Dynamic encryption network security management system based on federated learning

By using a federated learning-based dynamic encrypted network security management system, network traffic data is collected and processed in real time to generate personalized encryption policies. This solves the problem of insufficient intelligence and adaptability of traditional systems in dynamic environments, and achieves efficient network security management.

CN120602192BActive Publication Date: 2026-01-02BEIJING DUOYAN SILICON VALLEY TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510914134.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2026-01-02
Estimated Expiration
2045-07-03

AI Technical Summary

Technical Problem

Traditional network security management systems struggle to adapt to dynamically changing network environments and diverse attack methods. They lack intelligence and adaptability, resulting in insufficient detection and defense capabilities against new attacks and abnormal network behaviors. Furthermore, they consume significant computing and storage resources, impacting system response speed and stability.

Method used

A dynamic encrypted network security management system based on federated learning is adopted. The network data acquisition module collects traffic and encryption status data in real time, the federated learning processing module generates personalized encryption policies, the security status monitoring module monitors abnormal data in real time, the policy matching module performs multi-dimensional matching, selects the encryption policy with the highest matching degree for automatic adjustment, and the policy self-learning module optimizes the encryption policy.

Benefits of technology

It enables the generation of personalized encryption policies in a distributed environment without sharing original data, improving the system's intelligence and adaptability, enabling timely response to network security threats, and improving response speed and the accuracy and efficiency of policy adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602192B_ABST
    Figure CN120602192B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security management, and discloses a dynamic encryption network security management system based on federal learning, which comprises network data acquisition, federal learning processing, security state monitoring and the like. The network data acquisition module acquires traffic and encryption state data in real time, generates characteristic values and an encryption strategy dynamic adjustment set; the federal learning processing module generates individualized encryption strategies according to the traffic characteristic values; the security state monitoring module screens abnormal security data; the strategy matching module determines a target adjustment strategy through multidimensional matching; the strategy adjustment module drives an encryption engine to correct the strategy; and the strategy self-learning module updates a strategy correction factor based on feedback data. The system realizes dynamic encryption strategy adjustment and self-optimization, improves the intelligentization and self-adaptive capacity of network security protection, and is suitable for distributed network security management.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security management, in particular to a dynamic encryption network security management system based on federated learning. BACKGROUND

[0002] With the rapid development of Internet technology, network security problems are becoming increasingly serious, and data breaches, malicious attacks and other threats have brought huge losses to individuals, enterprises and society. Traditional network security management systems mostly use static encryption strategies, which are difficult to adapt to dynamic changes in network environment and diversified attack means. Static encryption strategies are usually based on fixed security rules and preset encryption parameters, and cannot be flexibly adjusted according to real-time network traffic, encryption status and changes in security threats, resulting in insufficient detection and defense capabilities for new attacks and abnormal network behaviors.

[0003] In a distributed network environment, traditional systems face challenges in data collection and processing. Network traffic and encryption status data of different node devices are stored in a decentralized manner, making it difficult to achieve efficient centralized analysis and management, resulting in a lack of comprehensiveness and real-time in security policy formulation and adjustment. In addition, when dealing with large-scale data, traditional systems consume a lot of computing and storage resources, which can easily cause performance bottlenecks, affecting the response speed and stability of the system.

[0004] Existing encryption strategy adjustment mechanisms often lack intelligence and adaptability. When the network environment changes, administrators need to manually adjust the encryption strategy, which not only consumes a lot of time and effort, but also is prone to human error, resulting in a mismatch between the security policy and actual needs. At the same time, traditional systems are difficult to monitor and evaluate the effectiveness of encryption strategies in real time, and cannot timely discover vulnerabilities and deficiencies in the strategy, further reducing the efficiency and reliability of network security management.

[0005] Federated learning, as a new machine learning technology, provides a new approach to model training and strategy optimization in distributed data scenarios. However, current research on applying federated learning to the field of network security management is still in its infancy. How to use federated learning technology to achieve dynamic encryption strategy generation, adjustment and optimization, and improve the intelligence and adaptability of network security management systems is a technical problem that needs to be solved. SUMMARY

[0006] The purpose of the present application is to provide a dynamic encryption network security management system based on federated learning to solve the problems raised in the background art.

[0007] To achieve the above purpose, the present application provides the following technical solution: a dynamic encryption network security management system based on federated learning, the system comprising:

[0008] a network data collection module, configured to collect network traffic data and encryption state data in real time through the distributed node device, analyze and process to generate traffic characteristic values and encryption dynamic parameter characteristic values, and generate a dynamic encryption policy adjustment set based on an initial encryption policy set stored in a security policy database;

[0009] a federated learning processing module, configured to process the personalized encryption policy of the current network environment based on the traffic characteristic values and generate a dynamic security control policy;

[0010] a security state monitoring module, configured to acquire real-time security state data in a network communication process through an encryption sensor, filter out abnormal security data meeting a dynamic adjustment range, and send the abnormal security data to the policy matching module;

[0011] a policy matching module, configured to perform multi-dimensional matching of the abnormal security data and each policy item in the dynamic encryption policy adjustment set, generate a matching degree of real-time data and each encryption policy item, and select an encryption policy corresponding to the highest matching degree as a target adjustment policy;

[0012] a policy adjustment module, configured to receive the target adjustment policy and call a preset policy adjustment protocol in the security policy database to drive an encryption engine to perform an encryption policy correction operation.

