Multi-layer protection method and system for high-performance industrial switch

Through multi-layer protection methods, including topological analysis, triple packaging, cross-layer security policy groups, multi-head security monitors and variational inference models, the security blind spots and performance problems of industrial switches under complex attacks are solved, and efficient security protection and real-time data transmission are achieved.

CN120200845AInactive Publication Date: 2025-06-24SHENZHEN HONGRUI OPTICAL TECH CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510595937.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Industrial switches have security blind spots when facing complex attacks, and existing protection technologies are difficult to maintain network performance under high security levels, which cannot meet the dual needs of high-performance industrial switches for real-time data transmission and security protection.

Method used

A multi-layer protection method is adopted to generate a security topology matrix and industrial data flow vector through topology analysis, perform triple encapsulation, build a cross-layer associated three-layer security policy group, deploy multi-head security monitors for parallel threat detection and SM3 algorithm integrity verification, and jointly iterative optimization of transmission efficiency and security strength through variational inference model.

Benefits of technology

It significantly improves protection depth and system resilience, eliminates security blind spots, ensures that high-performance industrial switches provide strong security guarantees while maintaining strict real-time performance requirements, and solves the problem of difficulty in taking into account both safety and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200845A_ABST
    Figure CN120200845A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial switches, and discloses a multi-layer protection method and system for a high-performance industrial switch. The method comprises the following steps: carrying out topology analysis on an industrial network to obtain a security topology matrix and an industrial data flow vector; executing triple encapsulation to obtain a security encapsulation data packet; constructing a cross-layer associated three-layer security policy group; based on the three-layer security policy group, deploying a multi-head security monitor to implement parallel threat detection and SM3 algorithm integrity verification, and generating security decision information and an integrity verification result; and inputting the security decision information and the integrity verification result into the variational inference model to execute joint iterative optimization of transmission efficiency and security intensity to obtain an optimal protection parameter, so that cooperative work of different network layer protection strategies is realized, the overall protection effect is improved, continuously changing security challenges in an industrial network can be effectively dealt with, and the safety of the industrial network is improved. And the limitation of a traditional static protection method is broken through.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial switches, and in particular, to a multi-layer protection method and system for a high-performance industrial switch. Background Art

[0002] Different from traditional enterprise networks, industrial network environments have characteristics such as high real-time requirements, diverse protocols, and heterogeneous data types, making high-performance industrial switches face more severe security challenges. Especially in industrial scenarios with high bandwidth, low latency, and high concurrency, industrial switches need to simultaneously process various industrial protocol data from devices such as PLCs, sensors, and actuators, and this data is often directly related to production safety and the core interests of enterprises.

[0003] However, the current protection technologies of industrial switches generally have problems such as single protection level and difficulty in balancing security and performance. Traditional protection methods usually only implement security measures for a single network layer and lack a cross-layer cooperation mechanism, resulting in security blind spots when facing complex attacks. Especially in the trend of OT and IT network convergence, industrial networks face more diverse security threats, and existing protection technologies either sacrifice real-time performance for security or seriously affect network performance at high security levels, and cannot meet the dual requirements of high-performance industrial switches for real-time data transmission and security protection. Summary of the Invention

[0004] The present invention provides a multi-layer protection method and system for a high-performance industrial switch. The present invention realizes the collaborative work of protection strategies at different network layers, improves the overall protection effect, can effectively cope with the changing security challenges in industrial networks, and breaks through the limitations of traditional static protection methods.

[0005] In a first aspect, the present invention provides a multi-layer protection method for a high-performance industrial switch. The multi-layer protection method for the high-performance industrial switch includes: Performing topology analysis on an industrial network to obtain a security topology matrix and an industrial data flow vector; Performing triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a security encapsulated data packet; Constructing a three-layer security policy group with cross-layer association according to the security header information of the security encapsulated data packet; Based on the three-layer security policy group, deploying a multi-head security monitor to perform parallel threat detection and SM3 algorithm integrity verification, and generating security decision information and an integrity verification result; Inputting the security decision information and the integrity verification result into a variational inference model to perform joint iterative optimization of transmission efficiency and security strength, and obtaining optimal protection parameters.

[0006] In a second aspect, the present invention provides a multi-layer protection system for a high-performance industrial switch, and the multi-layer protection system for the high-performance industrial switch includes: A topology analysis module for performing topology analysis on an industrial network to obtain a security topology matrix and an industrial data flow vector; A triple encapsulation module for performing triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a secure encapsulated data packet; A construction module for constructing a three-layer security policy group with cross-layer association according to the security header information of the secure encapsulated data packet; A verification module for deploying a multi-head security monitor to perform parallel threat detection and SM3 algorithm integrity verification based on the three-layer security policy group, and generating security decision information and an integrity verification result; A joint iterative optimization module for inputting the security decision information and the integrity verification result into a variational inference model to perform joint iterative optimization of transmission efficiency and security strength, and obtaining optimal protection parameters.

[0007] In the technical solution provided by the present invention, by constructing an edge-core hierarchical protection architecture and implementing a three-layer security policy group from the data link layer, network layer to transport layer, a complete protection system is formed. Compared with single-layer protection, this method can eliminate security blind spots. Even if a certain layer of protection is breached, other layers can still provide protection, significantly enhancing the protection depth and system resilience. By deploying a multi-channel parallel security processing unit at the edge node, through protocol parsing, anomaly detection, and triple encapsulation, efficient security processing in a resource-constrained environment is achieved. A lightweight variational autoencoder is used for anomaly detection to intercept a large amount of malicious data at the edge, reducing the burden on the core network and minimizing the impact of security protection on network performance. A three-layer security policy group with cross-layer association is constructed based on a multi-layer protocol state association matrix, solving the problem in traditional methods where each protection layer operates independently and lacks coordination. Through a two-way verification mechanism and dynamic weight adjustment, the collaborative operation of protection strategies at different network layers is realized, enhancing the overall protection effect. Multi-head security monitors for different threat types are deployed, and the monitoring results are integrated through an attention mechanism to comprehensively capture local and global threats. Compared with single monitoring methods, this method can identify multiple attack patterns simultaneously, significantly reducing the false alarm rate and missed alarm rate and improving the accuracy of threat detection. The variational inference principle is used to jointly iteratively optimize the transmission efficiency and security strength to find a balance between them. According to the optimization results, parameters such as encryption strength, authentication algorithm, and data verification mechanism are dynamically adjusted to ensure that the high-performance industrial switch can maintain strict real-time performance requirements while providing strong security guarantees, solving the problem in traditional methods where it is difficult to balance security and performance. Through virtual security domain division and deep reinforcement learning control, the protection system is endowed with adaptive learning ability. The system can dynamically adjust protection strategies according to network state changes and the emergence of new threats, and even reconstruct virtual security domains, realizing the continuous evolution of the protection system and effectively coping with the ever-changing security challenges in industrial networks, breaking through the limitations of traditional static protection methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0009] Figure 1 It is a schematic flowchart of a multi-layer protection method for a high-performance industrial switch provided by an embodiment of the present application; Figure 2 It is a schematic block diagram of the structure of a multi-layer protection system for a high-performance industrial switch provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0010] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0011] The flowchart shown in the accompanying drawings is only an example illustration, and does not necessarily include all contents and operations / steps, nor does it necessarily need to be executed in the described order. For example, some operations / steps can also be decomposed, combined, or partially merged. Therefore, the actual execution order may change based on the actual situation.

[0012] It should also be understood that the terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. As used in the specification of this application and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.

[0013] It should be further understood that the term "and / or" used in the specification of this application and the appended claims refers to any combination and all possible combinations of one or more of the related listed items, and includes these combinations.

[0014] The following will describe in detail some embodiments of this application with reference to the accompanying drawings. Without conflict, the features in the following embodiments and the embodiments can be combined with each other.

[0015] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of the multi-layer protection method for a high-performance industrial switch provided by an embodiment of this application. As Figure 1 shown, the multi-layer protection method for a high-performance industrial switch provided by an embodiment of this application includes steps S100 to step S600.

[0016] Step S100: Perform a topology analysis on the industrial network to obtain a security topology matrix and an industrial data flow vector; It can be understood that the execution subject of the present invention can be a multi-layer protection system for a high-performance industrial switch, or a terminal or a server. Specifically, it is not limited here. An embodiment of the present invention will be described by taking the server as the execution subject as an example.

