Intelligent network security analysis method and system based on big data

By embedding verification data packets during data transmission and using encryption templates for active encryption, the problems of tampering at the transmission terminal and the encryption of private data are solved, and the security and integrity of data transmission are achieved.

CN120200827APending Publication Date: 2025-06-24SHILUYI (BEIJING) BRAND MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510487434.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art cannot effectively analyze the tampering risk of transmission terminals during data transmission, and does not encrypt private data, resulting in a high risk of data leakage.

Method used

Ensure the integrity and privacy of the transmitted data by embedding verification packets in the transmission protocol and data and actively encrypting it with encryption templates.

Benefits of technology

Effectively judge the tampering risks of transmission terminals, and ensure the security of private data through encryption, avoid data leakage, and improve the security during the entire data transmission process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200827A_ABST
    Figure CN120200827A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent network security analysis method and system based on big data, relates to the technical field of data security, and solves the problems that whether a transmission terminal has tampered data is possibly in an agnostic state or not and private data in the transmission process is not encrypted. The data to be transmitted are confirmed, a verification data packet is confirmed from the data to be transmitted, each group of data in the verification data packet corresponds to different position parameters, follow-up transmission data are analyzed according to the corresponding position parameters, whether the position of specified data in the transmission data is changed or not is judged, and if the change condition exists, the data to be transmitted are sent to the data to be transmitted. If the virus data is not detected, it represents that the data has a tampering risk and the corresponding terminal has a certain risk, so that the virus data is easily implanted into the other terminal to cause data potential safety hazards.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and specifically to an intelligent network security analysis method and system based on big data. Background Art

[0002] Network security means that the hardware, software of the network system and the data in the system are protected and not damaged, changed or leaked due to accidental or malicious reasons, the system runs continuously, reliably and normally, and the network service is not interrupted; The application with the patent publication number CN114760124B discloses a computer network security intelligent analysis system and method based on big data. The intelligent analysis system includes an authentication database, an operation information monitoring module, a website judgment module and an access analysis module. The authentication database is used to store the website addresses of authenticated websites. The operation information monitoring module is used to monitor the operation information of the current user of the computer. When it detects that the current user opens a new website, the new website is obtained as the website to be detected, and the website address of the website to be detected is the website address to be detected. The website judgment module is used to judge whether the website address to be detected is the website address in the authentication database. If the website address to be detected is the website address in the authentication database, then the current user is allowed to directly access. If the website address to be detected is a website address other than the website addresses in the authentication database, the access analysis module obtains the characteristic information of the website to be detected and the historical operation information of the current user, and judges whether to send an access warning message accordingly.

[0003] Regarding network security, when normal data transmission is carried out, generally, corresponding firewalls are used for data protection without making other treatments, which easily leads to the theft of data by external personnel during data transmission. First, the transmission terminal is not analyzed, and it is unknown whether the transmission terminal has the possibility of tampering with data. Second, the private data during the transmission process is not encrypted, which easily leads to the theft of private data during the transmission process and causes data loss. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the present invention provides an intelligent network security analysis method and system based on big data, which solves the problems that it is unknown whether the transmission terminal has the possibility of tampering with data and the private data during the transmission process is not encrypted.

