A dynamic defense system based on immune data network
By building a dynamic defense system based on an immune data network, the shortcomings of the existing network security system in terms of perception, decision-making and execution are resolved, rapid response to unknown attacks and cross-terminal collaborative defense are achieved, and the security and real-time performance of the in-vehicle network are improved.
Patent Information
- Application Number
- CN202510947250.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-10
AI Technical Summary
The existing network security system cannot effectively identify zero-day attacks and variant threats at the perception layer, the decision-making layer has delayed responses, the execution layer lacks collaborative immunity capabilities, and the defense mechanism lacks adaptability, making it difficult to achieve dynamic defense, especially in resource-constrained mobile terminal scenarios.
Build a dynamic defense system based on the immune data network, realize real-time threat perception and cloud-based collaborative processing through dynamic networking architecture, anomaly identification strategy, immune generation strategy and immune operation strategy, and adopt multi-level response mechanism and immune evaluation algorithm to dynamically generate and distribute antibody data packets.
It significantly improves the system's adaptability to unknown attacks, shortens response delays, reduces missed detection rates, and enables rapid response and cross-terminal collaborative defense in resource-constrained environments.
Smart Images

Figure CN120456032B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electronic digital data processing, and in particular to a dynamic defense system based on an immune data network. Background Art
[0002] With the widespread adoption of intelligent connected devices and the in-depth application of IoT technologies, security defense in distributed network environments faces unprecedentedly complex challenges. Existing network security systems primarily utilize static defense mechanisms based on rule libraries, including signature-matching intrusion detection, fixed-policy access control, and centralized threat analysis platforms. These traditional approaches suffer from inherent flaws at three levels: at the perception layer, static signature libraries are unable to effectively identify zero-day attacks and variant threats, resulting in a high rate of missed detection of new attack behaviors; at the decision-making layer, centralized analysis models incur significant response delays, making it difficult to meet the real-time requirements of scenarios such as the Internet of Vehicles and the Industrial Internet; and at the execution layer, each terminal node operates its defense strategy in isolation, lacking collaborative immunity capabilities. This allows attacks to rapidly spread laterally after breaching a single point of attack.
[0003] Especially in resource-constrained mobile terminal scenarios, existing technologies face a dual contradiction: on the one hand, terminal devices are limited by storage capacity and computing power, making it difficult to carry a complete attack feature library and complex analysis algorithms; on the other hand, in a dynamic networking environment, terminal devices use different communication protocols and differentiated hardware configurations, making it difficult to adapt a unified defense strategy. Current mainstream solutions attempt to alleviate this contradiction through cloud collaboration, but this has created a new technical bottleneck: centralized cloud processing increases the transmission delay of key response instructions, while simple edge computing solutions cannot achieve global sharing of threat features and intelligent evolution of immunity strategies.
[0004] A deeper technical dilemma lies in the adaptability of the defense mechanism. Traditional systems rely on manually preset defense rules, and their strategy update cycle is much longer than the frequency of attack mutations. Although some studies have attempted to introduce machine learning algorithms for dynamic detection, these solutions generally have problems such as high false alarm rates and heavy computational loads. The generated defense strategies lack explainability, making it difficult to form a reusable immune knowledge base. In addition, existing distributed defense systems mostly adopt a master-slave architecture, and the efficiency of immune information transmission between nodes is low, making it impossible to achieve the rapid response and memory functions of the biological immune system. Summary of the Invention
[0005] The present invention addresses the shortcomings of the prior art (such as inconvenience in use) and provides a dynamic defense system based on an immune data network.
[0006] In order to solve the above technical problems, the present invention is solved by the following technical solutions: A dynamic defense system based on an immune data network is configured with a dynamic networking network architecture, the network architecture includes a user terminal, a communication base station and a cloud, the user terminals communicate with each other through a communication module, and the user terminals and the cloud communicate with each other through the communication base station, characterized in that it includes an abnormality identification strategy, an immune generation strategy, and an immune operation strategy;
[0007] The anomaly identification strategy is configured with an anomaly characterization database, which stores a number of anomaly characterization features and corresponding characterization response instructions. The anomaly identification strategy executes the corresponding characterization response instructions according to the anomaly characterization, and is configured with a preset immune evaluation algorithm for calculating the abnormal immunity value of the current user terminal. When the abnormal immunity value is greater than the preset immune reference value, the corresponding abnormal feature is extracted through a preset feature extraction sub-strategy and an intrusion immunity feature group is generated, and the intrusion immunity feature group is uploaded to the cloud for immune generation strategy processing;
[0008] The immune generation strategy is configured with an abnormal feature immune database in the cloud, and the abnormal feature immune database stores a number of feature recognition immune networks, each feature recognition immune network corresponds to an intrusion immune feature group configuration, and each feature recognition immune network includes a number of immune recognition nodes, and immune recognition links are configured between the immune recognition nodes, and the immune recognition links reflect the relationship between the immune recognition nodes; the immune generation strategy generates a corresponding feature recognition immune network according to the intrusion immune feature group;
[0009] The immune operation strategy encapsulates the immune recognition node into a corresponding antibody data packet according to the immune encapsulation sub-strategy, and sends the antibody data packet to the corresponding target terminal according to the immune distribution sub-strategy. The target terminal receives the antibody data packet to update the corresponding abnormal characterization database.
[0010] By adopting these technical solutions, a dynamic networking architecture and strategies for anomaly identification, immune generation, and operation have been established. Through real-time anomaly detection and cloud-based collaborative processing, a closed-loop system from threat perception to dynamic defense has been achieved. This technical advantage transcends the passive nature of traditional static defenses, significantly improving the system's adaptability to unknown attacks. Furthermore, through distributed updates of antibody data packets, the in-vehicle network can rapidly respond to threats even in resource-constrained environments.
[0011] The present invention is further configured as follows: the characterization response instruction includes a static response instruction, a dynamic response instruction, a cloud response instruction, and an interactive response instruction;
[0012] The static response instruction is to replace the target interaction instruction of the current user terminal with a preset static defense instruction set;
[0013] The dynamic response instruction is to monitor the interaction data of the target interaction interface of the current user terminal, trigger the corresponding interaction response instruction according to the interaction data and send it to the corresponding target interaction interface;
[0014] The cloud response instruction is to replace the corresponding user terminal's immune operation strategy with the target immune operation strategy in the cloud;
[0015] The interactive response instruction is to add a corresponding assisted immunity request to the interactive data between the current user terminal and the target user terminal.
[0016] By adopting the above technical solutions, a multi-level response mechanism, including static, dynamic, cloud-based, and interactive response commands, covers the defense requirements of different attack scenarios. For example, dynamic response commands monitor interactive data in real time and trigger targeted commands, while interactive response commands introduce cross-terminal collaborative requests, enhancing the joint defense and control capabilities of network nodes, thereby addressing the single weak point of defense in traditional in-vehicle networks.
[0017] The present invention is further configured as follows: the immune evaluation algorithm performs a comprehensive calculation based on the preset value weight of the feature recognition immune network and the security level risk value of the interaction data, specifically: the abnormal immunity value is equal to the sum of the ratios of the number of triggering times of each abnormal characterization feature within the time window to the corresponding feature weight, plus the product of the preset value weight and the determination coefficient when the feature combination triggers the feature recognition immune network, plus the product of the matching degree between the feature recognition immune network and the current abnormality and the security level risk value of the interaction data, wherein the determination coefficient is 1 when the feature combination triggers the feature recognition immune network, and otherwise it is 0.
