Optical fiber network data flow security management and control platform

By deploying dual-modal probes and a trusted execution environment in the fiber optic network, combining spatiotemporal correlation analysis with multi-dimensional decision fusion, and dynamically selecting and optimizing security policies, the dynamic adaptability and automated response issues of the existing fiber optic network security management and control platform are solved, achieving efficient and real-time network security management.

CN120614218AActive Publication Date: 2025-09-09SHENZHEN OPTICAL NETWORK CENTURY TECH CO LTD

Patent Information

Application Number
CN202511124331.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-09-09
Estimated Expiration
2045-08-12

AI Technical Summary

Technical Problem

The existing fiber optic network data flow security management and control platform has problems such as static policies that cannot dynamically adapt to new network attacks, data silos between security devices, and a lack of quantitative evaluation of policy execution effects in the full-process manual operation mode, resulting in low response efficiency and easy to cause secondary failures.

Method used

This comprehensive solution utilizes an environmental perception and secure access module, a multi-dimensional data acquisition module, a situation evolution modeling module, and a dynamic security management and control module. It achieves data acquisition and security isolation through a dual-modal probe deployment unit and a trusted execution environment unit. It utilizes a spatiotemporal correlation analysis engine and a multi-dimensional decision fusion center for real-time data analysis and prediction, dynamically selecting the optimal protection strategy and implementing adaptive tuning.

Benefits of technology

It realizes real-time monitoring and dynamic security management of fiber optic network data flow, can automatically adapt to sudden network threats, eliminate response delays, improve the ability to identify complex risks, and realize the continuous evolution of system autonomy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614218A_ABST
    Figure CN120614218A_ABST
Patent Text Reader

Abstract

The invention discloses an optical fiber network data flow security management and control platform, and particularly relates to the field of data analysis, which comprises an environment perception and security access module, a multi-dimensional data acquisition module, a situation evolution modeling module and a dynamic security management and control module. Through a dynamic probe and a hardware-level encryption mechanism, millisecond-level threat monitoring and adaptive strategy adjustment from a physical layer to a protocol layer are realized, and response delay is thoroughly eliminated; based on a multi-dimensional data fusion engine, flow characteristics, device states and security events are analyzed in a collaborative manner, and the composite risk identification precision is significantly improved. Weight parameter optimization and strategy loading are automatically executed by relying on strategy sandbox pre-verification and an efficiency feedback closed loop, manual intervention is comprehensively replaced, and autonomous continuous evolution of the system is achieved while the control precision is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data analysis technology, and more specifically, to a fiber optic network data flow security management and control platform. Background Art

[0002] The current mainstream solution in the industry adopts a model that combines static pre-configured access control lists (ACLs) with dispersed independent security devices (such as border firewalls, intrusion detection systems, traffic probes, etc.). Its typical operating process is as follows: basic network traffic feature data is periodically collected through hardware probes in fixed locations, and independent security devices match abnormal features based on preset rule bases; when potential threats are detected, an alarm is generated to notify operation and maintenance personnel, and ultimately the administrator relies on manual login to different device interfaces to adjust policies or isolate nodes.

[0003] This technical architecture has fundamental flaws: static policies cannot dynamically adapt to new network attack behaviors, resulting in a time window of minutes from the emergence of threats to the effectiveness of policies; data silos between security devices lead to the fragmented analysis of traffic characteristics, device health status (such as polarization mode dispersion, cache overload) and security event logs, making it difficult to identify cross-level complex risks; the full-process manual operation mode lacks quantitative evaluation of policy execution effects, which not only leads to low response efficiency but also makes it more likely to cause secondary failures due to human errors. Summary of the Invention

[0004] In order to overcome the above-mentioned defects of the prior art, the present invention provides a fiber optic network data flow security management and control platform, which solves the problems raised in the above-mentioned background technology through the following solutions.

