Satellite network threat analysis system based on AI

By generating threat analysis systems with adversarial networks and dynamic calibration mechanisms, the satellite network threat identification model is automatically optimized, which solves the problems of high cost of manual protection and poor real-time performance, and achieves fast and accurate threat response.

CN120358086AActive Publication Date: 2025-07-22GOLDEN SHIELD TESTING TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510829529.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-22
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

Existing satellite network security protection relies on manual screening of threat behaviors, resulting in high costs and poor real-time performance, making it difficult to deal with changes in dynamic threats.

Method used

A threat analysis system based on generative adversarial network is adopted, combined with a dynamic calibration mechanism, and the model performance is automatically optimized to achieve real-time and accurate threat recognition by generating virtual data and discriminant models.

Benefits of technology

It improves the real-time and protection accuracy of satellite network threat identification, reduces manual operation and maintenance costs, and can quickly respond to new threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358086A_ABST
    Figure CN120358086A_ABST
Patent Text Reader

Abstract

The invention discloses an AI-based satellite network threat analysis system, and the system comprises a training module which constructs a data generator, generates virtual data, and integrates threat data and the virtual data into a data package; the distinguishing module is used for constructing a data discriminator and carrying out first distinguishing on all data in the data packet; the judgment module adjusts the data generator according to the first judgment result, and takes the first judgment result exceeding the limit probability as a termination condition; the calibration module introduces the security data and the threat data through the database, and introduces the security data and the threat data into the discrimination module for second discrimination; the calibration module generates a reward index according to the second discrimination result, and dynamically adjusts a data discriminator in the discrimination module according to the reward index until the reward index exceeds a limit value; the data generation discrimination model is constructed based on the generative adversarial network, the model performance is continuously optimized in combination with a dynamic calibration mechanism, and the problems of low manual protection efficiency and poor real-time performance are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an AI-based satellite network threat analysis system. Background Art

[0002] In recent years, with the wide use of satellite network systems, the communication security protection problem of satellite networks affects the security of every user within the Internet.

[0003] Currently, there are many problems in the security protection of satellite networks. In particular, the current satellite network security requires manual screening of each type of threat behavior and formulation of protection strategies. For the construction of a protection system, it requires a large amount of manpower and material resources, and it also needs to be frequently updated according to the threat behaviors that change in real time. For the constructors of satellite networks, the cost is huge. Summary of the Invention

[0004] The present invention provides an AI-based satellite network threat analysis system, which constructs a data generation and discrimination model based on a generative adversarial network through a threat analysis subsystem, and continuously optimizes the model performance in combination with a dynamic calibration mechanism, solving the problems of low efficiency and poor real-time performance of manual protection, and having the advantages of improving the real-time performance of threat recognition and reducing the manual operation and maintenance cost.

[0005] To solve the above technical problems, the present invention provides the following technical solutions: An AI-based satellite network threat analysis system, comprising: A training module, which constructs a data generator, generates virtual data, and integrates threat data and virtual data into data packets; A discrimination module, which constructs a data discriminator to perform a first discrimination on all data in the data packet; the discrimination module adjusts the data generator according to the first discrimination result, and takes the first discrimination result exceeding a defined probability as the termination condition; A calibration module, which introduces security data and threat data through a database, and introduces the security data and threat data into the discrimination module for a second discrimination; the calibration module generates a reward index based on the second discrimination result, and dynamically adjusts the data discriminator in the discrimination module according to the reward index until the reward index exceeds a defined value.

[0006] Preferably, it further includes a data receiving module, a data encryption module, and a data transmission module; The data receiving module is used to receive real data sent by a terminal, and send the real data to the discrimination module to determine whether it is threat data; The data encryption module encrypts the data to ensure the security of the data during transmission; The data transmission module adopts a multi-path transmission protocol and sends the encrypted data to the satellite network through multiple transmission paths.

[0007] Preferably, the training module includes a data preprocessing unit, a model construction unit, and a model training unit; The data preprocessing unit obtains threat data, performs cleaning, normalization, and feature extraction operations on the threat data, removes noise and missing values, and extracts feature vectors from the threat data; The model construction unit constructs a data generator based on a generative adversarial network; wherein, the data generator is used to generate virtual data simulating network security threat behaviors; The model training unit uses the preprocessed threat data to train the generative adversarial network and optimize the loss function of the generator within the generative adversarial network.

[0008] Preferably, the discrimination module constructs a data discriminator based on a generative adversarial network; wherein, the data discriminator performs a first discrimination on each piece of data in the data packet to distinguish whether each piece of data in the data packet belongs to threat data or virtual data; The discrimination module adjusts the data generator according to the results of the first discrimination and optimizes the loss function of the discriminator within the generative adversarial network.