[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: An intelligent network security analysis system based on big data, including: A transmission protocol confirmation end, which confirms the transmission protocol between the terminals that need to perform data transmission, and transmits the confirmed transmission protocol to the protocol processing unit inside the security management center; The terminal data confirmation unit confirms the data to be transmitted between two terminals, calibrates the confirmed data as the data to be transmitted, and preferentially transmits the data to be transmitted into the protocol processing unit; The protocol processing unit processes the confirmed transmission protocol, selects the verification data from the data to be transmitted, merges the verification data, confirms the verification data packet, and bundles the verification data packet with the transmission protocol. The specific method is as follows: Divide the data to be transmitted into several paragraph data according to several paragraph symbols existing in the data to be transmitted; Then randomly extract a group of data streams from the paragraph data, record the specific position of this data stream, and mark the specific position as (H i , L i ), where H i represents the row number of this data stream in this paragraph data, L i represents the column number of this data stream in this paragraph data, and i represents different data streams. Hide the specific position (H i , L i ) into the corresponding data stream, hide H i at the front position of the corresponding data stream, hide L i at the back position of the corresponding data stream. After hiding, the specific manifestation form of the corresponding data stream is: H i data stream L i ; Arrange the several data streams after the hiding process in the sorting order of the paragraphs in turn to generate a verification data packet, bundle it with the transmission protocol, and hide the verification data packet into the transmission protocol; The data comparison unit extracts the verification data packet hidden in the transmission protocol, then extracts the transmitted transmission data, analyzes and verifies the transmission data, and judges whether there are security problems in the corresponding transmission terminal. The specific method is as follows: Confirm the transmitted transmission data and mark it as the data to be compared; Extract the verification data packet from the transmission protocol, and compare it with the corresponding paragraph according to the sorting order of the data streams in the verification data packet. According to the specific positions at the front and back ends, analyze and confirm whether there are the same data streams at the specified positions in the data to be compared. If the position information comparison is correct, it means that there is no problem with the transmission terminal. If the position information comparison is incorrect, an abnormal signal is generated and directly transmitted to the external display terminal for external operators to view; The transmission data confirmation unit confirms the network data to be transmitted. The network data includes public data and private data, and the private data has a corresponding private mark, and transmits the confirmed network data to the private data extraction unit; The private data extraction unit extracts private data from the confirmed network data. During the extraction process, it memorizes the positions of the specified private data and marks them within the specified private data. The specific method is as follows: Confirm the specific positions of the private data in the network data, set extraction marks at the specific positions, and at the same time, the extracted private data also carries the same extraction marks; Bundle the extracted private data to obtain a private data bundle, and transmit the private data bundle to the active encryption unit; The active encryption unit encrypts the private data bundle. By means of a set of encryption templates, the private data bundle is filled into the encryption templates. The specific method is as follows: Convert the private data bundle into source data, then split the source data so that the original source data is split into four groups of source data streams, and sort the four groups of source data streams according to the front and back data sorting; There are four groups of intervals set in the encryption templates, namely the first interval, the second interval, the third interval, and the fourth interval. The sorted source data streams are filled into the corresponding intervals in sequence. Among them, the first group of source data streams is filled into the first interval,..., and the fourth group of source data streams is filled into the fourth interval; After filling, the internal encryption program of the encryption template is started. According to the preset rotation period T (where T is a preset value), with the start moment as the initial time point, within the first rotation period T, the first interval,..., the fourth interval rotate and move in the clockwise direction. During the movement, the filled source data streams inside also move accordingly. Therefore, the first interval reaches the position of the second interval,..., and the fourth interval reaches the position of the first interval; Transmit the public data and the encrypted private data inside the network data.

[0006] Preferably, it further includes a storage unit for short-term storage of the verification data packets and the private data bundles during the transmission process.

[0007] Preferably, an intelligent network security analysis method based on big data. This security analysis method operates based on a network security analysis system and includes the following steps: Step 1: Confirm the transmission protocol between the terminals that need to perform data transmission, and then confirm the data to be transmitted that needs to be initially transmitted between the two terminals; Step 2: Process the confirmed transmission protocol, select verification data from the data to be transmitted, merge the verification data, confirm the verification data packet, and bundle the verification data packet with the transmission protocol; Step 3: Subsequently, during the transmission process, compare the transmitted data with the verification data packet to determine whether the transmitted data has been tampered with and take corresponding measures; Step 4: Confirm the network data transmitted between normal terminals, extract the internal private data, bundle it into a private data bundle, convert it into source data, decompose the source data into four groups of source data streams, and fill the four groups of source data streams into an encryption template for encryption; Step 5: Normally transmit the encrypted private data and public data. After the transmission is completed, integrate them to obtain the originally confirmed network data.

[0008] Beneficial effects The present invention provides an intelligent network security analysis method and system based on big data. Compared with the prior art, it has the following beneficial effects: The present invention conducts a security analysis on the terminals initially participating in the data parameters. First, confirm the transmission protocol, then confirm the data to be transmitted, and confirm the check data packet from the data to be transmitted. Each group of data in the check data packet corresponds to different position parameters. According to the corresponding position parameters, analyze the subsequent transmitted data to determine whether the position of the specified data in the transmitted data has changed. If there is a change, it means that this data has a risk of being tampered with, indicating that the corresponding terminal has a certain risk and is likely to implant virus data into another terminal, causing potential data security hazards; Subsequently, further process the network data during the transmission process, distinguish the public data and private data. After the distinction, encrypt the private data and encrypt the encryption template by means of periodic transformation. By using this encryption method, it is possible to fully prevent the encryption template from being stolen by external personnel, improve the encryption processing effect, avoid the leakage of private data, and enhance the security during the entire data transmission process. Description of the drawings

[0009] Figure 1 It is a schematic diagram of the principle framework of the present invention; Figure 2 It is a schematic diagram of the encryption template of the present invention. Specific embodiments

