A fiber optic network data stream security management platform
The fiber optic network data flow security management platform solves the problems of static policy response delay and data silos, realizes dynamic policy adaptation and system autonomy, and improves network security response efficiency and risk identification capabilities.
Patent Information
- Application Number
- CN202511124331.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-08-12
AI Technical Summary
In existing technologies, static strategies cannot dynamically adapt to new types of network attacks, have minute-level response delays, and the data silos between security devices make it difficult to identify complex risks. Manual operations are inefficient and prone to failure.
The fiber optic network data flow security management platform is adopted, which realizes dynamic policy adaptation, cross-level risk identification and system autonomy through environmental perception and security access module, multi-dimensional data acquisition module, situation evolution modeling module and dynamic security management module.
It achieves millisecond-level dynamic threat response, accurately identifies complex risks, and automates policy optimization, thereby improving network security response efficiency and reliability.
Smart Images

Figure CN120614218B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data analysis technology, and more specifically, to a secure management and control platform for fiber optic network data streams. Background Art
[0002] The current mainstream solution in the industry adopts a combination of statically pre-configured access control lists (ACLs) and distributed independent security devices (such as perimeter firewalls, intrusion detection systems, traffic probes, etc.). Its typical operation process is as follows: hardware probes at fixed locations periodically collect basic network traffic characteristic data, and independent security devices perform abnormal feature matching based on pre-configured rule bases; when a potential threat is detected, an alarm is generated to notify the operation and maintenance personnel, and finally, the administrator has to manually log in to the interfaces of different devices to adjust policies or isolate nodes.
[0003] The technical architecture has fundamental flaws: static policies cannot dynamically adapt to new network attack behaviors, resulting in a minute-level time window from the emergence of a threat to the effective implementation of the policy; the data silos between security devices lead to fragmented analysis of traffic characteristics, device health status (such as polarization mode dispersion, cache overload), and security event logs, making it difficult to identify complex risks across multiple levels; the manual operation mode throughout the entire process lacks quantitative evaluation of the policy execution effect, which not only results in low response efficiency but also makes it easy for secondary failures to be caused by human error. Summary of the Invention
[0004] To overcome the aforementioned deficiencies in the prior art, the present invention provides a fiber optic network data flow security management platform, which addresses the problems mentioned in the background section through the following solutions.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a fiber optic network data flow security management platform, comprising:
[0006] Environmental awareness and secure access module: includes a dual-mode probe deployment unit and a trusted execution environment unit. The dual-mode probe deployment unit is used to deploy dedicated probes at the core nodes and key access nodes of the optical fiber network to build a data acquisition environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for the raw data.
[0007] Multi-dimensional data acquisition module: Implements full-domain monitoring of the fiber optic network through dual-modal probes, including a traffic feature extraction unit, a device status monitoring unit, and a security event capture unit;
[0008] Situation Evolution Modeling Module: Through multi-stage feature extraction and decision fusion, raw traffic data is transformed into dynamic control strategies, including a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and an elastic strategy sandbox.
[0009] Dynamic security management module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism for performance verification, the policy execution unit dynamically selects the optimal protection policy and implements adaptive optimization, while the feedback adjustment unit continuously optimizes the policy matrix.
[0010] Preferably, the dual-mode probe deployment unit uses a tunable optical add-drop multiplexer at the physical layer to achieve non-intrusive traffic mirroring; it enables the IEEE 802.3ah EFM protocol at the protocol layer to achieve link-level monitoring; and the environmental constraints limit network latency to within 2ms and optical power fluctuation range to ≤±0.5dBm.
[0011] Preferably, the trusted execution environment unit integrates an SGX encryption module into the acquisition terminal and establishes a whitelist access mechanism, authorizing only the security policy configuration engine to access encrypted data.
[0012] Preferably, the traffic feature extraction unit is used to collect peak traffic, average traffic, and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; the device status monitoring unit is used to collect the polarization mode dispersion value of the optical transceiver, the switch cache utilization rate, and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the traffic signature anomaly degree.
