Distributed network security monitoring method and system for communication engineering

Through quantum trust chain and self-supervised learning, encrypted communication and dynamic trust evaluation are realized in distributed networks, solving the trust verification and intelligent detection problems of traditional security monitoring systems in large-scale and highly dynamic networks, and providing efficient and intelligent security monitoring and defense solutions.

CN120263405AInactive Publication Date: 2025-07-04TENGZHAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510472539.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the large-scale, highly dynamic distributed network, traditional security monitoring systems cannot adapt to changes in the network environment in real time, lack effective assessment of trust between nodes, resulting in the inability to respond to unknown threats and complex attacks in a timely manner, and the computing resources are consumed and the detection accuracy is low.

Method used

By introducing quantum trust chain technology and self-supervised learning, encrypted communication and identity authentication are established, combined with self-supervised learning models to perform abnormal analysis and trust evaluation, dynamically adjust defense strategies to achieve real-time monitoring and intelligent response to the network environment.

Benefits of technology

It realizes efficient, dynamic and intelligent security monitoring of large-scale distributed networks, reduces operation and maintenance costs, improves detection accuracy and response speed, and ensures network security and robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263405A_ABST
    Figure CN120263405A_ABST
Patent Text Reader

Abstract

The invention provides a distributed network security monitoring method and system for communication engineering, and the method comprises the steps: building a quantum trust chain among all nodes in a distributed network through a quantum key distribution technology, and carrying out the identity authentication of the nodes joining the network; the method comprises the following steps: acquiring sensor data from each node of a network in real time, arranging according to a time sequence to generate a time sequence matrix, and constructing a loss function of a self-supervised contrast learning task by taking the time sequence matrix as label-free data to train a self-supervised learning model; performing anomaly analysis on each node through the reconstruction error, and distinguishing different threat types through comparative learning based on an anomaly analysis result; dynamically evaluating the credibility of each node in the network; and determining the defense strength of the network at the current moment through the credibility of the global trust chain, and dynamically adjusting response measures based on the defense strength at the current moment and the credibility of the global trust chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security monitoring, and particularly relates to a distributed network security monitoring method and system for communication engineering. Background Art

[0002] In the current era of rapid development of informatization and networking, network security in communication engineering has become a crucial issue. With the wide application of emerging technologies such as 5G, Internet of Things, cloud computing, and artificial intelligence, the distributed router network architecture has become a core component of modern communication systems. Due to their huge scale and dynamic characteristics, these distributed networks are facing unprecedented security challenges. Traditional network security technologies, such as intrusion detection systems (IDS), firewalls, and traditional defense mechanisms, although effective in some scenarios, have exposed a series of problems in large-scale and highly dynamic network environments.

[0003] Firstly, traditional rule-based security monitoring systems, such as IDS and firewalls, mainly rely on preset rules and signature libraries for attack detection. This method has significant limitations. Attackers often adopt variant attack methods or use new attack means not included in the signature library, and existing security systems often cannot respond to these unknown threats in a timely manner. Secondly, existing defense mechanisms cannot adapt to the dynamically changing network environment in real time. In large-scale distributed networks, network traffic, node states, etc. often change, and traditional static defense methods usually cannot adjust defense strategies in a timely manner in the changing environment, resulting in the risk of the system being bypassed. In addition, many network security solutions lack effective evaluation and verification of trust between nodes. Due to the openness and complexity of distributed networks, it is difficult to guarantee the trust relationship between nodes. Especially when some nodes are affected by attacks or malicious behaviors, the security of the entire network is easily threatened.

[0004] When existing technologies solve these problems, most of them adopt means based on artificial intelligence (AI) or big data analysis, but these methods still face challenges such as excessive consumption of computing resources, the need for a large amount of labeled data for model training, and low detection accuracy. Even so, they usually lack an inherent security guarantee mechanism for network communication and have not effectively achieved dynamic adaptive security monitoring. Traditional defense systems cannot dynamically adjust monitoring strategies and usually rely on manual intervention in the face of highly dynamic attack methods, with slow response speed and difficulty in effectively dealing with complex security threats in real time.

[0005] Therefore, how to achieve efficient, dynamic and intelligent security monitoring and defense in a distributed network environment has become an urgent problem to be solved in communication engineering. This requirement has promoted further exploration of network security technologies, especially how to combine advanced encryption technologies, intelligent algorithms with real-time threat detection to fundamentally improve the system's adaptive ability, intelligent detection ability and security response ability. Summary of the Invention

[0006] The object of the present invention is to design a distributed network security monitoring method and system for communication engineering. By introducing quantum trust chain technology and self-supervised learning, it effectively overcomes the deficiencies of the prior art and realizes comprehensive, real-time monitoring and intelligent response to the network environment.

[0007] To achieve the above object, in the first aspect of the present invention, a distributed network security monitoring method for communication engineering is provided. The method includes:

[0008] Step 1: Establish a quantum trust chain among each node in the distributed network through quantum key distribution technology for realizing encrypted communication and identity authentication among nodes. Use the key pair generated by the quantum trust chain to authenticate the nodes joining the network. When a node joins, the system will perform double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain;

[0009] Step 2: Real-time collect sensor data from each node of the network, organize and generate a time series matrix according to the time series. Use the time series matrix as unlabeled data to construct a loss function of a self-supervised contrast learning task to train a self-supervised learning model and output a feature representation Z t ; The sensor data includes network traffic information, CPU load and temperature monitoring information;

[0010] Step 3: Based on the feature representation Z t , in combination with the quantum trust chain, perform anomaly analysis on each node through the reconstruction error, and distinguish different threat types through contrast learning based on the results of the anomaly analysis to obtain feedback information;

[0011] Step 4: Combine the feature representation Z t , the node behavior history of the node and the feedback information to dynamically evaluate the trust level of each node in the network, and update the global trust chain based on the trust level of each node to obtain the trust level of the global trust chain;

[0012] Step 5: Determine the defense intensity of the network at the current moment through the trust level of the global trust chain, and dynamically adjust the response measures based on the defense intensity at the current moment and the trust level of the global trust chain;

[0013] Among them, the response measures at least include one of the following: enhancing firewall filtering, adjusting node weights, and isolating nodes in real time.