[0013] Preferably, the real-time collection of network traffic data and encryption state data through the distributed node device includes the following specific process:

[0014] identifying a unique identification code of the distributed node, collecting basic network parameters including an initial traffic density, an encryption strength benchmark value and a delay control range if the node is a newly accessed node, establishing a security feature node based on the first data and performing parameter calibration to generate traffic characteristic values;

[0015] if the node is a historically accessed node, extracting a historical network data set and a security state change curve of the node, the historical network data set including traffic fluctuation extreme values, encryption deviation records and delay control delay time lengths, and marking the historical network data set as an initial parameter set for current security analysis.

[0016] Preferably, the dynamic encryption policy adjustment set generated based on the initial encryption policy set stored in the security policy database specifically includes:

[0017] extracting an initial standard set and a dynamic correction coefficient set of each encryption policy from the security policy database, the initial standard set including a traffic density security range, an encryption strength fluctuation tolerance interval and a delay adjustment benchmark value;

[0018] the dynamic correction coefficient set including a traffic density compensation coefficient, an encryption strength gradient adjustment coefficient and a delay response weight parameter;

[0019] Based on the real-time encryption dynamic parameter characteristic value, the initial standard set of each encryption strategy is dynamically adjusted, and the adjusted strategy set is recorded as an encryption strategy dynamic adjustment set.

[0020] The encryption strategy dynamic adjustment set includes a traffic dynamic range, an encryption strength adaptability threshold, and a delay optimization control value of each strategy item.

[0021] Preferably, based on the traffic characteristic value, a personalized encryption strategy of the current network environment is processed to generate a dynamic security control strategy, specifically including:

[0022] According to the mode matching of the traffic characteristic value and the preset security strategy feature library, an encryption strategy adjustment priority sequence is determined.

[0023] Based on the adjustment priority sequence, an adaptive control strategy including a strategy trigger condition, an adjustment step rule, and a fault handling mechanism is generated.

[0024] Preferably, the real-time security state data in the network communication process is obtained through an encryption sensor, specifically including:

[0025] The real-time sensor data stream of the encryption process implementation is monitored, including an encryption key change value, a security uniformity index, and a delay fluctuation value.

[0026] When the real-time sensor data stream exceeds the preset qualified security range, an abnormality marker is activated, and the security data of the abnormal period is extracted as effective monitoring data.

[0027] Preferably, the matching degree of the real-time data and each encryption strategy item is generated, specifically including:

[0028] The key deviation amount, the uniformity change gradient, and the delay fluctuation amplitude in the abnormal security data are analyzed, and difference value calculations are respectively performed on the traffic dynamic range, the encryption strength adaptability threshold, and the delay optimization control value of each encryption strategy.

[0029] Based on the difference value calculation result, a matching degree index of the real-time data and each encryption strategy item is generated.

[0030] Preferably, the encryption strategy corresponding to the highest matching degree is selected as the target adjustment strategy, specifically including:

[0031] A matching degree sorting list of each encryption strategy item is established, and the strategy item corresponding to the first matching degree in the list is selected.

[0032] If the first matching degree is lower than the preset adjustment trigger threshold, a backup strategy set is called and matching degree calculation is performed again.

[0033] Preferably, based on the difference value calculation result, a matching degree index of the real-time data and each encryption strategy item is generated, and the specific processing process is:

[0034] The multi-dimensional matching algorithm is used for standardizing the flow difference, encryption strength gradient difference and delay deviation, so as to generate an encryption strategy matching degree value in the range of 0-100;

[0035] The closer the matching degree value is to 100, the stronger the adaptability of real-time data to the encryption strategy.

[0036] Preferably, the strategy self-learning module specifically comprises:

[0037] The security state feedback data after each strategy adjustment is recorded, including actual key uniformity, security strength change and delay control effect.

[0038] The feedback data is reversely verified with the dynamic adjustment set of the encryption strategy, a strategy correction factor is generated and updated to the dynamic correction coefficient set of the security strategy database.

[0039] Preferably, the generation of the strategy correction factor specifically comprises:

[0040] Based on the deviation degree of the feedback data from the expected security target, a flow compensation factor, an encryption strength adjustment factor and a delay optimization weight are calculated.

[0041] An exponential weighted average algorithm is used for dynamically smoothing the historical correction factors, so as to generate a new dynamic correction coefficient set.

[0042] Compared with the prior art, the present application has the following beneficial effects:

[0043] In terms of data acquisition and processing, the network data acquisition module acquires network flow data and encryption state data in real time through distributed node devices, and different processing methods are used for new access nodes and historical access nodes. For new nodes, basic network parameters are collected and security feature nodes are established for parameter calibration, so as to ensure the accuracy and reliability of initial data. For historical nodes, historical network data sets and security state change curves are extracted, so as to provide rich historical data support for subsequent security analysis. This differentiated data acquisition and processing method can comprehensively and accurately obtain network state information, and lays a solid foundation for the generation of dynamic encryption strategies.

[0044] The federal learning processing module determines an encryption policy adjustment priority sequence by pattern matching with a preset security policy feature library based on the traffic feature value, and generates an adaptive control policy including a policy trigger condition, an adjustment step rule and a fault handling mechanism. The application of the federal learning technology enables the system to train and update the model without sharing the original data in a distributed data environment, protects the data privacy, improves the intelligence and adaptability of the policy generation, and can generate personalized encryption policies in real time according to the changes of the current network environment, effectively coping with the dynamically changing security threats.

[0045] The security state monitoring module can timely discover abnormal data exceeding the preset security range and send it to the policy matching module by acquiring the security state data in the network communication process in real time. The real-time monitoring mechanism ensures that the system can quickly perceive the security anomaly in the network and provides a basis for timely adjusting the encryption policy, improving the response speed and real-time performance of the system.

