key distribution unit and use the quantum key to encrypt the data packet information collected by the traffic collection subunit. The traffic collection subunit is used to capture data packets flowing through network nodes and perform preliminary analysis of the data packets to extract key information. The data cache statistical analysis subunit is used to temporarily store encrypted data packet information, manage the data cache according to the first-in-first-out principle, and perform statistical analysis on the data in the cache at preset time intervals to generate traffic data segments. The biometric feature extraction module includes: The biometric identification unit is used to collect the user's biometric information and convert it into a digital feature vector, which is then compared with the biometric data of the legitimate user stored in the biometric storage unit to verify the authenticity of the user's identity. The feature extraction subunit is used to receive the data cache and traffic data segments from the quantum encryption traffic acquisition module and extract the multi-dimensional feature vector of each traffic data segment. The biometric storage unit uses encrypted storage to store the biometric information of the legitimate user. The blockchain detection and traceability analysis module includes: The anomaly detection subunit has a built-in anomaly detection model and compares the received feature vector with the normal traffic feature distribution space stored in the blockchain storage unit. When it is found that the feature vector deviates from the normal distribution by more than the preset threshold, it is determined to be abnormal traffic and the corresponding traffic data segment is marked; the tracing analysis subunit, after receiving the abnormal traffic mark, uses network topology information and IP address tracking technology to trace back the source of the abnormal traffic, determine the possible attack source or fault node, and generate a tracing analysis report; the blockchain storage unit, as a distributed ledger, stores the normal traffic feature distribution space, abnormal traffic data, anomaly detection results and tracing analysis report.

2. A computer network security monitoring system according to claim 1, characterized in that: It also includes a visualization management module, which is connected to the biometric feature extraction module and the blockchain detection and traceability analysis module respectively; the visualization management module includes: a visualization display subunit, which uses intuitive charts and graphical interfaces to display the real-time status of network traffic, the distribution of abnormal traffic, and traceability analysis results for network administrators to view and analyze; an identity authentication and access control subunit, which works in conjunction with the biometric unit to verify the user's biometric information when the user logs in and accesses network resources, control their access to network resources based on their identity and permissions, and monitor and manage the user's operation process; the encrypted transmission unit supports integration with existing network protocols, so that encrypted data packets can be transmitted normally in the network, and decrypted at the receiving end to restore the original data; the traffic collection subunit extracts key information, including source IP, destination IP, port number, and protocol type; The biometric devices in the biometric unit include but are not limited to fingerprint readers, facial recognition cameras and iris readers; the multidimensional feature vectors in the feature extraction subunit include but are not limited to source IP address distribution features, destination IP address distribution features, port usage frequency features, data packet size distribution features and protocol type proportion features; the deep learning algorithm in the feature extraction subunit is a convolutional neural network combined with a quantum heuristic algorithm; the blockchain storage unit adopts a blockchain consensus mechanism, which includes but is not limited to proof of work, proof of stake or Byzantine fault tolerance algorithm; the blockchain-verified anomaly detection model of the anomaly detection subunit ensures the credibility of the normal traffic feature distribution space update and verification process through smart contracts; the charts and graphical interfaces of the visualization subunit support the query and display of historical information stored in the blockchain storage unit; the identity authentication and access control subunit combines traditional username and password authentication methods to achieve multi-factor authentication.

3. A computer network security monitoring method, characterized in that: The following steps are involved: S1: Collect quantum encryption traffic, use a dynamic quantum key length adjustment mechanism based on traffic load, and combine quantum chaos mapping to generate a dynamic key sequence; The step S1 specifically includes the following steps: S101: Start the quantum key distribution unit, establish a quantum key distribution channel at key nodes in the network, generate an unpredictable key sequence through quantum chaos mapping, and distribute the generated key based on the quantum key distribution protocol; S102: The traffic collection subunit captures data packets at key network nodes, performs preliminary analysis on the data packets, and extracts key information; S103: The encryption transmission unit encrypts the collected data packet information using the quantum key and transmits the encrypted data to the data cache statistical analysis subunit; S2: Extract biometric features, use federated learning methods to distribute updates to the biometric model, and use quantum keys to bind user behavioral characteristics; The step S2 specifically includes the following steps: S201: The biometric recognition unit collects user biometric information when the user accesses the network, converts it into a digital feature vector, and compares it with the biometric data of the legitimate user in the biometric storage unit to verify the authenticity of the user's identity; S202: The feature extraction subunit receives the encrypted traffic data segment and extracts a multi-dimensional feature vector using a quantum-inspired convolution kernel; S203: Using dynamic quantum key K t The model parameter R in federated learning i Encryption is performed to bind the quantum key to the user's behavioral characteristics; S3: Build a spatiotemporal dynamic graph model, locate abnormal nodes through the graph attention mechanism, and use historical data and smart contracts stored in the blockchain to locate the attack source and generate protection strategies; The step S3 specifically includes the following steps: S301: Constructing a spatiotemporal dynamic graph Model, detects traffic anomalies in real time and marks high-risk data segments; V is the set of network nodes, is the edge set at time t, representing the traffic interaction relationship between nodes, is the node feature matrix, is the spatiotemporal attention matrix, which is used to quantify the spatiotemporal correlation strength between nodes; S302: Capture the traffic interactions and temporal associations between nodes, assign higher attention weights to edges with recent interactions, and use the spatiotemporal attention mechanism to locate abnormal nodes. Score the located abnormal nodes. The spatiotemporal attention mechanism is: , in, is the spatiotemporal attention weight, Q is the generated query vector, is the generated key vector, is the time decay function, For nodes and Timestamp of the last interaction; S303: The anomaly detection subunit obtains the normal traffic feature distribution space from the blockchain storage unit. The traceability analysis subunit performs a retrospective analysis based on the real-time attention weight and historical frequency to locate the high-probability attack path and stores the traceability analysis report in the blockchain storage unit. The positioning formula for locating the high-probability attack path is: , Among them, Path(v attack ) is the most likely attack propagation path, ρ is the number of paths from the attack target v attack The set of paths back to potential source nodes, To record the historical interaction frequency from the blockchain, For nodes By combining the real-time attention weight and historical frequency, high-frequency legitimate interaction nodes will not be mistakenly identified as attack sources. S304: By dynamically updating the smart contract logic, when the node traffic exceeds the set high-risk threshold, a predefined protection action is automatically executed on the high-risk node, that is, the IP address of the abnormal node is blocked and an alarm information is sent to the administrator; S4: Adaptively adjust visualization layout using deep reinforcement learning.

