Network security protection system and method

Through a network security protection system combining manual and automated analysis rules, it is possible to efficiently identify abnormal traffic, optimize data storage and transmission, solve the problems of low identification efficiency and insufficient data processing in the prior art, and improve network security and transmission efficiency.

CN120498846AInactive Publication Date: 2025-08-15JILIN INST OF ARCHITECTURE & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510814967.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing network security protection systems lack efficient and accurate abnormal traffic identification mechanism in network traffic analysis, the manual analysis is low efficiency and is susceptible to subjective factors, and the data storage and transmission links lack deep processing and optimization, which cannot meet network application scenarios with high real-time and security requirements.

Method used

The network protection analysis unit, data storage analysis unit and data transmission analysis unit are used to combine manual and automated analysis rules to identify potential hazards and generate early warnings, data equalization, deduplication compression and non-repetitive data replacement, and encode and bundled transmission based on the average transmission speed and parity of data capacity to generate transmission protection information.

Benefits of technology

It improves the timeliness and accuracy of abnormal traffic detection, reduces data redundancy, improves storage efficiency, enhances the security and efficiency of data transmission, and reduces the risks of data leakage and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498846A_ABST
    Figure CN120498846A_ABST
Patent Text Reader

Abstract

The invention discloses a network security protection system and method, relates to the technical field of network security, and solves the technical problems that in data storage and transmission links, data storage lacks deep processing and optimization of data, and a network application scene with relatively high requirements on real-time performance and security cannot be met. According to the invention, the data storage and analysis unit carries out equipartition processing, deduplication compression and unique non-duplicated data replacement processing on the obtained network data, data redundancy is effectively reduced, the storage efficiency is improved, the data transmission and analysis unit dynamically adjusts a data transmission strategy according to a real-time network condition, and the data transmission efficiency is improved. According to the method, the data are segmented and judged by taking the average value of the transmission speed as the standard, and the data are coded and bundled according to the parity of the data capacity to generate the transmission protection information, so that the transmission efficiency of the data in different network environments is improved, the security in the data transmission process is enhanced, and the risk of data leakage and tampering is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security protection system and method. Background Art

[0002] With the rapid development of network technology, network security threats are becoming increasingly complex and diverse.

[0003] Patent application publication number CN115549989A discloses a network security protection method, comprising: obtaining login parameters of a target user, and determining a first reliability value of the target user based on the login parameters; wherein the login parameters include an activity index and a login anomaly index; obtaining behavioral parameters of the target user, and determining a second reliability value of the target user based on the behavioral parameters; wherein the behavioral parameters include an operation index and a behavior anomaly index; determining security parameters of the target user based on the first and second reliability values, and determining the security value and security of the current network based on the security parameters. The present invention can dynamically adjust the security network protection level based on login information and operation information, thereby improving the security of network information while ensuring the stability of normal user operations.

[0004] However, some existing network security protection systems lack efficient and accurate abnormal traffic identification mechanisms in terms of network traffic analysis. Manual analysis is inefficient and easily affected by subjective factors, and the flexibility and adaptability of automated analysis rules are insufficient. In the data storage and transmission links, data storage lacks in-depth processing and optimization of data, and changes in the network environment are not fully considered during the transmission process. Data security and transmission efficiency are difficult to guarantee, and cannot meet network application scenarios with high real-time and security requirements. Summary of the Invention

[0005] In response to the shortcomings of the existing technology, the present invention provides a network security protection system and method, which solves the problem that data storage lacks in-depth processing and optimization of data in the data storage and transmission links, and cannot meet the network application scenarios with high real-time and security requirements.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a network security protection system, the system comprising:

[0007] The network protection analysis unit is used to determine whether there is a potential danger based on the real-time network traffic information transmitted by the network information collection unit, and generate a danger warning or normal monitoring signal, and transmit the normal monitoring signal to the data storage and analysis unit;

[0008] The data storage and analysis unit is used to analyze normal monitoring signals, obtain the corresponding network data and data capacity in different storage nodes, and evenly divide the data according to the data capacity to obtain network data segmentation packets, while extracting non-duplicate data and replacing it according to preset rules to generate replacement data, and then store it to generate storage information, and transmit it to the data transmission analysis unit;

[0009] The data transmission analysis unit is used to perform transmission analysis on the storage information, calculate the average network transmission speed within a time period, and use it as a standard to divide and judge the storage information to be transmitted, obtain equal information packets, obtain the equal information packets and the storage information to be transmitted and record them as information to be transmitted, and simultaneously perform binary conversion to obtain conversion information, and obtain conversion information with the same data capacity and record it as same-capacity conversion information, bundle the same-capacity conversion information in pairs to generate a bundled package, and perform different transmission protection methods according to the parity of the data capacity values of the same-capacity conversion information, generate transmission protection information, and transmit it to the security protection information output unit.