[0005] To achieve the above objectives, the present invention provides the following technical solutions: a fiber optic network data flow security management and control platform, comprising: Environmental Perception and Secure Access Module: This module includes a dual-modal probe deployment unit and a trusted execution environment unit. The dual-modal probe deployment unit is used to deploy specialized probes at core nodes and key access nodes in the optical fiber network to build a data collection environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for raw data. Multi-dimensional data acquisition module: This module uses dual-modal probes to implement full-area monitoring of the optical fiber network, including a traffic feature extraction unit, an equipment status monitoring unit, and a security event capture unit. Situation Evolution Modeling Module: This module transforms raw traffic data into dynamic control strategies through multi-stage feature extraction and decision fusion. It includes a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and a flexible policy sandbox. Dynamic security management and control module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism with performance verification, the policy execution unit dynamically selects the optimal protection strategy and implements adaptive tuning, and combines this with the feedback adjustment unit to continuously optimize the strategy matrix.

[0006] Preferably, the dual-mode probe deployment unit uses a tunable optical add-drop multiplexer at the physical layer to implement non-intrusive traffic mirroring; enables the IEEE 802.3ah EFM protocol at the protocol layer to implement link-level monitoring; and the environment constrains network delay to be within 2ms, and the optical power fluctuation range is ≤±0.5dBm.

[0007] Preferably, the trusted execution environment unit integrates an SGX encryption module in the acquisition terminal and establishes a whitelist access mechanism to only authorize the security policy configuration engine to access encrypted data.

[0008] Preferably, the traffic feature extraction unit is used to collect peak traffic, mean traffic and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; the equipment status monitoring unit is used to collect the polarization mode dispersion value of the optical terminal, the switch cache utilization and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the abnormality of the traffic signature.

[0009] Preferably, the traffic feature extraction unit non-invasively collects the trunk optical fiber traffic through a tunable optical add-drop multiplexer, and uses a built-in programmable light source module to periodically emit a wavelength tunable test optical signal covering the C-band 1525nm to 1565nm, and at the same time uses a high-sensitivity polarization state analyzer to analyze the Stokes parameters of the optical signal in real time and calculate the polarization mode dispersion value and the differential group delay value; obtains a full traffic copy through the switch mirror port, uses deep packet inspection technology to parse the transport layer protocol header field to generate a five-tuple flow feature vector, and adds a pseudo-wire label parsing unit for the multi-protocol label switching network to identify the second layer tunnel protocol session field to achieve logical isolation of business flows; processes the traffic timing data through the Fourier transform algorithm to collect the fundamental frequency amplitude characteristics; calculates the peak traffic and mean traffic by the traffic extreme values ​​within the statistical period, and collects the burst coefficient based on the ratio of the two; and realizes the timing alignment of active detection data and passive traffic data through a timestamp dedicated control channel.

[0010] Preferably, the device status monitoring unit collects polarization mode dispersion values ​​through the polarization analysis sensor built into the optical terminal to monitor the degree of degradation of the physical layer performance of the optical fiber link in real time; collects the real-time status register value of the data plane cache chip through the switch management interface to calculate the cache utilization; continuously records neighbor state machine jump events through the border gateway protocol session monitoring probe, counts the number of session oscillations within a preset time window to collect the border gateway protocol oscillation frequency; continuously monitors the optical signal intensity fluctuation value of the splitting link through the optical power meter to ensure that the sensitivity of the receiving end is not less than -24dBm; collects the splitting ratio configuration parameters and the main link signal attenuation value through the control plane interface of the tunable optical add / drop multiplexer.

[0011] Preferably, the security event capture unit collects the number of policy violations through a real-time matching engine of a predefined policy rule base, which continuously compares traffic behavior with security baseline policy entries; extracts payload feature fingerprints through a deep packet inspection engine and performs similarity matching with a threat feature library, and collects traffic signature anomalies based on the accumulated offset value.