[0014] Furthermore, the quantum trust chain is established through quantum key distribution technology to achieve encrypted communication and identity authentication between nodes. Specifically:

[0015] Each node is initialized using a quantum communication channel; among them, node A and node B will share a quantum key K during initialization init , and the exchange process of its key is completed through quantum entanglement states;

[0016] When node A needs to communicate with node B, node A sends its public key K pub-A to node B and encrypts the information using the private key K priv-A in the quantum trust chain. After receiving the encrypted information, node B decrypts and verifies it through the quantum key exchange protocol to confirm whether the identity of node A is legal;

[0017] If the decryption result is consistent with the expectation, node B will consider node A to be trustworthy, otherwise it will be marked as untrustworthy and reject the communication request.

[0018] Furthermore, in step one, it also includes: when any abnormal situation occurs during the communication process between node A and node B, the quantum trust chain will update its trust level according to the behavior of node A.

[0019] Furthermore, the self-supervised learning model is trained using the loss function that constructs a self-supervised contrastive learning task with the time series matrix as unlabeled data, and the feature representation Z t is output. Specifically:

[0020] Two groups of samples are sampled from the data: a group of positive sample pairs (x i,positive , x j,positive ), which means two sensor data collected under similar network states; a group of negative sample pairs (x i,negative , x j,negative ), which means two sensor data collected under different network states;

[0021] Based on the positive sample pairs (x i,positive , x j,positive ) and the sample pairs (x i,negative , x j,negative ), the first loss function of the self-supervised learning model is constructed. By minimizing the first loss function, the self-supervised learning model can learn the latent representation of the data;

[0022] A regularization term is obtained by performing a hyperparameter weighted sum on the gradients of the model parameters of the self-supervised learning model and the determinant of the covariance matrix of the output, and the feature learning process of the self-supervised learning model is constrained by the regularization term.

[0023] Output the feature representation Z after the completion of feature learning t 。

[0024] Furthermore, based on the feature representation Z t , combined with the quantum trust chain, anomaly analysis is performed on each node through the reconstruction error, specifically:

[0025] For the feature representation Z t , it is reconstructed through the decoder of the self-supervised learning model to obtain the reconstructed data

[0026] Perform Euclidean distance analysis on the feature representation Z t and the reconstructed data to obtain the reconstruction error;

[0027] When the reconstruction error exceeds a certain dynamic threshold, the data point is determined to be abnormal; among them, the dynamic threshold is automatically adjusted according to the error distribution in the historical data.

[0028] Furthermore, different threat types are distinguished through contrastive learning based on the results of the anomaly analysis, specifically:

[0029] After detecting potential abnormal data, based on the feature representation Z t , optimize the first loss function to identify different threat types;

[0030] Among them, the optimization of the first loss function specifically includes:

[0031] Based on the feature representation Z t Construct positive samples (Z t , Z t' ), indicating similar network states, then the negative sample pair Z k represents data in different states, and a second loss function is generated

[0032]

[0033] Among them, f(Z t ) represents the feature embedding generated by the self-supervised learning model for the data point Z t , f(Z t' ) represents the feature embedding generated by the self-supervised learning model for the data point Z t' , f(Z k) represents the feature embedding generated by the self-supervised learning model for the data point Z, and sim represents the cosine similarity.

[0034] Further, the cosine similarity of the feature representation Z t the node behavior history of the node, and the feedback information are weighted and summed to obtain the trust degree of each node in the network;

[0035] Among them, updating the global trust chain based on the trust degree of each node to obtain the trust degree of the global trust chain is specifically:

[0036] Calculate the trust degree of each node according to the quantum entanglement degree between the current node and the node at the previous moment; among them, the quantum entanglement degree is measured by the correlation of the feature vectors between the nodes;

[0037] Perform aggregation analysis according to the trust degree of each node to obtain the trust degree of the global trust chain.

[0038] Further, determining the defense strength of the network at the current moment through the trust degree of the global trust chain, and dynamically adjusting the response measures based on the defense strength at the current moment and the trust degree of the global trust chain specifically includes:

[0039] Determine the defense strength at the current moment according to the trust degree of the global trust chain and the threat type;

[0040] Implement response measures based on the defense strength and the trust degree of the global trust chain; update the trust degree of the node according to the implementation of the response measures;

[0041] After multiple adaptive defenses and responses, feedback is performed according to the defense effects of multiple rounds, and the defense strategy for the next round is adjusted.

[0042] In the second aspect of the present invention, a distributed network security monitoring system for communication engineering is provided, and the system includes:

[0043] Quantum trust chain module: used to establish a quantum trust chain among various nodes in the distributed network through quantum key distribution technology for realizing encrypted communication and identity authentication between nodes, using the key pair generated by the quantum trust chain to authenticate the nodes joining the network. When a node joins, the system will perform double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain;

[0044] Data acquisition and model training module: used to collect sensor data from each node of the network in real time, organize and generate a time series matrix according to the time series, and construct a loss function of a self-supervised contrast learning task with the time series matrix as unlabeled data to train the self-supervised learning model, and output the feature representation Z t; The sensor data includes network traffic information, CPU load, and temperature monitoring information;

[0045] Anomaly Detection and Threat Identification Module: used to perform anomaly analysis on each node based on the feature representation Z t , combined with the quantum trust chain, and distinguish different threat types through contrastive learning based on the results of the anomaly analysis to obtain feedback information by reconstructing the error;

[0046] Dynamic Trust Evaluation Module: used to dynamically evaluate the trust level of each node in the network by combining the feature representation Z t , the node behavior history of the node, and the feedback information, and update the global trust chain based on the trust level of each node to obtain the trust level of the global trust chain;

[0047] Adaptive Defense and Response Module: used to determine the defense intensity of the network at the current moment through the trust level of the global trust chain, and dynamically adjust the response measures based on the defense intensity at the current moment and the trust level of the global trust chain;

[0048] Among them, the response measures at least include one of the following: enhancing firewall filtering, adjusting node weights, and real-time isolating nodes.

[0049] The beneficial technical effects of the present invention are at least as follows:

[0050] The present invention proposes a dynamic adaptive network security monitoring and defense system based on the quantum trust chain and self-supervised learning, aiming to solve the limitations of trust verification, dynamic defense, and intelligent detection existing in traditional network security monitoring and defense systems in large-scale distributed networks. By introducing quantum trust chain technology and self-supervised learning, the present invention can effectively overcome the deficiencies of the prior art and achieve comprehensive, real-time monitoring and intelligent response to the network environment.