[0010] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0011] Embodiment 1 Please refer to Figure 1 , this application provides an intelligent network security analysis system based on big data, including a transmission protocol confirmation end and a security management center; The security management center includes three major modules. The first major module includes a protocol processing unit, a terminal data confirmation unit, and a data comparison unit. The second major module includes a transmitted data confirmation unit, a private data extraction unit, and an active encryption unit. The third major module is a storage unit; The terminal data confirmation unit, the protocol processing unit, and the data comparison unit are electrically connected in sequence. The transmitted data confirmation unit, the private data extraction unit, and the active encryption unit are electrically connected in sequence; The transmission protocol confirmation end confirms the transmission protocol between terminals that need to perform data transmission and transmits the confirmed transmission protocol to the protocol processing unit inside the security management center. Specifically, when two data terminals perform data transmission for the first time, they both need to confirm the corresponding transmission protocol. After the transmission protocol is confirmed, it is necessary to analyze whether there are problems with the transmitted data between the two data terminals; The terminal data confirmation unit confirms the data to be transmitted between the two terminals, labels the confirmed data as data to be transmitted, and preferentially transmits the data to be transmitted to the protocol processing unit; The protocol processing unit processes the confirmed transmission protocol, selects check data from the data to be transmitted, combines the check data, confirms the check data packet, and bundles the check data packet with the transmission protocol. Among them, the specific processing method is: According to several paragraph symbols existing in the data to be transmitted, the data to be transmitted is divided into several paragraph data; Then, a group of data streams is randomly extracted from the paragraph data, and the specific position of this data stream is recorded, and the specific position is marked as (H i , L i ), where H i represents which line of this paragraph data this data stream is located in, L i represents which column of this paragraph data this data stream is located in, and i represents different data streams. The specific position (H i , L i ) is hidden in the corresponding data stream. H i is hidden at the front end position of the corresponding data stream, and L i is hidden at the back end position of the corresponding data stream. The specific manifestation form of the corresponding data stream after hiding is: H i data stream L i ; Arrange the processed data streams in sequence according to the paragraph sorting method to generate a check data packet, bundle it with the transmission protocol, and hide the check data packet in the transmission protocol.

[0012] The data comparison unit extracts the verification data packets hidden in the transmission protocol, then extracts the transmitted data after transmission, analyzes and verifies the transmitted data, and determines whether there are security problems with the corresponding transmission terminals. Specifically, the transmitted data here may have some changes compared to the original data to be transmitted. Some terminals, in order to avoid verification by the security system, first give the best virus-free data. Subsequently, during the transmission process, virus data is implanted into the transmitted data, and then transmitted, effectively implanting the virus data into another terminal to achieve the effect of intrusion. Among them, the specific method for determination is as follows: Confirm the transmitted data after transmission and mark it as the data to be compared; Extract the verification data packets from the transmission protocol, and compare them with the corresponding paragraphs according to the sorting method of the data stream in the verification data packets. According to the specific positions of the front and back ends, analyze and confirm whether there are the same data streams at the specified positions in the data to be compared. If the position information comparison is correct, it means that there is no problem with the transmission terminal. If the position information comparison is incorrect, an abnormal signal is generated and directly transmitted to the external display terminal for external operators to view.

[0013] Specifically, when there is an error in the comparison result, it means that the corresponding terminal has a risk and may carry attack data to tamper with the transmitted data. Therefore, external personnel need to intervene to see whether to block the corresponding terminal or take other countermeasures.

[0014] Embodiment 2 Based on the above embodiment, in the specific implementation process of this embodiment, it is carried out based on the premise that the transmission terminal is problem-free, and this embodiment is implemented for the encryption method of network data to be transmitted, and further includes: The transmitted data confirmation unit confirms the network data to be transmitted. The network data includes public data and private data, and the private data has a corresponding private mark. The private mark is formulated in advance by the operator, and the confirmed network data is transmitted to the private data extraction unit; The private data extraction unit extracts the private data from the confirmed network data, and during the extraction process, remembers the positions of the specified private data, marks them in the specified private data, bundles several processed private data, and transmits them to the active encryption unit for encryption processing. Among them, the specific method for processing the private data is as follows: Identify the specific location of the private data from the network data and set an extraction mark at the specific location. At the same time, the extracted private data also carries the same extraction mark. Specifically, in order to facilitate filling the private data back into the network data later, according to the corresponding extraction mark, the corresponding private data can be directly filled into the specific location; Bundle the extracted private data to obtain a private data bundle, and transmit the private data bundle to the active encryption unit.

