Low earth orbit satellite adaptive intrusion detection method and system

By identifying regional threat levels and predicting network traffic, dynamically switching detection container combinations are solved, and low-orbit satellites are not detecting in time in different regions and resource waste, achieving efficient intrusion detection and rapid response under limited resource conditions.

CN120415906AActive Publication Date: 2025-08-01WEBRAY TECH BEIJING CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510902678.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-08-01
Estimated Expiration
2045-07-01

AI Technical Summary

Technical Problem

The prior art cannot achieve real-time adjustments when low-orbit satellites frequently cross different threat level areas, resulting in untimely detection or waste of resources. The hardware acceleration solution is not suitable for resource-constrained environments of low-orbit satellites.

Method used

By obtaining the area where the satellite is about to enter, identifying the network threat level, predicting network traffic, calling the appropriate detection container combination, combining real-time network traffic for intrusion risk detection, and using an intelligent traffic distribution engine to achieve dynamic switching of the detection mode.

Benefits of technology

It has achieved rapid improvement of detection capabilities in high-risk areas, saved resources in low-risk areas, reduced system energy consumption, and ensured accurate monitoring and rapid feedback in full time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415906A_ABST
    Figure CN120415906A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a self-adaptive intrusion detection method and system for a low-orbit satellite. The method comprises the following steps: acquiring an area where a satellite is about to enter; identifying the network threat level of the area according to the network flow characteristics of the area; predicting the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area; calling an adaptive detection container combination according to a prediction result and the network threat level; and in response to the real-time network traffic after the satellite enters the area, distributing the real-time network traffic in the detection container combination to cooperatively complete intrusion risk detection. According to the embodiment, intrusion detection resources can be saved, and the detection speed is increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the technical field of satellite network security, and in particular, to a low-earth orbit satellite adaptive intrusion detection method and system. Background Art

[0002] In order to maintain satellite network security, a fixed detection module is usually used for full-time monitoring. However, this solution cannot be adjusted in real time for the low-earth orbit satellite frequently crossing different threat level regions. Therefore, detection may not be timely in high-risk regions, and there is a waste of resources in low-risk regions.

[0003] Another method uses hardware acceleration combined with software detection for intrusion prevention. Although it can improve the detection speed, due to the large volume and high energy consumption of hardware devices, it is not suitable for the resource-constrained environment of low-earth orbit satellites, and the system flexibility is insufficient to meet the needs of satellites frequently entering different regions.

[0004] Patent application CN117014203A discloses a satellite network adaptive security service system and method, and patent application CN119155101A discloses an intrusion detection and response method and system for a satellite Internet range, both of which cannot well solve the above problems. Summary of the Invention

[0005] Embodiments of the present invention provide a low-earth orbit satellite adaptive intrusion detection method and system to solve at least one of the above problems.

[0006] In a first aspect, embodiments of the present invention provide a low-earth orbit satellite adaptive intrusion detection method, including: Obtaining the area that the satellite is about to enter; Identifying the network threat level of the area according to the network traffic characteristics of the area; Predicting the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area; Invoking an adapted detection container combination according to the prediction result and the network threat level; In response to the real-time network traffic after the satellite enters the area, distributing the real-time network traffic within the detection container combination to cooperate to complete the intrusion risk detection.

[0007] In a second aspect, embodiments of the present invention provide an electronic device, where the electronic device includes: One or more processors; A memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the low-earth orbit satellite adaptive intrusion detection method according to any embodiment.

[0008] In a third aspect, an embodiment of the present invention further provides a low-earth orbit satellite adaptive intrusion detection system, including: A satellite system for obtaining the area that the satellite is about to enter; An area recognition component for identifying the network threat level of the area according to the network traffic characteristics of the area; A traffic prediction component for predicting the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area; A mode switching component for calling an adapted detection container combination according to the prediction result and the network threat level; A traffic distribution engine for distributing the real-time network traffic in the detection container combination in response to the real-time network traffic after the satellite enters the area, and cooperating to complete the intrusion risk detection.