[0012] Preferably, the time-space correlation analysis engine fuses the time-domain differential characteristics of the traffic burst coefficient β with the fundamental frequency amplitude A f The frequency domain integral deviation is used to generate the traffic anomaly index, which is specifically expressed as: ,Ψ t : Traffic anomaly index, : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weight factors, T: reference spectrum calibration period.

[0013] Preferably, the multidimensional decision fusion center is based on the traffic anomaly index Ψ t The real-time coupling relationship with the device status data performs multi-threshold branch judgment and drives the hidden Markov model to output the network security status prediction value S t+1 ∈{N,A,C}, specifically expressed as: when Ψ t >Θ high And U buf When the rate is >85%, the emergency control strategy is triggered. high : Emergency response threshold, Θ low : Baseline alarm threshold, U buf : Switch cache utilization, when Θ low <Ψ t ≤Θ high When , the hidden Markov state prediction model is started, which is specifically expressed as: , N: normal state, A: warning state, C: crisis state, V pol : number of policy violations, δ sig : Traffic signature abnormality.

[0014] Preferably, the elastic strategy sandbox is based on the predicted state S t+1 Construct candidate strategy set {P1,P2,...,P k}, quantitatively calculate the strategy effectiveness index E through the traffic simulator k , complete the packet loss risk prediction before strategy deployment, specifically expressed as: ,τ: policy effectiveness delay, R drop : Simulated packet loss rate, ΔΨ t : Traffic anomaly index change rate.

[0015] Preferably, the policy execution unit receives the candidate policy set {P1, P2, ..., P k} and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th is the preset performance threshold. When executed, t When the drop rate does not meet expectations, the strategy weight learning algorithm is activated, which is specifically expressed as follows: ,η: learning rate,w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.

[0016] Preferably, the feedback adjustment unit receives the policy execution result data packet from the policy execution unit and organizes it into a policy effectiveness triplet {E k ,ΔΨ t ,R drop}, and store it in the strategy effectiveness matrix of the ring buffer architecture with the timestamp as the index; when the Euclidean distance similarity calculation result Sim of five consecutive strategy records in the strategy effectiveness matrix PEM When the preset threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered, which deletes redundant policies and generates a new weighted policy set, while resetting the storage queue of the policy effectiveness matrix.

[0017] The technical effects and advantages of the present invention are as follows: 1. This invention uses the dynamic deployment mechanism of intelligent probes in the environmental perception module and the hardware-level encrypted channel technology of the security access module to achieve millisecond-level real-time monitoring of everything from physical layer optical signal characteristics to transport layer protocol behavior. This enables security policies to automatically adapt to dynamic threats such as sudden DDoS attacks and port scanning, completely eliminating the response delay defects of traditional solutions. 2. The present invention relies on a unified analysis engine built on a multi-dimensional data collection module, deeply integrating traffic characteristics, real-time device status, and security event logs to establish a correlation analysis model across the optical transport layer, network layer, and application layer, significantly improving the ability to accurately identify complex risks such as cache overflow-induced BGP routing oscillations; 3. The present invention is based on the policy sandbox pre-verification mechanism of the situation modeling module and the closed-loop optimization system of the dynamic control module. By automatically executing policy effectiveness evaluation, weight parameter feedback adjustment and dynamic loading of optimized policies, it completely replaces the manual policy intervention link, ensuring the accuracy of access control while realizing the continuous evolution of system autonomy. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is a schematic diagram of the overall structure of the present invention.

[0019] Figure 2 This is a structural diagram of the situation evolution modeling module of the present invention.

[0020] Figure 3 This is a schematic diagram of the structure of the dynamic security management and control module of the present invention. DETAILED DESCRIPTION

[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0022] refer to Figure 1-Figure 3 The optical fiber network data flow security management and control platform shown includes: Environmental perception and secure access module: includes a dual-modal probe deployment unit and a trusted execution environment unit. The dual-modal probe deployment unit is used to deploy dedicated probes at the core nodes and key access nodes of the optical fiber network to build a data collection environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for the original data.

