A data security detection method for signal transmission software
By analyzing the signal-to-noise ratio time series data during signal transmission and using time series decomposition algorithms and eigenvalue analysis, we can distinguish outliers caused by electromagnetic interference and network attacks, thereby improving the accuracy of detecting network anomalies and ensuring the security detection effect of signal transmission software.
Patent Information
- Application Number
- CN202510990240.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-07-18
AI Technical Summary
Existing technologies cannot effectively distinguish between outliers caused by electromagnetic interference and network attacks, resulting in inaccurate judgment of network anomalies and affecting security detection effects.
By obtaining the signal-to-noise ratio time series data during signal transmission, applying the time series decomposition algorithm to obtain the residual time series data, analyzing the trend eigenvalues, local distribution eigenvalues and electromagnetic correlation eigenvalues of the outliers, screening out the outliers affected by electromagnetic interference, and identifying network anomalies.
It achieves accurate distinction between outliers caused by electromagnetic interference and network attacks, improves the accuracy of network anomaly detection, and ensures the effectiveness of security detection.
Smart Images

Figure CN120493241B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security detection, and in particular to a data security detection method for signal transmission software. Background Art
[0002] Signal transmission software, as a key tool for processing and managing signal transmission, ensures efficient and secure data transmission. Ensuring data security is a critical issue facing current signal transmission software. Anomaly detection is a key component of data security testing. Anomalies represent potential security threats or data quality issues. By effectively detecting and identifying anomalies, abnormal behavior, potential attack patterns, or system failures can be promptly identified, allowing appropriate measures to be taken to protect data security.
[0003] When performing security detection on signals, existing technologies usually use a time series decomposition algorithm to obtain residual terms, and then obtain outliers as network anomalies that are affected by network attacks by setting upper and lower thresholds. However, since electromagnetic interference usually exists during signal transmission, and electromagnetic interference can also generate outliers, only setting upper and lower thresholds to determine outliers cannot effectively distinguish between outliers caused by electromagnetic interference and outliers caused by network attacks, resulting in inaccurate judgment of network anomalies and affecting the effectiveness of security detection. Summary of the Invention
[0004] In order to solve the technical problem that both electromagnetic interference and network attacks can generate outliers, and only setting upper and lower thresholds for outlier judgment cannot effectively distinguish outliers generated by electromagnetic interference from outliers generated by network attacks, resulting in inaccurate judgment of network anomalies and affecting the effectiveness of security detection, the purpose of the present invention is to provide a data security detection method for signal transmission software. The technical solution adopted is as follows:
[0005] Acquire signal-to-noise ratio time series data during signal transmission in at least two channels; acquire residual time series data corresponding to each signal-to-noise ratio time series data based on a time series decomposition algorithm;
[0006] In each residual time series data, outliers and trend attachment points of outliers are obtained based on the numerical distribution of each residual point; the trend characteristic value of the corresponding outlier is obtained based on the time and change trend of the trend attachment point corresponding to each outlier; the local distribution characteristic value of each outlier is obtained based on the position distribution concentration between all outliers; the electromagnetic property characteristic value of the corresponding outlier is obtained based on the numerical value, trend characteristic value, local distribution characteristic value of each outlier and the positional relationship between each outlier and the nearest residual point;
[0007] In the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, the electromagnetic correlation eigenvalue corresponding to each outlier is obtained based on the correlation of the local distribution eigenvalues between all outliers; the electromagnetic interference degree value of the corresponding outlier is obtained based on the electromagnetic attribute eigenvalue and electromagnetic correlation eigenvalue of each outlier;
[0008] In each residual time series data, according to the electromagnetic interference degree values of all outliers, the outliers affected by electromagnetic interference are screened out to obtain network anomalies.
[0009] Furthermore, the method of obtaining outliers and trend-dependent points of outliers based on the numerical distribution of each residual point includes:
[0010] Calculate the numerical mean and numerical standard deviation of all residual points, and determine the numerical fluctuation range based on the numerical mean and numerical standard deviation;
[0011] The residual points whose values exceed the numerical fluctuation range are regarded as outliers;
[0012] Obtain the extreme points in each residual time series data, and take all residual points between the previous and next extreme points in the time series of each outlier as trend attachment points of the corresponding outlier.
[0013] Furthermore, determining the numerical fluctuation range according to the numerical mean and the numerical standard deviation includes:
[0014] The difference between the numerical mean and the numerical standard deviation of the preset multiple is taken as the lower limit of the numerical fluctuation range, and the sum of the numerical mean and the numerical standard deviation of the preset multiple is taken as the upper limit of the numerical fluctuation range to obtain the numerical fluctuation range.
[0015] Furthermore, the residual time series data is a time series curve, and the trend characteristic value of the corresponding outlier is obtained according to the time and change trend of the trend attached point corresponding to each outlier, including:
[0016] The difference in time between each trend attachment point and the corresponding outlier point is taken as the time difference of the trend attachment point;
[0017] In the time series curve corresponding to the residual time series data, the slope of each trend attachment point is calculated, and the ratio of the absolute value of the slope of each trend attachment point to the corresponding time difference is used as the trend factor;
[0018] The normalized value of the mean of the trend factors corresponding to all trend attached points of each outlier is used as the trend characteristic value of the corresponding outlier.
[0019] Furthermore, the method of obtaining the local distribution characteristic value of each outlier point according to the position distribution concentration of all outliers includes:
[0020] Obtaining the optimal K value for clustering all outliers based on the elbow method, performing cluster analysis on all outliers based on the K-means clustering algorithm and the optimal K value to obtain cluster clusters;
[0021] Choose any outlier as the test point, and calculate the minimum Euclidean distance between each outlier and other outliers in the cluster where the test point is located, as the distance factor of the corresponding outlier;
[0022] The value after negative correlation mapping of the total number of outliers in the cluster where the test point is located is used as the quantity factor; the sum of the distance factors of all outliers in the cluster where the test point is located and the product of the quantity factor are normalized to obtain the local distribution characteristic value corresponding to the test point.