[0013] Preferably, the traffic feature extraction unit non-invasively collects backbone fiber traffic through a tunable optical add-drop multiplexer, periodically emits tunable test optical signals covering the C-band from 1525nm to 1565nm using a built-in programmable light source module, and simultaneously analyzes the Stokes parameters of the optical signals in real time and calculates the polarization mode dispersion and differential group delay values using a high-sensitivity polarization state analyzer; obtains a full traffic copy through the switch mirror port, uses deep packet inspection technology to parse the transport layer protocol header fields to generate a five-tuple flow feature vector, and adds a pseudo-wire tag parsing unit for multi-protocol label switching networks to identify the second-layer tunnel protocol session fields to achieve logical isolation of service flows; processes the traffic time-series data using a Fourier transform algorithm to collect fundamental frequency amplitude characteristics; calculates peak traffic and average traffic by traffic extreme values within a statistical period, and collects the burst coefficient based on their ratio; and simultaneously achieves time-series alignment of active probe data and passive traffic data through a dedicated timestamp control channel.
[0014] Preferably, the device status monitoring unit collects polarization mode dispersion values through the polarization analysis sensor built into the optical transceiver to monitor the physical layer performance degradation of the optical fiber link in real time; it collects the real-time status register values of the data plane cache chip through the switch management interface to calculate the cache utilization rate; it continuously records neighbor state machine transition events through the border gateway protocol session monitoring probe and collects the border gateway protocol oscillation frequency by counting the number of session oscillations within a preset time window; it continuously monitors the optical signal intensity fluctuation value of the splitter link through the optical power meter to ensure that the receiver sensitivity is not lower than -24dBm; and it collects the splitting ratio configuration parameters and the main link signal attenuation value through the control plane interface of the tunable optical add-drop multiplexer.
[0015] Preferably, the security event capture unit collects the number of policy violations through a real-time matching engine of a predefined policy rule base. This engine continuously compares traffic behavior with security baseline policy entries; it extracts payload feature fingerprints through a deep packet inspection engine and performs similarity matching with a threat feature database, and collects traffic signature anomaly based on the cumulative offset value.
[0016] Preferably, the spatiotemporal correlation analysis engine integrates the temporal differential characteristics of the traffic burst coefficient β with the fundamental frequency amplitude A. f The frequency domain integral deviation is used to generate a traffic anomaly index, specifically expressed as: Ψ t Traffic anomaly index : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weighting factors, T: reference spectrum calibration period.
[0017] Preferably, the multidimensional decision fusion center is based on the traffic anomaly index Ψ t The system is coupled with real-time device status data to perform multi-threshold branch judgments and drive the Hidden Markov Model, outputting a network security status prediction value S. t+1 ∈{N,A,C}, specifically represented as: when Ψ t >Θ high And U buf When the threshold is >85%, an emergency control strategy is triggered. high Emergency response threshold, Θ low Baseline alarm threshold, U buf : Switch buffer utilization, when Θ low <Ψ t ≤Θ high At that time, the Hidden Markov State Prediction Model is activated, specifically as follows: N: Normal state, A: Alarm state, C: Crisis state, V pol : Number of strategy violations, δ sig Traffic signature anomaly level.
[0018] Preferably, the elastic strategy sandbox is based on the predicted state S t+1 Construct a candidate policy set {P1, P2, ..., P} k The strategy effectiveness index E is calculated quantitatively using a traffic simulator. k Before deploying the strategy, packet loss risk prediction is completed, specifically as follows: τ: Policy activation delay, R drop Simulated packet loss rate, ΔΨ t : Rate of change of traffic anomaly index.
[0019] Preferably, the strategy execution unit receives the candidate strategy set {P1, P2, ..., P} from the elastic strategy sandbox. k} and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th To preset the performance threshold, after execution Ψ t When the rate of decline does not meet expectations, the policy weight learning algorithm is activated, specifically as follows: η: learning rate, w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.
[0020] Preferably, the feedback adjustment unit receives a policy execution result data packet from the policy execution unit and organizes it into a policy performance triple {E} according to a predefined data structure. k ,ΔΨ t ,R drop The policy performance matrix, indexed by timestamps, is stored in a circular buffer architecture. When the Euclidean distance similarity calculation results of five consecutive policy records in the policy performance matrix are Sim... PEM When the threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered. This mechanism will delete redundant policies and generate a new weighted policy set, while resetting the storage queue of the policy performance matrix.
[0021] The technical effects and advantages of this invention are as follows:
[0022] 1. This invention achieves millisecond-level real-time monitoring of physical layer optical signal characteristics to transport layer protocol behavior through the intelligent probe dynamic deployment mechanism of the environmental perception module and the hardware-level encryption channel technology of the security access module. This enables security policies to automatically adapt to dynamic threats such as sudden DDoS attacks and port scans, and completely eliminates the response delay defects of traditional solutions.
