Dynamic encryption network security management system based on federal learning
Through the dynamic encryption network security management system based on federated learning, network traffic data is collected and analyzed in real time, and personalized encryption strategies are generated, which solves the problem of insufficient intelligence and adaptability of traditional systems in dynamic environments and realizes efficient network security management.
Patent Information
- Application Number
- CN202510914134.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-07-03
AI Technical Summary
Traditional network security management systems are difficult to adapt to dynamically changing network environments and diverse attack methods. They lack intelligence and adaptability, resulting in insufficient detection and defense capabilities against new attacks and abnormal network behaviors. In addition, they consume a lot of computing and storage resources, affecting the system's response speed and stability.
A dynamic encryption network security management system based on federated learning is adopted. The network data acquisition module collects traffic and encryption status data in real time, and the federated learning processing module generates personalized encryption strategies. The security status monitoring module is combined to monitor abnormal data in real time. The policy matching module performs multi-dimensional matching. The policy adjustment module automatically adjusts the encryption strategy, and the encryption strategy is optimized through the policy self-learning module.
It enables the generation of personalized encryption strategies in a distributed environment without sharing original data, improves the intelligence and adaptability of the system, enables timely response to network security threats, and improves the response speed and accuracy and efficiency of policy adjustments.
Smart Images

Figure CN120602192A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security management, and in particular to a dynamic encryption network security management system based on federated learning. Background Art
[0002] With the rapid development of internet technology, network security issues are becoming increasingly severe. Threats such as data leaks and malicious attacks have caused significant losses to individuals, businesses, and society. Traditional network security management systems mostly rely on static encryption strategies, which are difficult to adapt to dynamically changing network environments and diverse attack vectors. Static encryption strategies are typically based on fixed security rules and preset encryption parameters. They cannot flexibly adjust to changes in real-time network traffic, encryption status, and security threats, resulting in insufficient detection and defense capabilities against new attacks and anomalous network behavior.
[0003] In a distributed network environment, traditional systems face challenges in data collection and processing. The dispersed storage of network traffic and encryption status data across different node devices makes efficient centralized analysis and management difficult, resulting in a lack of comprehensiveness and real-time security policy development and adjustments. Furthermore, traditional systems consume significant computing and storage resources when processing large amounts of data, leading to performance bottlenecks that impact system responsiveness and stability.
[0004] Existing encryption policy adjustment mechanisms often lack intelligence and adaptability. When the network environment changes, administrators need to manually adjust encryption policies. This not only consumes considerable time and effort but is also prone to human error, resulting in a mismatch between security policies and actual needs. Furthermore, traditional systems struggle to monitor and evaluate the effectiveness of encryption policies in real time, making it difficult to identify loopholes and deficiencies in policies, further reducing the efficiency and reliability of network security management.
[0005] Federated learning, an emerging machine learning technology, offers new solutions for model training and policy optimization in distributed data scenarios. However, research on its application in network security management is still in its infancy. Using federated learning to generate, adjust, and optimize dynamic encryption policies, and thus enhance the intelligence and adaptability of network security management systems, remains a pressing technical challenge. Summary of the Invention
[0006] The purpose of the present invention is to provide a dynamic encrypted network security management system based on federated learning to solve the problems raised in the above background technology.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a dynamic encrypted network security management system based on federated learning, the system comprising:
[0008] The network data acquisition module is used to collect network traffic data and encryption status data in real time through distributed node devices, analyze and process them to generate traffic characteristic values and encryption dynamic parameter characteristic values, and generate a dynamic adjustment set of encryption policies based on the initial encryption policy set stored in the security policy database;
[0009] The federated learning processing module obtains personalized encryption strategies for the current network environment and generates dynamic security control strategies based on traffic feature values.
[0010] The security status monitoring module is used to obtain real-time security status data during network communication through encrypted sensors, filter out abnormal security data that meets the dynamic adjustment range, and send it to the policy matching module;
[0011] The policy matching module is used to perform multi-dimensional matching between abnormal security data and each policy item in the encryption policy dynamic adjustment set, generate the matching degree between real-time data and each encryption policy item, and select the encryption policy corresponding to the highest matching degree as the target adjustment policy;
[0012] The policy adjustment module is used to receive the target adjustment policy and call the policy adjustment protocol preset in the security policy database to drive the encryption engine to perform encryption policy correction operations.
[0013] Preferably, the real-time collection of network traffic data and encryption status data by distributed node devices is carried out in the following specific process:
[0014] Identify the unique identification code of the distributed node. If it is a newly accessed node, collect basic network parameters including initial traffic density, encryption strength baseline value, and delay control range, establish a security feature node based on the initial data, perform parameter calibration, and generate traffic feature values;
[0015] If it is a historical access node, the historical network data set and security status change curve of the node are extracted. The historical network data set includes traffic fluctuation extremes, encryption deviation records and delay control delay duration, and is marked as the initial parameter set for the current security analysis.