[0023] Furthermore, the electromagnetic property characteristic value of the corresponding outlier point is obtained according to the numerical value, trend characteristic value, local distribution characteristic value and positional relationship between each outlier point and the nearest residual point, including:
[0024] Calculate the difference between the value of each outlier point and the mean value to obtain the value difference; use the minimum Euclidean distance between each outlier point and other residual points as the distance parameter;
[0025] The product of the numerical difference, distance parameter, trend characteristic value and local distribution characteristic value corresponding to each outlier point is normalized and used as the electromagnetic attribute characteristic value of the corresponding outlier point.
[0026] Furthermore, in the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, the electromagnetic correlation eigenvalue of each outlier is obtained based on the similarity and correlation of the local distribution eigenvalues between all outliers, including:
[0027] In the residual time series data corresponding to the signal-to-noise ratio time series data of each channel, the outliers are arranged in time series to obtain a sorted sequence;
[0028] An outlier point is randomly selected as the target point, and the length of the sorted sequence where the target point is located is aligned with each of the remaining sorted sequences to obtain all sequence groups corresponding to the target point. The length alignment process is as follows: in the two sorted sequences, with the shortest sorted sequence as the benchmark, the outlier point with the largest time difference from the target point is continuously removed from the longest sorted sequence until the sequence length is the same as the shortest sorted sequence. The updated sequence is then obtained, and the updated sequence and the shortest sorted sequence are combined into a sequence group.
[0029] In each sequence group corresponding to the target point, the Pearson correlation coefficient between the local distribution characteristic values of the outliers in the two sequences is calculated, and the difference in the local distribution characteristic values between the target point and the outliers with the same sequence number is calculated as the distribution difference value of the target point in the corresponding sequence group;
[0030] The sum of the absolute values of the Pearson correlation coefficients calculated for all sequence groups corresponding to the target point is negatively correlated and normalized to obtain the degree of independence between the target point and the outliers in the residual time series data of other channels; the sum of all distribution difference values of the target point in all sequence groups is used as the degree of difference between the target point and the outliers in the residual time series data of other channels;
[0031] The product of the irrelevance and difference corresponding to the target point is taken as the electromagnetic correlation eigenvalue of the target point.
[0032] Furthermore, the step of obtaining the electromagnetic interference degree value of the corresponding outlier point according to the electromagnetic property characteristic value and the electromagnetic correlation characteristic value of each outlier point includes:
[0033] The normalized value of the mean of the electromagnetic attribute eigenvalue and the electromagnetic correlation eigenvalue of each outlier point is used as the electromagnetic interference degree value of the corresponding outlier point.
[0034] Furthermore, in each residual time series data, according to the electromagnetic interference degree values of all outliers, the residual points affected by electromagnetic interference are screened out to obtain network anomalies, including:
[0035] The outliers corresponding to the electromagnetic interference degree values greater than or equal to the preset abnormal threshold are regarded as residual points affected by electromagnetic interference. Among all the outliers, the residual points affected by electromagnetic interference are removed, and the remaining outliers are network abnormal points.
[0036] Furthermore, the method of obtaining residual time series data corresponding to each signal-to-noise ratio time series data based on the time series decomposition algorithm includes:
[0037] Based on the STL time series decomposition algorithm, each signal-to-noise ratio time series data is detrended and deperiodic to obtain a residual term, and corresponding residual time series data is obtained according to all residual points in the residual term.
[0038] The present invention has the following beneficial effects:
[0039] The present invention provides a data security detection method for signal transmission software, the main purpose of which is to accurately distinguish outliers caused by electromagnetic interference and network attacks during signal transmission, thereby improving the accuracy of network anomaly detection and ensuring the effectiveness of security detection. First, the signal-to-noise ratio time series data of signal transmission in at least two channels is obtained, and then it is decomposed based on a time series algorithm to obtain residual time series data. Since electromagnetic interference has a process characteristic, specifically manifested in the interference intensity from weak to strong and then from strong to weak, and the noise interference caused by network attacks or other dangerous network factors usually appears suddenly and has no process characteristic, electromagnetic interference will cause the residual points in the residual time series data to show certain trends and regularities. Therefore, in each residual time series data, the numerical distribution and change trend of each residual point can be analyzed to obtain outliers and trend characteristic values corresponding to the outliers, which can be used as one of the indicators to characterize that the outliers are caused by electromagnetic interference. Furthermore, due to the diversity of electromagnetic interference sources, the distribution of outliers affected by electromagnetic interference exhibits random characteristics. However, cyber attacks are human-caused, resulting in more concentrated distributions of outliers. Therefore, based on the concentration of the positional distribution between outliers, local distribution eigenvalues can be derived as another indicator of whether the outliers are caused by electromagnetic interference. These two indicators are then combined to obtain the electromagnetic property eigenvalues of the outliers, which characterize the degree of electromagnetic interference exposure. Furthermore, since analyzing only the data points in the residual time series data corresponding to a single channel is somewhat one-sided, and the interference intensity of electromagnetic interference varies across different channels, cyber attacks typically attack multiple channels simultaneously, resulting in more similar and correlated anomalies or noise. Therefore, based on this characteristic, the residual time series data corresponding to multiple channels is combined to analyze the similarities and correlations between the local distribution eigenvalues of the outliers across these data to obtain the electromagnetic correlation eigenvalues. Finally, the electromagnetic correlation eigenvalues and the electromagnetic attribute eigenvalues are combined to obtain the electromagnetic interference degree value caused by electromagnetic interference, and then the outliers caused by electromagnetic interference can be removed according to the electromagnetic interference degree value of the outliers to obtain network anomalies, thereby accurately identifying network anomalies and ensuring the effect of security detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] Figure 1A flow chart of a data security detection method for signal transmission software provided by one embodiment of the present invention. DETAILED DESCRIPTION
[0042] To further illustrate the technical means and effectiveness of the present invention in achieving its intended objectives, the following, in conjunction with the accompanying drawings and preferred embodiments, describes in detail the specific implementation, structure, features, and effectiveness of a data security detection method for signal transmission software proposed in accordance with the present invention. In the following description, references to "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.
