Network defense capability verification method and system based on intrusion attack simulation

By using photoacoustic coupled waveforms and network behavior oscillation fields to simulate real attacks in network defense capability verification, combined with reverse gradient calculation and dynamic phase matching algorithm, the problem of insufficient verification accuracy in the existing technology is solved, and efficient and accurate defense performance verification is achieved.

CN120090868AInactive Publication Date: 2025-06-03BEIJING DISTRICT HEATING GRP CO LTD
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510533692.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-06-03
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, the accuracy of network defense capability verification is insufficient, and the static preset of the attack traffic template is difficult to simulate the synergistic interference effect of real attack and network dynamic characteristics, resulting in significant deviations from the test results and real attack and defense scenarios.

Method used

By inputting the target network topology parameters into the nonlinear oscillation equation, superimposing the random phase modulation function to generate a photoacoustic coupled waveform, and injecting it into the network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack level correlation degree, triggering an abnormal fluctuation mode equivalent to the real attack behavior. Then, the topological correlation of the network protocol interaction entropy value is analyzed through reverse gradient calculation, an attack instruction sequence carrying the protocol vulnerability feature vector is generated, and the coordinated interference between attack behavior and network dynamic perturbation is achieved through a dynamic phase matching algorithm, and a network defense response trajectory with defense strategy mapping characteristics is generated.

Benefits of technology

It achieves accurate triggering of traffic abnormal fluctuations that are exactly consistent with real attacks, improves the coverage rate and penetration success rate of attack instructions, ensures that the defense verification results are highly consistent with the actual defense effects, and significantly improves the interpretability of the evaluation results and the reliability of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090868A_ABST
    Figure CN120090868A_ABST
Patent Text Reader

Abstract

The invention provides a network defense capability verification method and system based on intrusion attack simulation. According to the method, network dynamics and a photoacoustic effect simulation technology are creatively fused, and network abnormal traffic equivalent to real attacks is dynamically excited by constructing a photoacoustic coupling waveform driven by network topology; reversely analyzing the vulnerability characteristics based on the protocol interaction entropy, and generating an attack instruction with a space-time cooperation characteristic; utilizing a phase matching algorithm to precisely couple the attack behavior and the network dynamic disturbance to form a defense response track capable of being quantitatively analyzed; and finally, through an asymmetric correlation model, analyzing a dynamic relationship between trajectory deformation and a node survival state, and realizing objective quantitative evaluation of defense efficiency. According to the technical scheme provided by the embodiment of the invention, high-precision quantitative verification of the virtual-real combined network security defense capability can be realized, and the real-time performance and credibility of defense strategy evaluation are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the technical field of dynamic collaborative verification, and in particular, to a method and system for verifying network defense capabilities based on intrusion attack simulation. Background Art

[0002] With the complication of network attack means and the dynamic evolution of defense systems, a highly reliable network environment urgently needs a verification method that can simulate real attack behaviors and quantitatively evaluate the effectiveness of defense strategies. Specific requirements include: accurately triggering network anomaly fluctuations equivalent to real attacks in a multi-protocol interaction environment, real-time analyzing the coupling relationship between attack behaviors and dynamic changes in network topologies, and quantitatively outputting defense effectiveness through objective indicators (such as node survival rate, protocol vulnerability exploitation paths), avoiding the subjectivity and lag of traditional manual penetration testing.

[0003] Currently, a typical solution for this requirement is the dynamic testing technology based on attack traffic simulation. This solution injects attack traffic into a virtualized network environment by predefining attack traffic templates (such as DDoS traffic packets, SQL injection features), monitors the interception rate and response delay of the defense system; at the same time, combines a protocol parsing engine to count the survival status of key nodes and the protocol interaction entropy value to generate a defense effectiveness score.

[0004] However, this solution has significant defects. The static preset of attack traffic templates is difficult to simulate the co-interference effect of real attacks and network dynamic characteristics (such as real-time changes in topological parameters, fluctuations in the correlation strength of protocol stack levels), resulting in a significant deviation between the test results and real attack and defense scenarios. In addition, the calculation of protocol interaction entropy does not consider the non-linear influence of the network node oscillation field on the propagation path of attack instructions, limiting the accuracy of vulnerability feature extraction and thus affecting the credibility of the defense response trajectory. Summary of the Invention

[0005] Embodiments of the present invention provide a method for verifying network defense capabilities based on intrusion attack simulation to solve the problem of insufficient accuracy in verifying network defense capabilities in the prior art.

[0006] In a first aspect, embodiments of the present invention provide a method for verifying network defense capabilities based on intrusion attack simulation, including: Inputting target network topology parameters into a non-linear oscillation equation and superimposing a random phase modulation function to generate an optoacoustic coupling waveform; Injecting the optoacoustic coupling waveform into a network behavior oscillation field constructed by a network node interaction strength matrix and a protocol stack level correlation degree to trigger an abnormal fluctuation mode in which network traffic generation is equivalent to real attack behaviors; During the duration of the abnormal fluctuation mode, the topological correlation of the network protocol interaction entropy value is analyzed through reverse gradient calculation, and an attack instruction sequence carrying protocol vulnerability feature vectors is generated; The execution path of the attack instruction sequence is spatiotemporally coupled with the frequency perturbation parameter of the photoacoustic coupling waveform, and the collaborative interference between the attack behavior and the network dynamics perturbation is realized through the dynamic phase matching algorithm, generating a network defense response trajectory with defense strategy mapping characteristics; According to the topological deformation characteristics of the network defense response trajectory, the defense effectiveness verification result is output through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate.

[0007] Optionally, analyzing the topological correlation of the network protocol interaction entropy value through reverse gradient calculation and generating an attack instruction sequence carrying protocol vulnerability feature vectors includes: Based on the dynamic manifold modeling of cross-layer interaction events in the protocol stack, the topological correlation of the network protocol interaction entropy value is reverse gradient analyzed, and the curvature change rate of the protocol state transition path is extracted as the gradient calculation reference quantity; Performing spectral coupling operation on the gradient calculation reference quantity and the partial derivative quantity of the network protocol interaction entropy value to generate the spectral weight parameter of the protocol vulnerability feature vector; Based on the spectral weight parameter and the dynamic direction parameter of the network protocol interaction entropy value, the penetration direction parameter and the penetration rate parameter of the protocol vulnerability feature vector are generated through tensor product calculation; Using the real-time topological neighborhood parameter of the network node interaction intensity matrix to dynamically correct the penetration direction parameter, adjusting the vector angle of the penetration direction parameter to obtain the corrected penetration direction parameter; Performing time-domain convolution operation on the corrected penetration direction parameter and the penetration rate parameter to generate an attack instruction sequence.

[0008] Optionally, performing spectral coupling operation on the gradient calculation reference quantity and the partial derivative quantity of the network protocol interaction entropy value to generate the spectral weight parameter of the protocol vulnerability feature vector includes: Performing frequency band division on the gradient calculation reference quantity, and extracting the fluctuation amplitude of the curvature change rate in each frequency band as the frequency band division parameter, and the frequency band division parameter is determined by the dynamic response period of the protocol interaction event; Performing frequency domain alignment processing on the frequency band division parameter and the partial derivative quantity of the network protocol interaction entropy value, and the frequency domain alignment processing process includes performing fluctuation phase decomposition on the direction parameter of the partial derivative quantity to generate a normalized frequency domain response parameter; Perform a dot product operation on the normalized frequency-domain response parameter and the frequency band division parameter to generate the spectral weight parameter of the protocol vulnerability feature vector. The phase consistency of the curvature change rate and the partial derivative quantity within each frequency band shall be maintained during the dot product operation process.

[0009] Optionally, perform frequency-domain alignment processing on the frequency band division parameter and the partial derivative quantity of the network protocol interaction entropy value to generate a normalized frequency-domain response parameter, including: Based on the dynamic response period of the protocol interaction event, dynamically adjust the frequency band boundaries of the frequency band division parameter, and output the adjusted frequency band division parameter. The frequency range of each frequency band in the adjusted frequency band division parameter is negatively correlated with the time window of the protocol state transition; Decompose the direction parameter of the partial derivative quantity of the network protocol interaction entropy value into multiple orthogonal phase components. Based on the adjusted frequency band division parameter, perform frequency band matching truncation on each orthogonal phase component, and only retain the frequency components in the same frequency band as the adjusted frequency band division parameter, and output the truncated orthogonal phase component; Within the same frequency band, perform phase offset compensation on the truncated orthogonal phase component and the adjusted frequency band division parameter to make the phase difference between the two converge to a preset threshold, and perform frequency band normalization on the amplitude of the compensated component to generate a normalized frequency-domain response parameter.

[0010] Optionally, inject the photoacoustic coupling waveform into the network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack layer correlation degree, and trigger an abnormal fluctuation mode equivalent to the real attack behavior in network traffic generation, including: Generate a network node interaction intensity matrix based on the interaction traffic of network nodes and the protocol handshake success rate. Combine the column vector weights of the protocol stack layer correlation degree, and construct a network behavior oscillation field through tensor coupling and nonlinear perturbation terms; According to the protocol response delay threshold in the protocol stack layer correlation degree, perform phase modulation on the frequency perturbation parameter of the photoacoustic coupling waveform to generate a modulated photoacoustic waveform, and align the phase parameter of the photoacoustic coupling waveform with the row vector weight of the network node interaction intensity matrix; Inject the modulated photoacoustic waveform into the network behavior oscillation field, and trigger the nonlinear resonance of node traffic fluctuation and protocol interaction by dynamically matching the waveform energy density with the column vector weight of the protocol stack layer correlation degree to generate an abnormal fluctuation mode.

[0011] Optionally, inject the modulated photoacoustic waveform into the network behavior oscillation field, and trigger the nonlinear resonance of node traffic fluctuation and protocol interaction by dynamically matching the waveform energy density with the column vector weight of the protocol stack layer correlation degree to generate an abnormal fluctuation mode, including: Based on the column vector weights of the protocol stack level correlation, calculate the energy density distribution required for each protocol layer in real time, and generate a dynamic energy coupling coefficient that matches the row vector weights of the network node interaction intensity matrix; Perform cross-layer interaction on the dynamic energy coupling coefficient and the frequency domain parameters of the modulated photoacoustic waveform. By iteratively adjusting the waveform phase offset, make the energy density distribution of the protocol stack level and the spectral peak of the node traffic fluctuation form phase locking within the same frequency band; When the number of locked protocol layers in the protocol stack level accumulates to the dynamic convergence threshold for the phase locking, perform a tensor convolution operation on the locked photoacoustic waveform parameters and the network node interaction intensity matrix to generate a non-linear resonance signal in the cross-protocol layer - physical waveform domain, and output the abnormal fluctuation mode.

[0012] Optionally, input the target network topology parameters into the non-linear oscillation equation, and superimpose a random phase modulation function to generate a photoacoustic coupling waveform, including: Based on the target network topology parameters, extract the connectivity, path length, and topological dynamic change rate parameters of the network nodes, generate a random phase modulation function through Fourier series expansion and probability distribution model, and introduce the random phase modulation function as an additional term into the non-linear oscillation equation; Input the target network topology parameters and the random phase modulation function into the non-linear oscillation equation, and calculate the photoacoustic coupling waveform through a numerical solution method; Optimize the calculated photoacoustic coupling waveform, eliminate noise and outliers, and verify the accuracy and effectiveness of the waveform; Output the optimized photoacoustic coupling waveform as multi-dimensional time series data and store it in a structured file format.

[0013] Optionally, according to the topological deformation characteristics of the network defense response trajectory, output the defense effectiveness verification result through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the survival rate of network nodes, including: Based on the topological deformation characteristics of the network defense response trajectory, calculate the distribution density of the trajectory curvature extreme points and generate a distribution density vector; Collect the network node survival status data, quantify the network node survival rate, and generate a node survival rate vector by statistically analyzing the survival time and survival ratio of network nodes; Input the distribution density vector and the node survival rate vector into a predefined asymmetric correlation analysis model, and calculate the correlation degree and deviation threshold between the distribution density and the node survival rate; Generate a defense effectiveness verification result vector according to the comparison result of the correlation degree and the deviation threshold.