[0023] 2. This invention relies on a unified analysis engine built on a multi-dimensional data acquisition module, which deeply integrates traffic characteristics, real-time device status and security event logs, and establishes a correlation analysis model across the optical transmission layer, network layer and application layer, significantly improving the ability to accurately identify complex risks such as buffer overflow-induced BGP route oscillation.
[0024] 3. The present invention is based on a strategy sandbox pre-verification mechanism of the situation modeling module and a closed-loop optimization system of the dynamic control module. By automatically executing strategy performance evaluation, weight parameter feedback adjustment and dynamic loading of optimization strategies, it completely replaces the manual strategy intervention link, and achieves the autonomous continuous evolution of the system while ensuring the accuracy of access control. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the overall structure of the present invention.
[0026] Figure 2 This is a schematic diagram of the situation evolution modeling module of the present invention.
[0027] Figure 3 This is a schematic diagram of the dynamic safety management module structure of the present invention. Detailed Implementation
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0029] refer to Figures 1-3 The fiber optic network data flow security management platform shown includes:
[0030] The environmental awareness and secure access module includes a dual-mode probe deployment unit and a trusted execution environment unit. The dual-mode probe deployment unit is used to deploy dedicated probes at the core nodes and key access nodes of the fiber optic network to build a data acquisition environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for the raw data.
[0031] The dual-mode probe deployment unit uses a tunable optical add-drop multiplexer at the physical layer to achieve non-intrusive traffic mirroring; it enables the IEEE 802.3ah EFM protocol at the protocol layer to achieve link-level monitoring; the environment constrains network latency to within 2ms and optical power fluctuation range to ≤±0.5dBm.
[0032] In this embodiment, it should be specifically noted that the core node is a cross-regional traffic scheduling hub of the backbone network, and the key access node is a metropolitan area edge service traffic aggregation point. The two achieve collaborative monitoring through dual-modal probes: the core node focuses on physical layer performance, and the access node focuses on service flow characteristics.
[0033] The Trusted Execution Environment (TEX) unit integrates an SGX encryption module into the acquisition terminal and establishes a whitelist access mechanism, authorizing only the security policy configuration engine to access encrypted data.
[0034] Multi-dimensional data acquisition module: Implements full-domain monitoring of the fiber optic network through dual-modal probes, including a traffic feature extraction unit, an equipment status monitoring unit, and a security event capture unit.
[0035] The traffic feature extraction unit is used to collect peak traffic, average traffic, and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; the device status monitoring unit is used to collect the polarization mode dispersion value of the optical transceiver, the switch cache utilization rate, and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the traffic signature anomaly degree.
[0036] The traffic feature extraction unit non-invasively collects backbone fiber traffic through a tunable optical add-drop multiplexer. It periodically emits tunable test optical signals covering the C-band from 1525nm to 1565nm using a built-in programmable light source module. Simultaneously, a high-sensitivity polarization state analyzer analyzes the Stokes parameters of the optical signals in real time and calculates the polarization mode dispersion and differential group delay values. A full traffic copy is obtained through the switch's mirror port. Deep packet inspection technology is used to parse the transport layer protocol header fields to generate a five-tuple flow feature vector. For multi-protocol label switching networks, a pseudo-wire label parsing unit is added to identify the Layer 2 tunneling protocol session fields to achieve logical isolation of service flows. Fourier transform algorithms are used to process the traffic time-series data to collect fundamental frequency amplitude characteristics. Peak and average traffic are calculated based on traffic extremes within a statistical period, and the burst coefficient is collected based on their ratio. Simultaneously, a dedicated timestamp control channel is used to achieve time-series alignment between active probe data and passive traffic data.
[0037] The device status monitoring unit collects polarization mode dispersion values through the polarization analysis sensor built into the optical transceiver to monitor the physical layer performance degradation of the optical fiber link in real time; it collects the real-time status register values of the data plane cache chip through the switch management interface to calculate the cache utilization rate; it continuously records neighbor state machine transition events through the border gateway protocol session monitoring probe and collects the border gateway protocol oscillation frequency by counting the number of session oscillations within a preset time window; it continuously monitors the optical signal intensity fluctuation value of the splitter link through the optical power meter to ensure that the receiver sensitivity is not lower than -24dBm; and it collects the splitting ratio configuration parameters and the main link signal attenuation value through the control plane interface of the tunable optical add-drop multiplexer.
[0038] The security event capture unit collects the number of policy violations through a real-time matching engine based on a predefined policy rule base. This engine continuously compares traffic behavior with security baseline policy entries. It also extracts payload feature fingerprints through a deep packet inspection engine and performs similarity matching with a threat feature database, collecting traffic signature anomaly based on the cumulative offset value.