[0043] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0044] The following describes in detail a specific solution of a data security detection method for signal transmission software provided by the present invention with reference to the accompanying drawings.
[0045] See also Figure 1 , which shows a method flow chart of a data security detection method for signal transmission software provided by an embodiment of the present invention, the method comprising the following steps:
[0046] Step S1: obtaining signal-to-noise ratio time series data during signal transmission in at least two channels; obtaining residual time series data corresponding to each signal-to-noise ratio time series data based on a time series decomposition algorithm.
[0047] Signal transmission software, a key tool for processing and managing signal transmission, ensures efficient and secure data transmission. However, cyberattacks can cause data transmission issues during actual signal transmission. Therefore, effectively monitoring the signal transmission process and promptly detecting anomalies is a critical challenge facing current signal transmission software.
[0048] Since the signal-to-noise ratio is an important indicator for measuring signal quality, and the signal-to-noise ratio can reflect the influence of noise during signal transmission, and when subjected to network attacks or electromagnetic interference, the signal-to-noise ratio will usually change accordingly, the embodiment of the present invention mainly analyzes the signal-to-noise ratio data. First, the signal-to-noise ratio timing data during signal transmission in at least two channels is obtained, wherein the signal-to-noise ratio timing data is timing curve data; the specific acquisition method is: installing a sensor or detection device at the transmission communication node of the signal transmission software to measure the signal and noise in the data transmission channel, thereby obtaining the signal-to-noise ratio timing data, and the acquisition frequency can be set to 44.1kHz. It should be noted that the acquisition method of the signal-to-noise ratio timing data can be adjusted according to the implementation scenario, and is not limited here.
[0049] Since the data is affected by trend terms and cycle terms, the trend represents the long-term trend of change, the cycle represents the periodic change pattern, and the residual represents those parts that cannot be explained by the trend and cycle, which usually contain some abnormal information and noise information. Therefore, when performing security detection on the signal, the time series decomposition algorithm can be used to decompose the data to obtain the residual term, and then further analyze the residual term to determine the network anomaly points and achieve security detection.
[0050] Preferably, in one embodiment of the present invention, obtaining residual time series data corresponding to each signal-to-noise ratio time series data based on a time series decomposition algorithm includes:
[0051] The STL time series decomposition algorithm can be used to remove the trend and periodicity of each signal-to-noise ratio time series data to obtain the corresponding residual term. Then, the residual time series data can be obtained based on all the residual points in the residual term. The residual time series data is also the time series curve data. It should be noted that the method of removing the trend and periodicity of the data based on the STL time series decomposition algorithm to obtain the residual term is a technical means well known to those skilled in the art and will not be described in detail here.
[0052] At this point, the residual time series data corresponding to each signal-to-noise ratio time series data can be obtained.
[0053] Step S2: In each residual time series data, the outliers and the trend attached points of the outliers are obtained according to the numerical distribution of each residual point; the trend characteristic value of the corresponding outlier is obtained according to the time and change trend of the trend attached point corresponding to each outlier; the local distribution characteristic value of each outlier is obtained according to the position distribution concentration between all outliers; the electromagnetic property characteristic value of the corresponding outlier is obtained according to the numerical value, trend characteristic value, local distribution characteristic value of each outlier and the positional relationship between each outlier and the nearest residual point.
[0054] We can first analyze the residual time series data corresponding to individual channels. Because electromagnetic interference is process-dependent, specifically, when electromagnetic radiation from an external electromagnetic interference source propagates to the channel, the interference intensity of the electromagnetic noise in the channel increases from weak to strong. As the electromagnetic interference from the external electromagnetic interference source weakens and disappears, the interference intensity of the electromagnetic noise in the channel decreases from strong to weak. In the residual time series data after time series decomposition, the signal-to-noise ratio in the corresponding channel will show a continuous trend between the abnormal outliers caused by electromagnetic interference and the adjacent residual points. In other words, the residual points on both sides of the adjacent residual points tend to gradually deviate from the outlier residual point. However, noise interference or anomalies caused by cyberattacks or other dangerous network factors often appear suddenly and lack a process-dependent nature. Therefore, the corresponding outlier residual points are not affected by the trend process and do not exhibit a continuous trend. Therefore, by analyzing the numerical distribution of each residual point in the residual time series data, we can identify the outlier residual points and the trend-dependent points that have a trend change with the outlier residual points.
[0055] Preferably, in one embodiment of the present invention, obtaining outliers and trend-attached points of outliers based on the numerical distribution of each residual point includes:
[0056] First, the numerical mean and numerical standard deviation of all residual points in the residual time series data are calculated, and the numerical fluctuation range is determined according to the numerical mean and the numerical standard deviation; the method for obtaining the fluctuation range is specifically as follows: the difference between the obtained numerical mean and the numerical standard deviation of the preset multiple is used as the lower limit value, and the sum of the numerical mean and the numerical standard deviation of the preset multiple is used as the upper limit value, wherein the preset multiple is usually 3. In other embodiments of the present invention, other values can also be taken, which are not limited here.
[0057] Then, residual points whose values exceed the numerical fluctuation range are regarded as outliers. After obtaining the outliers, based on the above analysis, it can be seen that the residual points on both sides of the outliers caused by electromagnetic interference usually have continuous trend changes, and the data on both sides of the peaks and troughs in the time series data can usually represent this change. Therefore, the extreme points in each residual time series data are obtained, and all residual points between the previous extreme point and the next extreme point adjacent to each outlier in the time series are regarded as the trend attachment points of the corresponding outlier. If there are special cases, such as if an outlier is the first residual point, then the trend attachment points of the outlier are all the residual points between it and the next extreme point. Similarly, if an outlier is the last residual point, then the trend attachment points of the outlier are all the residual points between it and the previous extreme point.
