Satellite dynamic simulation verification method based on generative adversarial network threat modeling

Through threat modeling methods based on generative adversarial networks, unknown threat scenarios are simulated and defense strategies are optimized, and the problem that traditional methods are difficult to identify and defend against unpreprogrammed threats is solved, and more efficient threat identification and defense is achieved, improving the security and efficiency of satellite communication systems.

CN120104249AActive Publication Date: 2025-06-06XINGCHEN XUANJI (BEIJING) MEASUREMENT & CONTROL TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510103125.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-06-06
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

Traditional satellite dynamic simulation methods are difficult to effectively identify and defend against unprogrammed threat types, resulting in insufficient response speed and efficiency in the face of evolving attack modes, which will not be able to effectively reduce damage, which will affect overall performance and security.

Method used

The threat modeling method based on generative adversarial network is adopted, and through iterative optimization of generator and discriminator, unknown threat scenarios are simulated, abnormal traffic header information is identified, dynamic simulation environment is constructed, and defense strategies are evaluated and optimized.

Benefits of technology

It significantly improves the system's identification accuracy of authenticity and false data, enhances the diversity and complexity of generated samples, can better adapt to and resist the ever-changing external threat environment, dynamically adjusts defense strategies, and improves overall security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104249A_ABST
    Figure CN120104249A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of simulation verification, in particular to a satellite dynamic simulation verification method based on generative adversarial network threat modeling. The method comprises the following steps of: setting initial network parameters based on a generative adversarial network environment, initializing weights of a generator and a discriminator, and performing basic configuration test on a model to obtain an initialized model state; according to the method, by simulating complex environments and scenes and testing behaviors and responses of the satellite communication system, the recognition precision of the system on true and false data can be improved by continuously iteratively optimizing the generator and the discriminator, and by enhancing the diversity and complexity of generated samples, the complexity and challenge of data generation are optimized; the method can better adapt to and resist the constantly changing external threat environment, ensures that the defense strategy of the satellite communication system can be dynamically adjusted according to actual threats by dynamically adjusting the parameters of the defense strategy and optimizing the response mechanism in the simulation environment, and improves the overall safety and efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of simulation verification technology, and in particular to a satellite dynamic simulation verification method based on generative adversarial network threat modeling. Background Art

[0002] The field of simulation verification technology involves the use of simulated environments to evaluate and verify the performance and behavior of various systems, components or models. This field mainly uses computer-generated environments to predict and reproduce situations that may occur in the real world, so that data and behavior can be analyzed without physical testing in the actual environment. Simulation technology is widely used in aerospace, automotive industry, construction engineering, network security and other fields. Especially in safety-critical systems such as satellite communications and control systems, simulation verification has become an indispensable part. This technology enables developers to test the system's response in different simulation scenarios, optimize operating strategies, and predict the system's performance when facing actual workloads or attacks.

[0003] Among them, the satellite dynamic simulation verification method is a simulation technology application specially designed for satellite systems. It aims to test and verify the behavior and response of satellite communication systems by simulating complex environments and scenarios. This method is mainly used to evaluate the robustness and reliability of satellite communication systems when encountering various expected internal and external threats or operational changes. Through dynamic simulation, the defense mechanism of the satellite communication system can be stress-tested in a safe virtual environment, its response capability to unknown threats can be evaluated, and the satellite's defense strategy can be adjusted and optimized. This method is crucial to improving the safety and efficiency of satellite operations, especially in the current situation of rapid technological development and increasing external threats, providing important guarantees for the continued operation and long-term success of satellite systems.

[0004] Traditional simulation methods rely on preset scenarios and parameters, and are unable to cope with unknown or dynamically changing threats. For example, in the fields of aerospace or satellite communications, traditional methods have difficulty in fully predicting and responding to emerging attack technologies or complex interference environments, and simulations are usually based on known data and preset scenarios. As a result, when faced with evolving attack patterns, it is impossible to effectively identify and defend against types of threats that are not pre-programmed, increasing the risk of the system being attacked. There are also deficiencies in real-time data processing and real-time defense strategy adjustments, resulting in insufficient response speed and efficiency when encountering actual attacks, which cannot effectively reduce damage and affects overall performance and security. Summary of the invention

[0005] The purpose of the present invention is to solve the shortcomings existing in the prior art and propose a satellite dynamic simulation verification method based on generative adversarial network threat modeling.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] The satellite dynamic simulation verification method based on generative adversarial network threat modeling includes the following steps:

[0008] S1: Based on the generative adversarial network environment, set the initial network parameters, initialize the weights of the generator and discriminator, and perform basic configuration tests on the model to obtain the initialized model state;

[0009] S2: Based on the initialization model state, extract the threat records of satellite communications, train the generator to simulate the unknown threat model, optimize the discrimination ability of the discriminator through round-by-round iteration, and obtain the trained model;

[0010] S3: Based on the trained model, a threat scenario generation operation is performed, the output of the generator is adjusted, the characteristics of the differentiated threats are matched, and the generated threat scenario data is obtained;

[0011] S4: Based on the generated threat scenario data, analyze the satellite communication network traffic, identify abnormal traffic packet header information, and obtain attack feature extraction results;

[0012] S5: Based on the attack feature extraction result, a dynamic simulation environment is constructed, and multiple defense strategies are input. By simulating attack and defense scenarios, the ability of differentiated defense strategies to combat threats is evaluated, and the parameters of the defense strategies are dynamically adjusted to obtain defense strategy optimization information.

[0013] S6: Based on the defense strategy optimization information, the optimized defense strategy is applied to the actual satellite communication network, the efficiency of system response and threat interception is analyzed, the simulation test results are evaluated, and the actual combat simulation effect evaluation results are obtained.