[0046] The policy matching module performs difference calculation and standardization processing on each policy item in the dynamic adjustment set of encryption policies through a multi-dimensional matching algorithm, generates a matching degree index, and selects the encryption policy with the highest matching degree as the target adjustment policy. The multi-dimensional matching method ensures the accuracy and scientificity of policy adjustment, can select the most suitable encryption policy according to the specific characteristics of abnormal data, and improves the pertinence and effectiveness of policy adjustment.

[0047] After receiving the target adjustment policy, the policy adjustment module calls the preset policy adjustment protocol to drive the encryption engine to perform correction operation, realizing the dynamic adjustment of the encryption policy. This automatic policy adjustment mechanism avoids the delay and mistakes of human intervention, improves the efficiency and reliability of policy adjustment, and can timely cope with the changes of network security threats.

[0048] The policy self-learning module records the security state feedback data after policy adjustment, and performs reverse verification with the dynamic adjustment set of encryption policies, generates a policy correction factor and updates the dynamic correction coefficient set. This self-learning mechanism enables the system to continuously optimize the encryption policy according to the actual operation effect, forms a closed loop feedback, continuously improves the security protection capability and adaptability of the system, so that the system can continuously evolve in the long-term operation and better cope with the increasingly complex network security challenges. BRIEF DESCRIPTION OF DRAWINGS

[0049] Figure 1 The working principle diagram of the dynamic encryption network security management system based on federal learning described in the application;

[0050] Figure 2 The design diagram of the distributed node device data acquisition process;

[0051] Figure 3 a design diagram for real-time security state data acquisition;

[0052] Figure 4 a design diagram for encryption policy item matching degree generation;

[0053] Figure 5 a design diagram for target adjustment policy selection. DETAILED DESCRIPTION

[0054] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work are within the scope of protection of the present application.

[0055] Please refer to Figures 1-5 The present application relates to a dynamic encryption network security management system based on federated learning, which comprises a network data acquisition module, a federated learning processing module, a security state monitoring module, a policy matching module and a policy adjustment module. Specifically, the following steps are included.

[0056] The network data acquisition module acquires network traffic data and encryption state data in real time through distributed node devices, analyzes and processes to generate traffic characteristic values and encryption dynamic parameter characteristic values, and generates an encryption policy dynamic adjustment set based on an initial encryption policy set stored in a security policy database. The federated learning processing module processes the traffic characteristic values to obtain a personalized encryption policy of the current network environment and generates a dynamic security control policy. The security state monitoring module acquires real-time security state data in the network communication process through an encryption sensor, filters out abnormal security data within the dynamic adjustment range and sends it to the policy matching module. The policy matching module performs multi-dimensional matching between the abnormal security data and each policy item in the encryption policy dynamic adjustment set, generates a matching degree of real-time data and each encryption policy item, and selects the encryption policy corresponding to the highest matching degree as the target adjustment policy. The policy adjustment module receives the target adjustment policy and calls a preset policy adjustment protocol in the security policy database to drive the encryption engine to perform encryption policy correction operations.

[0057] Embodiment 1

[0058] In this embodiment, the network data acquisition module of the system acquires network traffic data and encryption state data in real time through distributed node devices, and the specific process is as follows: the module identifies the unique identification code of the distributed node to determine whether the node is a newly connected node or a historically connected node.

[0059] When a new access node is identified, the module will start collecting basic network parameters, which include initial traffic density, encryption strength benchmark value and delay control range. After collecting these basic parameters, a security feature node is established based on the first obtained data. During the establishment of the security feature node, the collected parameters need to be analyzed and processed in detail to ensure that the node can accurately reflect the initial security features of the new access node. After the security feature node is established, parameter calibration is performed to eliminate possible errors in the collection process and make the parameters more accurate and reliable. After parameter calibration, the final traffic feature value is generated, which will serve as an important basis for subsequent processing.

[0060] For historical access nodes, the module's processing method is different. At this time, the module will extract the historical network data set and the security state change curve of the node. The historical network data set covers multiple key aspects, including traffic fluctuation extreme value, which can reflect the maximum and minimum fluctuation of the node's traffic in the historical operation process; encryption deviation record, which helps to understand the deviation of the node in the encryption process; and delay control delay duration, which reflects the performance of the node in delay control. At the same time, the security state change curve intuitively shows the trend of the node's security state change in the historical period. After extracting these data, the module will mark them as the initial parameter set for the current security analysis, providing a basis for subsequent security analysis of the historical node.

[0061] During the entire data collection process, the processing of new access nodes and historical access nodes has strict procedures and requirements. For the first data collection of new access nodes, each link needs to be operated accurately. When identifying the unique identifier, ensure the accuracy of the identification to avoid deviation in subsequent processing due to identification code identification error. When collecting basic network parameters, ensure the integrity and authenticity of the parameters, and do not miss any important parameter information. When establishing a security feature node, various factors need to be considered to make the node fully and accurately represent the characteristics of the new access node. In the parameter calibration process, scientific and reasonable methods should be used to adjust the parameters in detail to improve the accuracy of the parameters.

[0062] For the data extraction of historical access nodes, it also needs to be treated with rigor. Ensure that the historical network data set and the security state change curve can be fully and accurately obtained. When extracting traffic fluctuation extreme value, encryption deviation record and delay control delay duration, etc., ensure the accuracy and reliability of the data, as the quality of these data directly affects the results of the current security analysis. When marking the initial parameter set, it should be clear and explicit to facilitate subsequent use and management.