[0058] At this point, the outliers in the residual time series data and the trend attachment points corresponding to the outliers have been obtained. By analyzing the time difference and change trend between each outlier and its corresponding trend attachment point, the trend characteristic value of the outlier can be obtained as an indicator to evaluate whether the outlier is caused by electromagnetic interference.
[0059] Preferably, in one embodiment of the present invention, obtaining the trend characteristic value of the corresponding outlier according to the time and change trend of the trend attachment point corresponding to each outlier includes:
[0060] Since the slope can intuitively reflect the trend characteristics, the absolute value of the slope of each trend attachment point is calculated in the time series curve corresponding to the residual time series data. The closer the time distance between the trend attachment point and the outlier point, the higher the credibility. Conversely, the farther the time distance, the lower the credibility. Therefore, the time difference between each outlier point and each corresponding trend attachment point is calculated, and then the ratio of the absolute value of the slope of each trend attachment point to the corresponding time difference is used as the trend factor of the corresponding trend attachment point.
[0061] Finally, the normalized value of the trend factor of all trend-attached points of each outlier is used as the trend characteristic value of the corresponding outlier. The formula model of the trend characteristic value is:
[0062]
[0063] in, Indicates the The trend characteristic value of the outlier point, Indicates the The total number of trend-affiliated points corresponding to the outliers, Indicates the The outlier The slope value of the trend attachment point, Indicates the outliers and The time difference between trend attachment points, Indicates normalization.
[0064] In the trend characteristic value formula model, the slope value of each trend attachment point corresponding to the outlier is calculated to represent the trend at that location. The more gradual the outlier trend, the larger the slope value of the trend attachment point corresponding to the outlier. The time difference between the outlier and each corresponding trend attachment point is also calculated. This time difference can be used as the credibility of the slope. The smaller the time difference between a trend attachment point and the outlier, the closer they are, and the more credible its inclusion in the calculation process. Conversely, the larger the time difference between a trend attachment point and the outlier, the farther they are from each other, and the less credible its inclusion in the calculation process should be. Therefore, the time difference is used as the denominator and the absolute value of the slope as the numerator to obtain the trend factor corresponding to each trend attachment point. Finally, the trend factors of all trend attachment points corresponding to the outlier are averaged to obtain the trend characteristic value of the outlier. The larger the value, the more likely the outlier is caused by electromagnetic interference, rather than a network anomaly caused by a network attack or other network risk factors.
[0065] At this point, by analyzing the time difference and trend characteristics between the outlier point and its corresponding trend attached point, the trend characteristic value of the outlier point is obtained as one of the indicators to evaluate whether it is a network anomaly point.
[0066] In addition to being procedural, electromagnetic interference is also random. Because the signal transmission software environment often contains a variety of unknown electromagnetic interference sources, the outliers generated after time series decomposition are randomly distributed across multiple locations. Cyberattacks or other dangerous network factors are man-made, and within a short period of time from start to finish, a relatively concentrated amount of anomalies and noise will appear within the channel. Therefore, the outliers representing anomalies in the residual terms after time series decomposition exhibit a concentrated distribution. Based on this characteristic, the concentration or dispersion of outliers in each residual time series data set can be analyzed to determine the local distribution characteristic value of each outlier, which serves as an indicator for evaluating whether the outlier was caused by electromagnetic interference.
[0067] Preferably, in one embodiment of the present invention, obtaining the local distribution characteristic value of each outlier point based on the position distribution concentration between all outliers includes:
[0068] When analyzing the distribution concentration of outliers, since the results obtained will be more accurate by analyzing the distribution concentration or dispersion of a class of outliers with similar characteristics, the optimal K value for clustering all outliers is first obtained based on the elbow method. Then, all outliers can be clustered based on the K-means clustering algorithm and the optimal K value to obtain cluster clusters.
[0069] In order to facilitate subsequent explanation and illustration, an outlier point is selected as a test point, and the method for obtaining the local distribution characteristic value is explained by analyzing the test point.
[0070] Then, in the cluster where the test point is located, the minimum Euclidean distance between each outlier and other outliers is calculated as the distance factor of the corresponding outlier. The distance factor can characterize the distance between all outliers in the cluster where the test point is located, so it can be used as a parameter to analyze whether the distribution is concentrated or dispersed. The total number of outliers in the cluster can also characterize the concentration or dispersion of the outlier distribution. Therefore, the sum of the distance factors of all outliers is multiplied by the value of the negative correlation mapping of the total number of outliers in the cluster where the test point is located, and the obtained product is normalized to obtain the local distribution characteristic value corresponding to the test point. The test point is an outlier. For example, the formula model of the local distribution eigenvalue can be specifically as follows:
[0071]
[0072] in, Indicates the point to be tested The local distribution eigenvalue of Indicates the point to be tested The total number of outliers in the cluster. Indicates the point to be tested The cluster in which The distance factor of the outliers, Indicates normalization.
[0073] In the formula model of the local distribution eigenvalue, the minimum Euclidean distance between each outlier point and other outliers in the cluster where the test point is located is calculated as the distance factor of the corresponding outlier point At this time, the larger the distance factor is, the more dispersed the distribution of outliers in the cluster where the test point is located is, which is more consistent with the random characteristics of outliers generated by electromagnetic interference. Conversely, if the distance factor is smaller, the more concentrated the distribution of outliers in the cluster where the test point is located is, then it is more likely that it has been interfered with by a network attack or other dangerous network factors. Similarly, if the number of outliers in the cluster corresponding to the test point is greater, it means that the number of outliers with the same characteristics is greater, then it can be considered that the more concentrated the distribution of outliers is, the more likely it is that it has been attacked by a network. Conversely, if the number of outliers in the cluster corresponding to the test point is smaller, it means that the number of outliers with the same characteristics is smaller, and it can be considered that the generation of outliers is more likely to be caused by electromagnetic interference. Therefore, the total number of outliers in the cluster is negatively correlated to obtain the quantity factor. , after the logical relationship is corrected, it is multiplied by the distance factor and value of all outliers to obtain the local distribution eigenvalue corresponding to the test point, that is, the local distribution eigenvalue corresponding to the cluster where the test point is located. All outliers in the cluster have the same local distribution eigenvalue.
