An AI-based satellite network threat analysis system
Through the generation of threat analysis system with adversarial networks and dynamic calibration mechanisms, the problem of inefficient manual protection in satellite networks is solved, real-time threat identification and automated protection are achieved, and operation and maintenance costs are reduced.
Patent Information
- Application Number
- CN202510829529.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-06-20
AI Technical Summary
The existing satellite network security protection system relies on manual screening of threat behavior, resulting in high costs and poor real-time performance, and is unable to effectively deal with the threat of dynamic changes.
A threat analysis system based on a generative adversarial network is adopted, and a dynamic calibration mechanism is combined with a discriminant model to automatically optimize the model performance to achieve real-time and accuracy of threat recognition.
It improves the real-time and protection accuracy of satellite network threat identification, reduces manual operation and maintenance costs, can quickly respond to new threats and continuously optimize protection strategies.
Smart Images

Figure CN120358086B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an AI-based satellite network threat analysis system. Background Art
[0002] In recent years, with the widespread use of satellite network systems, the communication security protection issues of satellite networks have affected the security of every user on the Internet.
[0003] Currently, there are many problems with the security protection of satellite networks. In particular, the current satellite network security requires manual screening of each type of threat behavior and the formulation of protection strategies. The establishment of the protection system requires a lot of manpower and material resources, and it also needs to be frequently updated according to the real-time changes in threat behaviors. For the builders of satellite networks, the cost is huge. Summary of the Invention
[0004] The present invention provides an AI-based satellite network threat analysis system, which constructs a data generation and discrimination model based on a generative adversarial network through a threat analysis subsystem, and continuously optimizes the model performance in combination with a dynamic calibration mechanism, thereby solving the problems of low efficiency and poor real-time performance of manual protection. It has the advantages of improving the real-time performance of threat identification and reducing manual operation and maintenance costs.
[0005] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0006] An AI-based satellite network threat analysis system, comprising:
[0007] a training module, which builds a data generator, generates virtual data, and integrates threat data and virtual data into a data package;
[0008] a discrimination module, which constructs a data discriminator and performs a first discrimination on all data in the data packet; the discrimination module adjusts the data generator according to the first discrimination result, and takes the first discrimination result exceeding a limited probability as a termination condition;
[0009] A calibration module is provided for introducing security data and threat data through a database, and introducing the security data and threat data into the discrimination module for a second discrimination. The calibration module generates a reward index based on the second discrimination result, and dynamically adjusts the data discriminator in the discrimination module according to the reward index until the reward index exceeds a limit value.
[0010] Preferably, it also includes a data receiving module, a data encryption module and a data transmission module;
[0011] The data receiving module is used to receive real data sent by the terminal, and send the real data to the determination module to determine whether it is threat data;
[0012] The data encryption module encrypts the data to ensure the security of the data during transmission;
[0013] The data transmission module adopts a multi-path transmission protocol to send the encrypted data to the satellite network through multiple transmission paths.
[0014] Preferably, the training module includes a data preprocessing unit, a model building unit and a model training unit;
[0015] The data preprocessing unit acquires threat data, performs cleaning, normalization and feature extraction operations on the threat data, removes noise and missing values, and extracts feature vectors from the threat data;
[0016] The model building unit builds a data generator based on a generative adversarial network; wherein the data generator is used to generate virtual data that simulates network security threat behaviors;
[0017] The model training unit uses the preprocessed threat data to train the generative adversarial network to optimize the loss function of the generator in the generative adversarial network.
[0018] Preferably, the discrimination module constructs a data discriminator based on a generative adversarial network; wherein the data discriminator performs a first discrimination on each piece of data in the data packet to distinguish whether each piece of data in the data packet is threat data or virtual data;
[0019] The discrimination module adjusts the data generator according to the result of the first discrimination and optimizes the loss function of the discriminator in the generative adversarial network.
[0020] Preferably, it also includes a monitoring module;
[0021] The monitoring module constructs a screening model and performs corresponding monitoring processing on the real data according to the probability of the discrimination module discriminating whether the real data is threat data;
[0022] The screening model includes:
[0023] ;
[0024] in, is the discrimination probability;
[0025] The first monitoring process specifically involves sending a type of alert directly to the server platform of the satellite network threat analysis system for direct interception;
[0026] The second monitoring process is to directly send a Class A alert to the server platform of the satellite network threat analysis system when this real data file is sent from a high-risk transmission end, and directly intercept it;
[0027] The third monitoring process is to send a second-class alarm to the server platform when the real data file flows to the core marking area, informing the supervisor to conduct a review;
[0028] The fourth monitoring process is to send a second-class alarm to the server platform when the real data flows to an area that requires high-authorization, informing the supervisor to conduct a review.