[0014] Optionally, the initialized model state includes an initial learning rate, an initial batch size and a weight initialization state, the trained model includes optimized generator weights, discriminator weights and data recognition accuracy, the generated threat scenario data includes enhanced sample diversity, sample complexity and simulated threat types, the attack feature extraction results include calibrated abnormal communication patterns, identified specific traffic packet header information and key parameters for clustering analysis, the defense strategy optimization information includes adjusted defense parameters, optimized response strategies and tested scenario data, and the actual combat simulation effect evaluation results include recorded system response data, threat interception efficiency and simulation test data.

[0015] Optionally, based on the generative adversarial network environment, the initial network parameters are set, the weights of the generator and the discriminator are initialized, and the basic configuration test of the model is performed. The specific steps to obtain the initialized model state are:

[0016] S101: Based on the generative adversarial network environment, configure the computing platform required by the generative adversarial network, select a matching GPU configuration and neural network library, perform hardware configuration and software environment settings for the network, and obtain the environment configuration status;

[0017] S102: Based on the environment configuration state, use random numbers to initialize the network weights of the generator and the discriminator, set the learning rate and the batch size, perform network parameter setting, and obtain initial weight setting information;

[0018] S103: Based on the initial weight setting information, forward propagation and back propagation tests are performed to check the integrity of the network structure and the validity of the parameter settings, verify that the model components function normally, and obtain the initialized model state.

[0019] Optionally, based on the initialization model state, extracting the threat records of satellite communications, training the generator to simulate the unknown threat model, optimizing the discrimination ability of the discriminator by rounds of iterations, and obtaining the trained model are specifically as follows:

[0020] S201: extracting and screening threat records from satellite communication records based on the initialization model state, preprocessing the data, including normalization and encoding, constructing a data set suitable for training, and obtaining a historical threat data set;

[0021] S202: Based on the historical threat data set, simulating threat scenarios through a generator, iteratively training the generator, and optimizing the ability of the generator to simulate unknown threats by adjusting internal parameters of the generator to obtain a preliminary training model;

[0022] S203: Based on the preliminary training model, perform deep training on the discriminator to improve the ability of the discriminator to distinguish between generated data and real data, refine the parameter adjustment after each round of training, optimize the accuracy of the model in identifying true and false data, and obtain a trained model.

[0023] Optionally, based on the trained model, a threat scenario generation operation is performed, the output of the generator is adjusted, and the characteristics of the differentiated threat are matched to obtain the generated threat scenario data in the following steps:

[0024] S301: Based on the trained model, the output parameters of the generator are adjusted, including the modification of the output frequency and the data structure, so as to optimize the matching of the generated data with various threat scenarios and obtain the adjusted output parameters;

[0025] S302: Based on the adjusted output parameters, by importing multiple data sample types, adjusting the degree of variation of the data samples, enhancing the complexity and diversity of the generated samples, optimizing the generalization ability of the model, and obtaining an enhanced sample data set;

[0026] S303: Based on the enhanced sample data set, complexity analysis and challenge enhancement are performed on the generated data to verify the effect of the generated data in simulating multiple threat environments, thereby obtaining generated threat scenario data.

[0027] Optionally, based on the generated threat scenario data, the satellite communication network traffic is analyzed to identify abnormal traffic packet header information to obtain the attack feature extraction result. Specifically, the step is as follows:

[0028] S401: Based on the generated threat scenario data, data is screened and preprocessed, including cleaning irrelevant data and formatting traffic packet data, to obtain screened traffic data;

[0029] S402: Based on the filtered traffic data, analyzing traffic packets in the satellite communication network, identifying communication modes that are inconsistent with normal modes, calibrating abnormal communication modes, and obtaining abnormal mode calibration results;

[0030] S403: Based on the abnormal pattern calibration result, by comparing the standard traffic pattern with the abnormal pattern, identifying key traffic packet header information, extracting attack features, and obtaining attack feature extraction results.

[0031] Optionally, based on the attack feature extraction result, a dynamic simulation environment is constructed, multiple defense strategies are input, and the ability of differentiated defense strategies to combat threats is evaluated by simulating attack and defense scenarios, and the parameters of the defense strategies are dynamically adjusted to obtain the defense strategy optimization information. Specifically, the steps are as follows:

[0032] S501: Based on the attack feature extraction result, hardware and software resources are configured to establish a dynamic simulation environment capable of simulating multiple threats, and initial conditions and simulation parameters of multiple defense strategies are set to obtain a dynamic simulation test environment;

[0033] S502: Based on the dynamic simulation test environment, by real-time monitoring of the simulated attack and defense interactions, the operating parameters of the defense strategy are gradually adjusted to optimize the ability to resist multiple attack modes, and a real-time strategy adjustment record is obtained;

[0034] S503: Based on the real-time strategy adjustment record, the effect of the defense strategy is evaluated through comparative analysis of simulation results, and the response mechanism and defense parameters of the simulation environment are dynamically optimized to obtain defense strategy optimization information.

[0035] Optionally, the formula for adjusting the operating parameters of the defense strategy is:

[0036]

[0037] Among them, P(n+1) represents the defense strategy parameters of the next stage, P(n) represents the defense strategy parameters of the current stage, ΔL represents the loss change from the previous stage to the current stage, L(n) represents the loss value of the current stage, and L target represents the target loss value, and K represents the adjustment coefficient.