[0010] As a further solution of the present invention, the system further includes a network information collection unit and a security protection information output unit;

[0011] The network information collection unit is used to transmit the acquired real-time network traffic information to the network protection analysis unit;

[0012] The security protection information output unit is used to perform protection processing on the data during transmission according to the acquired transmission protection information.

[0013] As a further solution of the present invention, the network protection analysis unit generates a danger warning or normal monitoring signal in the following specific manner:

[0014] By using network traffic analysis tools to capture and analyze network data packets, you can view the header information, protocol content, load data, etc. of the data packets. Through manual or automated analysis rules, if there is a potential danger, a danger warning signal is generated, otherwise a normal monitoring signal is generated and transmitted to the data storage and analysis unit.

[0015] As a further solution of the present invention, the specific manner in which the data storage analysis unit analyzes the normal monitoring signal is:

[0016] All storage nodes in the network system are numbered i, and i = 1, 2…j, where j represents the number of storage nodes. A group of nodes are randomly selected as analysis objects, and the network data in the analysis objects are extracted, which are numbered n, and n = 1, 2…m, where m represents the amount of network data. The capacity Rn of each data is obtained and evenly divided to obtain network data segmentation packages. The data blocks are detected using a hash algorithm, and a single copy of the duplicate data is retained. An index is established, the duplicate data is compressed, and the non-duplicate data is replaced to obtain replacement data.

[0017] As a further solution of the present invention, the specific manner in which the data storage analysis unit performs replacement processing on non-duplicate data is:

[0018] Convert non-repetitive data into binary, obtain the data capacity and determine the parity. If the capacity is an odd number, extract 4 groups of odd bits in the binary number; if it is an even number, extract 4 groups of even bits to generate a replacement template. Use the replacement template to replace the original binary data to obtain the replacement data. After storage, generate storage information and transmit it to the security protection information output unit.

[0019] As a further solution of the present invention, the specific manner in which the data transmission analysis unit performs transmission analysis on the stored information is:

[0020] Obtain the storage information to be transmitted from the storage information, monitor the network speed with a time period of t, calculate the average of the maximum and minimum transmission speeds within the period, and obtain the average transmission speed, which is used as a standard to segment and judge the storage information to be transmitted;

[0021] If the data capacity of the stored information to be transmitted is greater than the average transmission speed, it will be divided equally according to the data capacity to obtain equally divided information packets. Otherwise, it means that no division is required.

[0022] As a further solution of the present invention, the specific manner in which the data transmission analysis unit generates the transmission protection information is as follows:

[0023] All equally divided information packets and stored information to be transmitted are uniformly recorded as information to be transmitted and labeled as o, where o = 1, 2, ..., p, where p represents the number of information to be transmitted. After converting to binary, conversion information is obtained. The information is grouped according to data capacity, and only conversion information with the same capacity is processed. Two of them are bundled into packets, and different processing is performed according to the parity of their data capacity values to generate transmission protection information.

[0024] As a further solution of the present invention, the data transmission analysis unit generates transmission protection information by performing different processing according to the parity of the data capacity value as follows:

[0025] If the data capacity value is an odd number, all odd-numbered binary digits are replaced and the positions of two sets of conversion information with the same capacity are swapped to generate a reassembled bundle and transmission protection information;

[0026] If the data capacity value is an even number, all even-digit binary numbers are replaced, and the two sets of conversion information with the same capacity are individually reversed as a whole to generate a recombined bundle, which is then transmitted to generate transmission protection information.

[0027] A network security protection method, the method specifically comprising the following steps:

[0028] Step S1: Collect and analyze real-time network traffic information to determine whether there is potential danger and generate a danger warning signal or a normal monitoring signal;

[0029] Step S2: Analyze the normal monitoring signals, obtain any group of storage nodes as the analysis object, and evenly divide the network data therein according to the data capacity to obtain network data segmentation packets, and replace the non-repeated data therein to obtain replacement data, and generate storage information;

[0030] Step S3: Perform transmission analysis on the obtained storage information, calculate the average network transmission speed within the time period, and use the average speed as a standard to divide and judge the transmission storage information to obtain evenly divided information packets;

[0031] Step S4: obtaining the equally divided information package and the storage information to be transmitted and recording them as information to be transmitted, and performing binary conversion to obtain conversion information, and obtaining conversion information with the same data capacity and recording them as same-capacity conversion information;

[0032] Step S5: Bundle the same capacity conversion information in pairs to generate a bundle package, and perform different transmission protection methods according to the parity of the data capacity values of the same capacity conversion information to generate transmission protection information.