[0014] Optionally, a cooperative interference between the attack behavior and the network dynamics perturbation is realized through a dynamic phase matching algorithm, and a network defense response trajectory with the characteristics of defense strategy mapping is generated, including: Calculate the phase compensation amount of each node in the spatio-temporal coupling field matrix based on the column vector weight of the protocol stack layer correlation degree, and the phase compensation amount is non-linearly correlated with the row vector weight of the network node interaction strength matrix and the reciprocal of the protocol response delay; Perform multi-dimensional superposition on the spatio-temporal coupling field matrix corresponding to the phase compensation amount and the attack instruction execution path parameters, and perform dynamic threshold truncation on the superposition result according to the node survival rate distribution to generate a cooperative interference matrix; Extract the node coordinates in the cooperative interference matrix whose energy density exceeds the dynamic threshold, and perform time-frequency inverse mapping on the coordinates and the frequency perturbation parameters of the photoacoustic coupling waveform to generate spatio-temporal trajectory parameters containing protocol vulnerability feature vectors; Perform gradient normalization processing on the spatio-temporal trajectory parameters under the network topology constraint, so that the distribution of the extreme points of the trajectory curvature converges to a preset interval with the asymmetry correlation of the node survival rate, and output the network defense response trajectory.

[0015] In a second aspect, an embodiment of the present invention provides a network defense capability verification system based on intrusion attack simulation, including: A generation module, configured to input target network topology parameters into a non-linear oscillation equation, and superimpose a random phase modulation function to generate a photoacoustic coupling waveform, where the photoacoustic coupling waveform includes frequency perturbation parameters; A trigger module, configured to inject the photoacoustic coupling waveform into a network behavior oscillation field constructed by a network node interaction strength matrix and a protocol stack layer correlation degree, and trigger an abnormal fluctuation mode equivalent to a real attack behavior in network traffic generation; An analysis module, configured to analyze the topological correlation of the network protocol interaction entropy value by reverse gradient calculation during the duration of the abnormal fluctuation mode, and generate an attack instruction sequence carrying protocol vulnerability feature vectors; An interference module, configured to perform spatio-temporal coupling on the execution path of the attack instruction sequence and the frequency perturbation parameters of the photoacoustic coupling waveform, and realize cooperative interference between the attack behavior and the network dynamics perturbation through a dynamic phase matching algorithm, and generate a network defense response trajectory with the characteristics of defense strategy mapping; A verification module, configured to output a defense effectiveness verification result through the asymmetry correlation analysis of the distribution density of the extreme points of the trajectory curvature and the network node survival rate according to the topological deformation characteristics of the network defense response trajectory.

[0016] In the embodiments of the present invention, the target network topology parameters are input into a non-linear oscillation equation, and a random phase modulation function is superimposed to generate an optoacoustic coupling waveform; the optoacoustic coupling waveform is injected into a network behavior oscillation field constructed by a network node interaction strength matrix and a protocol stack layer correlation degree to trigger an abnormal fluctuation mode in which network traffic is generated and is equivalent to a real attack behavior; during the duration of the abnormal fluctuation mode, the topological correlation of the network protocol interaction entropy value is analyzed by reverse gradient calculation to generate an attack instruction sequence carrying protocol vulnerability feature vectors; the execution path of the attack instruction sequence is spatiotemporally coupled with the frequency perturbation parameters of the optoacoustic coupling waveform, and a cooperative interference of the attack behavior and the network dynamics perturbation is realized through a dynamic phase matching algorithm to generate a network defense response trajectory with defense strategy mapping characteristics; according to the topological deformation characteristics of the network defense response trajectory, a defense effectiveness verification result is output through an asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate.

[0017] The technical solution of the present application has the following beneficial effects: Through the dynamic interaction between the optoacoustic coupling waveform and the network behavior oscillation field, the present application accurately triggers a traffic anomaly fluctuation that is exactly the same as a real attack, completely solving the problem of verification distortion caused by the simplification of attack behavior in traditional simulation tools; the adaptive attack instruction sequence generated based on the protocol vulnerability feature vector can accurately hit the vulnerability exposure path in real time, significantly improving the coverage rate and penetration success rate of the attack instructions; through the cooperative interference of the attack behavior and the network dynamics perturbation, a defense response trajectory is generated in real time, directly reflecting the blocking efficiency of the defense strategy, upgrading the defense verification from static rule matching to dynamic attack and defense game, ensuring that the verification result is highly consistent with the actual defense effect; at the same time, based on the correlation analysis of the trajectory curvature extreme points and the node survival rate, objective quantitative indicators are automatically output, eliminating the subjective deviation of manual experience evaluation, and significantly improving the interpretability of the evaluation results; the full process automation greatly shortens the verification time, supports parallel testing of large-scale network topologies, and realizes efficient and accurate defense effectiveness verification.

[0018] Furthermore, through the dynamic manifold modeling of cross-layer interaction events of the protocol stack, the topological correlation of the protocol interaction entropy is reversely analyzed. Taking the curvature change rate of the protocol state transition path as a reference quantity, the spectral weight parameters of the vulnerability feature vector are generated by combining spectral coupling operations; the penetration direction and rate parameters are calculated through tensor product, and the vector angle is dynamically corrected by using real-time topological neighborhood parameters. Finally, the attack instruction sequence is generated through time-domain convolution. Based on the dynamic manifold characteristics of the protocol state transition and the real-time correction of the topological neighborhood, high-precision extraction of the vulnerability feature vector and dynamic adaptation of the attack instruction sequence are realized, enabling the attack instructions to have protocol layer correlation, topological self-adaptability, and timing concealment at the same time, and significantly improving the modeling accuracy of the vulnerability exploitation path and the adversarial nature of the attack simulation.

[0019] These aspects or other aspects of the present invention will become more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0021] Figure 1 It is a flowchart of a method for verifying network defense capabilities based on intrusion attack simulation provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a system for verifying network defense capabilities based on intrusion attack simulation provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0022] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention.

[0023] In some processes described in the specification, claims and the above drawings of the present invention, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.

[0024] This project proposes a new method, which takes dynamic adversarial modeling as the core. By converting network topology parameters into non-linear photoacoustic coupling waveforms, it constructs a network behavior oscillation field to simulate the abnormal traffic fluctuations triggered by real attacks. Based on the reverse gradient analysis of protocol interaction entropy, it dynamically generates attack instruction sequences, and realizes the collaborative interference of attack paths and defense perturbations through spatio-temporal coupling and dynamic phase matching algorithms. Finally, according to the topological deformation characteristics of the defense response trajectory, it quantitatively evaluates the dynamic suppression ability of the defense strategy against attack behaviors. The core idea is to form a closed loop of attack simulation, protocol vulnerability mining, defense response interference and effectiveness verification: using non-linear physical models to replace traditional static attack templates, dynamically associating vulnerability characteristics through protocol entropy values, and combining network dynamics perturbations to achieve real-time adversarial mapping of attack and defense behaviors, thus breaking through the coverage limitations of traditional verification methods for dynamic scenarios.

[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0026] Figure 1 The flowchart of a method for verifying network defense capabilities based on intrusion attack simulation is provided for an embodiment of the present invention, as Figure 1 shown. The method includes: Step 101, input the target network topology parameters into the non-linear oscillation equation, and superimpose a random phase modulation function to generate a photoacoustic coupling waveform; In this step, the random phase modulation function refers to a phase perturbation function generated based on a pseudo-random sequence, which is used to simulate the randomness and uncertainty of attack behaviors in this method. Its core is to generate a phase offset that changes with time through a pseudo-random number generator (PRNG), and superimpose it on the initial waveform to enhance the dynamics and complexity of the waveform.

[0027] The photoacoustic coupling waveform refers to a dynamic signal generated through a non-linear oscillation equation, simulating the dynamic characteristics of the network topology. After superimposing random phase modulation, it forms a mixed waveform carrying network behavior characteristics, which is used as the physical signal input for subsequent attack simulations.

[0028] In the embodiments of the present application, first, parameters such as the connection weights and protocol response delays of network nodes are substituted into the nonlinear oscillation equation to solve for the initial oscillation waveform. Subsequently, a phase perturbation function that varies with time is generated based on a pseudo-random number generator and convolved with the initial waveform to generate a dynamically modulated composite waveform. Finally, signal synthesis technology is used to convert the frequency-domain modulation result into a time-domain waveform, which is output as an optoacoustic coupling waveform. This waveform not only carries the static information of the network topology but also can dynamically reflect the nonlinear characteristics of network behavior, providing a high-fidelity signal input for subsequent attack simulations.

[0029] In a practical case, in the network architecture of a large financial institution, the core switch, firewall, load balancer, and multiple servers form a complex topological structure. To verify its network security defense capabilities, first, the connection weights of network nodes (such as the communication frequency between the core switch and the firewall) and protocol response delays (such as the HTTP request processing time) are extracted and input into the nonlinear oscillation equation to generate the initial oscillation waveform, capturing nonlinear characteristics such as sudden traffic increases and delay jitters. Subsequently, a phase perturbation function that varies with time is generated based on a pseudo-random number generator and convolved with the initial waveform to generate a dynamically modulated composite waveform, simulating the randomness of attack behaviors. Finally, signal synthesis technology is used to convert the frequency-domain modulation result into a time-domain waveform, outputting the optoacoustic coupling waveform. This waveform successfully simulates the traffic burst characteristics of a DDoS attack, triggering abnormal fluctuations in network traffic, which are exactly the same as real attack behaviors, providing a high-fidelity dynamic signal input for subsequent attack simulations and significantly improving the simulation accuracy and the reliability of defense verification.

[0030] Step 102: Inject the optoacoustic coupling waveform into the network behavior oscillation field constructed from the network node interaction strength matrix and the protocol stack level correlation degree, triggering an abnormal fluctuation mode in network traffic that is equivalent to real attack behaviors. In this step, the network behavior oscillation field is a virtual field constructed from the network node interaction strength matrix and the protocol stack level correlation degree, used to simulate the dynamic behavior of network traffic. The abnormal fluctuation mode refers to the traffic anomaly characteristics equivalent to real attack behaviors, which are triggered and generated by injecting the optoacoustic coupling waveform into the oscillation field.

[0031] In the embodiments of the present application, after the photoacoustic coupling waveform is segmented by frequency band, it is injected into a network behavior oscillation field constructed by the network node interaction intensity matrix (describing the communication frequency and data throughput between nodes) and the protocol stack layer correlation degree (quantifying the data dependency relationship between different protocol layers); the resonance principle is used to stimulate the nonlinear interaction between protocol stack layers, triggering an abnormal fluctuation mode equivalent to network traffic generation and real attack behavior; the dynamic time warping (DTW) algorithm is used to match the abnormal fluctuation with the behavior pattern in the MITRE ATT&CK attack scenario library to ensure that the fluctuation pattern is exactly the same as the real attack behavior, providing a dynamic traffic basis for subsequent attack instruction generation.

[0032] In a practical case, in the intranet of a financial enterprise, first, a network node interaction intensity matrix (such as the communication frequency and data throughput between the core switch and the firewall) and a protocol stack layer correlation degree (such as the hierarchical dependency relationship of the TCP / IP protocol stack) are constructed to generate a network behavior oscillation field; the photoacoustic coupling waveform simulating a DDoS attack is segmented by frequency band and then injected into the oscillation field, and the resonance principle is used to trigger abnormal traffic fluctuations across protocol layers; the dynamic time warping (DTW) algorithm is used to match the abnormal fluctuation with the behavior pattern in the MITRE ATT&CK attack scenario library to confirm that the fluctuation is exactly the same as the DDoS attack characteristics. This process successfully generates abnormal traffic fluctuations equivalent to real attack behavior, providing a high-fidelity dynamic traffic basis for subsequent attack instruction generation and verifying the effectiveness and accuracy of the method in a complex network environment.

[0033] Step 103, during the duration of the abnormal fluctuation mode, analyze the topological correlation of the network protocol interaction entropy value through reverse gradient calculation to generate an attack instruction sequence carrying protocol vulnerability feature vectors; In this step, the protocol interaction entropy value is an index quantifying the degree of information chaos in the protocol interaction process, reflecting the risk of vulnerability exposure; Topological correlation refers to the dependency relationship between vulnerability characteristics and the positions of network nodes; The protocol vulnerability feature vector is a multi-dimensional vector composed of dimensions such as vulnerability type and exploitation path.