4. A computer network security monitoring method according to claim 3, characterized in that: The method of generating an unpredictable key sequence by quantum chaos mapping includes: generating an initial seed value K0 for ensuring the randomness of the initial key based on a quantum physical entropy source, defining a chaos mapping function for initializing the quantum chaos mapping, mapping the chaotic output into a binary key stream through quantization processing, and directly distributing the generated key stream through a quantum key distribution channel, wherein the chaos mapping function is: in, is the dynamic quantum key of the chaotic output, that is, the dynamic quantum key of the t-th time slice, θ is the chaos control parameter, is the secret key value of the previous period and the initial input of the chaotic iteration. Mod1 is used to make the result within the interval [0,1). φ(x) is the quantum state conversion function, and ω is the quantum phase perturbation term generated in real time by the quantum random number generator.

5. A computer network security monitoring method according to claim 4, characterized in that: The method of encrypting the collected data packet information by using quantum key includes: dynamically adjusting the key length according to the real-time network traffic load, defining the load index by building a traffic load quantization model, and , , in, is the instantaneous flow rate, is the maximum link bandwidth, λ is the weight coefficient, N is the number of concurrent connections, The maximum number of concurrent connections, select the key length by load level, set When the set threshold is crossed continuously, the key length is updated. At the same time, the overlong data packet is fragmented, and each fragment is encrypted with a different key segment. The encryption formula is: , where E is a quantum-safe encryption algorithm, is the secret key segment corresponding to the i-th shard; Furthermore, the encryption transmission unit adopts a hybrid mode of lattice post-quantum cryptography (PQC) and quantum key in the data transmission process: Even if a quantum computer cracks the PQC part, it still needs to obtain the quantum key to decrypt it, ensuring the absolute security of the data.

6. A computer network security monitoring method according to claim 5, characterized in that: The authenticity verification of the user identity specifically includes: collecting the user's biometric information and encrypting it using the dynamic quantum key K_t output by the chaotic method: , For encrypted user biometrics, is the encryption function based on quantum chaos mapping, Build a federated local model for quantum noise masks generated in real time by a quantum random number generator, using encrypted user biometrics Train the local model on the user side and simultaneously integrate the user's operation behavior analysis features through the loss function: , ,in, is the overall loss function of federated learning, is the loss of the local biometric model including Triplet Loss and cross entropy loss, μ is the weight coefficient of behavior analysis loss, is the prediction loss of user operation behavior, T is the time step of user operation behavior sequence, LSTM neural network model for temporal construction of operation behavior sequence, For user operation behavior sequence, is the normal behavior pattern label generated by historical data clustering, and finally the local model parameters are combined with the quantum key Binding hash values prevents model parameters from being tampered with during transmission; The quantum-inspired convolution kernel is ,Using the quantum annealing algorithm to optimize parameters can enhance the ability to extract the nonlinear characteristics of encrypted traffic. The optimization formula based on the quantum annealing algorithm is: ,in, To find the parameter W that minimizes the objective function, is the quantum annealing energy function, β is the sparsification coefficient, is the L1 regularization term; each node extracts encrypted traffic features , , aggregated global feature centers through the server , , n is the total number of nodes participating in the federation aggregation, is the encrypted traffic feature vector extracted from the i-th node, Quantum key Dynamically generated feature mask matrix; The use of dynamic quantum key Encrypting the model parameters R_i in federated learning specifically includes: using dynamic quantum keys Encrypting the model parameter R in federated learning i , achieving double encryption to resist classical and quantum attacks. The encryption process is: , where Enchybird is a hybrid encryption function, is the PQC algorithm used, ⊕ is the combination of quantum key and PQC ciphertext, Based on dynamic quantum key The generated key stream is synchronized through the quantum key distribution protocol, and the user's operation behavior sequence is Embed quantum watermarks to bind quantum keys to user behavior characteristics. The formula for embedding quantum watermarks is: , where QubitMeas is the quantum bit measurement operation, User operation behavior sequence O t The hash value is converted into a binary string. When the user's operation behavior is tampered with, the embedded quantum watermark verification fails, triggering a real-time alarm.

7. A computer network security monitoring method according to claim 6, characterized in that: The step S4 specifically includes: the visual display subunit displays the real-time status of network traffic, abnormal traffic information and tracing results in an intuitive chart and graphic interface.

Citation Information

Patent Citations

  • Data acquisition and signal identification method based on data information encryption method

    CN117082502A

  • Comprehensive network security risk assessment and management system

    CN118074904A