Network communication security management and control system and method adaptive to communication product, and medium
By employing multi-dimensional assessment and hierarchical self-healing operations, combined with spatiotemporal tag embedding and graph construction, a closed-loop management system for the entire process of network communication security of communication products was achieved. This system addresses the issues of one-sided node status assessment, untimely self-healing operations, and low data traceability efficiency, thereby improving security and stability.
Patent Information
- Application Number
- CN202511256239.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2025-11-18
AI Technical Summary
In existing technologies, the network communication security management of communication products suffers from several problems: a single dimension for node status assessment; a lack of precise classification of self-healing operations leading to untimely processing or waste of resources; vague data transmission path tracking; inaccurate location of suspicious nodes; low efficiency in tracing abnormal data; and fragmented security management, which can easily lead to the spread of security risks.
The system employs a multi-dimensional node health assessment module, a node hierarchical self-healing execution module, a spatiotemporal label embedding and graph construction module, and an abnormal data tracing and query module. Through multi-dimensional data collection and health calculation, hierarchical self-healing operation, spatiotemporal label embedding and graph construction, and abnormal data tracing and query, a closed-loop management system is formed throughout the entire process.
It improves the accuracy of node anomaly handling and resource utilization efficiency, significantly enhances the accuracy and efficiency of anomaly data tracing, strengthens the integrity and real-time response capability of network communication security management, and prevents the spread of security risks.
Smart Images

Figure CN120979979A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) security technology, and in particular to a network communication security management system, method, and medium adapted to communication products. Background Technology
[0002] Network communication security management adapted to communication products is essential to ensure the confidentiality, integrity, and availability of data during communication, prevent security risks such as unauthorized access, data leakage, and malicious attacks, and ensure the stable and reliable operation of communication products in complex network environments.
[0003] Currently, existing technologies for network communication security management adapted to communication products often suffer from problems such as single-dimensional node status assessment, lack of precise classification of self-healing operations leading to untimely processing or waste of resources, vague data transmission path tracking, and inaccurate location of suspicious nodes, resulting in low efficiency in tracing abnormal data. Furthermore, the fragmented nature of security management makes it difficult to form a closed loop, which can easily lead to the spread of security risks and affect the stability and security of communication product networks.
[0004] Therefore, a network communication security management system, method, and medium adapted to communication products are proposed to solve the above problems. Summary of the Invention
[0005] The main objective of this invention is to provide a network communication security management system, method, and medium adapted to communication products, so as to solve the problems mentioned in the background.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: a network communication security management and control system adapted to communication products, the network communication security management and control system including a multi-dimensional node health assessment module, a node hierarchical self-healing execution module, a spatiotemporal tag embedding and graph construction module, and an abnormal data tracing and query module; The node health multi-dimensional assessment module is used to collect multi-dimensional data on the hardware, software and communication status of distributed nodes in the network and calculate their health. The node hierarchical self-healing execution module is used to perform different levels of self-healing operations based on the node health assessment results. The spatiotemporal tag embedding and graph construction module is used to embed spatiotemporal tags into data packets and construct a spatiotemporal correlation graph for data transmission; The abnormal data tracing and query module is used to trace the transmission path of abnormal data and analyze the suspiciousness of nodes based on the spatiotemporal correlation graph.
[0007] Preferably, the evaluation dimensions of the node health multi-dimensional evaluation module include hardware status, software status, and communication status; Hardware status assessment metrics include CPU utilization, memory usage, and temperature; Software status assessment metrics include vulnerability patching rate and process anomaly rate; The evaluation metrics for communication status include packet loss rate and number of retransmissions; A health score ranging from 0 to 100 is calculated using a weighting of 30% for hardware, 40% for software, and 30% for communication. The formula for calculating the health score is as follows: ; Where H is the node health score, α is the hardware status weight coefficient, and H w β is the hardware state evaluation value, β is the software state weighting coefficient, and S w Here, λ is the software state evaluation value, and C is the communication state weighting coefficient. m For communication status evaluation values, α is 0.3, β is 0.4, λ is 0.3, and H... w S w C m The values of are all in the range of 0 to 100, and the values of H are in the range of 0 to 100.
[0008] Preferably, the multi-dimensional evaluation module for node health adopts an improved PBFT distributed consensus algorithm to ensure the consistency of the health evaluation results of each node, with the node consensus reaching time not exceeding 800ms, and divides the health status into three levels; A healthy state is defined as a health score of 80 or above; a sub-healthy state is defined as a health score of 60 to 79; and an abnormal state is defined as a health score of 60 or below.
[0009] Preferably, the node hierarchical self-healing execution module performs hierarchical processing for nodes in abnormal states; When the health level is 50-60, critical processes will be automatically restarted, and the restart time will not exceed 5 seconds. When the health score is 40-50, perform an incremental firmware update and the update data size does not exceed 100KB. When the health score is below 40, the abnormal node is isolated and a backup node is started, with a switchover time of no more than 100ms.