[0018] By employing this technical solution, the immune evaluation algorithm calculates anomaly immunity values using multiple parameters, including trigger count, weight, and matching, to quantify threat risk. This reduces false positives, improves the accuracy of threat assessments, and provides reliable data support for subsequent immune generation strategies, avoiding wasted resources on low-risk events.
[0019] The present invention is further configured as follows: the feature extraction sub-strategy includes configuring a behavior anomaly library, a period anomaly library and a content anomaly library in the cloud; the feature extraction sub-strategy includes obtaining all interaction data generated by the current user terminal within a time window when the anomaly identification strategy determines that the anomaly immunity value is greater than a preset immunity reference value, and dividing the interaction data into a number of sub-events through event classification rules; evaluating the anomaly sub-value of each sub-event through the behavior anomaly library, the period anomaly library and the content anomaly library; when the anomaly sub-value is greater than the preset feature extraction reference value, constructing behavior anomaly sub-data, period anomaly sub-data and content anomaly sub-data as a header for the characterizing content data corresponding to the sub-event to generate the anomaly feature.
[0020] By employing this technical solution, the feature extraction sub-strategy performs refined classification and evaluation of interaction data based on three types of anomaly libraries: behavior, period, and content. This allows for efficient extraction of key anomaly features from complex vehicle data. This improves the comprehensiveness and accuracy of feature extraction, ensuring a more representative intrusion immunity signature set, laying the foundation for the construction of a cloud-based immune network.
[0021] The present invention is further configured as follows: the immune generation strategy includes configuring a cluster analysis algorithm, assigning each abnormal feature of the intrusion immune feature group to a multidimensional coordinate system, the coordinate system including the attack type, threat level, timestamp and data source credibility, obtaining a feature cluster belonging to the same intrusion immune feature group through the cluster analysis algorithm, and translating each abnormal feature into a corresponding immune trigger link through a preset immune translation sub-strategy, each immune trigger link including a number of immune recognition nodes, and constructing the number of dimensions of the feature recognition immune network according to the number of the same immune recognition nodes in the same immune feature group, and loading the immune recognition node into the corresponding feature recognition immune network.
[0022] By adopting the above technical solution, the clustering analysis algorithm is used to map abnormal features to a multi-dimensional coordinate system such as attack type, threat level, etc., and a feature recognition immune network is generated through immune translation. The technical effect is to realize intelligent clustering and pattern recognition of complex attack patterns, enhance the system's ability to analyze multi-dimensional threats, and optimize the topological structure of the immune network to adapt to dynamic attack scenarios.
[0023] The present invention is further configured as follows: the immune encapsulation sub-strategy generates a mirror value based on the heat evaluation value of the immune network, encapsulates the immune recognition node and copies the antibody data packet with the mirror value number, the antibody data packet includes a link index, and the link index points to the antibody data packet related to the immune recognition node. When the user terminal calls a certain antibody data packet, all related antibody data packets can be obtained through the link index.
[0024] By adopting the above technical solution, a mirror replication mechanism based on heat evaluation values and a link index design ensures efficient packaging and rapid association and invocation of antibody data packets. The technical effect is to improve the utilization efficiency of defense resources, achieve "one-trigger, global association" through link indexing, shorten threat response time, and support lightweight terminals to quickly load antibody data.
[0025] The present invention is further configured as follows: the immune distribution sub-strategy generates a random number according to a random range corresponding to each antibody data packet, and if the random number falls within the range, the antibody data packet is distributed to the corresponding target terminal.
[0026] By adopting the above technical solution and a random number range-controlled antibody data packet distribution strategy, we can avoid the network congestion caused by centralized distribution. The technical effect is to optimize network bandwidth utilization and balance load pressure. At the same time, through probabilistic distribution, the coverage of defense measures is enhanced, which is suitable for high-concurrency scenarios in in-vehicle networks.
[0027] The present invention is further configured as follows: each antibody data packet is configured with an attenuation factor, and when the attenuation factor is 0, the corresponding antibody data is deleted; the attenuation factor is calculated as follows: the attenuation factor is equal to the product of the initial attenuation coefficient and the negative time attenuation rate of the natural logarithm base e and the power of the product of the time variable, plus the sum of the product of the local trigger number and the trigger superposition coefficient, plus the sum of the product of the trigger number of other user terminals in the same network and the adjacent trigger superposition coefficient, and then subtracted from the product of the repetition rate acceleration attenuation coefficient and the repetition trigger rate function, wherein the time variable is used to describe the length of time the system runs, and the repetition trigger rate function reflects the trigger repetition frequency of the antibody data packet.
[0028] By employing this technical solution, the decay factor dynamically regulates the lifecycle of antibody data packets, automatically adjusting their effectiveness based on parameters such as trigger count, time decay, and neighboring node behavior. This technically enables intelligent recycling and updating of defense resources, preventing outdated antibodies from occupying storage resources. Furthermore, accelerated decay through repetition rate suppresses invalid data redundancy, improving system real-time performance.
[0029] The present invention is further configured to include a forwarding trigger condition. When a change in the attenuation factor triggers the forwarding trigger condition, a forwarding instruction is generated to forward the antibody data packet to a neighboring user end. The forwarding trigger condition is that within a preset time, the attenuation factor decrease value exceeds a preset baseline decrease value.
[0030] By adopting the above technical solution, the forwarding trigger condition mechanism actively triggers the neighboring nodes to forward before the antibody data packet expires. Its technical effect is to extend the transmission chain of effective antibodies, form a ripple effect of defense measures, and enhance the protection capabilities of network edge nodes. It is especially suitable for rapid immune response in attack spread scenarios.
[0031] The present invention is further configured such that the step of executing the interactive response instruction includes:
[0032] Step S1: inserting an assisted immunity request field into the interaction data between the current user terminal and the target user terminal;
[0033] Step S2: After receiving the request, the target user terminal submits local abnormal feature data to the cloud;
[0034] Step S3: The cloud updates the feature recognition immune network based on the target user terminal data, and generates an adapted antibody data packet and transmits it back to the current user terminal.
[0035] By adopting this technical solution and implementing a standardized interactive response instruction execution process: inserting request fields, cloud-based updates, and returning antibodies, cross-terminal collaborative immunity is achieved. The technical effect is to bridge the gap between local and global defenses, ensuring that new threat signatures can be quickly learned by the cloud and adaptive antibodies generated, forming a "herd immunity" effect in the vehicle network and significantly suppressing the lateral spread of attacks.
[0036] Due to the adoption of the above technical solutions, the present invention has significant technical effects: through anomaly identification, immune generation and operation strategies, collaborative defense of user terminals, communication base stations and cloud is realized through dynamic networking architecture. The anomaly identification strategy is combined with the immune evaluation algorithm to calculate the anomaly immunity value in real time. The immune generation strategy constructs a feature recognition immune network. The immune operation strategy dynamically distributes antibody data packets, effectively solving the problems of high response delay and inability to cope with new attacks in traditional defense systems. It has the advantages of improving real-time response speed, realizing dynamic collaborative defense, and reducing the missed detection rate of zero-day attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 It is a flowchart of the execution steps of the interactive response instruction. DETAILED DESCRIPTION
[0038] The present invention is further described in detail below with reference to the accompanying drawings and embodiments.