[0051] Introduction of the quantum trust chain: The present invention uses quantum key distribution technology (QKD) to construct a distributed quantum trust chain to encrypt and securely verify the communication of each node in the network. Traditional rule-based security detection methods are vulnerable to interference and attacks from malicious nodes, and it is difficult to establish trust between nodes. The quantum trust chain ensures secure communication between nodes through quantum key distribution. Any attempt to tamper with or eavesdrop on the communication will be detected and responded to in real time, fundamentally solving the problems of trust and communication security between nodes.

[0052] Self-Supervised Learning and Dynamic Threat Detection: Through self-supervised learning algorithms, this invention combines a large amount of unlabeled data collected by various sensors (such as traffic sensors, health monitoring sensors, etc.) to automatically learn and identify normal and abnormal network behaviors. This solves the bottleneck that traditional signature-based detection methods cannot respond to new attacks and unknown threats in a timely manner. Self-supervised learning can dynamically adapt to the network environment, automatically mine potential security threats from big data without manual annotation, thereby reducing the system's operation and maintenance costs and improving the detection accuracy.

[0053] Adaptive Defense and Response Mechanism: The adaptive defense mechanism proposed in this invention can adjust the network's defense strategy in real time according to the security status of the quantum trust chain and the detection results of the self-supervised learning model. This innovative mechanism ensures that in the face of complex attacks, the system can automatically identify and respond to attacks, dynamically optimize network security policies, and avoid the static and manual-dependence problems of traditional firewalls and intrusion detection systems. The system can automatically adjust the defense level according to information such as network traffic and node status. Even when a node trust chain break is detected, the affected node can be immediately isolated or disconnected to ensure the overall security of the network.

[0054] Therefore, the core innovation of this invention lies in ensuring the security and trust of node communication through the quantum trust chain, using self-supervised learning to intelligently identify abnormal behaviors without manual intervention, and combining the adaptive defense mechanism to achieve automated threat detection and response in a large-scale and dynamic network environment. Through these innovations, this invention can overcome the problems of poor dynamic adaptation ability, low detection accuracy, and difficult security guarantee existing in the prior art, thereby providing an efficient, reliable, and intelligent solution applicable to security monitoring and defense in large-scale distributed router network architectures. Brief Description of the Drawings

[0055] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the following drawings.

[0056] Figure 1 It is a flowchart of the distributed network security monitoring method for communication engineering of the present invention.

[0057] Figure 2 It is a framework diagram of the distributed network security monitoring system for communication engineering of the present invention. Detailed Embodiments

[0058] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where like or similar reference numerals denote like or similar elements or elements having like or similar functions throughout. The embodiments described below by referring to the drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.

[0059] In one or more embodiments, as Figure 1 shown, a distributed network security monitoring method for communication engineering is disclosed. The method includes the following steps one to five:

[0060] Step 1: Among the various nodes in the distributed network, establish a quantum trust chain through quantum key distribution technology for realizing encrypted communication and identity authentication between nodes. Use the key pair generated by the quantum trust chain to authenticate the nodes joining the network. When a node joins, the system will perform double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain.

[0061] Specifically, in this step 1, the goal of the system is to establish a quantum trust chain through quantum key distribution (QKD) technology and use this trust chain to complete the identity authentication of each node in the network. This process relies on the security of quantum communication technology and the dynamic adjustment ability of the quantum trust chain mechanism to ensure the authenticity of node identities, the encryption strength of communication, and the integrity of data. The following is the detailed solution for this step, including the core mathematical formulas and variable explanations.

[0062] Furthermore, initialization of the quantum trust chain: In the network, each node needs to generate a quantum key pair (including a public key and a private key). To ensure the high security of the generation and distribution of the key pair, the quantum key distribution protocol (QKD) is adopted. First, the system initializes a quantum trust chain, and nodes establish a secure communication channel through the quantum key exchange protocol (such as the BB84 protocol).

[0063] Each node uses the quantum communication channel for initialization. Specifically, when initializing, node A and node B will share a quantum key K init , and the exchange process of the key is completed through quantum entanglement states. In this way, the quantum trust chain ensures that the encrypted communication between each node and other nodes in the network is secure and can prevent man-in-the-middle (MITM) attacks.

[0064] Furthermore, node identity authentication: The goal of node identity authentication is to ensure that the identity of each node can be verified by the system and that the behavior of the node in the network is not affected by malicious attacks. When each node joins the network, its identity is first authenticated using the key pair generated by the quantum trust chain. To ensure the immutability of each node's identity, a quantum key-based authentication protocol is used.

[0065] Specifically, when node A needs to communicate with node B, node A sends its public key K pub-A to node B and encrypts the information using the private key K priv-A in the quantum trust chain. After receiving the encrypted information, node B decrypts and verifies it through the quantum key exchange protocol to confirm whether the identity of node A is legal. The following formula is used during the verification process:

[0066] K pub-A = Dec(K priv-A , E comm ) (1)

[0067] where K pub-A is the public key of node A for identity authentication. K priv-A is the private key of node A for encrypting the communication content. E comm is the encrypted communication content. If the decryption result is consistent with the expectation, node B will consider node A trustworthy; otherwise, it will be marked as untrustworthy and reject the communication request.

[0068] Furthermore, in the system, the quantum trust chain is not static. During the actual application process, the trust value of a node will be dynamically updated according to its behavior and communication history. When any abnormal situation (such as data tampering, abnormal traffic) occurs during the communication between node A and node B, the quantum trust chain will update the trust level T A of node A according to its behavior. Specifically, the trust level of node A can be updated through the following formula:

[0069] T A = αT A + (1 - α)·ΔT A (2)

[0070] where T A is the current trust level of node A. α is a weighting factor representing the weight of historical behavior. ΔT A is the trust increment obtained by node A due to its current behavior, based on real-time threat assessment and anomaly detection results. This trust value T A will affect the subsequent communication permissions and access control of the node. For nodes marked as untrustworthy, their trust levels will be dynamically reduced or even completely isolated to ensure the security of the network.

[0071] Further, when a node joins, the system will perform double authentication on the node through the quantum trust chain. First, identity authentication is completed through quantum key exchange; then, the node proves its identity to other nodes in the network by submitting its public key K pub and private key signature S priv to other nodes in the network.