[0009] Preferably, it further includes a monitoring module; The monitoring module constructs a screening model and performs corresponding monitoring processing on the real data according to the discrimination probability of the discrimination module on whether the real data is threat data; The screening model includes: ; Wherein, is the discrimination probability; The first monitoring processing is specifically to directly send a type I alarm to the server platform of the satellite network threat analysis system and directly intercept it; The second monitoring processing is that when this real data file is sent from a high-risk transmission end, a type I alarm is directly sent to the server platform of the satellite network threat analysis system and directly intercepted; The third monitoring processing is that when this real data file flows to the core marking area, a type II alarm is sent to the server platform to inform the supervisors to conduct a review; The fourth monitoring processing is that when this real data flows to an area that requires high-authority authorization, a type II alarm is sent to the server platform to inform the supervisors to conduct a review.

[0010] Preferably, the discrimination module further includes a result evaluation unit and a feedback adjustment unit; The result evaluation unit conducts a quantitative evaluation of the first discrimination result and the second discrimination result, calculates the accuracy rate, recall rate, and F1 value metrics for discriminating various types of threat data, and generates an evaluation report; The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator according to the metric data in the evaluation report, and feeds back the adjusted hyperparameters to the model training process to achieve continuous improvement of the model.

[0011] Preferably, the calibration module introduces the security data and threat data into the discrimination module for the second discrimination, and the discrimination module distinguishes whether each piece of data belongs to security data or threat data.

[0012] Preferably, the calibration module further includes a data screening unit and a weight assignment unit; The data screening unit screens and filters the security data and threat data in the database according to the dimensions of timeliness, relevance, and credibility of the data, and selects representative and valuable data samples for the second discrimination; The weight assignment unit assigns different weight coefficients to the data samples according to the importance and influence of the data samples, so that the contribution differences of different data samples can be fully considered when calculating the reward index, thereby improving the accuracy and effectiveness of the calibration process.

[0013] Preferably, it further includes a threat response module; The threat response module is connected to the discrimination module and is used to formulate corresponding threat response strategies according to the discrimination results output by the discrimination module; The threat response strategies include but are not limited to blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rule measures; the threat response module can dynamically adjust the priority and intensity of the response strategies according to factors such as the type, severity, and impact scope of the threat, so as to achieve fast, accurate, and effective disposal of satellite network threats.

[0014] Preferably, the threat response module further includes a response evaluation unit and an effect feedback unit; The response evaluation unit monitors and evaluates the execution effect of the threat response strategy in real time, collects relevant metric data, and the relevant metric data includes the attack blocking success rate, system recovery time, and business impact degree, and generates a detailed response evaluation report; The effect feedback unit feeds back the key information in the response evaluation report to the training module, discrimination module, and calibration module in the threat analysis subsystem, so that each module can further optimize its own functions and performance according to the feedback information of the response effect, forming a closed threat analysis and response optimization loop, and continuously improving the security protection ability and intelligent level of the entire system.

[0015] Advantages of the present invention: A satellite network threat analysis system based on AI provided by the present application, through the threat analysis subsystem constructs a data generation and discrimination model based on the generative adversarial network, continuously optimizes the model performance in combination with the dynamic calibration mechanism, and at the same time introduces a closed-loop threat response mechanism, solves the problems of low efficiency and poor real-time performance of manual protection, and has the advantages of improving the real-time performance of threat recognition, enhancing the accuracy of protection, and reducing the manual operation and maintenance cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flowchart of a satellite network threat analysis system based on AI provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be given in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments.

[0018] In the prior art, the security protection of satellite network communication has long relied on manual screening of threat behaviors and formulation of protection strategies. However, due to the dynamic change characteristics of threat behaviors, traditional methods need to continuously invest a large amount of human resources to update the rule base, resulting in a high system maintenance cost. Moreover, the existing protection systems have a lag in the face of new and unknown threats and cannot meet the real-time security protection requirements of satellite networks. This manual-dominated protection mode is prone to response delays and protection loopholes in the face of massive data transmission scenarios, threatening the overall security of satellite networks.

[0019] To solve the above problems, referring to Figure 1 , the present invention proposes a satellite network threat analysis system based on AI, including a data intermediate subsystem and a threat analysis subsystem. The data intermediate subsystem is responsible for data transmission between the terminal and the satellite network. The threat analysis subsystem includes a training module, a discrimination module and a calibration module. The training module constructs a data generator that generates virtual data, and integrates real threat data to form a training data packet. The discrimination module performs the first threat recognition on the data packet through the discrimination model, and optimizes the generation model according to the recognition result. The calibration module introduces security data and threat data for secondary discrimination, and dynamically adjusts the discrimination model parameters through the reward index until the performance index is reached.