[0009] In summary, an embodiment of the present invention provides a low-earth orbit satellite adaptive intrusion detection method, aiming to overcome the defects of fixed detection mode, resource waste, and hardware dependence in the prior art, and realizing dynamic detection container switching when the satellite enters different threat areas. This method can: 1. By combining real-time satellite positioning data with historical area attack data, construct an area threat judgment model to realize the instant assessment of the network risk in the area where the satellite is located, and provide an accurate basis for subsequent detection container switching; 2. Adopt a traffic prediction and mode switching mechanism to preload or adjust the corresponding detection strategies and detection containers before the satellite enters different threat areas, so as to ensure that the detection ability can be quickly improved in high-risk areas and resources can be effectively saved in low-risk areas; 3. Realize request orientation through an intelligent traffic distribution engine to ensure that each detection container obtains sufficient detection data, and realize dynamic traffic distribution and detection mode switching under the conditions of limited computing and energy resources to ensure full-time and accurate monitoring; 4. Reduce system energy consumption, improve the satellite security protection efficiency, and support the rapid feedback and timely warning of abnormal information.

[0010] Through the above various methods, this embodiment not only has a significant improvement in data processing speed, but also can ensure highly accurate intrusion detection under limited energy conditions, with outstanding technical advantages and practical application and promotion value: 1. Save resources: Automatically switch the detection mode according to the actual area threat level, adopt high-precision detection containers in high-risk areas, and adopt lightweight detection methods in low-risk areas, greatly optimizing the use of computing resources and energy; 2. Improve the detection response speed: By combining the preloading of the detection engine container with real-time traffic distribution technology, a high-performance detection mode can be quickly launched when entering a high-risk area, thereby shortening the time for attack detection and warning response. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0012] Figure 1 is a schematic diagram of the architecture of a low-earth orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention; Figure 2 is a timing flowchart of the coordinated operation of each part of a low-earth orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention; Figure 3 is a flowchart of a low-earth orbit satellite adaptive intrusion detection method provided by an embodiment of the present invention; Figure 4 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0013] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0014] In the description of the present invention, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention. In addition, the terms "first", "second", "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0015] In the description of the present invention, it should also be noted that unless otherwise clearly specified and defined, the terms "installation", "connection", and "coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0016] An embodiment of the present invention provides a low-earth orbit satellite adaptive intrusion detection method. To illustrate this method, a low-earth orbit satellite adaptive intrusion detection system that supports the implementation of this method is introduced first. Figure 1 is a schematic diagram of the architecture of a low-earth orbit satellite adaptive intrusion detection system provided by an embodiment of the present invention, as Figure 1 shown, the system includes a region and pre-judgment module, a detection mode and container scheduling module, a traffic distribution and detection module, and a system management and logging module.

[0017] Among them, the region and pre-judgment module is used to compare the current position of the satellite with historical data to obtain a regional threat value, and initiate a mode switch according to the traffic prediction result; the detection mode and container scheduling module is responsible for automatically selecting and loading the corresponding detection container according to the pre-judgment result, and synchronously updating the policy to the configuration manager at the same time; after receiving the real-time traffic, the traffic distribution and detection module imports the data into a specific intrusion detection engine container according to the scheduling result for in-depth detection; the system management and logging module is responsible for the configuration, management of the entire system parameters, as well as the recording of detection results and the reporting of alarm information.

[0018] Figure 2 The following uses a timing flowchart to illustrate how the system modules cooperate with each other when the low-earth orbit satellite enters a new region, so as to realize the whole process of data capture, processing, distribution to detection: ① The satellite system continuously transmits the current position information and preliminary traffic data during flight; ② The region recognition component compares the positioning data with the pre-stored regional database to obtain a threat rating; ③ The traffic prediction component estimates the future traffic situation based on historical data and real-time information, and assists the mode switching component to make a response judgment; ④ The mode switching component notifies the detection container management system to load or update the detection container, and at the same time ensures that the parameters of each module are consistent through the configuration manager; ⑤ The traffic distribution engine imports the real-time data into the specified intrusion detection engine container according to the configuration policy, and the latter performs in-depth data analysis; ⑥ The detection results are archived through the log recording module, and when an anomaly is found, the satellite system and the ground terminal are quickly notified to achieve rapid response and security protection.

[0019] Based on the above system architecture and basic timing, Figure 3 is a flowchart of an adaptive intrusion detection method for low-earth orbit satellites provided by an embodiment of the present invention. This method relies on regional pre-judgment and dynamic detection container switching technologies to achieve a full-link response from data positioning, pre-judgment, detection to alarm, which can be executed in cooperation with each part of the above system or by a separate electronic device. As Figure 3 shown, the method specifically includes: S110. Obtain the area that the satellite is about to enter.