[0034] In the embodiments of the present application, during the continuous period of the abnormal fluctuation mode, first, based on the dynamic manifold modeling of the cross-layer interaction events in the protocol stack, the curvature change rate of the protocol state transition path is extracted as the gradient calculation reference quantity; subsequently, the spectral coupling operation is performed on the gradient calculation reference quantity and the partial derivative quantity of the protocol interaction entropy value to generate the spectral weight parameter of the protocol vulnerability feature vector; based on the spectral weight parameter and the dynamic direction parameter of the protocol interaction entropy value, the penetration direction parameter and the penetration rate parameter of the protocol vulnerability feature vector are generated through tensor product calculation; finally, the real-time topological neighborhood parameter of the network node interaction strength matrix is used to dynamically correct the penetration direction parameter, adjust the vector angle, and perform the time-domain convolution operation on the corrected penetration direction parameter and the penetration rate parameter to generate the attack instruction sequence carrying the protocol vulnerability feature vector.

[0035] In a practical case, in an industrial control system, after the abnormal fluctuation mode is triggered, dynamic manifold modeling is performed based on the cross-layer interaction events of the Modbus protocol, and the curvature change rate of the protocol state transition path is extracted as the gradient calculation reference quantity; the spectral coupling operation is performed on the reference quantity and the partial derivative quantity of the protocol interaction entropy value to generate the spectral weight parameter of the vulnerability feature vector; based on the spectral weight parameter and the dynamic direction parameter of the entropy value, the penetration direction and rate parameters are generated through tensor product calculation; the real-time topological neighborhood parameter of the PLC node is used to correct the penetration direction, adjust the vector angle, and then perform the time-domain convolution operation with the penetration rate parameter to generate the attack instruction sequence for the SCADA system, successfully simulating the penetration path of the buffer overflow attack and verifying the accuracy and efficiency of this method in a complex protocol environment.

[0036] Step 104: Spatially and temporally couple the execution path of the attack instruction sequence with the frequency perturbation parameter of the photoacoustic coupling waveform, and through the dynamic phase matching algorithm, achieve the collaborative interference between the attack behavior and the network dynamics perturbation, and generate the network defense response trajectory with the defense strategy mapping characteristics. In this step, the frequency perturbation parameter is the frequency band offset corresponding to the defense strategy response in the photoacoustic coupling waveform, and is used to dynamically adjust the trigger timing and intensity of the defense strategy. The execution path is the propagation path topology of the attack instruction among network nodes, describing the specific jump process of the attack behavior from the starting point to the ending point. The collaborative interference refers to achieving the spatio-temporal alignment between the attack behavior and the network dynamics perturbation through the dynamic phase matching algorithm, so that the defense strategy can accurately interfere with the propagation path of the attack instruction.

[0037] In the embodiments of the present application, first, a correspondence table between the hop count of the attack path and the frequency band of the photoacoustic waveform is established to ensure the spatio-temporal alignment between the attack behavior and the defense strategy. Subsequently, the dynamic phase matching algorithm (such as the phase-locked loop technology) is used to adjust the phase of the frequency band triggered by the defense strategy to synchronize it with the propagation path of the attack command, so as to achieve the collaborative interference between the attack behavior and the network dynamics perturbation. Finally, the phase change path triggered by the defense strategy is recorded to generate a network defense response trajectory with the mapping characteristics of the defense strategy, reflecting the dynamic blocking process of the defense strategy against the attack behavior.

[0038] In a practical case, first, a correspondence table between the hop count of the attack path and the frequency band of the photoacoustic waveform is established to ensure the spatio-temporal alignment between the attack behavior and the defense strategy. Subsequently, the dynamic phase matching algorithm (such as the phase-locked loop technology) is used to adjust the phase of the frequency band triggered by the defense strategy to synchronize it with the propagation path of the attack command, so as to achieve the collaborative interference between the attack behavior and the network dynamics perturbation. Finally, the phase change path triggered by the defense strategy is recorded to generate a network defense response trajectory with the mapping characteristics of the defense strategy, reflecting the dynamic blocking process of the defense strategy against the attack behavior.

[0039] Step 105, according to the topological deformation characteristics of the network defense response trajectory, output the defense effectiveness verification result through the asymmetric correlation analysis of the distribution density of the extreme points of the trajectory curvature and the survival rate of network nodes; In this step, the topological deformation characteristics are the change characteristics of the network defense response trajectory in the network topological structure, including the distribution density of the extreme points of the trajectory curvature (i.e., the inflection points where the defense strategy takes effect or fails), the trajectory length, and the node coverage range, etc., which are used to quantify the dynamic impact of the defense strategy on the attack behavior; The asymmetric correlation analysis is an analysis method based on a statistical model, which is used to study the non-linear relationship between the distribution density of the extreme points of the trajectory curvature and the survival rate of network nodes, and reveal the internal correlation between the suppression intensity of the defense strategy on the attack behavior and the node protection effect.

[0040] In the embodiments of the present application, first, based on the topological deformation characteristics of the network defense response trajectory, the distribution density of the extreme points of the trajectory curvature (i.e., the inflection points where the defense strategy takes effect or fails) is extracted to quantify the dynamic impact of the defense strategy on the attack behavior. Subsequently, the survival rate of network nodes (i.e., the proportion of nodes not captured by the attack command) is statistically analyzed, and a data mapping relationship between the distribution density of the extreme points of the trajectory curvature and the survival rate of nodes is established. Then, the asymmetric correlation analysis (such as the logistic regression model) is used to study the non-linear relationship between the two, and reveal the internal correlation between the suppression intensity of the defense strategy on the attack behavior and the node protection effect. Finally, the defense effectiveness verification result is output, including quantitative indicators such as the suppression intensity of the defense strategy on the attack and the node protection priority, providing data support for the optimization of the defense strategy.

[0041] In a practical case, during the attack and defense drill on a certain e-commerce platform, based on the topological deformation characteristics of the network defense response trajectory, the distribution density of the extreme points of the trajectory curvature was extracted, and the survival rate of network nodes was statistically analyzed. Through a logistic regression model, the non-linear relationship between the two was analyzed, and it was found that the survival rate was negatively correlated with the inflection point density, that is, the higher the inflection point density, the lower the node survival rate. Further, the verification results of the defense effectiveness were output, showing that the suppression intensity of multi-device collaborative defense (such as the linkage between WAF and IDS) against attacks was increased by 40%, and the node protection priority was significantly optimized, verifying the effectiveness and practicality of this method in a complex network environment.

[0042] To sum up, steps 101 to 105 accurately simulate the randomness of network dynamic characteristics and attack behaviors by generating photoacoustic coupling waveforms, trigger abnormal traffic fluctuations equivalent to real attack behaviors, and provide high-fidelity dynamic signal inputs for attack simulation; generate an attack instruction sequence carrying vulnerability feature vectors based on the protocol interaction entropy value to achieve dynamic adaptation of the vulnerability exploitation path; generate a defense response trajectory through collaborative interference to map in real time the dynamic blocking process of defense strategies against attack behaviors; finally, based on the asymmetric correlation analysis of the trajectory topological deformation characteristics and the node survival rate, quantitatively output the verification results of the defense effectiveness, provide data support for the optimization of defense strategies, and significantly improve the accuracy of attack simulation and the objectivity of defense evaluation.

[0043] To solve the problem that traditional attack instruction generation methods rely on static vulnerability libraries and cannot dynamically associate with network protocol states, resulting in the disconnection between the vulnerability exploitation path and the actual network environment, a method is proposed to analyze the topological relevance of the protocol interaction entropy value based on reverse gradient calculation. By dynamic manifold modeling, spectral coupling operation, and tensor product calculation, combined with real-time topological neighborhood parameters, the penetration direction of attack instructions is dynamically corrected to ensure the adaptation of attack instructions to the real-time state of the network. This method realizes the dynamic association between attack instructions and the real-time state of the protocol, and significantly improves the accuracy of the vulnerability exploitation path and the efficiency of attack simulation.

[0044] Based on this, the present invention provides a specific embodiment. In step 103, the topological relevance of the network protocol interaction entropy value is analyzed by reverse gradient calculation to generate an attack instruction sequence carrying protocol vulnerability feature vectors, which specifically includes the following steps: Step 201, based on the dynamic manifold modeling of cross-layer interaction events in the protocol stack, perform reverse gradient analysis on the topological relevance of the network protocol interaction entropy value, and extract the curvature change rate of the protocol state transition path as the gradient calculation reference quantity; In this step, the cross-layer interaction events in the protocol stack refer to data interaction events between different layers (such as the physical layer, transport layer, application layer) in the network protocol stack. For example, an application layer request is encapsulated by the transport layer and then transmitted to the physical layer; Dynamic manifold modeling refers to mapping protocol interaction events to a high-dimensional manifold space (a non-linear topological structure), and characterizing the dynamic evolution law of protocol states through the geometric characteristics of the manifold; The protocol interaction entropy value is an index that quantifies the degree of information chaos in the protocol interaction process. The higher the entropy value, the more unstable the protocol state; The curvature change rate refers to the rate of change of the geometric curvature of the protocol state transition path in the manifold space over time, and is used to characterize the mutation of the protocol state transition.

[0045] In the embodiments of the present application, first, time series data of cross-layer interaction events in the protocol stack (such as handshake success rate, packet retransmission rate) is collected, and the event sequence is mapped to a high-dimensional manifold space by using dynamic manifold modeling techniques (such as diffusion mapping algorithm). Subsequently, the topological correlation of the protocol interaction entropy value in the manifold space is analyzed through the reverse gradient analysis algorithm (such as backpropagation gradient calculation), and the curvature change rate of the state transition path is extracted. In specific implementation, the curvature change rate is obtained by calculating the second derivative of the path in the manifold tangent space, and the final output is the gradient calculation reference quantity (such as the curvature change rate matrix).

[0046] Step 202, perform a spectral coupling operation on the gradient calculation reference quantity and the partial derivative of the network protocol interaction entropy value to generate a spectral weight parameter of the protocol vulnerability feature vector; In this step, the partial derivative is the partial derivative of the protocol interaction entropy value with respect to the network topology parameter, which reflects the sensitivity of the entropy value to topological changes; The spectral weight parameter is the importance weight that characterizes the protocol vulnerability feature vector in different frequency bands.

[0047] In the embodiments of the present application, first, the gradient calculation reference quantity (curvature change rate matrix) output in step 201 is divided into frequency bands, and the frequency band boundaries are determined by the dynamic response period of the protocol interaction event (such as the TCP retransmission period). The divided frequency band parameters are frequency-domain aligned with the partial derivative of the protocol interaction entropy value (calculated by the automatic differentiation technique), and the direction parameters of the partial derivative are decomposed by using the short-time Fourier transform (STFT) to generate normalized frequency-domain response parameters. The frequency band division parameters and the normalized frequency-domain response parameters are fused through the dot product operation to generate a spectral weight parameter (such as a weight vector), and the phase consistency is ensured (such as using the phase-locked loop technique).

[0048] Step 203, based on the spectral weight parameter and the dynamic direction parameter of the network protocol interaction entropy value, generate a penetration direction parameter and a penetration rate parameter of the protocol vulnerability feature vector through tensor product calculation; In this step, the penetration direction parameter is the diffusion direction of the vulnerability feature vector in the network topology; the penetration rate parameter is the diffusion speed of the vulnerability feature vector.

[0049] In the embodiments of the present application, the dynamic direction parameter of the protocol interaction entropy value (representing the global trend of the protocol entropy change) is extracted through principal component analysis (PCA), and the Kronecker outer product operation is performed on the spectrum weight parameter (vulnerability priority distribution) and the dynamic direction parameter to generate a multi-dimensional penetration direction tensor (such as a 3×3×3 matrix, representing the diffusion path of vulnerabilities in different protocol layers, frequency bands, and node directions); at the same time, the penetration rate scalar (such as 0.85, mapped to 850 instructions per second) is generated through the matrix inner product operation to quantify the propagation speed of attack instructions. In specific implementation, the outer product operation fuses the frequency band weight and the protocol layer direction (for example, when the weight of frequency band 2 is high and the main direction of the protocol layer is HTTP, the preferred attack path of the HTTP layer is generated), and the inner product operation combines the linear relationship between the weight and the direction vector to generate the rate value, ensuring that the attack instructions are dynamically adapted to the real-time state of the network, and solving the problems of path solidification and rate blind setting in traditional methods.