[0020] Among them, the data rotor system refers to the infrastructure for establishing a secure transmission channel, which can be implemented using a multi-path encryption transmission protocol. The integrity and confidentiality of the original data transmission are ensured through parallel transmission paths and data encryption technologies. The threat analysis subsystem refers to an intelligent threat recognition architecture, which is specifically constructed using a generative adversarial network framework. The threat detection ability is enhanced through the adversarial training mechanism of the generator and the discriminator. The training module refers to a virtual data generation unit, which can specifically use a deep neural network to construct a generator. Synthetic data with threat behavior characteristics is generated through feature space mapping to expand the diversity of training samples. The discriminant module refers to a threat recognition unit, which can specifically use a convolutional neural network to construct a classifier. The discriminant threshold is continuously optimized through the gradient backpropagation mechanism. The calibration module can use a reinforcement learning algorithm to construct an evaluation mechanism. The performance metrics of the generation model are generated through the mixed verification of secure data and threat data to ensure the continuous improvement of the recognition accuracy.

[0021] Specifically, during the data transmission process, the data rotor system ensures the security of the original data through an encrypted channel. The threat analysis subsystem first uses a generative adversarial network to generate virtual data with attack characteristics, which together with real threat data constitutes an enhanced training set. The discriminant module conducts the first classification and recognition of the mixed data set, and adjusts the generator parameters according to the misjudgment situation to improve the authenticity of the virtual data. At this time, through the cyclic confrontation between the generator and the discriminator, the discriminator's judgment ability for real threat data is improved. The calibration module introduces labeled secure samples for secondary verification, and generates a reward index by calculating the classification accuracy of the discriminator. When the reward index does not reach the preset threshold, the system automatically adjusts the weight of the discriminator, forming a closed-loop optimization cycle of generation-discrimination-calibration. This dual training mechanism enables the discriminant model to not only strengthen the recognition of known threat patterns but also learn potential attack characteristics through virtual data, achieving comprehensive coverage of new and old threats. At the same time, through the closed-loop optimization cycle, the discrimination method for threat data can be automatically updated and generated.

[0022] Compared with the prior art, traditional satellite network security systems require manual formulation of corresponding protection rules, resulting in protection gaps when facing attacks. In contrast, this solution automatically generates a threat judgment model for the corresponding threat type through a generative adversarial network. At the same time, this solution integrates data generation, model training, and performance calibration into a closed-loop system, significantly improving the real-time performance and adaptability of the protection strategy.

[0023] Through the above technical solution, this application effectively solves the problems of low efficiency and update delay in the manual protection mode. The automated generation of the threat judgment model reduces the labor cost of formulating corresponding protection rules, and the adversarial training mechanism improves the model's recognition ability for new threats. The dynamic calibration system ensures the detection accuracy during long-term use.

[0024] The present application further proposes that the data rotor system includes a data receiving module, a data encryption module, and a data transmission module; the data receiving module is used to receive data sent by the terminal; the data encryption module encrypts the data to ensure the security of the data during transmission; the data transmission module uses a multi-path transmission protocol to send the encrypted data to the satellite network through multiple transmission paths.

[0025] Among them, the data receiving module refers to an interface module for obtaining raw data from terminal devices, which can be specifically implemented by a network interface card or a wireless communication chip to provide a basic data source for subsequent processing. The data encryption module refers to a component that performs cryptographic processing on raw data, which can be specifically implemented by AES-256 or RSA encryption algorithms to prevent data from being stolen or tampered with during transmission by obfuscating the data content. The data transmission module refers to a communication unit for distributing the encrypted data to the satellite network, which can be specifically implemented by a multi-path TCP protocol or a custom sharding transmission protocol. By splitting the data into multiple sub-streams and transmitting them through different physical links, the risk of single-path failure is reduced.

[0026] Specifically, the data generated by the terminal device is first obtained by the data receiving module to ensure the integrity and timeliness of the data source. The data encryption module encrypts the raw data. For example, an encryption key is generated through an asymmetric encryption algorithm, and then the symmetric encryption algorithm is used to obfuscate the data, making it difficult to be cracked even if intercepted during transmission. The encrypted data is split into multiple data blocks by the transmission module and sent to the satellite network in parallel through multiple pre-established communication paths. The multi-path transmission protocol adds redundant check information during data splitting, enabling the receiving end to still recover the complete information through the data of other paths when part of the path data is lost. At the same time, it is difficult for attackers to obtain all the data content through a single interception point.

[0027] The present application further proposes that the training module includes a data preprocessing unit, a model construction unit, and a model training unit; the data preprocessing unit obtains threat data, performs cleaning, normalization, and feature extraction operations on the threat data, removes noise and missing values, and extracts feature vectors from the threat data; the model construction unit constructs a data generator based on a generative adversarial network; the data generator is used to generate virtual data simulating network security threat behaviors; the model training unit uses the preprocessed threat data to train the generative adversarial network and optimize the loss function of the generator within the generative adversarial network.

