Network security protection method, device and equipment

By collecting traffic data in the network security protection system and using distributed nodes to train threat identification models, and dynamically adjusting protection strategies, the problem of low adaptability and intelligence of the protection system in the existing technology is solved, and higher fault tolerance and robustness are achieved, as well as the ability to quickly respond to changes in network traffic.

CN120151005APending Publication Date: 2025-06-13GUANGDONG POWER GRID CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510263315.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The low adaptability and intelligence level of existing network security protection methods lead to reduced fault tolerance and robustness, unable to quickly deal with changes in network traffic, and prone to security vulnerabilities caused by fixed strategies being unable to cope with new attacks.

Method used

By collecting traffic data from multiple terminal devices, server logs and firewall data sources, using distributed nodes to train threat identification models, optimize attack mode analysis in real time, dynamically adjust the traffic feature extraction process, and automatically generate the optimal protection strategy based on the risk assessment results.

Benefits of technology

It improves the adaptability and intelligence level of the protection system, improves fault tolerance and robustness, reduces training time, can quickly deal with changes in network traffic, and avoids security vulnerabilities caused by fixed strategies being unable to cope with new attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151005A_ABST
    Figure CN120151005A_ABST
Patent Text Reader

Abstract

The invention discloses a network security protection method, device and equipment, and belongs to the technical field of network security, and the protection method comprises the following specific steps: I, collecting traffic data from a plurality of terminal devices, server logs and data sources of a firewall, and preprocessing each group of collected traffic data; iI, training a threat identification model by using distributed nodes, and carrying out preliminary identification and classification on potential threats through the trained threat identification model; according to the method, the self-adaptability and the intelligent level of the protection system can be improved, the fault tolerance and the robustness of the protection system are improved, the training time is shortened, and the change of network flow can be quickly coped with; the protection measures can be rapidly adjusted, security vulnerabilities caused by the fact that a system cannot cope with new attacks due to a fixed strategy are avoided, the depth and breadth of overall protection are enhanced, and the risk of false alarm and missing alarm is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a network security protection method, device and equipment. Background Art

[0002] With the rapid development of information technology, the network has penetrated into all walks of life and become the basis of social, economic and cultural activities. However, the extensive application of the network has also brought increasingly complex security threats. The forms of network attacks are constantly evolving, and the attack means are increasingly diverse. Traditional protection measures such as firewalls and intrusion detection systems are facing huge challenges. Especially with the popularization of big data, the Internet of Things and cloud computing, the scale and frequency of network attacks have increased sharply, bringing unprecedented pressure to the network security of enterprises and individuals.

[0003] After retrieval, Chinese Patent No. CN116996294A discloses a network security protection method, device and equipment. Although the invention can be applied to a network application firewall to enable the network application firewall to effectively identify the detection behavior of the attacker and achieve attack prevention, the self-adaptability and intelligent level of the protection system are low, reducing the fault tolerance and robustness of the protection system, and the training time is long, and it cannot quickly respond to the changes in network traffic. In addition, the existing network security protection methods, devices and equipment are prone to security vulnerabilities caused by fixed strategies being unable to cope with new attacks, reducing the depth and breadth of overall protection, and increasing the risks of false positives and false negatives. Therefore, we propose a network security protection method, device and equipment. Summary of the Invention

[0004] The purpose of the present invention is to solve the defects existing in the prior art, and to propose a network security protection method, device and equipment.

[0005] In order to achieve the above purpose, the present invention adopts the following technical solutions:

[0006] A network security protection method, and the specific steps of the protection method are as follows:

[0007] Ⅰ. Collect traffic data from multiple terminal devices, server logs and each data source of the firewall, and preprocess each group of collected traffic data;

[0008] Ⅱ. Use distributed nodes to train a threat recognition model, and preliminarily identify and classify potential threats through the trained threat recognition model;

[0009] Ⅲ. Identify the attack patterns of the classified abnormal traffic data, optimize the attack pattern analysis in real time, and dynamically adjust the traffic feature extraction process;

[0010] Ⅳ. Combine historical data analysis, perform clustering analysis and quantitative evaluation on attack samples of multiple abnormal traffic data, and assign different attack priorities according to the evaluation results;

[0011] Ⅴ. According to the risk assessment results, the system automatically generates the optimal protection strategy and dynamically adjusts the security strategy.