[0015] The active encryption unit encrypts the private data bundle. Through a set of encryption templates, as Figure 2 shown, fill the private data bundle into the encryption template to complete the encryption process of the private data bundle. Among them, the specific method of encryption is: Convert the private data bundle into source data, and then split the source data so that the original source data is split into four groups of source data streams, and sort the four groups of source data streams according to the front and back data sorting; There are four groups of intervals set in the encryption template, namely the first interval, the second interval, the third interval, and the fourth interval. Fill the sorted source data streams into the corresponding intervals in turn. The first group of source data streams is filled into the first interval,..., and the fourth group of source data streams is filled into the fourth interval; After filling, the internal encryption program of the encryption template is started. According to the predetermined rotation period T, where T is a preset value, with the start time as the initial time point, within the first rotation period T, the first interval,..., the fourth interval rotate clockwise, and the filled source data streams inside also move accordingly. Therefore, the first interval reaches the position of the second interval,..., and the fourth interval reaches the position of the first interval; Transmit the public data and the encrypted private data inside the network data. Specifically, first, when the corresponding terminal confirms no problem, during the transmission of the corresponding network data, there is also a risk of being attacked, which can easily lead to data being stolen. Using this method to encrypt the private data, when the data is stolen, it is difficult for external personnel to find a cracking method to display the private data. This method is to ensure the security of the private data during transmission and prevent the private data from being stolen by external personnel during transmission, resulting in data loss.

[0016] It also includes the integration process of the public data and the private data after the data transmission is completed, which is as follows: According to the interval of the transmission time and the specific duration of the rotation period T, determine how many periods have passed for the transmission time, then confirm the location of the first interval within the encryption template. In the clockwise sorting manner, sequentially extract the source data streams within the subsequent intervals, integrate them into source data, and then convert the source data to obtain a private data bundle; According to the extraction marks within the private data bundle, sequentially fill the private data at the corresponding positions into the specified positions of the public data to obtain the original network data, thus completing the entire decryption process.

[0017] It further includes a storage unit; used for short-term storage of the verification data packets and the private data bundles during the transmission process to avoid data loss.

[0018] Embodiment III An intelligent network security analysis method based on big data includes the following steps: Step 1: Confirm the transmission protocol between the terminals before data transmission, and then confirm the data to be transmitted that needs to be initially transmitted between the two terminals; Step 2: Process the confirmed transmission protocol, select verification data from the data to be transmitted, merge the verification data, confirm the verification data packet, and bundle the verification data packet with the transmission protocol; Step 3: Subsequently, during the transmission process, check the transmitted data against the verification data packet, determine whether the transmitted data has been tampered with, and take corresponding measures; Step 4: Confirm the network data transmitted between normal terminals, extract the private data inside, bundle it into a private data bundle, convert it into source data, decompose the source data into four groups of source data streams, and fill the four groups of source data streams into the encryption template for encryption; Step 5: Normally transmit the encrypted private data and the public data. After the transmission is completed, integrate them to obtain the originally confirmed network data.

[0019] Embodiment IV In the specific implementation process of this embodiment, it includes all the implementation processes of the above embodiments.

[0020] Some of the data in the above formulas are numerically calculated after removing their dimensions, and the content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.

[0021] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. An intelligent network security analysis system based on big data, characterized in that: include: The transmission protocol confirmation terminal confirms the transmission protocol of the terminals that need to transmit data, and transmits the confirmed transmission protocol to the protocol processing unit in the security management center; The terminal data confirmation unit confirms the data to be transmitted between the two terminals, marks the confirmed data as data to be transmitted, and transmits the data to be transmitted to the protocol processing unit in priority; The protocol processing unit processes the confirmed transmission protocol, selects verification data from the data to be transmitted, merges the verification data, confirms the verification data packet, and bundles the verification data packet with the transmission protocol; The data comparison unit extracts the verification data packet hidden in the transmission protocol, then extracts the transmission data after the transmission is completed, analyzes and verifies the transmission data, and determines whether there is a security problem in the corresponding transmission terminal; The transmission data confirmation unit confirms the network data to be transmitted, and the network data includes public data and private data, and the private data has a corresponding privacy mark, and transmits the confirmed network data to the private data extraction unit; The private data extraction unit extracts the private data from the confirmed network data, memorizes the location of the designated private data during the extraction process, marks the designated private data, bundles the processed private data, and transmits them to the active encryption unit for encryption processing; The active encryption unit encrypts the private data bundle and fills the private data bundle into the encryption template through a set of encryption templates to complete the encryption processing of the private data bundle.