[0028] Among them, cleaning refers to identifying and deleting invalid, duplicate, or abnormal data in threat data. Specifically, regular expression matching or clustering algorithms can be used to achieve this, solving the problem of noise interference in the original data. Among them, feature extraction refers to screening out the key attributes representing attack behaviors from threat data. Specifically, principal component analysis or convolutional neural network autoencoders can be used to achieve this, retaining the core information of the data through dimensionality reduction processing. A generative adversarial network refers to an adversarial training framework composed of a generator and a discriminator. The generator is used to generate virtual threat data, and the discriminator is used to distinguish between real data and generated data.

[0029] The present application further proposes that the discrimination module constructs a data discriminator based on a generative adversarial network. The data discriminator performs a first discrimination on each piece of data in the data packet to distinguish whether the data belongs to threat data or virtual data. The discrimination module adjusts the data generator according to the first discrimination result and optimizes the loss function of the discriminator in the generative adversarial network.

[0030] Among them, a convolutional neural network structure can be specifically used to implement the discriminator, and through adversarial training, the discriminator can make more accurate judgments on real threat data. Among them, the first discrimination refers to performing binary classification analysis on each piece of data in the data packet, used to distinguish the feature differences between real threat data and generated virtual data, with the focus on obtaining the obvious features of real threats. Optimizing the loss function of the discriminator refers to dynamically adjusting the model parameters through adversarial training. Specifically, a cross-entropy loss function combined with a weight regularization method can be used to improve the discriminator's generalization and recognition ability for threat data.

[0031] Specifically, in the generative adversarial network constructed by the discrimination module, the discriminator performs binary classification on each piece of data in the data packet, inputs the processed feature vectors into a multi-layer neural network for probability calculation, and outputs the probability value indicating whether the data belongs to a real threat or virtual generation. When the discrimination result is fed back to the generator, the generator parameters are adjusted through the backpropagation algorithm to make it generate more deceptive virtual data. At the same time, the loss function of the discriminator is continuously optimized during the training process. By calculating the distribution difference between real data and generated data through cross-entropy and combining regularization constraints to prevent the model from overfitting. This adversarial mechanism prompts the generator and the discriminator to continuously evolve in a dynamic game. The virtual data generated by the generator gradually approaches the real threat characteristics, and the discriminator simultaneously improves its sensitivity to identify subtle differences, forming a closed-loop optimization process.

[0032] For example, in the case of 10 iterations (high iteration times), when the probability value of the discriminator identifying a real threat is greater than 90%, it can be determined that the discrimination model inside the discrimination module reaches the preset target.

[0033] Compared with the prior art, the traditional method relies on manual annotation of threat data and regular update of discrimination rules, which has the problems of response lag and high maintenance cost. In this solution, through the adversarial training mechanism of the generative adversarial network, the discrimination model can automatically learn the dynamic features of threat data without manually defining discrimination rules. Through the above technical solution, the generation mechanism of the generative adversarial network enables the discrimination model to be automatically generated, reducing the dependence on manual rule-making. Through the adversarial training of the generator and the discriminator, a positive promotion relationship is formed between the virtual data generation quality and the threat recognition accuracy, significantly reducing the system maintenance cost. The optimization process of the discriminator loss function enhances the model's ability to distinguish complex threat patterns and improves the detection sensitivity to new attack behaviors.

[0034] The present application further proposes that the satellite network threat analysis system further includes a monitoring module; wherein, the monitoring module constructs a screening model, and performs corresponding monitoring processing on the real data according to the discrimination probability of the discrimination module on whether the real data is threat data.

[0035] Specifically, the screening model includes: ; wherein, is the discrimination probability of the discrimination module on whether the real data is threat data. The first monitoring process is specifically to directly send a type I alarm to the server platform of the satellite network threat analysis system and directly intercept it. The second monitoring process is to conduct a type I supervision. When this real data file is sent from a high-risk transmission end (the data port category that emits threat behavior data frequently after statistics), directly send a type I alarm to the server platform of the satellite network threat analysis system and directly intercept it; if not, downgrade it to a type II supervision and maintain normal supervision. The third monitoring process is to conduct a type II supervision. When this real data file flows to the core marking area (the port in the satellite network that is easily invaded), send a type II alarm to the server platform to inform the supervisor to conduct a review. The fourth monitoring process is to conduct a type III supervision and maintain normal supervision. When this real data flows to an area that requires high-privilege authorization, not only the privilege level of the terminal user needs to be reviewed, but also a type II alarm needs to be sent to the server platform to inform the supervisor to conduct a review.