[0033] The present invention provides a network security protection system and method. Compared with the existing technology, it has the following advantages:

[0034] By combining manual analysis with automated analysis rules and utilizing professional network traffic analysis tools, this invention can accurately capture and deeply analyze network data packets. It can not only detect common attack patterns, but also build traffic behavior models through machine learning algorithms, effectively identify new and hidden security threats, and improve the timeliness and accuracy of abnormal traffic detection.

[0035] The data storage and analysis unit of the present invention performs equal distribution, deduplication compression, and unique non-duplicate data replacement on the acquired network data, effectively reducing data redundancy, improving storage efficiency, and conserving storage resources. Furthermore, through in-depth data processing, the security and reliability of data storage are enhanced.

[0036] The data transmission analysis unit of the present invention dynamically adjusts the data transmission strategy according to the real-time network situation, divides and judges the data based on the average transmission speed, encodes and bundles the data for transmission according to the parity of the data capacity, and generates transmission protection information. This not only improves the data transmission efficiency in different network environments, but also enhances the security of the data transmission process and reduces the risk of data leakage and tampering. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 This is a block diagram of the system principle of the present invention;

[0038] Figure 2 It is a diagram of the steps of the present invention. DETAILED DESCRIPTION

[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0040] Example 1

[0041] See also Figure 1 The present application provides a network security protection system, which includes: a network information collection unit, a network protection analysis unit, a data storage analysis unit, a data transmission analysis unit and a security protection information output unit, and is combined with Figure 1 It can be known that the functional units are electrically connected in a unidirectional manner.

[0042] The network information collection unit is used to obtain real-time network traffic information, including content, flow direction, size and frequency of data packets, and transmit it to the network protection analysis unit.

[0043] The network protection analysis unit is used to determine whether there is a potential risk based on the real-time network traffic information obtained. The specific analysis method is as follows:

[0044] Use professional network traffic analysis tools, such as Wireshark and Tcpdump, to capture network data packets in real time by setting specific capture interfaces and filtering conditions. These tools, based on the network interface drivers provided by the operating system, can capture the raw data frames flowing through the network card. During the capture process, you can set filtering conditions such as capture start and end times, traffic direction (inbound / outbound), specific protocols (such as TCP, UDP, ICMP), or IP address ranges to precisely select the packets you need to analyze, avoiding the loss of analysis efficiency due to capturing too much useless data.

[0045] After the capture is complete, the tool's built-in decoding function allows you to deeply view the header information, protocol content, and payload data of the data packet. Taking TCP data packets as an example, the header information contains key fields such as source port, destination port, sequence number, confirmation number, flag bit, etc. These fields can reflect the establishment, transmission, and termination process of the connection. In terms of protocol content, the protocol specifications followed by the data packet can be clearly presented, such as the request method (GET, POST, etc.) in the HTTP protocol, URL path, HTTP version, and other information. The payload data carries the application layer data actually transmitted, such as web page content, email body, file data, etc.

[0046] A combination of manual analysis and automated analysis rules can effectively identify abnormal traffic patterns. Manual analysis relies on the experience of network security experts, who can use their expertise to discern anomalies from packet details. For example, if a packet contains a large number of malformed protocol fields, unusual port usage, or non-standard interaction procedures in a specific application protocol, it can be initially identified as a potential threat.

[0047] Automated analysis rules process and analyze captured data packets in batches based on pre-set logic and algorithms. For example, regular expressions are used to match specific strings in data packets to detect the presence of malicious code or sensitive information leaks. Statistical analysis monitors indicators such as the number of connections and data packets initiated by a specific source IP address per unit time. If a large number of SYN packets originating from the same source IP address are detected, with widely distributed destination ports exceeding normal thresholds, a SYNFlood attack may have occurred. Furthermore, machine learning algorithms can be used to construct behavioral models of normal traffic. When new traffic data deviates significantly from the model, an abnormality alert is automatically triggered.