[0074] It should be noted that the process of obtaining the optimal K value of data based on the elbow method is an operation process well known to those skilled in the art. Similarly, the process of clustering data based on the K-means clustering algorithm is also an operation process well known to those skilled in the art and will not be described in detail here.
[0075] At this point, based on another characteristic of electromagnetic interference: randomness, the local distribution characteristic value corresponding to each outlier can be obtained as one of the indicators for evaluating whether it is a network anomaly point.
[0076] In the above process, the process and randomness of electromagnetic interference are analyzed, and the trend characteristic value and local distribution characteristic value of each outlier in each residual time series data are obtained. Therefore, the two can be combined here and combined with the numerical value of the outlier and the positional relationship between the outlier and the adjacent residual points to obtain the electromagnetic attribute characteristic value of the outlier. Due to the combination of multiple factors, it can better characterize whether the outlier is caused by electromagnetic interference.
[0077] Preferably, in one embodiment of the present invention, obtaining the electromagnetic property characteristic value of the corresponding outlier point according to the numerical value, trend characteristic value, local distribution characteristic value and positional relationship of each outlier point with the nearest residual point includes:
[0078] First, the difference between the numerical value of each outlier and the numerical mean of all residual points in the residual time series data is calculated to obtain the numerical difference; in the embodiment of the present invention, the closest distance is considered to be the closest Euclidean distance, so the minimum Euclidean distance between each outlier and other residual points is calculated to obtain the distance parameter; the numerical difference and distance parameter corresponding to each outlier can characterize the degree of outlier of the outlier, and the degree of outlier can be used as the confidence of the trend characteristic value and local distribution characteristic value corresponding to the outlier.
[0079] Finally, the product of the numerical difference, distance parameter, trend characteristic value, and local distribution characteristic value corresponding to each outlier point is used as the electromagnetic attribute characteristic value of the corresponding outlier point. The formula model of the electromagnetic attribute characteristic value is:
[0080]
[0081] in, Indicates the The electromagnetic property eigenvalues of the outliers, Indicates the The trend characteristic value of the outlier point, Indicates the The local distribution eigenvalues of outliers, Indicates the The numerical difference corresponding to the outliers is Indicates the The distance parameter corresponding to the outlier point.
[0082] In the formula model of electromagnetic attribute characteristic values, based on the above analysis, it can be seen that the larger the trend characteristic value and local distribution characteristic value of the outlier, the more likely the outlier is caused by electromagnetic interference. At the same time, this embodiment of the present invention also calculates the difference between the value of the outlier and the mean value of all residual points in the residual time series data, obtains the numerical difference, and then calculates the minimum Euclidean distance between the outlier and other residual points to obtain the distance parameter. The larger the numerical difference, the larger the distance parameter, the more outlier the outlier is, and the more likely it is to be judged as an abnormal point. Therefore, it is more necessary to distinguish whether it is caused by electromagnetic interference or a true abnormal point, so the product of the two is taken. The larger the product of the outlier's trend characteristic value and the local distribution characteristic value, the higher the credibility of the outlier's trend characteristic value and the local distribution characteristic value. Finally, the four parameters of numerical difference, distance parameter, trend characteristic value, and local distribution characteristic value are multiplied together to obtain the electromagnetic property characteristic value of the outlier.
[0083] At this point, the outliers in each residual time series data are analyzed according to the characteristics of electromagnetic interference, and the electromagnetic attribute characteristic values are obtained to characterize the degree to which the outliers are affected by electromagnetic interference. This can be used in the subsequent process of distinguishing whether the outliers are caused by electromagnetic interference or network attacks.
[0084] Step S3: In the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, the electromagnetic correlation eigenvalue corresponding to each outlier is obtained according to the correlation of the local distribution eigenvalues between all outliers; the electromagnetic interference degree value of the corresponding outlier is obtained according to the electromagnetic attribute eigenvalue and electromagnetic correlation eigenvalue of each outlier.
[0085] Given that the above analysis process is only for a single channel, the judgment of the degree of electromagnetic interference of outliers in the residual time series data is somewhat one-sided. Since electromagnetic interference has many interference sources and is highly random, the impact it produces in multiple channels should be different, which is specifically reflected in the distribution characteristics. Network attacks or other dangerous network factors usually choose multiple channels for simultaneous attacks, which leads to the distribution of anomalies or noise generated in multiple channels being more similar and correlated. Based on this feature, the embodiment of the present invention analyzes the similarity and correlation of the local distribution eigenvalues between outliers in the residual time series data corresponding to all channels, and obtains the electromagnetic correlation eigenvalue as the final indicator for evaluating the degree to which outliers are affected by electromagnetic interference.
[0086] Preferably, in one embodiment of the present invention, in the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, obtaining the electromagnetic correlation eigenvalue of each outlier based on the correlation of the local distribution eigenvalues between all outliers includes:
[0087] First, in the residual time series data corresponding to the signal-to-noise ratio time series data of each channel, the outliers are sorted according to their time sequence to obtain a sorted sequence. For ease of explanation and illustration, a single outlier is selected as the target point and analyzed to explain the method for obtaining the electromagnetic correlation eigenvalue.