[0036] Specifically, The calculation of is as follows: First, it can be clearly seen from the prior art that the value output by the discriminator in the generative adversarial network belongs to [0,1], that is, when real data is input into the discriminator after training is completed, any value in [0,1] will be obtained; Next, according to the description in the present application, " The discrimination probability of the discrimination module for whether the real data is threat data. It can be seen that the discrimination probability is the probability that the discrimination module (discriminator) discriminates whether the real data is threat data; At this time, since the discriminator determines whether it is real threat data by looking at the range of the output value in [0, 1], that is, when it is greater than 0.5, it is judged as real threat data, which is highly similar to the concept of discrimination probability; thus, it is easy for technicians to understand that the calculation of the discrimination probability is to convert the position of the output value in [0, 1] into a percentage when the discriminator inputs real data; That is, The calculation formula of is as follows: ; is the discrimination probability, is the output value of the discriminator when real data is input into the discriminator.

[0037] This application further proposes that the discrimination module further includes a result evaluation unit and a feedback adjustment unit. The result evaluation unit quantitatively evaluates the first discrimination result and the second discrimination result, calculates the accuracy rate, recall rate, and F1 value indicators for discriminating various threat data, and generates an evaluation report. The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator according to the indicator data in the evaluation report, and feeds the adjusted hyperparameters back into the model training process to achieve continuous improvement of the model.

[0038] Among them, the evaluation report refers to a statistical analysis document containing various quantitative indicators, and specifically, dynamic charts can be generated through data visualization tools to intuitively present the discrimination effect of the model. Hyperparameters refer to the preset parameters that control the model training process, and specifically, learning rate, regularization coefficient, or network layer parameter types can be adopted to optimize the model convergence speed and generalization ability.

[0039] Specifically, by converting the discrimination result into quantifiable indicators such as accuracy rate, recall rate, and F1 value, the evaluation of the model performance no longer depends on manual experience judgment, but is based on objective data analysis. After the indicator data in the evaluation report is input into the feedback adjustment unit, through predefined optimization algorithms such as gradient descent or Bayesian optimization, the learning rate or regularization strength of the discrimination model is automatically adjusted. The adjusted parameters are fed back to the training process in real time, enabling the model to adapt to the change of data distribution in the new round of training. For example, when it is detected that the recall rate of a certain type of new threat data is lower than the threshold, the feedback adjustment unit will lower the classification threshold of the discriminator to expand the detection range, and at the same time reallocate the feature weights to enhance the sensitivity to specific attack patterns. This process forms a closed-loop optimization mechanism, enabling the model to continuously iterate and adapt to the dynamic threat environment.

[0040] Through the above technical solution, this application solves the technical problems of low efficiency of manual evaluation and lag in model parameter update, and realizes the automatic performance monitoring and dynamic parameter optimization of the threat detection model. This solution can quickly respond to the changes in new threat patterns, continuously improve the accuracy and stability of the discrimination model, reduce the manual maintenance cost at the same time, and ensure the long-term effective operation of the satellite network security protection system.

[0041] This application further proposes that the evaluation report includes a comprehensive evaluation index calculation model, and its quantitative calculation formula is as follows: ; Among them, is the comprehensive evaluation index (that is, the reward index), is the accuracy rate, is the recall rate, is the F1 value index; is the weight of each evaluation index, and .

[0042] Through the construction of the comprehensive evaluation index calculation model, the comprehensive evaluation index can be quantified. When the overall quantified comprehensive evaluation index is relatively low, it means that the evaluation method is biased. Therefore, the user needs to optimize the evaluation methods of the accuracy rate, recall rate, and F1 value index for discriminating various threat data according to the actual situation.

[0043] This application further proposes that the calibration module introduces security data and threat data through the database, and introduces the security data and threat data into the discrimination module for secondary discrimination; the calibration module generates a reward index based on the secondary discrimination result, and dynamically adjusts the data discriminator in the discrimination module according to the reward index until the reward index exceeds the limit value.

[0044] For example, when the reward index reaches 95% - 99% of the maximum value, it can be judged that the discrimination model in the discrimination module reaches the preset target.

[0045] Among them, the calibration module refers to a component that introduces security data and threat data in a real scenario through a database for secondary calibration of the discrimination model. Specifically, it can be implemented by combining a data screening unit and a weight assignment unit. By screening high-value data samples and assigning different weights, the representativeness and effectiveness of the data during the calibration process are ensured. Among them, the second discrimination refers to the process of the discrimination module classifying and discriminating the security data and threat data introduced by the calibration module. Specifically, it can be implemented by using a classification algorithm based on a deep neural network. By comparing the distribution differences between the threat data and the security data, the model's ability to identify threat behaviors is improved. Among them, the reward index refers to a quantitative evaluation index based on the results of the second discrimination. Specifically, it can be implemented by weighted calculation using a confusion matrix combined with F1 value and accuracy rate indicators, and is used to measure the performance of the discrimination model on the current data samples. Among them, dynamic adjustment refers to optimizing the parameters of the data discriminator according to the change of the reward index. Specifically, it can be implemented by using the policy gradient algorithm in reinforcement learning. By gradually adjusting the decision boundary of the discriminator through gradient update, it can adapt to the characteristic changes of new threats.