[0020] Optionally, satellite area division can be performed in advance. Specifically, according to the orbital characteristics of low-earth orbit satellites, the area on the earth's surface is segmented, and a regional database is constructed based on historical traffic data and network attack events. The regional database records the attack characteristics, traffic peak statistics, and descriptions of abnormal behaviors that each area may face. The prior regional characteristics provide data support for the subsequent selection of detection modes.

[0021] After the division is completed, the satellite continuously obtains its own position information during operation. When it detects that it is about to enter a certain area, it starts to execute the method of this embodiment.

[0022] S120. Identify the network threat level of the area according to the network traffic characteristics of the area.

[0023] Combined with Figure 2 , the regional identification component judges the network threat level of the area where it is located and transmits the result to the traffic prediction component. The regional identification component uses the geographic information system module to map the current position to a predefined area and calls the relevant historical data in the regional database to obtain the threat level of the current area through a decision model. The threat level is divided into low, medium, and high levels, and its result directly affects the selection of subsequent intrusion detection strategies.

[0024] Specifically, the above decision model combines historical statistical information and real-time satellite status to accurately and dynamically evaluate the network risk of the area where the satellite is currently located. In a specific embodiment, the identification of the network threat level includes the following steps: Step 1. Feature extraction and quantization. The regional identification component retrieves the historical data of the corresponding area from the "regional database", extracts and quantifies the following key features to form a multi-dimensional feature vector V = [f1, f2, f3, f4, ..., fn], where: f1 represents the historical attack frequency. For example: the number of attack events detected in this area in the past X days / frequency, where X is a natural number; f2 represents the historical attack severity. For example, it is the average or maximum severity score assigned according to the attack type (such as DDoS, probing, malicious code, etc.). Among them, the full Chinese and English name of DDoS is Distributed Denial of Service; f3 represents the historical traffic peak anomaly. For example, it is the standard deviation multiple or percentage by which the historical peak traffic exceeds the normal baseline of this area; f4 represents the known vulnerability indicator. For example, it is the vulnerability score of the network infrastructure or protocol that is known to exist and may be exploited within this area; f5 represents the threat transfer factor of the neighboring area. Considering the threat level of the neighboring area that the satellite is about to enter or has just left, an impact factor based on distance or relevance is assigned; f6 represents the real-time global threat intelligence correlation degree, that is, matching the current area characteristics with the real-time updated global network threat intelligence library to evaluate whether there are known active attack activities or early warnings targeting this area.

[0025] Step 2: Dynamic weight assignment. Assign a weight wi to each feature fi in the feature vector V, where i = 1, 2, …, n. These weights are not fixed but can be dynamically adjusted according to the system policy or the real-time situation. The adjustment basis can include: Satellite mission priority: During high-priority missions, higher weights are assigned to "attack severity" and "real-time intelligence"; Global security situation: When a certain specific attack (such as large-scale DDoS) occurs frequently globally, the weight of the corresponding attack feature is increased; Model feedback: According to the historical prediction accuracy and the actual attack events that occurred, through machine learning or reinforcement learning methods, the weight assignment is optimized regularly to make it more suitable for the current environment.

[0026] Step 3: Weighted fusion calculation. Calculate the weighted comprehensive threat score S: S = Σ(wi × fi), where fi here is the normalized feature value.

[0027] Step 4: Dynamic threshold determination. Set dynamic thresholds T_low and T_high to map the comprehensive threat score S to threat levels Threat Level (Low, Medium, High). Among them, the dynamic nature of the thresholds is reflected in that these thresholds can be fine-tuned based on the overall satellite resource status. For example, when the satellite's computing or storage resources are strained, the threshold for entering the "High" threat level may be appropriately increased to avoid resource consumption caused by overly frequent mode switches. Optionally, the thresholds can also be associated with the predicted traffic peak. For example, when a coming traffic peak is predicted, even if the threat score S is the same, it may be more likely to be determined as the "Medium" or "High" level to prepare stronger detection capabilities in advance.

[0028] The determination method is as follows: If S<T_low, Threat Level = Low (the network threat level is Low) If T_low ≤ S<T_high, Threat Level = Medium (the network threat level is Medium) If S ≥ T_high, Threat Level = High (the network threat level is High) S130. Predict the network traffic of the satellite after it enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area.

[0029] Combined with Figure 2 , the traffic prediction component performs short-term deduction on the future traffic fluctuation trend based on the historical data model and formulates the next detection strategy. This strategy determines the activation mode and resource allocation plan of the detection container.