[0012] As a further solution of the present invention, the specific steps of using distributed nodes to train the threat recognition model described in step II are as follows:

[0013] S1.1: The central server constructs and initializes a set of global models according to the DNN model architecture, and then collects information of each client. The central server sends the initial model parameters to each distributed client, and each client initializes the parameters of the local model based on the initial model parameters;

[0014] S1.2: Each client inputs its own stored local data set into the local model. Each local model performs forward propagation on the input data, and the output layer performs non-linear processing on the forward propagation result through the sigmoid activation function and outputs the classification result;

[0015] S1.3: Calculate the loss value of the classification result through the cross-entropy loss function, and propagate the calculated loss value layer by layer from the output layer to the input layer, and calculate the gradient of the loss value for each network layer of the corresponding local model. Based on the calculated gradient information, use the stochastic gradient descent method to update the local model parameters;

[0016] S1.4: After each client performs parameter updates for a preset number of rounds locally, each client sends the updated model parameters to the central server. Then the central server receives each group of model parameters and aggregates the model parameters of all clients through the weighted average algorithm to obtain new global model parameters;

[0017] S1.5: The central server sends the new global model parameters back to each client and repeats local training and weighted averaging until the change in the loss value during multiple rounds of training of each client converges to a preset range and then stops, and the final global model parameters are sent to each client.

[0018] As a further solution of the present invention, the specific steps of performing clustering analysis and quantitative evaluation on multiple attack samples described in step V are as follows:

[0019] S2.1: According to the attack data characteristics corresponding to the attack samples of each group of identified abnormal traffic data, initialize a clustering population containing multiple groups of individuals, where the position of each group of individuals represents a potential clustering center, and determine the clustering center of each attack type based on the mean value of the abnormal traffic data in each class;

[0020] S2.2: Calculate the fitness of each individual in the clustering population according to the distance from the attack data characteristics to the clustering center, sort the individuals in each group of the clustering population from largest to smallest according to fitness, and take the individual ranked first as the optimal individual. For the remaining individuals, update their positions based on the position information of the optimal individual, the randomly generated step size, and the direction coefficient.

[0021] S2.3: After the position update of each individual is completed, detect whether the position of each individual exceeds the preset boundary value. If it does, modify the position of the individual exceeding the boundary value to the boundary value. Otherwise, recalculate the fitness value of each individual after the position update, and sort the individuals in each group of the clustering population from largest to smallest again. Then, perform position update based on the new optimal individual.

[0022] S2.4: Repeatedly perform clustering center update, optimal individual selection, and position update until the clustering center position converges to the preset range, then stop the iteration, analyze the result of the final clustering, evaluate the range of devices or networks affected by the attack based on factors such as the geographical distribution of the attack data, the number of affected devices, and the network topology, and calculate the duration of the attack by monitoring the timestamp of the attack data.

[0023] A network security protection device includes a collection and processing module, an anomaly monitoring module, an identification and classification module, a distribution optimization module, a risk assessment module, a policy generation module, a response and isolation module, a monitoring and alarm module, and a traceability analysis module.

[0024] The collection and processing module is used to collect network traffic information from multiple data sources and clean and standardize the collected data.

[0025] The anomaly monitoring module is used to monitor the real-time network traffic and detect abnormal behaviors.

[0026] The identification and classification module further identifies the threat type based on the anomaly detection result, the traffic pattern, and each dimension of the attack characteristics.

[0027] The distribution optimization module is used to monitor the operation information of the anomaly monitoring module and perform distributed optimization on it.

[0028] The risk assessment module is used to evaluate the threat levels of different security events and divide priorities.

[0029] The policy generation module is used to dynamically adjust the protection policy based on the risk assessment result.

[0030] The response and isolation module is used to immediately execute the defense policy generated by the policy generation module when a threat is detected.

[0031] The monitoring and alarm module is used to monitor the network status in real time and issue an alarm when a security event occurs.

[0032] The traceability analysis module is used to conduct forensic evidence collection and attack traceability after an attack occurs, and generate a security report.