[0050] Step 204, dynamically correct the penetration direction parameter by using the real-time topological neighborhood parameter of the network node interaction strength matrix, adjust the vector angle of the penetration direction parameter, and obtain the corrected penetration direction parameter; In this step, the real-time topological neighborhood parameter describes the real-time state of the neighborhood nodes in the network node interaction strength matrix and is used to dynamically correct the penetration direction parameter.

[0051] The adjustment of the vector angle means optimizing the propagation path of the attack instruction by adjusting the vector angle of the penetration direction parameter.

[0052] In the embodiments of the present application, first, an interaction strength matrix is generated based on the real-time monitored network node interaction traffic, and the topological neighborhood parameter is obtained in combination with the neighbor discovery protocol. Subsequently, the cosine similarity between the penetration direction vector and the neighborhood node direction vector is calculated to evaluate its adaptability. The angle of the penetration direction vector is dynamically adjusted through the gradient descent method to gradually align it with the direction of the high interaction strength nodes, and finally the corrected penetration direction parameter is generated. This process ensures that the penetration direction can adapt to the dynamic changes of the network topology, thereby improving the adaptability of the attack instruction sequence and the authenticity of the attack simulation.

[0053] Step 205, perform a time-domain convolution operation on the corrected penetration direction parameter and the penetration rate parameter to generate an attack instruction sequence; In this step, the time-domain convolution operation: a method of fusing the corrected penetration direction parameter and the penetration rate parameter in the time domain, used to generate an attack instruction sequence.

[0054] In the embodiment of the present application, the corrected penetration direction parameter (direction vector) and the penetration rate parameter (rate scalar) are first aligned in the time domain to ensure the consistency of the two in the time dimension. Subsequently, a one-dimensional convolution kernel is used to perform sliding window weighted fusion of the parameters, and the time length of the sliding window is determined by the dynamic response cycle of the network protocol (such as the TCP retransmission cycle). During the convolution operation, the direction vector and the rate scalar are multiplied and accumulated point by point in the time window to generate a time-related attack instruction sequence. The final output instruction sequence can accurately simulate the time distribution characteristics of the attack behavior and provide highly realistic attack simulation data for network defense capability verification.

[0055] Here is a specific example: In a certain enterprise intranet, we first collect cross-level interaction event data between HTTP (application layer) and TCP (transport layer), and extract the curvature change rate of the protocol state transition path through dynamic manifold modeling. Subsequently, we divide the curvature change rate into frequency bands according to the TCP retransmission cycle, align it with the partial derivative of the HTTP protocol interaction entropy value in the frequency domain, and generate the spectrum weight parameter. Next, we generate the penetration direction parameter and penetration rate parameter through tensor product calculation, and adjust the penetration direction vector angle according to the real-time topology neighborhood parameter to point to the load balancing node with high interaction intensity. Finally, we use time domain convolution operation to generate an attack instruction sequence, simulate the behavior of sending 500 malformed TCP packets per second, trigger the defense system to respond, and verify its detection capability.

[0056] In summary, this method achieves accurate extraction of protocol vulnerability feature vectors through dynamic manifold modeling and reverse gradient analysis; spectrum coupling operation and tensor product calculation enhance the frequency domain adaptability of attack instructions; dynamic correction based on real-time topological neighborhood ensures that the instruction sequence is synchronized with the dynamic changes of the network. The final generated attack instruction sequence can simulate the spatiotemporal characteristics of real attacks, significantly improving the accuracy and automation of defense capability verification.

[0057] In order to improve the accuracy and dynamic response capability of protocol vulnerability detection, this method optimizes the detection performance through frequency domain feature fusion and dynamic quantitative evaluation, maps the protocol status and vulnerability features into the frequency domain space, and solves the problems of disconnection between static features and real-time protocol status, frequency band splitting and phase mismatch in traditional detection.

[0058] Based on this, the present invention provides a specific embodiment, wherein step 202 performs a spectrum coupling operation on the gradient calculation reference amount and the partial derivative of the network protocol interaction entropy value to generate a spectrum weight parameter of the protocol vulnerability feature vector, specifically comprising the following steps: Step 301, dividing the gradient calculation reference amount into frequency bands, extracting the fluctuation amplitude of the curvature change rate in each frequency band as a frequency band division parameter, wherein the frequency band division parameter is determined by the dynamic response cycle of the protocol interaction event; In this step, the gradient calculation reference quantity refers to a multi-dimensional data set that reflects dynamic characteristics such as traffic mutation and protocol field anomalies during protocol interaction, and includes sub-parameters such as the amplitude of time series fluctuations and the dispersion of protocol fields; The frequency band division parameter is a frequency band interval divided by the dynamic response period of protocol interaction events (such as TCP handshake frequency, HTTP request interval), and its core index is the amplitude of the curvature change rate within each frequency band (i.e., the mutation intensity of the protocol state in the frequency domain).

[0059] In the embodiment of the present application, first, based on the protocol dynamic response period (such as the DNS query period of 0.5 - 2 seconds), the frequency band division boundary is determined. The wavelet transform technology is used to perform multi-scale decomposition on the gradient calculation reference quantity, and the root mean square value of the curvature change rate within each frequency band is extracted as the amplitude index. For example, the high-frequency band (2 - 5Hz) corresponds to short-term intensive attack behaviors (such as SYN Flood), and the low-frequency band (0.1 - 0.5Hz) corresponds to slow penetration attacks. The frequency band division parameter is dynamically updated through the sliding window mechanism to ensure synchronization with the real-time protocol state.

[0060] Step 302, perform frequency domain alignment processing on the frequency band division parameter and the partial derivative of the network protocol interaction entropy value. The frequency domain alignment processing process includes performing fluctuation phase decomposition on the direction parameter of the partial derivative to generate a normalized frequency domain response parameter; In this step, the partial derivative of the network protocol interaction entropy value is a quantization index that characterizes the change rate of the chaos degree of protocol fields (such as IP address distribution, port number dispersion).

[0061] In the embodiment of the present application, first, perform short-time Fourier transform (STFT) on the partial derivative of the entropy value, and extract the phase deviation in the overlapping region of the phase spectrum and the frequency band division parameter; then, fit the phase compensation function (such as a linear phase corrector) by the least squares method to eliminate the phase lag caused by protocol stack delay in the high-frequency band; finally, recombine the corrected phase component and the original amplitude component to generate a normalized frequency domain response parameter. For example, in the detection of HTTP protocol vulnerabilities, for the mutation of the entropy value of the request header field (such as X-Forwarded-For forgery attack), the detection error caused by response delay is eliminated through phase alignment.

[0062] Step 303, perform a dot product operation on the normalized frequency domain response parameter and the frequency band division parameter to generate the spectral weight parameter of the protocol vulnerability feature vector. The dot product operation process needs to maintain the phase consistency of the curvature change rate and the partial derivative within each frequency band.

[0063] In this step, the phase consistency constraint means that the phase angle difference between the two parameters in the dot product operation is required to be less than a preset threshold (such as π / 6 radians).

[0064] In the embodiment of the present application, the normalized frequency domain response parameters are first converted into complex form (amplitude × e^(jθ)), where θ is the corrected phase angle; then the frequency band division parameters are processed in the same complex form; finally, a frequency-by-frequency dot product operation is performed within the frequency band that satisfies the phase consistency constraint (Δθ<π / 6) to generate a spectrum weight parameter containing a real part (threat level) and an imaginary part (dynamic sensitivity). Taking SMTP protocol vulnerability detection as an example, the real part of the weight parameter for the high frequency band (abnormal email transmission frequency) can reach 0.83, which is significantly higher than 0.12 for the low frequency band.

[0065] Here is a specific example: When a certain enterprise server was attacked by tens of thousands of SYN message floods per second, the system first divided the high-frequency band (1-5Hz) and low-frequency band (0.3-1Hz) based on the protocol interaction cycle (1-3 seconds), and extracted the curvature fluctuation amplitude in the high-frequency band (up to 0.82, exceeding the threshold of 0.6) through wavelet transform, accurately locking the abnormal traffic. Subsequently, the frequency band parameters and the partial derivative of the SYN / ACK response entropy value were phase-decomposed, and the 0.2 radian phase offset caused by the protocol stack delay was eliminated by Fourier correction to generate normalized frequency domain response parameters (amplitude weight 0.89). Finally, the high-frequency band parameters and the corrected parameters were fused through the phase-consistent dot product operation to generate a threat weight of 0.91 (far exceeding the 0.65 of traditional static detection), triggering a real-time cleaning strategy. This method combines dynamic thresholds and machine learning models (such as the improved random forest algorithm) to increase the attack detection rate from 65.2% to 98.7%, reduce the false positive rate to 1.3%, and compress the response delay to 12ms, effectively distinguishing normal traffic peaks from attack behaviors. On the defense level, Nginx speed limit strategy, IP blacklist and whitelist, and distributed traffic cleaning nodes are used to achieve attack containment in seconds, ensuring that the business bandwidth remains stable at more than 95%.

[0066] In summary, this solution effectively responds to high-frequency DDoS attacks through dynamic frequency domain fusion technology. Step 301 performs intelligent frequency band division based on the protocol dynamic response cycle, and uses wavelet transform to accurately capture the characteristics of short-term intensive and slow penetration attacks; Step 302 eliminates protocol delays through short-time Fourier transform, reduces the false positive rate, and generates normalized parameters; Step 303 increases the threat weight under the phase consistency constraint and predicts the attack intention. Combining AI algorithms with CNN models, the detection rate is significantly improved, the false positive rate is reduced, the computing load is reduced, a rapid response is achieved, and robust protection is provided for high-concurrency scenarios.

[0067] To solve the problem of reduced detection accuracy caused by the mismatch between the protocol state transition time window and the frequency band boundary in traditional frequency domain alignment techniques, this method starts from the dynamic response period of protocol interaction, combines the correlation between frequency domain features and protocol states, solves the problems of frequency band fragmentation and phase mismatch in traditional techniques, and provides an efficient and dynamic solution for protocol vulnerability detection.

[0068] Based on this, the present invention provides a specific embodiment. In step 302, the frequency domain alignment process is performed on the partial derivative of the frequency band division parameter and the network protocol interaction entropy value to generate a normalized frequency domain response parameter, which specifically includes the following steps: Step 401, based on the dynamic response period of the protocol interaction event, dynamically adjust the frequency band boundary of the frequency band division parameter, and output the adjusted frequency band division parameter; In this step, the dynamic response period refers to the time interval during which the network protocol interaction event transfers between different protocol states, reflecting the real-time dynamic characteristics of the protocol interaction; The frequency band boundary is the boundary value that defines the frequency range of each frequency band in the frequency band division parameter. Its dynamic adjustment is performed according to the time window of the protocol state transition. The shorter the time window, the higher the corresponding frequency band boundary frequency, and vice versa.

[0069] In the embodiment of the present application, first, monitor the network protocol interaction event to obtain its dynamic response period. According to the length of the dynamic response period, calculate the corresponding frequency band boundary adjustment amount, and then adjust the frequency band boundary in the frequency band division parameter. The frequency range of each frequency band in the adjusted frequency band division parameter is negatively correlated with the time window of the protocol state transition, that is, the shorter the time window, the higher the frequency band frequency, and vice versa. Finally, output the adjusted frequency band division parameter to provide dynamically adapted frequency band information for subsequent steps.

[0070] Step 402, decompose the partial derivative direction parameter of the network protocol interaction entropy value into multiple orthogonal phase components. Based on the adjusted frequency band division parameter, perform frequency band matching truncation on each orthogonal phase component, and only retain the frequency components in the same frequency band as the adjusted frequency band division parameter, and output the truncated orthogonal phase components; In this step, the partial derivative direction parameter of the network protocol interaction entropy value reflects the direction characteristics of the entropy value change during the protocol interaction process. Decomposing it into multiple orthogonal phase components is to decompose the complex partial derivative direction parameter into multiple simple and independent components for subsequent processing; Frequency band matching truncation means retaining the frequency components in the same frequency band as the adjusted frequency band division parameter in each orthogonal phase component, and truncating and removing other frequency components to achieve frequency domain alignment.