[0030] Optionally, this model is based on the sliding window algorithm and combines the actual traffic data of the satellite in different areas to predict the possible attack traffic in a future period (such as the next 5 - 15 minutes) and generate a warning report. This warning report includes the traffic peak, attack probability, and possible abnormal behavior indicators at future times, providing a decision-making basis for the mode switching component.

[0031] In a specific implementation, a hybrid model of an LSTM (Long Short-Term Memory) network and an ARIMA (Autoregressive Integrated Moving Average method) model is used as the core prediction engine. S130 specifically includes the following steps: Step 1: Data Preparation and Sliding Window. Obtain the real-time traffic data (such as total bandwidth, specific protocol traffic, packet rate, etc.) of the satellite in the recent period (e.g., the past Y minutes) to form time series data; at the same time, obtain information such as the historical traffic patterns and known attack characteristics of the target area (the area the satellite is about to enter) provided by the "Area Identification and Threat Prediction" module. Then, use the sliding window technique to process the historical time series data, and use the data of the most recent W window length for each prediction.

[0032] Step 2: Use the core prediction engine to predict the network traffic trend in the future period. Specifically, input the data within the sliding window into both the LSTM component and the ARIMA component. Among them, the LSTM component utilizes its ability to capture complex non-linear dependencies and long-term patterns in time series to handle the periodicity, trend, and complex fluctuations caused by satellite behaviors (such as angle adjustment, mission switching) or covert attacks in the traffic data. The ARIMA component takes advantage of its strength in dealing with stationary time series or time series that can be made stationary through differencing to capture the linear relationships and autocorrelations in the data. After the two components finish processing, two future network traffic event sequences are obtained respectively; the prediction results of LSTM and ARIMA are weighted and fused or ensemble learning is performed (e.g., using a meta-learner or simple weighted average) as the preliminary prediction result output by the prediction engine. Among them, the weight allocation can be based on cross-validation performance or dynamically adjusted according to the current data characteristics (such as volatility), and the model prediction that performs better in the current scenario is preferably selected.

[0033] Step 3: Use area features to correct the prediction results. Combine the preliminary prediction results output by the core prediction engine with the features of the target area for correction. Optionally, if the target area database shows that there are periodic traffic peaks in a specific period (such as the daytime peak period of corresponding ground users) in this area, even if the time series model does not fully capture it, the prediction peak should be adjusted upward according to the historical pattern; if a certain specific type of attack (such as UDP Flood, User Datagram Protocol Flood) often occurs in the history of the target area, and the current global intelligence or satellite sensor data shows similar precursors, the model will pay special attention and may increase the prediction value of the corresponding protocol traffic and add an "attack probability" indicator; if the area features show that the network environment is extremely stable and there are almost no attacks in history, the abnormal peaks predicted by the model purely based on recent fluctuations may be adjusted downward to reduce false alarms.

[0034] Step 4: Perform abnormal indicator prediction. Based on the corrected traffic prediction values and the attack feature library of the target area, the model further predicts possible abnormal behavior indicators in the future. Optionally, a classifier (such as a decision tree, support vector machine, or simple rule engine) can be trained, with the input being the predicted traffic patterns (peak value, protocol distribution change rate, etc.) and regional features, and the output being the probability of the most likely abnormal behavior types (such as DDoS, scanning detection, increase in abnormal connection count, etc.).

[0035] Step 5: Generate a warning report. Integrate the prediction results to generate a structured warning report. The report content includes: future short-term (such as per minute) traffic prediction values (bandwidth, packet rate, etc.), the predicted traffic peak value and its occurrence time, the estimated attack probability (based on the matching degree between the predicted traffic pattern and the regional historical attacks), and the most likely abnormal behavior indicators or types.

[0036] S140: According to the prediction results and the network threat level, call the adapted detection container combination.

[0037] Combined with Figure 2 , after receiving the prediction results, the mode switching component immediately schedules the intrusion detection engine container, and pre-loads or activates the corresponding detection engine through virtualization technology to ensure that the detection system can respond to attack traffic in the first time.

[0038] Optionally, in this embodiment, multiple intrusion detection engine containers are pre-constructed for different regional protection requirements, and different detection algorithms and strategies are built into each container. The containers in high-threat areas adopt multi-level detection and in-depth analysis algorithms; while the containers in low-threat areas adopt lightweight detection to reduce memory and computing resource occupancy.