[0033] As a further solution of the present invention, the specific steps for the recognition and classification module to further identify threat types based on traffic patterns and various dimensions of attack characteristics are as follows:

[0034] S3.1: Use the current network traffic or attack characteristic set as the root node, establish a preliminary threat classification based on historical attack data, and then start from the root node. Generate different attack characteristics or traffic patterns according to existing network attack data or real-time traffic data, and connect them as child nodes to the original root node to construct an initial classification tree;

[0035] S3.2: Start from the root node of the initial classification tree, calculate the UCB value of each child node, and layer by layer select the child node with the highest UCB value for exploration. At the same time, according to the monitoring results of the anomaly monitoring module, existing network attack data, and real-time traffic data, expand the current child node to generate new potential threat types and add them to the classification tree;

[0036] S3.3: After expanding the node, simulate the effects of new protection strategies or threat recognition paths. By analyzing the possible attack impacts brought by each node and calculating its potential damage degree, after the simulation process is completed, trace back the simulation results from the current node to the root node and update the evaluation values of each node on the path;

[0037] S3.4: Repeat the processes of selection, expansion, simulation, and backtracking multiple times until the preset number of iterations is reached. Then traverse the final classification tree, and use the path with the highest evaluation value as the threat type classification of the current attack data.

[0038] As a further solution of the present invention, the specific steps for the policy generation module to dynamically adjust the protection policy are as follows:

[0039] S4.1: Collect historical network protection policies, construct a corresponding policy space according to the configurations of various parameters in the network security protection systems in each network protection policy, and then initialize a group of exploration populations and randomly initialize the positions of each exploration body in the policy space;

[0040] S4.2: Establish a corresponding fitness function based on the risk assessment results, then calculate the fitness values of each exploration body through the fitness function, and select the exploration body with the highest fitness value in the exploration population as the target body. When each exploration body updates its position, update the position according to the randomly generated step size coefficient, the target body, and the position of any randomly selected exploration body;

[0041] S4.3: After the positions of all exploration entities are updated, each exploration entity exchanges protection effects, attack modes, and security improvement information with the remaining exploration entities according to its own fitness value. Then, based on the exchange results, the positions of the exploration entities are adjusted again. After that, based on random perturbations, each exploration entity is replicated to generate new exploration entities. Next, the fitness values of each exploration entity are calculated, and the positions of the exploration entities with fitness values lower than the preset threshold are reset.

[0042] S4.4: Repeatedly perform the processes of exploration entity position update, information sharing, reproduction, and dispersion until the change value of the fitness value of the target entity converges within the preset range after multiple rounds of iteration. Then, the protection strategy corresponding to the target entity is used as the optimal protection strategy and is executed.

[0043] A network security protection device includes a memory, a processor, a network interface card, an acceleration card, a security chip, a power supply, a temperature sensor, and a radiator.

[0044] The memory is used to cache network data monitored in real time and store attack feature data and historical logs. The processor is used to execute all computing tasks.

[0045] The network interface card is used for data transmission between the device and the external network. The acceleration card is used to improve the performance of specific computing tasks of the processor. The security chip is used for encryption and decryption, key management, and prevention of physical tampering.

[0046] The power supply is used to provide a stable power supply for each component of the network security protection device. The temperature sensor is used to monitor temperature changes inside and outside the device. The radiator is used to reduce the heat generated during the operation of the device according to the temperature data collected by the temperature sensor.

[0047] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0048] 1. The central server of this network security protection method constructs and initializes a set of global models according to the DNN model architecture, and then collects information from each client. The central server sends the initial model parameters to each distributed client. Each client initializes the parameters of its local model based on the initial model parameters. Each client uses the local dataset stored by itself to train the local model. After each client performs parameter updates for a preset number of rounds locally, each client sends the updated model parameters to the central server. Then, the central server receives each group of model parameters and aggregates the model parameters of all clients through a weighted average algorithm to obtain new global model parameters. The central server sends the new global model parameters back to each client and repeats the local training and weighted average until the change in the loss value during multiple rounds of training by each client converges to a preset range and then stops. Finally, the central server distributes the final global model parameters to each client, which can improve the adaptability and intelligence level of the protection system, enhance the fault tolerance and robustness of the protection system, reduce the training time, and quickly respond to changes in network traffic.

