A computer network security data transmission system

By using the data collection module and multiple algorithm units in the computer network security data transmission system, factors such as attack frequency, strength, and key length are quantified, and encryption strategies are dynamically adjusted. This solves the problem of insufficient security and risk assessment in existing data transmission systems, and achieves more intelligent and efficient data transmission.

CN120389887BActive Publication Date: 2026-02-17SHENZHEN GUNAI TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510524763.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2026-02-17
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

Existing computer network data transmission systems struggle to adjust encryption algorithms based on real-time attack conditions, leading to data leaks. Furthermore, it is difficult to comprehensively quantify and assess the impact of network bandwidth, latency, and packet size on transmission risks.

Method used

Security information is acquired through the data collection module. The data encryption hazard value algorithm unit, the data transmission hazard value algorithm unit, and the dynamic adjustment algorithm unit are used to calculate the data encryption hazard value Esv and the data transmission hazard value Dtr, and the encryption strategy is dynamically adjusted to adapt to different security requirements.

Benefits of technology

It realizes an adaptive and evolvable mathematical framework for computer network data transmission systems, improves security and intelligence, provides comprehensive risk assessment and encryption strategy adjustment, and ensures the security and efficiency of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389887B_ABST
    Figure CN120389887B_ABST
Patent Text Reader

Abstract

The application discloses a computer network security data transmission system and relates to the technical field of network security.The application forms a core framework of the computer network security data transmission system through mutual cooperation of multiple sets of algorithm units, calculates a data encryption danger value Esv by quantifying multiple factors such as attack frequency, intensity, fluctuation amplitude and key length, can dynamically adjust an encryption strategy to adapt to different security requirements, provides a self-adaptive and evolvable mathematical framework for the computer network security data transmission system, significantly improves the intelligent level of the system, and calculates a data transmission danger value Dtr by combining multiple influence factors such as data transmission time Dtt and network delay Nd through a transmission danger value algorithm unit, so that the computer network security data transmission system can comprehensively quantitatively evaluate data transmission risks and also provides scientific and reliable data support for adjustment of the encryption strategy in subsequent data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of network security, and particularly relates to a computer network security data transmission system. BACKGROUND

[0002] The computer network refers to a computer system in which multiple computers with independent functions and different geographical positions and external devices thereof are connected through communication lines and communication devices, and resources are shared and information is transmitted under the management and coordination of a network operating system, network management software and network communication protocols.

[0003] A computer network data security transmission method, device, equipment and medium are disclosed in Chinese Invention CN202310923973.1, and a computer network data security transmission method, device and storage medium are disclosed in Chinese Invention CN202410120621.7. In the current computer network data transmission, it is difficult to adjust the computer encryption algorithm according to the attack state (attack frequency, intensity, attack fluctuation amplitude) suffered in real time during the data transmission process, and data leakage is prone to occur due to attack intensity fluctuation during the data transmission process.

[0004] In addition, it is difficult to consider the bandwidth, delay and data packet size of the network to comprehensively quantitatively evaluate the data transmission risk, which is not conducive to the adjustment of the encryption algorithm and the secure transmission of data in subsequent data transmission.

[0005] Therefore, there is an urgent need for a computer network security data transmission system to solve the above problems. SUMMARY

[0006] The application aims to provide a computer network security data transmission system to solve the problems in the background art.

[0007] To achieve the above-mentioned purpose, the application provides a computer network security data transmission system, which comprises:

[0008] A data collection module is configured to acquire security information in network data transmission through a computer, and the security information comprises:

[0009] attack frequency, i-th attack flow, i-th attack time window, attack times, encryption key length, data transmission time, network delay, network bandwidth, data packet payload length and computer running memory remaining value.

[0010] A data preprocessing module is configured to decode and preprocess the security information in network data transmission to obtain parameters in a calculation processing module.