[0017] Specifically, all nodes and links in the industrial network are automatically detected and identified. This process relies on the network scanning module to obtain the basic information of all nodes in the industrial network by combining active detection and passive detection methods, identify the communication relationships between nodes, generate a node set and a link set, form a first network topology map, and reflect the overall layout of nodes and links in the industrial network. The nodes in the network are classified and marked according to the computing power, network location, and data flow characteristics carried by each node, and these nodes are divided into an edge node set and a core node set. Among them, the edge nodes are located on the outer layer of the industrial network and process data flows from devices such as sensors, PLCs, and actuators, requiring high concurrent processing capabilities and low-latency response capabilities. The core nodes are located at the center of the network, undertaking a large number of data forwarding and protocol conversion tasks, and having higher computing and data processing capabilities. After completing the node classification, for each link in the network topology map, bandwidth capacity measurement, current load monitoring, and security risk assessment are performed to obtain a link status parameter data set. Bandwidth capacity measurement is used to determine the maximum amount of data that a link can carry, current load monitoring reflects the real-time communication load status of the link, and security risk assessment is used to evaluate the potential security threats of the link in a specific communication environment. At the same time, the data transmitted in the industrial network is analyzed. By parsing the original information of the data flow, the source address and target address of the data are extracted, and the data type is identified, the priority is determined, and the corresponding security level is assigned. After analysis and processing, an industrial data flow vector is formed, which records the key information of each data flow in the network. Based on the link status parameter data set, the communication security cost between nodes is comprehensively calculated and matrixed to generate a security topology matrix, which reflects the security cost of the communication path between nodes, including multi-dimensional factors such as link bandwidth usage, load status, and security risk level.

[0018] Step S200: Perform triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a securely encapsulated data packet; Specifically, according to the security communication cost of nodes in the security topology matrix and the information of data protocol types in the industrial data flow vector, a multi-channel parallel security processing unit is deployed on the nodes in the edge node set. The security processing unit shunts different types of industrial data through a multi-channel architecture, and each channel is responsible for parsing industrial protocol data of a specific type, so as to ensure the efficient parsing and processing of multiple protocol data streams in a complex industrial network environment. The industrial data flow entering the multi-channel parallel security processing unit is parsed for industrial protocols through a decision tree structure. The decision tree consists of a series of protocol field judgment nodes, and each node makes a branch decision according to the protocol field characteristics in the data packet until a complete protocol feature vector is formed. The protocol feature vector can accurately describe the protocol structure, field information and key parameters of the data packet, providing basic data for subsequent anomaly detection. The generated protocol feature vector is input into a lightweight variational autoencoder in the multi-channel parallel security processing unit for anomaly detection processing. The variational autoencoder establishes the normal mode of the data by learning the feature distribution of the normal industrial data flow. For the input protocol feature vector, if the reconstruction error exceeds the preset threshold, the data is determined to be abnormal, otherwise it is regarded as normal data. The results of anomaly detection are used to distinguish normal data streams from abnormal data streams. For the industrial data stream determined to be normal, a first-level encapsulation process is performed, and the Huffman coding algorithm is used to perform lightweight compression on the data. The Huffman coding represents the frequently occurring data features with shorter codes by constructing an optimal prefix tree, thereby greatly compressing the data volume and reducing the computational pressure of subsequent encryption processing. The compressed data enters the second-level encapsulation stage, and in this stage, the SM4 block cipher algorithm is used to encrypt the lightweight compressed data. The SM4 algorithm is a symmetric encryption algorithm that uses a 128-bit key and a 128-bit block for data encryption. The encrypted data can effectively resist the risks of data theft and tampering in the industrial environment, thereby enhancing the security of data transmission. After the encrypted data is generated, it enters the third-level encapsulation stage, and the SM3 cryptographic hash algorithm is used to calculate the digital signature of the encrypted data. The SM3 algorithm is a cryptographic hash algorithm with high security, which converts data of any length into a fixed-length 256-bit digest information. This digest information is used to verify the integrity of the data and the authenticity of the source. The encrypted data, digital signature, and a security header containing the source address, destination address, priority, and timestamp are combined for the third-level encapsulation process to form a secure encapsulated data packet.

[0019] Step S300: Construct a three-layer security policy group with cross-layer association according to the security header information of the secure encapsulated data packet; Specifically, the correlation between network protocol states and the data link layer, network layer, and transport layer is processed through matrix mapping to generate a multi-layer protocol state correlation matrix. This matrix is used to reflect the correlation strength between different network layers and various industrial protocol states and provides a mapping basis for the subsequent construction of security policy groups. Through matrix processing, the correlation between protocols at each layer is captured, and the inter-layer policy weights are dynamically adjusted according to the characteristics of different data flows to achieve the effect of cross-layer collaborative protection. Extract security header information from the secure encapsulated data packets, including key fields such as source address, destination address, priority, data type, and timestamp, and conduct comprehensive analysis in combination with network state parameters such as network congestion degree, error rate, and threat level to generate a security context vector, which reflects the security situation in the current network environment. By real-time sensing the dynamic characteristics of network traffic, the security policy can be adaptively adjusted and optimized according to the changing network state. Based on this security context vector, a security policy group is formulated for the data link layer, including a MAC address filtering list, a port isolation matrix, and VLAN segmentation rules. The MAC address filtering list initially filters abnormal data packets by matching the physical addresses of legitimate devices, while the port isolation matrix prevents unauthorized devices from communicating illegally through network ports. The VLAN segmentation rules logically segment the network according to the service attributes of the data flow to improve the isolation and security of network data. While formulating the security policy group for the data link layer, a security policy group is formulated for the network layer based on the security context vector, including an IP address filtering list, a routing control table, and an access control list. Among them, the IP address filtering list intercepts unauthorized data flows by screening legitimate IP addresses. The routing control table is used to dynamically adjust the forwarding path of data packets to reduce potential network security risks, while the access control list manages access to specific resources by setting access permissions, thus effectively preventing illegal access behaviors. For the transport layer, a security policy group is formulated based on the security context vector, including a port filtering list, a session control policy, and traffic shaping parameters. The port filtering list prevents potential port scanning and intrusion behaviors by restricting access permissions to specific ports. The session control policy dynamically manages the persistence of data flow sessions to ensure the normal operation of legitimate sessions and at the same time blocks the continuous connection of abnormal sessions. The traffic shaping parameters dynamically adjust bandwidth resources according to the priorities of different data flows to achieve bandwidth optimization and load balancing during data transmission. Perform two-way verification and association processing on the security policy groups of the data link layer, network layer, and transport layer according to the multi-layer protocol state correlation matrix. Through the mutual verification and association analysis of security policies at each layer, it is ensured that when the protection policy of a certain layer fails, other layers can still provide supplementary protection, thereby enhancing the overall security of the system. To improve the execution efficiency of the security policy, calculate the policy weight distribution for each layer according to the security context vector and dynamically adjust the resource allocation of the three-layer security policy groups.Through weight calculation, the protection resources are preferentially allocated to the most vulnerable layer according to different network states, realizing the adaptive optimization of security policies, and finally obtaining a three-layer security policy group with cross-layer association.

[0020] Step S400: Based on the three-layer security policy group, deploy a multi-headed security monitor to implement parallel threat detection and SM3 algorithm integrity verification, and generate security decision information and integrity verification results. Specifically, deploy a multi-headed security monitor on the core node based on the three-layer security policy group. This monitor contains multiple monitoring heads running in parallel. Each monitoring head consists of a feature extractor, a threat analyzer, and a response generator. Different monitoring heads perform real-time analysis and protection against different types of security threats, such as security risks like DDoS attacks, ARP spoofing, malicious scanning, and abnormal traffic, and perform real-time detection and response control on various industrial data streams. Use each feature extractor in the multi-headed security monitor to extract features from the data stream. The feature extractor adopts a sliding window mechanism to capture temporal features from the data stream and generate a temporal feature vector, which reflects the traffic fluctuations, protocol field changes, and access pattern features of the data stream at different time periods. Input the generated temporal feature vector into the threat analyzer for threat assessment. The threat analyzer adopts an improved long short-term memory network structure, which captures the long-term dependencies of the data stream and determines the security of the current data stream by learning the feature differences between normal traffic and abnormal traffic. The result output by the threat analyzer is a threat probability vector, which contains the occurrence probabilities of different threat types and provides a decision basis for subsequent protection responses. According to the threat probability vector, the response generator in the multi-headed security monitor selects the optimal protection response from five strategies: allowing, logging, alerting, blocking, and redirecting according to the current network state and threat level, and generates a preliminary protection response. The preliminary protection response includes specific security operations, and also involves dynamic adjustment of the data stream processing path and enhanced control of security policies, providing flexible protection capabilities for the core node. The preliminary protection responses of all monitoring heads are subjected to correlation analysis and priority judgment through integrated calculation to generate the final security decision information. On the basis of generating the security decision information, integrity verification is performed in combination with the digital signature in the security encapsulated data packet. This process uses the SM3 algorithm to perform a hashing operation on the encrypted data and compares the calculated digest with the digital signature in the data packet to verify whether the data packet has been tampered with or illegally modified during transmission. If the verification result of the SM3 algorithm indicates that the integrity of the data packet has not been damaged, the generated integrity verification result will further confirm the legitimacy of the current data packet, allow it to pass through the core node and continue data transmission; otherwise, if the verification fails, an exception handling mechanism will be triggered to prevent abnormal data packets from entering the core network and send a security alert to the management center.