[0046] Specifically, the calibration module screens security data and threat data with timeliness and credibility from the database and inputs them into the discrimination module for secondary discrimination. The discrimination module classifies the real threat data and security data and generates discrimination results including accuracy rate and recall rate indicators. Based on this result, the reward index is calculated. When the index does not reach the preset threshold, the loss function parameters of the discriminator are iteratively updated through the backpropagation algorithm to optimize the model's ability to capture the characteristics of new threats. For example, when a new attack pattern causes a decrease in discrimination accuracy, the reward index triggers the parameter adjustment mechanism of the discriminator, and the model automatically learns the change trend of the attack characteristics and re-establishes the classification decision boundary.

[0047] Compared with the prior art, this solution online calibrates the discrimination model by introducing real data, combines the reinforcement learning mechanism to realize dynamic optimization of parameters, enables the model to continuously adapt to the dynamic changes of threat characteristics, and can complete the update and iteration of the discrimination logic without manual intervention.

[0048] This application further proposes that the calibration module further includes a data screening unit and a weight assignment unit; the data screening unit screens and filters the security data and threat data in the database according to the dimensions of timeliness, relevance, and credibility of the data, and selects representative and valuable data samples for the second discrimination; the weight assignment unit assigns different weight coefficients to the data samples according to their importance and influence, so that the contribution differences of different data samples can be fully considered when calculating the reward index.

[0049] Among them, the data screening unit refers to a functional module that automatically extracts valid data samples from a database based on preset rules. Specifically, it can calculate the data timeliness score using a time decay model, generate data correlation indicators based on a semantic matching algorithm, and implement it in combination with a data source credibility grading mechanism to eliminate low-value data through a triple filtering mechanism. Among them, the weight assignment unit refers to a calculation module that dynamically adjusts the sample weights according to data characteristics. Specifically, it can be implemented using a weight coefficient table based on threat impact level division and combining a machine learning model to predict the contribution of samples to the optimization of the discrimination model, and strengthen the role of key samples in model training through differential weight mapping.

[0050] Specifically, the data screening unit automatically reduces the weight of data that exceeds the preset timeliness threshold through a time decay factor. For example, it assigns a lower selection priority to historical threat data from half a year ago compared to recent data; at the same time, it uses natural language processing technology to analyze the relevance between the data content and the current network threat situation, filtering out irrelevant or redundant information; and further combines the authentication level of the data collection device to quantitatively evaluate the credibility. When calculating the reward index, the weight assignment unit dynamically adjusts the weight coefficient according to the misjudgment rate of the threat type in the sample record in the discrimination model. For example, it assigns a higher weight to zero-day attack data that is difficult for the model to identify, so that the calibration process focuses on optimizing weak links.

[0051] Compared with the prior art, this solution realizes the accurate quantitative evaluation of data value by constructing an automatic screening mechanism and a dynamic weight system, enabling the model calibration process to adaptively focus on high-value samples and breaking through the bottleneck of manual processing efficiency.

[0052] This application further proposes that the threat analysis subsystem further includes a threat response module; the threat response module is connected to the discrimination module and is used to formulate corresponding threat response strategies according to the discrimination results output by the discrimination module; the threat response strategies include but are not limited to blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rule measures; the threat response module can dynamically adjust the priority and intensity of the response strategy according to factors such as the type, severity, and impact scope of the threat, and realize the rapid, accurate, and effective disposal of satellite network threats.

[0053] Among them, the threat response module refers to the automated response control unit deployed on satellite network nodes, which can be specifically implemented by an intelligent decision-making system based on a policy engine. Disposal instructions are generated through the linkage between the preset response rule library and the real-time discrimination results. The threat response policy refers to the set of disposal solutions preset for different threat scenarios, which can be specifically implemented by a multi-level policy mapping table. The optimal response method is determined through the matching relationship between threat attributes and disposal means. Dynamically adjusting the priority and intensity refers to the adaptive optimization mechanism of the response policy, which can be specifically implemented by a weighted scoring algorithm. Through comprehensive evaluation by assigning classification weights to threat types, grade coefficients to severity levels, and regional parameters to the scope of influence, a policy execution sequence and execution intensity parameters are generated.

[0054] Specifically, after the threat classification result output by the discrimination module is input into the threat response module, the preset disposal means library is first matched according to the threat type. For example, the strategy of blocking the attack connection is automatically triggered for a distributed denial-of-service attack, and the strategy of isolating the infected device is activated for the spread of malware. Subsequently, based on the threat severity index in the discrimination result, such as the attack traffic intensity or the number of infected devices, the response level is automatically divided and the corresponding disposal intensity is matched. For example, full-band blocking is adopted for high-risk attacks, and flow limiting control is implemented for medium-risk attacks. At the same time, combined with the satellite network topology data, the policy priority is dynamically adjusted according to the scope of influence of the threatened node. For example, the threat of the backbone node is preferentially disposed of to control the spread risk. After the policy is generated, it is sent to the corresponding node for execution through the satellite network control interface, forming a closed-loop disposal process of discrimination - decision - execution.