[0011] The calculation processing module comprises:

[0012] a data encryption risk value algorithm unit, configured to calculate an attack strength and an attack fluctuation amplitude according to the ith attack traffic, the ith attack time window, and the attack number, and calculate a data encryption risk value Esv and a reference value of the data encryption risk value Esv in combination with an attack frequency and an encryption key length in data transmission Danger , and calculate the data encryption risk value Esv and the reference value of the data encryption risk value Esv by calculation Danger calculate a risk multiple, and adjust the encryption algorithm according to the risk multiple;

[0013] a data transmission risk value algorithm unit, configured to take the encryption risk value Esv as an input parameter and calculate a data transmission risk value Dtr and an average value of the data transmission risk value Dtr in combination with a data transmission time, a network delay, a data packet payload length, and a network bandwidth average , and dynamically adjust the encryption strategy;

[0014] a dynamic adjustment algorithm unit, configured to take the data transmission risk value Dtr as an input parameter and calculate a dynamic adjustment value Dav in combination with a computer running memory remaining value, and perform parameter adjustment.

[0015] Optionally, the security information in the network data transmission is obtained, and specifically includes the following steps.

[0016] the ith attack traffic ATi, the attack frequency Afh, the ith attack time window TWi, and the attack number N are monitored and obtained by using a network security monitoring tool built in the computer;

[0017] the data transmission time Dtt and the network delay Nd are monitored and obtained by using a pin tool built in the computer;

[0018] the network bandwidth Nb is monitored and obtained by using a network bandwidth monitoring software built in the computer;

[0019] the data packet payload length PL is obtained by using a network protocol analyzer built in the computer;

[0020] the encryption key length KI in the data transmission is obtained by using an encryption algorithm built in the computer.

[0021] Optionally, the dynamic adjustment of the encryption strategy specifically includes the following steps.

[0022] a risk threshold Y of the data transmission risk value Dtr is set to 1.3 times Dtr in the database average ; when the data transmission risk value Dtr is less than the risk threshold Y, the network data transmission is continued;

[0023] When the data transmission risk value Dtr≥ the risk threshold Y, the safety measure is triggered: enabling data backup and blocking this data transmission, and the encryption algorithm is adjusted by one order.

[0024] Optionally, the parameter adjustment specifically includes:

[0025] The value αnew of the encryption risk coefficient α in the new round of calculation and the value βnew of the data transmission risk coefficient β in the new round of calculation are calculated through the dynamic adjustment value Dav.

[0026] The influence degree of the value αnew of the encryption risk coefficient α in the new round of calculation and the value βnew of the data transmission risk coefficient β in the new round of calculation is amplified when the dynamic adjustment value Dav is low, and the influence degree of the value αnew of the encryption risk coefficient α in the new round of calculation and the value βnew of the data transmission risk coefficient β in the new round of calculation is reduced when the dynamic adjustment value Dav is high, so that the value αnew of the encryption risk coefficient α in the new round of calculation and the value βnew of the data transmission risk coefficient β in the new round of calculation are stable.

[0027] Optionally, the calculation logic of the data encryption risk value algorithm unit is as follows:

[0028] S11, the attack frequency Afh is mapped to the logarithmic space through the natural logarithm, when the attack frequency Afh is high, the logarithmic function can inhibit the explosive growth of the calculation value, and avoid that the data encryption risk value Esv is dominated by a single factor and leads to distortion of the calculation result, when the attack frequency is low, the influence of the slight change on the encryption strength is amplified through the logarithmic function, and the sensitivity of the system to the initial attack behavior is improved;

[0029] S12, the attack strength of the i-th attack suffered by the computer data transmission is obtained by dividing the i-th attack traffic by the time window TWi of the i-th attack;

[0030] The amplitude value of the attack strength is obtained by calculating the ratio of the standard deviation of the multiple attack strengths and the average value μ of the attack strengths;

[0031] S13, the influence of the key length KI on the data encryption risk value Esv is normalized to the value interval [0.5, 1.5], which reflects the reverse influence of the key length KI on the data encryption risk value Esv and avoids the excessive influence of the key length KI on the data encryption risk value Esv.

[0032] Optionally, the calculation logic of the data transmission risk value algorithm unit is as follows:

[0033] S31, the data risk exposure area is obtained by multiplying the data transmission time by the network delay Nd, specifically:

[0034] The time risk of computer network data during transmission is analogized into a rectangle, the length of the rectangle is the data transmission time Dtt, and the width is the network delay Nd, the Dtt*Nd is increased, the "area" of the rectangle is increased, the time-space range of the data packet exposed to the attack is increased, the risk during data transmission is higher, and the data transmission risk value Dtr obtained by increasing the calculation is higher;

[0035] S32, the non-linear influence of the data packet payload length PL on the data transmission risk value Dtr is embodied by a logarithmic function, the logarithmic function makes the system more sensitive to small packet data changes, and meanwhile, the excessive influence of the payload length PL on the data transmission risk value Dtr is avoided.