2. According to the big data-based intelligent network security analysis system of claim 1, it is characterized in that: The specific method of processing by the protocol processing unit is as follows: According to a number of paragraph symbols existing in the data to be transmitted, the data to be transmitted is divided into a number of paragraph data; Then randomly extract a set of data streams from the paragraph data, record the specific position of this data stream, and mark the specific position as (H i , L i ), where H i Indicates the row number of this data stream in this paragraph data, L i Indicates the column number of this data stream in this paragraph, and i represents different data streams. i , L i ) is hidden in the corresponding data stream, and H i Hide to the front end of the corresponding data stream and change L i Hide to the back end of the corresponding data stream. The specific form of the corresponding data stream after hiding is: H i Data Flow L i ; Arrange the hidden processed data streams in sequence according to the paragraph sorting method to generate a verification data packet, which is bundled with the transmission protocol and the verification data packet is hidden in the transmission protocol.

3. According to claim 2, the intelligent network security analysis system based on big data is characterized in that: The specific method of the data comparison unit to determine whether the corresponding transmission terminal has a security problem is: Confirm the transmitted data after the transmission is completed and mark it as data to be compared; The verification data packet is extracted from the transmission protocol, and compared with the corresponding paragraph according to the sorting method of the data stream in the verification data packet. According to the specific positions of the front and back ends, it is analyzed and confirmed whether there is an identical data stream at the specified position of the data to be compared. If the position information is compared correctly, it means that there is no problem with the transmission terminal. If the position information is compared incorrectly, an abnormal signal is generated and directly transmitted to the external display terminal for external operators to view.

4. According to the intelligent network security analysis system based on big data as claimed in claim 1, it is characterized in that: The specific method of processing the private data by the private data extraction unit is as follows: Confirm the specific location of the private data from the network data and set an extraction mark at the specific location. At the same time, the extracted private data also carries the same extraction mark; The extracted private data is bundled to obtain a private data bundle package, and the private data bundle package is transmitted to the active encryption unit.

5. The intelligent network security analysis system based on big data according to claim 4 is characterized in that: The specific method of the active encryption unit to encrypt the private data bundle is as follows: Convert the private data bundle into source data, and then segment the source data so that the original source data is segmented into four groups of source data streams, and sort the four groups of source data streams according to the order of the previous and next data; Four groups of intervals are set in the encryption template, namely, a first interval, a second interval, a third interval, and a fourth interval. The sorted source data streams are filled into the corresponding intervals in sequence, wherein the first group of source data streams are filled into the first interval, ..., and the fourth group of source data streams are filled into the fourth interval; After the filling is completed, the encryption program inside the encryption template is started. According to the proposed rotation period T, where T is a preset value and the start time is taken as the initial time point, within the first group of rotation periods T, the first interval, ..., the fourth interval, rotate and move in a clockwise direction. During the movement, the filled source data stream inside also moves along, so the first interval reaches the position of the second interval, ..., the fourth interval reaches the position of the first interval; Transmit public data within the network as well as encrypted private data.

6. The intelligent network security analysis system based on big data according to claim 1 is characterized in that: It also includes a storage unit for storing the verification data packet and the private data bundle during the transmission process for a short period of time.

7. An intelligent network security analysis method based on big data, which is operated based on the network security analysis system according to any one of claims 1 to 6, characterized in that: The following steps are involved: Step 1: confirm the transmission protocol of the terminals that need to transmit data, and then confirm the data to be transmitted that needs to be initially transmitted between the two terminals; Step 2: Process the confirmed transmission protocol, select verification data from the data to be transmitted, merge the verification data, confirm the verification data packet, and bundle the verification data packet with the transmission protocol; Step 3: Subsequently, the transmitted data is checked against the verification data packet during the transmission process to determine whether the transmitted data has been tampered with and to take countermeasures; Step 4: confirm the network data transmitted between normal terminals, extract the private data inside, bundle it into a private data bundle, convert it into source data, decompose the source data into four groups of source data streams, and fill the four groups of source data streams into the encryption template for encryption; Step 5: Transmit the encrypted private data and public data normally. After the transmission is completed, integrate them to obtain the original confirmed network data.

Citation Information

Patent Citations

  • A Big Data-Based Intelligent Analysis System and Method for Computer Network Security

    CN114760124B

  • Data security transmission system based on cloud computing

    CN116527382A

  • Network security monitoring system based on mobile computer

    CN117220935A

  • Computer network security analysis system and method based on big data

    WO2024120111A2