[0063] Through this differentiated processing mode for new and old nodes, the network data acquisition module can effectively obtain accurate and comprehensive network traffic data and encryption state data. These data provide a solid data foundation for each link of subsequent encryption policy dynamic adjustment set generation, personalized encryption policy processing, and security state monitoring, ensuring that the entire system can operate and make decisions based on reliable data, thereby achieving effective management and dynamic encryption adjustment of network security. This processing mode fully considers the characteristics of different nodes, with new nodes focusing on the establishment of initial features and the calibration of parameters, and historical nodes using their historical data to more accurately analyze the current state, making the data acquisition work more scientific and reasonable, and better adapting to the complexity and dynamics of the network environment. In actual application, the module will continuously identify and collect data from distributed nodes, update data in real time to ensure that the system can respond to various changes that may occur in the network in a timely manner, ensuring the effectiveness and real-time performance of network security management.

[0064] Embodiment 2

[0065] In this embodiment, the network data acquisition module generates the encryption policy dynamic adjustment set based on the initial encryption policy set stored in the security policy database, and the specific implementation is as follows: when performing the generation operation, the module needs to access the security policy database first, and extract the initial standard set and dynamic correction coefficient set corresponding to each encryption policy from the database. Among them, the initial standard set contains three types of core parameters: traffic density security range, encryption strength fluctuation tolerance interval, and delay adjustment benchmark value. These parameters are the basic standards of the encryption policy, which are used to define the reasonable range of each index in the normal encryption state; the dynamic correction coefficient set includes traffic density compensation coefficient, encryption strength gradient adjustment coefficient, and delay response weight parameter. These coefficients and parameters are used to dynamically adjust the initial standard set to adapt to the real-time changing network environment.

[0066] After the extraction of the initial standard set and the dynamic correction coefficient set is completed, the module needs to dynamically adjust the initial standard set of each encryption strategy based on the real-time acquisition of encrypted dynamic parameter characteristic values. Real-time encrypted dynamic parameter characteristic values are generated by real-time acquisition and analysis by the network data acquisition module through distributed node devices, reflecting the encrypted state parameter characteristics under the current network environment. During the adjustment process, the module will calculate each parameter in the initial standard set in combination with the corresponding dynamic correction coefficient. For example, for the traffic density safety range, the module will adjust it using the traffic density compensation coefficient based on the traffic-related characteristics in the real-time encrypted dynamic parameter characteristic values to determine the current applicable traffic dynamic range; for the encryption strength fluctuation tolerance interval, it will be modified by the encryption strength gradient adjustment coefficient based on the real-time characteristics related to the encryption strength to obtain the encryption strength adaptability threshold; for the delay adjustment reference value, it will also be adjusted by the delay response weight parameter in combination with the real-time parameter characteristics related to the delay to generate the delay optimization control value.

[0067] When extracting data from the security policy database, the module needs to follow a strict data extraction process to ensure that the extracted initial standard set and dynamic correction coefficient set are accurate. This requires that the access interface of the database have a reliable authentication mechanism and data verification function to prevent errors or data loss during the data extraction process. At the same time, during the extraction process, the extracted data needs to be format-verified and integrity-checked to ensure that the format of each parameter meets the system requirements and that no key data is missing.

[0068] When adjusting based on real-time encrypted dynamic parameter characteristic values, the module needs to use scientific and reasonable adjustment algorithms and logic. First, the real-time encrypted dynamic parameter characteristic values need to be preprocessed to remove possible noise data and outliers to ensure that the data used for adjustment is accurate and reliable. Then, according to the characteristics of different parameters and the nature of the dynamic correction coefficient, the corresponding adjustment rules are designed. For example, when adjusting the traffic density safety range, the actual traffic load of the current network, historical traffic data, and the characteristics of network services need to be considered, and the traffic density compensation coefficient needs to be reasonably used for adjustment, so that the adjusted traffic dynamic range can meet the needs of the current network traffic and ensure the security and stability of the network.

[0069] After the adjustment is completed, the module will integrate the adjusted parameters of each strategy item to form the encrypted strategy dynamic adjustment set. This set contains the traffic dynamic range, encryption strength adaptability threshold, and delay optimization control value of each strategy item, which are important bases for the subsequent federal learning processing module to generate personalized encryption strategies and dynamic security control strategies, and are also key references for the strategy matching module to match abnormal security data.

[0070] Throughout the process of generating the dynamic adjustment set of encryption strategy, the real-time and accuracy of data are crucial. In order to ensure the real-time of data, the network data acquisition module needs to continuously collect and update the encryption dynamic parameter characteristic value, and timely deliver it to the module responsible for generating the dynamic adjustment set of encryption strategy. In order to ensure the accuracy of data, in addition to strict checking in the data acquisition and extraction link, multiple data verification and correction are needed in the adjustment process to avoid the generated dynamic adjustment set of encryption strategy not meeting the actual demand due to data error.

[0071] In addition, the generation of the dynamic adjustment set of encryption strategy also needs to consider the dynamic change characteristics of the network environment. The factors such as traffic and encryption demand in the network environment may change at any time, therefore, the module needs to have the ability to respond to these changes in real time, and can update the dynamic adjustment set of encryption strategy in time according to the latest encryption dynamic parameter characteristic value, to ensure that the system can always adopt the most suitable encryption strategy for the current network environment, thereby effectively improving the security and stability of the network.

[0072] This embodiment generates the dynamic adjustment set of encryption strategy by extracting initial parameters and correction coefficients from the security policy database, and combining real-time encryption dynamic parameter characteristic values for dynamic adjustment, which provides a policy basis for dynamically adapting to the current network environment for the subsequent operation of the entire system. This way makes full use of the pre-set standards and dynamic correction mechanism, which not only guarantees the basic framework and security requirements of the strategy, but also can be flexibly adjusted according to real-time conditions, so that the system can better cope with the complex and changeable network security environment. In practical application, this module will continue to run and update the dynamic adjustment set of encryption strategy according to real-time data, to ensure that the encryption strategy of the system is always in the optimal state, thereby realizing effective management and protection of network security.