[0036] Optionally, the calculation logic of the dynamic adjustment algorithm unit is as follows:

[0037] The risk ratio value of data transmission is obtained by dividing the data transmission risk value Dtr by the average value Dtraverage of the data transmission risk value, and the risk ratio value is a basic value for calculating the dynamic adjustment value Dav;

[0038] The influence value of the computer running memory remaining value Crm on the dynamic adjustment value Dav is mapped to the interval of 0-1 through a Sigmoid function, the positive influence of the computer running memory remaining value Crm on the dynamic adjustment value Dav is embodied, and meanwhile, the excessive influence of the key length KI on the data encryption risk value Esv is avoided;

[0039] The dynamic adjustment value Dav is calculated according to the risk ratio value and the influence value of the computer running memory remaining value Crm on the dynamic adjustment value Dav;

[0040] The value of the encryption risk coefficient alpha in the new round of calculation and the value of the data transmission risk coefficient beta in the new round of calculation are calculated according to the dynamic adjustment value Dav.

[0041] Optionally, the encryption algorithm adjustment according to the risk multiple specifically includes:

[0042] When the risk multiple is greater than or equal to 1.5, it is represented that the computer network data transmission risk is over-standard, the encryption algorithm is adjusted, and the AES-256 is replaced by the AES-128;

[0043] When the risk multiple is greater than or equal to 1.5, it is represented that the computer network data transmission risk is over-standard, the encryption algorithm is adjusted, and the AES-256 is replaced by the AES-128;

[0044] When the risk multiple is less than 0.75, it is represented that the computer network data transmission is safe and redundant, and the encryption algorithm is degraded.

[0045] Compared with the prior art, the beneficial effects of the present application are as follows:

[0046] The present application is a kind of computer network security data transmission system core architecture by the mutual cooperation of three groups of algorithm units, by quantifying attack frequency, intensity, fluctuation amplitude and key length and other factors, data encryption risk value Esv is calculated, which can provide an intuitive security index in computer network security data transmission system, to help the system to evaluate the security of the current data transmission environment, and can dynamically adjust the encryption strategy according to the data encryption risk value Esv value, to adapt to different security requirements, provide a self-adaptive, evolutionary mathematical framework for computer network security data transmission system, significantly improve the intelligent level of the system.

[0047] The present application is a kind of computer network security data transmission system core architecture by the mutual cooperation of three groups of algorithm units, by quantifying attack frequency, intensity, fluctuation amplitude and key length and other factors, data encryption risk value Esv is calculated, which can provide an intuitive security index in computer network security data transmission system, to help the system to evaluate the security of the current data transmission environment, and can dynamically adjust the encryption strategy according to the data encryption risk value Esv value, to adapt to different security requirements, provide a self-adaptive, evolutionary mathematical framework for computer network security data transmission system, significantly improve the intelligent level of the system. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 It is a kind of computer network security data transmission system overall structure schematic diagram. DETAILED DESCRIPTION

[0049] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0050] Embodiment one, please refer to Figure 1 The present application provides a kind of computer network security data transmission system, comprising:

[0051] Data collection module is used to obtain security information in network data transmission by computer, specifically comprising:

[0052] The first i attack flow ATi, attack frequency Afh, the time window TWi of the i attack, attack number N are monitored and obtained by computer built-in network security monitoring tool;

[0053] The data transmission time Dtt and network latency Nd are monitored and obtained using the computer's built-in pin tool.

[0054] The network bandwidth Nb is obtained by monitoring the network bandwidth monitoring software built into the computer.

[0055] The effective payload length PL of the data packets is obtained using the computer's built-in network protocol analyzer.