[0039] Situation Evolution Modeling Module: Through multi-stage feature extraction and decision fusion, raw traffic data is transformed into dynamic management and control strategies, including a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and an elastic strategy sandbox.
[0040] The spatiotemporal correlation analysis engine integrates the time-domain differential characteristics of the traffic burst coefficient β with the fundamental frequency amplitude A. f The frequency domain integral deviation is used to generate a traffic anomaly index, specifically expressed as: Ψ t Traffic anomaly index : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weighting factors, T: reference spectrum calibration period.
[0041] The spatiotemporal correlation analysis engine constructs an anomaly detection model by fusing the temporal burstiness and frequency stability characteristics of traffic, and the formula incorporates the time partial derivative of the traffic burst coefficient β. Capture the rate of change in flow rate, combined with the time-domain integral term of the fundamental frequency amplitude deviation. The cumulative effect of quantified spectrum shift is assessed, with dynamic weighting factors ω1 and ω2 adaptively adjusted based on network load (initial values 0.6 / 0.4). During periods of high network load, the frequency domain weight is automatically increased to 0.7. This model combines the burst traffic characteristics of DDoS attacks (manifested as a sharp increase in β) with the spectral perturbation characteristics of low-frequency covert attacks (manifested as A...). f Continuous deviation from historical benchmark Joint modeling is performed to output the traffic anomaly index Ψ. t .
[0042] The multidimensional decision fusion center is based on the traffic anomaly index Ψ t The system is coupled with real-time device status data to perform multi-threshold branch judgments and drive the Hidden Markov Model, outputting a network security status prediction value S. t+1 ∈{N,A,C}, specifically represented as: when Ψ t >Θ high And U buf When the threshold is >85%, an emergency control strategy is triggered. high Emergency response threshold, Θ low Baseline alarm threshold, U buf : Switch buffer utilization, when Θ low <Ψt ≤Θ high At that time, the Hidden Markov State Prediction Model is activated, specifically as follows: N: Normal state, A: Alarm state, C: Crisis state, V pol : Number of strategy violations, δ sig Traffic signature anomaly level.
[0043] The multidimensional decision fusion center is based on the Ψ output of the first stage. t And the equipment state parameters, using branch decision and Hidden Markov Model (HMM) to construct the state transition function, when Ψ t Entering the intermediate threat zone (Θ) low <Ψ t ≤Θ high When V is violated, the strategy is considered. pol and traffic signature anomaly degree δ sig Calculate the state transition probability P(s|V) pol ,δ sig This function defines three discrete states: normal (N), alarm (A), and crisis (C), and determines the next state S by maximizing the posterior probability. t+1 This model will handle device-level abnormal events (such as U...) buf >85% cache overflow risk) and application-layer threat indicators (such as delta) sig The detected protocol malformed messages are mapped to a unified state space.
[0044] The elastic strategy sandbox is based on the predicted state S. t+1 Construct a candidate policy set {P1, P2, ..., P} k The strategy effectiveness index E is calculated quantitatively using a traffic simulator. k Before deploying the strategy, packet loss risk prediction is completed, specifically as follows: τ: Policy activation delay, R drop Simulated packet loss rate, ΔΨ t : Rate of change of traffic anomaly index.
[0045] The elastic strategy sandbox is for predicting state S. t+1 Generate a candidate policy set {P} k}, through the efficiency index formula To conduct a quantitative assessment, the numerator term ΔΨ t The ratio of the two terms represents the decrease in the abnormal exponent after the strategy simulation is executed, with the denominator τ being the strategy's effective delay. The logarithmic term represents the control efficiency. Strengthening the packet loss rate R drop Sensitivity (when R) drop(A negative correction is generated when the threshold is >15%). The model verifies the balance of the strategy in a virtual environment: requiring both rapid threat suppression (ΔΨ) and [the ability to] quickly suppress threats. t To maximize / τ, it is also necessary to avoid business interruption (R). drop minimize).
[0046] Dynamic security management module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism for performance verification, the policy execution unit dynamically selects the optimal protection policy and implements adaptive optimization, while the feedback adjustment unit continuously optimizes the policy matrix.
[0047] The strategy execution unit receives the candidate strategy set {P1, P2, ..., P} from the elastic strategy sandbox. k} and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th To preset the performance threshold, after execution Ψ t When the rate of decline does not meet expectations, the policy weight learning algorithm is activated, specifically as follows: η: learning rate, w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.