[0029] Preferably, the discrimination module further includes a result evaluation unit and a feedback adjustment unit;
[0030] The result evaluation unit performs quantitative evaluation on the first discrimination result and the second discrimination result, calculates the accuracy, recall rate and F1 value index of distinguishing various types of threat data, and generates an evaluation report;
[0031] The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator according to the indicator data in the evaluation report, and feeds the adjusted hyperparameters back to the model training process to achieve continuous improvement of the model.
[0032] Preferably, the calibration module introduces the safety data and threat data into the discrimination module for a second discrimination, and the discrimination module distinguishes whether each piece of data is safety data or threat data.
[0033] Preferably, the calibration module further includes a data screening unit and a weight distribution unit;
[0034] The data screening unit screens and filters the security data and threat data in the database according to the timeliness, relevance and credibility of the data, and selects representative and valuable data samples for the second judgment;
[0035] The weight allocation unit allocates different weight coefficients to the data samples according to their importance and influence, so that the contribution differences of different data samples can be fully considered when calculating the reward index, thereby improving the accuracy and effectiveness of the calibration process.
[0036] Preferably, it also includes a threat response module;
[0037] The threat response module is connected to the discrimination module and is used to formulate a corresponding threat response strategy based on the discrimination result output by the discrimination module;
[0038] The threat response strategy includes but is not limited to blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rules and measures; the threat response module can dynamically adjust the priority and intensity of the response strategy based on the type, severity and impact range of the threat, so as to achieve rapid, accurate and effective disposal of satellite network threats.
[0039] Preferably, the threat response module further includes a response evaluation unit and an effect feedback unit;
[0040] The response assessment unit monitors and evaluates the effectiveness of the threat response strategy in real time, collects relevant indicator data, including attack blocking success rate, system recovery time, and business impact, and generates a detailed response assessment report;
[0041] The effect feedback unit feeds back the key information in the response assessment report to the training module, discrimination module and calibration module in the threat analysis subsystem, so that each module can further optimize its own function and performance according to the feedback information of the response effect, forming a closed threat analysis and response optimization loop, and continuously improving the security protection capability and intelligence level of the entire system.
[0042] Beneficial effects of the present invention:
[0043] This application provides an AI-based satellite network threat analysis system. The threat analysis subsystem constructs a data generation and discrimination model based on a generative adversarial network, combines a dynamic calibration mechanism to continuously optimize the model performance, and introduces a closed-loop threat response mechanism. It solves the problems of low efficiency and poor real-time performance of manual protection, and has the advantages of improving the real-time performance of threat identification, enhancing protection accuracy, and reducing manual operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 This is a flowchart of an AI-based satellite network threat analysis system provided by the present invention. DETAILED DESCRIPTION
[0045] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, but not all of the embodiments.
[0046] Existing technologies have long relied on manual screening of threat behaviors and the development of protection strategies for satellite network communications. However, due to the dynamic nature of threat behavior, traditional methods require significant human resources to continuously update the rule base, resulting in high system maintenance costs. Furthermore, existing protection systems lag in responding to new and unknown threats, failing to meet the real-time security needs of satellite networks. This manually-led protection model is prone to response delays and protection vulnerabilities when dealing with massive data transmission scenarios, threatening the overall security of satellite networks.
[0047] To solve the above problems, refer to Figure 1 The present invention proposes an AI-based satellite network threat analysis system, comprising a data center rotor system and a threat analysis subsystem. The data center rotor system is responsible for data transmission between the terminal and the satellite network. The threat analysis subsystem includes a training module, a discrimination module, and a calibration module. The training module constructs a data generator that generates virtual data and integrates real threat data to form a training data packet. The discrimination module uses a discrimination model to perform an initial threat identification on the data packet and optimizes the generation model based on the identification results. The calibration module introduces security data and threat data for secondary discrimination and dynamically adjusts the discrimination model parameters through the reward index until the performance index is achieved.