[0038] Optionally, based on the defense strategy optimization information, the optimized defense strategy is applied to the actual satellite communication network, the efficiency of system response and threat interception is analyzed, and the simulation test results are evaluated to obtain the actual combat simulation effect evaluation results. Specifically, the steps are:

[0039] S601: Based on the defense strategy optimization information, deploy the optimized defense strategy in the actual satellite communication network, set the network environment, match the new defense parameters, and obtain the actual strategy deployment environment;

[0040] S602: Based on the actual combat strategy deployment environment, start the actual attack and defense scenario simulation test, record the response and defense effect of the satellite network system under various attacks, fine-tune and optimize the strategy, and obtain the actual combat adjustment and test results;

[0041] S603: Based on the actual combat adjustment and test results, the effectiveness of the strategy in actual operation is evaluated through system response and threat interception analysis to obtain actual combat simulation effect evaluation results.

[0042] Optionally, the formula for evaluating the effectiveness of the strategy in actual operation is:

[0043]

[0044] Among them, E is the effectiveness index of the strategy, T tp Represents the number of times the attack is successfully intercepted, T tn represents the number of times non-attack situations are correctly ignored, T fp represents the number of times non-attack situations are falsely reported as attacks, T fn represents the number of times the attack was not detected, W tp and W tn is the weight coefficient.

[0045] Compared with the prior art, the advantages and positive effects of the present invention are:

[0046] In the present invention, by simulating complex environments and scenarios and testing the behavior and response of the satellite communication system, the potential threats faced by the satellite system can be accurately simulated. The system can significantly improve the accuracy of identifying true and false data by continuously iterating and optimizing the generator and the discriminator. By enhancing the diversity and complexity of the generated samples, the complexity and challenge of data generation are optimized, and the system can better adapt to and resist the ever-changing external threat environment. By dynamically adjusting the parameters of the defense strategy and optimizing the response mechanism in the simulation environment, it is ensured that the defense strategy of the satellite communication system can be dynamically adjusted according to the actual threat, thereby improving the overall security and efficiency, helping to discover potential vulnerabilities in advance, and being able to test and improve various defense measures without affecting the actual operation, thereby reducing the risks in practical applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0048] Figure 1 It is a schematic diagram of the main steps of the present invention;

[0049] Figure 2 It is a schematic diagram of the refinement of S1 of the present invention;

[0050] Figure 3 It is a schematic diagram of the refinement of S2 of the present invention;

[0051] Figure 4 It is a schematic diagram of the refinement of S3 of the present invention;

[0052] Figure 5 It is a schematic diagram of the refinement of S4 of the present invention;

[0053] Figure 6 It is a detailed schematic diagram of S5 of the present invention;

[0054] Figure 7 It is a detailed schematic diagram of S6 of the present invention. DETAILED DESCRIPTION

[0055] The technical solution of the present invention is described below in conjunction with the accompanying drawings.

[0056] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "example" in the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present the concept in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or it can be either of the two.

[0057] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same. "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same.

[0058] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0059] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0060] See also Figure 1 As shown, the present invention provides a satellite dynamic simulation verification method based on generative adversarial network threat modeling, comprising the following steps:

[0061] S1: Based on the generative adversarial network environment, set the initial network parameters, including adjusting the learning rate and batch size, initialize the weights of the generator and discriminator, and perform basic configuration tests on the model to verify that the model components are operating normally and obtain the initialized model state;

[0062] S2: Based on the initialization model state, according to the satellite communication records, extract the threat records of satellite communication, input the historical threat data, train the generator to simulate the unknown threat model, optimize the discrimination ability of the discriminator through round-by-round iteration, adjust the discriminator parameters after each round of output, optimize the accuracy of identifying true and false data, and obtain the trained model;

[0063] S3: Based on the trained model, perform threat scenario generation operations, adjust the output of the generator, match the characteristics of differentiated threats, and optimize the complexity and challenge of generated data by enhancing the diversity and complexity of generated samples to obtain generated threat scenario data;

[0064] S4: Based on the generated threat scenario data, analyze the satellite communication network traffic, perform cluster analysis on the satellite communication network traffic, calibrate the abnormal communication mode, identify the abnormal traffic packet header information, and obtain the attack feature extraction result;

[0065] S5: Based on the attack feature extraction results, a dynamic simulation environment is constructed, and multiple defense strategies are input. By simulating attack and defense scenarios, the ability of differentiated defense strategies to combat threats is evaluated, and the parameters of the defense strategies are dynamically adjusted to optimize the response mechanism in the simulation environment and obtain defense strategy optimization information.

[0066] S6: Based on the defense strategy optimization information, the optimized defense strategy is applied to the actual satellite communication network, and actual combat simulation tests are conducted to analyze the efficiency of system response and threat interception, evaluate the simulation test results, and obtain the actual combat simulation effect evaluation results.

[0067] The initialization model state includes the initial learning rate, initial batch size and weight initialization state. The trained model includes the optimized generator weights, discriminator weights and data recognition accuracy. The generated threat scenario data includes enhanced sample diversity, sample complexity and simulated threat types. The attack feature extraction results include calibrated abnormal communication patterns, identified specific traffic packet header information and key parameters for clustering analysis. The defense strategy optimization information includes adjusted defense parameters, optimized response strategies and tested scenario data. The actual combat simulation effect evaluation results include recorded system response data, threat interception efficiency and simulation test data.