[0016] Preferably, generating the encryption policy dynamic adjustment set based on the initial encryption policy set stored in the security policy database specifically includes:
[0017] Extracting an initial standard set and a dynamic correction coefficient set for each encryption policy from a security policy database, wherein the initial standard set includes: a traffic density safety range, an encryption strength fluctuation tolerance range, and a delay adjustment reference value;
[0018] The dynamic correction coefficient set includes a traffic density compensation coefficient, an encryption strength gradient adjustment coefficient, and a delay response weight parameter;
[0019] Based on the real-time encryption dynamic parameter characteristic value, dynamically adjust the initial standard set of each encryption policy, and record the adjusted policy set as the encryption policy dynamic adjustment set;
[0020] The encryption policy dynamic adjustment set includes the traffic dynamic range, encryption strength adaptability threshold and delay optimization control value of each policy item.
[0021] Preferably, the processing based on the traffic characteristic value to obtain a personalized encryption strategy for the current network environment and generate a dynamic security control strategy specifically includes:
[0022] According to the traffic characteristic value and the preset security policy characteristic library, the encryption policy adjustment priority sequence is determined;
[0023] An adaptive control strategy including strategy triggering conditions, adjustment step rules and fault handling mechanism is generated based on the adjustment priority sequence.
[0024] Preferably, the acquiring of real-time security status data during network communication by means of an encryption sensor specifically includes:
[0025] Real-time sensor data streams monitoring the implementation of the encryption process, including encryption key changes, security uniformity indicators, and latency fluctuations;
[0026] When the real-time sensor data stream exceeds the preset qualified safety range, the abnormal flag is activated and the safety data of the abnormal period is extracted as effective monitoring data.
[0027] Preferably, the matching degree between the generated real-time data and each encryption policy item specifically includes:
[0028] Analyze the key deviation, uniformity gradient, and delay fluctuation amplitude in abnormal security data, and perform differential calculations with the traffic dynamic range, encryption strength adaptability threshold, and delay optimization control value of each encryption strategy;
[0029] Based on the difference calculation results, a matching index between real-time data and each encryption policy item is generated.
[0030] Preferably, the step of selecting the encryption strategy corresponding to the highest matching degree as the target adjustment strategy specifically includes:
[0031] Create a list of encryption policy items ranked by their matching degree, and select the policy item with the highest matching degree in the list;
[0032] If the first matching degree is lower than the preset adjustment trigger threshold, the backup strategy set is called and the matching degree is recalculated.
[0033] Preferably, the matching index between the real-time data and each encryption policy item is generated based on the difference calculation result, and the specific processing process is as follows:
[0034] A multi-dimensional matching algorithm is used to normalize traffic differences, encryption strength gradients, and delay deviations to generate an encryption policy matching degree value ranging from 0 to 100.
[0035] The closer the matching value is to 100, the stronger the adaptability of the real-time data to the encryption policy.
[0036] Preferably, the strategy self-learning module specifically includes:
[0037] Record security status feedback data after each policy adjustment, including actual key uniformity, security strength changes, and delay control effects;
[0038] The feedback data is reversely verified with the dynamic adjustment set of the encryption policy to generate a policy correction factor and update the dynamic correction coefficient set to the security policy database.
[0039] Preferably, the generation strategy correction factor specifically includes:
[0040] Based on the degree of deviation between the feedback data and the expected security target, the traffic compensation factor, encryption strength adjustment factor, and delay optimization weight are calculated;
[0041] The exponentially weighted average algorithm is used to dynamically smooth the historical correction factors to generate a new set of dynamic correction coefficients.
[0042] Compared with the prior art, the present invention has the following beneficial effects:
[0043] In terms of data collection and processing, the network data collection module collects network traffic and encryption status data in real time through distributed node devices, applying different processing methods for newly connected nodes and those with historical access. For new nodes, basic network parameters are collected and security feature nodes are established for parameter calibration to ensure the accuracy and reliability of initial data. For historical nodes, historical network datasets and security status change curves are extracted to provide rich historical data support for subsequent security analysis. This differentiated data collection and processing approach enables comprehensive and accurate acquisition of network status information, laying a solid foundation for the development of dynamic encryption strategies.
[0044] The federated learning processing module determines the encryption policy adjustment priority sequence based on traffic signatures through pattern matching against a pre-set security policy signature library. It then generates an adaptive control strategy that includes policy trigger conditions, adjustment step rules, and troubleshooting mechanisms. The application of federated learning technology enables the system to train and update models in a distributed data environment without sharing raw data. This protects data privacy while improving the intelligence and adaptability of policy generation. It can generate personalized encryption policies in real time based on changes in the current network environment, effectively addressing dynamically changing security threats.
[0045] The Security Status Monitoring Module uses encryption sensors to acquire real-time security status data during network communications. It promptly identifies abnormal data that exceeds the preset security range and sends this information to the Policy Matching Module. This real-time monitoring mechanism ensures the system can quickly detect security anomalies in the network, providing a basis for timely adjustments to encryption policies and improving the system's responsiveness and real-time performance.
[0046] The policy matching module uses a multi-dimensional matching algorithm to calculate the difference between abnormal security data and each policy item in the dynamic encryption policy adjustment set, perform normalization processing, generate a matching index, and select the encryption policy with the highest matching score as the target adjustment policy. This multi-dimensional matching approach ensures the accuracy and scientific nature of policy adjustments, selecting the most appropriate encryption policy based on the specific characteristics of abnormal data, and improving the relevance and effectiveness of policy adjustments.