[0021] Step S500: Input the security decision information and the integrity verification result into the variational inference model to perform joint iterative optimization of transmission efficiency and security strength, and obtain the optimal protection parameters.

[0022] Specifically, input the security decision information and the integrity verification result as input parameters into the variational inference model. The security decision information includes threat type, threat level, and protection actions, which can accurately reflect the security threat status in the current network environment and the system's response strategy. At the same time, the integrity verification result provides the data integrity status and privacy protection requirements. By comprehensively analyzing these input parameters, the variational inference model generates an initial security state assessment result, which reflects the security situation in the current network environment and reveals potential security risks under different protection strategies. Based on the initial security state assessment result, combined with the current key transmission performance indicators of the high-performance industrial switch, such as data transmission delay, throughput, and packet loss rate, establish a trade-off relationship between transmission efficiency and security strength, and form an optimization objective. The core of this optimization objective is to balance the real-time nature of data transmission and the security of system protection. In a high-load, low-latency industrial network environment, ensure that the security protection strategy will not significantly reduce the data transmission efficiency, while ensuring that the protection strategy can resist potential security threats. By comprehensively considering performance factors such as transmission delay, throughput, and packet loss rate, as well as the assessment result of the current security state, form a dynamic optimization objective. After determining the optimization objective, set the initial parameter configuration of the variational inference model based on this objective, including initial encryption strength, initial authentication algorithm selection, initial data verification mechanism, initial buffering strategy, and initial congestion control parameters. These parameters jointly determine the protection strength and transmission performance of the high-performance industrial switch under different security strategies. The variational inference model takes these initial parameters as the starting point for optimization and performs parameter optimization through iterative update operations. In each iteration, the model calculates the transmission efficiency and security strength based on the current parameter configuration and fine-tunes the current parameters to gradually approach the optimal solution. As the number of iterations increases, the model comprehensively evaluates the changes in transmission efficiency and security strength during the process of continuously adjusting parameters such as encryption strength, authentication algorithm, and data verification mechanism, so as to dynamically optimize the parameter configuration and ensure the best protection state under different network conditions. During the iterative process, conduct an industrial network environment adaptability assessment for each updated parameter configuration. This assessment process matches the current parameter configuration with the actual industrial communication requirements and analyzes its impact on data transmission delay, throughput, and security protection, so as to screen out a candidate parameter set that meets the industrial communication requirements. Through multiple rounds of adaptability assessment, screen out the parameter combination that meets the best balance point of transmission efficiency and security strength from the candidate parameter set and use it as the final optimal protection parameter.

[0023] Cluster analysis is performed on the security topology matrix based on optimal protection parameters. The improved K-medoids algorithm is used to calculate the security similarity of network nodes. According to the security characteristics, communication cost, and link load of nodes, the network is divided into multiple virtual security domains. Each virtual security domain consists of a node set, a link set, and a security policy set. The node set defines the communication devices within the security domain. The link set reflects the data transmission paths between nodes within the security domain. The security policy set contains various protection policies configured to ensure the security of data flows within the security domain. The security similarity of nodes within each pair of virtual security domains is calculated to obtain the intra-domain node security similarity matrix. This matrix provides a data basis for the generation of subsequent adaptive protection strategies by quantifying the similarity of security features between different nodes. Based on the intra-domain node security similarity matrix, a state space including network status, threat level, and resource occupancy, and an action space including protection policy adjustment instructions are constructed. The state space comprehensively describes the security situation and communication status of the current network, while the action space defines the set of protection policy adjustment instructions in different situations. Based on the state space and action space, a reward function including security score, performance score, and resource cost is established to evaluate the impact of the current protection policy on network security and communication performance, providing guidance for the optimization of the deep reinforcement learning controller. In each virtual security domain, a deep reinforcement learning controller based on the double deep Q-network (DDQN) structure is deployed. This controller works in coordination with a policy network and a target network to dynamically adjust the configuration of security policies and achieve adaptive protection of the network environment. The DDQN structure includes an input layer, a hidden layer, and an output layer. It samples batch data from the experience pool through an experience replay mechanism for learning, continuously updating the weights of the policy network and the target network to generate adaptive protection policies that can adapt to different network environments. Based on the generated adaptive protection policies, the boundaries and protection configurations of each virtual security domain are periodically evaluated and dynamically adjusted to ensure that the protection policies can still maintain an optimal state when the network topology changes or security threats increase. The protection configuration of the virtual security domain is re-evaluated at a set time interval, and the security domain boundaries and policy configurations are dynamically adjusted according to the changes in the current network environment to ensure that each security domain can continuously maintain an efficient protection ability. When a new threat type is detected or a major change occurs in the network topology, a security domain reconstruction mechanism is triggered. By re-dividing the virtual security domains and adjusting the protection policies at each layer, the dynamic evolution of the multi-layer protection system is achieved.

[0024] In the embodiments of the present invention, by constructing an edge-core hierarchical protection architecture and implementing three-layer security policy groups from the data link layer, network layer to transport layer, a complete protection system is formed. Compared with single-layer protection, this method can eliminate security blind spots. Even if a certain layer of protection is breached, other layers can still provide protection, significantly improving the protection depth and system resilience. Deploying multi-channel parallel security processing units at edge nodes, through protocol parsing, anomaly detection, and triple encapsulation, efficient security processing in resource-constrained environments is achieved. Using lightweight variational autoencoders for anomaly detection, a large amount of malicious data is intercepted at the edge, reducing the burden on the core network and the impact of security protection on network performance. Based on a multi-layer protocol state association matrix, a cross-layer associated three-layer security policy group is constructed, solving the problem in traditional methods where each protection layer operates independently and lacks coordination. Through a two-way verification mechanism and dynamic weight adjustment, the collaborative work of protection strategies for different network layers is achieved, improving the overall protection effect. Deploying multi-headed security monitors for different threat types and integrating monitoring results through an attention mechanism, comprehensive capture of local and global threats is achieved. Compared with single monitoring methods, this method can identify multiple attack patterns simultaneously, significantly reducing the false alarm rate and missed alarm rate, and improving the accuracy of threat detection. Using the principle of variational inference to jointly iteratively optimize the transmission efficiency and security strength, finding the balance point between the two. Dynamically adjusting parameters such as encryption strength, authentication algorithms, and data verification mechanisms according to the optimization results ensures that high-performance industrial switches can still maintain strict real-time performance requirements while providing strong security guarantees, solving the problem in traditional methods where it is difficult to balance security and performance. Through virtual security domain partitioning and deep reinforcement learning control, the protection system is given the ability to adaptively learn. The system can dynamically adjust protection strategies according to network state changes and the emergence of new threats, and even reconstruct virtual security domains, realizing the continuous evolution of the protection system, effectively coping with the ever-changing security challenges in industrial networks, and breaking through the limitations of traditional static protection methods.