[0056] The encryption key length KI in data transmission is obtained through the computer's built-in encryption algorithm;

[0057] Uploaded together to the database;

[0058] The calculation and processing module, and the specific calculation and processing steps are as follows:

[0059] S1, calculates the data encryption hazard value Esv and the baseline value Esv of the data encryption hazard value through the data encryption hazard value algorithm unit. Danger ;

[0060] S2, by calculating the data encryption risk value Esv and the baseline value Esv of the data encryption risk value. Danger Calculate the danger multiple and adjust the encryption algorithm accordingly;

[0061] S3. Input the encryption risk value Esv into the data transmission risk value algorithm unit to calculate the data transmission risk value Dtr and the average value Dtr of the data transmission risk value. average ;

[0062] S4, set the danger threshold Y of the data transmission danger value Dtr in the database to 1.3 times Dtr. average When the data transmission danger value Dtr < danger threshold Y, network data transmission continues.

[0063] When the data transmission danger value Dtr is greater than or equal to the danger threshold Y, security measures are triggered, including:

[0064] Enable data backup and block this data transmission; increase the encryption algorithm by one level.

[0065] The data transmission hazard value Dtr is input into the dynamic adjustment algorithm unit to calculate the dynamic adjustment value Dav and perform parameter adjustments. Parameter adjustments specifically include:

[0066] The encryption risk factor α and the data transmission risk factor β in the new round of calculation are calculated by dynamically adjusting the value Dav.

[0067] The adjusted parameters are used to re-transmit the secondary data and perform a new round of formula calculations.

[0068] In the present embodiment:

[0069] The present application, through the cooperation of multiple algorithm units, constitutes the core architecture of a computer network security data transmission system, can quantify the influencing factors such as attack frequency, intensity, fluctuation amplitude and key length, calculate the data encryption danger value Esv, provide an intuitive security index in the computer network security data transmission system, help the system to evaluate the security of the current data transmission environment, and dynamically adjust the encryption strategy according to the data encryption danger value Esv, to adapt to different security requirements, provide an adaptive and evolutionary mathematical framework for the computer network security data transmission system, and significantly improve the intelligent level of the system.

[0070] And by inputting the data encryption danger value Esv into the data transmission danger value algorithm unit, and combining multiple factors such as data transmission time Dtt, network delay Nd, data packet payload length PL, network bandwidth Nb, etc., the data transmission danger value Dtr is calculated, so that the computer network security data transmission system can comprehensively quantify and evaluate the data transmission risk, improve the comprehensiveness and accuracy of network security evaluation, and provide scientific and reliable data support for the adjustment of encryption strategy in subsequent data transmission, which helps to build a more intelligent, efficient and secure computer network data transmission system to meet the high standard requirements of modern network security.

[0071] Please refer to Figure 1 , the data encryption danger value algorithm unit is as follows:

[0072] ;

[0073] Among them:

[0074] Esv represents the data encryption danger value;

[0075] Afh represents the attack frequency, which represents the number of attacks on the network per unit time;

[0076] ATi represents the i-th attack flow, which represents the flow generated by abnormal user requests or business interactions, and is the flow of the computer when malicious subjects overload target servers or network devices through a large amount of network flow. It is obtained by monitoring through the built-in network security monitoring tool of the computer;

[0077] TWi represents the time window of the i-th attack, which is the time length of the i-th attack, and is obtained by monitoring through the built-in network security monitoring tool of the computer;

[0078] KI represents the key length, which is the length of the protection key during computer data transmission;

[0079] N represents the number of attacks;

[0080] a represents the encryption risk coefficient, the default value is 0.8;

[0081] μ represents the average value of attack intensity;

[0082] The calculation formula of μ is as follows:

[0083] ;

[0084] This part maps the attack frequency Afh from the linear space to the logarithmic space through the natural logarithm function. When the attack frequency Afh is high (such as a distributed denial of service attack), the logarithmic function can suppress the explosive growth of the calculation value, avoiding the distortion of the calculation result caused by the dominance of a single factor in the encryption risk value Esv. When the attack frequency is low, the logarithmic function can amplify the influence of small changes on the encryption strength, making the system more sensitive to initial attack behavior;

[0085] By dividing the ith attack traffic by the time window TWi of the ith attack, the traffic intensity of the ith attack in the unit time window is represented, that is, the attack intensity of the ith attack suffered by the computer data transmission. Then, by This part calculates the variance of the attack intensity, and finally the standard deviation of the attack intensity is obtained by taking the square root of the whole, This part represents the amplitude value of the attack intensity by dividing the standard deviation of the attack intensity by the average value μ of the attack intensity. Specifically:

[0086] The higher the fluctuation amplitude, the more unpredictable the attack behavior (such as burst pulse attack), and the higher the encryption requirement of computer network data. The larger the data encryption risk value Esv calculated;

[0087] The lower the fluctuation amplitude, the more regular the attack behavior (such as periodic attack), and the relatively lower the encryption requirement of computer network data. The data encryption risk value Esv calculated is reduced;

[0088] This part normalizes the influence of the key length KI on the data encryption risk value Esv to the value interval [0.5, 1.5]. Specifically:

[0089] When the key length KI takes the value of 128 (which is the commonly used key length for computer data transmission), The value of this part is 1, and at this time the key length KI has no influence on the calculation of the data encryption risk value Esv;

[0090] When the key length KI takes the value from 128 and increases, the longer the key length, the more complex the encryption algorithm needed, and the stronger the protection effect on computer data. At this time The part of the value is located in the interval [0.5, 1), and the calculated data encryption risk value Esv is reduced;

[0091] When the key length KI is reduced from 128, the protection effect of the computer data is reduced, and at this time The part of the value is located in the interval (1, 1.5], and the calculated data encryption risk value Esv is increased;

[0092] In the embodiment, the data encryption risk value algorithm unit quantifies the influencing factors such as attack frequency, intensity, fluctuation amplitude and key length, and calculates the data encryption risk value Esv, which can provide an intuitive security index and help the computer network security data transmission system to evaluate the security of the current data transmission environment. According to the data encryption risk value Esv, the system can dynamically adjust the encryption strategy to adapt to different security requirements. For example, when the data encryption risk value Esv is high, longer protection keys, more complex encryption algorithms or more encryption layers can be selected to improve the confidentiality and integrity of the data. On the contrary, when the data encryption risk value Esv is low, the encryption strategy can be appropriately simplified to balance security and performance. Specifically:

[0093] When the data encryption risk value Esv increases, the computer network security data transmission system can automatically select and adjust the encryption algorithm such as AES-256 instead of AES-128, increase the key length from 128 bits to 256 bits, and replace the CBC operation mode with the GCM operation mode to ensure that the data transmission intensity and risk match, and avoid data leakage due to attack intensity fluctuation.

[0094] And through long-term monitoring and analysis of the encryption risk value Esv, the computer network security data transmission system can identify attack patterns and predict future threat trends, so as to develop defense strategies in advance, providing an adaptive and evolutionary mathematical framework for the computer network security data transmission system, and significantly improving the intelligent level of the system.

[0095] The above-mentioned AES encryption algorithm, GCM encryption operation mode and CBC encryption operation mode are relatively mature existing technologies in computer network data encryption, and will not be described here.

[0096] Please refer to Figure 1 , the data transmission risk value algorithm unit is as follows:

[0097] ;

[0098] Among them:

[0099] Dtr represents the data transmission risk value;

[0100] Esv represents the data encryption risk value, which is calculated by the data encryption risk value algorithm unit;

[0101] Esv Danger The reference value of the data encryption risk value is the calculated value when the attack frequency Afh=10, the attack number N=5, the key length KI=128, and the amplitude value of the attack strength is 1.5;

[0102] Dtt represents the data transmission time, which is measured in seconds, and is obtained by monitoring the computer's built-in pin tool;

[0103] Nd represents the network delay, which is measured in milliseconds, and is obtained by monitoring the computer's built-in pin tool;

[0104] PL represents the data packet payload length, which is measured in MB, and is obtained by the computer's built-in network protocol analyzer (Wireshark);

[0105] Nb represents the network bandwidth, which is measured in Mbps, and is obtained by monitoring the computer's built-in network bandwidth monitoring software;

[0106] β is the data transmission risk coefficient, and the default value is 1.2;

[0107] This part represents the data risk exposure area by multiplying the data transmission time by the network delay Nd. Specifically:

[0108] The larger the data transmission time Dtt, the longer the total duration of data exposure in the transmission channel, the higher the probability of interception or tampering, and the larger the calculated data transmission risk value Dtr;