[0068] See also Figure 2 As shown, the steps of setting the initial network parameters based on the generative adversarial network environment, including adjusting the learning rate setting and batch size, initializing the weights of the generator and the discriminator, and performing the basic configuration test of the model to verify the normal operation of the model components and obtain the initialization model state are as follows:

[0069] S101: Based on the generative adversarial network environment, configure the computing platform required by the generative adversarial network, select a matching GPU configuration and neural network library, perform hardware configuration and software environment settings for the network, and obtain the environment configuration status;

[0070] Based on the generative adversarial network environment, configure the computing platform required for the generative adversarial network. For the selection of matching GPU configuration and neural network library, it is necessary to optimize the selection based on full consideration of computing power and algorithm requirements. According to the computing requirements of the generative adversarial network, select a GPU with higher computing power to support a large amount of parallel processing and fast data flow. To ensure the compatibility and optimal performance of hardware and software, select a neural network library that supports CUDA and TensorFlow or PyTorch. It provides specially optimized functions and modules, which can effectively improve the efficiency and stability of model training. Systematically configure hardware connections and drivers to ensure that all components are correctly installed and configured at the physical and software levels, including installing the correct operating system version, GPU driver, deep learning framework and related dependent libraries. Perform performance tests to verify the correctness and performance of the configuration. The tests include benchmark tests and small-scale model training experiments to ensure the stability and efficiency of the entire environment configuration and obtain the environment configuration status.

[0071] S102: Based on the environment configuration state, use random numbers to initialize the network weights of the generator and the discriminator, set the learning rate and the batch size, set the network parameters, and obtain the initial weight setting information;

[0072] Based on the environment configuration state, random numbers are used to initialize the network weights of the generator and discriminator. Random initialization is to break the network symmetry and start effective learning. Usually, He or Xavier initialization methods are used to set the initial weights to provide a starting point for network training. Setting the learning rate and batch size directly affects the speed and stability of model training. Usually, a smaller batch size is used with a higher learning rate to promote fast learning while avoiding overfitting, while a larger batch size may require a lower learning rate to ensure the stability of training. In this way, parameters can be adjusted according to specific training requirements and hardware capabilities. The parameter settings will be encoded into the training algorithm to ensure the effectiveness and efficiency of each iteration and obtain the initial weight setting information.

[0073] S103: Based on the initial weight setting information, forward propagation and back propagation tests are performed to check the integrity of the network structure and the validity of the parameter settings, verify that the model components function normally, and obtain the initialized model state.

[0074] Based on the initial weight setting information, forward propagation and back propagation tests are performed. Forward propagation calculates the output of each layer until the last layer through input samples. The process involves matrix operations and the application of nonlinear activation functions. Its purpose is to obtain the network's response to the current input. Backward propagation calculates the gradient of the loss function for each weight and updates the weights in turn. It can check whether the network structure is implemented correctly and whether the connections between layers and parameter updates meet the predetermined design. At the same time, potential numerical instability or implementation errors can also be discovered. Testing helps confirm whether each component of the model works as expected, thereby verifying that the model components function properly and obtaining the initialized model state.

[0075] See also Figure 3 As shown, based on the initialization model state, according to the satellite communication records, the threat records of satellite communication are extracted, the historical threat data is input, the training generator simulates the unknown threat model, and the discriminator's distinguishing ability is optimized by iteration. After each round of output, the discriminator parameters are adjusted to optimize the accuracy of identifying true and false data. The steps of obtaining the trained model are as follows:

[0076] S201: Based on the initialization model state, extract and filter threat records from satellite communication records, preprocess the data, including normalization and encoding, and construct a data set suitable for training to obtain a historical threat data set;

[0077] Based on the initialized model state, relevant communication logs and data records are obtained from the satellite communication system. The data usually contains a large amount of communication signals and metadata. The records are screened to identify records with potential threat characteristics, such as the occurrence of abnormal signal strength or abnormal communication frequency. The screened data are preprocessed, including data normalization and encoding. Normalization is to eliminate the impact of different scales and make model training more efficient. Data encoding is to convert the original data into a format that the model can process, such as converting classified data into one-hot encoding. The preprocessed data is organized into a structured data set, which will be directly used for subsequent model training to obtain a historical threat data set.

[0078] S202: Based on the historical threat data set, the threat scenario is simulated by the generator, the generator is iteratively trained, and the ability of the generator to simulate unknown threats is optimized by adjusting the internal parameters of the generator to obtain a preliminary training model;

[0079] Based on the historical threat data set, the generator uses the features extracted from the historical threat data set as input. The generation of simulated unknown threat scenarios starts with randomly generated seed data. Through a multi-layer network structure, the generator gradually learns how to construct data similar to real threat records. The internal parameters of the generator are continuously adjusted through iterative training, mainly through the gradient descent algorithm to optimize the parameters to reduce the difference between the generated data and the real data. The training method relies on a large number of iterations and repeated adjustments to ensure that the generator can perform well in various threat scenarios. Continuous training and adjustment steps result in the generator simulation being able to effectively simulate more unknown threat scenarios and obtain a preliminary training model.

[0080] S203: Based on the preliminary training model, perform in-depth training on the discriminator to improve the discriminator's ability to distinguish between generated data and real data, refine the parameter adjustment after each round of training, optimize the model's accuracy in identifying true and false data, and obtain a trained model.

[0081] Based on the preliminary training model, the training of the discriminator begins by identifying the difference between the data produced by the generator and the actual historical data. By inputting these two, the discriminator attempts to predict the source of the data through its network structure. As the training progresses, the parameters of the discriminator are continuously adjusted through back propagation to optimize its ability to distinguish between real data and generated data, including adjusting the learning rate, improving the loss function, and experimenting with different network architectures. The parameter adjustment after each round of training is optimized based on the previous training results to improve the overall performance and accuracy of the model. This continuous in-depth training and meticulous parameter optimization enable the discriminator to more accurately identify and distinguish true and false data and obtain a trained model.