[0073] Embodiment 3:

[0074] In this embodiment, the federated learning processing module processes the traffic characteristic value to obtain the personalized encryption strategy of the current network environment and generates a dynamic security control strategy, and the specific implementation manner is as follows: after receiving the traffic characteristic value generated by the network data acquisition module, the module needs to perform pattern matching on the traffic characteristic value and the pre-set security policy feature library. The security policy feature library stores multiple pre-set policy feature patterns based on historical data and security requirements, and these patterns correspond to different network traffic conditions and encryption strategy adjustment directions.

[0075] In the pattern matching process, the module will decompose the traffic feature value into multiple dimensional feature parameters, such as the time distribution characteristics of the traffic, the change characteristics of the traffic size, the composition characteristics of the traffic type, etc. Then, these feature parameters are compared with the corresponding dimensions of each policy feature mode in the security policy feature library one by one, and the similarity between them is calculated. Here, a similarity calculation function is used to quantify the matching degree of the traffic feature value and each policy feature mode, and the expression of the similarity calculation function is:

[0076]

[0077] where S represents the overall similarity of the traffic feature value and a certain policy feature mode; n is the number of feature dimensions; w i is the weight of the i-th feature dimension, which is in the range of 0 to 1, reflecting the importance of the feature dimension in the overall matching; sim i (f i , p i ) is the similarity value of the traffic feature parameter f i and the corresponding parameter p i of the policy feature mode under the i-th feature dimension, and the calculation result is also in the range of 0 to 1.

[0078] When determining the weight w i of each feature dimension, the module will consider the actual needs of network security and the influence of each feature dimension on the encryption policy adjustment. For feature dimensions that have a greater impact on network security, such as the proportion of abnormal traffic in the traffic, a higher weight is given; while for feature dimensions that have a relatively small impact, such as the time distribution characteristics of normal traffic, a relatively low weight is given.

[0079] After completing the similarity calculation, the module will determine the encryption policy adjustment priority sequence according to the size of the similarity value. The priority sequence is arranged from high to low according to the similarity, and the higher the similarity, the higher the priority of the encryption policy adjustment corresponding to the policy feature mode, that is, the direction of the encryption policy adjustment corresponding to the policy feature mode is more in line with the current network traffic characteristics, which needs to be given priority.

[0080] After determining the encryption policy adjustment priority sequence, the module generates a dynamic security control policy based on the sequence. The dynamic security control policy includes three main parts: policy trigger condition, adjustment step rule and fault handling mechanism.

[0081] The setting of the policy trigger condition is associated with each policy feature mode in the priority sequence. When the similarity between the network traffic feature value and a certain policy feature mode reaches or exceeds the preset trigger threshold, the corresponding encryption policy adjustment trigger condition is activated. The setting of the trigger threshold needs to be reasonably determined according to the actual situation and historical experience of network security, avoiding both too strict trigger conditions that prevent timely policy adjustment and too loose trigger conditions that frequently trigger unnecessary policy adjustments.

[0082] The adjustment step rule specifies the specific adjustment steps that the system needs to perform after triggering the corresponding encryption policy adjustment. These steps include the selection of encryption algorithms, the update method of encryption keys, and the adjustment range of encryption strength. The design of the adjustment step rule needs to follow the principles of security, efficiency, and stability, ensuring that each adjustment operation is accurately performed and does not seriously affect the normal operation of the network.

[0083] The fault handling mechanism is set to deal with abnormal situations that may occur during policy adjustment. For example, problems such as adjustment failure and significant decline in network performance after adjustment may occur during encryption policy adjustment. The fault handling mechanism specifies emergency measures that the system should take in these situations, such as rolling back to the previous encryption policy or starting a backup encryption policy, to ensure that the security and stability of the network are not severely affected.

[0084] When generating dynamic security control policies, the module needs to fully consider the dynamic changes and uncertainties of the network environment. Network traffic may change significantly in a short period of time, so the generated dynamic security control policies need to have certain flexibility and adaptability, and be able to adjust and optimize according to real-time traffic feature values.

[0085] The module also needs to verify the rationality of the generated dynamic security control policies. The verification process includes checking whether the policy trigger conditions are reasonable, whether the adjustment step rules are complete and feasible, and whether the fault handling mechanism is effective. Through rationality verification, problems in the policy can be found and corrected in a timely manner, improving the reliability and effectiveness of the policy.

[0086] The federated learning processing module also uses the characteristics of federated learning to continuously optimize the weights w i in the security policy feature library and the similarity calculation function. By collecting learning data from multiple distributed nodes without revealing the privacy data of each node, the security policy feature library is updated and expanded, making the policy feature modes in the library more rich and accurate. At the same time, the weights of each feature dimension are adjusted to better meet the actual needs of current network security, thereby improving the accuracy of pattern matching and the effectiveness of dynamic security control policies.

[0087] The whole process, from the reception of the traffic characteristic value, the pattern matching with the security policy feature library, to the determination of the encryption policy adjustment priority sequence, and then to the generation of the dynamic security control policy, each link is closely connected and influences each other. The module needs to accurately perform the operation of each link to ensure that the generated personalized encryption policy and dynamic security control policy can accurately adapt to the current network environment and provide effective protection for network security.