[0048] Among them, the data subsystem refers to the infrastructure for establishing a secure transmission channel, which can be implemented using a multi-path encrypted transmission protocol. The integrity and confidentiality of the original data transmission are ensured through parallel transmission paths and data encryption technology. The threat analysis subsystem refers to the intelligent threat identification architecture, which is specifically constructed using a generative adversarial network framework. The threat detection capability is improved through the adversarial training mechanism of the generator and the discriminator. The training module refers to the virtual data generation unit. Specifically, a deep neural network can be used to construct a generator. Synthetic data with threat behavior characteristics is generated through feature space mapping to expand the diversity of training samples. The discriminant module refers to the threat identification unit. Specifically, a convolutional neural network can be used to construct a classifier. The gradient backpropagation mechanism is used to continuously optimize the discrimination threshold. The calibration module can use a reinforcement learning algorithm to construct an evaluation mechanism. The performance indicators of the generated model are generated through mixed verification of security data and threat data to ensure the continuous improvement of recognition accuracy.
[0049] Specifically, during data transmission, the data transfer system ensures the security of the original data through an encrypted channel. The threat analysis subsystem first uses a generative adversarial network to generate virtual data with attack signatures, which, together with real threat data, form an enhanced training set. The discriminator module performs an initial classification on the mixed dataset and adjusts the generator parameters based on feedback from misclassifications to improve the authenticity of the virtual data. This cyclical adversarial process between the generator and the discriminator improves the discriminator's ability to discriminate against real threat data. The calibration module introduces labeled safe samples for secondary verification and calculates a reward index based on the discriminator's classification accuracy. If the reward index falls below a preset threshold, the system automatically adjusts the discriminator's weights, forming a closed-loop optimization cycle of generation, discrimination, and calibration. This dual training mechanism enables the discriminator model to both strengthen its recognition of known threat patterns and learn potential attack signatures from virtual data, achieving comprehensive coverage of both new and existing threats. Furthermore, through this closed-loop optimization cycle, the discriminator automatically updates and generates new discriminant methods for distinguishing threat data.
[0050] Compared to existing technologies, traditional satellite network security systems require manual development of protection rules, leaving gaps in protection when facing attacks. This solution, however, uses a generative adversarial network to automatically generate threat assessment models corresponding to threat types. Furthermore, this solution integrates data generation, model training, and performance calibration into a closed-loop system, significantly improving the real-time and adaptability of protection strategies.
[0051] Through the above technical solutions, this application effectively solves the problems of inefficiency and update delays in manual protection modes. Automated threat assessment model generation reduces the labor cost of developing corresponding protection rules, while adversarial training mechanisms improve the model's ability to identify new threats. A dynamic calibration system ensures detection accuracy over long-term use.
[0052] The present application further proposes that the data rotor system includes a data receiving module, a data encryption module and a data transmission module; the data receiving module is used to receive data sent by the terminal; the data encryption module encrypts the data to ensure the security of the data during transmission; the data transmission module adopts a multi-path transmission protocol to send the encrypted data to the satellite network through multiple transmission paths.
[0053] The data receiving module is an interface module used to obtain raw data from terminal devices. This module can be implemented using a network interface card or wireless communication chip, providing a basic data source for subsequent processing. The data encryption module is a component that performs cryptographic processing on raw data. This module can be implemented using the AES-256 or RSA encryption algorithms, obfuscating the data content to prevent theft or tampering during transmission. The data transmission module is a communication unit used to distribute encrypted data to the satellite network. This module can be implemented using the multi-path TCP protocol or a custom fragmented transmission protocol. By splitting the data into multiple sub-streams and transmitting them across different physical links, the risk of single-path failure is reduced.
[0054] Specifically, the data generated by the terminal device is first received by the data receiving module to ensure the integrity and timeliness of the data source. The data encryption module encrypts the original data, for example, by generating an encryption key through an asymmetric encryption algorithm, and then using a symmetric encryption algorithm to obfuscate the data, making it difficult to decipher even if intercepted during transmission. The encrypted data is divided into multiple data blocks by the transmission module and sent in parallel to the satellite network via multiple pre-established communication paths. The multi-path transmission protocol adds redundant checksum information during data segmentation, allowing the receiver to recover the complete information through data from other paths even if data on some paths is lost. At the same time, it is difficult for attackers to obtain the entire data content through a single interception point.
[0055] This application further proposes that the training module includes a data preprocessing unit, a model building unit and a model training unit; the data preprocessing unit obtains threat data, cleans, normalizes and extracts features on the threat data, removes noise and missing values, and extracts feature vectors from the threat data; the model building unit constructs a data generator based on a generative adversarial network; the data generator is used to generate virtual data that simulates network security threat behavior; the model training unit uses the preprocessed threat data to train the generative adversarial network and optimizes the loss function of the generator within the generative adversarial network.