[0025] In a specific embodiment, the process of executing step S100 may specifically include the following steps: Automatically detect and identify all nodes and links in the industrial network to obtain a first network topology map including a node set and a link set; Classify and label the nodes in the first network topology map according to the computing power index, network location, and data flow characteristics carried by each node to obtain an edge node set and a core node set; According to the edge node set and the core node set, measure the bandwidth capacity, monitor the current load, and evaluate the security risk of each link in the network topology map to obtain a link state parameter data set; Extract the source address, identify the destination address, classify the data type, determine the priority, and assign the security level to the data transmitted in the industrial network to obtain the industrial data stream vector; Based on the link state parameter data set, comprehensively calculate and matrix process the communication security cost between nodes to obtain the security topology matrix.

[0026] Specifically, all nodes and links in the industrial network are automatically detected and identified. Relying on the automated scanning function of the network scanning module, node information and link status in the network are obtained through a combination of active detection and passive detection. Active detection sends detection requests to network nodes via ICMP (Internet Control Message Protocol) and SNMP (Simple Network Management Protocol), and extracts key information such as the IP address, MAC address, and device type of the nodes from the response data of the nodes. Passive detection, on the other hand, performs traffic analysis by capturing data traffic in the network, identifies hidden nodes and link status in the network, and constructs the logical association relationship between nodes and links in combination with the packet header information, forming a first network topology map containing a node set and a link set. In this topology map, the node set represents all detectable communication devices in the network, including devices such as PLCs (Programmable Logic Controllers), sensors, actuators, and control systems, while the link set reflects the communication paths between nodes and their transmission characteristics. The nodes in the first network topology map are classified and marked according to the computing power index, network location, and data stream characteristics of each node, and the nodes are divided into an edge node set and a core node set. Edge nodes are located at the periphery of the industrial network and are responsible for data interaction with sensors, PLCs, and industrial actuators. The characteristics of the data traffic are mainly periodic data collection and status feedback, with the characteristics of high concurrency and low latency. Therefore, the computing power of edge nodes is usually weak, but the requirement for real-time performance is extremely high. Core nodes, on the other hand, are located at the center of the network and undertake tasks such as data aggregation, routing, and protocol conversion for a large amount of data. They need to have strong data processing capabilities and network resource management capabilities. Therefore, core nodes have higher computing power, and the data traffic they carry is mostly cross-regional data interaction and status control traffic. During the classification and marking process, the CPU processing power, memory capacity, network location, and characteristics of historical data streams of each node are comprehensively considered, and each node is scored and graded to form an edge node set and a core node set. According to the edge node set and the core node set, bandwidth capacity measurement, current load monitoring, and security risk assessment are performed on each link in the network topology map to form a link status parameter data set. Bandwidth capacity measurement obtains the maximum bandwidth capacity of the link by periodically testing the maximum available data transmission rate between the nodes at both ends of the link. This measurement result can provide a reference for network load balancing and link allocation. Current load monitoring tracks the usage of the link in real time by collecting data traffic information on the link, including traffic rate, number of data packets, and congestion situation, so as to judge the load status of the link. Security risk assessment calculates the security risk score of the link by analyzing the historical data traffic patterns, potential security threats, and abnormal behavior characteristics on the link, and combining the physical characteristics and logical security policies of the link. The bandwidth capacity, current load, and security risk score together constitute the link status parameter data set.Meanwhile, source address extraction, destination address identification, data type classification, priority determination, and security level assignment are performed on the data transmitted in the industrial network to form an industrial data stream vector. The generation of the data stream vector extracts the source address and destination address by parsing the data packet, and analyzes the specific type of the data packet in combination with the protocol field, classifying the data stream into different types of data streams such as control instruction streams, status feedback streams, device monitoring streams, and alarm event streams. According to the different data types, the priority of the data stream is determined, and a corresponding security level is assigned to each data stream in combination with the security attributes and transmission sensitivity of the data stream, forming an industrial data stream vector that reflects the characteristics of different data streams in the industrial network. Based on the link state parameter dataset and the industrial data stream vector, the security cost of node - to - node communication is comprehensively calculated and matrix - processed to generate a security topology matrix. The construction of the security topology matrix requires an associative analysis of the link state parameters and the security characteristics of the data stream. By calculating the communication cost between different nodes, the bandwidth occupancy, link load, and security risk are comprehensively incorporated into the communication cost evaluation model. The calculation of the security cost is achieved by the weighted sum of the inverse quantization of the bandwidth capacity, the influence weight of the current load, and the security risk score, realizing the precise quantization of the communication security cost between each pair of nodes and storing the results in the security topology matrix. The matrix elements of the security topology matrix reflect the security cost of data communication between different nodes.

[0027] In a specific embodiment, the process of executing step S200 may specifically include the following steps: Deploy multi - channel parallel security processing units at the nodes in the edge node set according to the node security communication cost in the security topology matrix and the data protocol type information in the industrial data stream vector; Perform industrial protocol parsing on the industrial data stream entering the multi - channel parallel security processing unit through a decision tree structure to obtain a protocol feature vector; Input the protocol feature vector into the lightweight variational auto - encoder in the multi - channel parallel security processing unit for anomaly detection processing to obtain a data anomaly marking result; Use the Huffman coding algorithm to perform the first - stage encapsulation processing on the industrial data stream determined to be normal in the data anomaly marking result to obtain lightweight compressed data; Use the SM4 block cipher algorithm to perform the second - stage encapsulation processing on the lightweight compressed data to obtain encrypted data; Use the SM3 cryptographic hash algorithm to calculate the digital signature of the encrypted data, and perform the third - stage encapsulation processing on the combination of the encrypted data, digital signature, and security header containing the source address, destination address, priority, and timestamp to obtain a securely encapsulated data packet.

[0028] Specifically, according to the node security communication cost in the security topology matrix and the data protocol type information in the industrial data flow vector, a multi-channel parallel security processing unit is deployed on the nodes in the edge node set. This unit performs parallel processing on different types of industrial data flows. Since the industrial network contains multiple data protocols such as Modbus, Profinet, EtherCAT, etc., data flows of different protocols have different security levels and priority requirements. Therefore, a multi-channel architecture is used to shunt and process these data flows. The multi-channel parallel security processing unit adopts n independent channels, and each channel is responsible for processing a specific type of industrial data flow, thereby realizing the classified management and efficient parsing of different data protocols. By combining the node communication cost information in the security topology matrix, according to the communication path and security risk of the data flow, the industrial data flow is intelligently allocated to the appropriate edge node for parallel processing, ensuring low-latency and highly reliable security data processing in a complex industrial environment. The industrial data flow entering the multi-channel parallel security processing unit is parsed for industrial protocols through a decision tree structure. Each node of the decision tree represents a judgment condition for protocol fields. By gradually parsing the protocol fields, the packet features are mapped to a specific protocol type, and a protocol feature vector is generated. This protocol feature vector contains key protocol field information of the packet, including function code, address field, data field, check code, etc., accurately reflecting the protocol structure and communication characteristics of the packet. The protocol feature vector is input into a lightweight variational autoencoder in the multi-channel parallel security processing unit for anomaly detection processing. The variational autoencoder learns the feature distribution of normal industrial data flows through the structures of the encoder and decoder, and maps the protocol feature vector into the latent space for data reconstruction. By calculating the reconstruction error between the original feature vector and the reconstructed vector, it is judged whether the data flow is abnormal. If the reconstruction error is lower than the preset threshold, the data is marked as normal; otherwise, the data is marked as abnormal, and the corresponding security response mechanism is triggered. The data anomaly marking result is used to screen the data flows that need to be subsequently encapsulated. For the determined normal industrial data flows, a first-level encapsulation process is performed. This process uses the Huffman coding algorithm to perform lightweight compression on the data. Huffman coding is a lossless compression algorithm that encodes the high-frequency features of the data flow by constructing an optimal prefix tree, representing the high-frequency data with shorter codes, thereby significantly reducing the redundant information of the data flow and improving the data transmission efficiency. The compressed data occupies less network bandwidth and also reduces the computational complexity for subsequent encryption processing. The compressed data enters the second-level encapsulation stage, and in this stage, the SM4 block cipher algorithm is used to encrypt the lightweight compressed data. SM4 is a symmetric encryption algorithm that uses a 128-bit key and a 128-bit block size to perform multiple rounds of iterative encryption on the data, making the data difficult to be decrypted and tampered with during transmission.The data encrypted by SM4 has a high level of security, which can effectively defend against malicious behaviors such as man-in-the-middle attacks and data theft, ensuring the security of data transmission in the industrial network. After the encryption process is completed, it enters the third-level encapsulation stage. In this stage, the SM3 cryptographic hash algorithm is used to calculate the digital signature of the encrypted data. SM3 is a cryptographic hash algorithm with relatively high security. It maps data of any length to a fixed-length 256-bit hash value. By performing a hash operation on the encrypted data to generate a digital signature, it effectively verifies the integrity of the data and the authenticity of the source. The encrypted data, digital signature, and security header information are combined to form a secure encapsulated data packet. The security header information includes key information such as the source address, destination address, priority, and timestamp of the data packet, providing support for subsequent security policy group applications and multi-layer protection mechanisms. By combining the encrypted data, digital signature, and security header, the formed secure encapsulated data packet has a high level of security, integrity, and anti-tampering ability, and can effectively resist potential security threats in the industrial network.