[0088] The length of the sorted sequence containing the target point is aligned with each of the remaining sorted sequences to obtain all sequence groups corresponding to the target point. The length alignment process involves using the shortest sorted sequence as the benchmark and continuously removing outliers with the largest time differences from the target point in the longest sorted sequence until the sequence length matches the shortest sorted sequence. This results in an updated sequence, which is then combined with the shortest sorted sequence to form a sequence group. At this point, if there are s channels in total, there are s-1 sequence groups in total. An example of the length alignment process is given: if the target point is 4 and its sorted sequence is (0, 1, 2, 3, 4, 5), in the process of forming a sequence group with the sorted sequence (6, 7, 8, 9), the length of the sorted sequence (6, 7, 8, 9) is used as the benchmark. In the sorted sequence (0, 1, 2, 3, 4, 5), the outlier with the largest difference from the target point 4 is calculated. Assuming it is outlier 0, outlier 0 is removed and the sequence becomes (1, 2, 3, 4, 5). Then, in (1, 2, 3, 4, 5), the outlier with the largest difference from the target point 4 is removed. Assuming it is outlier 5, the sequence becomes (1, 2, 3, 4) and its length is the same as that of the sorted sequence (6, 7, 8, 9). Then (1, 2, 3, 4) is used as the update sequence and forms a sequence group with the sorted sequence (6, 7, 8, 9).
[0089] Since the Pearson correlation coefficient can characterize the correlation between two sets of data, the Pearson correlation coefficient between the local distribution eigenvalues of the outliers in the two sequences is calculated in each sequence group corresponding to the target point. Since only correlation is considered, whether it is positive or negative correlation is not necessary. Therefore, the sum of the absolute values of the Pearson correlation coefficients calculated for all sequence groups corresponding to the target point is negatively correlated and normalized to serve as the degree of independence between the target point and the outliers in the residual time series data of other channels. The independence degree analyzes the correlation between the local distribution eigenvalues of the outliers in the residual time series data corresponding to the channel from a global perspective.
[0090] Next, we can analyze the similarity between the local distribution eigenvalues of outliers in the residual time series data corresponding to the channel at the specific point level. In each sequence group corresponding to the target point, we calculate the difference in the local distribution eigenvalues between the target point and the outliers with the same sequence number as the distribution difference value corresponding to the target point. Then, we calculate the sum of all the distribution difference values corresponding to the target point as the difference between the target point and the outliers in the residual time series data of other channels.
[0091] Finally, the product of the irrelevance and difference corresponding to the target point is taken as the electromagnetic correlation eigenvalue of the target point. For example, the formula model of the electromagnetic correlation eigenvalue can be specifically as follows:
[0092]
[0093] in, Indicates the target point The electromagnetic correlation eigenvalue of Indicates the target point The corresponding The Pearson correlation coefficient calculated for each sequence group is Indicates the target point The total number of corresponding sequence groups, Represents the local distribution eigenvalue of the target point, Indicates the target point The corresponding In the sequence group, the target point Outliers with the same ordinal value The local distribution eigenvalue of Expressed as a natural constant An exponential function with base .
[0094] In the formula model of the electromagnetic correlation eigenvalue, the outliers in each residual time series data are first arranged in time series to obtain a sorted sequence. Then, the distribution characteristics of the outliers in the residual time series data between each channel are analyzed from an overall perspective, and the sorted sequence where the target point is located is aligned with the length of each remaining sorted sequence to obtain a sequence group, thereby analyzing the Pearson correlation coefficient between the local distribution eigenvalues of the two outlier sequences in the sequence group. Based on prior knowledge, it can be known that the closer the Pearson correlation coefficient is to 0, the less correlated the two sets of data are, and the more likely it is caused by electromagnetic interference. Therefore, in the embodiment of the present invention, the absolute value of the Pearson correlation coefficient calculated by the sequence group is calculated, and then the sum of the absolute values of the Pearson correlation coefficients corresponding to all sequence groups is negatively correlated and normalized to achieve logical relationship correction, and the degree of independence between the target point and the outliers in the residual time series data of other channels is obtained as one of the parameters for calculating the electromagnetic correlation eigenvalue. Then, we can analyze the similarity of the target point and the outliers in the residual time series data corresponding to other channels from the perspective of specific points. In each sequence group, we calculate the difference in the local distribution feature value between the target point and the outliers with the same sequence number value as the distribution difference value of the target point. The larger the distribution difference value, the greater the difference in the local distribution eigenvalues between outliers with the same sequence number in the sequence. This indicates that the similarity between the target point and the outliers at corresponding positions in the residual time series data of other signals is smaller. All distribution difference values of the target point are then accumulated to form the difference between the target point and the outliers in the residual time series data of other channels. The larger the difference, the lower the similarity, and the more likely the target point is to be caused by electromagnetic interference. Finally, the product of the target point's irrelevance and difference is used as the electromagnetic correlation eigenvalue of the target point. The larger the irrelevance and difference, the larger the electromagnetic correlation eigenvalue, and the greater the possibility that the outlier is caused by electromagnetic interference.
[0095] At this point, by comprehensively analyzing the outliers in the residual time series data of all channels, the electromagnetic correlation eigenvalue corresponding to each outlier is obtained. This can be combined with the electromagnetic attribute eigenvalue of the outlier to obtain an indicator for judging whether the outlier is caused by electromagnetic interference or is a network anomaly: the electromagnetic interference degree value.
[0096] Preferably, in one embodiment of the present invention, obtaining the electromagnetic interference degree value of the corresponding outlier point according to the electromagnetic attribute characteristic value and the electromagnetic correlation characteristic value of each outlier point includes:
[0097] Since the main purpose of the embodiment of the present invention is to distinguish truly abnormal outliers from outliers caused by electromagnetic interference, thereby avoiding misjudgment, and at the same time, the electromagnetic attribute characteristic value and electromagnetic correlation characteristic value of each outlier can both characterize the degree of electromagnetic interference of the outlier, the mean of the electromagnetic attribute characteristic value and electromagnetic correlation characteristic value of each outlier can be calculated and normalized to obtain the electromagnetic interference degree value of the corresponding outlier. The formula model of the electromagnetic interference degree value is:
[0098]
[0099] in, Indicates the The electromagnetic interference degree value of the outlier point, Indicates the The electromagnetic correlation eigenvalues of outliers, Indicates the The electromagnetic property eigenvalues of the outliers, Indicates normalization.