[0056] Cleansing refers to identifying and removing invalid, duplicate, or abnormal data from threat data. This can be achieved using regular expression matching or clustering algorithms to address noise interference in the original data. Feature extraction refers to filtering out key attributes that characterize attack behavior from threat data. This can be achieved using principal component analysis or convolutional neural network autoencoders, preserving the core information of the data through dimensionality reduction. Generative adversarial networks are adversarial training frameworks consisting of a generator and a discriminator. The generator is used to generate virtual threat data, while the discriminator distinguishes between real data and generated data.
[0057] This application further proposes that the discrimination module constructs a data discriminator based on a generative adversarial network. The data discriminator performs a first discrimination on each piece of data in the data packet to determine whether the data belongs to threat data or virtual data. The discrimination module adjusts the data generator according to the first discrimination result and optimizes the loss function of the discriminator in the generative adversarial network.
[0058] Specifically, a convolutional neural network structure can be used to implement the discriminator. Adversarial training can be used to make the discriminator more accurate in identifying real threat data. The first step involves performing a binary classification analysis on each piece of data within a data packet to distinguish the differences in features between real threat data and generated virtual data, with a focus on identifying the distinct characteristics of real threats. Optimizing the discriminator's loss function involves dynamically adjusting model parameters through adversarial training. Specifically, a cross-entropy loss function combined with weight regularization can be used to improve the discriminator's ability to generalize and identify threat data.
[0059] Specifically, in the generative adversarial network constructed by the discriminator module, the discriminator performs binary classification on each piece of data in the data packet, inputs the processed feature vector into a multi-layer neural network for probability calculation, and outputs a probability value for whether the data belongs to a real threat or a virtual generation. When the discrimination results are fed back to the generator, the generator parameters are adjusted through the backpropagation algorithm, causing it to generate virtual data with higher deceptiveness. At the same time, the discriminator's loss function is continuously optimized during the training process, calculating the distribution difference between real data and generated data through cross-entropy, combined with regularization constraints to prevent model overfitting. This adversarial mechanism forces the generator and discriminator to continuously evolve in a dynamic game. The virtual data generated by the generator gradually approaches the characteristics of real threats, while the discriminator simultaneously improves its sensitivity to subtle differences, forming a closed-loop optimization process.
[0060] For example, in the case of 10 iterations (a high number of iterations), when the probability value of the discriminator identifying a real threat is greater than 90%, it can be determined that the discriminant model within the discriminant module has achieved the preset goal.
[0061] Compared with existing technologies, traditional methods rely on manual labeling of threat data and regular updating of discrimination rules, which leads to delayed response and high maintenance costs. However, this solution uses the adversarial training mechanism of a generative adversarial network to enable the discriminant model to automatically learn the dynamic characteristics of threat data, eliminating the need for manual definition of discrimination rules. Through the above technical solution, the generation mechanism of the generative adversarial network enables the discriminant model to be automatically generated, reducing reliance on manual rule-making. Through adversarial training between the generator and the discriminator, the quality of virtual data generation and the accuracy of threat identification form a positive relationship, significantly reducing system maintenance costs. The optimization process of the discriminator loss function enhances the model's ability to distinguish complex threat patterns and improves the detection sensitivity of new attack behaviors.
[0062] The present application further proposes that the satellite network threat analysis system also includes a monitoring module; wherein, the monitoring module constructs a screening model, and performs corresponding monitoring processing on the real data based on the judgment probability of whether the real data is threat data by the discrimination module.
[0063] Specifically, the screening model includes:
[0064] ;
[0065] in, The probability of the determination module determining whether real data is threat data is determined. The first monitoring process specifically involves sending a Class I alert directly to the server platform of the satellite network threat analysis system for immediate interception. The second monitoring process involves performing Class I supervision. If the real data file is sent from a high-risk transmission port (a data port category that has been statistically identified as frequently emitting threat behavior data), a Class I alert is sent directly to the server platform of the satellite network threat analysis system for immediate interception. If not, the monitoring process is downgraded to Class II supervision and maintained as normal. The third monitoring process involves performing Class II supervision. If the real data file flows to a core marked area (a port in the satellite network that is prone to intrusion), a Class II alert is sent to the server platform, notifying supervisors for review. The fourth monitoring process involves performing Class III supervision, maintaining normal supervision. If the real data file flows to an area requiring high-authorization privileges, not only is the end user's privilege level verified, but a Class II alert is also sent to the server platform for supervisors for review.
[0066] Specifically, The calculation is as follows:
[0067] First, based on existing technology, it is clear that the value output by the discriminator in the generative adversarial network belongs to [0, 1]. That is, when real data is input into the trained discriminator, any value in [0, 1] will be obtained;
[0068] Then, according to the description of this application, “ is the probability of the discriminant module judging whether the real data is threat data. It can be seen that the discriminant probability is the probability of the discriminant module (discriminator) judging whether the real data is threat data.