[0088] Embodiment 4:

[0089] In this embodiment, the security state monitoring module obtains real-time security state data in the network communication process through the encryption sensor, and the specific implementation is as follows: in the network communication process, the module continuously monitors the real-time sensor data stream of the encryption process implementation with the help of the encryption sensor deployed in the network node or communication link. These data streams contain parameters of multiple key dimensions, such as the encryption key change value, which reflects the dynamic change of the key in the encryption process and is one of the important indicators for measuring encryption security; the security uniformity index, which is used to represent the uniform distribution degree of the encrypted data in the security layer, and the high and low of this index directly affects the overall effect of encryption; the delay fluctuation value, which reflects the change range of the delay in the network communication process, and too large delay fluctuation may affect the normal use of the network and the effective execution of the security policy.

[0090] Taking the network communication of a certain enterprise local area network as an example, when the servers and terminal devices in the enterprise perform data transmission, the encryption sensor will collect the encryption key change value, the security uniformity index and the delay fluctuation value in the transmission process in real time. Assuming that at a certain moment, the server sends an encrypted business document to the terminal, the encryption sensor will continuously obtain the related data stream parameters in each stage of data transmission, such as the data encryption stage, the transmission stage and the decryption stage.

[0091] In the monitoring process, the module will compare the real-time collected sensor data stream with the preset qualified security range. The preset qualified security range is preset according to the network security requirements and historical data, and is used to define the reasonable interval of each parameter under normal security state. For example, for the encryption key change value, the preset qualified security range may stipulate that the change range of the key in unit time cannot exceed a certain specific value, so as to avoid that the key changes too frequently or slowly and affects the encryption security; for the security uniformity index, a minimum threshold value may be set, and when the index is lower than the threshold value, it means that the security distribution of the encrypted data is not uniform enough, and there may be security risks; for the delay fluctuation value, there will also be a corresponding range limit to ensure that the delay of network communication fluctuates within an acceptable range.

[0092] When any parameter in the real-time sensor data stream exceeds the preset qualified safety range, the module will immediately activate the exception flag. The activation of the exception flag can be recording exception information in the system log, sending alarm notifications to administrators, etc. For example, in the above example of the enterprise LAN, if the encryption sensor detects that the security uniformity index during transmission suddenly falls below the preset minimum threshold, the module will quickly activate the exception flag, indicating that the current encryption state may be abnormal.

[0093] After activating the exception flag, the module extracts the security data during the exception period as valid monitoring data. The determination of the exception period needs to consider the time point and duration when the parameter exceeds the range. For example, from the time when the security uniformity index starts to fall below the threshold to the time when the index returns to the qualified range, all security data during this period will be extracted. During the extraction process, the module will ensure the integrity and accuracy of the data, including the encryption key change value during the exception period, the specific value of the security uniformity index, the change of the delay fluctuation value, etc.

[0094] In practical applications, the deployment location of the encryption sensor needs to be reasonably planned according to the network topology and security requirements. For example, in an enterprise network, encryption sensors can be deployed on key nodes such as core switches, border routers, and servers to comprehensively monitor the encryption communication state in the network. At the same time, in order to ensure that the encryption sensor can accurately collect the required data stream, it is necessary to regularly maintain and calibrate the sensor, check whether its working state is normal, and whether the accuracy of the collected data meets the requirements.

[0095] In addition, the preset qualified safety range is not fixed and will be adjusted and optimized regularly by the module according to changes in the network environment and analysis results of historical abnormal data. For example, if the delay fluctuation value frequently exceeds the preset range in the network for a period of time, and it is found through analysis that it is caused by insufficient network bandwidth, the module will adjust the qualified safety range of the delay fluctuation value according to the actual situation, so that it is more in line with the current network situation, avoiding the misactivation of the exception flag due to unreasonable range setting.

[0096] The security state monitoring module can timely discover security abnormal conditions in network communication process through a series of operations such as continuous monitoring, comparative analysis, exception flag activation and effective data extraction, and provide accurate abnormal security data for the subsequent policy matching module. These effective monitoring data are important basis for multi-dimensional matching and generation of target adjustment strategy by the policy matching module, which helps the system to timely adjust the encryption policy and ensure the safe operation of the network.

[0097] For another example, when a network of a certain financial institution conducts online transactions, the encryption sensor monitors the encryption state in real time during the transaction process. If the delay fluctuation value suddenly increases and exceeds the preset range during the transaction peak period, the module will activate the abnormal flag and extract the relevant security data during the peak period. After these data are sent to the strategy matching module, the module will match the corresponding encryption strategy according to these abnormal data, so as to adjust the encryption method during the transaction process to reduce the impact of delay fluctuation on the transaction and ensure the safety and smooth progress of the transaction.

[0098] Embodiment 5:

[0099] In this embodiment, the strategy matching module generates the matching degree of real-time data and each encryption strategy item and selects the target adjustment strategy, and the system realizes strategy optimization through the strategy self-learning module. The specific implementation manner is as follows:

[0100] Taking the network transaction system of a certain e-commerce platform as an example, when the security state monitoring module extracts the security data of the abnormal period, the strategy matching module will analyze these data. Assuming that during a promotion activity, the system monitors that an abnormality occurs in the encrypted communication of the payment interface, and the abnormal security data extracted by the security state monitoring module includes a key deviation amount of 0.35, a uniformity change gradient of 0.28, and a delay fluctuation amplitude of 150 ms. At this time, the strategy matching module needs to perform multi-dimensional matching of these data with each strategy item in the dynamic adjustment set of encryption strategies.