[0055] In some specific implementation manners, blocking the attack connection can be achieved through a traffic filtering system deployed on the satellite gateway, isolating the infected device can adopt network segmentation isolation technology, repairing system vulnerabilities can call an automated patch distribution platform, and updating the protection rules can push a new rule set through the security policy management interface. The adjustment of the policy priority can set a weighting coefficient based on the importance of the satellite node. For example, the priority coefficient of the core routing node is set to three times that of the ordinary node. The response intensity control can adopt a progressive disposal mechanism. For example, monitoring and early warning are implemented in the initial stage, and it is gradually enhanced to complete blocking as the threat escalates.

[0056] Compared with the prior art, this solution realizes the conversion from millisecond-level discrimination results to disposal strategies by constructing an automated threat response module, and the response time is shortened to the second level. At the same time, based on the dynamic adjustment mechanism of multi-dimensional threat characteristics, the protection policy can automatically evolve with the change of attack means, avoiding the lag of manual policy maintenance. For example, in the face of a new zero-day attack, the system can automatically classify according to the attack behavior characteristics and generate a temporary blocking policy, while the traditional method needs to wait for manual analysis of the attack characteristics before updating the protection rules.

[0057] The present application further proposes that the threat response module includes a response evaluation unit and an effect feedback unit; the response evaluation unit monitors and evaluates the execution effect of the threat response strategy in real time, collects relevant metric data, such as the attack blocking success rate, system recovery time, and business impact degree, and generates a detailed response evaluation report; the effect feedback unit feeds back the key information in the response evaluation report to other modules of the threat analysis subsystem, so that each module can further optimize its own functions and performance according to the feedback information of the response effect, forming a closed-loop threat analysis and response optimization cycle.

[0058] Among them, the response evaluation unit refers to a system component that dynamically monitors the threat disposal effect through quantitative metrics, and can be specifically implemented by using real-time data acquisition algorithms and metric calculation models, and is used to objectively evaluate key parameters such as the blocking success rate and system recovery efficiency. Among them, the effect feedback unit refers to a communication mechanism that reversely transmits the evaluation result to the model training and discrimination module, and can be specifically implemented by using an automated data pipeline and a priority assignment strategy to ensure that the feedback information can trigger model parameter adjustment and data weight update.

[0059] Specifically, the response evaluation unit continuously collects network status data and business recovery logs after attack blocking. When calculating the attack blocking success rate through built-in algorithms, it can conduct comparative analysis based on historical baseline data and real-time results. The evaluation of the system recovery time can be achieved through timestamp records and event sequence matching, such as the interval time from the occurrence of the attack to the complete recovery of the network service. The effect feedback unit transmits inefficient strategies or misjudgment cases identified in the evaluation report to the training module, so that the generative adversarial network increases the weight of relevant threat data in subsequent training, and at the same time adjusts the threshold parameters of the discrimination model to improve the detection accuracy. This process forms a closed loop from threat identification to response execution and then to model optimization, enabling the system to autonomously adjust strategies according to the actual protection effect.

[0060] Compared with the prior art, this solution directly applies the actual protection effect data to the model optimization link through an automated evaluation and feedback mechanism, enabling the threat response strategy to dynamically adapt to new attack patterns, while reducing the manual maintenance cost.

[0061] Those skilled in the art should understand that the embodiments of the present invention may provide a method, a system or a computer program product. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media that contain computer-usable program code. Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disk. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, and the instruction device implements the process Figure 1 one process or multiple processes and / or blocks Figure 1 the functions specified in one block or multiple blocks.

[0062] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. An AI-based satellite network threat analysis system, characterized in that, Including: A training module that constructs a data generator to generate virtual data and integrates threat data and virtual data into data packets; A discrimination module that constructs a data discriminator to perform a first discrimination on all data within the data packets; the discrimination module adjusts the data generator according to the first discrimination result, with the condition that the first discrimination result exceeds a defined probability as the termination condition; A calibration module that introduces security data and threat data through a database and introduces the security data and threat data into the discrimination module for a second discrimination; the calibration module generates a reward index based on the second discrimination result and dynamically adjusts the data discriminator within the discrimination module until the reward index exceeds a defined value.

2. The AI-based satellite network threat analysis system according to claim 1, characterized in that: It further includes a data receiving module, a data encryption module, and a data transmission module; The data receiving module is used to receive real data sent by a terminal and send the real data to the discrimination module to determine whether it is threat data; The data encryption module performs encryption processing on the data to ensure the security of the data during transmission; The data transmission module uses a multi-path transmission protocol to send the encrypted data to a satellite network through multiple transmission paths.