[0039] After the traffic prediction component obtains the warning results, the mode switching component automatically selects the most suitable intrusion detection container according to the threat level of the current satellite's location area. This switching process includes pre-loading the detection module, initializing the network traffic data cache, and synchronously updating the traffic distribution strategy. When the mode switching is implemented, seamless docking is ensured to ensure that detection data is not missed during the switching process and reduce the generation of detection blind spots.

[0040] In a specific embodiment, the mode switching component jointly makes a decision based on the "regional threat level" and the "short-term traffic prediction report" to select and activate the most suitable detection container combination. Here, the "combination" may include one or more types of detection containers and may involve multiple instances of the same type of container. The specific selection and activation process may include the following steps: Step 1: Input integration. The mode switching component receives two key inputs: The current regional threat level: output by the regional identification component (low, medium, high); and Short-term traffic prediction report: Output by the short-term traffic prediction component, including predicted traffic peak, attack probability, possible abnormal behavior metrics, etc.

[0041] Step 2: Perform decision matrix / rule engine matching. Optionally, maintain a predefined decision matrix or rule engine internally, which takes the "threat level" and key metrics in the "prediction report" as inputs and outputs the configuration of the "detection container combination" to be activated.

[0042] In a specific embodiment, the specific matching logic includes: Rule 1 (low-risk steady state): IF Threat Level = Low AND Predicted Peak<Threshold_Low AND AttackProbability = Low THEN Activate Profile = {1 × Lightweight_Container} (activate one lightweight container instance); Rule 2 (low-risk high traffic): IF Threat Level = Low AND Predicted Peak>Threshold_High AND AttackProbability = Low THEN Activate Profile = {N × Lightweight_Container} (activate N lightweight container instances to handle high traffic, where N is calculated based on the predicted peak); Rule 3 (medium risk): IF Threat Level = Medium AND Attack Probability = Low THEN Activate Profile = {1 × Standard_Container} (activate one standard configuration container); Rule 4 (medium risk potential attack): IF Threat Level = Medium AND (Predicted Peak>Threshold_Medium OR Attack Probability = Medium) THEN Activate Profile = {1 × Standard_Container, 1 × Specialized_Container(type=predicted_anomaly)} (Activate the standard container and preload a specialized container for handling attacks of this type according to the predicted anomaly type, such as a DDoS mitigation container); Rule 5 (High Risk): IF Threat Level = High THEN Activate Profile = {1 × Advanced_Container, M × Specialized_Container(type=common_high_risk)} (Activate an advanced multi-level detection container and preload M specialized containers for handling common high-risk attacks); Rule 6 (Early Warning for High-Risk and Intense Attacks): IF Threat Level = High AND Attack Probability = High AND PredictedPeak>Threshold_VeryHigh THEN Activate Profile = {K × Advanced_Container, P × Specialized_Container(type=predicted_attack)} (Maximize resources and activate K advanced containers and P targeted specialized containers).

[0043] Among them, Threat Level represents the threat level, Predicted Peak represents the predicted traffic peak, AttackProbability represents the attack probability, and Activate Profile represents the activation strategy. The thresholds (Threshold_Low / Medium / High / VeryHigh) in the decision matrix / rule engine and the number of activated containers (N, M, K, P) are configurable and can be adjusted through the "Configuration Manager" according to the satellite's real-time resource status (CPU, memory), task priority, or ground instructions to achieve more refined adaptive switching.

[0044] Based on the above rules, a combination of detection containers suitable for the area where the satellite is to enter can be determined.

[0045] Step 3: Container instantiation and preloading. According to the decision result, the mode switching component instantiates the required detection containers through virtualization technologies (such as lightweight virtualizations like Docker and Kubernetes). Optionally, for the upcoming area, the corresponding container images and detection rules / models are preloaded into the memory in advance to reduce the cold start latency during the switch.

[0046] Step 4: Resource allocation and initialization. Allocate computing resources (CPU cores, memory quotas) to the activated container instances; initialize the internal state of the containers, such as clearing the old cache, loading the latest threat intelligence, setting up the initial network connection, etc.

[0047] Step 5: Traffic distribution policy synchronization. Notify the "traffic distribution engine" of the information of the newly activated container group (container address, processing capacity, type, etc.), and update its routing table or distribution policy to ensure that the traffic can be correctly directed to the new container group.

[0048] Step 6: Seamless switch execution. At the precise moment when the satellite crosses the regional boundary or the predicted condition meets the switch threshold, complete the switch operation atomically. This may involve a short traffic buffer or using redundant links / container instances to ensure that no data packets are lost or detection is interrupted during the switch moment.