[0047] After receiving the target policy, the policy adjustment module invokes a pre-defined policy adjustment protocol to drive the encryption engine to perform the correction, thus dynamically adjusting the encryption policy. This automated policy adjustment mechanism avoids the delays and errors associated with human intervention, improves the efficiency and reliability of policy adjustments, and enables timely response to evolving network security threats.
[0048] The policy self-learning module records security status feedback after policy adjustments and back-verifies it against the dynamic encryption policy adjustment set to generate policy correction factors and update the dynamic correction coefficient set. This self-learning mechanism enables the system to continuously optimize encryption policies based on actual operational results, forming a closed-loop feedback loop that continuously improves the system's security protection capabilities and adaptability, enabling the system to evolve over the long term and better address increasingly complex network security challenges. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 This is a working principle diagram of the dynamic encryption network security management system based on federated learning described in the present invention;
[0050] Figure 2 A design diagram for the data collection process of distributed node devices;
[0051] Figure 3 Design diagrams for real-time security status data acquisition;
[0052] Figure 4 Design graph generated for encryption policy item matching;
[0053] Figure 5 Design diagram selected for the target adjustment strategy. DETAILED DESCRIPTION
[0054] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0055] See also Figure 1-Figure 5 The present invention relates to a dynamic encrypted network security management system based on federated learning. The system includes: a network data acquisition module, a federated learning processing module, a security status monitoring module, a policy matching module, and a policy adjustment module. Specifically, the system includes the following steps:
[0056] The network data acquisition module collects network traffic data and encryption status data in real time through distributed node devices, analyzes and processes them to generate traffic characteristic values and encryption dynamic parameter characteristic values, and generates a dynamic adjustment set of encryption policies based on the initial encryption policy set stored in the security policy database. The federated learning processing module processes the traffic characteristic values to obtain personalized encryption policies for the current network environment and generates dynamic security control policies. The security status monitoring module obtains real-time security status data during network communications through encryption sensors, filters out abnormal security data that falls within the dynamic adjustment range, and sends it to the policy matching module. The policy matching module performs a multi-dimensional match between abnormal security data and each policy item in the dynamic adjustment set of encryption policies, generates a matching degree between the real-time data and each encryption policy item, and selects the encryption policy with the highest matching degree as the target adjustment policy. The policy adjustment module receives the target adjustment policy and invokes the policy adjustment protocol preset in the security policy database to drive the encryption engine to perform encryption policy correction operations.
[0057] Example 1:
[0058] In this embodiment, the network data acquisition module of the system collects network traffic data and encryption status data in real time through distributed node devices. The specific process is as follows: the module will identify the unique identification code of the distributed node to determine whether the node is a new access node or a historical access node.
[0059] When a new access node is identified, the module begins collecting basic network parameters, including initial traffic density, encryption strength baseline, and latency control range. After collecting these basic parameters, a security signature node is established based on the initially acquired data. During the security signature node establishment process, the collected parameters are carefully analyzed and processed to ensure that the node accurately reflects the initial security characteristics of the new access node. After the security signature node is established, parameter calibration is performed to eliminate potential errors in the acquisition process and ensure more accurate and reliable parameters. After parameter calibration, traffic signature values are generated, which serve as an important basis for subsequent processing.
[0060] The module handles historical access nodes differently. It extracts the node's historical network dataset and security status change curve. The historical network dataset covers several key aspects, including traffic fluctuation extremes, which reflect the maximum and minimum traffic fluctuations during the node's historical operation; encryption deviation records, which help understand the deviations that occurred during the node's encryption process; and delay control delay duration, which reflects the node's performance in delay control. Meanwhile, the security status change curve intuitively displays the changing trend of the node's security status over the historical time period. After extracting this data, the module marks it as the initial parameter set for the current security analysis, providing a foundation for subsequent security analysis of the historical node.
[0061] Throughout the data collection process, strict procedures and requirements are in place for handling new and historical access nodes. For the initial data collection of new access nodes, every step requires precise operation. When identifying the unique identification code, accuracy must be ensured to avoid deviations in subsequent processing due to incorrect identification of the code. When collecting basic network parameters, the integrity and authenticity of the parameters must be guaranteed, and no important parameter information must be omitted. When establishing security feature nodes, various factors must be comprehensively considered to ensure that the nodes can fully and accurately represent the characteristics of the new access node. During parameter calibration, scientific and rational methods must be used to carefully adjust the parameters to improve their accuracy.
[0062] Extracting historical access node data also requires rigorous attention. Ensure comprehensive and accurate acquisition of historical network datasets and security status change curves. When extracting data such as traffic fluctuation extremes, encryption deviation records, and latency control delay duration, ensure data accuracy and reliability. The quality of this data directly impacts the results of current security analysis. When labeling initial parameter sets, ensure clarity and unambiguity to facilitate subsequent use and management.
[0063] Through this differentiated processing approach for new and existing nodes, the network data collection module can effectively acquire accurate and comprehensive network traffic and encryption status data. This data provides a solid foundation for subsequent dynamic encryption policy adjustment set generation, personalized encryption policy processing, and security status monitoring, ensuring that the entire system can operate and make decisions based on reliable data, thereby achieving effective network security management and dynamic encryption adjustments. This processing approach fully considers the characteristics of different nodes. New nodes focus on establishing initial features and calibrating parameters, while historical nodes use their historical data to more accurately analyze the current status, making data collection more scientific and reasonable, and better able to adapt to the complexity and dynamic nature of the network environment. In actual applications, the module will continuously identify and collect data from distributed nodes, updating data in real time to ensure that the system can promptly respond to various changes that may occur in the network and ensure the effectiveness and real-time nature of network security management.