[0029] In a specific embodiment, the process of executing step S300 may specifically include the following steps: Perform a matrix mapping process on the association relationship between the network protocol state and the data link layer, network layer, and transport layer to obtain a multi-layer protocol state association matrix; Extract the security header information from the secure encapsulated data packet, and perform a comprehensive analysis in combination with network state parameters such as network congestion degree, error rate, and threat level to obtain a security context vector; Based on the security context vector, formulate a data link layer security policy group for the data link layer that includes a MAC address filtering list, port isolation matrix, and VLAN segmentation rules; Based on the security context vector, formulate a network layer security policy group for the network layer that includes an IP address filtering list, routing control table, and access control list; Based on the security context vector, formulate a transport layer security policy group for the transport layer that includes a port filtering list, session control policy, and traffic shaping parameters; Perform a two-way verification association process on the data link layer security policy group, network layer security policy group, and transport layer security policy group according to the multi-layer protocol state association matrix, and calculate the policy weight distribution of each layer according to the security context vector to obtain a three-layer security policy group with cross-layer association.

[0030] Specifically, a matrix mapping process is performed on the association relationships between the network protocol state and the data link layer, network layer, and transport layer to obtain a multi-layer protocol state association matrix. By establishing a three-dimensional mapping matrix, the protocol states at different layers are associated and modeled. The dimension of the matrix is 3×k, where the data link layer, network layer, and transport layer serve as the three-dimensional axes of the matrix respectively, and the matrix elements represent the association degrees between different protocol states. By extracting the state information of different layer protocols in the industrial network, including the MAC address, VLAN tag, and port isolation state of the link layer, the IP address, routing policy, and access control list of the network layer, and the port filtering, session control, and traffic shaping parameters of the transport layer, these state parameters are mapped and a multi-layer protocol state association matrix is constructed. The security header information is extracted from the secure encapsulated data packet, and a comprehensive analysis is performed in combination with network state parameters such as network congestion degree, error rate, and threat level to generate a security context vector. The secure encapsulated data packet contains security header information such as source address, destination address, priority, timestamp, and protocol identifier, and this information can provide the basic attributes and security levels of the data stream for the system. At the same time, in combination with dynamic network parameters such as the current network congestion degree, link error rate, and security threat level, through a data fusion and feature extraction mechanism, a security context vector that comprehensively reflects the current network state is generated. This context vector includes the security risks of the data stream path, the load status of network nodes, and the potential security threats of the link. Based on the generated security context vector, security policy groups are formulated for the data link layer, network layer, and transport layer respectively. At the data link layer, a data link layer security policy group including a MAC address filtering list, a port isolation matrix, and VLAN segmentation rules is formulated. The MAC address filtering list filters the data packets of abnormal devices by matching the physical addresses of legitimate devices; the port isolation matrix isolates sensitive devices in different port areas according to the communication relationships of different devices to prevent unauthorized access; and the VLAN segmentation rules isolate different data streams in a virtual local area network by logically grouping the data streams, thereby reducing the risk of data stream cross-contamination. This policy group can prevent illegal access and enhance the isolation of data streams at the data link layer. At the network layer, a network layer security policy group including an IP address filtering list, a routing control table, and an access control list is formulated according to the security context vector. The IP address filtering list prevents data packets from abnormal addresses from entering the core network by matching the legitimate IP address range; the routing control table dynamically adjusts the forwarding path of data packets according to the priority and security level of the data stream, thereby avoiding data transmission on high-risk links; and the access control list restricts the access rights of specific data streams according to the authentication results of devices and users to prevent unauthorized access behaviors. The network layer security policy group effectively ensures the legitimacy of data streams through these rules and adjusts the policies according to the dynamic network environment to form a flexible network security protection mechanism.At the transport layer, a transport layer security policy group containing a port filtering list, a session control policy, and traffic shaping parameters is formulated according to the security context vector. The port filtering list prevents malicious programs from invading through open ports by restricting the range of ports allowed for communication; the session control policy monitors the status of data connections based on the session characteristics of data flows and terminates illegal sessions in case of anomalies; the traffic shaping parameters achieve load balancing and bandwidth optimization of data transmission by dynamically adjusting the bandwidth resource allocation according to the priority of data flows. The transport layer security policy group provides fine-grained traffic control and security guarantee during data transmission, thus ensuring the stability and security of data during transmission. After formulating the three-layer security policy group, two-way verification and association processing are performed on the data link layer security policy group, the network layer security policy group, and the transport layer security policy group according to the multi-layer protocol state association matrix. The two-way verification and association processing perform consistency detection on policy groups at different levels through a multi-layer cross-verification mechanism to ensure that when the protection policy at a certain layer is bypassed or fails, the protection policies at other layers can still provide effective supplementary protection, thereby avoiding security vulnerabilities caused by single-point failures. The two-way verification mechanism can also identify potential conflicts between different layers to ensure the coordinated operation of security policies at different layers and avoid protection failures caused by policy conflicts. After completing the two-way verification, the policy weights of each layer are calculated according to the security context vector to obtain a three-layer security policy group with cross-layer association. The calculation of policy weights is dynamically allocated based on the priority of different data flows, network status, and security threat levels to ensure that security policies at each layer can be flexibly adjusted under different security requirements. For example, when the data flow belongs to a high-priority control instruction, the system will increase the security weights of the data link layer and the transport layer to ensure the real-time performance and integrity of the data flow. For status feedback flows or device monitoring flows, the security weights of the network layer will be preferentially allocated to optimize the overall transmission efficiency of the data flow. Through dynamic weight allocation, a three-layer security policy group with cross-layer association is formed to achieve multi-layer protection optimization of high-performance industrial switches and effectively improve the security and protection capabilities of industrial networks.

[0031] In a specific embodiment, the process of executing step S400 may specifically include the following steps: Deploy multi-headed security monitors for different types of security threats on the core node based on the three-layer security policy group. The multi-headed security monitors include a feature extractor, a threat analyzer, and a response generator; Use each feature extractor in the multi-headed security monitor to extract features from the data flow to obtain a time series feature vector; Input the time series feature vector into the threat analyzer in the multi-headed security monitor for threat assessment to obtain a threat probability vector; Through the response generator in the multi-head security monitor, the corresponding action is selected from release, log recording, alarm, blocking and redirection according to the threat probability vector to obtain the initial protection response, and the initial protection response is integrated and calculated to obtain the security decision information; Combined with the security decision information, the SM3 algorithm integrity verification is performed on the digital signature in the security encapsulation data packet to obtain the integrity verification result.