[0071] In the embodiment of the present application, first, the Fourier transform is used to decompose the direction parameter of the partial derivative of the network protocol interaction entropy value into multiple orthogonal phase components. Then, according to the adjusted frequency band division parameters, each orthogonal phase component is subjected to frequency band matching truncation. Specifically, each orthogonal phase component is filtered by a filter, and only the frequency components in the same frequency band as the adjusted frequency band division parameters are retained, and other frequency components are filtered out. Finally, the truncated orthogonal phase components are output, providing the orthogonal phase component data after frequency domain alignment for subsequent steps.

[0072] Step 403, within the same frequency band, perform phase offset compensation on the truncated orthogonal phase component and the adjusted frequency band division parameters, so that the phase difference between the two converges to a preset threshold, and perform frequency band normalization on the amplitude of the compensated component to generate a normalized frequency domain response parameter; In this step, phase offset compensation refers to adjusting the phase of the truncated orthogonal phase component so that the phase difference between it and the adjusted frequency band division parameters converges to a preset threshold to eliminate the influence of phase deviation on subsequent processing.

[0073] Frequency band normalization refers to performing normalization processing on the amplitude of the compensated component within each frequency band so that its amplitude value is within a certain range, facilitating subsequent unified processing and analysis.

[0074] In the embodiment of the present application, first, the phase difference between the truncated orthogonal phase component and the adjusted frequency band division parameters is calculated. Then, according to the magnitude of the phase difference, a phase correction algorithm is used to perform phase offset compensation on the truncated orthogonal phase component so that the phase difference between the two converges to a preset threshold. Then, the amplitude of the compensated component is normalized within each frequency band. Specifically, the amplitude value of the compensated component is normalized to the range [0, 1] through a normalization algorithm. Finally, a normalized frequency domain response parameter is generated, providing standardized frequency domain data for subsequent network protocol interaction analysis and anomaly detection, etc.

[0075] The following is a specific example: In a network environment, it is necessary to perform frequency-domain analysis on the interaction process of the HTTP protocol to detect abnormal behaviors. First, in step 401, the dynamic response period of the HTTP protocol interaction event is monitored to be 10 ms. Based on this dynamic response period, the corresponding frequency band boundary adjustment amount is calculated, and the frequency band boundaries in the frequency band division parameters are adjusted to obtain the adjusted frequency band division parameters. For example, the low-frequency band boundary is adjusted from 0.1 Hz to 0.2 Hz, and the high-frequency band boundary is adjusted from 10 Hz to 20 Hz. Then, in step 402, the partial derivative direction parameter of the HTTP protocol interaction entropy value is decomposed into multiple orthogonal phase components. Then, according to the adjusted frequency band division parameters, each orthogonal phase component is subjected to frequency band matching truncation, and only the frequency components with frequencies ranging from 0.2 Hz to 20 Hz are retained, and other frequency components are truncated. Finally, in step 403, within the same frequency band, phase offset compensation is performed on the truncated orthogonal phase components and the adjusted frequency band division parameters to make the phase difference between the two converge to a preset threshold, such as π / 6 radians. Then, the amplitude of the compensated component is subjected to frequency band normalization processing to generate normalized frequency-domain response parameters. Through this series of processes, finally, standardized frequency-domain data is obtained, which can be used for subsequent abnormal detection of HTTP protocol interactions.

[0076] Through the frequency-domain alignment processing in the above steps 401 to 403, accurate matching between the frequency band division parameters and the partial derivative of the network protocol interaction entropy value in the frequency domain is achieved. Dynamically adjusting the frequency band boundaries can adapt to the real-time dynamic characteristics of protocol interactions, improving the flexibility and adaptability of frequency band division; frequency band matching truncation removes irrelevant frequency components, reducing noise interference; phase offset compensation and frequency band normalization processing further improve the consistency and comparability of data. The finally generated normalized frequency-domain response parameters provide high-quality and standardized frequency-domain data for network protocol interaction analysis and abnormal detection, improving the accuracy and reliability of detection, and being able to effectively cope with complex and changeable network environments.

[0077] To solve the problem that it is difficult to trigger the equivalent fluctuation mode of real attack behaviors in traditional attack simulations, this method realizes the non-linear resonance of traffic perturbation and protocol interaction by constructing a network behavior oscillation field and injecting optoacoustic coupling waveforms into it. Based on the tensor coupling of the network node interaction intensity matrix and the protocol stack layer correlation degree, an oscillation field is generated by combining non-linear perturbation terms; the phase of the optoacoustic waveform is modulated according to the protocol response delay threshold to align it with the node interaction intensity; by dynamically matching the waveform energy density and the protocol stack weight, node traffic fluctuations are triggered to generate an abnormal fluctuation mode equivalent to a real attack, providing a solution for high-fidelity attack simulation.

[0078] Based on this, the present invention provides a specific embodiment. In step 102, injecting the photoacoustic coupling waveform into the network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack layer correlation degree triggers an abnormal fluctuation mode in which the network traffic generation is equivalent to the real attack behavior, which specifically includes the following steps: Step 501, generating a network node interaction intensity matrix based on the interaction traffic of network nodes and the protocol handshake success rate, and constructing a network behavior oscillation field through tensor coupling and a non-linear perturbation term in combination with the column vector weights of the protocol stack layer correlation degree; In this step, the non-linear perturbation term refers to introducing dynamic changes to simulate the complexity and uncertainty of network behavior, so that the oscillation field can dynamically reflect the non-linear characteristics of network behavior.

[0079] In the embodiment of the present application, first, the interaction traffic and protocol handshake success rate of each node in the network are statistically analyzed to generate a network node interaction intensity matrix. Then, in combination with the column vector weights of the protocol stack layer correlation degree, the matrix and the weights are multi-dimensionally correlated using tensor coupling technology. Finally, a non-linear perturbation term is introduced to construct an oscillation field that can dynamically reflect network behavior. Ultimately, the network behavior oscillation field is obtained through this process, providing a basis for subsequent steps.

[0080] Step 502, performing phase modulation on the frequency perturbation parameter of the photoacoustic coupling waveform according to the protocol response delay threshold in the protocol stack layer correlation degree to generate a modulated photoacoustic waveform, and aligning the phase parameter of the photoacoustic coupling waveform with the row vector weights of the network node interaction intensity matrix; In this step, the network node interaction intensity matrix is used to quantify the interaction intensity between each node in the network, and its elements are determined by the interaction traffic and protocol handshake success rate between nodes; The protocol response delay threshold is used to evaluate the response speed of each layer in the protocol stack, reflecting the delay characteristics of protocol interaction, and is a key parameter for simulating the dynamic changes of network behavior.

[0081] The photoacoustic coupling waveform is a signal used to simulate network traffic fluctuations, and its frequency and phase characteristics can be dynamically adjusted to match network behavior characteristics.

[0082] Phase modulation refers to adjusting the phase parameter of the waveform to match the network behavior characteristics and enhancing the coupling effect between the waveform and the network behavior oscillation field.

[0083] Row vector weight alignment refers to aligning the phase parameter of the modulated photoacoustic waveform with the row vector weights of the network node interaction intensity matrix to ensure the consistency between the waveform and network behavior characteristics, providing conditions for subsequent non-linear resonance.

[0084] In the embodiments of the present application, first, according to the protocol response delay threshold in the protocol stack level correlation, the frequency perturbation parameter of the photoacoustic coupling waveform is determined. Then, the waveform is processed using phase modulation technology to generate a modulated photoacoustic waveform. Finally, the phase parameter of the modulated photoacoustic waveform is aligned with the row vector weights of the network node interaction strength matrix to ensure the consistency between the waveform and the network behavior characteristics. Ultimately, a modulated photoacoustic waveform that matches the network behavior characteristics is obtained.

[0085] Step 503: Inject the modulated photoacoustic waveform into the network behavior oscillation field. By dynamically matching the waveform energy density with the column vector weights of the protocol stack level correlation, trigger the non-linear resonance of node traffic fluctuations and protocol interactions, and generate an abnormal fluctuation pattern. In this step, the waveform energy density is used to quantify the energy distribution of the photoacoustic coupling waveform, reflecting the intensity and dynamic change characteristics of the waveform.

[0086] The non-linear resonance dynamically matches the waveform energy density with the column vector weights of the protocol stack level correlation, causing the network traffic fluctuations and protocol interactions to produce a resonance effect, thereby generating an abnormal fluctuation pattern equivalent to the real attack behavior.

[0087] In the embodiments of the present application, first, the modulated photoacoustic waveform is injected into the network behavior oscillation field constructed in step 501. At this time, the oscillation field has been dynamically modeled through the column vector weights of the network node interaction strength matrix and the protocol stack level correlation, and can reflect the dynamic characteristics of network traffic and protocol interactions. Then, by dynamically adjusting the energy density of the waveform to match the column vector weights of the protocol stack level correlation. This process utilizes the principle of non-linear dynamics. Through the dynamic adjustment of the energy density, the injected photoacoustic waveform resonates with the node traffic fluctuations and protocol interactions in the network behavior oscillation field. Ultimately, through this non-linear resonance effect, an abnormal fluctuation pattern equivalent to the real attack behavior is generated, providing an accurate simulation signal for subsequent network anomaly detection.

[0088] The following is a specific example: In an enterprise network environment, it is necessary to detect potential DDoS attack behaviors. First, in step 501, by monitoring the interaction traffic and protocol handshake success rate of each node in the network, a network node interaction intensity matrix is generated. Combining the column vector weights of the protocol stack layer correlation degree, a network behavior oscillation field is constructed using tensor coupling and a non-linear perturbation term. Next, in step 502, according to the protocol response delay threshold in the protocol stack layer correlation degree, phase modulation is performed on the frequency perturbation parameter of the photoacoustic coupling waveform to generate a modulated photoacoustic waveform, and its phase parameter is aligned with the row vector weight of the network node interaction intensity matrix. Finally, in step 503, the modulated photoacoustic waveform is injected into the network behavior oscillation field. By dynamically matching the waveform energy density with the column vector weight of the protocol stack layer correlation degree, non-linear resonance of node traffic fluctuations and protocol interactions is triggered to generate an abnormal fluctuation pattern. Through this process, an abnormal fluctuation pattern equivalent to the real DDoS attack behavior is successfully simulated, providing strong support for subsequent attack detection.

[0089] Through the above steps 501 to 503, this solution successfully constructs a network behavior oscillation field that can dynamically simulate real attack behaviors. By combining the network node interaction intensity matrix with the protocol stack layer correlation degree, the network behavior characteristics are accurately characterized; the phase modulation and alignment of the photoacoustic coupling waveform ensure the consistency between the simulated signal and the network behavior; dynamically matching the waveform energy density with the protocol stack layer correlation degree weight triggers non-linear resonance to generate an abnormal fluctuation pattern equivalent to the real attack behavior. This solution not only improves the accuracy of network anomaly detection but also provides a new technical means for network behavior analysis, capable of effectively coping with security threats in complex network environments.

[0090] To solve the problem that the dynamic characteristics of attack behaviors cannot be accurately simulated in existing network anomaly detection, it is found through research that traditional methods cannot effectively capture the interaction characteristics between the protocol layer and the physical layer, resulting in insufficient detection accuracy and real-time performance. For this reason, this application proposes a new method based on dynamic energy coupling and phase locking. Through cross-layer interaction and non-linear resonance technologies, deep cooperation between the protocol layer and the physical layer is achieved. This method solves the problem of separation between the protocol layer and the physical layer in traditional detection, improves the generation accuracy of abnormal fluctuation patterns, and provides more accurate technical support for network anomaly detection.

[0091] Based on this, the present invention provides a specific embodiment. In step 503, injecting the modulated photoacoustic waveform into the network behavior oscillation field, by dynamically matching the waveform energy density with the column vector weight of the protocol stack layer correlation degree, triggering non-linear resonance of node traffic fluctuations and protocol interactions, and generating an abnormal fluctuation pattern, specifically includes the following steps: Step 601: Based on the column vector weights of the protocol stack layer correlation degree, calculate the energy density distribution required for each protocol layer in real time, and generate a dynamic energy coupling coefficient that matches the row vector weights of the network node interaction strength matrix; In this step, the column vector weights of the protocol stack layer correlation degree represent the correlation strength and importance between different protocol layers, and are used to quantify the contributions of each protocol layer in network behavior; The energy density distribution reflects the energy distribution required for each protocol layer in the dynamic interaction process, and is used to simulate the dynamic behavior of the protocol layer; The dynamic energy coupling coefficient is used to connect the energy distribution of the protocol stack layer with the network node interaction strength, ensuring dynamic matching and coordination between the two.