[0049] S150: In response to the real-time network traffic after the satellite enters the area, distribute the real-time network traffic within the detection container group to cooperate in completing the intrusion risk detection.

[0050] Combined with Figure 2 , the traffic distribution engine distributes the traffic data transmitted by the satellite in real time to each detection container according to the latest configuration, and the intrusion detection engines in each container perform in-depth detection and real-time analysis on the data.

[0051] Optionally, in the face of high-density attack traffic, the traffic distribution engine preferentially imports all traffic into high-threat containers for in-depth detection, while for normal or low-risk traffic, it selects low-risk containers for processing, so as to achieve dynamic allocation and optimal utilization of resources under limited hardware resource conditions. The scheduling rules between containers set priorities and traffic switching thresholds to ensure that the system automatically adjusts the response strategy according to the actual traffic risk.

[0052] In a specific embodiment, the following traffic distribution strategy can be adopted: Load balancing: If the activated group contains multiple container instances of the same type (for example, Rule 2 activates N lightweight containers), the traffic distribution engine will evenly distribute the traffic (or according to the current load of the containers) to these instances to avoid single-point overload.

[0053] Content-based Routing: The traffic distribution engine can perform preliminary and lightweight traffic identification (e.g., based on protocols, ports, sudden increases in traffic rates, etc.), and then preferentially direct specific types of traffic to the container within the combination that is most suitable for handling it. For example: When suspected UDP Flood traffic is identified, it is preferentially sent to the activated "DDoS-specific container" within the combination; when ordinary Web requests are identified, they are sent to the "standard container" or "advanced container"; traffic that is default or cannot be quickly classified may be distributed according to the load balancing strategy.

[0054] Priority and Threshold Control: Different containers within the combination can be set with processing priorities. For example, even if there are multiple containers available, the "advanced container" may be given the highest priority to handle all the traffic it can handle, and only when it is saturated will other containers be used. Traffic thresholds can also be set. For example, when the traffic rate entering the "standard container" or the number of detected suspicious events exceeds a certain threshold, the traffic distribution engine automatically redirects the subsequent part or all of the traffic to a container with stronger capabilities or specialization within the combination (such as the "advanced container" or the "specific attack protection container"), even if these containers have not processed much traffic before. This realizes the real-time response upgrade during an attack, rather than waiting for the next macro pattern switch.

[0055] As the hub of the entire system, the traffic distribution engine receives the traffic data of the satellite in real time and distributes the data to the corresponding intrusion detection engine containers according to the current detection mode. This distribution process is based on data tagging, traffic classification, and routing algorithms, which can not only ensure the seamless transfer of data between different containers but also make full use of the computing resources of each detection engine.

[0056] Each intrusion detection engine container is built-in with a variety of detection algorithms, including rule matching, behavior baseline models, statistical anomaly detection, and machine learning algorithm fusion strategies. By deeply analyzing the traffic entering the container, the detection engine can quickly identify abnormal traffic and potential attacks.

[0057] After detecting abnormal data, the intrusion detection engine immediately passes the abnormal information to the logging and alerting module. The latter not only records every step of the detection data but also immediately sends an alert message to the ground command center or the satellite's automatic control system according to the severity of the abnormality, triggering subsequent security disposal measures. Thus, rapid response is achieved.

[0058] Combined with Figure 1, the configuration management and logging module includes a configuration manager and a logging mechanism. Specifically, to ensure the consistency of each module in different operating environments, a unified configuration manager is adopted in this embodiment. The configuration manager is responsible for loading and updating the parameters of each detection container, detection policies, and traffic distribution rules, ensuring that each part operates according to the predetermined policies at all times. System administrators can update and optimize the detection policies through the remote configuration management interface to adapt to the ever-changing network attack situation. All data flows, detection results, and anomaly alerts within the system need to be stored through the logging module. The logging not only meets the requirements in terms of real-time performance but also supports offline data aggregation and historical data analysis. This mechanism provides a large amount of reference data for the subsequent update of security policies and the training of intrusion detection algorithms, and can also help system developers promptly discover system performance or configuration problems, ensuring that the entire solution is always in the best operating state.

[0059] In addition, the system adopts a lightweight distributed architecture. Considering the limited hardware resources of low-earth orbit satellites, each detection module adopts a containerized design with independent operation to achieve modular deployment and flexible scheduling. Modules communicate with each other through message queues and data pipelines to ensure that the system can still maintain high-efficient data transmission and processing capabilities under high concurrency.