[0072] When a new node A joins, it first requests to join the network and submits an authentication request. Node A shares the quantum key pair it generates with other nodes in the network through the quantum trust chain. Other nodes decide whether to allow the node to enter the network based on the authentication result of A. If the authentication passes, node A will be assigned an initial trust level T A = 1, enter the trust chain and become part of the network.

[0073] The innovation of this step lies in achieving strong identity authentication and communication encryption for nodes through the quantum trust chain, enabling the trust level of nodes in the network and data exchange to be guaranteed by quantum encryption. This mechanism avoids the risks of node identity forgery and communication tampering in traditional methods, ensuring the authenticity of each node's identity and the immutability of the communication process in the network. Through the dynamic maintenance and update of the quantum trust chain, the network can isolate untrusted nodes in a timely manner, improving the overall security and robustness of the system.

[0074] Step 2: Real-time collect sensor data from each node in the network, organize and generate a time series matrix according to the time series, and use the time series matrix as unlabeled data to construct a loss function for a self-supervised contrastive learning task to train a self-supervised learning model, and output a feature representation Z t ; The sensor data includes network traffic information, CPU load, and temperature monitoring information.

[0075] Specifically, the goal of this step is to provide real-time anomaly detection capabilities for the network security monitoring system by real-time collecting sensor data from each node in the network and using a self-supervised learning model to initialize the training of the data. This process not only processes data from each node but also involves how to effectively analyze and warn of potential security threats through an innovative self-supervised learning framework in a real-time dynamic network environment.

[0076] Further, in step 1, the quantum trust chain has ensured the authenticity of each node and the data source and the confidentiality of data transmission. Each sensor (such as network traffic monitoring, device health status, temperature monitoring, etc.) regularly sends the network operation information it collects to the central system through the quantum trust chain. The present invention sets the data of each node as D i = {d1, d2,..., d n}, where each d j is the raw data collected by the j-th sensor at time t i The sensors of each node include multiple types of sensors, which are respectively responsible for monitoring tasks in different dimensions:

[0077] Network traffic information.

[0078] CPU load.

[0079] Temperature monitoring information.

[0080] Furthermore, this data is organized into a matrix X according to the time series i , and its structure is:

[0081]

[0082] This matrix X i becomes the input data for the subsequent self-supervised learning model.

[0083] Self-supervised learning model initialization: Contrastive learning and data preprocessing

[0084] Self-supervised learning avoids relying on manual labels by defining appropriate tasks, enabling the system to automatically extract features from the data and generate useful representations. To initialize the self-supervised learning model, the key in this step lies in how to perform meaningful learning on the sensor data through feature extraction.

[0085] The present invention introduces an innovative self-supervised learning framework based on contrastive learning and designs an enhanced regularization term on this basis to adapt to the dynamically changing data features in the distributed network system.

[0086] Furthermore, in the initialization stage of the self-supervised learning model, the present invention processes the data and learns features through the following steps:

[0087] a. Data standardization and denoising

[0088] First, the present invention standardizes the collected sensor data X i to reduce the difference in data dimensions between different sensors. Each data dimension d j is standardized through the following formula:

[0089]

[0090] where μ j is the mean of data d j , and σ j is its standard deviation. The standardized data Xi 'is fed into the subsequent model.

[0091] b. Self-supervised task construction and contrastive learning

[0092] To learn effective features from unlabeled data, the present invention introduces the idea of contrastive learning. Specifically, the present invention defines a self-supervised contrastive learning task based on sensor data:

[0093] Objective: To learn similar "positive sample" pairs and different "negative sample" pairs from sensor data through contrastive learning. The present invention constructs sample pairs based on the similarity in data X i 'to construct sample pairs.

[0094] First, the present invention samples two groups of samples from the data: a group of positive sample pairs (x i,positive , x j,positive ), which means two sensor data collected under similar network states; a group of negative sample pairs (x i,negative , x j,negative ), which means two sensor data collected under different network states.

[0095] Next, the model is trained through the following contrastive loss function:

[0096]

[0097] where f(x) represents the embedding vector obtained by the sensor data passing through the model network. sim(·,·) represents the similarity between two data points, usually calculated using cosine similarity:

[0098]

[0099] The positive sample pair (x i,positive , x j,positive ) is the sensor data of the similar network state, and the negative sample pair (x k,negative ) is the data of different network states. By minimizing the above first contrastive loss L contrastive , the model can learn the latent representation of the data.

[0100] c. Regularization term: enhancing network dynamic adaptability

[0101] To enhance the adaptability of the model to the dynamic network environment, the present invention introduces an innovative regularization term to constrain the feature learning process of the model. This regularization term aims to balance the stability and dynamic adaptability of data features and prevent the model from overfitting to past static features during real-time data updates. The innovative regularization term is in the form of:

[0102]

[0103] Where: λ1 and λ2 are hyperparameters used to balance different regularization terms. is the gradient of the model parameter θ. Cov(·) is the covariance matrix of the model output, which is used to measure the range of feature variation. |det(·)| is the determinant of the covariance matrix, which measures the diversity of the feature space. This regularization term helps to enhance the dynamic balance in the feature learning process, enabling the model to better adapt to real-time data changes from each node.

[0104] Furthermore, the output of this step will be a self-supervised learning model that has been initialized and can automatically extract features from real-time sensor data and perform incremental training when the data changes. As the network environment changes, newly collected data will be promptly transmitted to the model for updating and adjustment. The model parameter θ is continuously adjusted according to the real-time data to ensure continuous and effective monitoring of the network status in a dynamic environment. The update formula for incremental training is:

[0105]

[0106] where η t is the learning rate, which is gradually adjusted with the time step t. is the gradient of the loss function L contrastive with respect to the model parameter θ. This incremental training method ensures that the model can adapt to the new network environment and respond promptly to any abnormal changes.

[0107] This step enables the system to automatically extract from the raw data by collecting real-time sensor data from different nodes and applying an innovative self-supervised learning framework.

[0108] Step Three: Based on the feature representation Z t , combined with the quantum trust chain, perform anomaly analysis on each node through the reconstruction error, and distinguish different threat types through contrast learning based on the results of the anomaly analysis to obtain feedback information.

[0109] Specifically, in Step Two, the present invention has initialized the feature extraction model through self-supervised learning (including contrast learning and regularization terms) and ensured that the model can adapt to changes in the network environment in real time through incremental learning. At this time, the model can automatically extract high-quality feature representations Z t . The goal of this step is to achieve anomaly detection and threat recognition based on these feature representations.