[0069] At this point, the discriminator considers the output value within the range [0, 1], i.e., when it is greater than 0.5, it is considered to be real threat data. This is very similar to the concept of discrimination probability. Therefore, technicians can easily understand that the calculation of discrimination probability is to convert the position of the output value of the discriminator in [0, 1] into a percentage when the discriminator inputs real data.
[0070] Right now, The calculation formula is as follows:
[0071] ;
[0072] is the discriminant probability, The output value of the discriminator when the real data is input into the discriminator.
[0073] This application further proposes that the discrimination module also includes a result evaluation unit and a feedback adjustment unit. The result evaluation unit quantitatively evaluates the first discrimination result and the second discrimination result, calculates the accuracy, recall rate, and F1 value indicators for distinguishing various types of threat data, and generates an evaluation report. The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator based on the indicator data in the evaluation report and feeds the adjusted hyperparameters back to the model training process to achieve continuous improvement of the model.
[0074] The evaluation report is a statistical analysis document containing various quantitative indicators. Data visualization tools can be used to generate dynamic charts to visually demonstrate the model's discriminative performance. Hyperparameters are preset parameters that control the model training process. These parameters can include learning rates, regularization coefficients, or the number of network layers, and are used to optimize the model's convergence speed and generalization capabilities.
[0075] Specifically, by converting the discrimination results into quantifiable indicators such as accuracy, recall rate and F1 value, the evaluation of model performance no longer relies on manual experience judgment, but is based on objective data analysis. After the indicator data in the evaluation report is input into the feedback adjustment unit, the learning rate or regularization strength of the discriminant model is automatically adjusted through predefined optimization algorithms, such as gradient descent or Bayesian optimization. The adjusted parameters are fed back to the training process in real time, so that the model can adapt to changes in data distribution in the next round of training. For example, when the recall rate of a certain type of new threat data is detected to be lower than the threshold, the feedback adjustment unit will lower the classification threshold of the discriminator to expand the detection range, and redistribute the feature weights to enhance sensitivity to specific attack patterns. This process forms a closed-loop optimization mechanism, allowing the model to continuously iterate and adapt to the dynamic threat environment.
[0076] Through the above technical solution, this application solves the technical problems of inefficient manual evaluation and delayed model parameter updates, achieving automated performance monitoring and dynamic parameter optimization of the threat detection model. This solution can quickly respond to changes in new threat patterns, continuously improve the accuracy and stability of the discrimination model, while reducing manual maintenance costs and ensuring the long-term effective operation of the satellite network security protection system.
[0077] This application further proposes an evaluation report including a comprehensive evaluation index calculation model, the quantitative calculation formula of which is as follows:
[0078] ;
[0079] in, is a comprehensive evaluation index (also known as the reward index), is the accuracy, is the recall rate, is the F1 value indicator; is the weight of each evaluation indicator, and .
[0080] By constructing a comprehensive evaluation index calculation model, we can quantify the comprehensive evaluation index. Low overall quantitative comprehensive evaluation indices indicate a bias in the evaluation method. Therefore, users need to optimize the evaluation methods for accuracy, recall, and F1 value indicators for identifying various types of threat data based on actual conditions.
[0081] The present application further proposes that the calibration module introduces security data and threat data through a database, and introduces the security data and threat data into the discrimination module for a second discrimination; the calibration module generates a reward index based on the second discrimination result, and dynamically adjusts the data discriminator in the discrimination module according to the reward index until the reward index exceeds a limit value.
[0082] For example, when the reward index reaches 95% to 99% of the maximum value, it can be determined that the discriminant model in the discriminant module has achieved the preset target.
[0083] The calibration module refers to a component that introduces real-world security and threat data from a database to perform a secondary calibration of the discriminant model. This can be achieved by combining a data screening unit with a weight assignment unit. By screening high-value data samples and assigning different weights, the representativeness and validity of the data during the calibration process are ensured. Secondary discrimination refers to the process by which the discrimination module classifies and discriminates the security and threat data introduced by the calibration module. This can be achieved using a classification algorithm based on a deep neural network. By comparing the distribution differences between threat and security data, the model's ability to identify threatening behaviors is improved. The reward index refers to a quantitative evaluation metric based on the results of the secondary discrimination. This can be achieved using a confusion matrix combined with a weighted calculation of the F1 value and accuracy index to measure the performance of the discriminant model on the current data sample. Dynamic adjustment refers to optimizing the parameters of the data discriminator based on changes in the reward index. This can be achieved using the policy gradient algorithm in reinforcement learning. Through gradient updates, the decision boundary of the discriminator is gradually adjusted to adapt to the changing characteristics of new threats.