[0109] The larger the network delay Nd, the longer the data packet stays in the network nodes (such as routers, firewalls), i.e., the longer the data is temporarily stored in the intermediate nodes, the larger the vulnerability window, and the larger the calculated data transmission risk value Dtr;

[0110] The time risk of computer network data during transmission is analogous to a rectangle, with the length of the rectangle being the data transmission time Dtt and the width being the network delay Nd. The larger the area of the rectangle (Dtt x Nd) , the larger the space-time range of data packets exposed to attacks, the higher the risk, and thus the larger the calculated data transmission risk value Dtr;

[0111] This part as the formula in the molecule, through the logarithmic function embodies the nonlinear influence of data packet payload length PL on data transmission risk value Dtr, with the increase of data packet payload length PL, the data to be transmitted is larger, so it will increase the calculated data transmission risk value Dtr, network attackers often use small packet high frequency attack (such as SYN Flood) when attacking data, rather than simply large packet form of attack, using logarithmic function can make the system more sensitive to small packet data changes, while avoiding the excessive influence of payload length PL on data transmission risk value Dtr when it is too large, improving the robustness of computer network security data transmission system;

[0112] Network bandwidth Nb as the denominator in the formula, when the network bandwidth Nb increases, it means that the computer has faster data transmission speed, with the increase of data transmission speed, the total time of data in the transmission channel will be reduced, the probability of interception or tampering will be reduced, so as to reduce the calculated data transmission risk value Dtr;

[0113] This part is divided by the data encryption risk value Esv Danger , which represents the risk multiple, the specific value is the risk degree of the current network attack, which is how many times of the "baseline risk value". Specifically:

[0114] When ≥1.5, it means that the computer network data transmission risk is over standard, adjust the encryption algorithm, replace AES-128 with AES-256;

[0115] When 0.75≤ <1.5, it means that the computer network data transmission is in a safe range, and there is no need to adjust the encryption algorithm;

[0116] When <0.75, it means that the computer network data transmission is safe and redundant, and the encryption algorithm should be degraded to save resources;

[0117] By analyzing the data transmission risk value Dtr in the computer network security data transmission system database, the system can dynamically adjust the encryption algorithm. Specifically:

[0118] Set the risk threshold Y of data transmission risk value Dtr in the database as 1.3 times Dtr average , where Dtr averageThe average value of the data transmission risk value Dtr in the system in the past month, when the data transmission risk value Dtr exceeds the risk threshold Y, the system automatically enables data backup and blocks this data transmission to prevent data leakage, at the same time, the encryption algorithm is adjusted by one order, and the data transmission risk value Dtr is input into the dynamic adjustment algorithm unit for parameter adjustment and then the secondary data transmission and a new round of formula calculation are carried out.

[0119] In this embodiment:

[0120] By inputting the data encryption risk value Esv into the data transmission risk value algorithm unit, and integrating multiple factors such as data transmission time Dtt, network delay Nd, data packet payload length PL, network bandwidth Nb, etc. through the data transmission risk value algorithm unit, the data transmission risk value Dtr is calculated, which avoids the limitation of single influencing parameter, so that the computer network security data transmission system can comprehensively quantify the data transmission risk. Through analyzing the data transmission risk value Dtr in the system, the computer network security data transmission system intelligently adjusts the bandwidth allocation, for example:

[0121] When the data transmission risk value Dtr is high, the system can preferentially allocate more bandwidth to critical data transmission, reducing transmission failure or delay caused by insufficient bandwidth;

[0122] And by analyzing the trend of Dtr value, the system can predict potential network failures, for example, when the network delay Nd continuously increases and the data transmission risk value Dtr value rises, the system can early warning network congestion or attack risk, and the data transmission risk value Dtr is associated with data encryption risk value Esv, data transmission time Dtt and other parameters to generate intuitive risk report, so as to help computer quickly identify high-risk data transmission area.

[0123] In summary, combining data encryption risk value Esv with data transmission parameters and calculating data transmission risk value Dtr not only improves the comprehensiveness and accuracy of network security evaluation, but also provides scientific basis for optimizing resource allocation, enhancing encryption strategy and improving network reliability, which helps to build more intelligent, efficient and secure computer network data transmission system to meet the high standard requirements of modern network security.