[0048] Once a potential threat is detected, the system immediately generates a detailed warning signal containing key information such as the source and destination of the abnormal traffic, the protocols involved, and a description of the abnormal characteristics. It then promptly notifies relevant security personnel via a visual interface, email, or text message. If no potential threat is detected, a normal monitoring signal is generated and transmitted to the data storage and analysis unit.

[0049] a data storage and analysis unit, which is used to analyze the acquired normal monitoring signals, obtain all storage nodes in the network system, denoted by i, where i=1, 2, ..., j, where j represents the number of storage nodes, and obtain any group of storage nodes as an analysis object;

[0050] The network data in the analysis object is obtained and labeled as n, where n=1, 2, ..., m, and m represents the number of network data. At the same time, the data capacity corresponding to the network data n is obtained and recorded as Rn. The data is evenly divided according to the data capacity to obtain a network data segmentation package. Then, duplicate data in the network data segmentation package is obtained, and duplicate data and non-duplicate data are obtained. The segmentation package is deduplicated and compressed. Duplicate data blocks are detected by a hash algorithm. A single copy of the duplicate data is retained, and an index is established to point to the original data. Then, the non-duplicate data is replaced accordingly, and the specific replacement processing method is as follows:

[0051] The non-repetitive data is converted into binary form, and the data capacity corresponding to the non-repetitive data is obtained at the same time, and the parity of the numerical value corresponding to the data capacity is determined. Then, based on the corresponding numerical parity, the binary numbers corresponding to the odd or even bits in the four groups of converted non-repetitive data are obtained. For example, if the numerical value corresponding to the data capacity is an odd number, the odd-bit binary numbers in the converted non-repetitive data are obtained, and the number of obtained binary numbers is four, which are obtained in sequence from front to back. On the contrary, if it is an even number, the even-bit binary numbers are obtained, and the obtained binary numbers are used as the standard to generate a replacement template, and the replacement template is replaced at the same time. Specifically, the sum of the numerical values of the binary numbers of the replacement template is calculated. For example, if the four binary numbers obtained are 0111, the sum of their numerical values is calculated to be 3, and 0111 is further replaced with 3. Then, the replacement template and the converted non-repetitive data are replaced to obtain replacement data, which is stored at the same time to generate storage information, and then transmitted to the security protection information output unit.

[0052] A security protection information output unit is used to store data according to the generated storage information.

[0053] Example 2

[0054] As the second embodiment of the present invention, it is implemented on the basis of the first embodiment, and differs from the first embodiment in the following aspects:

[0055] The data storage analysis unit transmits the generated storage information to the data transmission analysis unit, and performs transmission analysis on the storage information through the data transmission analysis unit.

[0056] a data transmission analysis unit, which is used to perform transmission analysis on the acquired stored information, obtain the stored information to be transmitted in the stored information, where the stored information to be transmitted here refers to the stored information that needs to be transmitted in real time, and analyze the real-time network situation. Taking time t as a period, the unit obtains the maximum and minimum transmission values corresponding to the network transmission speed within the time period, calculates the sum of the two values and the average value, and then calculates the average transmission speed. Then, the unit uses the average transmission speed as a standard to segment and judge the stored information to be transmitted;

[0057] If the data capacity of the storage information to be transmitted is greater than the average transmission speed, it means that the storage information to be transmitted needs to be split and divided equally according to the data capacity to obtain equally divided information packets. On the contrary, if the data capacity of the storage information to be transmitted is less than the average transmission speed, it means that the storage information to be transmitted does not need to be split and is subjected to transmission analysis.

[0058] Obtain all equally divided information packets and stored information to be transmitted, record them as information to be transmitted, and label them as o, where o=1, 2, ..., p, where p represents the number of information to be transmitted. Simultaneously, perform binary conversion on the information to be transmitted o to obtain conversion information. Then, obtain the data capacity corresponding to the conversion information. The conversion information with the same data capacity is recorded as the same-capacity conversion information. The conversion information with different data capacities is not processed.

[0059] Then, all the conversion information with the same capacity is obtained and a bundle is generated for each of them. At the same time, the data capacity corresponding to the conversion information with the same capacity in the bundle is obtained and different processing is performed according to the parity of the data capacity value.