[0049] 2. This invention collects historical network protection strategies and constructs a corresponding strategy space according to the configuration of various parameters in the network security protection system in each network protection strategy. Then, it initializes a set of exploration populations and randomly initializes the positions of each exploration entity in the strategy space of the exploration population. Based on the risk assessment results, a corresponding fitness function is established. Then, the fitness values of each exploration entity are calculated through the fitness function, and the exploration entity with the highest fitness value in the exploration population is selected as the target entity. When each exploration entity updates its position, it updates its position based on the randomly generated step coefficient, the target entity, and the position of any randomly selected exploration entity. After the positions of each exploration entity are updated, each exploration entity exchanges information on protection effects, attack modes, and security improvements with the other exploration entities according to its own fitness value, and adjusts the position of the exploration entity again according to the exchange results. Then, based on random perturbation, each exploration entity is replicated to generate new exploration entities, and then the fitness values of each exploration entity are calculated, and the positions of the exploration entities with fitness values lower than the preset threshold are reset. The processes of exploration entity position update, information sharing, reproduction, and dispersion are repeated until the change value of the fitness value of the target entity after multiple rounds of iteration converges to a preset range. The protection strategy corresponding to the target entity is used as the optimal protection strategy and is executed, which can quickly adjust the protection measures, avoid security vulnerabilities caused by the system's inability to cope with new attacks due to fixed strategies, enhance the depth and breadth of overall protection, and reduce the risks of false positives and false negatives. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation to the present invention.

[0051] Figure 1Flow chart of a network security protection method proposed by the present invention;

[0052] Figure 2 System block diagram of a network security protection device proposed by the present invention. Detailed implementation manners

[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0054] Embodiment 1

[0055] Referring to Figure 1 , this embodiment discloses a network security protection method, and the specific steps of the protection method are as follows:

[0056] Collect traffic data from multiple terminal devices, server logs, and firewall data sources, and preprocess each group of collected traffic data.

[0057] Use distributed nodes to train a threat recognition model, and initially identify and classify potential threats through the trained threat recognition model.

[0058] Specifically, the central server constructs and initializes a set of global models according to the DNN model architecture, and then collects information of each client. The central server sends the initial model parameters to each distributed client. Each client initializes the parameters of the local model based on the initial model parameters. Each client inputs its own stored local data set into the local model. Each local model performs forward propagation on the input data. The output layer performs nonlinear processing on the forward propagation result through the sigmoid activation function and outputs a classification result. Calculate the loss value of the classification result through the cross-entropy loss function, and backpropagate the calculated loss value layer by layer from the output layer to the input layer, and calculate the gradient of the loss value for each network layer of the corresponding local model. Based on the calculated gradient information, use the stochastic gradient descent method to update the local model parameters. After each client performs parameter updates for a preset number of rounds locally, each client sends the updated model parameters to the central server. Then the central server receives each group of model parameters and aggregates all the model parameters of the clients through the weighted average algorithm to obtain new global model parameters. The central server sends the new global model parameters back to each client and repeats local training and weighted average until the change in the loss value during multiple rounds of training of each client converges to a preset range and then stops, and the final global model parameters are sent to each client.

[0059] Identify the attack patterns of the classified abnormal traffic data, optimize the attack pattern analysis in real time, and dynamically adjust the traffic feature extraction process.

[0060] Combined with historical data analysis, perform clustering analysis and quantitative evaluation on the attack samples of multiple abnormal traffic data, and assign different attack priorities according to the evaluation results.

[0061] Specifically, according to the attack data characteristics corresponding to the attack samples of each group of identified abnormal traffic data, initialize a clustering population containing multiple groups of individuals, where the position of each group of individuals represents a potential clustering center. Determine the clustering centers of each attack type based on the mean value of the abnormal traffic data in each class. Calculate the fitness of each group of individuals in the clustering population according to the distance from the attack data characteristics to the clustering center. Sort the groups of individuals in the clustering population from largest to smallest according to fitness, and take the individual ranked first as the optimal body. The remaining individuals update their own positions based on the position information of the optimal body, the randomly generated step size, and the direction coefficient. After the position update of each individual is completed, detect whether the position of each individual exceeds the preset boundary value. If it exceeds, modify the position of the individual exceeding the boundary value to the boundary value. Otherwise, recalculate the fitness values of each individual after the position update, and sort the groups of individuals in the clustering population from largest to smallest again. Then, perform position update according to the new optimal body. Repeatedly perform clustering center update, optimal body selection, and position update until the clustering center position converges to the preset range, then stop the iteration, and analyze the results of the final clustering. Evaluate the scope of devices or networks affected by the attack based on factors such as the geographical distribution of the attack data, the number of affected devices, and the network topology. Calculate the duration of the attack by monitoring the timestamps of the attack data.