[0064] Example 2:
[0065] In this embodiment, the network data acquisition module generates a dynamic encryption policy adjustment set based on the initial encryption policy set stored in the security policy database. The specific implementation is as follows: When executing the generation operation, the module first accesses the security policy database and extracts the initial standard set and dynamic correction coefficient set corresponding to each encryption policy from the database. The initial standard set includes three core parameters: a traffic density safety range, an encryption strength fluctuation tolerance interval, and a delay adjustment baseline value. These parameters are pre-set encryption policy basic standards and are used to define the reasonable range of various indicators under normal encryption conditions. The dynamic correction coefficient set includes a traffic density compensation coefficient, an encryption strength gradient adjustment coefficient, and a delay response weight parameter. These coefficients and parameters are used to dynamically adjust the initial standard set to adapt to the ever-changing network environment.
[0066] After completing the extraction of the initial standard set and the dynamic correction coefficient set, the module needs to dynamically adjust the initial standard set of each encryption strategy based on the encryption dynamic parameter characteristic values collected in real time. The real-time encryption dynamic parameter characteristic values are collected and analyzed in real time by the network data acquisition module through distributed node devices, reflecting the encryption status parameter characteristics under the current network environment. During the adjustment process, the module will calculate each parameter in the initial standard set in combination with the corresponding dynamic correction coefficient. For example, for the traffic density safety range, the module will adjust it based on the traffic-related characteristics in the real-time encryption dynamic parameter characteristic values using the traffic density compensation coefficient to determine the currently applicable traffic dynamic range; for the encryption strength fluctuation tolerance interval, it will be corrected based on the real-time characteristics related to the encryption strength through the encryption strength gradient adjustment coefficient to obtain the encryption strength adaptability threshold; for the delay adjustment baseline value, it will also be combined with the real-time parameter characteristics related to the delay, and adjusted with the help of the delay response weight parameter to generate the delay optimization control value.
[0067] When extracting data from the security policy database, the module must adhere to a strict data extraction process to ensure the accuracy of the initial standard set and dynamic correction coefficient set. This requires the database access interface to have reliable authentication mechanisms and data validation capabilities to prevent errors or data loss during the data extraction process. Furthermore, during the extraction process, the extracted data must undergo format verification and integrity checks to ensure that the format of each parameter meets system requirements and that no critical data is missing.
[0068] When making adjustments based on the eigenvalues of real-time encryption dynamic parameters, the module needs to adopt scientific and reasonable adjustment algorithms and logic. First, the eigenvalues of real-time encryption dynamic parameters must be preprocessed to remove any noise data and outliers that may exist, to ensure that the data used as the basis for adjustment is accurate and reliable. Then, based on the characteristics of different parameters and the properties of the dynamic correction coefficients, corresponding adjustment rules are designed. For example, when adjusting the traffic density safety range, it is necessary to consider factors such as the actual traffic load of the current network, historical traffic data, and the characteristics of the network services, and reasonably use the traffic density compensation coefficient to make adjustments so that the adjusted traffic dynamic range can not only meet the current network traffic needs, but also ensure the security and stability of the network.
[0069] After the adjustment is complete, the module integrates the adjusted policy parameters into a dynamic encryption policy adjustment set. This set includes the traffic dynamic range, encryption strength adaptability threshold, and latency optimization control value for each policy item. These parameters serve as an important basis for the subsequent federated learning processing module to generate personalized encryption policies and dynamic security control policies. They also serve as a key reference for the policy matching module to match abnormal security data.
[0070] Throughout the process of generating dynamic encryption policy adjustment sets, data real-time and accuracy are crucial. To ensure real-time data, the network data acquisition module must continuously collect and update dynamic encryption parameter characteristic values and promptly transmit them to the module responsible for generating dynamic encryption policy adjustment sets. To ensure data accuracy, in addition to rigorous validation during data collection and extraction, multiple data verification and corrections are also required during the adjustment process to prevent data errors from causing the generated dynamic encryption policy adjustment set to fail to meet actual requirements.
[0071] Furthermore, the generation of the dynamic encryption policy adjustment set must also consider the dynamic nature of the network environment. Factors such as network traffic and encryption requirements can change at any time. Therefore, the module must be able to respond to these changes in real time and promptly update the dynamic encryption policy adjustment set based on the latest dynamic encryption parameter values. This ensures that the system consistently uses the encryption policy most appropriate for the current network environment, effectively improving network security and stability.
[0072] This implementation method extracts initial parameters and correction coefficients from the security policy database, dynamically adjusts them in combination with the real-time encryption dynamic parameter characteristic values, and ultimately generates a dynamic adjustment set of encryption policies, providing a policy basis for dynamic adaptation to the current network environment for subsequent operations of the entire system. This approach makes full use of pre-set standards and dynamic correction mechanisms, which not only ensures the basic framework and security requirements of the policy, but also allows for flexible adjustments based on real-time conditions, enabling the system to better cope with complex and changing network security environments. In actual applications, the module will continue to run, constantly updating the dynamic adjustment set of encryption policies based on real-time data, ensuring that the system's encryption policy is always in the optimal state, thereby achieving effective management and protection of network security.