[0110] Furthermore, anomaly behavior detection and reconstruction error calculation:

[0111] In this step, the present invention will use the output feature Z of the self-supervised learning model tTo calculate the anomaly degree. Specifically, the present invention calculates the reconstruction error E of each data point by inputting the feature Z t into a reconstruction module (such as an autoencoder), and determines whether there is an abnormal behavior based on this error. t Specifically, the reconstruction error calculation: for each sensor data point Z

[0112] , it is reconstructed through the decoder of the self-supervised learning model t to obtain the reconstructed data The reconstruction error E is defined as the Euclidean distance between the original data and the reconstructed data: t

[0113]

[0114] where Z t is the data feature representation at the t-th moment, is the data after model reconstruction.

[0115] Anomaly detection decision: when the reconstruction error E t exceeds a certain dynamic threshold θ t , it is determined that this data point is abnormal. This threshold is automatically adjusted according to the error distribution in historical data, and the threshold θ t is defined by the following formula:

[0116] θ t = μ t + λ·σ t (11)

[0117] where μ t is the mean of the reconstruction errors in the previous time period, σ t is the standard deviation, and λ is a hyperparameter that controls the sensitivity to error fluctuations.

[0118] For each sensor data point Z t , the anomaly score A t output by the model reflects the anomaly degree of this data point. The anomaly score A t is calculated by the following formula:

[0119]

[0120] If A t exceeds the preset threshold, it is considered an abnormal data point.

[0121] Threat recognition based on self-supervised learning: After detecting potential abnormal data, the next step is to identify whether these anomalies belong to a certain network threat. To perform threat classification, the present invention uses the features Z generated by self-supervised learning t, and further distinguish different threat types through the feature space obtained by contrastive learning training.

[0122] Feature space of contrastive learning: In this step, a contrastive learning-based framework is adopted to optimize the feature space, making similar threat types closer in the feature space and keeping different types of threats at a greater distance. By minimizing the contrastive loss function The present invention can extract different types of threat behaviors from historical data and construct feature representations for them.

[0123] Contrastive loss function: The second contrastive loss function is in the following form:

[0124]

[0125] where f(Z t ) represents the feature embedding generated by the self-supervised learning model for the data point Z t , and sim represents the cosine similarity. The positive sample pair (Z t , Z t' ) are similar network states, and the negative sample pair Z k represents data in different states.

[0126] Threat classification: Using the trained feature representations, the present invention can input each data point Z t into a classifier (such as a support vector machine SVM or a multi-layer perceptron MLP) to classify the data point into different types of network threats. The classifier determines whether the data point constitutes a certain attack (such as a DDoS attack, malware intrusion, etc.) according to the relative position in the feature space.

[0127] Incremental learning and model update: Network attacks are dynamic, so the self-supervised learning model needs to be continuously updated to cope with new threats. For this purpose, the present invention uses an incremental learning method to update the parameters θ of the self-supervised learning model after detecting a new threat pattern. The update of the model parameters is given by the following formula:

[0128]

[0129] where η t is the learning rate, which is gradually adjusted with the time step t, represents the gradient of the loss function with respect to the model parameters.

[0130] Step Four: Combine the feature representation Z t , the node behavior history of the node, and the feedback information to dynamically evaluate the trustworthiness of each node in the network, and update the global trust chain based on the trustworthiness of each node to obtain the trustworthiness of the global trust chain.

[0131] Specifically, in step 4, the goal of the present invention is to perform dynamic trust evaluation and update based on the quantum trust chain to ensure that in a real-time network environment, the credibility of data transmission and calculation results can be accurately updated over time, ultimately providing more reliable trust guarantee for the network security monitoring system. Specifically, the solution of the present invention will introduce the combination of the quantum trust chain and dynamic trust evaluation, and dynamically update the trust value of each node according to the relationship between sensor data, system feedback, and previous evaluation results, and adjust the trust degree of node behavior in real time. This process can effectively cope with network attacks, malicious node behaviors, and other factors that may damage the trust chain.

[0132] The input of this step comes from the feature representation Z output by the self-supervised learning model in step 3 t , as well as the node status information dynamically generated by the system in previous steps (such as node historical performance, data transmission frequency, quality, etc.). On this basis, the trust evaluation algorithm will comprehensively consider the following factors to calculate the trust degree of each node:

[0133] Sensor data features: The sensor data Z of each node t reflects its status and is represented as a high-dimensional vector. The self-supervised learning model has extracted effective features from these data.

[0134] Node behavior history: The impact of whether the node frequently exhibits abnormal behaviors (such as data transmission not meeting expectations, being attacked, data loss, etc.) in history on the node trust degree.

[0135] System feedback information: The feedback received from the system (such as anomaly detection results, warning information, etc.) will also affect the trust evaluation result, specifically by dynamically updating the trust degree through the weighted average of the feedback information.

[0136] Furthermore, to achieve dynamic trust evaluation, the present invention proposes a calculation method based on the quantum trust chain, which dynamically adjusts the trust degree by combining node features and historical behaviors, and enhances the adaptability of the model to the trust update process through the superposition and entanglement features in the quantum chain.

[0137] Trust degree T t The update can be expressed as:

[0138] T t = α·Similarity(Z t , Z t-1 ) + β·History(H t-1 ) + γ·Feedback(F t-1 ) (15)

[0139] Where Z tis the feature representation extracted from sensor data at the current moment, Z t-1 is the feature representation at the previous moment. Similarity(Z t , Z t-1 ) represents the similarity between the current feature and the historical feature, which is calculated using cosine similarity:

[0140]

[0141] where, H t-1 represents the historical behavior performance of the node at the previous time step, such as the number of successful transmissions, the number of failed transmissions, etc. This historical behavior can be converted into a trust weight value. F t-1 is the information obtained by the system from the previous feedback, such as whether an anomaly detection result has occurred, the severity of the anomaly, etc. The trust degree is updated based on the feedback-based weighting method. α, β, γ are hyperparameters used to adjust the weight of each factor in the trust degree update process.

[0142] The trust degree T t has a value range of [0, 1], where 0 represents complete distrust and 1 represents complete trust. The present invention dynamically adjusts the system's dependence on the node according to the trust degree of the node. For example, during the anomaly detection process, if the trust degree of the node is low, the influence of the node on the detection result is reduced.