3. The AI-based satellite network threat analysis system according to claim 2, wherein: The training module includes a data preprocessing unit, a model construction unit, and a model training unit; The data preprocessing unit obtains threat data, performs cleaning, normalization, and feature extraction operations on the threat data, removes noise and missing values, and extracts feature vectors from the threat data; The model construction unit constructs a data generator based on a generative adversarial network; wherein, the data generator is used to generate virtual data simulating network security threat behaviors; The model training unit uses the preprocessed threat data to train the generative adversarial network and optimize the loss function of the generator within the generative adversarial network.

4. The AI-based satellite network threat analysis system according to claim 3, wherein: The discrimination module constructs a data discriminator based on a generative adversarial network; wherein, the data discriminator performs a first discrimination on each piece of data within the data packets to distinguish whether each piece of data within the data packets belongs to threat data or virtual data; The discrimination module adjusts the data generator according to the result of the first discrimination and optimizes the loss function of the discriminator within the generative adversarial network.

5. The AI-based satellite network threat analysis system according to claim 3, wherein: It further includes a monitoring module; The monitoring module constructs a screening model and performs corresponding monitoring processing on the real data according to the discrimination probability of the discrimination module on whether the real data is threat data; The screening model includes: ; Among them, is the discrimination probability; The first monitoring processing is specifically to directly send a type of alarm to the server platform of the satellite network threat analysis system and directly intercept it; The second monitoring processing is that when this real data file is sent from a high-risk transmission end, directly send a type of alarm to the server platform of the satellite network threat analysis system and directly intercept it; The third monitoring processing is that when this real data file flows to the core marking area, send a type of two alarm to the server platform to inform the supervisor to conduct a review; The fourth monitoring process is to send a second - class alert to the server platform when this real - data flow direction needs high - privilege authorization, informing the supervisor to conduct a review.

6. The AI-based satellite network threat analysis system according to claim 1, wherein: The discrimination module further includes a result evaluation unit and a feedback adjustment unit; The result evaluation unit quantitatively evaluates the first discrimination result and the second discrimination result, calculates the accuracy rate, recall rate, and F1 - value indicators for discriminating various threat data, and generates an evaluation report; The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator according to the index data in the evaluation report, and feeds the adjusted hyperparameters back into the model training process to achieve continuous improvement of the model.

7. The AI - based satellite network threat analysis system according to claim 1, wherein: The calibration module introduces the security data and threat data into the discrimination module for a second discrimination, and the discrimination module distinguishes whether each piece of data belongs to security data or threat data.

8. The AI-based satellite network threat analysis system according to claim 7, wherein: The calibration module further includes a data screening unit and a weight assignment unit; The data screening unit screens and filters the security data and threat data in the database according to the dimensions of data timeliness, relevance, and credibility, and selects representative and valuable data samples for the second discrimination; The weight assignment unit assigns different weight coefficients to the data samples according to their importance and influence, so that the contribution differences of different data samples can be fully considered when calculating the reward index, thereby improving the accuracy and effectiveness of the calibration process.

9. The AI-based satellite network threat analysis system according to claim 1, characterized in that: It further includes a threat response module; The threat response module is connected to the discrimination module and is used to formulate corresponding threat response strategies according to the discrimination results output by the discrimination module; The threat response strategies include, but are not limited to, blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rule measures; the threat response module can dynamically adjust the priority and intensity of the response strategies according to factors such as the type, severity, and impact scope of the threat, so as to achieve fast, accurate, and effective disposal of satellite network threats.

10. The AI-based satellite network threat analysis system according to claim 9, wherein: The threat response module further includes a response evaluation unit and an effect feedback unit; The response evaluation unit monitors and evaluates the execution effect of the threat response strategy in real - time, collects relevant index data, and the relevant index data includes the attack blocking success rate, system recovery time, and business impact degree, and generates a detailed response evaluation report; The effect feedback unit feeds the key information in the response evaluation report back to the training module, discrimination module, and calibration module in the threat analysis subsystem, so that each module can further optimize its own functions and performance according to the feedback information of the response effect, forming a closed threat analysis and response optimization loop, and continuously improving the security protection ability and intelligent level of the entire system.

Citation Information

Patent Citations

  • Method and system for quickly deploying meta-learning detection model of network threats in power network

    CN117633779A

  • Network security threat intelligent identification method based on generative large model

    CN119921976A

  • Satellite network multi-dimensional threat simulation method and system based on isolated forest detection

    CN120050067A

  • Satellite dynamic simulation verification method based on generative adversarial network threat modeling

    CN120104249A

  • Dynamic network security shielding system

    WO2025111588A1