[0073] Example 3:
[0074] In this embodiment, the federated learning processing module processes traffic feature values to derive a personalized encryption policy for the current network environment and generates a dynamic security control policy. The specific implementation is as follows: After receiving the traffic feature values generated by the network data acquisition module, the module performs pattern matching against a pre-set security policy feature library. The security policy feature library stores a variety of policy feature patterns pre-set based on historical data and security requirements. These patterns correspond to different network traffic conditions and encryption policy adjustment directions.
[0075] During the pattern matching process, the module decomposes traffic feature values into characteristic parameters of multiple dimensions, such as the time distribution characteristics of traffic, the variation characteristics of traffic volume, and the composition characteristics of traffic types. These characteristic parameters are then compared one by one with the corresponding dimensions of each policy feature pattern in the security policy feature library, and the similarity between the two is calculated. Here, a similarity calculation function is used to quantify the degree of match between traffic feature values and each policy feature pattern. The expression of the similarity calculation function is:
[0076]
[0077] Among them, S represents the overall similarity between the traffic feature value and a certain strategy feature pattern; n is the number of feature dimensions; w i is the weight of the i-th feature dimension, which ranges from 0 to 1 and reflects the importance of the feature dimension in the overall matching; sim i (f i ,p i ) is the traffic characteristic parameter f under the i-th characteristic dimension i Parameter p corresponding to the strategy characteristic pattern i The similarity value is also calculated between 0 and 1.
[0078] In determining the weight w of each feature dimension i When adjusting encryption policies, the module comprehensively considers the actual needs of network security and the impact of each feature dimension on encryption policy adjustments. Feature dimensions with a greater impact on network security, such as the proportion of abnormal traffic, are given a higher weight; while feature dimensions with a relatively smaller impact, such as the time distribution of normal traffic, are given a lower weight.
[0079] After calculating similarity, the module determines the encryption policy adjustment priority sequence based on the similarity values. The priority sequence is arranged from high to low similarity. Policy feature patterns with higher similarity scores have higher encryption policy adjustment priorities. This means that the encryption policy adjustment direction corresponding to these policy feature patterns is more consistent with the current network traffic characteristics and should be given priority.
[0080] After determining the encryption policy adjustment priority sequence, the module generates a dynamic security control policy based on the sequence. The dynamic security control policy consists of three main parts: policy trigger conditions, adjustment step rules, and fault handling mechanism.
[0081] Policy trigger conditions are associated with each policy's characteristic pattern in the priority sequence. When the similarity between network traffic characteristics and a particular policy's characteristic pattern reaches or exceeds the preset trigger threshold, the corresponding encryption policy adjustment trigger condition is activated. The trigger threshold should be appropriately determined based on actual network security conditions and historical experience. It's important to avoid overly restrictive trigger conditions, which can prevent timely policy adjustments, while also preventing overly loose conditions, which can lead to frequent and unnecessary policy adjustments.
[0082] Adjustment step rules define the specific adjustment steps the system must perform after triggering a corresponding encryption policy adjustment. These steps include selecting the encryption algorithm, updating the encryption key, and adjusting the encryption strength. Adjustment step rules must be designed to adhere to the principles of security, efficiency, and stability, ensuring that each adjustment step is executed accurately and without significantly impacting network operations.
[0083] The fault handling mechanism is designed to address anomalies that may arise during policy adjustments. For example, during encryption policy adjustments, adjustments may fail or network performance may degrade significantly. The fault handling mechanism specifies emergency measures to be taken in these situations, such as rolling back to the previous encryption policy or initiating a backup encryption policy, to ensure that network security and stability are not seriously affected.
[0084] When generating dynamic security control policies, the module must fully consider the dynamic variability and uncertainty of the network environment. Network traffic can fluctuate significantly over a short period of time, so the generated dynamic security control policies need to be flexible and adaptable, allowing for adjustments and optimization based on real-time traffic characteristics.
[0085] The module also needs to verify the rationality of the generated dynamic security control policy. This verification process includes checking whether the policy trigger conditions are reasonable, whether the adjustment steps and rules are complete and feasible, and whether the fault handling mechanism is effective. This rationality verification can promptly identify and correct policy issues, thereby improving the reliability and effectiveness of the policy.
[0086] The federated learning processing module also uses the characteristics of federated learning to continuously optimize the weights w in the security policy feature library and the similarity calculation function. i By collecting learning data from multiple distributed nodes, the security policy feature library is updated and expanded without leaking the privacy data of each node, making the policy feature patterns in the library richer and more accurate. At the same time, the weights of each feature dimension are adjusted to make it more in line with the actual needs of current network security, thereby improving the accuracy of pattern matching and the effectiveness of dynamic security control strategies.
[0087] The entire process, from receiving traffic signatures and matching them against the security policy signature database to determining the priority sequence for encryption policy adjustments and generating dynamic security control policies, is closely interconnected and mutually influential. The module must precisely execute each step to ensure that the generated personalized encryption and dynamic security control policies accurately adapt to the current network environment and provide effective network security.