[0084] Specifically, the calibration module selects timely and credible security and threat data from the database and inputs it into the discrimination module for secondary discrimination. The discrimination module classifies real threat and security data, generating a discrimination result that includes accuracy and recall metrics. Based on this result, a reward index is calculated. When the index does not reach the preset threshold, the discriminator's loss function parameters are iteratively updated using a backpropagation algorithm to optimize the model's ability to capture new threat signatures. For example, when a new attack pattern causes a decrease in discrimination accuracy, the reward index triggers the discriminator's parameter adjustment mechanism, allowing the model to automatically learn the changing trends of attack signatures and re-establish the classification decision boundary.
[0085] Compared with existing technologies, this solution introduces real data to perform online calibration of the discriminant model and combines it with a reinforcement learning mechanism to achieve dynamic parameter optimization, enabling the model to continuously adapt to the dynamic changes of threat characteristics and complete the update and iteration of the discriminant logic without human intervention.
[0086] The present application further proposes that the calibration module also includes a data screening unit and a weight allocation unit; the data screening unit screens and filters the security data and threat data in the database according to the timeliness, relevance and credibility dimensions of the data, and selects representative and valuable data samples for the second judgment; the weight allocation unit assigns different weight coefficients to the data samples according to their importance and influence, so that the contribution differences of different data samples can be fully considered when calculating the reward index.
[0087] The data screening unit refers to a functional module that automatically extracts valid data samples from the database based on preset rules. This can be achieved by using a time decay model to calculate data timeliness scores, a semantic matching algorithm to generate data relevance indicators, and a data source credibility grading mechanism. Low-value data is eliminated through a triple filtering mechanism. The weight allocation unit refers to a calculation module that dynamically adjusts sample weights based on data characteristics. This can be achieved by using a weight coefficient table based on threat impact levels and combining a machine learning model to predict the contribution of samples to the optimization of the discriminant model. This strengthens the role of key samples in model training through differentiated weight mapping.
[0088] Specifically, the data screening unit automatically downgrades data that exceeds a preset age threshold using a time decay factor. For example, historical threat data from six months ago is given a lower selection priority than recent data. Natural language processing technology is also used to analyze the correlation between data content and the current network threat landscape, filtering out irrelevant or redundant information. Furthermore, the credibility is quantitatively assessed based on the certification level of the data acquisition equipment. When calculating the reward index, the weight allocation unit dynamically adjusts the weight coefficient based on the false positive rate of the threat type recorded in the sample in the discrimination model. For example, a higher weight is assigned to zero-day attack data that is difficult for the model to identify, allowing the calibration process to focus on optimizing weak links.
[0089] Compared with existing technologies, this solution achieves accurate quantitative assessment of data value by building an automated screening mechanism and a dynamic weighting system, enabling the model calibration process to adaptively focus on high-value samples and break through the bottleneck of manual processing efficiency.
[0090] The present application further proposes that the threat analysis subsystem also includes a threat response module; the threat response module is connected to the discrimination module, and is used to formulate corresponding threat response strategies based on the discrimination results output by the discrimination module; the threat response strategies include but are not limited to blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rules and measures; the threat response module can dynamically adjust the priority and intensity of the response strategy according to the type, severity and impact range of the threat, so as to achieve rapid, accurate and effective disposal of satellite network threats.
[0091] The threat response module refers to an automated response control unit deployed at a satellite network node. This can be implemented using an intelligent decision-making system based on a policy engine, generating response instructions by linking a preset response rule base with real-time judgment results. A threat response strategy refers to a set of preset response solutions for different threat scenarios. This can be implemented using a multi-level strategy mapping table, which determines the optimal response method by matching threat attributes with response methods. Dynamic adjustment of priority and intensity refers to an adaptive optimization mechanism for response strategies. This can be implemented using a weighted scoring algorithm. By assigning classification weights to threat types, grade coefficients to severity, and regional parameters to impact ranges, a comprehensive assessment is performed to generate a strategy execution sequence and execution intensity parameters.