[0082] See also Figure 4 As shown, the steps of generating threat scenarios based on the trained model, adjusting the output of the generator, matching the characteristics of differentiated threats, and optimizing the complexity and challenge of generated data by enhancing the diversity and complexity of generated samples to obtain the generated threat scenario data are as follows:

[0083] S301: Based on the trained model, the output parameters of the generator are adjusted, including the modification of the output frequency and the data structure, so as to optimize the matching of the generated data with various threat scenarios and obtain the adjusted output parameters;

[0084] Based on the trained model, evaluate the current output parameters of the generator, such as output frequency and data structure. The adjustment of output frequency is based on the dynamic response requirements between the generated data and the expected threat scenarios. For example, for rapidly changing threat scenarios, increase the output frequency to update the data more frequently. The modification of the data structure involves the layout and presentation of the generated data to ensure that the data structure can effectively express the key characteristics of the threat data, including adjusting the configuration of data fields or introducing new data types to support more complex scenario analysis. The adjustment is verified through simulation tests to ensure that the new parameters can more accurately reflect the requirements of the threat model. Through parameter adjustment, the generated data is optimized to match various threat scenarios to obtain the adjusted output parameters.

[0085] S302: Based on the adjusted output parameters, by importing multiple data sample types, adjusting the degree of variation of the data samples, enhancing the complexity and diversity of the generated samples, optimizing the generalization ability of the model, and obtaining an enhanced sample data set;

[0086] Based on the adjusted output parameters, data samples from different sources and types are selected and integrated to increase the complexity and diversity of the data set. The data samples are classified and labeled to ensure that each sample is representative and diverse. The degree of variation of the data samples is adjusted through variation processing techniques, such as random transformation and noise addition. Different data variations are processed through model learning to improve its adaptability to unknown threats. The adjusted samples are recombined into a new data set. This enhanced sample data set is not only more challenging, but also better able to test and optimize the generalization ability of the model, so as to enhance the complexity and diversity of the generated samples and obtain an enhanced sample data set.

[0087] S303: Based on the enhanced sample data set, complexity analysis and challenge enhancement are performed on the generated data to verify the effect of the generated data in simulating various threat environments, and to obtain generated threat scenario data.

[0088] Based on the enhanced sample data set, the complex structures and patterns in the data set are analyzed through statistical analysis and pattern recognition. The complexity of the data is enhanced by setting new challenging parameters, such as increasing the nonlinear relationship and fuzziness between the data. The parameter adjustment is based on the feedback from the previous model training and the identified improvement points. Through simulation tests, it is verified whether the adjusted data set can effectively simulate multiple threat environments, and ensure that the model can accurately identify and respond to these environments. The effect of the generated data simulating multiple threat environments is verified, and the generated threat scenario data is obtained.

[0089] See also Figure 5As shown, the steps of analyzing the satellite communication network traffic based on the generated threat scenario data, performing cluster analysis on the satellite communication network traffic, calibrating the abnormal communication mode, identifying the abnormal traffic packet header information, and obtaining the attack feature extraction result are specifically as follows:

[0090] S401: Based on the generated threat scenario data, data is screened and preprocessed, including cleaning irrelevant data and formatting traffic packet data, to obtain screened traffic data;

[0091] Based on the generated threat scenario data, evaluate and identify information in the data set that is not related to the threat scenario, delete redundant data that does not belong to the communication mode, such as background noise data of non-satellite communications, format the data, especially the traffic packet data, including standardizing the structure of the traffic packet, such as the unified timestamp format and signal strength unit, to make it suitable for subsequent analysis. The preprocessing operation ensures the consistency and accuracy of the data, improves the efficiency and accuracy of subsequent analysis, facilitates subsequent analysis and processing, and obtains the filtered traffic data.

[0092] S402: Based on the filtered traffic data, traffic packets in the satellite communication network are analyzed to identify communication patterns that are inconsistent with normal patterns, and abnormal communication patterns are calibrated to obtain abnormal pattern calibration results;

[0093] Based on the filtered traffic data, the traffic packets in the satellite communication network are analyzed. Through machine learning classifiers or pattern recognition algorithms, the content of each traffic packet is analyzed and checked to identify data that does not conform to known regular communication patterns, usually including abnormal increases in traffic, signals from unknown sources, or non-standard data packet structures. Characteristics indicate abnormal or malicious communication activities. The abnormal communication patterns are calibrated, including classifying them and recording their characteristics for easy tracking and analysis, to obtain abnormal pattern calibration results.

[0094] S403: Based on the abnormal pattern calibration result, by comparing the standard traffic pattern with the abnormal pattern, identify the key traffic packet header information, extract the attack features, and obtain the attack feature extraction result.

[0095] Based on the abnormal pattern calibration results, by analyzing the information in the traffic packet header, such as the source address, destination address, port number and protocol type, information is the key to identifying potential attack behaviors. By extracting abnormal features in the data, such as a specific source address frequently sending a large number of requests to an uncommon destination port, the analysis reveals the strategies and techniques that the attacker may use, extracting the specific features of the attack from a large amount of data, and obtaining the attack feature extraction results.

[0096] See also Figure 6As shown, the steps of constructing a dynamic simulation environment based on the attack feature extraction results, inputting multiple defense strategies, evaluating the ability of differentiated defense strategies to combat threats by simulating attack and defense scenarios, dynamically adjusting the parameters of the defense strategies, optimizing the response mechanism in the simulation environment, and obtaining the defense strategy optimization information are as follows:

[0097] S501: Based on the attack feature extraction results, hardware and software resources are configured to establish a dynamic simulation environment capable of simulating multiple threats, and initial conditions and simulation parameters of multiple defense strategies are set to obtain a dynamic simulation test environment;

[0098] Based on the attack feature extraction results, hardware and software resources are configured. The configuration process includes selecting servers and network devices that can support high-load and complex simulation operations. The hardware resources must have high-speed processing capabilities and large-capacity storage to support the needs of the dynamic simulation environment. The simulation software is installed and configured. The software can generate corresponding threat scenarios based on the extracted attack features and set the initial conditions of various defense strategies, including firewall rules, intrusion detection system parameters, and abnormal traffic monitoring strategies. The simulation parameters are set according to the specific characteristics of the attack data, such as attack frequency and attack type, to ensure that the simulation environment can cover various potential threat situations, build a dynamic simulation environment that can simulate multiple threats, and obtain a dynamic simulation test environment.