[0048] The policy execution unit follows a dual-track mechanism of policy selection and dynamic tuning. Its physical meaning lies in converting policy effectiveness into network state correction quantities to achieve adaptive control. This unit first receives a set of candidate policies and the corresponding policy effectiveness index E from the elastic policy sandbox. k E is filtered by threshold comparison unit k Exceeding the policy activation threshold E th Qualified strategies (where E) th (Dynamically calculated from historical performance data of the strategy performance matrix) When multiple qualified strategies exist, the optimal decision arbitrator is activated, based on minimizing the simulated packet loss rate R. drop With the maximum flow anomaly index decline rate ΔΨ t The dual-objective optimization principle selects the strategy to be executed, and after the strategy is deployed, the traffic anomaly index Ψ in the actual network environment is monitored in real time. t The rate of change is activated when the measured rate of decline is lower than the expected threshold. The strategy weight learning algorithm dynamically adjusts the weight factor ω in the spatiotemporal correlation analysis engine through a gradient descent mechanism. i Based on the feedback from the strategy execution, the traffic burst parameter β and the spectrum offset parameter A are corrected in reverse. fThe contribution weights in the anomaly detection model enable the system to continuously approach the optimal detection state.
[0049] The feedback adjustment unit receives policy execution result data packets from the policy execution unit and organizes them into policy performance triples {E} according to a predefined data structure. k ,ΔΨ t ,R drop The policy performance matrix, indexed by timestamps, is stored in a circular buffer architecture. When the Euclidean distance similarity calculation results of five consecutive policy records in the policy performance matrix are Sim... PEM When the threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered. This mechanism will delete redundant policies and generate a new weighted policy set, while resetting the storage queue of the policy performance matrix.
[0050] This invention begins with an environmental perception and secure access module. A dual-modal probe deployment unit deploys dedicated probes at core and critical access nodes of the fiber optic network, enabling non-intrusive traffic mirroring at the physical layer and protocol-layer link monitoring. Simultaneously, a trusted execution environment unit provides hardware-level encryption isolation to ensure data acquisition security. Next, a multi-dimensional data acquisition module implements comprehensive monitoring through dual-modal probes. A traffic feature extraction unit collects peak traffic, average traffic, burst coefficient, and fundamental frequency amplitude; an equipment status monitoring unit collects optical transceiver polarization mode dispersion, switch buffer utilization, and router BGP oscillation frequency; and a security event capture unit collects policy violation counts and traffic signature anomalies. Finally, a situational evolution modeling module performs spatiotemporal... The correlation analysis engine integrates changes in traffic burst coefficients and fundamental frequency amplitude deviations to generate a traffic anomaly index. The multi-dimensional decision fusion center combines device status data to predict whether the network security status is normal, alarm, or crisis. The elastic policy sandbox generates a set of candidate policies based on the predicted status and quantifies the policy effectiveness index through a traffic simulator to evaluate the packet loss risk and the rate of decrease in the anomaly index after policy execution. Finally, the policy execution unit of the dynamic security management module selects the candidate policy with the highest effectiveness index for implementation. When the rate of decrease in the anomaly index does not meet expectations, the weight learning algorithm is activated to dynamically adjust the weights of the analysis engine. The feedback adjustment unit stores the policy effectiveness data and triggers a policy merging mechanism to optimize the policy matrix when the policy similarity meets the standard, forming a closed-loop control.
[0051] Secondly: The drawings of the embodiments disclosed in the present invention only involve structures related to the embodiments disclosed in the present invention. Other structures may refer to conventional designs. The same embodiment and different embodiments of the present invention may be combined with each other without conflict.