[0023] The dual-modal probe deployment unit uses a tunable optical add-drop multiplexer at the physical layer to implement non-intrusive traffic mirroring; enables the IEEE 802.3ah EFM protocol at the protocol layer to implement link-level monitoring; and environmentally constrains network latency to be within 2ms, with an optical power fluctuation range of ≤±0.5dBm.

[0024] What needs to be specifically explained in this embodiment is that the core node is the cross-regional traffic scheduling hub of the backbone network, and the key access node is the metropolitan edge business traffic aggregation point. The two achieve collaborative monitoring through dual-modal probes: the core node focuses on physical layer performance, and the access node focuses on business flow characteristics.

[0025] The trusted execution environment unit integrates the SGX encryption module in the acquisition terminal and establishes a whitelist access mechanism to only authorize the security policy configuration engine to access encrypted data.

[0026] Multi-dimensional data acquisition module: Implements full-area monitoring of the optical fiber network through dual-modal probes, including a traffic feature extraction unit, an equipment status monitoring unit, and a security event capture unit.

[0027] The traffic feature extraction unit is used to collect peak traffic, mean traffic and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; the equipment status monitoring unit is used to collect the polarization mode dispersion value of the optical terminal, the switch cache utilization and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the abnormality of the traffic signature.

[0028] The traffic feature extraction unit collects trunk optical fiber traffic through non-invasive optical splitting using a tunable optical add-drop multiplexer, and uses a built-in programmable light source module to periodically emit a wavelength-tunable test optical signal covering the C-band range of 1525nm to 1565nm. At the same time, a high-sensitivity polarization state analyzer is used to analyze the Stokes parameters of the optical signal in real time and calculate the polarization mode dispersion value and the differential group delay value. A full traffic copy is obtained through the switch mirror port, and deep packet inspection technology is used to parse the transport layer protocol header field to generate a five-tuple flow feature vector. A pseudo-wire label parsing unit is added to the multi-protocol label switching network to identify the second layer tunnel protocol session field to achieve logical isolation of business flows. The traffic timing data is processed by a Fourier transform algorithm to collect fundamental frequency amplitude characteristics. The peak traffic and mean traffic are calculated by counting the traffic extreme values ​​within the period, and the burst coefficient is collected based on the ratio of the two. At the same time, the timing alignment of active detection data and passive traffic data is achieved through a timestamp dedicated control channel.

[0029] The device status monitoring unit collects polarization mode dispersion values ​​through the polarization analysis sensor built into the optical terminal to monitor the degree of degradation of the physical layer performance of the optical fiber link in real time; collects the real-time status register value of the data plane cache chip through the switch management interface to calculate the cache utilization rate; continuously records neighbor state machine jump events through the Border Gateway Protocol session monitoring probe, counts the number of session oscillations within a preset time window, and collects the Border Gateway Protocol oscillation frequency; continuously monitors the optical signal intensity fluctuation value of the splitting link through the optical power meter to ensure that the sensitivity of the receiving end is not less than -24dBm; and collects the splitting ratio configuration parameters and the main link signal attenuation value through the control plane interface of the tunable optical add-drop multiplexer.

[0030] The security event capture unit collects the number of policy violations through a real-time matching engine of a predefined policy rule base, which continuously compares traffic behavior with security baseline policy entries; extracts payload feature fingerprints through a deep packet inspection engine and performs similarity matching on a threat feature base, and collects traffic signature anomalies based on the accumulated offset value.

[0031] Situation Evolution Modeling Module: This module transforms raw traffic data into dynamic management and control strategies through multi-stage feature extraction and decision fusion. It includes a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and a flexible policy sandbox.

[0032] The time-space correlation analysis engine integrates the time-domain differential characteristics of the traffic burst coefficient β and the fundamental frequency amplitude A f The frequency domain integral deviation is used to generate the traffic anomaly index, which is specifically expressed as: ,Ψ t : Traffic anomaly index, : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weight factors, T: reference spectrum calibration period.