[0032] Specifically, a multi-headed security monitor is deployed on the core node based on a three-layer security policy group. This monitoring system can handle different types of security threats simultaneously, including DDoS attacks, ARP spoofing, abnormal traffic, malicious scanning, etc. Each monitoring head focuses on a specific threat type and works collaboratively through modules such as feature extraction, threat analysis, and response generation. The multi-headed security monitor consists of a feature extractor, a threat analyzer, and a response generator. Its parallel structure can achieve synchronous monitoring of multi-type data streams and dynamic threat detection in an industrial environment with high bandwidth and low latency. As the front-end module of the monitor, the feature extractor extracts time-series feature vectors from industrial data streams. These features include the basic information of data packets and also the time-series behavior features of the data stream, such as the arrival interval of data packets, changes in data length, and changes in protocol fields, thus reflecting the dynamic changes of the data stream. When the data stream enters the multi-headed security monitor, the feature extractor extracts features from the data stream through a sliding window mechanism, converting the features of the data stream within a fixed time window into time-series feature vectors. The feature extractor adopts an improved feature extraction algorithm. By analyzing the time-series behavior features of the data stream and combining key features such as protocol fields, data packet length, and communication frequency, the data stream is mapped into a high-dimensional feature vector to form a time-series feature vector. The time-series feature vector is input into the threat analyzer in the multi-headed security monitor for threat assessment. The threat analyzer uses a deep learning model based on long short-term memory network (LSTM). The LSTM network can capture the long-term dependencies and time-series feature changes of the data stream, thus accurately identifying abnormal data streams. By learning the time-series feature patterns of normal data streams, the threat analyzer detects abnormal behaviors in the data stream and generates a threat probability vector. This threat probability vector reflects the probability of the data stream matching different threat types, and each element represents the likelihood of the corresponding threat type occurring. According to the analysis results of the threat probability vector, the response generator in the multi-headed security monitor selects corresponding actions from five protection actions: allow, log, alert, block, and redirect through an adaptive strategy. The response generator combines the priority, security level, and threat type of the current data stream, and dynamically selects the optimal protection response strategy for each data flow according to the weight distribution of the threat probability vector. For example, when the threat probability is low, the response generator selects to allow or log, while when the threat probability is high, it triggers the block or redirect mechanism, thus achieving flexible response to different threats. At the same time, to ensure the consistency of protection responses and the overall protection effect, the multi-headed security monitor integrates and calculates all preliminary protection responses. Through correlation analysis and priority matching mechanisms, the preliminary protection responses of each monitoring head are fused to generate the final security decision information. The security decision information includes the threat type, response action, and security level of the current data stream, and also records the processing path of the data stream in the multi-layer security protection system.Combined with the generated security decision information, perform SM3 algorithm integrity verification on the digital signature in the secure encapsulated data packet to ensure that the data has not been tampered with during transmission. As a cryptographic hash algorithm with relatively high security, the SM3 algorithm can perform hash operations on data and generate a 256-bit digest information of a fixed length. When performing integrity verification, recalculate the SM3 hash value for the encrypted data part in the secure encapsulated data packet, and compare the calculated digest with the digital signature in the data packet. If the two match, it indicates that the data has maintained integrity during transmission; otherwise, it indicates that the data has been tampered with and an appropriate exception handling mechanism needs to be triggered. The integrity verification mechanism of the SM3 algorithm can effectively prevent data tampering and man-in-the-middle attacks. Through the multi-channel feature extraction, threat analysis, response generation of the multi-head security monitor and the integrity verification of the SM3 algorithm, parallel detection and dynamic protection of different types of security threats are realized, ensuring the security, stability and reliability of data transmission in the high-performance industrial switch in a complex industrial network environment.

[0033] In a specific embodiment, the process of executing step S500 may specifically include the following steps: Enter the threat type, threat level, and protection actions in the security decision information, as well as the data integrity status and privacy protection requirements in the integrity verification result as input parameters into the variational inference model to obtain the initial security state assessment result; According to the initial security state assessment result, combined with the current data transmission delay, throughput, and packet loss rate of the high-performance industrial switch, establish a trade-off relationship between transmission efficiency and security strength to obtain the optimization objective; Based on the optimization objective, set the initial encryption strength, initial authentication algorithm selection, initial data verification mechanism, initial buffering strategy, and initial congestion control parameters of the variational inference model to obtain the parameter optimization starting point; Perform iterative update operations on the parameter optimization starting point, and evaluate the transmission efficiency and security strength under the current parameter configuration in each iteration to obtain the updated parameter configuration; Conduct an industrial network environment adaptability assessment on the updated parameter configuration to obtain a candidate parameter set that meets industrial communication requirements, and select the best balance point from the candidate parameter set to determine the optimal protection parameters.

[0034] Specifically, the threat type, threat level, and protection actions in the security decision information, as well as the data integrity status and privacy protection requirements in the integrity verification result, are entered as input parameters into the variational inference model to obtain the initial security state assessment result. The security decision information reflects the threat characteristics of the industrial data stream after being analyzed by the multi-head security monitor, including the classification of potential threat types (such as DDoS attacks, ARP spoofing, malicious scanning, etc.), the level of threat, and the protection actions taken against these threats (such as blocking, alerting, redirecting, etc.). This information provides the security situation data in the current network environment for the model. At the same time, the integrity verification result provides the data integrity status and privacy protection requirements. The integrity status reflects whether the data has been tampered with during transmission through the SM3 hash verification result, while the privacy protection requirements determine what level of privacy protection measures should be taken for the data based on the sensitivity and security level of the data stream. These data parameters jointly provide the key input for the initial security state assessment of the variational inference model. The variational inference model models the joint distribution of the input parameters, calculates the data security state under different threat scenarios, and obtains the initial security state assessment result by maximizing the posterior probability. This assessment result comprehensively reflects the data security, integrity, and privacy protection levels in the current network environment. After obtaining the initial security state assessment result, a trade-off relationship between transmission efficiency and security intensity is established by combining the current key performance parameters of the high-performance industrial switch, such as data transmission delay, throughput, and packet loss rate. Based on this, an optimization objective is constructed. In the industrial environment with high bandwidth and low latency, the industrial switch needs to simultaneously meet the real-time requirement of data transmission and the protection intensity of system security. Therefore, the optimization objective needs to dynamically balance between security and transmission efficiency. By combining the initial security state assessment result with the current network state parameters, a multi-objective optimization function is established. This function takes performance indicators such as transmission delay, throughput, and packet loss rate as part of the optimization objective, and at the same time incorporates the threat level, data integrity status, and privacy protection requirements in the security state assessment result into the optimization function, forming a dynamic trade-off relationship, thus providing a clear direction for parameter optimization. Based on this optimization objective, the initial parameter configuration of the variational inference model is set, including the initial encryption intensity, the selection of the initial authentication algorithm, the initial data verification mechanism, the initial buffering strategy, and the initial congestion control parameters, to obtain the starting point for parameter optimization. The initial parameter configuration is directly related to the security of industrial data and network performance. The encryption intensity determines the security level of the data during transmission, the authentication algorithm affects the verification of the legitimacy of the packet source, the data verification mechanism determines the integrity verification method of the data during transmission, and the buffering strategy and congestion control parameters directly affect the traffic scheduling and congestion control effect of the data stream in a high-load environment.By comprehensively analyzing the current network status and security assessment results, a reasonable initial parameter configuration is set for the variational inference model under the guidance of the optimization objective, thus providing a stable starting point for subsequent parameter optimization. An iterative update operation is performed on the parameter optimization starting point. By evaluating the transmission efficiency and security strength under the current parameter configuration in each iteration, and adjusting the parameter configuration according to the evaluation results, the optimal solution is gradually approximated. In each iteration process, the transmission efficiency and security strength corresponding to the current parameter configuration are calculated according to the optimization objective. By fine-tuning the encryption strength, authentication algorithm, data verification mechanism, buffering strategy, and congestion control parameters, the parameter configuration is dynamically adjusted, so as to seek the best balance between security and performance. During the iterative update process, the variational lower bound principle of the variational inference model is adopted, and the parameter configuration is optimized by maximizing the posterior probability of the data, continuously reducing the gap between the current parameter configuration and the optimal solution, and finding the optimal parameter combination in the parameter space through the gradient update method. After multiple iterative updates, a set of parameter configurations that are dynamically adapted to different network environments is obtained. The updated parameter configurations are evaluated for their adaptability to the industrial network environment. According to different industrial application scenarios, the updated parameter configurations are applied to the simulation environment, and by analyzing indicators such as the transmission delay of data packets, data integrity, packet loss rate, and security protection strength, it is judged whether the current parameter configuration can meet the industrial communication requirements. During the industrial environment adaptability evaluation process, multi-dimensional tests are performed on the updated parameter configurations according to the communication load, data sensitivity, and security requirements of different application scenarios, so as to obtain a candidate parameter set that meets different industrial communication requirements. After completing the industrial network environment adaptability evaluation, a parameter combination that meets the best balance of security, privacy protection, and transmission efficiency is selected from the candidate parameter set, and finally the optimal protection parameters are determined. The candidate parameter set contains different parameter combinations generated during multiple rounds of iterative updates. After strict environment adaptability tests, these parameter combinations can maintain good security and transmission efficiency in different industrial environments. Through multi-dimensional weighing analysis of the candidate parameter set, a parameter configuration with the best balance of security strength and transmission efficiency is selected and applied as the optimal protection parameters to the multi-layer protection system of the high-performance industrial switch.