[0052] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A fiber optic network data stream security management and control platform, characterized in that, include: Environmental awareness and secure access module: includes a dual-mode probe deployment unit and a trusted execution environment unit. The dual-mode probe deployment unit is used to deploy dedicated probes at the core nodes and key access nodes of the optical fiber network to build a data acquisition environment. The trusted execution environment unit is used to provide hardware-level encryption isolation for the raw data. Multi-dimensional data acquisition module: Implements full-domain monitoring of the fiber optic network through dual-modal probes, including a traffic feature extraction unit, a device status monitoring unit, and a security event capture unit; The flow feature extraction unit is used to collect peak flow, average flow and burst coefficient, and extract the fundamental frequency amplitude through Fourier transform; The device status monitoring unit is used to collect the polarization mode dispersion value of the optical transceiver, the switch buffer utilization rate, and the router BGP oscillation frequency; the security event capture unit is used to collect the number of policy violations and the abnormality of traffic signatures. Situation Evolution Modeling Module: Through multi-stage feature extraction and decision fusion, the raw traffic data is parsed into dynamic control strategies, including a spatiotemporal correlation analysis engine, a multi-dimensional decision fusion center, and an elastic strategy sandbox. The spatiotemporal correlation analysis engine integrates the time-domain differential characteristics of the traffic burst coefficient β with the fundamental frequency amplitude A. f The frequency domain integral deviation is used to generate a flow anomaly index; The multidimensional decision fusion center is based on the traffic anomaly index Ψ t The system is coupled with real-time device status data to perform multi-threshold branch judgments and drive the Hidden Markov Model, outputting a network security status prediction value S. t+1 ; The elastic strategy sandbox is based on the network security status prediction value S. t+1 Construct a candidate policy set {P1, P2, ..., P} k The strategy effectiveness index E is calculated quantitatively using a traffic simulator. k Complete the packet loss risk prediction before strategy deployment; Dynamic security management module: includes a policy execution unit and a feedback adjustment unit. Based on a closed-loop control mechanism for performance verification, the policy execution unit dynamically selects the optimal protection policy and implements adaptive optimization, while the feedback adjustment unit continuously optimizes the policy matrix.
2. The fiber optic network data flow security management platform according to claim 1, characterized in that: The traffic anomaly index is specifically expressed as follows: Ψ t Traffic anomaly index : Historical fundamental frequency amplitude reference value, ω1, ω2: dynamic weighting factors, T: reference spectrum calibration period.
3. The fiber optic network data flow security management platform according to claim 2, characterized in that: The multidimensional decision fusion center is specifically represented as: when Ψ t >Θ high And U buf When the threshold is >85%, an emergency control strategy is triggered. high Emergency response threshold, Θ low Baseline alarm threshold, U buf : Switch buffer utilization, when Θ low <Ψ t ≤Θ high At that time, the Hidden Markov State Prediction Model is activated, specifically as follows: N: Normal state, A: Alarm state, C: Crisis state, V pol : Number of strategy violations, δ sig Traffic signature anomaly level.
4. The fiber optic network data flow security management platform according to claim 3, characterized in that: The elastic strategy sandbox is specifically represented as follows: τ: Policy activation delay, R drop Simulated packet loss rate, ΔΨ t : Rate of change of traffic anomaly index.
5. The fiber optic network data flow security management platform according to claim 4, characterized in that: The strategy execution unit receives the candidate strategy set {P1, P2, ..., P} from the elastic strategy sandbox. k } and its corresponding strategy effectiveness index E k Value, select E k >E th The optimal strategy, E th To preset the performance threshold, after execution Ψ t When the rate of decline does not meet expectations, the policy weight learning algorithm is activated, specifically as follows: η: learning rate, w i (new) : The updated value of the i-th dynamic weight factor, w i (old) : The current value of the i-th dynamic weight factor, w i : The i-th dynamic weight factor in the spatiotemporal correlation analysis engine.
6. The fiber optic network data flow security management platform according to claim 5, characterized in that: The feedback adjustment unit receives policy execution result data packets from the policy execution unit and organizes them into policy performance triples {E} according to a predefined data structure. k ,ΔΨ t ,R drop The policy performance matrix, indexed by timestamps, is stored in a circular buffer architecture. When the Euclidean distance similarity calculation results of five consecutive policy records in the policy performance matrix are Sim... PEM When the threshold of 0.8 is exceeded, the policy merging mechanism is automatically triggered. This mechanism will delete redundant policies and generate a new weighted policy set, while resetting the storage queue of the policy performance matrix.
7. The fiber optic network data flow security management platform according to claim 1, characterized in that: The dual-mode probe deployment unit employs a tunable optical add-drop multiplexer at the physical layer to achieve non-intrusive traffic mirroring; it enables the IEEE 802.3ah EFM protocol at the protocol layer to achieve link-level monitoring; the environment constrains network latency to within 2ms and optical power fluctuation range to ≤±0.5dBm. The Trusted Execution Environment (TEX) unit integrates an SGX encryption module into the acquisition terminal and establishes a whitelist access mechanism, authorizing only the security policy configuration engine to access encrypted data.
Citation Information
Patent Citations
Substation network security defense system based on artificial intelligence
CN119276602A
Cross-domain network security policy automatic generation and protection policy collaboration method and system
CN119449428A