[0039] In existing technologies, the in-vehicle network security defense of intelligent connected vehicles mainly relies on static rule bases and centralized detection mechanisms. Traditional methods intercept threats through predefined attack features, and there is a response lag problem when facing new threats such as zero-day attacks and APT attacks. The in-vehicle network environment includes multiple protocols such as CAN, LIN, and Ethernet coexisting scenarios, and the terminal computing resources are limited. The existing defense system is difficult to achieve low-latency real-time protection. Each node runs the defense strategy independently and lacks a coordination mechanism, which makes it easy for attacks to spread in the network.
[0040] To address the above issues, the R&D team observed that the dynamic collaborative mechanism of the biological immune system has environmental adaptability. By simulating the antibody generation and distribution process, they attempted to build a distributed defense system. First, they solved the problem of dynamic threat perception and established a scalable anomaly feature extraction model. Secondly, they designed a lightweight immune network generation algorithm for heterogeneous network environments. Finally, they broke through the limitations of single-point defense and explored a collaborative immune mechanism based on data packets.
[0041] This application proposes a defense system that includes a dynamic networking architecture. The system consists of a user terminal, a communication base station and a cloud. The user terminals are connected to each other through a communication module and are connected to the cloud through the base station. The system is configured with an anomaly identification strategy, an immune generation strategy and an immune operation strategy. The anomaly identification strategy executes response instructions and calculates immune values through an anomaly characterization database. After triggering feature extraction, an intrusion immune feature group is generated and uploaded to the cloud. The cloud constructs a feature identification immune network through the immune generation strategy. The immune operation strategy encapsulates network nodes into antibody data packets and distributes them to the terminal to update the database.
[0042] A dynamic networking architecture refers to an architecture that supports the user end to automatically establish communication links based on changes in network topology. It can use software-defined network technology to achieve dynamic adjustment of the connection relationship between nodes to adapt to the topology changes brought about by the mobility of vehicle-mounted network terminals. An anomaly characterization database refers to a database that stores abnormal behavior patterns and response strategies. Specifically, a graph database can be used to store the mapping relationship between multi-dimensional feature vectors and defense instructions to achieve rapid matching of abnormal behaviors. An immune evaluation algorithm refers to a mathematical model for evaluating the security status of terminal nodes. For example, a composite function of the weighted statistical abnormal feature trigger frequency and threat level is used to quantify the defense capability gap of the node. A feature recognition immune network refers to a topological structure that describes the correlation between attack features. Specifically, knowledge graph technology can be used to construct logical relationships between nodes to reflect the derivative laws between different attack features. An antibody data packet refers to a data unit that encapsulates specific defense logic. For example, a microservice architecture is used to package detection rules and response strategies into independent functional modules to achieve plug-and-play defense capability updates.
[0043] The user side continuously monitors the interactive data stream. When the anomaly identification strategy detects an abnormal behavior pattern, it calls the immune evaluation algorithm to evaluate the current defense capability. If the abnormal immunity value exceeds the threshold, the feature extraction module is started to extract the attack feature sequence from the original data, generate a standardized intrusion immunity feature group and upload it to the cloud. After the cloud receives the feature group, it analyzes the feature correlation through the clustering algorithm and constructs a feature identification immune network containing nodes and connections. The immune operation strategy encapsulates the nodes in the network into independent antibody data packets and dynamically distributes them according to the terminal device status. After receiving the data packet, the terminal updates the local anomaly feature library to form a continuously evolving defense capability.
[0044] Traditional solutions rely on fixed rule bases, resulting in rigid defense strategies. However, this solution achieves self-growth of defense capabilities through dynamic immune networks. Existing methods require the cloud to centrally process all detection tasks. This solution reduces the cloud load through a distributed antibody data packet distribution mechanism. Each node in the existing system independently updates the defense strategy. This solution achieves cross-terminal collaborative defense through a feature recognition immune network, blocking the attack propagation path.
[0045] This application realizes the dynamic evolution of vehicle network defense strategies, effectively identifies unknown attack patterns and generates targeted defense logic. Through the lightweight encapsulation and distribution of antibody data packets, it reduces the occupancy of terminal computing resources. Based on the collaborative mechanism of the immune network, a single terminal can quickly synchronize to the entire network nodes after acquiring new defense capabilities, forming a group immunity effect.
[0046] It is proposed that characterization response instructions include static response instructions, dynamic response instructions, cloud response instructions and interactive response instructions; static response instructions are to replace the target interaction instructions of the current user end with a preset static defense instruction set; dynamic response instructions are to monitor the interaction data of the target interaction interface of the current user end, trigger the corresponding interactive response instructions according to the interaction data and send them to the corresponding target interaction interface; cloud response instructions are to replace the immune operation strategy of the corresponding user end with the target immune operation strategy in the cloud; interactive response instructions are to add corresponding assisted immunity requests to the interaction data between the current user end and the target user end.
[0047] A static defense instruction set refers to a set of pre-set fixed defense rules, which can be implemented through a pre-compiled instruction sequence or a logic judgment module. Its function is to quickly replace abnormal interactive behaviors and block known attack patterns. Interaction data monitoring in dynamic response instructions refers to feature scanning of real-time transmitted data streams. Specifically, it can be implemented by combining a data packet parser with a behavior analysis algorithm. This mechanism can dynamically capture abnormal interaction patterns and trigger real-time responses. A target immunity operation strategy refers to a customized defense strategy generated by the cloud based on the security status of different terminals. Specifically, it can be implemented through a policy configuration engine combined with a terminal attribute matching algorithm. This strategy can adjust the terminal's defense logic in a targeted manner. An assisted immunity request refers to a security collaboration instruction embedded in the interactive data. Specifically, it can be implemented using preset protocol fields or metadata tags to trigger collaborative defense actions of neighboring terminals.
[0048] When the static response instruction is activated, the pre-stored static defense instruction set will overwrite the original interaction instructions of the current user end, such as replacing the data request instruction with an encryption verification process. The dynamic response instruction monitors the data traffic of the target interaction interface in real time. When an abnormal interaction pattern is detected, such as high-frequency illegal access requests, the corresponding response action is immediately triggered, such as flow control or blocking operations. The cloud response instruction is dynamically issued by the cloud based on the global threat situation. For example, when a new attack feature is discovered, the defense strategy of all associated terminals is uniformly updated. The interactive response instruction automatically attaches security collaboration information when communicating between terminals. For example, when the vehicle network node transmits data, a feature sharing request is embedded to trigger the neighboring nodes to synchronize the latest defense strategy.
[0049] Traditional vehicle-mounted defense systems use a fixed rule base and are unable to cope with zero-day attacks and dynamically changing attack characteristics. Existing solutions lack a cloud-based collaborative update mechanism, resulting in delayed security policy updates. This solution, through the synergy of multi-level response instructions, retains the rapid response advantage of static defense while forming an adaptive defense system through dynamic monitoring and cloud-based policy updates. The interactive response mechanism breaks through the traditional single-point defense model and realizes active immune collaboration between Internet of Vehicles nodes.