[0062] According to the risk assessment results, the system automatically generates the optimal protection strategy and dynamically adjusts the security strategy.

[0063] Embodiment 2

[0064] Refer to Figure 2 , this embodiment discloses a network security protection device, including a collection and processing module, an anomaly monitoring module, an identification and classification module, a distribution optimization module, a risk assessment module, a strategy generation module, a response and isolation module, a monitoring and alarm module, and a traceability analysis module;

[0065] The collection and processing module is used to collect network traffic information from multiple data sources and clean and standardize the collected data; the anomaly monitoring module is used to monitor the real-time network traffic and detect abnormal behaviors; the identification and classification module further identifies the threat types based on each dimension of the traffic pattern and attack characteristics according to the anomaly detection results.

[0066] Specifically, take the current network traffic or attack feature set as the root node, establish a preliminary threat classification based on historical attack data. Then, starting from the root node, generate different attack features or traffic patterns according to the existing network attack data or real-time traffic data, and connect them as child nodes to the original root node to construct an initial classification tree. Starting from the root node of the initial classification tree, calculate the UCB values of each child node, and layer by layer select the child node with the highest UCB value for exploration. At the same time, according to the monitoring results of the anomaly detection module, the existing network attack data, and the real-time traffic data, expand the current child node to generate new potential threat types and add them to the classification tree. After expanding the node, simulate the effects of new protection strategies or threat recognition paths. By analyzing the possible attack impacts brought by each node and calculating their potential damage levels, after the simulation process is completed, trace back the simulation results from the current node to the root node and update the evaluation values of each node on the path. Repeat the selection, expansion, simulation, and backtracking multiple times until the preset number of iterations is reached. Then traverse the final classification tree and take the path with the highest evaluation value as the threat type classification of the current attack data.

[0067] The distribution optimization module is used to monitor the operation information of the anomaly detection module and perform distributed optimization on it; the risk assessment module is used to evaluate the threat levels of different security events and divide priorities; the policy generation module is used to dynamically adjust the protection strategy based on the risk assessment results.

[0068] Specifically, collect historical network protection strategies, and construct the corresponding policy space according to the configurations of various parameters in the network security protection system in each network protection strategy. Then initialize a group of exploration populations, and randomly initialize the positions of each explorer in the policy space. Establish the corresponding fitness function based on the risk assessment results. Then calculate the fitness values of each explorer through the fitness function, and select the explorer with the highest fitness value in the exploration population as the target body. When updating the positions of each explorer, update the positions according to the randomly generated step coefficient, the target body, and the position of any randomly selected explorer. After the positions of each explorer are updated, each explorer exchanges information on protection effects, attack modes, and security improvements with the rest of the explorers according to its own fitness value, and adjusts the positions of the explorers again according to the exchange results. Then, based on random perturbations, replicate each explorer to generate new explorers, calculate the fitness values of each explorer again, and reset the positions of the explorers with fitness values lower than the preset threshold. Repeatedly perform the processes of explorer position update, information sharing, reproduction, and dispersion until the change value of the fitness value of the target body converges within the preset range after multiple iterations. Take the protection strategy corresponding to the target body as the optimal protection strategy and execute it.

[0069] The response isolation module is used to immediately execute the defense policies generated by the policy generation module when a threat is detected; the monitoring and alerting module is used to monitor the network status in real time and issue alerts when security incidents occur; the traceability analysis module is used to conduct forensic evidence collection and attack traceability after an attack occurs and generate security reports.

[0070] Embodiment 3.

[0071] A network security protection device, including a memory, a processor, a network interface card, an acceleration card, a security chip, a power supply, a temperature sensor, and a radiator.