[0088] Example 4:
[0089] In this embodiment, the security status monitoring module uses encryption sensors to obtain real-time security status data during network communications. The specific implementation is as follows: During network communications, the module continuously monitors the real-time sensor data streams of the encryption process using encryption sensors deployed in network nodes or communication links. These data streams contain parameters from multiple key dimensions, such as the encryption key change value, which reflects the dynamic changes in the encryption key during the encryption process and is a key indicator of encryption security; the security uniformity index, which indicates the uniform distribution of encrypted data at the security level and directly affects the overall effectiveness of encryption; and the delay fluctuation value, which reflects the variation in delay during network communications. Excessive delay fluctuation can affect the normal use of the network and the effective implementation of security policies.
[0090] For example, when data is transmitted between a server and a terminal device within an enterprise's local area network, encryption sensors collect real-time data on encryption key changes, security uniformity, and latency fluctuations. For example, if a server sends an encrypted business document to a terminal at a specific moment, the encryption sensors continuously capture relevant data flow parameters at each stage of the data transmission: encryption, transmission, and decryption.
[0091] During the monitoring process, the module will compare the sensor data stream collected in real time with the preset qualified security range. The preset qualified security range is pre-set based on network security requirements and historical data, and is used to define the reasonable range of various parameters under normal security conditions. For example, for the encryption key change value, the preset qualified security range may stipulate that the key change amplitude per unit time cannot exceed a certain value to avoid the key changing too frequently or too slowly and affecting the encryption security; for the security uniformity index, a minimum threshold may be set. When the index is lower than the threshold, it means that the encrypted data security distribution is not uniform enough and there may be security risks; for the delay fluctuation value, there will also be corresponding range restrictions to ensure that the network communication delay fluctuates within an acceptable range.
[0092] If any parameter in a real-time sensor data stream exceeds a pre-defined acceptable safety range, the module immediately activates an anomaly flag. This can be achieved by logging the anomaly in the system log or sending an alert notification to the administrator. For example, in the aforementioned enterprise LAN example, if the encryption sensor detects that the security uniformity indicator during transmission suddenly drops below a pre-defined minimum threshold, the module will quickly activate an anomaly flag, indicating a possible anomaly in the current encryption status.
[0093] After activating the anomaly flag, the module extracts security data from the anomaly period as valid monitoring data. The determination of the anomaly period requires a comprehensive consideration of both the timing and duration of the parameter out-of-range. For example, all security data from the moment the security uniformity index falls below the threshold until it returns to within the acceptable range will be extracted. During this extraction process, the module ensures the integrity and accuracy of the data, including changes in encryption keys, specific values of the security uniformity index, and changes in latency fluctuation values during the anomaly period.
[0094] In practical applications, the deployment location of encryption sensors needs to be carefully planned based on the network topology and security requirements. For example, in an enterprise network, encryption sensors can be deployed at key nodes such as core switches, edge routers, and servers to comprehensively monitor the status of encrypted communications within the network. Furthermore, to ensure that encryption sensors accurately capture the required data streams, regular maintenance and calibration are required to check their proper operation and the accuracy of the collected data.
[0095] Furthermore, the preset safety range is not fixed; the module regularly adjusts and optimizes it based on changes in the network environment and analysis of historical anomaly data. For example, if latency fluctuations frequently exceed the preset range over a period of time, and analysis reveals that this is due to insufficient network bandwidth, the module will adjust the safety range to better reflect current network conditions, avoiding the inadvertent activation of anomaly flags due to improper range settings.
[0096] The Security Status Monitoring Module, through a series of operations including continuous monitoring, comparative analysis, anomaly tagging, and valid data extraction, promptly detects security anomalies during network communications and provides accurate anomaly security data to the subsequent Policy Matching Module. This effective monitoring data serves as a crucial basis for the Policy Matching Module's multi-dimensional matching and target adjustment strategy generation, enabling the system to promptly adjust encryption policies and ensure secure network operation.
[0097] For example, during online transactions on a financial institution's network, encryption sensors monitor the encryption status of transactions in real time. If latency fluctuations suddenly increase and exceed a preset range during peak trading hours, the module activates an anomaly flag and extracts relevant security data from that peak period. This data is then sent to the policy matching module, which matches the anomaly data with the corresponding encryption policy and adjusts the encryption method during the transaction to minimize the impact of latency fluctuations and ensure a secure and smooth transaction.
[0098] Example 5:
[0099] In this embodiment, the policy matching module generates the matching degree between real-time data and each encryption policy item and selects the target adjustment policy. At the same time, the system implements policy optimization through the policy self-learning module. The specific implementation method is as follows:
[0100] For example, in the online transaction system of an e-commerce platform, after the security status monitoring module extracts security data from abnormal periods, the policy matching module analyzes this data. For example, during a promotional event, the system detected an anomaly in the encrypted communication of the payment interface. The abnormal security data extracted by the security status monitoring module included a key deviation of 0.35, a uniformity gradient of 0.28, and a latency fluctuation of 150ms. At this point, the policy matching module needs to perform a multi-dimensional match between this data and the various policy items in the dynamic encryption policy adjustment set.