[0050] This application can realize the coordinated operation of multi-dimensional defense response, effectively shorten the response delay of unknown attacks, static defense instructions ensure the immediate effectiveness of basic protection, dynamic monitoring mechanism enhances the ability to identify new attacks, cloud-based policy updates realize the continuous evolution of defense capabilities, and interactive collaboration mechanism builds a distributed immune network. The organic combination of four types of response instructions solves the technical problems of delayed defense policy updates and weak single-point protection in the vehicle network environment, and significantly improves the overall defense effectiveness in complex attack scenarios.
[0051] An immune evaluation algorithm is proposed to perform comprehensive calculation based on the preset value weight of the feature recognition immune network and the security level risk value of the interactive data. Specifically, the anomaly immunity value is equal to the sum of the ratios of the number of triggering times of each anomaly characterization feature within the time window and the corresponding feature weight, plus the product of the preset value weight and the determination coefficient when the feature combination triggers the feature recognition immune network, plus the product of the matching degree between the feature recognition immune network and the current anomaly and the security level risk value of the interactive data. The determination coefficient is 1 when the feature combination triggers the feature recognition immune network, and 0 otherwise. Its formula is:
[0052] ,
[0053] in, C i For the i Abnormal characterization features in the time window T Number of triggers within; W i is the weight of the corresponding feature; The determination coefficient of whether the feature combination triggers the feature recognition immune network, which is 1 when triggered and 0 otherwise; S Preset value weights for feature recognition immune networks; To identify the matching degree between the immune network and the current abnormality; M is the security level risk value of the interaction data.
[0054] The preset value weight refers to the importance evaluation parameter of the feature recognition immune network in the global defense system. It can be achieved through the historical attack defense success rate or dynamic adjustment of machine learning. It is used to quantify the priority of different immune networks in resisting specific attack types. The security level risk value refers to the quantitative indicator of the potential threat of interactive data during transmission or processing. It can be achieved by a multi-dimensional scoring model based on data encryption level, access rights and protocol vulnerability scanning results. It is used to reflect the security status of the current data interaction. The number of triggers refers to the frequency of a certain abnormal characterization feature being detected within a preset time window. It can be achieved through sliding window statistics or event counters. It is used to identify high-frequency abnormal behaviors. The matching degree refers to the strength of the correlation between the feature recognition immune network and the currently detected anomaly. It can be achieved by similarity algorithm or hit rate calculation of the rule engine. It is used to judge the applicability of the immune network.
[0055] The immune evaluation algorithm realizes the comprehensive calculation of abnormal immunity value by dynamically integrating real-time abnormal feature triggering data, immune network value weight and interactive risk status. For example, when a certain abnormal feature is triggered multiple times in a short period of time, the product of its corresponding weight and the number of triggering times will be added to the total abnormal immunity value; if the abnormal feature combination triggers a certain feature recognition immune network, it will be weighted and superimposed according to the preset value weight of the network and the matching degree with the current attack; at the same time, combined with the security level risk value of the interactive data, the comprehensive abnormal immunity value is finally obtained. When this value exceeds the preset immunity baseline value, the system will start the feature extraction sub-strategy to generate an intrusion immunity feature group and trigger the subsequent immune network generation and distribution process.
[0056] Traditional vehicle-mounted defense systems typically use fixed thresholds or single-dimensional statistical methods to determine anomalies. For example, they rely solely on attack frequency or static rule matching and are unable to dynamically adapt to complex and changing attack scenarios. This solution introduces a multidimensional calculation model that combines preset value weights and security level risk values. It not only considers the frequency and feature correlation of attack behaviors, but also integrates the priority of network defense resources and the real-time security status of data interaction, thereby significantly improving the accuracy and environmental adaptability of anomaly detection.
[0057] This application effectively solves the problems of high false alarm rate and delayed defense in vehicle networks due to variable attack modes and limited resources. By dynamically quantifying abnormal immunity values, the system can quickly identify high-risk attacks under limited computing resources, while avoiding excessive response to low-frequency misjudgment events, thereby optimizing defense resource allocation and enhancing the active defense capability against unknown threats.
[0058] A feature extraction sub-strategy is proposed, which includes configuring a behavior anomaly library, a period anomaly library, and a content anomaly library in the cloud. The feature extraction sub-strategy includes obtaining all interaction data generated by the current user terminal during the period, and dividing the interaction data into several sub-events through event classification rules. The abnormal sub-value of each sub-event is evaluated through the behavior anomaly library, the period anomaly library, and the content anomaly library. When the abnormal sub-value is greater than the preset feature extraction benchmark value, the characterization content data corresponding to the sub-event is used as the header to construct behavior anomaly sub-data, period anomaly sub-data, and content anomaly sub-data to generate abnormal features.
[0059] A behavioral anomaly database refers to a database that stores the deviation of user-side interactive behavior patterns. It can be implemented by analyzing statistical models of historical normal operation sequences and is used to detect unexpected operational behaviors. A periodic anomaly database refers to a database that analyzes the periodic regularity of interactive data based on the time dimension. For example, a time series prediction algorithm is used to identify abnormal time intervals or frequency fluctuations. A content anomaly database refers to a compliance detection library for data packet payload content, which can be implemented through regular expression matching or semantic analysis models. Event classification rules refer to the logic of grouping interactive data according to protocol type, data flow direction or operation category, such as dividing events according to CAN bus ID or Ethernet port number. Anomaly sub-values refer to comprehensive indicators obtained by weighted calculation of anomaly scores in behavior, period and content dimensions, such as using a linear weighting method to proportionally superimpose the scores of the three dimensions. Feature extraction baseline values refer to the conditional threshold that triggers feature generation, such as set by a dynamic adjustment algorithm based on the current network load or threat situation.
[0060] In an in-vehicle network environment, interactive data, such as CAN bus messages or in-vehicle Ethernet traffic, is first divided into sub-events. For example, the data stream is divided into sub-events such as engine control and braking system based on the CAN frame ID. Each sub-event is simultaneously input into the behavior anomaly library, the period anomaly library, and the content anomaly library for parallel analysis: the behavior anomaly library detects whether the operation instruction sequence conforms to the preset pattern, such as the continuous transmission of throttle control instructions exceeding the normal frequency; the period anomaly library analyzes whether the data transmission interval deviates from historical patterns, such as the high-frequency burst of braking signals in non-emergency conditions; and the content anomaly library verifies whether the data payload conforms to the protocol specification, such as detecting the presence of buffer overflow attack signatures. When the sum of the anomaly scores of any sub-event in the three dimensions exceeds the feature extraction baseline value (for example, within a certain second, the engine control sub-event has a behavior anomaly score of 0.6, a period anomaly score of 0.3, and a content anomaly score of 0.5, and the sum exceeds the baseline value of 1.2), the system extracts the packet header fields corresponding to the sub-event to construct a multi-dimensional anomaly feature vector. For example, the CAN frame ID, timestamp offset, and payload signature code are combined into structured data as input for subsequent immune network generation.