[0072] The memory is used to cache the network data monitored in real time and store attack feature data and historical logs; the processor is used to execute all computing tasks.

[0073] The network interface card is used for data transmission between the device and the external network; the acceleration card is used to improve the performance of specific computing tasks of the processor; the security chip is used for encryption and decryption, key management, and prevention of physical tampering.

[0074] The power supply is used to provide a stable power supply for each component of the network security protection device; the temperature sensor is used to monitor the temperature changes inside and outside the device; the radiator is used to reduce the heat generated during the operation of the device according to the temperature data collected by the temperature sensor.

Claims

1. A network security protection method, characterized in that: The specific steps of this protection method are as follows: Ⅰ. Collect traffic data from multiple terminal devices, server logs and firewall data sources, and pre-process each group of collected traffic data; II. Use distributed nodes to train threat identification models, and use the trained threat identification models to preliminarily identify and classify potential threats; III. Identify attack patterns of classified abnormal traffic data and optimize attack pattern analysis in real time while dynamically adjusting the traffic feature extraction process; IV. Combined with historical data analysis, cluster analysis and quantitative evaluation are performed on attack samples of multiple abnormal traffic data, and different attack priorities are assigned based on the evaluation results; Ⅴ. Based on the risk assessment results, the system automatically generates the optimal protection strategy and dynamically adjusts the security strategy.

2. A network security protection method according to claim 1, characterized in that: The specific steps of using distributed nodes to train the threat identification model in step II are as follows: S1.1: The central server builds and initializes a set of global models according to the DNN model architecture, and then collects information from each client. The central server sends the initial model parameters to each distributed client, and each client initializes the parameters of the local model based on the initial model parameters. S1.2: Each client inputs its own stored local data set into the local model. Each local model performs forward propagation on the input data. The output layer performs nonlinear processing on the forward propagation result through the sigmoid activation function and outputs the classification result. S1.3: Calculate the loss value of the classification result through the cross entropy loss function, and back-propagate the calculated loss value from the output layer to the input layer layer by layer, and calculate the gradient of the loss value for each network layer of the corresponding local model. Based on the gradient information at the calculation point, use the stochastic gradient descent method to update the local model parameters; S1.4: After each client performs a preset round of parameter updates locally, each client sends the updated model parameters to the central server. The central server then receives each set of model parameters and aggregates the model parameters of all clients through a weighted average algorithm to obtain new global model parameters. S1.5: The central server sends the new global model parameters back to each client, and repeats local training and weighted averaging until the loss value changes of each client during multiple rounds of training converge to the preset range, and then sends the final global model parameters to each client.

3. A network security protection method according to claim 2, characterized in that: The specific steps of clustering analysis and quantitative evaluation of multiple attack samples described in step V are as follows: S2.1: Based on the attack data features corresponding to the attack samples of each group of abnormal traffic data identified, a cluster population containing multiple groups of individuals is initialized, where the position of each group of individuals represents a potential cluster center, and the cluster center of each attack type is determined based on the mean value of the abnormal traffic data in each class; S2.2: Calculate the fitness of each group of individuals in the cluster population according to the distance from the attack data feature to the cluster center, sort the individuals in the cluster population from large to small according to the fitness, and take the first-ranked individual as the optimal individual. The remaining individuals update their positions based on the position information of the optimal individual and the randomly generated step length and direction coefficient; S2.3: After the position of each individual is updated, check whether the position of each individual exceeds the preset boundary value. If so, modify the position of the individual that exceeds the boundary value to the boundary value. Otherwise, recalculate the fitness value of each individual after the position update, and arrange the groups of individuals in the cluster population from large to small again, and then update the position according to the new optimal individual; S2.4: Repeat the cluster center update, optimal body selection and position update until the cluster center position converges to the preset range, stop the iteration, and analyze the final clustering results. Evaluate the range of devices or networks affected by the attack based on the geographical distribution of the attack data, the number of affected devices, and the network topology factors. Calculate the duration of the attack by monitoring the timestamp of the attack data.