[0060] If the data capacity value is an odd number, all odd-numbered binary digits are replaced, and the binary replacement here specifically replaces 0 with 1 and 1 with 0, and at the same time, the positions of the two sets of identical capacity conversion information are reversed. Specifically, the two sets of identical capacity conversion information are reversed according to the corresponding labels. For example, if the two sets of identical capacity conversion information are numbered 12 and 16 respectively, 16 is ranked first and 12 is ranked second during the reversal. A reassembled bundle is generated and transmitted, and transmission protection information is generated.

[0061] If the data capacity value is an even number, all even-digit binary digits are replaced, and the two sets of conversion information with the same capacity are reversed as a whole. The reverse order here is to reverse the binary numbers in the two sets of conversion information with the same capacity as a whole. For example, if the original binary number is 010111001101, the binary number after reverse order is 101100111010. A reassembled bundle is generated and transmitted to generate transmission protection information.

[0062] Similarly, the conversion information with different data capacities are bundled in pairs to generate bundled packages. Similarly, the conversion information with the same capacity is processed to generate recombined bundled packages, which are then transmitted to generate transmission protection information.

[0063] The generated transmission protection information is then transmitted to the security protection information output unit.

[0064] A security protection information output unit is used to perform protection processing on the data during transmission according to the acquired transmission protection information.

[0065] Embodiment 3, as the third embodiment of the present invention, focuses on combining the implementation processes of embodiment 1 and embodiment 2.

[0066] Example 4

[0067] See also Figure 2 , this application provides a network security protection method, which specifically includes the following steps:

[0068] Step S1: collect real-time network traffic information and analyze it to determine whether there is potential danger, generate a danger warning signal or a normal monitoring signal, and the specific processing method is the same as the processing method of the network protection analysis unit in Example 1;

[0069] Step S2: Analyze the normal monitoring signal, obtain any group of storage nodes as the analysis object, and evenly divide the network data therein according to the data capacity to obtain network data segmentation packets. At the same time, replace the non-repeated data therein to obtain replacement data, and generate storage information. The processing method here is the same as the processing method of the data storage analysis unit in Example 1;

[0070] Step S3: Perform transmission analysis on the obtained storage information, calculate the average network transmission speed within the time period, and use the average network transmission speed as a standard to divide and judge the transmission storage information to obtain evenly divided information packets. The specific processing method is the same as that of the data transmission analysis unit in Example 2.

[0071] Step S4: Obtain the equally divided information packet and the storage information to be transmitted and record them as information to be transmitted, perform binary conversion to obtain conversion information, and obtain conversion information with the same data capacity and record them as same-capacity conversion information. The specific processing method is the same as that of the data transmission analysis unit in Example 2.

[0072] Step S5: Bundle the same capacity conversion information in pairs to generate a bundle package, and perform different transmission protection methods according to the parity of the data capacity values of the same capacity conversion information to generate transmission protection information. The specific processing method is the same as the processing method of the data transmission analysis unit in Example 2.

[0073] Some of the data in the above formulas are calculated based on their numerical values and are not substituted into parameter units for calculation. At the same time, the contents not described in detail in this specification belong to the existing technology known to those skilled in the art.

[0074] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A network security protection system, characterized in that: The system includes: The network protection analysis unit is used to determine whether there is a potential danger based on the real-time network traffic information transmitted by the network information collection unit, and generate a danger warning or normal monitoring signal, and transmit the normal monitoring signal to the data storage and analysis unit; The data storage and analysis unit is used to analyze normal monitoring signals, obtain the corresponding network data and data capacity in different storage nodes, and evenly divide the data according to the data capacity to obtain network data segmentation packets, while extracting non-duplicate data and replacing it according to preset rules to generate replacement data, and then store it to generate storage information, and transmit it to the data transmission analysis unit; The data transmission analysis unit is used to perform transmission analysis on the storage information, calculate the average network transmission speed within a time period, and use it as a standard to divide and judge the storage information to be transmitted, obtain equal information packets, obtain the equal information packets and the storage information to be transmitted and record them as information to be transmitted, and simultaneously perform binary conversion to obtain conversion information, and obtain conversion information with the same data capacity and record it as same-capacity conversion information, bundle the same-capacity conversion information in pairs to generate a bundled package, and perform different transmission protection methods according to the parity of the data capacity values of the same-capacity conversion information, generate transmission protection information, and transmit it to the security protection information output unit.

2. A network security protection system according to claim 1, characterized in that: The system also includes a network information collection unit and a security protection information output unit; The network information collection unit is used to transmit the acquired real-time network traffic information to the network protection analysis unit; The security protection information output unit is used to perform protection processing on the data during transmission according to the acquired transmission protection information.