[0143] Furthermore, in order to enhance the robustness of trust update, combined with the characteristics of the quantum trust chain, the present invention introduces the concept of quantum entanglement to adjust the trust degree update process of the node. Specifically, by constructing a quantum trust chain, the present invention can make the trust degree of the node not only affected by its own historical data, but also affected by the quantum entanglement with other nodes, forming a dynamic and interactive trust evaluation system.

[0144] The present invention defines the trust degree update process of each node as follows:

[0145]

[0146] where, is the trust degree adjusted by quantum entanglement. ε(Z t , Z t-1 ) represents the quantum entanglement degree between the current node and the node at the previous moment. The quantum entanglement degree ε can be measured by the correlation of the eigenvectors between nodes. For example, the similarity of the eigenvectors is measured by quantum state similarity:

[0147]

[0148] Among them, λ is a hyperparameter used to adjust the influence degree of quantum entanglement on the update of trust degree. Through this method, the node trust degree is not only related to its own behavior, but also closely related to the interaction with other nodes, enhancing the multi-dimensionality and dynamics of trust degree calculation.

[0149] Furthermore, the update of the trust chain not only needs to consider the trust degree of a single node, but also needs to consider the trust interaction relationship among multiple nodes. The update of the trust degree of each node will affect the trust chain of other nodes. Therefore, the update of the trust chain must maintain consistency.

[0150] To achieve this goal, the present invention updates the global trust chain through the following steps:

[0151]

[0152] Among them, is the trust degree of the global trust chain. is the trust degree of each node i (the trust degree adjusted by the quantum entanglement mechanism). N is the total number of nodes.

[0153] By averaging the trust degrees of each node, the global trust chain is updated, and the global trust chain is used for system decision-making and anomaly detection in the next step. The continuous update of the trust chain enables the system to adapt to the changes in node behavior in the network environment and respond to new threats and attacks in a timely manner.

[0154] Through the dynamic trust evaluation and update mechanism based on the quantum trust chain, the present invention provides an efficient and dynamic trust management scheme for the network security monitoring system. In this scheme, the trust degree of a node is not only affected by its historical behavior and current data, but also regulated by the quantum entanglement relationship with other nodes, thereby enhancing the sensitivity and adaptability of the system to node behavior. This scheme can effectively cope with the dynamic changes in the network environment and ensure that the network security monitoring system can accurately identify potential security threats.

[0155] Step Five: Determine the defense intensity of the network at the current moment through the trust degree of the global trust chain, and dynamically adjust the response measures based on the defense intensity at the current moment and the trust degree of the global trust chain.

[0156] Specifically, in step five, the objective of the present invention is to design an adaptive defense and response mechanism based on threat recognition and trust assessment. This mechanism will combine the threat detection and trust assessment results in the previous steps and perform real-time defense and response according to the current network state and the dynamic changes of the trust chain. Through the real-time recognition of threats and the adjustment of node trust levels, the defense system of the present invention can adaptively adjust the defense strategy according to the specific threat types and the behavior performance of nodes, ensuring that the system can quickly respond and guarantee network security when facing different types of attacks.

[0157] Further, the input of this step comes from the trust level update result generated in step four and the global trust chain dynamically adjusted through the quantum trust chain These trust level metrics provide the basis for the defense mechanism to judge the credibility of node behavior. Another input is the output of the threat recognition module This output represents the threat types recognized in the current system, which may include network attacks (such as DDoS attacks, data tampering, malware propagation, etc.) or abnormal behaviors.

[0158] Further, based on the trust level and threat recognition results, the objective of the present invention is to dynamically adjust the defense strategy. To ensure the flexibility and effectiveness of the defense, the present invention proposes a mechanism for dynamically adjusting the defense intensity based on the trust level. Specifically, the defense intensity S t can be calculated by the following formula:

[0159]

[0160] where S t is the defense intensity at the current moment. is the node trust level adjusted through the quantum trust chain. is the output of the threat recognition module, representing the type and severity of the current threat (for example, represents an ordinary network attack, represents a high-intensity DDoS attack). λ1 and λ2 are hyperparameters used to adjust the influence of the trust level and threat type on the defense intensity.

[0161] Through this formula, the system can automatically adjust the defense intensity according to the current trust level of the node and the recognized threat type. Nodes with a higher trust level may require a lower defense intensity, while nodes with a low trust level will activate stronger defense measures. The more severe the threat type, the higher the corresponding defense intensity.

[0162] Further, after the defense intensity is determined, the system determines the appropriate defense actions according to the current defense intensity S t and the global information of the trust chain to implement specific response measures. These response measures include, but are not limited to:

[0163] Enhance firewall filtering: For attacks with a high threat level, the system can automatically enhance the firewall's filtering rules.

[0164] Adjust node weights: On nodes with a low level of trust, the system can reduce their influence in overall decision-making. For example, reduce data transmission or computing task allocation to low-trust nodes.

[0165] Isolate nodes in real time: For nodes determined to be malicious or untrusted, the system will temporarily isolate the node to prevent it from further participating in network activities.

[0166] The decision-making in the dynamic response process can be expressed as:

[0167]

[0168] where represents the response strategy at the current moment (such as node isolation, weight adjustment, firewall enhancement, etc.). S t is the defense strength calculated based on trust degree and threat recognition. is the current trust degree of the global trust chain.

[0169] This function makes response decisions based on the current defense strength and the trust degree of the global trust chain. By comprehensively judging the network security status, the system can flexibly adjust the response strategy. The details of specific responses depend on the preset strategies of the system and the security situation monitored in real time.

[0170] Furthermore, as the defense strategy is implemented, the system will continuously monitor the defense effect and the changes in the network security status. After each round of defense response, the system needs to update the trust chain based on real-time feedback. Assume that after the defense response, the trust degree evaluation result of the system changes. At this time, the present invention needs to update the trust degree of the nodes.

[0171] The updated trust degree can be adjusted in the following way:

[0172]

[0173] where T t ' is the updated trust degree after defense. S t is the defense strength, reflecting the impact of the defense response on the nodes. is the trust degree after adjustment of the quantum trust chain. α and β are adjustment coefficients used to balance the influence of the defense strength and the trust degree on the final trust degree of the nodes.

[0174] By dynamically adjusting the trust level, the system can conduct long-term tracking and real-time response to the behaviors of nodes in the network, ensuring the continuous security of the network environment.