[0061] Traditional vehicle-mounted defense systems typically rely on a single-dimensional feature library, such as content detection based on fixed attack signatures. However, this solution can capture complex attack signatures, such as periodic, low-frequency penetration attacks targeting vehicle networks, by collaboratively analyzing anomaly libraries across three dimensions: behavior, period, and content. Furthermore, dynamically adjusted feature extraction baseline values can adapt to the resource constraints of different vehicle-mounted terminals, such as automatically lowering the threshold on LIN bus nodes with lower computing power to ensure real-time performance.
[0062] This application effectively solves the problem that the in-vehicle network cannot pre-store a complete attack feature library due to storage capacity limitations. It realizes unknown attack detection by dynamically generating abnormal features. For example, when an abnormally high frequency of Bluetooth pairing requests is detected in a certain in-vehicle entertainment system, abnormal features with generalization capabilities are generated through multi-dimensional feature extraction, so that adjacent nodes that do not store the attack features can also identify similar behaviors. At the same time, the parallel processing mechanism based on event classification reduces the consumption of computing resources. For example, only the complete three-dimensional analysis is enabled for the sub-events of the key control system to ensure that the real-time requirements of the in-vehicle terminal are met.
[0063] An immune generation strategy is proposed, which includes configuring a clustering analysis algorithm, assigning each abnormal feature of the intrusion immune feature group to a multidimensional coordinate system, which includes the attack type, threat level, timestamp and data source credibility. The feature clusters belonging to the same intrusion immune feature group are obtained through the clustering analysis algorithm, and each abnormal feature is translated into a corresponding immune trigger link through a preset immune translation sub-strategy. Each immune trigger link includes several immune recognition nodes, and the number of dimensions of the feature recognition immune network is constructed according to the number of identical immune recognition nodes in the same immune feature group, and the immune recognition nodes are loaded into the corresponding feature recognition immune network.
[0064] Clustering analysis algorithm refers to a machine learning method for unsupervised grouping based on data similarity. It can be implemented using K-means, hierarchical clustering, or density clustering algorithms. It is used to discover potential correlations between abnormal features and solve the problem that multidimensional features are difficult to classify manually. The multidimensional coordinate system refers to a four-dimensional space model composed of attack type, threat level, timestamp, and data source credibility. It can be implemented using vector space modeling technology. By converting discrete features into continuous numerical values for quantitative analysis, multi-dimensional dynamic characterization of attack behavior can be achieved. The immune trigger link refers to the node logical link generated by abnormal feature mapping. It can be implemented using the edge-node structure in the graph database. It is used to describe the defense logic association between different immune recognition nodes and form a dynamically expandable defense rule topology.
[0065] In the vehicle network environment, when the anomaly identification strategy detects that the abnormal immunity value exceeds the standard, the intrusion immunity feature group will be uploaded to the cloud. The cloud will use the clustering analysis algorithm to perform four-dimensional spatial mapping of the features. For example, the CAN bus abnormal message is classified as "protocol tampering" in the attack type dimension, the threat level is set to level 5, and the timestamp is recorded as the time window when the attack occurred. The credibility of the data source is dynamically adjusted according to the historical false alarm rate. The feature cluster generated after clustering is converted into an immune trigger link through the immune translation sub-strategy. For example, the link corresponding to a feature cluster contains three immune identification nodes: "message frequency monitoring node", "protocol verification node", and "data source authentication node". The system automatically determines the network dimension based on the number of repeated node appearances. For example, when 80% of the feature clusters contain "protocol verification node", this node becomes one of the core dimensions of the three-dimensional defense network.
[0066] Traditional vehicle-mounted defense systems rely solely on single-dimensional feature matching, such as making rule judgments based solely on attack type or threat level. These systems are unable to effectively handle complex attack scenarios where multiple protocols coexist. This solution uses a four-dimensional coordinate system to achieve a holographic characterization of attack features, combined with cluster analysis to overcome the limitations of manual rule setting. For example, when detecting cross-protocol time series attacks, it can automatically discover the correlation pattern between the timestamp dimension and the threat level, generating a composite defense link with cross-protocol verification.
[0067] This application solves the technical problem that it is difficult to effectively integrate multi-dimensional attack features in the vehicle network environment, and realizes the adaptive generation and dynamic optimization of defense rules. In specific applications, when a DDoS attack against the vehicle Ethernet is detected, the system can identify abnormal traffic cycles through the timestamp dimension, filter the real attack source based on the credibility of the data source, and generate a multi-node defense link including traffic shaping and source address filtering, thereby improving the real-time blocking capability of complex attacks. At the same time, the dynamic clustering mechanism based on feature clusters reduces the storage overhead of redundant defense rules and adapts to the resource limitations of the vehicle terminal.
[0068] An immune encapsulation sub-strategy is proposed to generate a mirror value based on the heat evaluation value of the immune network, encapsulate the immune recognition node and copy the antibody data packet with the mirror value number. The antibody data packet includes a link index, which points to the antibody data packet related to the immune recognition node. When the user terminal calls a certain antibody data packet, all related antibody data packets can be obtained through the link index.
[0069] The heat evaluation value refers to a priority index calculated by counting the frequency of the immune recognition node being called within a preset time window and the number of associated threat events. Specifically, it can be implemented by a sliding window counting algorithm combined with a weighted accumulation method, which is used to reflect the current node's activity level in the defense system. The mirror value refers to a copy number parameter dynamically generated according to the heat evaluation value. Specifically, it can be implemented by using a logarithmic function to map the heat value to an integer range of 1 to N. It is used to control the degree of redundant backup of antibody data packets in a distributed network. The antibody data packet refers to a data unit that serializes and encapsulates the immune recognition node and its associated threat features. Specifically, it can be implemented by using a TLV encoding format combined with a lightweight compression algorithm. It is used for transmission between resource-constrained vehicle terminals. The link index refers to metadata that records the association between antibody data packets and antibody data packets. Specifically, it can be implemented by using a hash pointer combined with a distributed hash table. It is used to achieve fast retrieval and joint loading across data packets.
[0070] In the scenario where the storage capacity of the on-board terminal is limited, the immune encapsulation sub-strategy first calculates the heat evaluation value based on the call frequency of each immune recognition node in real-time threat interception. For example, if the number of triggers of a node in the last 5 minutes exceeds the threshold, its heat evaluation value will increase exponentially. The mirror value generation module converts the evaluation value into a specific number of copies. For example, when the heat value is in the medium range, 3 copies are generated, and when the heat value is high, 5 copies are generated. During the encapsulation process, each antibody data packet is assigned a unique link index, which contains the hash address and association relationship tag pointing to the antibody data packet. When the on-board terminal loads an antibody data packet, it automatically initiates parallel requests for associated data packets by parsing the link index. For example, when a CAN bus anomaly is detected, it only needs to load the main antibody data packet to automatically obtain the LIN protocol antibody data packet associated with it through the index, thereby realizing the coordinated call of cross-protocol defense resources.