3. A network security protection system according to claim 1, characterized in that: The specific method for the network protection analysis unit to generate a danger warning or normal monitoring signal is: By using network traffic analysis tools to capture and analyze network data packets, you can view the header information, protocol content, load data, etc. of the data packets. Through manual or automated analysis rules, if there is a potential danger, a danger warning signal is generated, otherwise a normal monitoring signal is generated and transmitted to the data storage and analysis unit.

4. A network security protection system according to claim 1, characterized in that: The specific method in which the data storage analysis unit analyzes the normal monitoring signal is as follows: All storage nodes in the network system are numbered i, and i = 1, 2…j, where j represents the number of storage nodes. A group of nodes are randomly selected as analysis objects, and the network data in the analysis objects are extracted, which are numbered n, and n = 1, 2…m, where m represents the amount of network data. The capacity Rn of each data is obtained and evenly divided to obtain network data segmentation packages. The data blocks are detected using a hash algorithm, and a single copy of the duplicate data is retained. An index is established, the duplicate data is compressed, and the non-duplicate data is replaced to obtain replacement data.

5. A network security protection system according to claim 4, characterized in that: The specific method in which the data storage analysis unit replaces the non-duplicate data is as follows: Convert non-repetitive data into binary, obtain the data capacity and determine the parity. If the capacity is an odd number, extract 4 groups of odd bits in the binary number; if it is an even number, extract 4 groups of even bits to generate a replacement template. Use the replacement template to replace the original binary data to obtain the replacement data. After storage, generate storage information and transmit it to the security protection information output unit.

6. A network security protection system according to claim 1, characterized in that: The specific manner in which the data transmission analysis unit performs transmission analysis on the stored information is as follows: Obtain the storage information to be transmitted from the storage information, monitor the network speed with a time period of t, calculate the average of the maximum and minimum transmission speeds within the period, and obtain the average transmission speed, which is used as a standard to segment and judge the storage information to be transmitted; If the data capacity of the stored information to be transmitted is greater than the average transmission speed, it will be divided equally according to the data capacity to obtain equally divided information packets. Otherwise, it means that no division is required.

7. A network security protection system according to claim 1, characterized in that: The specific manner in which the data transmission analysis unit generates the transmission protection information is as follows: All equally divided information packets and stored information to be transmitted are uniformly recorded as information to be transmitted and labeled as o, where o = 1, 2, ..., p, where p represents the number of information to be transmitted. After converting to binary, conversion information is obtained. The information is grouped according to data capacity, and only conversion information with the same capacity is processed. Two of them are bundled into packets, and different processing is performed according to the parity of their data capacity values to generate transmission protection information.

8. A network security protection system according to claim 7, characterized in that: The specific manner in which the data transmission analysis unit generates transmission protection information by performing different processing according to the parity of the data capacity value is as follows: If the data capacity value is an odd number, all odd-numbered binary digits are replaced and the positions of two sets of conversion information with the same capacity are swapped to generate a reassembled bundle and transmission protection information; If the data capacity value is an even number, all even-digit binary numbers are replaced, and the two sets of conversion information with the same capacity are individually reversed as a whole to generate a recombined bundle, which is then transmitted to generate transmission protection information.

9. A network security protection method, executed by a network security protection system according to any one of claims 1 to 8, characterized in that: The method specifically comprises the following steps: Step S1: Collect and analyze real-time network traffic information to determine whether there is potential danger and generate a danger warning signal or a normal monitoring signal; Step S2: Analyze the normal monitoring signals, obtain any group of storage nodes as the analysis object, and evenly divide the network data therein according to the data capacity to obtain network data segmentation packets, and replace the non-repeated data therein to obtain replacement data, and generate storage information; Step S3: Perform transmission analysis on the obtained storage information, calculate the average network transmission speed within the time period, and use the average speed as a standard to divide and judge the transmission storage information to obtain evenly divided information packets; Step S4: obtaining the equally divided information package and the storage information to be transmitted and recording them as information to be transmitted, and performing binary conversion to obtain conversion information, and obtaining conversion information with the same data capacity and recording them as same-capacity conversion information; Step S5: Bundle the same capacity conversion information in pairs to generate a bundle package, and perform different transmission protection methods according to the parity of the data capacity values of the same capacity conversion information to generate transmission protection information.

Citation Information

Patent Citations

  • Network security protection method and network security protection system thereof

    CN115549989A