[0092] In the embodiment of the present application, first, according to the column vector weights of the protocol stack layer correlation degree, calculate the energy density distribution required for each protocol layer in real time. This process is achieved by dynamically monitoring network traffic and protocol interaction status, ensuring that the energy density distribution can reflect the changes in network behavior in real time. Then, based on the energy density distribution and the row vector weights of the network node interaction strength matrix, calculate the dynamic energy coupling coefficient. This coefficient is dynamically adjusted through an optimization algorithm to ensure energy matching between the protocol layer and node interaction. Finally, the generated dynamic energy coupling coefficient is used for subsequent cross-layer interaction.

[0093] Step 602: Perform cross-layer interaction between the dynamic energy coupling coefficient and the frequency domain parameters of the modulated photoacoustic waveform. By iteratively adjusting the waveform phase offset, make the energy density distribution of the protocol stack layer and the spectral peak of the node traffic fluctuation form phase locking in the same frequency band; In this step, cross-layer interaction refers to combining the energy density distribution of the protocol layer with the frequency domain parameters of the photoacoustic waveform through the dynamic energy coupling coefficient to achieve coordination between the protocol layer and the physical layer; Phase locking is achieved by iteratively adjusting the waveform phase offset, so that the energy density distribution of the protocol layer and the spectral peak of the node traffic fluctuation are consistent in the same frequency band, enhancing the stability and consistency of the signal.

[0094] In the embodiment of the present application, first, combine the dynamic energy coupling coefficient generated in step 601 with the frequency domain parameters of the modulated photoacoustic waveform to achieve cross-layer interaction. Then, adjust the phase offset of the photoacoustic waveform through an iterative algorithm, so that the energy density distribution of the protocol stack layer and the spectral peak of the node traffic fluctuation are gradually aligned in the same frequency band. This process utilizes the principle of nonlinear dynamics and is optimized through multiple iterations to finally achieve phase locking. Finally, the result of phase locking provides a stable signal basis for subsequent nonlinear resonance.

[0095] Step 603: When the number of locked protocol layers in the protocol stack hierarchy accumulates to the dynamic convergence threshold, perform a tensor convolution operation on the locked photoacoustic waveform parameters and the network node interaction intensity matrix to generate a non-linear resonance signal in the cross-protocol layer - physical waveform domain, and output an abnormal fluctuation pattern. In this step, the dynamic convergence threshold is a threshold used to determine whether the phase lock reaches a stable state. When the number of locked protocol layers reaches this threshold, it indicates that the system enters a stable resonance state. The tensor convolution operation is a multi-dimensional operation method used to deeply fuse the locked photoacoustic waveform parameters and the network node interaction intensity matrix to generate a non-linear resonance signal in the cross-protocol layer - physical waveform domain. The abnormal fluctuation pattern is the finally generated signal, which is used to simulate the dynamic characteristics of real attack behaviors and provide accurate references for network anomaly detection.

[0096] In the embodiment of this application, first, the number of locked protocol layers is monitored. When it accumulates to the dynamic convergence threshold, it indicates that the system enters a stable resonance state. Then, a tensor convolution operation is performed on the locked photoacoustic waveform parameters and the network node interaction intensity matrix. This process is implemented through a tensor convolution algorithm, which can fully integrate the information of the protocol layer and the physical layer to generate a non-linear resonance signal in the cross-protocol layer - physical waveform domain. Finally, the output abnormal fluctuation pattern can accurately simulate the dynamic characteristics of real attack behaviors and provide strong support for network anomaly detection.

[0097] The following is a specific example: In an enterprise network, it is necessary to detect potential DDoS attack behaviors. Traditional methods often rely on fixed feature extraction and rule matching, and it is difficult to cope with complex and changeable attack patterns. However, this solution dynamically calculates the energy density distribution of each protocol layer by real-time monitoring of network traffic and protocol interaction status, and generates a dynamic energy coupling coefficient that matches the network node interaction intensity. This process utilizes the characteristics of the protocol stack hierarchy correlation degree and can accurately reflect the dynamic changes of network behaviors.

[0098] Subsequently, the system performs cross-layer interaction between the dynamic energy coupling coefficient and the modulated photoacoustic waveform. By iteratively adjusting the waveform phase, the energy distribution of the protocol layer is made to be consistent with the spectral peak of the node traffic fluctuation in the same frequency band to form a phase lock. This cross-layer interaction and phase lock mechanism significantly enhances the stability and consistency of the signal and can effectively identify weak abnormal signals.

[0099] When the number of phase-locked protocol layers accumulates to the dynamic convergence threshold, the system generates a non-linear resonance signal across the protocol layer - physical waveform domain through tensor convolution operations. This process not only integrates the information of the protocol layer and the physical layer, but also significantly improves the computational efficiency through the compact structure and multilinear characteristics of the tensor network. The finally output abnormal fluctuation pattern can accurately simulate the dynamic characteristics of real DDoS attacks, providing strong support for network anomaly detection.

[0100] Through the above steps 601 - 603, this solution has successfully achieved the deep cooperation between the protocol layer and the physical layer, accurately simulating the dynamic characteristics of network abnormal behaviors. Through the generation of the dynamic energy coupling coefficient, the energy matching between the protocol layer and node interactions is achieved; through cross-layer interaction and phase locking, the stability and consistency of the signal are enhanced; through tensor convolution operations, a non-linear resonance signal across the protocol layer - physical waveform domain is generated, and the finally output abnormal fluctuation pattern can accurately reflect the dynamic characteristics of real attack behaviors. This solution significantly improves the accuracy and reliability of network anomaly detection, providing a new technical means for security protection in complex network environments.

[0101] Considering the limitations of the existing optoacoustic coupling waveform generation methods in network anomaly detection, traditional methods are difficult to fully reflect the complexity and dynamic changes of the network topology, resulting in insufficient matching between the generated waveforms and real network behaviors. For this reason, this application proposes an optoacoustic coupling waveform generation method based on target network topology parameters, which solves the problems of single waveforms and inability to adapt to complex network environments in traditional waveform generation methods, significantly improving the accuracy and effectiveness of the waveforms, and providing a more accurate signal basis for network anomaly detection.

[0102] Based on this, the present invention provides a specific embodiment. In step 101, inputting the target network topology parameters into the non-linear oscillation equation and superimposing a random phase modulation function to generate an optoacoustic coupling waveform, which specifically includes the following steps: Step 701, based on the target network topology parameters, extract the connectivity, path length, and topological dynamic change rate parameters of network nodes, generate a random phase modulation function through Fourier series expansion and probability distribution model, and introduce the random phase modulation function as an additional term into the non-linear oscillation equation; In this step, the target network topology parameters include the connection relationship, path length, and dynamic change rate of network nodes, etc., which are used to describe the structural characteristics and dynamic behaviors of the network.

[0103] In the embodiments of the present application, first, the connectivity, path length, and topological dynamic change rate in the target network topology parameters are extracted. Then, based on these parameters, the topological features are decomposed into multiple frequency components by using the Fourier series expansion method, and a random phase modulation function is generated in combination with the probability distribution model. By introducing a random phase offset, this function simulates the randomness and uncertainty of network behavior. Finally, the random phase modulation function is introduced as an additional term into the nonlinear oscillation equation to provide a dynamic modulation basis for subsequent waveform generation.

[0104] Step 702: Input the target network topology parameters and the random phase modulation function into the nonlinear oscillation equation, and calculate the photoacoustic coupling waveform through a numerical solution method. In the embodiments of the present application, the target network topology parameters and the random phase modulation function are substituted into the nonlinear oscillation equation. The equation is solved through a numerical solution method (such as the Runge-Kutta method) to obtain the time-domain expression of the photoacoustic coupling waveform. This process utilizes the dynamic characteristics of the nonlinear oscillation equation and combines the randomness of the random phase modulation function to generate a photoacoustic coupling waveform that can reflect the dynamic changes of the network topology.

[0105] Step 703: Optimize the calculated photoacoustic coupling waveform to eliminate noise and outliers, and verify the accuracy and effectiveness of the waveform. In this step, the accuracy and effectiveness of the waveform refer to verifying whether the waveform can truly reflect network behavior to ensure that the generated waveform can be used for subsequent network anomaly detection.

[0106] In the embodiments of the present application, first, noise detection and outlier analysis are performed on the photoacoustic coupling waveform calculated in step 702. The noise components in the waveform are eliminated through a filtering algorithm (such as wavelet transform filtering), and outliers are identified and removed through statistical analysis methods. Then, through comparison and verification with known network behavior data, it is ensured that the optimized waveform can accurately reflect the dynamic changes of the network topology, thereby generating a high-quality photoacoustic coupling waveform.

[0107] Step 704: Output the optimized photoacoustic coupling waveform as multi-dimensional time series data and store it in a structured file format. In this step, the multi-dimensional time series data: waveform data output in the form of a time series, containing information in multiple dimensions, for subsequent analysis and storage. The structured file format refers to storing the waveform data in a format that is convenient for reading and processing, such as CSV or HDF5.

[0108] In the embodiments of the present application, the optimized photoacoustic coupling waveform is converted into a multi-dimensional time series data format. The waveform data at each time point contains information in multiple dimensions, reflecting the dynamic characteristics of the network topology. Finally, this data is stored in a structured file format for subsequent analysis and processing, providing standardized input data for network anomaly detection.

[0109] The following is a specific example: In an enterprise network, it is necessary to generate a photoacoustic coupling waveform that can reflect the dynamic behavior of the network for subsequent DDoS attack detection. First, network topology parameters are extracted, including the node connectivity, path length, and topological dynamic change rate, and a random phase modulation function is generated through Fourier series expansion and probability distribution model, which is introduced into the nonlinear oscillation equation (step 701). Then, these parameters and functions are input into the nonlinear oscillation equation, and the photoacoustic coupling waveform is calculated through numerical solution methods (step 702). Next, the generated waveform is optimized to eliminate noise and outliers, and its accuracy and effectiveness are verified (step 703). Finally, the optimized waveform is output as multi-dimensional time series data and stored in a structured file format for subsequent analysis and detection (step 704). Through this process, the generated photoacoustic coupling waveform can accurately reflect the dynamic behavior of the network, providing a high-quality signal basis for DDoS attack detection.

[0110] In summary, through the above steps 701-704, this solution successfully generates a photoacoustic coupling waveform that can accurately reflect the dynamic changes of the network topology. By extracting network topology parameters and introducing a random phase modulation function, the dynamicity and complexity of the waveform are enhanced; by using the nonlinear oscillation equation and numerical solution methods, a high-quality photoacoustic coupling waveform is generated; through the optimization and verification of the waveform, its accuracy and effectiveness are ensured; and finally, it is output in the form of multi-dimensional time series data, providing standardized input for network anomaly detection. This solution significantly improves the generation accuracy and adaptability of the photoacoustic coupling waveform, providing more efficient and accurate technical support for anomaly detection in complex network environments.

[0111] Considering the problem that it is difficult to accurately reflect the impact of defense measures on the network topology structure and node status in existing network defense effectiveness evaluation methods, traditional methods often rely only on static indicators and cannot comprehensively evaluate the dynamic effects of defense strategies. Therefore, the present application proposes an asymmetric correlation analysis method based on the topological deformation characteristics and network node survival rate of network defense response trajectories. This method solves the problem that traditional evaluation methods cannot dynamically reflect the defense effect, can verify the effectiveness of defense measures in real time, and provides a scientific basis for the optimization of network defense strategies.

[0112] Based on this, the present invention provides a specific embodiment. In step 105, according to the topological deformation characteristics of the network defense response trajectory, the defense effectiveness verification result is output through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate, which specifically includes the following steps: Step 801: Based on the topological deformation characteristics of the network defense response trajectory, calculate the distribution density of the trajectory curvature extreme points and generate a distribution density vector; In this step, the topological deformation characteristics of the network defense response trajectory refer to the change characteristics of the network topological structure during the defense process, reflecting the dynamic impact of the defense behavior on the network structure; The trajectory curvature extreme point refers to the point with the most significant curvature change in the defense response trajectory, reflecting the key turning point of the defense behavior; The distribution density vector describes the distribution density of the trajectory curvature extreme points in different regions and is used to quantify the spatial characteristics of the defense behavior.