4. A network security protection device, used to implement a network security protection method according to any one of claims 1 to 3, characterized in that: It includes collection and processing module, anomaly monitoring module, identification and classification module, distribution optimization module, risk assessment module, strategy generation module, response isolation module, monitoring and alarm module and source tracing analysis module; The collection and processing module is used to collect network traffic information from multiple data sources and clean and standardize the collected data; The anomaly monitoring module is used to monitor real-time network traffic and detect abnormal behavior; The identification and classification module further identifies the threat type based on the traffic pattern and attack characteristics according to the anomaly detection results; The distribution optimization module is used to monitor the operation information of the anomaly detection module and perform distributed optimization on it; The risk assessment module is used to assess the threat levels of different security events and prioritize them; The strategy generation module is used to dynamically adjust the protection strategy based on the risk assessment results; The response isolation module is used to immediately execute the defense strategy generated by the strategy generation module when a threat is detected; The monitoring and alarm module is used to monitor the network status in real time and issue an alarm when a security incident occurs; The source tracing analysis module is used to collect evidence and trace the attack source after the attack occurs, and generate a security report.

5. A network security protection device according to claim 4, characterized in that: The specific steps of the identification and classification module to further identify threat types based on traffic patterns and attack characteristics are as follows: S3.1: Take the current network traffic or attack feature set as the root node, establish a preliminary threat classification based on historical attack data, and then start from the root node to generate different attack features or traffic patterns based on the existing network attack data or real-time traffic data, and connect them to the original root node as child nodes to build an initial classification tree; S3.2: Starting from the root node of the initial classification tree, the UCB value of each child node is calculated, and the child node with the highest UCB value is selected layer by layer for exploration. At the same time, according to the monitoring results of the anomaly monitoring module, the existing network attack data and the real-time traffic data, the current child node is expanded to generate a new potential threat type and add it to the classification tree; S3.3: After expanding the node, simulate the effect of the new protection strategy or threat identification path by analyzing the possible attack impact of each node and calculating its potential damage. After the simulation process is completed, trace the simulation results from the current node to the root node and update the evaluation value of each node on the path; S3.4: Repeat the selection, expansion, simulation and backtracking multiple times until the preset number of iterations is reached, then traverse the final classification tree and take the path with the highest evaluation value as the threat type classification of the current attack data.

6. A network security protection device according to claim 4, characterized in that: The specific steps of dynamically adjusting the protection strategy by the strategy generation module are as follows: S4.1: Collect historical network protection strategies, and construct corresponding strategy spaces according to the configuration of various parameters in the network security protection system in each network protection strategy. Then initialize a set of exploration populations, and randomly initialize the position of each exploration body in the exploration population in the strategy space. S4.2: Establish the corresponding fitness function based on the risk assessment results, then calculate the fitness value of each explorer through the fitness function, and select the explorer with the highest fitness value in the exploration population as the target body. When each explorer updates its position, it updates its position based on the randomly generated step coefficient, the target body, and the position of any randomly selected explorer. S4.3: After the position of each explorer is updated, each explorer exchanges the protection effect, attack mode and security improvement information with other explorers according to its own fitness value, and adjusts the position of the explorer again according to the exchange result. Then, based on random perturbations, each explorer is copied to generate a new explorer, and the fitness value of each explorer is calculated, and the position of the explorer whose fitness value is lower than the preset threshold is reset; S4.4: Repeat the exploration body position update, information sharing, reproduction and dispersion process until the fitness value of the target body converges to a preset range after multiple rounds of iterations, and take the protection strategy corresponding to the target body as the optimal protection strategy and execute it.

7. A network security protection device, used to implement a network security protection method according to any one of claims 1 to 3, characterized in that: Including memory, processor, network interface card, accelerator card, security chip, power supply, temperature sensor and heat sink; The memory is used to cache the network data monitored in real time and store attack feature data and historical logs; the processor is used to execute all computing tasks; The network interface card is used for data transmission between the device and the external network; the accelerator card is used to improve the performance of specific computing tasks of the processor; the security chip is used for encryption and decryption, key management and prevention of physical tampering; The power supply is used to provide a stable power supply for each component of the network security protection device; the temperature sensor is used to monitor the temperature changes inside and outside the device; the radiator is used to reduce the heat generated by the device during operation according to the temperature data collected by the temperature sensor.

Citation Information

Patent Citations

  • Network security protection method, device and equipment

    CN116996294A