[0033] The spatiotemporal correlation analysis engine builds an anomaly detection model by integrating the time domain burstiness and frequency domain stability characteristics of traffic. The time partial derivative term of the traffic burst coefficient β is introduced into the formula. , capturing the traffic mutation rate, combined with the time domain integral term of the fundamental frequency amplitude deviation To quantify the cumulative effect of spectrum shift, the dynamic weight factors ω1 and ω2 are adaptively adjusted according to the network load status (initial values ​​0.6 / 0.4). When the network is in a high-load period, the frequency domain weight is automatically increased to 0.7. This model combines the burst traffic characteristics of DDoS attacks (manifested by a sharp increase in β) with the spectrum disturbance characteristics of low-frequency covert attacks (manifested by A f Continued deviation from historical benchmarks ) to conduct joint modeling and output the traffic anomaly index Ψ t .

[0034] The multi-dimensional decision fusion center is based on the traffic anomaly index Ψ t The real-time coupling relationship with the device status data performs multi-threshold branch judgment and drives the hidden Markov model to output the network security status prediction value S t+1 ∈{N,A,C}, specifically expressed as: when Ψ t >Θ high And U buf When the rate is >85%, the emergency control strategy is triggered. high : Emergency response threshold, Θ low : Baseline alarm threshold, U buf : Switch cache utilization, when Θ low <Ψt ≤Θ high When , the hidden Markov state prediction model is started, which is specifically expressed as: , N: normal state, A: warning state, C: crisis state, V pol : number of policy violations, δ sig : Traffic signature abnormality.

[0035] The multidimensional decision fusion center is based on the output of the first stage t and device state parameters, the state transfer function is constructed using branch judgment and hidden Markov model (HMM). t Entering the intermediate threat interval (Θ low <Ψ t ≤Θ high ), according to the number of policy violations V pol and traffic signature anomaly δ sig Calculate the state transition probability P(s|V pol ,δ sig ), the function defines three discrete states: normal state (N), alarm state (A), and crisis state (C), and determines the next state S by maximizing the posterior probability t+1 , the model considers device-level abnormal events (such as U buf >85% of buffer overflow risk) and application layer threat indicators (such as δ sig The detected protocol malformed packets are mapped into a unified state space.

[0036] The elastic policy sandbox is based on the predicted state S t+1 Construct candidate strategy set {P1,P2,...,P k}, quantitatively calculate the strategy effectiveness index E through the traffic simulator k , complete the packet loss risk prediction before strategy deployment, specifically expressed as: ,τ: policy effectiveness delay, R drop : Simulated packet loss rate, ΔΨ t : Traffic anomaly index change rate.

[0037] The elastic policy sandbox is targeted at the predicted state S t+1 Generate candidate strategy set {P k}, through the performance index formula For quantitative evaluation, the numerator ΔΨ t It represents the decrease of abnormal index after the execution of strategy simulation, the denominator τ is the strategy effective delay, and the ratio of the two reflects the control efficiency; the logarithmic term Enhanced packet loss rate R drop Sensitivity (when R drop>15% produces a negative correction). The model verifies the balance of strategies in a virtual environment: it requires rapid suppression of threats (ΔΨ t / τ maximization), while avoiding business interruption (R drop minimize).

[0038] Dynamic security management and control module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism with performance verification, the policy execution unit dynamically selects the optimal protection strategy and implements adaptive tuning, and combines this with the feedback adjustment unit to continuously optimize the strategy matrix.

[0039] The policy execution unit receives a candidate policy set {P1, P2, ..., P k} and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th is the preset performance threshold. When executed, t When the drop rate does not meet expectations, the strategy weight learning algorithm is activated, which is specifically expressed as follows: ,η: learning rate,w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.