[0175] Furthermore, ultimately, after multiple rounds of adaptive defense and response, the system will provide feedback based on the defense effect and adjust the defense strategy for the next round. For example, in the case of no new threats for a long time, the system may gradually reduce the defense intensity and return to the normal network operation state. The feedback mechanism can be expressed as:

[0176]

[0177] where is the feedback result, which determines the adjustment of the defense strategy for the next round. S t is the current defense intensity. T t ' is the updated trust level after defense.

[0178] This feedback mechanism ensures that the system can automatically optimize the defense strategy according to the actual defense effect and the evolution of the trust chain, enhancing the overall anti-attack ability of the system.

[0179] The adaptive defense and response mechanism based on threat recognition and trust assessment enables the system to flexibly adjust the defense intensity according to the node trust level and real-time threat intelligence, and dynamically implement response strategies on this basis. Through the adjustment of the trust level and the optimization of the defense strategy by the quantum trust chain, the system can effectively cope with various complex network security threats and ensure the long-term security and stability of the network environment.

[0180] In one or more embodiments, as Figure 2 shown, a distributed network security monitoring system for communication engineering is disclosed. The system includes:

[0181] Quantum trust chain module 101: used to establish a quantum trust chain among various nodes in the distributed network through quantum key distribution technology for realizing encrypted communication and identity authentication between nodes. Using the key pair generated by the quantum trust chain, it authenticates the nodes joining the network. When a node joins, the system will conduct double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain;

[0182] Data acquisition and model training module 102: used to collect sensor data from each node in the network in real time, organize and generate a time series matrix according to the time series, and train a self-supervised learning model with the loss function of the self-supervised contrast learning task constructed with the time series matrix as unlabeled data, and output the feature representation Z t ; The sensor data includes network traffic information, CPU load, and temperature monitoring information;

[0183] Anomaly Detection and Threat Recognition Module 103: It is used to perform anomaly analysis on each node based on the reconstruction error by combining the quantum trust chain based on the feature representation Z t , and distinguish different threat types through contrastive learning based on the results of the anomaly analysis to obtain feedback information;

[0184] Dynamic Trust Evaluation Module 104: It is used to dynamically evaluate the trust level of each node in the network by combining the feature representation Z t , the node behavior history of the node and the feedback information, and update the global trust chain based on the trust level of each node to obtain the trust level of the global trust chain;

[0185] Adaptive Defense and Response Module 105: It is used to determine the defense strength of the network at the current moment through the trust level of the global trust chain, and dynamically adjust the response measures based on the defense strength at the current moment and the trust level of the global trust chain;

[0186] Wherein, the response measures at least include one of the following: enhancing firewall filtering, adjusting node weights, and isolating nodes in real time.

[0187] It should be noted that the specific working process of the distributed network security monitoring system for communication engineering provided by the embodiments of the present invention is the same as the process of the distributed network security monitoring method for communication engineering described in the above embodiments, and will not be elaborated here.

[0188] Compared with the prior art, the distributed network security monitoring system for communication engineering provided by the embodiments of the present invention collects and generates NFC interaction data, extracts and models historical usage data to construct a feature vector, constructs a scenario prediction model based on the feature vector to predict future usage scenarios; according to the scenario prediction results, generates a priority list of loading data; adjusts the strategy of the loading data priority list according to the real-time signal strength to obtain an adjusted loading set; constructs a dynamically decoded tree structure with optimized dependencies, and parses the loaded data from the adjusted loading set to ensure that the data can be provided to users in time. Optimize the scenario prediction model and loading strategy based on the feedback data during the loading process to form a closed-loop optimization.

[0189] The embodiments of the present invention also provide a distributed network security monitoring device for communication engineering, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the steps in the embodiments of the distributed network security monitoring method for communication engineering as described above, such as Figure 1 the steps S1-S5 described therein; or, when the processor executes the computer program, it implements the functions of each module in the above system embodiments.

[0190] Exemplarily, the computer program may be divided into one or more modules, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the distributed network security monitoring device for communication engineering.

[0191] The distributed network security monitoring device for communication engineering may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The distributed network security monitoring device for communication engineering may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the distributed network security monitoring device for communication engineering may further include input / output devices, network access devices, a bus, etc.

[0192] The processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the distributed network security monitoring device for communication engineering, and connects various parts of the entire distributed network security monitoring device for communication engineering through various interfaces and lines.

[0193] The memory may be used to store the computer program and / or modules. The processor realizes various functions of the distributed network security monitoring device for communication engineering by running or executing the computer program and / or modules stored in the memory, and by calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the operation of the air-conditioning controller, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0194] Among them, if the modules integrated in the distributed network security monitoring device for communication engineering are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0195] Those of ordinary skill in the art can understand that to implement all or part of the processes in the above-described embodiment methods, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-described various method embodiments. Among them, the storage medium can be a magnetic disk, optical disc, read-only memory (ROM), or random access memory (RAM), etc.

[0196] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and refinements can still be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A distributed network security monitoring method for communication engineering, characterized in that, The method includes: Step 1: Establish a quantum trust chain among various nodes in the distributed network through quantum key distribution technology to achieve encrypted communication and identity authentication among nodes. Use the key pair generated by the quantum trust chain to authenticate the nodes joining the network. When a node joins, the system will perform double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain; Step 2: Collect sensor data from each node of the network in real time, organize and generate a time series matrix according to the time series, and use the time series matrix as unlabeled data to construct a loss function for the self-supervised contrastive learning task to train the self-supervised learning model, and output the feature representation Z t ; The sensor data includes network traffic information, CPU load, and temperature monitoring information; Step 3. Based on the feature representation Z t , combined with the quantum trust chain, perform anomaly analysis on each node through the reconstruction error, and distinguish different threat types through contrastive learning based on the results of the anomaly analysis to obtain feedback information; Step 4: Combine the feature representation Z t , the node behavior history and feedback information of the nodes, dynamically evaluate the trustworthiness of each node in the network, and update the global trust chain based on the trustworthiness of each node to obtain the trustworthiness of the global trust chain; Step 5: Determine the defense strength of the network at the current moment based on the trust degree of the global trust chain, and dynamically adjust the response measures based on the defense strength at the current moment and the trust degree of the global trust chain; Among them, the response measures include at least one of the following: enhancing firewall filtering, adjusting node weights, and isolating nodes in real time.