[0101] First, the module parses various parameters in the anomalous security data. For the key deviation in the example above, it's important to clarify the degree of deviation from the standard key parameters; the uniformity gradient reflects the rate of change in the encrypted data's security distribution; and the latency fluctuation range represents the difference between the actual latency and the typical latency. After parsing, the module calculates the difference between these parameters and the traffic dynamic range, encryption strength adaptability threshold, and latency optimization control value for each encryption policy item. For example, the traffic dynamic range for a particular encryption policy item corresponds to the standard range for processing payment interface traffic, the encryption strength adaptability threshold is the upper limit of 0.4 for key deviation, and the latency optimization control value is the upper limit of 180ms for latency fluctuation under normal transaction scenarios. Calculations show that the key deviation difference between this policy item and the anomalous data is 0.05 (0.4-0.35), the uniformity gradient is correlated with the encryption strength gradient adjustment coefficient corresponding to the policy item, and the latency fluctuation difference is 30ms (180-150).
[0102] Based on the difference calculation results, the module generates a match index for each encryption policy item against the real-time data. The match calculation considers the weighting of each dimension's difference. For example, key deviation might account for 40%, uniformity gradient 30%, and latency fluctuation 30%. For the policy item in the example above, assuming the standardized match scores for each dimension are 90, 85, and 80, respectively, the overall match score is 90 × 40% + 85 × 30% + 80 × 30% = 85.5. The module performs a similar calculation for all encryption policy items and creates a ranked match list. Assuming the match score of the first policy item in the ranked list is 88, which exceeds the preset adjustment trigger threshold of 80, this policy is selected as the target adjustment policy.
[0103] If the first match score falls below the threshold—for example, if the highest match score between the anomalous data and all policy items in a certain scenario is 75 points—the module invokes the backup policy set. This backup policy set contains encryption policies for special scenarios, such as emergency encryption policies for sudden traffic attacks. After invocation, the module recalculates the match scores between the anomalous data and the backup policy items until a policy with a satisfactory match is found.
[0104] After the policy adjustment is completed, the policy self-learning module will record the adjusted security status feedback data. Continuing with the e-commerce platform as an example, after adjusting the target policy, the system will record data such as actual key uniformity, security strength changes, and delay control effects. Assume that the key uniformity index of the payment interface after adjustment is increased from 0.6 before the adjustment to 0.75 (this is only a logical illustration and does not involve specific effect data), and the delay control effect is reduced from 150ms fluctuations to 120ms fluctuations (same as above). The module reversely verifies these feedback data with the dynamic adjustment set of the encryption policy to analyze the deviation between the current policy and actual needs.
[0105] During the reverse verification process, the module will generate a policy correction factor. For example, based on the degree of deviation between the feedback data and the expected security target, the traffic compensation factor, encryption strength adjustment factor and delay optimization weight are calculated. If the expected key uniformity target is 0.8 and it actually reaches 0.75, the encryption strength adjustment factor may need to be increased by 5% to enhance encryption uniformity. The module uses an exponential weighted average algorithm to dynamically smooth the historical correction factors to avoid policy fluctuations due to errors in a single adjustment. For example, if the weighted average of the encryption strength adjustment factor in the historical correction factor is +3% and the currently calculated adjustment factor is +5%, then the factor in the new dynamic correction coefficient set may be updated to +4% (the specific calculation logic is dynamically adjusted according to the weight of historical data).
[0106] After the correction factor is updated, it is synchronized to the dynamic correction coefficient set in the security policy database and used in the subsequent generation of dynamic encryption policy adjustment sets. For example, the next time a policy adjustment set is generated, the encryption strength adaptability threshold will be dynamically adjusted based on the updated encryption strength adjustment factor, ensuring that the policy better meets actual security requirements.
[0107] In practical applications, the policy matching module's multi-dimensional matching process must be integrated with real-time changes in the network environment. For example, when abnormal traffic occurs in a cloud service provider's distributed nodes, the abnormal data analyzed by the module may contain encryption delay fluctuations caused by a sudden increase in traffic density. In this case, the traffic dynamic range and delay optimization control value must be accurately matched with the traffic characteristics and delay fluctuation amplitude in the abnormal data. The policy self-learning module continuously accumulates historical feedback data to gradually optimize the dynamic correction coefficient set. For example, after multiple policy adjustments, the message encryption system of a social platform optimized the dynamic correction coefficient of the encryption strength adjustment factor to a more precise range through a self-learning mechanism, thereby improving the encryption policy's adaptability to sudden message peaks.
[0108] Throughout the implementation process, the policy matching module ensures that abnormal security data is quickly matched to the optimal policy through precise multi-dimensional matching and a dynamic policy selection mechanism. The policy self-learning module continuously optimizes the system's encryption policy architecture through feedback data, thereby achieving dynamic adaptive management of network security. This mechanism is particularly important in scenarios with high network security requirements, such as finance, e-commerce, and cloud computing. It can effectively respond to complex and changing network attacks and traffic fluctuations, ensuring system security and stability.
[0109] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0110] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A dynamic encryption network security management system based on federated learning, characterized in that: include: The network data acquisition module is used to collect network traffic data and encryption status data in real time through distributed node devices, analyze and process them to generate traffic characteristic values and encryption dynamic parameter characteristic values, and generate a dynamic adjustment set of encryption policies based on the initial encryption policy set stored in the security policy database; The federated learning processing module obtains personalized encryption strategies for the current network environment and generates dynamic security control strategies based on traffic feature values. The security status monitoring module is used to obtain real-time security status data during network communication through encrypted sensors, filter out abnormal security data that meets the dynamic adjustment range, and send it to the policy matching module; The policy matching module is used to perform multi-dimensional matching between abnormal security data and each policy item in the dynamic adjustment set of encryption policies, generate the matching degree between real-time data and each encryption policy item, and select the encryption policy corresponding to the highest matching degree as the target adjustment policy; The policy adjustment module is used to receive the target adjustment policy and call the policy adjustment protocol preset in the security policy database to drive the encryption engine to perform encryption policy correction operations.