[0092] Specifically, after the threat classification results output by the identification module are input into the threat response module, they are first matched to a preset library of response measures based on the threat type. For example, a strategy for blocking attack connections is automatically triggered for distributed denial-of-service attacks, while a strategy for isolating infected devices is activated for malware propagation. Subsequently, based on threat severity indicators from the identification results, such as attack traffic intensity or the number of infected devices, response levels are automatically divided and matched to corresponding response levels. For example, full-band blocking is implemented for high-risk attacks, while current limiting is implemented for medium-risk attacks. Simultaneously, combined with satellite network topology data, policy priorities are dynamically adjusted based on the impact range of the threatened node, for example, prioritizing threats to backbone nodes to control the risk of spread. Once generated, the policy is distributed to the corresponding node for execution via the satellite network control interface, forming a closed-loop response process of identification, decision-making, and execution.
[0093] In some specific implementations, blocking attack connections can be achieved through traffic filtering systems deployed at satellite gateways. Isolating infected devices can utilize network segmentation and isolation technology. System vulnerabilities can be fixed through an automated patch distribution platform. Updating protection rules can be achieved by pushing new rule sets through the security policy management interface. Policy priority can be adjusted by setting weighted coefficients based on the importance of satellite nodes. For example, the priority coefficient of core routing nodes can be set to three times that of ordinary nodes. Response intensity can be controlled through a progressive response mechanism, such as initial monitoring and early warning, which can be gradually strengthened to complete blocking as the threat escalates.
[0094] Compared to existing technologies, this solution, through the construction of an automated threat response module, achieves millisecond-level conversion from identification results to response strategies, reducing response time to seconds. Furthermore, a dynamic adjustment mechanism based on multi-dimensional threat signatures enables protection strategies to automatically evolve as attack methods change, eliminating the lag associated with manual policy maintenance. For example, when faced with a new zero-day attack, the system can automatically categorize the attack based on its behavioral characteristics and generate a temporary blocking strategy, whereas traditional methods require manual analysis of attack signatures before updating protection rules.
[0095] This application further proposes that the threat response module includes a response evaluation unit and an effect feedback unit; the response evaluation unit monitors and evaluates the execution effect of the threat response strategy in real time, collects relevant indicator data, such as attack blocking success rate, system recovery time, and business impact, and generates a detailed response evaluation report; the effect feedback unit feeds back the key information in the response evaluation report to other modules of the threat analysis subsystem, so that each module can further optimize its own functions and performance based on the feedback information of the response effect, forming a closed threat analysis and response optimization loop.
[0096] The response assessment unit is a system component that dynamically monitors threat response effectiveness through quantitative indicators. This can be achieved through real-time data collection algorithms and indicator calculation models, objectively evaluating key parameters such as blocking success rate and system recovery efficiency. The effect feedback unit is a communication mechanism that transmits assessment results back to the model training and discrimination modules. This can be achieved through automated data pipelines and priority allocation strategies to ensure that feedback information triggers model parameter adjustments and data weight updates.
[0097] Specifically, the response evaluation unit continuously collects network status data and business recovery logs after the attack is blocked. When calculating the attack blocking success rate through the built-in algorithm, it can be compared and analyzed based on historical baseline data and real-time results. The evaluation of system recovery time can be achieved through timestamp recording and event sequence matching, such as the interval from the occurrence of the attack to the complete recovery of network services. The effect feedback unit transmits the inefficient strategies or misjudgment cases identified in the evaluation report to the training module, so that the generative adversarial network increases the weight of relevant threat data in subsequent training, and adjusts the threshold parameters of the discriminant model to improve detection accuracy. This process forms a closed loop from threat identification to response execution to model optimization, enabling the system to autonomously adjust strategies based on the actual protection effect.
[0098] Compared with existing technologies, this solution uses an automated evaluation and feedback mechanism to directly apply actual protection effect data to the model optimization process, enabling threat response strategies to dynamically adapt to new attack patterns while reducing manual maintenance costs.