[0060] Meanwhile, the system can achieve dynamic resource scheduling: when the real-time traffic and threat level fluctuate, according to the predetermined resource scheduling policy, it automatically starts, stops, scales in, and scales out the intrusion detection containers. The dynamic resource scheduling module makes judgments based on its own load indicators, allocates computing resources to the most needed detection containers, and maximizes the resource utilization rate. At the same time, during the container switching period, a real-time backup and fast recovery mechanism for traffic data is maintained to ensure that the detection process is not interrupted.

[0061] The configuration manager continuously monitors the status of each module, automatically adjusts parameters or issues alarms when necessary, and ensures the overall stability and high-efficient operation of the system.

[0062] In summary, an adaptive intrusion detection method for low-earth orbit satellites in this embodiment aims to overcome the defects such as fixed detection mode, resource waste, and hardware dependence in the prior art, and realizes the dynamic switching of detection containers when the satellite enters different threat regions. This method can: 1. By combining real-time satellite positioning data with historical regional attack data, construct a regional threat judgment model to achieve an instant assessment of the network risk in the area where the satellite is located, and provide an accurate basis for subsequent detection container switching; 2. Adopt a traffic prediction and mode switching mechanism to preload or adjust the corresponding detection policies and detection containers before the satellite enters different threat regions, so as to ensure that the detection ability can be rapidly improved in high-risk regions and resources can be effectively saved in low-risk regions; 3. Request orientation is achieved through the intelligent traffic distribution engine to ensure that each detection container obtains sufficient detection data. Under the conditions of limited computing and energy resources, dynamic traffic distribution and detection mode switching are realized to ensure full-time and accurate monitoring. 4. Reduce the system energy consumption, improve the satellite security protection efficiency, and support the rapid feedback and timely warning of abnormal information.

[0063] Through the above various methods, this embodiment not only has a significant improvement in data processing speed, but also can ensure highly accurate intrusion detection under limited energy conditions, with prominent technical advantages and practical application promotion value: 1. Resource saving: Automatically switch the detection mode according to the actual regional threat level. High-precision detection containers are used in high-risk areas, and lightweight detection methods are used in low-risk areas, greatly optimizing the use of computing resources and energy.

[0064] 2. Improve the detection response speed: Combine the pre-loaded detection engine container with the real-time traffic distribution technology to quickly start the high-performance detection mode when entering a high-risk area, thus shortening the time for attack detection and warning response.

[0065] Figure 4 The structural schematic diagram of an electronic device provided by an embodiment of the present invention is shown as Figure 4 shown, the device includes a processor 60, a memory 61, an input device 62, and an output device 63; the number of processors 60 in the device can be one or more, Figure 4 taking one processor 60 as an example; the processor 60, the memory 61, the input device 62, and the output device 63 in the device can be connected through a bus or other means, Figure 4 taking the connection through the bus as an example.

[0066] The memory 61, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the low-earth orbit satellite adaptive intrusion detection method in the embodiment of the present invention. The processor 60 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 61, that is, implements the above-mentioned low-earth orbit satellite adaptive intrusion detection method.

[0067] The memory 61 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory 61 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 61 may further include a memory remotely provided with respect to the processor 60, and these remote memories may be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0068] The input device 62 can be used to receive input digital or character information, and generate key signal inputs related to user settings and function controls of the device. The output device 63 may include a display device such as a display screen.

[0069] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the low-earth orbit satellite adaptive intrusion detection method of any embodiment.

[0070] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.

[0071] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium may send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0072] The program code contained on a computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0073] The computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the C language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0074] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention.

Claims

1. An adaptive intrusion detection method for low-earth orbit satellites, characterized in that, Including: Obtain the area that the satellite is about to enter; Identify the network threat level of the area according to the network traffic characteristics of the area; Predict the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area; Call an adapted detection container combination according to the prediction result and the network threat level; In response to the real-time network traffic after the satellite enters the area, distribute the real-time network traffic within the detection container combination to cooperate to complete the intrusion risk detection.