2. The dynamic encrypted network security management system based on federated learning according to claim 1, characterized in that: The real-time collection of network traffic data and encryption status data by distributed node devices is as follows: Identify the unique identification code of the distributed node. If it is a newly accessed node, collect basic network parameters including initial traffic density, encryption strength baseline value, and delay control range, establish a security feature node based on the initial data, perform parameter calibration, and generate traffic feature values; If it is a historical access node, the historical network data set and security status change curve of the node are extracted. The historical network data set includes traffic fluctuation extremes, encryption deviation records and delay control delay duration, and is marked as the initial parameter set for the current security analysis.
3. The dynamic encryption network security management system based on federated learning according to claim 1, characterized in that: Generating a dynamic encryption policy adjustment set based on an initial encryption policy set stored in a security policy database specifically includes: Extracting an initial standard set and a dynamic correction coefficient set for each encryption policy from a security policy database, wherein the initial standard set includes: a traffic density safety range, an encryption strength fluctuation tolerance range, and a delay adjustment reference value; The dynamic correction coefficient set includes a traffic density compensation coefficient, an encryption strength gradient adjustment coefficient, and a delay response weight parameter; Based on the real-time encryption dynamic parameter characteristic value, dynamically adjust the initial standard set of each encryption policy, and record the adjusted policy set as the encryption policy dynamic adjustment set; The encryption policy dynamic adjustment set includes the traffic dynamic range, encryption strength adaptability threshold and delay optimization control value of each policy item.
4. The dynamic encryption network security management system based on federated learning according to claim 3, characterized in that: The process of obtaining a personalized encryption strategy for the current network environment and generating a dynamic security control strategy based on the traffic characteristic value specifically includes: According to the traffic characteristic value and the preset security policy characteristic library, the encryption policy adjustment priority sequence is determined; An adaptive control strategy including strategy triggering conditions, adjustment step rules and fault handling mechanism is generated based on the adjustment priority sequence.
5. The dynamic encryption network security management system based on federated learning according to claim 4, characterized in that: The real-time security status data of the network communication process is obtained by using an encryption sensor, specifically including: Real-time sensor data streams monitoring the implementation of the encryption process, including encryption key changes, security uniformity indicators, and latency fluctuations; When the real-time sensor data stream exceeds the preset qualified safety range, the abnormal flag is activated and the safety data of the abnormal period is extracted as effective monitoring data.
6. The dynamic encryption network security management system based on federated learning according to claim 4, characterized in that: The matching degree between the generated real-time data and each encryption policy item specifically includes: Analyze the key deviation, uniformity gradient, and delay fluctuation amplitude in abnormal security data, and perform differential calculations with the traffic dynamic range, encryption strength adaptability threshold, and delay optimization control value of each encryption strategy; Based on the difference calculation results, a matching index between real-time data and each encryption policy item is generated.
7. The dynamic encryption network security management system based on federated learning according to claim 3, characterized in that: The step of selecting the encryption policy corresponding to the highest matching degree as the target adjustment policy specifically includes: Create a list of encryption policy items ranked by their matching degree, and select the policy item with the highest matching degree in the list; If the first matching degree is lower than the preset adjustment trigger threshold, the backup strategy set is called and the matching degree is recalculated.
8. The dynamic encryption network security management system based on federated learning according to claim 6, characterized in that: The matching index between the real-time data and each encryption policy item is generated based on the difference calculation result. The specific processing process is as follows: A multi-dimensional matching algorithm is used to normalize traffic differences, encryption strength gradients, and delay deviations to generate an encryption policy matching degree value ranging from 0 to 100. The closer the matching value is to 100, the stronger the adaptability of the real-time data to the encryption policy.
9. The dynamic encryption network security management system based on federated learning according to claim 1, characterized in that: It also includes a strategy self-learning module, including: Record security status feedback data after each policy adjustment, including actual key uniformity, security strength changes, and delay control effects; The feedback data is reversely verified with the dynamic adjustment set of the encryption policy to generate a policy correction factor and update the dynamic correction coefficient set to the security policy database.
10. The dynamic encryption network security management system based on federated learning according to claim 9, characterized in that: The generation strategy correction factor specifically includes: Based on the degree of deviation between the feedback data and the expected security target, the traffic compensation factor, encryption strength adjustment factor, and delay optimization weight are calculated; The exponentially weighted average algorithm is used to dynamically smooth the historical correction factors to generate a new set of dynamic correction coefficients.
Citation Information
Patent Citations
Data traffic security defense method based on Internet of Things
CN118200055A
Mine network security operation system
CN119728294A
Distributed data security protection system based on Internet of Things nodes
CN119766556A
Heterogeneous encrypted multi-modal multimedia message real-time fragmentation transmission method for 5G network
CN120201420A
Cited By
Unmanned aerial vehicle data encryption transmission system
CN120980520A
Fault positioning method and system for communication network
CN121151203A