2. The distributed network security monitoring method for communication engineering according to claim 1, wherein The establishment of the quantum trust chain through quantum key distribution technology to achieve encrypted communication and identity authentication among nodes is specifically as follows: Initialize each node separately using a quantum communication channel; among them, nodes A and B will share a quantum key K during initialization init , and the exchange process of its key is completed through a quantum entangled state; When node A needs to communicate with node B, node A sends its public key K pub-A to node B and encrypts this information with the private key K priv-A in the quantum trust chain. After receiving the encrypted information, node B decrypts and verifies it through the quantum key exchange protocol to confirm whether the identity of node A is legal; If the decryption result is consistent with the expectation, node B will consider node A to be trustworthy; otherwise, it will be marked as untrustworthy and the communication request will be rejected.

3. The distributed network security monitoring method for communication engineering according to claim 1, characterized in that Step 1 further includes: When any abnormal situation occurs during the communication between node A and node B, the quantum trust chain will update its trust level according to the behavior of node A.

4. The distributed network security monitoring method for communication engineering according to claim 1, characterized in that, Training the self-supervised learning model with the loss function of the self-supervised contrastive learning task constructed from the time series matrix as unlabeled data, and outputting the feature representation Z t , specifically: Sample two sets of samples from the data: one set of positive sample pairs (x i,positive , x j,positive ), which means two sensor data collected under similar network states; one set of negative sample pairs (x i,negative , x j,negative ), which means two sensor data collected under different network states; Based on the positive sample pair (x i,positive , x j,positive ) and the sample pair (x i,negative , x j,negative ), construct the first loss function of the self-supervised learning model. By minimizing the first loss function, the self-supervised learning model can learn the latent representation of the data; Perform hyperparameter weighted summation on the gradient of the model parameters of the self-supervised learning model and the determinant of the covariance matrix of the output to obtain a regularization term, and use the regularization term to constrain the feature learning process of the self-supervised learning model. The feature representation Z after the completion of output feature learning t .

5. The distributed network security monitoring method for communication engineering according to claim 4, characterized in that, The feature representation Z t , combined with the quantum trust chain, performs anomaly analysis on each node through the reconstruction error, specifically as follows: For the feature representation Z t , it is reconstructed through the decoder of the self-supervised learning model to obtain the reconstructed data For the feature representation Z t and the reconstructed data perform Euclidean distance analysis to obtain the reconstruction error; When the reconstruction error exceeds a certain dynamic threshold, it is determined that the data point is abnormal; among them, the dynamic threshold is automatically adjusted according to the error distribution in historical data.

6. The distributed network security monitoring method for communication engineering according to claim 5, wherein, The differentiation of different threat types based on the result of anomaly analysis through contrastive learning is specifically as follows: After detecting potential abnormal data, based on the feature representation Z t , optimize the first loss function to identify different threat types; Among them, the optimization of the first loss function specifically includes: Based on the feature representation Z t Construct positive samples (Z t , Z t' ), indicating similar network states, then the negative sample pair Z k represents data in different states, and generates the second loss function Among them, f(Z t ) represents the feature embedding generated by the self-supervised learning model for the data point Z t ; f(Z t' ) represents the feature embedding generated by the self-supervised learning model for the data point Z t' ; f(Z k ) represents the feature embedding generated by the self-supervised learning model for the data point Z, and sim represents the cosine similarity.

7. The distributed network security monitoring method for communication engineering according to claim 1, characterized in that The cosine similarity of the feature representation Z t is weighted and summed with the node behavior history and feedback information of the nodes to obtain the trustworthiness of each node in the network; Among them, the update of the global trust chain based on the trust degree of each node to obtain the trust degree of the global trust chain is specifically as follows: Calculate the trust degree of each node according to the quantum entanglement degree between the current node and the node at the previous moment; among them, the quantum entanglement degree is measured by the correlation of the eigenvectors between nodes; Perform aggregation analysis based on the trust degree of each node to obtain the trust degree of the global trust chain.

8. The distributed network security monitoring method for communication engineering according to claim 1, characterized in that The determination of the defense strength of the network at the current moment based on the trust degree of the global trust chain and the dynamic adjustment of the response measures based on the defense strength at the current moment and the trust degree of the global trust chain specifically include: Determine the defense strength at the current moment according to the trust degree of the global trust chain and the threat type; Implement response measures based on the defense strength and the trust degree of the global trust chain; update the trust degree of the node according to the implementation of the response measures; After multiple adaptive defenses and responses, perform feedback based on the defense effects of multiple rounds and adjust the defense strategy for the next round.

9. A distributed network security monitoring system for communication engineering, characterized in that, The system includes: Quantum Trust Chain Module: It is used to establish a quantum trust chain among various nodes in a distributed network through quantum key distribution technology, for realizing encrypted communication and identity authentication between nodes. Using the key pair generated by the quantum trust chain, it authenticates the nodes joining the network. When a node joins, the system will conduct double authentication on the node through the quantum trust chain and add the authenticated node to the quantum trust chain; Data Acquisition and Model Training Module: It is used to collect sensor data from each node of the network in real time, organize and generate a time series matrix according to the time series, construct a loss function for the self-supervised contrastive learning task with the time series matrix as the unlabeled data to train the self-supervised learning model, and output the feature representation Z t ; The sensor data includes network traffic information, CPU load, and temperature monitoring information; Anomaly Detection and Threat Recognition Module: used to perform anomaly analysis on each node based on the reconstruction error by combining the quantum trust chain with the feature representation Z, and distinguish different threat types through contrastive learning based on the results of the anomaly analysis to obtain feedback information; t , combined with the quantum trust chain, perform anomaly analysis on each node through the reconstruction error, and distinguish different threat types through contrastive learning based on the results of the anomaly analysis to obtain feedback information; Dynamic trust evaluation module: used to combine the feature representation Z t , the node behavior history and feedback information of the node, dynamically evaluate the trust level of each node in the network, and update the global trust chain based on the trust level of each node to obtain the trust level of the global trust chain; Adaptive Defense and Response Module: It is used to determine the current defense intensity of the network based on the trust level of the global trust chain, and dynamically adjust response measures based on the current defense intensity and the trust level of the global trust chain; Among them, the response measures at least include one of the following: enhancing firewall filtering, adjusting node weights, and isolating nodes in real time.