[0099] S502: Based on the dynamic simulation test environment, by real-time monitoring of the simulated attack and defense interactions, the operating parameters of the defense strategy are gradually adjusted to optimize the ability to resist multiple attack modes, and a real-time strategy adjustment record is obtained;

[0100] The formula for adjusting the operating parameters of the defense strategy is:

[0101]

[0102] Among them, P(n+1) represents the defense strategy parameters of the next stage, P(n) represents the defense strategy parameters of the current stage, ΔL represents the loss change from the previous stage to the current stage, L(n) represents the loss value of the current stage, and L target represents the target loss value, and K represents the adjustment coefficient.

[0103] formula:

[0104]

[0105] Parameter meaning and acquisition method:

[0106] P(n+1) and P(n) represent the defense strategy parameters for the next stage and the current stage, respectively. The parameters are usually maintained by the control system in the dynamic simulation environment and adjusted according to the defense effect at the end of each simulation cycle.

[0107] ΔL is the change in loss from the previous stage to the current stage of attack simulation. It is calculated by comparing the attack loss values ​​of two consecutive simulation cycles, that is, ΔL = L(n) - L(n-1).

[0108] L(n) and L target are the loss value of the current stage and the target loss value. The current stage loss L(n) is usually determined by the amount of data loss caused by the simulated attack, while the target loss value L target It is the upper limit of the expected loss set by the defense strategy, which is set according to security requirements and system tolerance. The loss value L(n) refers to the quantitative representation of the data loss or system performance loss suffered by the system during the simulated attack in a dynamic simulation environment. The value can be set based on a variety of indicators, depending on the purpose of the simulation and security requirements. For example, data integrity loss: If the attack causes the data to be tampered with or lost, the loss value can reflect the proportion or importance of the lost data. Service availability loss: In the case of a service denial attack, the loss value may represent the ratio of the time the service is unavailable to the total running time. Performance degradation: For attacks that cause the system response time to increase or the processing capacity to decrease, the loss value can be the degree of performance degradation.

[0109] K is the adjustment coefficient, which is used to control the speed and amplitude of parameter adjustment. The coefficient is set according to the response sensitivity of the system and the adjustment requirements of the defense strategy, and the optimal value is generally determined through historical data analysis.

[0110] Calculation example:

[0111] Set the current defense strategy parameter P(n) to 0.5 and the target loss value L target Set to 0.05, the current stage loss L(n) is 0.1, and the previous stage loss L(n-1) is 0.15. The adjustment coefficient K is assumed to be 0.3.

[0112] Calculate the change in loss:

[0113] ΔL=L(n)-L(n-1)=0.1-0.15=-0.05;

[0114] Calculate the defense strategy parameters for the next stage:

[0115]

[0116]

[0117] The calculation example shows that due to the reduction in loss, the defense strategy parameters of the next stage are slightly reduced from 0.5 to 0.4933, reflecting that the system fine-tunes the defense strategy when reaching a loss closer to the target. This adjustment helps to refine the defense strategy so that the security goal can be achieved more accurately.

[0118] S503: Based on the real-time strategy adjustment record, the effectiveness of the defense strategy is evaluated through comparative analysis of simulation results, and the response mechanism and defense parameters of the simulation environment are dynamically optimized to obtain defense strategy optimization information.

[0119] Based on the real-time strategy adjustment records, the attack success rate and defense efficiency before and after the implementation of different defense strategies are compared. The improvement effect of the defense strategy is verified through statistical testing and effect evaluation. According to the analysis results, the response mechanism of the simulation environment is dynamically optimized, such as adjusting the defense parameters and enhancing the adaptive ability of the strategy, so as to better respond to emerging attack modes, ensure that the simulation environment continues to adapt to changes in real-world threats, improve the overall security and responsiveness of the simulation system, and obtain defense strategy optimization information.

[0120] See also Figure 7 As shown, the steps of applying the optimized defense strategy to the actual satellite communication network based on the defense strategy optimization information, conducting actual combat simulation tests, analyzing the efficiency of system response and threat interception, evaluating the simulation test results, and obtaining the actual combat simulation effect evaluation results are specifically as follows:

[0121] S601: Based on the defense strategy optimization information, the optimized defense strategy is deployed in the actual satellite communication network, the network environment is set, the new defense parameters are matched, and the actual strategy deployment environment is obtained;

[0122] Based on the defense strategy optimization information, the new defense strategy is integrated into the actual satellite communication network, including updating firewall rules, intrusion detection system settings and other relevant security parameters. The updated parameters are based on the optimization information obtained in the previous simulation test to ensure that the defense strategy is consistent with the actual threat scenario. The network hardware and software resources are configured to ensure that all security devices can handle the updated configuration and higher data traffic requirements. The test environment is set up to ensure the stability and compatibility of the new strategy and to ensure that there are no negative effects that affect network performance. A practical strategy deployment environment that matches the new defense parameters is constructed to obtain a practical strategy deployment environment.