2. The method according to claim 1, characterized in that, The identifying the network threat level of the area according to the network traffic characteristics of the area includes: Extract the network traffic characteristics of the area from the area database, and the network traffic characteristics include historical attack frequency, historical attack severity, historical traffic peak anomaly degree, known vulnerability indicators, adjacent area threat transfer factor, and real-time global threat intelligence correlation degree; Dynamically assign weighted weights to each network traffic characteristic according to the satellite mission priority and the global security situation; Perform weighted fusion calculation on each network traffic characteristic according to the assigned weights; Determine the network threat level of the area according to the fusion result and the dynamic threshold.

3. The method according to claim 2, wherein The dynamically assigning weighted weights to each network traffic characteristic according to the satellite mission priority and the global security situation includes: During the high-priority mission of the satellite, assign higher weights to historical attack severity and real-time global threat intelligence correlation degree; When a specific attack occurs frequently globally, increase the weight of the global threat situation correlation degree; During the detection process, regularly optimize the weight assignment according to the historical prediction accuracy and the actually occurred attack events.

4. The method according to claim 1, wherein The predicting the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area includes: Use a hybrid model of a long short-term memory network and an autoregressive integrated moving average model to process the real-time sequence of the satellite network traffic, and initially predict the network traffic time sequence after the satellite enters the area; Correct the initially predicted time sequence according to the network traffic characteristics of the area, and adjust the prediction peak and the attack probability; Predict future possible abnormal behavior indicators based on the corrected data and the attack feature library of the area.

5. The method according to claim 4, wherein The using a hybrid model of a long short-term memory network and an autoregressive integrated moving average model to process the real-time sequence of the satellite network traffic and initially predict the network traffic time sequence after the satellite enters the area includes: Use a long short-term memory network to process the real-time sequence of the satellite network traffic to obtain a first network traffic sequence; Use an autoregressive integrated moving average model to process the real-time sequence of the satellite network traffic to obtain a second network traffic sequence; Use weighted average or ensemble learning to fuse the first network traffic sequence and the second network traffic sequence to obtain a final prediction result.

6. The method according to claim 4, characterized in that, The predicting future possible abnormal behavior indicators based on the corrected data and the attack feature library of the area includes: Input the corrected traffic peak value, protocol distribution change rate, and the traffic characteristics of the area into the trained classifier to predict possible future abnormal behavior types.

7. The method according to claim 1, wherein The prediction results include the traffic peak value and the attack probability; According to the prediction results and the network threat level, call the adapted detection container combination, including: According to the network threat level, judge the risk status of the satellite in the area; In the case where the risk status is a low-risk steady state, activate a lightweight container instance; In the case where the risk status is a low-risk high-traffic state, activate N lightweight container instances to handle high traffic; In the case where the risk status is a medium risk, activate a standard-configured container; In the case where the risk status is a medium-risk potential attack, activate a standard container and preload a dedicated container for handling the abnormal type according to the predicted abnormal type; In the case where the risk status is a high risk, activate an advanced multi-level detection container and preload M dedicated containers for handling common high-risk attacks; In the case where the risk status is a high-risk strong attack warning, activate K advanced containers and P targeted dedicated containers; Among them, N, M, K, and P are dynamically configured parameters.

8. The method according to claim 1, characterized in that, The distribution of the real-time network traffic within the detection container combination includes: According to load balancing and traffic content, distribute the real-time network traffic within the detection container combination; According to container priorities and traffic thresholds, allocate the distributed traffic.

9. An electronic device, characterized in that, Including: One or more processors; A memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the low-earth orbit satellite adaptive intrusion detection method according to any one of claims 1-8.

10. An adaptive intrusion detection system for low-earth orbit satellites, characterized in that, Including: A satellite system for obtaining the area that the satellite is about to enter; An area identification component for identifying the network threat level of the area according to the network traffic characteristics of the area; A traffic prediction component for predicting the network traffic after the satellite enters the area according to the real-time network traffic of the satellite and the network traffic characteristics of the area; A mode switching component for calling the adapted detection container combination according to the prediction results and the network threat level; A traffic distribution engine for distributing the real-time network traffic within the detection container combination in response to the real-time network traffic after the satellite enters the area, and cooperating to complete the intrusion risk detection.

Citation Information

Patent Citations

  • Satellite network load balancing routing strategy based on flow prediction

    CN116760758A

  • Dynamic capacity expansion and contraction method and device for satellite edge computing service and storage medium

    CN117573339A

  • Network attack detection method, device, equipment, medium and program

    CN118316701A

  • Intrusion detection and response method and system of satellite internet target range

    CN119155101A

  • Satellite network multi-dimensional threat simulation method and system based on isolated forest detection

    CN120050067A