[0071] Traditional vehicle-mounted defense systems use a fixed number of feature library copies for storage, resulting in high-heat defense strategies being unable to obtain sufficient redundant backups, while low-heat strategies occupy too much storage space. This solution uses a dynamic mirror value adjustment mechanism to enable high-value antibody data packets to obtain more copies in distributed nodes. For example, frequently used ECU communication encryption policy packages are copied to adjacent controllers, while seldom triggered diagnostic interface protection packages only retain a single copy. The indexing mechanism in existing technologies mostly uses a linear search method, while this solution uses hash pointers to achieve O(1) time complexity for associated data location. The measured data retrieval speed on a microcontroller with 128KB memory is increased by about 40 times.
[0072] This application effectively resolves the contradiction between the storage capacity of the vehicle terminal and the completeness of the defense strategy. It prioritizes the local availability of high-frequency usage strategies through a heat-driven dynamic copy mechanism, and realizes on-demand loading across data packets in combination with link indexes. While ensuring the real-time performance of anomaly detection, it reduces storage usage by more than 60%. When an attacker moves laterally in the Internet of Vehicles, neighboring nodes can quickly synchronize related antibody data packets through link indexes to form a distributed collaborative immune response, avoiding defense gaps caused by insufficient single-point storage in traditional solutions.
[0073] An immune distribution sub-strategy is proposed to generate a random number according to the random range corresponding to each antibody data packet. If the random number falls within the range, the antibody data packet will be distributed to the corresponding target terminal.
[0074] The random range refers to the numerical interval set in advance for the antibody data packet. It can be implemented by a preset probability distribution model or a dynamic interval adjustment algorithm based on the terminal load status. This range is used to control the distribution probability distribution of the antibody data packet between the target terminals to avoid network congestion caused by centralized distribution. The random number refers to the value generated by a specific algorithm. It can be implemented by a pseudo-random number generator such as the linear congruential method and the Mersenne rotation algorithm. The random number is compared with the random range to form a basis for distribution decision-making, ensuring that the distribution process is unpredictable to reduce the possibility of reverse tracking by attackers. Distribution to the corresponding target terminal means selecting the recipient based on the network topology and terminal defense status. It can be implemented by a hash map or a dynamic routing table based on terminal identification. This mechanism reduces cloud scheduling pressure through distributed decision-making and adapts to the low latency requirements of the vehicle network.
[0075] In the vehicle network environment, after the cloud generates an antibody data packet, the immune distribution sub-strategy first sets a dynamic random range for each antibody data packet based on the data packet type, the remaining computing resources of the target terminal, or the network link quality. For example, the random range of the antibody data packet for high-priority threats can be set to [0.6, 1.0], while that of the regular data packet is set to [0.3, 0.7]. The system calls the pseudo-random number generator to generate a floating-point number in the interval [0, 1). When the value falls within the preset range, the distribution operation is triggered. During the distribution process, the target terminal is selected based on the real-time status of the vehicle network topology. Through the terminal health score table maintained by the vehicle gateway, the antibody data packet is preferentially sent to the terminal with a score higher than the threshold. This mechanism ensures the efficiency of antibody propagation while preventing attackers from locking the critical transmission path through probabilistic distribution.
[0076] Traditional vehicle-mounted defense systems use fixed distribution paths or priority-based global queue scheduling, which are prone to single-point overload or path prediction risks in heterogeneous network environments. This solution combines dynamic random ranges with local decision-making mechanisms to make the distribution paths of antibody data packets temporally and spatially random. This not only adapts to the fluctuation characteristics of vehicle network bandwidth, but also reduces the computational load of the central control node through distributed decision-making. Compared with centralized scheduling that requires maintaining global terminal status information, this solution only needs to maintain local topology data at the gateway level, significantly reducing communication overhead.
[0077] This application effectively solves the problem of antibody distribution delay in vehicle networks due to limited terminal resources. Through a probabilistically triggered localized decision-making mechanism, dynamic allocation of defense resources is achieved without the need for global state synchronization. This solution enables antibody data packets to adaptively adjust the distribution density according to the real-time network conditions, avoiding overload of key nodes while ensuring that newly generated antibodies quickly cover high-risk areas before the attack spreads, thereby improving the collaborative defense response speed of the vehicle network in sudden threat scenarios.
[0078] Each antibody data packet is configured with an attenuation factor. When the attenuation factor is 0, the corresponding antibody data is deleted. The attenuation factor is calculated as follows: the attenuation factor is equal to the product of the initial attenuation coefficient and the negative time attenuation rate of the natural logarithm base e and the product of the time variable to the power of the product, plus the sum of the product of the number of local triggers and the trigger superposition coefficient, plus the sum of the product of the number of triggers of other user terminals in the same network and the product of the adjacent trigger superposition coefficients, and then minus the product of the repetition rate acceleration attenuation coefficient and the repetition trigger rate function. Among them, the time variable is used to describe the length of time the system runs, and the repetition trigger rate function reflects the trigger repetition frequency of the antibody data packet. The specific expression is:
[0079] ,
[0080] α is the initial attenuation coefficient; e is the base of natural logarithms; β is the time decay rate; t Represents a time variable, which is used to describe the length of time the system runs; n The total number of times this antibody data packet is triggered; X i The number of times this antibody data packet is triggered; K is the trigger superposition coefficient; m The total number of times other user terminals in the same network are triggered; Y j is the number of times other user terminals in the same network are triggered. is the proximity trigger superposition coefficient; is the repetition rate acceleration attenuation coefficient;f (Repeat Rate) is the repetition trigger rate function.
[0081] The attenuation factor refers to the calculation parameter used to dynamically adjust the survival period of the antibody data packet. Specifically, it can be implemented by a composite function based on trigger frequency, time attenuation and neighboring node behavior. The life cycle of the antibody data is automatically controlled by this factor. The initial attenuation coefficient refers to the basic attenuation value set when the antibody data packet is generated. Specifically, it can be assigned through a preset initial weight parameter to reflect the default survival strength of the antibody data. The time decay rate refers to the rate parameter that causes the attenuation factor to decrease over time. Specifically, it can be configured using the time coefficient in the exponential function to simulate the natural metabolic process of antibodies in the biological immune system. The trigger superposition coefficient refers to the dynamic adjustment parameter of the attenuation factor when the antibody data packet is triggered by a local or neighboring node. Specifically, it can be implemented using a cumulative weight algorithm to enhance the survival period of frequently used antibodies. The repetition rate acceleration attenuation coefficient refers to the accelerated attenuation control parameter for repeated triggering scenarios. Specifically, it can be implemented using a piecewise function based on the number of triggers to avoid redundant antibody data occupying storage resources for a long time.
[0082] In the vehicle network scenario, the life cycle of the antibody data packet is dynamically controlled by the attenuation factor. When the vehicle terminal receives the antibody data packet, the system sets the initial survival strength based on the initial attenuation coefficient, and gradually reduces the attenuation factor through the time attenuation rate over time. If the antibody data packet is frequently triggered in the local or neighboring nodes, the trigger superposition coefficient will increase the value of the attenuation factor to extend its validity period; conversely, if it is not triggered for a long time or the neighboring nodes already have the same antibody, the repetition rate acceleration attenuation coefficient will accelerate the decline of the attenuation factor. When the attenuation factor returns to zero, the system automatically deletes the corresponding antibody data packet to avoid wasting storage resources. This mechanism uses comprehensive calculations of multi-dimensional variables to dynamically adapt the survival cycle of the antibody data to the current network threat situation.