[0124] Please refer to Figure 1 , the dynamic adjustment algorithm unit is as follows:

[0125] ;

[0126] Among them:

[0127] Dav represents the dynamic adjustment value;

[0128] Dtr represents the data transmission risk value;

[0129] Dtr average Dtr represents the average value of the data transmission risk value;

[0130] Cth represents the available threshold value of the computer running memory, and the default value is 0.3;

[0131] Crm represents the computer running memory remaining value, which is obtained by subtracting the running memory usage from 100%, and the running memory usage is obtained by real-time monitoring of the task manager of the computer;

[0132] Se min Se represents the minimum value of the encryption performance compensation value, which is the minimum value in the calculation of the encryption performance compensation value in the previous encryption recorded in the database;

[0133] This part is divided by the average value of the data transmission risk value Dtr average , which represents the risk ratio value of data transmission, and is the basis value for calculating the dynamic adjustment value Dav;

[0134] This part is a transformation of the Sigmoid function, which maps the influence value of the computer running memory remaining value Crm on the dynamic adjustment value Dav to the interval of 0 to 1 through the Sigmoid function. With the increase of the computer running memory remaining value Crm, it represents that the computer has more running memory remaining, and there is more running memory to enhance the encryption algorithm and adjust the parameters, thereby increasing the dynamic adjustment value Dav obtained by calculation;

[0135] The parameter adjustment formula of the encryption risk coefficient a and the data transmission risk coefficient β is as follows:

[0136] ;

[0137] Wherein:

[0138] αnew represents the value of the encryption risk coefficient a in the new round of calculation;

[0139] βnew represents the value of the data transmission risk coefficient β in the new round of calculation;

[0140] In this embodiment:

[0141] The dynamic adjustment algorithm unit takes the data transmission risk value Dtr as an input parameter and combines the computer running memory remaining value and the available threshold value to calculate the dynamic adjustment value Dav, so that the computer network security data transmission system can dynamically perceive the security risks (such as insufficient encryption strength, transmission delay, network congestion, etc.) in the current network environment, and combine the computer running memory remaining value and the available threshold value to dynamically adjust the parameter values in the data encryption risk value algorithm unit and the data transmission risk value algorithm unit, thereby enhancing protection when the computer network data transmission risk is high, and in the face of constantly changing network attack means (such as man-in-the-middle attacks, data tampering, denial-of-service attacks, etc.), this kind of dynamic adjustment mechanism can quickly respond, and by adjusting the parameter values, the anti-attack ability of the computer network security data transmission system is improved, and the overall efficiency of the computer network security data transmission system is improved, making it more robust, efficient and reliable in complex and variable network environments.

[0142] Although embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements and changes can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A computer network security data transmission system, characterized by, include: The data collection module is used to acquire security information in network data transmission via computer. The security information includes attack frequency, traffic of the i-th attack, time window of the i-th attack, number of attacks, encryption key length, data transmission time, network latency, network bandwidth, data packet payload length, and remaining computer memory. The data preprocessing module decodes and preprocesses security information in network data transmission to obtain parameters that will be used in the computation and processing module. The computational processing module includes: The data encryption risk value algorithm unit is used for calculating the attack strength and attack fluctuation amplitude according to the ith attack traffic, the time window of the ith attack, and the attack times, and calculating the data encryption risk value Esv and the reference value of the data encryption risk value Esv in combination with the attack frequency and the encryption key length in the data transmission. Danger The data encryption risk value Esv and the reference value of the data encryption risk value Esv are calculated by calculating the data encryption risk value Esv and the reference value of the data encryption risk value Esv. Danger The risk multiple is calculated, and the encryption algorithm is adjusted according to the risk multiple. a data transmission risk value algorithm unit, configured to take the encryption risk value Esv as an input parameter, and calculate a data transmission risk value Dtr and an average value Dtr of the data transmission risk value in combination with a data transmission time, a network delay, a data packet payload length and a network bandwidth average and dynamically adjust the encryption policy; The data transmission hazard value algorithm unit is as follows: ; in: Dtr represents the data transmission risk value, Esv represents the data encryption risk value, Esv Danger Dtt represents the data transmission time, Nd represents the network delay, PL represents the data packet payload length, Nb represents the network bandwidth, and β is the data transmission risk coefficient, This part represents the data risk exposure area; The dynamic adjustment algorithm unit is used to calculate the dynamic adjustment value Dav by taking the data transmission danger value Dtr as an input parameter and combining it with the remaining value of the computer's running memory, and then adjust the parameters.