[0099] Those skilled in the art will appreciate that embodiments of the present invention may provide methods, systems, or computer program products. Therefore, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. The storage medium may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0100] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. An AI-based satellite network threat analysis system, characterized in that: include: a training module, which builds a data generator, generates virtual data, and integrates threat data and virtual data into a data package; a discrimination module, which constructs a data discriminator and performs a first discrimination on all data in the data packet; the discrimination module adjusts the data generator according to the first discrimination result, and takes the first discrimination result exceeding a limited probability as a termination condition; a calibration module, which introduces security data and threat data from a database and introduces the security data and threat data into the discrimination module for a second discrimination; the calibration module generates a reward index based on the second discrimination result and dynamically adjusts the data discriminator in the discrimination module according to the reward index until the reward index exceeds a limit value; The training module includes a data preprocessing unit, a model building unit and a model training unit; The data preprocessing unit acquires threat data, performs cleaning, normalization and feature extraction operations on the threat data, removes noise and missing values, and extracts feature vectors from the threat data; The model building unit builds a data generator based on a generative adversarial network; wherein the data generator is used to generate virtual data that simulates network security threat behaviors; The model training unit uses the pre-processed threat data to train the generative adversarial network to optimize the loss function of the generator in the generative adversarial network; The discrimination module constructs a data discriminator based on a generative adversarial network; wherein the data discriminator performs a first discrimination on each piece of data in the data packet to distinguish whether each piece of data in the data packet is threat data or virtual data; The discrimination module adjusts the data generator according to the result of the first discrimination to optimize the loss function of the discriminator in the generative adversarial network; The calibration module also includes a data screening unit and a weight allocation unit; The data screening unit screens and filters the security data and threat data in the database according to the timeliness, relevance and credibility of the data, and selects representative and valuable data samples for the second judgment; The weight allocation unit allocates different weight coefficients to the data samples according to their importance and influence, so that the contribution differences of different data samples can be fully considered when calculating the reward index, thereby improving the accuracy and effectiveness of the calibration process.
2. The AI-based satellite network threat analysis system according to claim 1, wherein: It also includes a data receiving module, a data encryption module and a data transmission module; The data receiving module is used to receive real data sent by the terminal, and send the real data to the determination module to determine whether it is threat data; The data encryption module encrypts the data to ensure the security of the data during transmission; The data transmission module adopts a multi-path transmission protocol to send the encrypted data to the satellite network through multiple transmission paths.
3. The AI-based satellite network threat analysis system according to claim 1, wherein: Also includes monitoring module; The monitoring module constructs a screening model and performs corresponding monitoring processing on the real data according to the probability of the discrimination module discriminating whether the real data is threat data; The screening model includes: ; in, is the discrimination probability; The first monitoring process specifically involves sending a type of alert directly to the server platform of the satellite network threat analysis system for direct interception; The second monitoring process is to directly send a Class A alert to the server platform of the satellite network threat analysis system when this real data file is sent from a high-risk transmission end, and directly intercept it; The third monitoring process is to send a second-class alarm to the server platform when the real data file flows to the core marking area, informing the supervisor to conduct a review; The fourth monitoring process is to send a second-class alarm to the server platform when the real data flows to an area that requires high-authorization, informing the supervisor to conduct a review.
4. The AI-based satellite network threat analysis system according to claim 1, wherein: The discrimination module also includes a result evaluation unit and a feedback adjustment unit; The result evaluation unit performs quantitative evaluation on the first discrimination result and the second discrimination result, calculates the accuracy, recall rate and F1 value index of distinguishing various types of threat data, and generates an evaluation report; The feedback adjustment unit automatically adjusts the hyperparameters of the data discriminator according to the indicator data in the evaluation report, and feeds the adjusted hyperparameters back to the model training process to achieve continuous improvement of the model.
5. The AI-based satellite network threat analysis system according to claim 1, wherein: The calibration module introduces the safety data and threat data into the discrimination module for a second discrimination, and the discrimination module distinguishes whether each piece of data is safety data or threat data.
6. The AI-based satellite network threat analysis system according to claim 1, wherein: Also included is a threat response module; The threat response module is connected to the discrimination module and is used to formulate a corresponding threat response strategy based on the discrimination result output by the discrimination module; The threat response strategy includes but is not limited to blocking attack connections, isolating infected devices, repairing system vulnerabilities, and updating protection rules and measures; the threat response module can dynamically adjust the priority and intensity of the response strategy based on the type, severity and impact range of the threat, so as to achieve rapid, accurate and effective disposal of satellite network threats.
7. The AI-based satellite network threat analysis system according to claim 6, characterized in that: The threat response module also includes a response evaluation unit and an effect feedback unit; The response assessment unit monitors and evaluates the effectiveness of the threat response strategy in real time, collects relevant indicator data, including attack blocking success rate, system recovery time, and business impact, and generates a detailed response assessment report; The effect feedback unit feeds back the key information in the response assessment report to the training module, discrimination module and calibration module in the threat analysis subsystem, so that each module can further optimize its own function and performance according to the feedback information of the response effect, forming a closed threat analysis and response optimization loop, and continuously improving the security protection capability and intelligence level of the entire system.
Citation Information
Patent Citations
Method and system for quickly deploying meta-learning detection model of network threats in power network
CN117633779A
Satellite network multi-dimensional threat simulation method and system based on isolated forest detection
CN120050067A