[0083] Traditional solutions rely on fixed storage cycles or manual strategies to delete antibody data, making them difficult to adapt to the dynamically changing threat environment of in-vehicle networks. For example, existing systems may forcibly delete non-expired antibodies due to storage capacity limitations, resulting in the loss of effective defense strategies; or retain expired antibodies, causing resource occupation. This solution achieves adaptive optimization of the antibody data survival cycle by integrating multi-dimensional calculations of time decay, trigger frequency, and neighboring node behavior, significantly reducing the proportion of redundant data while ensuring defense effectiveness.
[0084] This application solves the contradiction between the limited storage capacity of vehicle terminals and the dynamic defense needs, and realizes the intelligent lifecycle management of antibody data packets. When the attack characteristics change or the defense strategy fails, the system automatically eliminates inefficient antibodies and prioritizes retaining high-frequency used valid data, thereby maintaining high-coverage active defense capabilities within limited storage space. At the same time, by introducing neighboring node behavior data, the propagation trend of regionalized attacks can be quickly identified, and the antibody distribution strategy can be dynamically adjusted to avoid repeated consumption of defense resources.
[0085] It is proposed that when the change of the attenuation factor triggers the forwarding trigger condition, a forwarding instruction is generated to forward the antibody data packet to the adjacent user end. The forwarding trigger condition is that the attenuation factor decreases by more than a preset baseline decrease value within a preset time.
[0086] The forwarding trigger condition refers to the logical rule that determines whether to trigger data packet forwarding based on the time window and the attenuation threshold. It can be implemented by combining a timer module and a threshold comparator to dynamically evaluate the degree of attenuation of the effectiveness of the antibody data packet. The attenuation factor drop value refers to the reduction in the attenuation factor value per unit time. It can be achieved by calculating the difference between the initial attenuation coefficient and the current attenuation coefficient within the preset time window. It is used to quantify the failure rate of the immune strategy. The adjacent user terminal refers to the on-board device node that has a direct communication connection with the current terminal. It can be determined by the communication protocol handshake information in the on-board network topology structure, and is used to achieve directional propagation of antibody data packets.
[0087] When the system detects that the attenuation factor of a certain antibody data packet decreases by more than the baseline value within the preset time window, it indicates that the threat suppression ability of the immune strategy corresponding to the antibody in the current area has significantly decreased. At this time, the forwarding trigger condition is activated, and the system automatically generates a forwarding instruction to transmit the antibody data packet to the adjacent user end through the vehicle communication protocol. For example, when the vehicle gateway detects that the attenuation factor of the antibody data packet for the CAN bus injection attack decreases by more than 0.5 within 30 seconds, the data packet is immediately sent to the ECU node under the same domain controller through the vehicle Ethernet. In this process, the preset time window length can be 5-60 seconds, and the baseline drop value can be a dynamic threshold in the range of 0.3-0.7. The specific value can be dynamically adjusted according to the vehicle driving status.
[0088] In some specific embodiments, the judgment period of the forwarding trigger condition can be synchronized with the vehicle system clock. For example, the attenuation factor change rate calculation is performed once every 100 milliseconds. When it is detected that the cumulative decrease value exceeds the benchmark value in three consecutive cycles, the forwarding operation is triggered. The transmission of the antibody data packet can be multicast and prioritized through the TSN time-sensitive network channel of the vehicle network.
[0089] Traditional on-board defense systems lack a dynamic forwarding mechanism for antibody data packets, resulting in newly generated immunity strategies being effective only on a single terminal. However, this solution enables the active propagation of immunity strategies by introducing trigger conditions based on attenuation factors, allowing neighboring terminals to obtain updated defense capabilities before the attack spreads. For example, when a vehicle detects a new OTA attack, it can broadcast antibody data packets directly to surrounding vehicles through inter-vehicle communication before the attack signature is uploaded to the cloud, forming regional collaborative immunity.
[0090] This application effectively solves the problem of delayed antibody data packet propagation in the vehicle network environment, improves the diffusion efficiency of the immune strategy, and can realize multi-hop transmission of threat characteristics in vehicle-dense scenarios, so that terminals that are not directly attacked can load defense strategies in advance, significantly reducing the probability of lateral penetration of attacks in the vehicle network. At the same time, through the dynamic trigger mechanism, excessive transmission of invalid data packets is avoided, reducing the resource occupation of vehicle communication bandwidth.
[0091] The execution steps of the interactive response instruction are proposed, including: inserting an assisted immunity request field in the interaction data between the current user end and the target user end; after receiving the request, the target user end submits local abnormal feature data to the cloud; the cloud updates the feature recognition immune network based on the target user end data, and generates an adapted antibody data packet and transmits it back to the current user end.
[0092] The assisted immunity request field refers to a specific instruction field embedded in the interactive data, which can be implemented by a preset identifier or encrypted tag, and is used to transmit immune cooperation signals between user terminals. Local abnormal feature data refers to abnormal behavior logs or threat features detected and stored locally by the target user terminal, which can be extracted through data compression or feature hashing algorithm to enrich the coverage of the cloud immune network. Feature recognition immune network update refers to the cloud recalculating the correlation of immune nodes based on the newly added abnormal features. Specifically, incremental learning algorithms or graph neural networks can be used to dynamically adjust the node connection weights to ensure the real-time nature of the immune strategy. Adapted antibody data packets refer to defense instruction sets customized for the current user terminal operating environment. Specifically, they can be generated through difference comparison or environmental variable matching to accurately improve the defense capabilities of the target terminal.
[0093] When the current user end detects a potential threat, a specific format of assistance immunity request field is inserted into the header of the interactive data message sent to the target user end. For example, a binary identification code is set in the extension bit reserved in the CAN bus message. After the target user end parses the field, it automatically triggers the local abnormal feature collection program, and uploads the abnormal event feature code in the most recent time window to the cloud server through the on-board gateway. After the cloud receives the data, it first normalizes the feature code, and then matches it with the nodes in the existing feature recognition immune network for similarity. If the matching degree is found to be lower than the preset threshold, the network expansion process is started, new immune recognition nodes are added and the link relationship is optimized. The updated immune network generates an antibody data packet containing the latest threat features through the encapsulation sub-strategy, and pushes it to the current user end in a targeted manner via OTA, completing the closed-loop update of the defense strategy.
[0094] Traditional vehicle-mounted defense systems rely on fixed rule bases or manually configured whitelists when collaborating across terminals, and are unable to adjust their own defense strategies in real time based on threat intelligence from surrounding nodes. However, this solution uses standardized assistance request fields and a cloud-based dynamic immune network update mechanism to enable vehicles to quickly call upon the defense knowledge accumulated by neighboring nodes or the cloud when encountering unknown attacks, forming a dynamic collaborative immune barrier and effectively solving the problem of lateral spread of attacks caused by insufficient single-point defense capabilities.
[0095] This application enables vehicle-mounted terminals to dynamically enhance their defense capabilities through lightweight data interaction under resource-constrained conditions, reduce dependence on centralized cloud analysis, and shorten threat response delays. At the same time, by uploading local abnormal features and optimizing the global immune network, a distributed threat feature sharing mechanism is formed to enhance the group immunity of the Internet of Vehicles against zero-day attacks and avoid systemic security risks caused by the failure of single-node defense.