2. The computer network security data transmission system of claim 1, wherein: The data collection module acquires security information during network data transmission, specifically including: The computer's built-in network security monitoring tools are used to monitor and obtain the attack traffic ATi, attack frequency Afh, time window TWi, and number of attacks N for the i-th attack. The data transmission time Dtt and network latency Nd are monitored and obtained using the computer's built-in pin tool. The network bandwidth Nb is obtained by monitoring the network bandwidth monitoring software built into the computer. The effective payload length PL of the data packets is obtained using the computer's built-in network protocol analyzer. The encryption key length KI in data transmission is obtained through the computer's built-in encryption algorithm.

3. The computer network security data transmission system of claim 2, wherein: The data transmission risk value algorithm unit dynamically adjusts the encryption strategy, specifically including: The danger threshold Y of the data transmission danger value Dtr is set to 1.3 times Dtr in the database average ; when the data transmission danger value Dtr is less than the danger threshold Y, the network data transmission is continued; When the data transmission danger value Dtr is greater than or equal to the danger threshold Y, security measures are triggered: data backup is enabled and the data transmission is blocked, and the encryption algorithm is upgraded by one level.

4. The computer network security data transmission system of claim 3, wherein: The parameter adjustment in the dynamic adjustment algorithm unit specifically includes: The encryption risk factor α and the data transmission risk factor β in the new round of calculation are calculated by dynamically adjusting the value Dav. By amplifying the impact of low dynamic adjustment value Dav on the encryption risk coefficient αnew and the data transmission risk coefficient βnew in the new round of calculation, and reducing the impact of high dynamic adjustment value Dav on the encryption risk coefficient αnew and the data transmission risk coefficient βnew in the new round of calculation, we obtain numerically stable values ​​of encryption risk coefficient αnew and data transmission risk coefficient βnew in the new round of calculation.

5. The computer network security data transmission system of claim 4, wherein: The calculation logic of the data encryption risk value algorithm unit is as follows: S11 maps the attack frequency Afh to the logarithmic space using the natural logarithm; S12, the attack strength of the i-th attack suffered during computer data transmission is obtained by dividing the traffic of the i-th attack by the time window TWi of the i-th attack. The amplitude value of the attack intensity is obtained by calculating the ratio of the standard deviation of the attack intensity to the average value μ of the attack intensity over multiple attacks. S13, normalize the effect of key length KI on the data encryption risk value Esv to the numerical range of [0.5, 1.5].

6. The computer network security data transmission system of claim 1, wherein: The calculation logic of the dynamic adjustment algorithm unit is as follows: The risk ratio value of data transmission is obtained by dividing the data transmission risk value Dtr by the average value Dtraverage of the data transmission risk value, and is a basis value for calculating the dynamic adjustment value Dav; The influence value of the computer running memory remaining value Crm on the dynamic adjustment value Dav is mapped to the interval of 0-1 by a Sigmoid function; The dynamic adjustment value Dav is calculated according to the risk ratio value and the influence value of the computer running memory remaining value Crm on the dynamic adjustment value Dav; The value of the encryption risk coefficient a in the new round of calculation and the value of the data transmission risk coefficient β in the new round of calculation are calculated according to the dynamic adjustment value Dav.

7. The computer network security data transmission system of claim 1, wherein, The encryption algorithm adjustment according to the risk multiple specifically includes: When the risk multiple is greater than or equal to 1.5, it represents that the computer network data transmission risk is over standard, and the encryption algorithm is adjusted by replacing AES-128 with AES-256; When the risk multiple is greater than 0.75 and less than 1.5, it represents that the computer network data transmission is in a safe range, and no encryption algorithm adjustment is needed; When the risk multiple is less than 0.75, it represents that the computer network data transmission is safe and redundant, and the encryption algorithm is degraded.

Citation Information

Patent Citations

  • Computer network data secure transmission method and device, equipment and medium

    CN116938567A

  • Computer network data secure transmission method and device and storage medium

    CN117914486A

  • Communication management system based on artificial intelligence

    CN117544428A

  • Data encryption transmission system and method

    CN119544242A