[0113] In the embodiment of the present application, first, the topological deformation characteristics of the network defense response trajectory are extracted. By calculating the curvature change of the trajectory, the curvature extreme points are identified. Then, the distribution density of these extreme points in different regions is statistically analyzed to generate a distribution density vector. This process uses differential geometry methods to calculate the curvature and obtains the distribution density through spatial statistical analysis, ultimately providing a quantitative description for subsequent analysis.

[0114] Step 802: Collect the network node survival status data, quantify the network node survival rate, and generate a node survival rate vector by statistically analyzing the survival time and survival ratio of the network nodes; In this step, the network node survival status data records the survival status of each node in the network during the defense process, including survival or failure; the node survival rate is used to quantify the proportion of surviving nodes in the network and reflects the impact of the defense measures on the overall health status of the network; the node survival rate vector describes the distribution of the survival rates of each node in the network and is used for subsequent correlation analysis.

[0115] In the embodiment of the present application, first, the survival status data of each node in the network is collected. The survival status of each node during the defense process, including the survival time, failure time, etc., is recorded in real time through the monitoring system. Then, by statistically analyzing the ratio of the survival time of each node to the total running time, the survival rate of each node is obtained. Next, the survival rates of all nodes are aggregated to generate a node survival rate vector. This process uses statistical methods to quantitatively process the node survival status and provides basic data for subsequent asymmetric correlation analysis. Through the node survival rate vector, the impact of the defense measures on different nodes in the network can be intuitively reflected.

[0116] Step 803: Input the distribution density vector and the node survival rate vector into a predefined asymmetric correlation analysis model to calculate the correlation degree between the distribution density and the node survival rate and the deviation threshold; In this step, the deviation threshold is used to evaluate the deviation degree of the correlation between two vectors and reflects the actual effect of the defense behavior.

[0117] In the embodiment of the present application, the distribution density vector generated in step 801 and the node survival rate vector generated in step 802 are input into the asymmetric correlation analysis model. The model first calculates the covariance matrix of the two vectors, and then calculates the correlation degree through the correlation coefficient formula. At the same time, the model evaluates the deviation degree between the two vectors through the set deviation threshold. The deviation threshold is set based on historical data and experience and is used to judge whether the actual correlation meets the expectation. Finally, the model outputs the correlation degree and the deviation threshold, providing a quantitative basis for the verification of the defense effectiveness.

[0118] Step 804: Generate a defense effectiveness verification result vector according to the comparison result between the correlation degree and the deviation threshold; In this step, the defense effectiveness verification result vector describes the actual effect of the defense measures on different regions or nodes and is used to evaluate the effectiveness of the defense strategy.

[0119] In the embodiment of the present application, the system first compares the correlation degree with the preset deviation threshold to judge whether the actual correlation meets the expectation. If the correlation degree is lower than the deviation threshold, it indicates that the defense measures have poor effects in this region or node; if the correlation degree is higher than the deviation threshold, it indicates that the defense measures have good effects. The system quantifies these comparison results into vector form, and each element corresponds to the defense effectiveness evaluation result of a region or node. Finally, the generated defense effectiveness verification result vector intuitively reflects the actual effects of the defense strategy on different regions or nodes, providing a scientific basis for subsequent optimization.

[0120] The following is a specific example: In an enterprise network, a new defense strategy is deployed to resist DDoS attacks. First, in step 801, by analyzing the changes in the network topology during the defense process, the distribution density of the curvature extreme points of the defense response trajectory is calculated to generate a distribution density vector. Specifically, the system calculates the curvature change of the trajectory through differential geometry methods, identifies the curvature extreme points, and counts the distribution density of these points in different regions. Then, in step 802, the survival state data of each node in the network is collected, the survival time and proportion of the nodes are counted, and a node survival rate vector is generated. Next, in step 803, the distribution density vector and the node survival rate vector are input into an asymmetric correlation analysis model to calculate the correlation degree and deviation threshold between the two. Finally, in step 804, according to the comparison result of the correlation degree and the deviation threshold, a defense effectiveness verification result vector is generated. Through this process, the actual effect of the defense strategy in different regions or nodes can be intuitively evaluated, providing a scientific basis for optimizing the defense strategy.

[0121] Through the above steps 801 to 804, this solution has successfully achieved the accurate evaluation of network defense effectiveness. By calculating the distribution density of the curvature extreme points of the defense response trajectory and the survival rate of network nodes, and using the asymmetric correlation analysis model to quantify the relationship between the two, a defense effectiveness verification result vector is finally generated. This solution can not only dynamically reflect the impact of defense measures on the network topology structure and node status, but also provide a scientific basis for optimizing the defense strategy, significantly improving the evaluation accuracy and practicality of network defense.

[0122] Considering the problems of lack of dynamic coordination between attacks and defense responses and difficulty in accurately mapping attack characteristics in traditional network defense, a cooperative interference method based on a dynamic phase matching algorithm is proposed. The present invention proposes to introduce a spatio-temporal coupling field matrix and a phase compensation mechanism to achieve dynamic matching between attack behaviors and network dynamics perturbations, thereby generating a response trajectory with defense strategy mapping characteristics. This method aims to break through the limitations of existing defense technologies, enhance the self-adaptability and accuracy of defense by dynamically adjusting the phase compensation amount and energy density threshold, and ultimately improve the overall effectiveness of network defense.

[0123] Based on this, the present invention provides a specific embodiment. In step 104, cooperative interference between attack behaviors and network dynamics perturbations is achieved through a dynamic phase matching algorithm to generate a network defense response trajectory with defense strategy mapping characteristics, which specifically includes the following steps: Step 901, based on the column vector weights of the protocol stack layer correlation degree, calculate the phase compensation amount of each node in the spatio-temporal coupling field matrix, and the phase compensation amount is non-linearly correlated with the row vector weights of the network node interaction strength matrix and the reciprocal of the protocol response delay; In this step, the column vector weights of the protocol stack level correlation represent the correlation strength between different protocol levels, reflecting the importance of each level in the protocol stack in network behavior; the non-linear correlation represents the complex relationship between the phase compensation amount, the row vector weights of the network node interaction strength matrix, and the reciprocal of the protocol response delay.

[0124] In the embodiment of the present application, first, according to the column vector weights of the protocol stack level correlation, the phase compensation amount of each node in the spatio-temporal coupling field matrix is calculated. Specifically, by analyzing the row vector weights of the network node interaction strength matrix and the reciprocal of the protocol response delay, the phase compensation amount of each node is calculated using a non-linear function. This process ensures that the phase of the network node can match the dynamic characteristics of the attack behavior by dynamically adjusting the phase compensation amount, providing a basis for subsequent cooperative interference.

[0125] Step 902: Multidimensionally superimpose the spatio-temporal coupling field matrix corresponding to the phase compensation amount and the attack instruction execution path parameters, and perform dynamic threshold truncation on the superimposed result according to the node survival rate distribution to generate a cooperative interference matrix; In this step, the attack instruction execution path parameters describe the propagation path and execution order of the attack instruction in the network; Multidimensional superimposition means fusing the spatio-temporal coupling field matrix corresponding to the phase compensation amount and the attack instruction execution path parameters to generate a comprehensive interference matrix.

[0126] In the embodiment of the present application, first, the phase compensation amount calculated in step 901 is combined with the spatio-temporal coupling field matrix to form an enhanced spatio-temporal coupling field matrix containing phase information. This matrix not only reflects the interaction relationship of each node in the network in time and space, but also introduces phase adjustment information matching the dynamic characteristics of the attack behavior through the phase compensation amount. Subsequently, the attack instruction execution path parameters are multidimensionally superimposed on the enhanced spatio-temporal coupling field matrix. The attack instruction execution path parameters describe the propagation path and execution order of the attack instruction in the network. Through multidimensional superimposition, the propagation characteristics of the attack behavior are combined with the dynamic interaction characteristics of the network nodes to generate a comprehensive interference matrix.

[0127] Step 903: Extract the node coordinates in the cooperative interference matrix whose energy density exceeds the dynamic threshold, and perform time-frequency inverse mapping on the coordinates and the frequency perturbation parameters of the photoacoustic coupling waveform to generate spatio-temporal trajectory parameters containing protocol vulnerability feature vectors; In this step, the energy density dynamic threshold is used to screen the nodes with high energy density in the cooperative interference matrix, reflecting the key attack characteristics; time-frequency inverse mapping maps the node coordinates and the frequency perturbation parameters of the photoacoustic coupling waveform to generate spatio-temporal trajectory parameters; the protocol vulnerability feature vector is used to describe the characteristics of the protocol vulnerability, providing a basis for subsequent defense strategies.

[0128] In the embodiments of the present application, first, the node coordinates with energy density exceeding the dynamic threshold are extracted from the cooperative interference matrix. Then, through time-frequency analysis technology, the node coordinates are inversely mapped with the waveform parameters to generate spatio-temporal trajectory parameters that can reflect the protocol vulnerability characteristics. This process combines the dynamic behavior of key nodes with protocol vulnerability characteristics through time-frequency inverse mapping, providing important input for the generation of subsequent defense strategies.

[0129] Step 904: Perform gradient normalization processing on the spatio-temporal trajectory parameters under network topology constraints, so that the distribution of extreme points of trajectory curvature and the asymmetry correlation of node survival rates converge to a preset interval, and output a network defense response trajectory; In this step, network topology constraint means constraining the spatio-temporal trajectory parameters based on the network topology structure to ensure that the generated defense response trajectory conforms to the actual structure of the network; gradient normalization processing means normalizing the spatio-temporal trajectory parameters so that the distribution of extreme points of trajectory curvature and the asymmetry correlation of node survival rates converge to a preset interval; the defense response trajectory is the finally generated trajectory used to describe the dynamic response of the defense strategy in the network.

[0130] In the embodiments of the present application, first, the spatio-temporal trajectory parameters are constrained according to the network topology structure to ensure that the generated trajectory conforms to the actual structure of the network. Then, through the gradient normalization algorithm, the trajectory parameters are normalized so that the distribution of extreme points of trajectory curvature and the asymmetry correlation of node survival rates converge to a preset interval. Finally, a network defense response trajectory with defense strategy mapping characteristics is output. This process ensures the accuracy and effectiveness of the defense response trajectory through gradient normalization processing.

[0131] The following is a specific example: Suppose in an enterprise network, it is necessary to cope with complex DDoS attacks. First, in step 901, according to the column vector weights of the protocol stack layer correlation degree, calculate the phase compensation amount of each node in the spatio-temporal coupling field matrix to ensure that the phase of the node can match the dynamic characteristics of the attack behavior. Then, in step 902, the spatio-temporal coupling field matrix corresponding to the phase compensation amount is multi-dimensionally superimposed with the attack instruction execution path parameters, and dynamic threshold truncation is performed according to the node survival rate distribution to generate a cooperative interference matrix. Then, in step 903, extract the node coordinates with energy density exceeding the dynamic threshold, and perform time-frequency inverse mapping with the frequency perturbation parameters of the photoacoustic coupling waveform to generate spatio-temporal trajectory parameters containing protocol vulnerability feature vectors. Finally, in step 904, perform gradient normalization processing on the spatio-temporal trajectory parameters under network topology constraints, and output a network defense response trajectory with defense strategy mapping characteristics. Through this process, the system can accurately reflect the cooperative relationship between the attack behavior and the network dynamics perturbation, providing a scientific basis for optimizing the defense strategy.

[0132] Through the above steps 901-904, this solution has successfully achieved the dynamic collaborative interference between attack behaviors and network dynamics perturbations, generating a network defense response trajectory with the characteristics of defense strategy mapping. Through dynamic phase matching and multi-dimensional superposition, the system can accurately reflect the dynamic characteristics of attack behaviors; through time-frequency inverse mapping and gradient normalization processing, the generated defense response trajectory can effectively map the protocol vulnerability characteristics, providing important support for the optimization of defense strategies. This solution significantly improves the dynamic adaptability and accuracy of network defense, providing a new technical means for security protection in complex network environments.