[0100] In the formula model of the electromagnetic interference degree value, the larger the electromagnetic attribute characteristic value of the outlier point and the larger the electromagnetic correlation characteristic value, the more likely the outlier point is caused by electromagnetic interference and is not a true abnormal point. Therefore, the electromagnetic attribute characteristic value and the electromagnetic correlation characteristic value of the outlier point are combined, and the product of the two is normalized as the electromagnetic interference degree value of the outlier point, which is used to characterize the degree of electromagnetic interference of the outlier point.
[0101] At this point, by analyzing the residual time series data corresponding to a single channel and combining it with the overall analysis of the residual time series data corresponding to multiple channels, the electromagnetic interference degree value of each outlier point is obtained based on the process, randomness, and mutual irrelevance of electromagnetic interference. In the subsequent process, this indicator can be used to distinguish outliers from network anomalies and outliers caused by electromagnetic interference, thereby improving the accuracy of the final safety detection.
[0102] Step S4: In each residual time series data, based on the electromagnetic interference degree values of all outliers, filter out the outliers affected by electromagnetic interference to obtain network anomalies.
[0103] After obtaining the electromagnetic interference degree value of each outlier, the outliers can be distinguished according to the electromagnetic interference degree value, thereby filtering out the outliers caused by electromagnetic interference. The remaining outliers are outliers caused by network attacks or other network risk factors, that is, network anomalies.
[0104] Preferably, in one embodiment of the present invention, in each residual time series data, residual points affected by electromagnetic interference are screened out according to the electromagnetic interference degree values of all outliers to obtain network anomalies, including:
[0105] Because a larger electromagnetic interference value indicates a greater impact on an outlier, outliers with electromagnetic interference values greater than or equal to the preset anomaly threshold are considered residual points affected by electromagnetic interference. These residual points affected by electromagnetic interference are then removed from all outliers, and the remaining outliers are considered network anomalies. The preset anomaly threshold can be set to 0.6, and the specific value can be adjusted based on the implementation scenario and is not limited here.
[0106] At this point, the outliers caused by electromagnetic interference can be excluded, and the remaining outliers are network anomalies caused by network attacks or other network risk factors. The embodiment of the present invention improves the detection accuracy of network anomalies, thereby ensuring the effect of security detection.
[0107] In summary, the present invention provides a data security detection method for signal transmission software, the main purpose of which is to accurately distinguish outliers caused by electromagnetic interference and network attacks during signal transmission, thereby improving the accuracy of network anomaly detection and ensuring the effect of security detection. First, the signal-to-noise ratio time series data of signal transmission in at least two channels is obtained, and then it is decomposed based on the time series algorithm to obtain residual time series data. Since electromagnetic interference has a process characteristic, which is specifically manifested in that the interference intensity changes from weak to strong and then from strong to weak, and the noise interference caused by network attacks or other dangerous network factors usually appears suddenly and does not have a process characteristic, electromagnetic interference will cause the residual points in the residual time series data to show certain trends and regularities. Therefore, in each residual time series data, the numerical distribution and change trend of each residual point can be analyzed to obtain outliers and trend characteristic values corresponding to the outliers, which can be used as one of the indicators to characterize that the outliers are caused by electromagnetic interference. Furthermore, due to the diversity of electromagnetic interference sources, the distribution of outliers affected by electromagnetic interference exhibits random characteristics. However, cyber attacks are human-caused, resulting in more concentrated distributions of outliers. Therefore, based on the concentration of the positional distribution between outliers, local distribution eigenvalues can be derived as another indicator of whether the outliers are caused by electromagnetic interference. These two indicators are then combined to obtain the electromagnetic property eigenvalues of the outliers, which characterize the degree of electromagnetic interference exposure. Furthermore, since analyzing only the data points in the residual time series data corresponding to a single channel is somewhat one-sided, and the interference intensity of electromagnetic interference varies across different channels, cyber attacks typically attack multiple channels simultaneously, resulting in more similar and correlated anomalies or noise. Therefore, based on this characteristic, the residual time series data corresponding to multiple channels is combined to analyze the similarities and correlations between the local distribution eigenvalues of the outliers in these data to obtain the electromagnetic correlation eigenvalues. Finally, the electromagnetic correlation eigenvalues and electromagnetic attribute eigenvalues are combined to obtain the electromagnetic interference degree value caused by electromagnetic interference for the evaluation outliers. Then, according to the electromagnetic interference degree value of the outliers, the outliers caused by electromagnetic interference can be removed to obtain network anomalies, thereby achieving accurate detection of network anomalies and ensuring the effect of safety detection.
[0108] It should be noted that the order in which the embodiments of the present invention are described above is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0109] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.
Claims
1. A data security detection method for signal transmission software, characterized in that: The method comprises: Acquire signal-to-noise ratio time series data during signal transmission in at least two channels; acquire residual time series data corresponding to each signal-to-noise ratio time series data based on a time series decomposition algorithm; In each residual time series data, outliers and trend attachment points of outliers are obtained based on the numerical distribution of each residual point; the trend characteristic value of the corresponding outlier is obtained based on the time and change trend of the trend attachment point corresponding to each outlier; the local distribution characteristic value of each outlier is obtained based on the position distribution concentration between all outliers; the electromagnetic property characteristic value of the corresponding outlier is obtained based on the numerical value, trend characteristic value, local distribution characteristic value of each outlier and the positional relationship between each outlier and the nearest residual point; In the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, the electromagnetic correlation eigenvalue corresponding to each outlier is obtained based on the correlation of the local distribution eigenvalues between all outliers; the electromagnetic interference degree value of the corresponding outlier is obtained based on the electromagnetic attribute eigenvalue and electromagnetic correlation eigenvalue of each outlier; In each residual time series data, according to the electromagnetic interference degree values of all outliers, the outliers affected by electromagnetic interference are screened out to obtain network anomalies.