[0123] S602: Based on the actual combat strategy deployment environment, start the actual attack and defense scenario simulation test, record the response and defense effect of the satellite network system under various attacks, fine-tune and optimize the strategy, and obtain the actual combat adjustment and test results;

[0124] Based on the actual combat strategy deployment environment, actual attack and defense scenario simulation tests are launched to verify the effectiveness of the deployed defense strategy by simulating actual attacks. The response and defense performance of the satellite network system in the face of various attacks, including simple denial of service attacks to complex data penetration attempts, are monitored and recorded in real time. Through testing, performance data is collected, and the data is analyzed to identify weaknesses and potential areas for improvement in the defense strategy. The strategy is fine-tuned, such as adjusting the sensitivity of the firewall or updating the parameters of intrusion detection. The entire process is based on actual test data to ensure the efficiency and accuracy of the defense strategy in real scenarios and obtain actual combat adjustments and test results.

[0125] S603: Based on actual combat adjustments and test results, the effectiveness of the strategy in actual operations is evaluated through system response and threat interception analysis to obtain actual combat simulation effect evaluation results.

[0126] The formula for evaluating the effectiveness of the strategy in actual operation is:

[0127]

[0128] Among them, E is the effectiveness index of the strategy, T tp Represents the number of times the attack is successfully intercepted, T tn represents the number of times non-attack situations are correctly ignored, T fp represents the number of times non-attack situations are falsely reported as attacks, T fn represents the number of times the attack was not detected, W tp and W tn is the weight coefficient.

[0129] formula:

[0130]

[0131] Parameter meaning and acquisition method:

[0132] T tp : The number of attacks that were successfully intercepted. This value indicates the number of attacks that the defense system correctly identified and intercepted during the simulation test. This value is obtained by counting all correctly identified attack events during the test.

[0133] T tn : The number of times non-attack situations are correctly ignored. This value indicates the number of non-attack behaviors that the system correctly ignores in the simulation test. It is obtained by counting the number of events during the test that all normal behaviors are not falsely reported as attacks.

[0134] T fp : The number of times non-attack situations are falsely reported as attacks. This value indicates the number of events where the system mistakenly identifies normal behavior as attacks. It is obtained by counting all normal events that are incorrectly marked as attacks.

[0135] T fn : The number of times the attack was not detected, which indicates the number of events in which the attack was not detected by the system. This is obtained by counting all the missed attack events during the test.

[0136] W tp and W tn :The weight coefficient is set according to the importance of the system strategy. tp reflects the emphasis on defense attack, while W tn This reflects the emphasis on reducing false positives. Usually the weights are optimized based on historical data and strategy goals.

[0137] Calculation example:

[0138] In a specific simulation test, the following data is obtained: T tp =80, indicating that 80 attacks were correctly intercepted, T tn =150, indicating that 150 non-aggressive behaviors were correctly ignored, T fp =20, indicating that 20 normal behaviors were misreported as attacks, T fn =10, indicating that 10 attacks were not detected, W tp =0.6,W tn =0.4, the weight set according to the defense strategy.

[0139] The effectiveness index E of the calculation strategy is as follows:

[0140]

[0141]

[0142] The calculation example shows that the effectiveness index of the defense strategy is 0.415. The result indicates that the overall effectiveness of the strategy in the simulation environment is below average under given weights and number of events. This index helps quantify the performance of the defense system under real-world conditions, so that necessary adjustments can be made to the strategy to improve efficiency and effectiveness.

[0143] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.

[0144] In the present invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0145] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0146] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0147] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0148] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0149] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0150] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0151] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0152] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. A satellite dynamic simulation verification method based on generative adversarial network threat modeling, characterized in that: The following steps are involved: S1: Based on the generative adversarial network environment, set the initial network parameters, initialize the weights of the generator and discriminator, and perform basic configuration tests on the model to obtain the initialized model state; S2: Based on the initialization model state, extract the threat records of satellite communications, train the generator to simulate the unknown threat model, optimize the discrimination ability of the discriminator through round-by-round iteration, and obtain the trained model; S3: Based on the trained model, a threat scenario generation operation is performed, the output of the generator is adjusted, the characteristics of the differentiated threats are matched, and the generated threat scenario data is obtained; S4: Based on the generated threat scenario data, analyze the satellite communication network traffic, identify abnormal traffic packet header information, and obtain attack feature extraction results; S5: Based on the attack feature extraction result, a dynamic simulation environment is constructed, and multiple defense strategies are input. By simulating attack and defense scenarios, the ability of differentiated defense strategies to combat threats is evaluated, and the parameters of the defense strategies are dynamically adjusted to obtain defense strategy optimization information. S6: Based on the defense strategy optimization information, the optimized defense strategy is applied to the actual satellite communication network, the efficiency of system response and threat interception is analyzed, the simulation test results are evaluated, and the actual combat simulation effect evaluation results are obtained.

2. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: The initialization model state includes the initial learning rate, the initial batch size and the weight initialization state; the trained model includes the optimized generator weights, the discriminator weights and the data recognition accuracy; the generated threat scenario data includes the enhanced sample diversity, the sample complexity and the simulated threat type; the attack feature extraction results include the calibrated abnormal communication mode, the identified specific traffic packet header information and the key parameters of the cluster analysis; the defense strategy optimization information includes the adjusted defense parameters, the optimized response strategy and the tested scenario data; the actual combat simulation effect evaluation results include the recorded system response data, the threat interception efficiency and the simulation test data.

3. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the generative adversarial network environment, the initial network parameters are set, the weights of the generator and discriminator are initialized, and the basic configuration test of the model is performed. The specific steps to obtain the initialization model state are: S101: Based on the generative adversarial network environment, configure the computing platform required by the generative adversarial network, select a matching GPU configuration and neural network library, perform hardware configuration and software environment settings for the network, and obtain the environment configuration status; S102: Based on the environment configuration state, use random numbers to initialize the network weights of the generator and the discriminator, set the learning rate and the batch size, perform network parameter setting, and obtain initial weight setting information; S103: Based on the initial weight setting information, forward propagation and back propagation tests are performed to check the integrity of the network structure and the validity of the parameter settings, verify that the model components function normally, and obtain the initialized model state.

4. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the initialization model state, the threat records of satellite communications are extracted, the generator is trained to simulate the unknown threat model, and the distinguishing ability of the discriminator is optimized through round-by-round iterations. The steps of obtaining the trained model are as follows: S201: extracting and screening threat records from satellite communication records based on the initialization model state, preprocessing the data, including normalization and encoding, constructing a data set suitable for training, and obtaining a historical threat data set; S202: Based on the historical threat data set, simulating threat scenarios through a generator, iteratively training the generator, and optimizing the ability of the generator to simulate unknown threats by adjusting internal parameters of the generator to obtain a preliminary training model; S203: Based on the preliminary training model, perform deep training on the discriminator to improve the ability of the discriminator to distinguish between generated data and real data, refine the parameter adjustment after each round of training, optimize the accuracy of the model in identifying true and false data, and obtain a trained model.

5. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the trained model, the threat scenario generation operation is performed, the output of the generator is adjusted, the characteristics of the differentiated threats are matched, and the steps of obtaining the generated threat scenario data are specifically as follows: S301: Based on the trained model, the output parameters of the generator are adjusted, including the modification of the output frequency and the data structure, so as to optimize the matching of the generated data with various threat scenarios and obtain the adjusted output parameters; S302: Based on the adjusted output parameters, by importing multiple data sample types, adjusting the degree of variation of the data samples, enhancing the complexity and diversity of the generated samples, optimizing the generalization ability of the model, and obtaining an enhanced sample data set; S303: Based on the enhanced sample data set, complexity analysis and challenge enhancement are performed on the generated data to verify the effect of the generated data in simulating multiple threat environments, thereby obtaining generated threat scenario data.

6. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the generated threat scenario data, the satellite communication network traffic is analyzed, abnormal traffic packet header information is identified, and the steps of obtaining attack feature extraction results are specifically as follows: S401: Based on the generated threat scenario data, data is screened and preprocessed, including cleaning irrelevant data and formatting traffic packet data, to obtain screened traffic data; S402: Based on the filtered traffic data, analyzing traffic packets in the satellite communication network, identifying communication modes that are inconsistent with normal modes, calibrating abnormal communication modes, and obtaining abnormal mode calibration results; S403: Based on the abnormal pattern calibration result, by comparing the standard traffic pattern with the abnormal pattern, identifying key traffic packet header information, extracting attack features, and obtaining attack feature extraction results.

7. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the attack feature extraction results, a dynamic simulation environment is constructed, multiple defense strategies are input, and the ability of differentiated defense strategies to combat threats is evaluated by simulating attack and defense scenarios, and the parameters of the defense strategies are dynamically adjusted to obtain the defense strategy optimization information. Specifically, the steps are as follows: S501: Based on the attack feature extraction result, hardware and software resources are configured to establish a dynamic simulation environment capable of simulating multiple threats, and initial conditions and simulation parameters of multiple defense strategies are set to obtain a dynamic simulation test environment; S502: Based on the dynamic simulation test environment, by real-time monitoring of the simulated attack and defense interactions, the operating parameters of the defense strategy are gradually adjusted to optimize the ability to resist multiple attack modes, and a real-time strategy adjustment record is obtained; S503: Based on the real-time strategy adjustment record, the effect of the defense strategy is evaluated through comparative analysis of simulation results, and the response mechanism and defense parameters of the simulation environment are dynamically optimized to obtain defense strategy optimization information.

8. According to the satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 7, the formula for adjusting the operating parameters of the defense strategy is: in, P(n+1) represents the defense strategy parameters of the next stage, P(n) represents the defense strategy parameters of the current stage, ΔL represents the change in loss from the previous stage to the current stage, L(n) represents the loss value of the current stage, and L target represents the target loss value, and K represents the adjustment coefficient.

9. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 1 is characterized in that: Based on the defense strategy optimization information, the optimized defense strategy is applied to the actual satellite communication network, the efficiency of system response and threat interception is analyzed, and the simulation test results are evaluated to obtain the actual combat simulation effect evaluation results. The specific steps are: S601: Based on the defense strategy optimization information, deploy the optimized defense strategy in the actual satellite communication network, set the network environment, match the new defense parameters, and obtain the actual strategy deployment environment; S602: Based on the actual combat strategy deployment environment, start the actual attack and defense scenario simulation test, record the response and defense effect of the satellite network system under various attacks, fine-tune and optimize the strategy, and obtain the actual combat adjustment and test results; S603: Based on the actual combat adjustment and test results, the effectiveness of the strategy in actual operation is evaluated through system response and threat interception analysis to obtain actual combat simulation effect evaluation results.

10. The satellite dynamic simulation verification method based on generative adversarial network threat modeling according to claim 9 is characterized in that: The formula for evaluating the effectiveness of the strategy in actual operation is: Among them, E is the effectiveness index of the strategy, T tp Represents the number of times the attack was successfully intercepted, T tn represents the number of times non-attack situations are correctly ignored, T fp represents the number of times non-attack situations are falsely reported as attacks, T fn represents the number of times the attack was not detected, W tp and W tn is the weight coefficient.

Citation Information

Patent Citations

  • Network traffic anomaly detection method based on generative adversarial network

    CN117749477A

  • Network security protection method and system

    CN117879970A

  • Network boundary threat detection system based on AI drive

    CN118827227A

  • Detecting cyber threats using artificial intelligence

    US20240314164A1

Cited By

  • Satellite network threat analysis system based on AI

    CN120358086A