[0035] In a specific embodiment, the method for performing multi-layer protection of a high-performance industrial switch further includes the following steps: Based on the optimal protection parameters, clustering analysis is performed on the security topology matrix, and network nodes are divided into multiple virtual security domains. Each security domain consists of a node set, a link set, and a security policy set; The security similarity of nodes within each pair of virtual security domains is calculated to obtain the in-domain node security similarity matrix; According to the in-domain node security similarity matrix, a state space including network status, threat level, and resource occupancy, and an action space including protection policy adjustment instructions are constructed; Based on the state space and the action space, a reward function including a security score, a performance score, and a resource cost is established, and a double deep Q-network structure is deployed for the deep reinforcement learning controller of each virtual security domain. Learning is carried out by sampling batches from the experience pool through the experience replay mechanism based on the reward function to obtain an adaptive protection strategy; According to the adaptive protection strategy, the boundaries and protection configurations of each virtual security domain are periodically evaluated and dynamically adjusted, and when new threats or network topology changes are detected, a security domain reconstruction is triggered to obtain a multi-layer protection system.

[0036] Specifically, based on the optimal protection parameters, clustering analysis is performed on the security topology matrix, and the nodes and links in the network are automatically partitioned according to communication security costs, load status, and security levels, generating multiple virtual security domains. The security topology matrix contains information on the communication security costs between all nodes in the network, and the cost factors include bandwidth occupancy, link load, and potential security risks. Through an improved K-medoids clustering algorithm, clustering analysis is performed on the nodes according to the security costs and communication frequencies between the nodes, thereby partitioning multiple virtual security domains. Each security domain consists of a node set, a link set, and a security policy set. The node set contains all network devices in the domain that are partitioned into the same security domain. The link set represents the communication paths between these devices, their bandwidth capacities, load status, and security risk levels. The security policy set, on the other hand, tailors different security policies for each security domain, including access control, data encryption, traffic isolation, and intrusion detection, etc. After completing the partitioning of the virtual security domains, the security similarity of the nodes within each pair of virtual security domains is calculated to obtain the in-domain node security similarity matrix. The calculation of the security similarity comprehensively considers the communication frequency, data flow type, protocol characteristics, and security risk levels between the nodes. Through Euclidean distance and weighted feature mapping, the similarity measure between the nodes is mapped into a high-dimensional matrix, where each element of the matrix represents the security similarity score between two nodes. Based on the in-domain node security similarity matrix, a state space containing network status, threat level, and resource occupancy is constructed, as well as an action space containing protection policy adjustment instructions. The construction of the state space synthesizes the topological state, threat situation, and resource allocation of the network. The state parameters include the current network topology structure, the load levels of each node and link, the threat level distribution, and the resource occupancy situation. The action space contains various instructions for adjusting protection policies, and the action options include encryption intensity adjustment, access control policy update, reallocation of data flow isolation rules, optimization of traffic shaping parameters, etc. These protection policy adjustment instructions provide diverse operation options for the dynamic adjustment of policies in different security states. After constructing the state space and action space, a reward function containing security score, performance score, and resource cost is established. This reward function is used to evaluate the protection policy effect of each virtual security domain and provide an optimization target for the training of the deep reinforcement learning controller. The security score is used to measure the ability of the current protection policy to resist threats. The performance score reflects the impact of the current protection configuration on data transmission latency, throughput, and packet loss rate. The resource cost calculates the consumption of network resources (such as computing power, storage capacity, and bandwidth usage) by the current protection configuration. To optimize the protection policies of different security domains, a deep reinforcement learning controller based on the double deep Q-network (DDQN) structure is deployed in each virtual security domain.The DDQN structure consists of a main network and a target network. The main network is responsible for generating policies and executing actions, while the target network is used to evaluate the future rewards of the current policy, thus avoiding the overestimation problem in the policy update process. Through the experience replay mechanism, the deep reinforcement learning controller can sample batch data from the experience pool for learning, continuously update the weights of the policy network and the target network, and obtain a more adaptive protection policy. As the deep reinforcement learning controller is continuously trained, the system periodically evaluates and dynamically adjusts the boundaries and protection configurations of each virtual security domain according to the adaptive protection policy. The periodic evaluation mechanism evaluates the rationality of the current security domain boundary by regularly analyzing the threat situation, data flow changes, and network topology dynamics within the virtual security domain, and makes dynamic adjustments according to the execution effect of the protection policy. When a new threat is detected or a major change occurs in the network topology, the system will trigger the security domain reconstruction mechanism, and by re-dividing the virtual security domain and adjusting the security policy, achieve the adaptive evolution of the protection system. During the security domain reconstruction process, the security similarity matrix between nodes is recalculated, and the improved K-medoids algorithm is used to re-cluster the nodes. Nodes with higher security costs and higher threat levels are preferentially assigned to the same security domain, thus forming a more compact security domain boundary and achieving more efficient security protection. Throughout the process, the deep reinforcement learning controller continuously updates the security policies of each virtual security domain through multiple rounds of iteration and policy optimization, ensuring the best security protection effect in different network states. Through the security domain reconstruction mechanism, deep reinforcement learning control, and policy dynamic adjustment mechanism, a multi-layer protection system for high-performance industrial switches in a complex industrial network environment is realized.

[0037] Please refer to Figure 2 , Figure 2 which is a schematic block diagram of the structure of the multi-layer protection system 200 of the high-performance industrial switch provided by the embodiment of the present application. As Figure 2 shown, the multi-layer protection system 200 of the high-performance industrial switch includes: A topology analysis module 210, configured to perform topology analysis on the industrial network to obtain a security topology matrix and an industrial data flow vector; A triple encapsulation module 220, configured to perform triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a security encapsulated data packet; A construction module 230, configured to construct a three-layer security policy group with cross-layer association according to the security header information of the security encapsulated data packet; A verification module 240, configured to deploy a multi-head security monitor based on the three-layer security policy group to perform parallel threat detection and SM3 algorithm integrity verification, and generate security decision information and an integrity verification result; The joint iterative optimization module 250 is used to input the security decision information and integrity verification results into the variational inference model to perform joint iterative optimization of transmission efficiency and security strength, and obtain the optimal protection parameters.

[0038] Through the collaborative cooperation of the above-mentioned various components, by constructing an edge-core hierarchical protection architecture and implementing a three-layer security policy group from the data link layer, network layer to the transport layer, a complete protection system is formed. Compared with single-layer protection, this method can eliminate security blind spots. Even if a certain layer of protection is breached, other layers can still provide protection, significantly improving the protection depth and system resilience. Deploying multi-channel parallel security processing units at the edge nodes, through protocol parsing, anomaly detection and triple encapsulation, efficient security processing in resource-constrained environments is achieved. Using a lightweight variational autoencoder for anomaly detection, a large amount of malicious data is intercepted at the edge, reducing the burden on the core network and the impact of security protection on network performance. Based on the multi-layer protocol state association matrix, a cross-layer associated three-layer security policy group is constructed, solving the problem that each protection layer in the traditional method operates independently and lacks coordination. Through the two-way verification mechanism and dynamic weight adjustment, the collaborative work of protection strategies at different network layers is realized, improving the overall protection effect. Deploying multi-headed security monitors for different threat types and integrating the monitoring results through the attention mechanism, comprehensive capture of local and global threats is achieved. Compared with single monitoring methods, this method can identify multiple attack patterns simultaneously, significantly reducing the false alarm rate and missed alarm rate, and improving the accuracy of threat detection. Using the variational inference principle to perform joint iterative optimization of transmission efficiency and security strength to find the balance point between the two. Dynamically adjusting parameters such as encryption strength, authentication algorithm and data verification mechanism according to the optimization results, ensuring that the high-performance industrial switch can still maintain strict real-time performance requirements while providing strong security guarantees, and solving the problem that it is difficult to balance security and performance in traditional methods. Through virtual security domain division and deep reinforcement learning control, the protection system is given the ability of adaptive learning. The system can dynamically adjust the protection strategy according to the network state changes and the emergence of new threats, and even reconstruct the virtual security domain, realizing the continuous evolution of the protection system, effectively coping with the constantly changing security challenges in industrial networks, and breaking through the limitations of traditional static protection methods.

[0039] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems, systems and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0040] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0041] As described above, the above embodiments are only used to illustrate the technical solutions of this application and are not intended to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of various embodiments of this application.