2. A data security detection method for signal transmission software according to claim 1, characterized in that: The method of obtaining outliers and trend-attached points of outliers based on the numerical distribution of each residual point includes: Calculate the numerical mean and numerical standard deviation of all residual points, and determine the numerical fluctuation range based on the numerical mean and numerical standard deviation; The residual points whose values exceed the numerical fluctuation range are regarded as outliers; Obtain the extreme points in each residual time series data, and take all residual points between the previous and next extreme points in the time series of each outlier as trend attachment points of the corresponding outlier.
3. A data security detection method for signal transmission software according to claim 2, characterized in that: Determining the numerical fluctuation range according to the numerical mean and the numerical standard deviation includes: The difference between the numerical mean and the numerical standard deviation of the preset multiple is taken as the lower limit of the numerical fluctuation range, and the sum of the numerical mean and the numerical standard deviation of the preset multiple is taken as the upper limit of the numerical fluctuation range to obtain the numerical fluctuation range.
4. A data security detection method for signal transmission software according to claim 1, characterized in that: The residual time series data is a time series curve, and the trend characteristic value of the corresponding outlier is obtained according to the time and change trend of the trend attachment point corresponding to each outlier, including: The difference in time between each trend attachment point and the corresponding outlier point is taken as the time difference of the trend attachment point; In the time series curve corresponding to the residual time series data, the slope of each trend attachment point is calculated, and the ratio of the absolute value of the slope of each trend attachment point to the corresponding time difference is used as the trend factor; The normalized value of the mean of the trend factors corresponding to all trend attached points of each outlier is used as the trend characteristic value of the corresponding outlier.
5. The data security detection method for signal transmission software according to claim 1, characterized in that: The method of obtaining the local distribution characteristic value of each outlier point according to the position distribution concentration of all outliers includes: Obtaining the optimal K value for clustering all outliers based on the elbow method, performing cluster analysis on all outliers based on the K-means clustering algorithm and the optimal K value to obtain cluster clusters; Choose any outlier as the test point, and calculate the minimum Euclidean distance between each outlier and other outliers in the cluster where the test point is located, as the distance factor of the corresponding outlier; The value after negative correlation mapping of the total number of outliers in the cluster where the test point is located is used as the quantity factor; the sum of the distance factors of all outliers in the cluster where the test point is located and the product of the quantity factor are normalized to obtain the local distribution characteristic value corresponding to the test point.
6. A data security detection method for signal transmission software according to claim 2, characterized in that: The method of obtaining the electromagnetic property characteristic value of each outlier point according to its numerical value, trend characteristic value, local distribution characteristic value, and positional relationship with the nearest residual point includes: Calculate the difference between the value of each outlier point and the mean value to obtain the value difference; use the minimum Euclidean distance between each outlier point and other residual points as the distance parameter; The product of the numerical difference, distance parameter, trend characteristic value and local distribution characteristic value corresponding to each outlier point is normalized and used as the electromagnetic attribute characteristic value of the corresponding outlier point.
7. The data security detection method for signal transmission software according to claim 1, characterized in that: The electromagnetic correlation eigenvalue of each outlier is obtained based on the similarity and correlation of the local distribution eigenvalues between all outliers in the residual time series data corresponding to the signal-to-noise ratio time series data of all channels, including: In the residual time series data corresponding to the signal-to-noise ratio time series data of each channel, the outliers are arranged in time series to obtain a sorted sequence; An outlier point is selected as the target point, and the length of the sorted sequence where the target point is located is aligned with each of the remaining sorted sequences to obtain all sequence groups corresponding to the target point. The length alignment process is as follows: in the two sorted sequences, with the shortest sorted sequence as the benchmark, the outlier point with the largest time difference from the target point is continuously removed from the longest sorted sequence until the sequence length is the same as the shortest sorted sequence. The updated sequence is then obtained, and the updated sequence and the shortest sorted sequence are combined into a sequence group. In each sequence group corresponding to the target point, the Pearson correlation coefficient between the local distribution characteristic values of the outliers in the two sequences is calculated, and the difference in the local distribution characteristic values between the target point and the outliers with the same sequence number is calculated as the distribution difference value of the target point in the corresponding sequence group; The sum of the absolute values of the Pearson correlation coefficients calculated for all sequence groups corresponding to the target point is negatively correlated and normalized to obtain the degree of independence between the target point and the outliers in the residual time series data of other channels; the sum of all distribution difference values of the target point in all sequence groups is used as the degree of difference between the target point and the outliers in the residual time series data of other channels; The product of the irrelevance and difference corresponding to the target point is taken as the electromagnetic correlation eigenvalue of the target point.
8. The data security detection method for signal transmission software according to claim 1, characterized in that: The step of obtaining the electromagnetic interference degree value of the corresponding outlier point according to the electromagnetic attribute characteristic value and the electromagnetic correlation characteristic value of each outlier point includes: The normalized value of the mean of the electromagnetic attribute eigenvalue and the electromagnetic correlation eigenvalue of each outlier point is used as the electromagnetic interference degree value of the corresponding outlier point.
9. The data security detection method for signal transmission software according to claim 1, characterized in that: In each residual time series data, according to the electromagnetic interference degree values of all outliers, the residual points affected by electromagnetic interference are screened out to obtain network anomalies, including: The outliers corresponding to the electromagnetic interference degree values greater than or equal to the preset abnormal threshold are regarded as residual points affected by electromagnetic interference. Among all the outliers, the residual points affected by electromagnetic interference are removed, and the remaining outliers are network abnormal points.
10. The data security detection method for signal transmission software according to claim 1, characterized in that: The method of obtaining residual time series data corresponding to each signal-to-noise ratio time series data based on a time series decomposition algorithm includes: Based on the STL time series decomposition algorithm, each signal-to-noise ratio time series data is detrended and deperiodic to obtain a residual term, and corresponding residual time series data is obtained according to all residual points in the residual term.