Claims
1. A dynamic defense system based on an immune data network, configured with a dynamic networking network architecture, the network architecture including a user terminal, a communication base station and a cloud, wherein the user terminals communicate with each other via a communication module, and the user terminals and the cloud communicate with each other via a communication base station, characterized in that: Including abnormality identification strategy, immune generation strategy, and immune operation strategy; The anomaly identification strategy is configured with an anomaly characterization database, which stores a number of anomaly characterization features and corresponding characterization response instructions. The anomaly identification strategy executes the corresponding characterization response instructions according to the anomaly characterization, and is configured with a preset immune evaluation algorithm for calculating the abnormal immunity value of the current user terminal. When the abnormal immunity value is greater than the preset immune reference value, the corresponding abnormal feature is extracted through a preset feature extraction sub-strategy and an intrusion immunity feature group is generated, and the intrusion immunity feature group is uploaded to the cloud for immune generation strategy processing; The immune generation strategy is configured with an abnormal feature immune database in the cloud, and the abnormal feature immune database stores a plurality of feature recognition immune networks, each feature recognition immune network corresponds to an intrusion immune feature group configuration, and each feature recognition immune network includes a plurality of immune recognition nodes, and immune recognition links are configured between the immune recognition nodes, and the immune recognition links reflect the relationship between the immune recognition nodes; The immune generation strategy generates a corresponding feature recognition immune network according to the invasion immune feature group; The immune operation strategy encapsulates the immune recognition node into a corresponding antibody data packet according to the immune encapsulation sub-strategy, and sends the antibody data packet to the corresponding target terminal according to the immune distribution sub-strategy. The target terminal receives the antibody data packet to update the corresponding abnormal characterization database; The immune evaluation algorithm performs a comprehensive calculation based on the preset value weight of the feature recognition immune network and the security level risk value of the interactive data. Specifically, the abnormal immunity value is equal to the sum of the ratios of the number of triggering times of each abnormal characterization feature within the time window and the corresponding feature weight, plus the product of the preset value weight and the determination coefficient when the feature combination triggers the feature recognition immune network, plus the product of the matching degree between the feature recognition immune network and the current abnormality and the security level risk value of the interactive data. The determination coefficient is 1 when the feature combination triggers the feature recognition immune network, and 0 otherwise. The formula is: , in, C i For the i Abnormal characterization features in the time window T Number of triggers within; W i is the weight of the corresponding feature; The determination coefficient of whether the feature combination triggers the feature recognition immune network, which is 1 when triggered and 0 otherwise; S Preset value weights for feature recognition immune networks; To identify the matching degree between the immune network and the current abnormality; M is the security level risk value of the interaction data.
2. A dynamic defense system based on immune data network according to claim 1, characterized in that: Characterization response instructions include static response instructions, dynamic response instructions, cloud response instructions, and interactive response instructions; The static response instruction is to replace the target interaction instruction of the current user terminal with a preset static defense instruction set; The dynamic response instruction is to monitor the interaction data of the target interaction interface of the current user terminal, trigger the corresponding interaction response instruction according to the interaction data and send it to the corresponding target interaction interface; The cloud response instruction is to replace the corresponding user terminal's immune operation strategy with the target immune operation strategy in the cloud; The interactive response instruction is to add a corresponding assisted immunity request to the interactive data between the current user terminal and the target user terminal.
3. A dynamic defense system based on immune data network according to claim 1, characterized in that: The feature extraction sub-strategy includes configuring a behavior anomaly library, a period anomaly library and a content anomaly library in the cloud. The feature extraction sub-strategy includes obtaining all interaction data generated by the current user terminal within the time window when the anomaly identification strategy determines that the anomaly immunity value is greater than the preset immunity reference value, and dividing the interaction data into several sub-events through event classification rules. The anomaly sub-value of each sub-event is evaluated through the behavior anomaly library, the period anomaly library and the content anomaly library. When the anomaly sub-value is greater than the preset feature extraction reference value, the characterization content data corresponding to the sub-event is used as a header to construct behavior anomaly sub-data, period anomaly sub-data and content anomaly sub-data to generate the anomaly feature.
4. A dynamic defense system based on immune data network according to claim 1, characterized in that: The immune generation strategy includes configuring a cluster analysis algorithm, assigning each abnormal feature of the intrusion immune feature group to a multidimensional coordinate system, wherein the coordinate system includes the attack type, threat level, timestamp and data source credibility. The feature cluster belonging to the same intrusion immune feature group is obtained through the cluster analysis algorithm, and each abnormal feature is translated into a corresponding immune trigger link through a preset immune translation sub-strategy. Each immune trigger link includes several immune recognition nodes, and the number of dimensions of the feature recognition immune network is constructed according to the number of identical immune recognition nodes in the same immune feature group, and the immune recognition nodes are loaded into the corresponding feature recognition immune network.
5. The dynamic defense system based on immune data network according to claim 1, characterized in that: The immune encapsulation sub-strategy generates a mirror value based on the heat evaluation value of the immune network, encapsulates the immune recognition node and copies the antibody data packet with the mirror value number. The antibody data packet includes a link index, and the link index points to the antibody data packet related to the immune recognition node. When the user terminal calls a certain antibody data packet, all related antibody data packets can be obtained through the link index.
6. A dynamic defense system based on immune data network according to claim 1, characterized in that: The immune distribution sub-strategy generates a random number according to the random range corresponding to each antibody data packet, and distributes the antibody data packet to the corresponding target terminal if the random number falls within the range.
7. A dynamic defense system based on immune data network according to claim 1, characterized in that: Each antibody data packet is configured with an attenuation factor. When the attenuation factor is 0, the corresponding antibody data is deleted. The attenuation factor is calculated as follows: the attenuation factor is equal to the product of the initial attenuation coefficient and the negative time attenuation rate of the natural logarithm base e and the product of the time variable, plus the sum of the product of the local trigger times and the trigger superposition coefficient, plus the sum of the product of the trigger times of other user terminals in the same network and the adjacent trigger superposition coefficients, and then minus the product of the repetition rate acceleration attenuation coefficient and the repetition trigger rate function. Among them, the time variable is used to describe the length of time the system runs, and the repetition trigger rate function reflects the trigger repetition frequency of the antibody data packet.
8. A dynamic defense system based on immune data network according to claim 7, characterized in that: It also includes a forwarding trigger condition. When the change in the attenuation factor triggers the forwarding trigger condition, a forwarding instruction is generated to forward the antibody data packet to the adjacent user end. The forwarding trigger condition is that the attenuation factor decreases by more than a preset benchmark decrease value within a preset time.
9. The dynamic defense system based on immune data network according to claim 2, characterized in that: The execution steps of the interactive response instruction include: Step S1: inserting an assisted immunity request field into the interaction data between the current user terminal and the target user terminal; Step S2: After receiving the request, the target user terminal submits local abnormal feature data to the cloud; Step S3: The cloud updates the feature recognition immune network based on the target user terminal data, and generates an adapted antibody data packet and transmits it back to the current user terminal.
Citation Information
Patent Citations
Network boundary intrusion dynamic detection method and system
CN118041573A
Active immune defense strategy generation method under cloud-side cooperation
CN119602985A