Claims

1. A multi-layer protection method for a high-performance industrial switch, characterized in that: include: Perform topological analysis on the industrial network to obtain the security topology matrix and industrial data flow vector; Perform triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a secure encapsulated data packet; Constructing a cross-layer associated three-layer security policy group according to the security header information of the security encapsulated data packet; Based on the three-layer security policy group, deploy multiple security monitors to implement parallel threat detection and SM3 algorithm integrity verification, and generate security decision information and integrity verification results; The security decision information and the integrity verification result are input into a variational inference model to perform joint iterative optimization of transmission efficiency and security strength to obtain optimal protection parameters.

2. The multi-layer protection method for a high-performance industrial switch according to claim 1 is characterized in that: The topological analysis of the industrial network is performed to obtain a security topology matrix and an industrial data flow vector, including: Automatically detect and identify all nodes and links in the industrial network to obtain a first network topology diagram including a node set and a link set; Classify and mark the nodes in the first network topology diagram according to the computing power index, network location and data flow characteristics of each node to obtain an edge node set and a core node set; According to the edge node set and the core node set, bandwidth capacity measurement, current load monitoring and security risk assessment are performed on each link in the network topology diagram to obtain a link state parameter data set; Extracting source addresses, identifying destination addresses, classifying data types, determining priorities, and allocating security levels for data transmitted in the industrial network to obtain industrial data flow vectors; Based on the link state parameter data set, the security cost of communication between nodes is comprehensively calculated and matrixed to obtain a security topology matrix.

3. The multi-layer protection method for a high-performance industrial switch according to claim 1 is characterized in that: The performing triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a secure encapsulated data packet includes: Deploy multi-channel parallel security processing units at nodes in the edge node set according to the node security communication cost in the security topology matrix and the data protocol type information in the industrial data flow vector; Performing industrial protocol parsing on the industrial data stream entering the multi-channel parallel security processing unit through a decision tree structure to obtain a protocol feature vector; Inputting the protocol feature vector into the lightweight variational autoencoder in the multi-channel parallel security processing unit for anomaly detection processing to obtain a data anomaly labeling result; Using a Huffman coding algorithm to perform a first repackaging process on the industrial data stream determined to be normal in the data anomaly marking result, to obtain lightweight compressed data; Performing a second encapsulation process on the lightweight compressed data using the SM4 block cipher algorithm to obtain encrypted data; The digital signature of the encrypted data is calculated using the SM3 cryptographic hash algorithm, and the encrypted data, the digital signature and a security header including a source address, a destination address, a priority and a timestamp are combined for a third encapsulation process to obtain a securely encapsulated data packet.

4. The multi-layer protection method for a high-performance industrial switch according to claim 1 is characterized in that: The step of constructing a cross-layer associated three-layer security policy group according to the security header information of the security encapsulated data packet includes: Matrix mapping is performed on the association relationship between the network protocol status and the data link layer, network layer, and transport layer to obtain a multi-layer protocol status association matrix; Extracting security header information from the security encapsulated data packet, and performing comprehensive analysis in combination with network state parameters such as network congestion, error rate, and threat level to obtain a security context vector; Formulate a data link layer security policy group including a MAC address filter list, a port isolation matrix and a VLAN segmentation rule for the data link layer based on the security context vector; Formulate a network layer security policy group including an IP address filter list, a routing control table and an access control list for the network layer based on the security context vector; Formulate a transport layer security policy group including a port filter list, a session control policy and a traffic shaping parameter for the transport layer based on the security context vector; According to the multi-layer protocol state association matrix, bidirectional verification association processing is performed on the data link layer security policy group, the network layer security policy group and the transport layer security policy group, and the weight distribution of each layer policy is calculated according to the security context vector to obtain a three-layer security policy group with cross-layer association.

5. The multi-layer protection method for a high-performance industrial switch according to claim 1, characterized in that: Based on the three-layer security policy group, deploying multiple security monitors to implement parallel threat detection and SM3 algorithm integrity verification, generating security decision information and integrity verification results, includes: Deploy a multi-head security monitor for different types of security threats on the core node based on the three-layer security policy group, wherein the multi-head security monitor includes a feature extractor, a threat analyzer, and a response generator; Using each feature extractor in the multi-head security monitor to extract features from the data stream to obtain a time series feature vector; Inputting the time series feature vector into the threat analyzer in the multi-head security monitor for threat assessment to obtain a threat probability vector; By means of a response generator in the multi-head security monitor, a corresponding action is selected from release, log recording, alarm, blocking and redirection according to the threat probability vector to obtain a preliminary protection response, and the preliminary protection response is integrated and calculated to obtain security decision information; In combination with the security decision information, the SM3 algorithm integrity verification is performed on the digital signature in the security encapsulation data packet to obtain an integrity verification result.

6. The multi-layer protection method for a high-performance industrial switch according to claim 1, characterized in that: The step of inputting the security decision information and the integrity verification result into a variational inference model to perform joint iterative optimization of transmission efficiency and security strength to obtain optimal protection parameters includes: Entering the threat type, threat level and protection action in the security decision information, and the data integrity status and privacy protection requirements in the integrity verification result as input parameters into the variational reasoning model to obtain an initial security status assessment result; According to the initial security status assessment result, combined with the current data transmission delay, throughput and packet loss rate of the high-performance industrial switch, a trade-off relationship between transmission efficiency and security strength is established to obtain an optimization target; Based on the optimization objective, the initial encryption strength, initial authentication algorithm selection, initial data verification mechanism, initial buffer strategy and initial congestion control parameters of the variational inference model are set to obtain a parameter optimization starting point; Performing an iterative update operation on the parameter optimization starting point, evaluating the transmission efficiency and security strength under the current parameter configuration in each iteration, and obtaining an updated parameter configuration; An industrial network environment adaptability assessment is performed on the updated parameter configuration to obtain a candidate parameter set that meets industrial communication requirements, and an optimal balance point is screened out from the candidate parameter set to determine optimal protection parameters.

7. The multi-layer protection method for a high-performance industrial switch according to claim 1, characterized in that: The multi-layer protection method of the high-performance industrial switch also includes: Performing cluster analysis on the security topology matrix based on the optimal protection parameters, dividing the network nodes into a plurality of virtual security domains, each security domain consisting of a node set, a link set and a security policy set; Calculate the security similarity of each pair of nodes in the virtual security domain to obtain the security similarity matrix of nodes in the domain; Constructing a state space including network status, threat level and resource occupancy, and an action space including protection strategy adjustment instructions according to the security similarity matrix of nodes in the domain; Based on the state space and the action space, a reward function including a safety score, a performance score and a resource cost is established, and a dual deep Q network structure is deployed for the deep reinforcement learning controller of each virtual safety domain. Based on the reward function, batches are sampled from the experience pool through an experience replay mechanism for learning to obtain an adaptive protection strategy; According to the adaptive protection strategy, the boundaries and protection configurations of each virtual security domain are periodically evaluated and dynamically adjusted. When new threats or changes in network topology are detected, security domain reconstruction is triggered to obtain a multi-layer protection system.

8. A multi-layer protection system for a high-performance industrial switch, characterized in that: The multi-layer protection method for a high-performance industrial switch according to any one of claims 1 to 7, wherein the multi-layer protection system for the high-performance industrial switch comprises: Topology analysis module, used to perform topology analysis on industrial networks to obtain security topology matrix and industrial data flow vector; A triple encapsulation module, used to perform triple encapsulation based on the security topology matrix and the industrial data flow vector to obtain a secure encapsulated data packet; A construction module, used to construct a cross-layer associated three-layer security policy group according to the security header information of the security encapsulated data packet; A verification module, used to deploy multiple security monitors to implement parallel threat detection and SM3 algorithm integrity verification based on the three-layer security policy group, and generate security decision information and integrity verification results; The joint iterative optimization module is used to input the security decision information and the integrity verification result into the variational inference model to perform joint iterative optimization of transmission efficiency and security strength to obtain optimal protection parameters.

Citation Information

Cited By

  • Business internet platform big data security protection system

    CN121000484A

  • Network policy automatic generation and verification method, system, product and medium

    CN121530716A

  • A method, system, product, and medium for automatic generation and verification of network policies.

    CN121530716B

  • Deterministic communication network security guarantee method for industrial internet

    CN121864482A