[0101] First, the module analyzes each parameter in the abnormal security data. For the key deviation amount in the above example, it needs to be clear that it is the deviation degree relative to the standard key parameter; the uniformity change gradient reflects the change rate of the security distribution of the encrypted data; and the delay fluctuation amplitude is the difference range between the actual delay and the normal delay. After the analysis is completed, the module will perform difference calculation on these parameters and the traffic dynamic range, the encryption strength adaptability threshold, and the delay optimization control value of each encryption strategy item. For example, the traffic dynamic range of a certain encryption strategy item corresponds to the standard range of processing payment interface traffic, the encryption strength adaptability threshold is the upper limit of the allowed key deviation 0.4, and the delay optimization control value is the upper limit of the allowed delay fluctuation in the normal transaction scenario 180 ms. Through the calculation, it can be known that the key deviation amount difference of the strategy item and the abnormal data is 0.05 (0.4-0.35), the uniformity change gradient needs to be associated and compared with the encryption strength gradient adjustment coefficient corresponding to the strategy item, and the delay fluctuation amplitude difference is 30 ms (180-150).

[0102] Based on the difference calculation result, the module generates the matching degree index of real-time data and each encryption policy item. The matching degree calculation comprehensively considers the weight of each dimension difference, for example, the key deviation amount may account for 40% weight, the uniformity change gradient accounts for 30%, and the delay fluctuation amplitude accounts for 30%. For the policy item in the above example, assuming that the matching degree scores corresponding to the dimension differences after standardization are 90 points, 85 points, and 80 points respectively, the comprehensive matching degree is 90*40%+85*30%+80*30%=85.5 points. The module performs similar calculation on all encryption policy items to establish a matching degree ranking list. Assuming that the matching degree of the first policy item in the ranking list is 88 points, which is higher than the preset adjustment trigger threshold of 80 points, the policy is selected as the target adjustment policy.

[0103] If the first matching degree is lower than the threshold, for example, the highest matching degree of the abnormal data and all policy items is 75 points in a certain scene, the module will call the backup policy set. The backup policy set stores encryption policies for special scenes, such as emergency encryption policies for sudden traffic attacks. After calling, the module will recalculate the matching degree of the abnormal data and the backup policy item until a policy with a matching degree meeting the requirements is found.

[0104] After the policy adjustment is completed, the policy self-learning module records the feedback data of the adjusted security state. Continuing with the example of the e-commerce platform, after the target policy is adjusted, the system records data such as actual key uniformity, security strength change, and delay control effect. Assuming that the key uniformity index of the payment interface is improved from 0.6 before adjustment to 0.75 after adjustment (this is only a logical illustration and does not involve specific effect data), and the delay control effect is reduced from 150ms fluctuation to 120ms fluctuation (same as above). The module will perform reverse verification of these feedback data with the dynamic adjustment set of encryption policies to analyze the deviation of the current policy from the actual demand.

[0105] During the reverse verification process, the module generates a policy correction factor. For example, based on the deviation of the feedback data from the expected security target, a traffic compensation factor, an encryption strength adjustment factor, and a delay optimization weight are calculated. If the expected key uniformity target is 0.8 and the actual value is 0.75, the encryption strength adjustment factor may need to be increased by 5% to enhance encryption uniformity. The module uses an exponentially weighted average algorithm to dynamically smooth the historical correction factors to avoid policy fluctuations caused by errors in single adjustments. For example, the weighted average value of the encryption strength adjustment factor in the historical correction factor set is +3%, and the current calculated adjustment factor is +5%, so the factor in the new dynamic correction factor set may be updated to +4% (the specific calculation logic is dynamically adjusted according to the weight of historical data).

[0106] After the correction factor is updated, it is synchronized to the dynamic correction coefficient set of the security policy database, which is used for the generation of the subsequent encryption policy dynamic adjustment set. For example, when generating the policy adjustment set next time, the encryption strength adaptability threshold will be dynamically adjusted based on the updated encryption strength adjustment factor, so that the policy is more in line with the actual security requirements.

[0107] In practical applications, the multi-dimensional matching process of the policy matching module needs to be combined with the real-time changes of the network environment. For example, when abnormal traffic occurs in the distributed nodes of the cloud service provider, the abnormal data parsed by the module may contain encryption delay fluctuations caused by sudden increase in traffic density. At this time, the traffic dynamic range and delay optimization control value need to be accurately matched with the traffic characteristics and delay fluctuation amplitude in the abnormal data. The policy self-learning module gradually optimizes the dynamic correction coefficient set by continuously accumulating historical feedback data. For example, after multiple policy adjustments, the message encryption system of a social platform optimizes the dynamic correction coefficient of the encryption strength adjustment factor to a more accurate range through the self-learning mechanism, thereby improving the adaptability of the encryption policy to sudden message peaks.

[0108] Throughout the implementation process, the policy matching module ensures that abnormal security data can be quickly matched to the optimal policy through accurate multi-dimensional matching and dynamic policy selection mechanism, while the policy self-learning module continuously optimizes the feedback data, so that the encryption policy system of the system continuously evolves, thereby realizing dynamic self-adaptive management of network security. This mechanism is particularly important in scenarios such as finance, e-commerce, and cloud computing, which have high requirements for network security, and can effectively cope with complex and variable network attacks and traffic fluctuations, ensuring the security and stability of the system.

[0109] It should be noted that, in this text, relational terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device.