[0040] The policy execution unit follows the dual-track mechanism of policy optimization and dynamic tuning. Its physical meaning is to convert policy effectiveness into network status correction to achieve adaptive control. The unit first receives the candidate policy set and the corresponding policy effectiveness index E from the elastic policy sandbox. k , filter E by threshold comparison unit k Exceeds the policy effectiveness threshold E th Eligible strategies (where E th Dynamically calculated by the historical effectiveness data of the strategy effectiveness matrix), when there are multiple qualified strategies, the optimal decision arbitrator is started, based on the minimum simulated packet loss rate R drop and maximize the flow anomaly index decrease rate ΔΨ t The dual-objective optimization principle is used to select the strategy to be executed, and the traffic anomaly index Ψ in the actual network environment is monitored in real time after the strategy is deployed. t When the measured rate of change is lower than the expected threshold, the strategy weight learning algorithm is activated: the weight factor ω in the spatiotemporal correlation analysis engine is dynamically adjusted through the gradient descent mechanism. i , according to the strategy execution feedback, reversely modify the traffic burst parameter β and spectrum offset parameter A fThe contribution weight in the anomaly detection model enables the system to continuously approach the optimal detection state.

[0041] The feedback adjustment unit receives the policy execution result data packet from the policy execution unit and organizes it into a policy effectiveness triplet {E k ,ΔΨ t ,R drop}, and store it in the strategy effectiveness matrix of the ring buffer architecture with the timestamp as the index; when the Euclidean distance similarity calculation result Sim of five consecutive strategy records in the strategy effectiveness matrix PEM When the preset threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered, which deletes redundant policies and generates a new weighted policy set, while resetting the storage queue of the policy effectiveness matrix.

[0042] The present invention starts with the environment perception and security access module, and deploys dedicated probes at the core nodes and key access nodes of the optical fiber network through the dual-modal probe deployment unit to achieve non-intrusive traffic mirroring at the physical layer and link monitoring at the protocol layer. At the same time, the trusted execution environment unit provides hardware-level encryption isolation to ensure data collection security; then the multi-dimensional data acquisition module implements full-area monitoring through the dual-modal probe, the traffic feature extraction unit collects peak traffic, mean traffic, burst coefficient and fundamental frequency amplitude, the equipment status monitoring unit collects the polarization mode dispersion value of the optical terminal, the switch cache utilization and the router BGP oscillation frequency, and the security event capture unit collects the number of policy violations and the abnormality of the traffic signature; then the spatiotemporal and temporal data of the situation evolution modeling module are analyzed. The correlation analysis engine integrates the changes in traffic burst coefficient and fundamental frequency amplitude deviation to generate a traffic anomaly index. The multi-dimensional decision fusion center combines device status data to predict whether the network security status is normal, alarm or crisis. The elastic policy sandbox generates a set of candidate policies based on the predicted status and quantifies the policy effectiveness index through a traffic simulator to evaluate the packet loss risk and the decline in the anomaly index after policy execution. Finally, the policy execution unit of the dynamic security management module selects the candidate policy with the highest effectiveness index for implementation. When the anomaly index decline rate does not meet expectations, the weight learning algorithm is activated to dynamically adjust the analysis engine weight. The feedback adjustment unit stores the policy effectiveness data and triggers the policy merging mechanism to optimize the policy matrix when the policy similarity meets the standard, forming a closed-loop control.

[0043] Secondly: The drawings of the embodiments disclosed in the present invention only involve structures related to the embodiments disclosed in the present invention. Other structures may refer to conventional designs. The same embodiment and different embodiments of the present invention may be combined with each other without conflict. Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A fiber optic network data flow security management and control platform, characterized in that: include: Environmental Perception and Secure Access Module: This module includes a dual-modal probe deployment unit and a trusted execution environment unit. The dual-modal probe deployment unit is used to deploy specialized probes at core nodes and key access nodes in the optical fiber network to build a data collection environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for raw data. Multi-dimensional data acquisition module: This module uses dual-modal probes to implement full-area monitoring of the optical fiber network, including a traffic feature extraction unit, an equipment status monitoring unit, and a security event capture unit. Situation Evolution Modeling Module: This module transforms raw traffic data into dynamic control strategies through multi-stage feature extraction and decision fusion. It includes a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and a flexible policy sandbox. Dynamic security management and control module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism with performance verification, the policy execution unit dynamically selects the optimal protection strategy and implements adaptive tuning, and combines this with the feedback adjustment unit to continuously optimize the strategy matrix.

2. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The traffic feature extraction unit is used to collect peak traffic, mean traffic and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; the equipment status monitoring unit is used to collect the polarization mode dispersion value of the optical terminal, the switch cache utilization and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the abnormality of the traffic signature.

3. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The time-space correlation analysis engine integrates the time-domain differential characteristics of the traffic burst coefficient β and the fundamental frequency amplitude A f The frequency domain integral deviation is used to generate the traffic anomaly index, which is specifically expressed as: ,Ψ t : Traffic anomaly index, : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weight factors, T: reference spectrum calibration period.

4. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The multi-dimensional decision fusion center is based on the traffic anomaly index Ψ t The real-time coupling relationship with the device status data performs multi-threshold branch judgment and drives the hidden Markov model to output the network security status prediction value S t+1 ∈{N,A,C}, specifically expressed as: when Ψ t >Θ high AndU buf When the rate is >85%, the emergency control strategy is triggered. high : Emergency response threshold, Θ low : Baseline alarm threshold, U buf : Switch cache utilization, when Θ low <Ψ t ≤Θ high When , the hidden Markov state prediction model is started, which is specifically expressed as: , N: normal state, A: warning state, C: crisis state, V pol : number of policy violations, δ sig : Traffic signature abnormality.

5. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The elastic policy sandbox is based on the predicted state S t+1 Construct candidate strategy set {P1,P2,...,P k }, quantitatively calculate the strategy effectiveness index E through the traffic simulator k , complete the packet loss risk prediction before strategy deployment, specifically expressed as: ,τ: policy effectiveness delay, R drop : Simulated packet loss rate, ΔΨ t : Traffic anomaly index change rate.

6. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The policy execution unit receives a candidate policy set {P1, P2, ..., P k } and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th is the preset performance threshold. When executed t When the drop rate does not meet expectations, the strategy weight learning algorithm is activated, which is specifically expressed as follows: ,η: learning rate,w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.

7. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The feedback adjustment unit receives the policy execution result data packet from the policy execution unit and organizes it into a policy effectiveness triplet {E k ,ΔΨ t ,R drop }, and store it in the strategy effectiveness matrix of the ring buffer architecture with the timestamp as the index; when the Euclidean distance similarity calculation result Sim of five consecutive strategy records in the strategy effectiveness matrix PEM When the preset threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered, which deletes redundant policies and generates a new weighted policy set, while resetting the storage queue of the policy effectiveness matrix.

8. The optical fiber network data flow security management and control platform according to claim 1, characterized in that: The dual-mode probe deployment unit uses a tunable optical add-drop multiplexer at the physical layer to implement non-intrusive traffic mirroring; the IEEE 802.3ah EFM protocol is enabled at the protocol layer to implement link-level monitoring; the environment constrains network latency to be within 2ms, and the optical power fluctuation range is ≤±0.5dBm; The trusted execution environment unit integrates the SGX encryption module in the acquisition terminal and establishes a whitelist access mechanism to only authorize the security policy configuration engine to access encrypted data.

Citation Information

Patent Citations

  • Substation network security defense system based on artificial intelligence

    CN119276602A

  • Cross-domain network security policy automatic generation and protection policy collaboration method and system

    CN119449428A

  • Intelligent flow measurement and control system of Internet of Things

    CN119802476A

  • Urban network security multi-dimensional monitoring management system and method

    CN120342674A

  • Method for anomaly classification of industrial control system communication network

    US20220269258A1

Cited By

  • Wi-Fi access control method and system based on multidimensional feature fusion and dynamic ACL cooperation

    CN122205425A