[0133] Figure 2 The following is a schematic structural diagram of a big data processing system for implementing hybrid data analysis provided by an embodiment of the present invention, as Figure 2 shown. The system includes: A generating module 21, configured to input target network topology parameters into a non-linear oscillation equation, and superimpose a random phase modulation function to generate an optoacoustic coupling waveform, where the optoacoustic coupling waveform includes frequency perturbation parameters; A triggering module 22, configured to inject the optoacoustic coupling waveform into a network behavior oscillation field constructed by a network node interaction intensity matrix and a protocol stack layer correlation degree, and trigger an abnormal fluctuation mode equivalent to a real attack behavior in network traffic generation; An analysis module 23, configured to, during the duration of the abnormal fluctuation mode, analyze the topological correlation of the network protocol interaction entropy value through reverse gradient calculation, and generate an attack instruction sequence carrying protocol vulnerability feature vectors; An interference module 24, configured to perform spatio-temporal coupling on the execution path of the attack instruction sequence and the frequency perturbation parameters of the optoacoustic coupling waveform, and implement the collaborative interference between attack behaviors and network dynamics perturbations through a dynamic phase matching algorithm, generating a network defense response trajectory with the characteristics of defense strategy mapping; A verification module 25, configured to output a defense effectiveness verification result through an asymmetric correlation analysis of the distribution density of the extreme points of the trajectory curvature and the survival rate of network nodes according to the topological deformation characteristics of the network defense response trajectory.

[0134] Figure 2 The described network defense ability verification system based on intrusion attack simulation can execute Figure 1 the network defense ability verification method described in the embodiment shown. The implementation principle and technical effects will not be elaborated again. For the network defense ability verification system based on intrusion attack simulation in the above embodiment, the specific ways for each module and unit to perform operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network defense capability verification method based on intrusion attack simulation, characterized in that: include: The target network topology parameters are input into the nonlinear oscillation equation, and the random phase modulation function is superimposed to generate the photoacoustic coupling waveform; Injecting the photoacoustic coupling waveform into a network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack level correlation, triggering network traffic to generate an abnormal fluctuation pattern equivalent to the real attack behavior; During the period when the abnormal fluctuation mode persists, the topological correlation of the network protocol interaction entropy value is analyzed by reverse gradient calculation to generate an attack instruction sequence carrying a protocol vulnerability feature vector; The execution path of the attack instruction sequence is spatiotemporally coupled with the frequency perturbation parameter of the photoacoustic coupling waveform, and the coordinated interference of the attack behavior and the network dynamics perturbation is achieved through a dynamic phase matching algorithm to generate a network defense response trajectory with defense strategy mapping characteristics; According to the topological deformation characteristics of the network defense response trajectory, the defense effectiveness verification result is output through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate.

2. The method according to claim 1, characterized in that The topological correlation of the network protocol interaction entropy value is analyzed through reverse gradient calculation to generate an attack instruction sequence carrying the protocol vulnerability feature vector, including: Based on the dynamic manifold modeling of cross-level interaction events in the protocol stack, the topological correlation of the network protocol interaction entropy value is analyzed by reverse gradient, and the curvature change rate of the protocol state transition path is extracted as the gradient calculation benchmark; Performing spectrum coupling operation on the gradient calculation reference and the partial derivative of the network protocol interaction entropy value to generate a spectrum weight parameter of the protocol vulnerability feature vector; Based on the spectrum weight parameter and the dynamic direction parameter of the network protocol interaction entropy value, a penetration direction parameter and a penetration rate parameter of the protocol vulnerability feature vector are generated by tensor product calculation; Dynamically correct the penetration direction parameter by using the real-time topological neighborhood parameter of the network node interaction intensity matrix, and adjust the vector angle of the penetration direction parameter to obtain a corrected penetration direction parameter; The modified penetration direction parameter is subjected to a time domain convolution operation with the penetration rate parameter to generate an attack instruction sequence.

3. The method according to claim 2, characterized in that The gradient calculation reference quantity and the partial derivative of the network protocol interaction entropy value are subjected to spectrum coupling operation to generate spectrum weight parameters of the protocol vulnerability feature vector, including: Performing frequency band division on the gradient calculation reference quantity, extracting the fluctuation amplitude of the curvature change rate in each frequency band as a frequency band division parameter, wherein the frequency band division parameter is determined by a dynamic response cycle of a protocol interaction event; Performing frequency domain alignment processing on the frequency band division parameter and the partial derivative of the network protocol interaction entropy value, wherein the frequency domain alignment processing process includes performing fluctuation phase decomposition on the directional parameter of the partial derivative to generate a normalized frequency domain response parameter; The normalized frequency domain response parameter is subjected to a dot product operation with the frequency band division parameter to generate a spectrum weight parameter of the protocol vulnerability feature vector. The dot product operation process needs to maintain the phase consistency of the curvature change rate and the partial derivative in each frequency band.

4. The method according to claim 3, characterized in that Performing frequency domain alignment processing on the frequency band division parameter and the partial derivative of the network protocol interaction entropy value to generate a normalized frequency domain response parameter includes: Based on the dynamic response cycle of the protocol interaction event, the frequency band boundary of the frequency band division parameter is dynamically adjusted, and the adjusted frequency band division parameter is output, wherein the frequency range of each frequency band in the adjusted frequency band division parameter is negatively correlated with the time window of the protocol state transition; Decomposing the partial derivative direction parameter of the network protocol interaction entropy value into multiple orthogonal phase components, performing frequency band matching truncation on each orthogonal phase component based on the adjusted frequency band division parameter, retaining only the frequency components in the same frequency band as those in the adjusted frequency band division parameter, and outputting the truncated orthogonal phase components; In the same frequency band, the phase offset compensation is performed on the truncated orthogonal phase component and the adjusted frequency band division parameter so that the phase difference between the two converges to a preset threshold, and the amplitude of the compensated component is frequency band normalized to generate a normalized frequency domain response parameter.

5. The method according to claim 1, characterized in that The photoacoustic coupling waveform is injected into the network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack layer correlation, triggering the network traffic to generate an abnormal fluctuation pattern equivalent to the real attack behavior, including: Generate the network node interaction intensity matrix based on the interaction traffic of network nodes and the success rate of protocol handshake. Combined with the column vector weight of the protocol stack level association, the network behavior oscillation field is constructed through tensor coupling and nonlinear perturbation terms. According to the protocol response delay threshold in the protocol stack level association degree, phase modulate the frequency perturbation parameter of the photoacoustic coupling waveform to generate a modulated photoacoustic waveform, and align the phase parameter of the photoacoustic coupling waveform with the row vector weight of the network node interaction intensity matrix; The modulated photoacoustic waveform is injected into the network behavior oscillation field, and the nonlinear resonance of node traffic fluctuation and protocol interaction is triggered by dynamically matching the column vector weight of the waveform energy density with the protocol stack level correlation, thus generating an abnormal fluctuation pattern.

6. The method according to claim 5, characterized in that The modulated photoacoustic waveform is injected into the network behavior oscillation field. By dynamically matching the column vector weights of the waveform energy density and the correlation between the protocol stack level, the nonlinear resonance of the node traffic fluctuation and the protocol interaction is triggered, generating abnormal fluctuation patterns, including: Based on the column vector weights of the protocol stack layer association degree, the energy density distribution required by each protocol layer is calculated in real time to generate a dynamic energy coupling coefficient that matches the row vector weights of the network node interaction intensity matrix; The dynamic energy coupling coefficient is interacted with the frequency domain parameters of the modulated photoacoustic waveform across layers, and the waveform phase offset is iteratively adjusted so that the energy density distribution at the protocol stack level and the spectrum peak of the node traffic fluctuation are phase-locked in the same frequency band; When the number of locked protocol layers in the protocol stack hierarchy of the phase lock accumulates to a dynamic convergence threshold, a tensor convolution operation is performed on the locked photoacoustic waveform parameters and the network node interaction intensity matrix to generate a nonlinear resonance signal across the protocol layer-physical waveform domain and output an abnormal fluctuation pattern.

7. The method according to claim 1, characterized in that Input the target network topology parameters into the nonlinear oscillation equation and superimpose the random phase modulation function to generate the photoacoustic coupling waveform, including: Based on the target network topology parameters, the connectivity, path length and topology dynamic change rate parameters of the network nodes are extracted, a random phase modulation function is generated through Fourier series expansion and probability distribution model, and the random phase modulation function is introduced into the nonlinear oscillation equation as an additional term; Input the target network topology parameters and the random phase modulation function into a nonlinear oscillation equation, and calculate the photoacoustic coupling waveform by a numerical solution method; Optimize the calculated photoacoustic coupling waveform, eliminate noise and outliers, and verify the accuracy and validity of the waveform; The optimized photoacoustic coupling waveform is output as multi-dimensional time series data and stored in a structured file format.

8. The method according to claim 1, characterized in that: According to the topological deformation characteristics of the network defense response trajectory, the defense effectiveness verification results are output through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate, including: Based on the topological deformation characteristics of the network defense response trajectory, the distribution density of the trajectory curvature extreme points is calculated to generate a distribution density vector; Collect network node survival status data, quantify network node survival rate, and generate node survival rate vector by counting the survival time and survival ratio of network nodes; Input the distribution density vector and the node survival rate vector into a predefined asymmetric correlation analysis model to calculate the correlation degree and deviation threshold between the distribution density and the node survival rate; According to the comparison result of the correlation degree and the deviation threshold, a defense effectiveness verification result vector is generated.

9. The method according to claim 1, characterized in that: The coordinated interference between attack behavior and network dynamics disturbance is achieved through the dynamic phase matching algorithm, generating a network defense response trajectory with defense strategy mapping characteristics, including: Based on the column vector weight of the protocol stack level association degree, the phase compensation amount of each node in the spatiotemporal coupling field matrix is ​​calculated, and the phase compensation amount is nonlinearly associated with the row vector weight of the network node interaction intensity matrix and the inverse of the protocol response delay; The space-time coupling field matrix corresponding to the phase compensation amount is multi-dimensionally superimposed with the attack instruction execution path parameters, and the superposition result is dynamically threshold-cut according to the node survival rate distribution to generate a collaborative interference matrix; Extracting the node coordinates whose energy density exceeds the dynamic threshold in the collaborative interference matrix, performing time-frequency inverse mapping on the coordinates and the frequency perturbation parameters of the photoacoustic coupling waveform, and generating space-time trajectory parameters containing the protocol vulnerability feature vector; The spatiotemporal trajectory parameters are subjected to gradient normalization processing under network topology constraints, so that the asymmetric correlation between the distribution of trajectory curvature extreme points and the node survival rate converges to a preset interval, and the network defense response trajectory is output.

10. A network defense capability verification system based on intrusion attack simulation, characterized in that: include: A generation module, used for inputting the target network topology parameters into the nonlinear oscillation equation, superimposing the random phase modulation function to generate a photoacoustic coupling waveform, wherein the photoacoustic coupling waveform includes a frequency perturbation parameter; A trigger module, used to inject the photoacoustic coupling waveform into a network behavior oscillation field constructed by the network node interaction intensity matrix and the protocol stack layer correlation, to trigger the network traffic to generate an abnormal fluctuation pattern equivalent to the real attack behavior; A parsing module, used to parse the topological correlation of the network protocol interaction entropy value by reverse gradient calculation during the duration of the abnormal fluctuation mode, and generate an attack instruction sequence carrying the protocol vulnerability feature vector; An interference module is used to couple the execution path of the attack instruction sequence with the frequency disturbance parameter of the photoacoustic coupling waveform in time and space, realize the coordinated interference of the attack behavior and the network dynamics disturbance through a dynamic phase matching algorithm, and generate a network defense response trajectory with defense strategy mapping characteristics; The verification module is used to output the defense effectiveness verification result according to the topological deformation characteristics of the network defense response trajectory through the asymmetric correlation analysis of the distribution density of the trajectory curvature extreme points and the network node survival rate.

Citation Information

Cited By

  • Smart park monitoring method and system based on end-to-end cooperation

    CN120378459A

  • Network security defense method and device for automatic fire alarm system

    CN120675820A

  • Network encryption attack detection method based on deep learning

    CN121309209A

  • A deep learning-based network encryption attack detection method

    CN121309209B

  • Network security monitoring method and system based on distributed nodes

    CN121585476A