[0110] Although embodiments of the present application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A dynamic encryption network security management system based on federated learning, characterized in that, The application relates to a network encryption strategy dynamic adjustment system, which comprises the following modules: a network data acquisition module, which is used for collecting network flow data and encryption state data in real time through distributed node equipment, analyzing and processing flow characteristic values and encryption dynamic parameter characteristic values, and generating an encryption strategy dynamic adjustment set based on an initial encryption strategy set stored in a security strategy database; a federal learning processing module, which is used for processing personalized encryption strategies of a current network environment based on flow characteristic values and generating a dynamic security control strategy; a security state monitoring module, which is used for acquiring real-time security state data in a network communication process through an encryption sensor, screening out abnormal security data meeting a dynamic adjustment range, and sending the abnormal security data to a strategy matching module; a strategy matching module, which is used for performing multidimensional matching of the abnormal security data and each strategy item in the encryption strategy dynamic adjustment set, generating a matching degree of real-time data and each encryption strategy item, and selecting an encryption strategy corresponding to the highest matching degree as a target adjustment strategy; a strategy adjustment module, which is used for receiving the target adjustment strategy, calling a preset strategy adjustment protocol in a security strategy database, and driving an encryption engine to perform an encryption strategy correction operation.

2. The dynamic encryption network security management system based on federated learning according to claim 1, characterized in that: The network flow data and the encryption state data are collected in real time through the distributed node equipment, and the specific process is as follows: a unique identification code of the distributed node is recognized, if the node is a newly accessed node, basic network parameters including an initial flow density, an encryption intensity benchmark value and a delay control range are collected, a security characteristic node is established based on the first data and parameter calibration is performed, and flow characteristic values are generated; if the node is a historically accessed node, a historical network data set and a security state change curve of the node are extracted, the historical network data set includes flow fluctuation extreme values, encryption deviation records and delay control delay time lengths, and is marked as an initial parameter set for current security analysis.

3. The dynamic encryption network security management system based on federated learning according to claim 1, characterized in that: The encryption strategy dynamic adjustment set is generated based on the initial encryption strategy set stored in the security strategy database, and the specific process comprises the following steps: initial standard sets and dynamic correction coefficient sets of each encryption strategy are extracted from the security strategy database, the initial standard sets include a flow density security range, an encryption intensity fluctuation tolerance interval and a delay adjustment benchmark value; the dynamic correction coefficient sets include a flow density compensation coefficient, an encryption intensity gradient adjustment coefficient and a delay response weight parameter; based on real-time encryption dynamic parameter characteristic values, the initial standard sets of each encryption strategy are dynamically adjusted, and the adjusted strategy set is recorded as the encryption strategy dynamic adjustment set; the encryption strategy dynamic adjustment set includes a flow dynamic range, an encryption intensity adaptability threshold and a delay optimization control value of each strategy item.

4. The dynamic encryption network security management system based on federated learning according to claim 3, characterized in that: Based on the flow characteristic values, personalized encryption strategies of a current network environment are processed and a dynamic security control strategy is generated, and the specific process comprises the following steps: mode matching is performed on the flow characteristic values and a preset security strategy feature library to determine an encryption strategy adjustment priority sequence; an adaptive control strategy containing a strategy triggering condition, an adjustment step rule and a fault processing mechanism is generated based on the adjustment priority sequence.

5. The dynamic encryption network security management system based on federated learning according to claim 4, characterized in that: Real-time security state data in a network communication process are acquired through an encryption sensor, and the specific process comprises the following steps: Monitoring real-time sensor data stream of encryption process implementation, including encryption key change value, security uniformity index and delay fluctuation value; When the real-time sensor data stream exceeds the preset qualified security range, activating the abnormality marker and extracting the security data of the abnormal period as effective monitoring data.

6. The dynamic encryption network security management system based on federated learning according to claim 4, characterized in that: The matching degree of the generated real-time data and each encryption policy item, specifically includes: Analyzing the key deviation amount, uniformity change gradient and delay fluctuation amplitude in the abnormal security data, and respectively performing difference calculation with the flow dynamic range, encryption strength adaptability threshold and delay optimization control value of each encryption policy; Generating the matching degree index of the real-time data and each encryption policy item based on the difference calculation result.

7. The dynamic encryption network security management system based on federated learning according to claim 3, characterized in that: The encryption policy corresponding to the highest matching degree is selected as the target adjustment strategy, specifically including: Establishing a matching degree sorting list of each encryption policy item, and selecting the policy item corresponding to the first matching degree in the list; If the first matching degree is lower than the preset adjustment trigger threshold, the standby strategy set is called and the matching degree calculation is performed again.

8. The dynamic encryption network security management system based on federated learning according to claim 6, characterized in that: The matching degree index of the real-time data and each encryption policy item is generated based on the difference calculation result, and the specific processing process is: Using a multi-dimensional matching algorithm to standardize the flow difference, encryption strength difference and delay deviation, and generating an encryption policy matching degree value ranging from 0 to 100; The closer the matching degree value is to 100, the stronger the adaptability of the real-time data to the encryption policy.

9. The dynamic encryption network security management system based on federated learning according to claim 1, wherein: Also including a strategy self-learning module, specifically including: Recording the security state feedback data after each policy adjustment, including actual key uniformity, security strength change and delay control effect; Performing reverse verification on the feedback data and the encryption policy dynamic adjustment set, generating a policy correction factor and updating it to the dynamic correction coefficient set of the security policy database.

10. The dynamic encryption network security management system based on federated learning according to claim 9, characterized in that: The generation of the policy correction factor, specifically includes: Based on the deviation degree of the feedback data and the expected security target, calculating the flow compensation factor, encryption strength adjustment factor and delay optimization weight; Using an exponentially weighted average algorithm to dynamically smooth the historical correction factors and generate a new dynamic correction coefficient set.

Citation Information

Patent Citations

  • Data traffic security defense method based on Internet of Things

    CN118200055A

  • Mine network security operation system

    CN119728294A