[0010] Preferably, the spatiotemporal tag embedding and graph construction module embeds a spatiotemporal tag containing a sending timestamp, geographic location coordinates, node ID, and a list of neighboring node IDs for each transmission data packet, and constructs a dynamically updated spatiotemporal correlation graph of data transmission based on the tag information.
[0011] Preferably, the spatiotemporal tag embedding and graph construction module uses a distributed hash table to store tag and path information, supporting fast query of historical data within 30 days, with a query response time of no more than 1 second.
[0012] Preferably, when the abnormal data tracing and query module detects tampered or forged data, it traces the complete data transmission path through a spatiotemporal correlation graph and calculates the suspiciousness of each node. The suspiciousness is determined based on the data packet dwell time deviation rate, forwarding path deviation, and the number of historical anomalies. The calculation formula is as follows: ; Where S is the node suspiciousness, ω1 is the dwell time deviation rate weight, T is the data packet dwell time deviation rate at the node, ω2 is the forwarding path deviation weight, P is the forwarding path deviation, ω3 is the historical anomaly count weight, and H is the normalized value of the node's historical anomaly count. ω1 takes the value of 0.3, ω2 takes the value of 0.4, ω3 takes the value of 0.3, T, P, and H all range from 0% to 100%, and S ranges from 0% to 100%.
[0013] Preferably, the abnormal data tracing and query module lists nodes with a suspicion level of not less than 70% as key tracing targets, the accuracy of the tracing process is not less than 96%, and generates a tracing report that includes the abnormal time of the node, the path deviation value, and historical records.
[0014] Preferably, the network communication security management method includes the following steps: Step 1: Node health assessment, which involves collecting hardware, software, and communication status data from multiple dimensions, and then... Calculate health scores and classify health status; Step 2: Tiered self-healing process, performing critical process restarts, incremental firmware updates, or node switching operations according to the anomaly level; Step 3: Spatiotemporal tag embedding and graph construction, adding spatiotemporal tags to data packets and constructing a transmission path association graph; Step 4: Tracing the source of abnormal data, tracing the path back through the graph and following the... Calculate the suspiciousness of nodes and locate key targets for tracing.
[0015] Preferably, the network communication security management medium includes a computer-readable storage medium on which a computer program is stored, and the program, when executed by a processor, implements the network communication security management method.
[0016] The present invention has the following beneficial effects: 1. This invention incorporates a multi-dimensional node health assessment module, employing hardware, software, and communication indicators combined with a specific weighting model to calculate health. An improved PBFT algorithm ensures consistent assessment. Simultaneously, a node-level self-healing execution module performs tiered operations—critical process restart, incremental firmware update, and node isolation switching—based on different health ranges. Compared to existing technologies, this significantly improves the accuracy of node anomaly handling and resource utilization efficiency, thus resolving the problems of untimely processing and resource waste caused by incomplete node status assessment and crude self-healing operations in existing technologies.
[0017] 2. This invention, by incorporating a spatiotemporal tag embedding and graph construction module, can embed spatiotemporal tags containing information such as sending timestamps and geographic coordinates into data packets. A dynamically linked graph is stored and constructed based on a distributed hash table. The abnormal data tracing and query module then traces back the path based on this graph, calculating node suspiciousness using a weighted model of dwell time deviation rate, forwarding path deviation, and historical anomaly count, enabling precise tracing of highly suspicious nodes. Compared to existing technologies, this significantly improves the accuracy and efficiency of abnormal data tracing, thus solving the tracing failure problems caused by ambiguous data transmission path tracking and inaccurate suspicious node location in existing technologies.
[0018] 3. This invention, through a collaborative architecture comprising a multi-dimensional node health assessment module, a node hierarchical self-healing execution module, a spatiotemporal tag embedding and graph construction module, and an anomaly data tracing and query module, forms a closed-loop control mechanism covering the entire process from real-time node health status assessment and hierarchical self-healing response to spatiotemporal tagging of data transmission and precise anomaly data tracing. Adaptable to network communication security management systems for communication products, the node health assessment results provide precise evidence for hierarchical self-healing, while spatiotemporal tags and correlation graphs lay the data foundation for anomaly tracing. The four modules support each other and dynamically interact. Compared with existing technologies, this significantly improves the completeness and real-time response capability of network communication security management, thus effectively solving the problem of fragmented security management links and broken event handling chains in existing technologies, leading to the spread of security risks. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the network communication security management system architecture of the present invention; Figure 2 This is a flowchart illustrating the multi-dimensional node health assessment module of the present invention. Figure 3 This is a flowchart illustrating the node-level self-healing execution module of the present invention. Figure 4 This is a flowchart illustrating the spatiotemporal tag embedding and map construction module of the present invention; Figure 5This is a flowchart illustrating the abnormal data tracing and query module of the present invention. Figure 6 This is a schematic diagram of the network communication security management method of the present invention. Detailed Implementation
[0020] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.
[0021] Example 1, please refer to Figure 1 As shown: A network communication security management and control system adapted to communication products. The network communication security management and control system includes a multi-dimensional node health assessment module, a node hierarchical self-healing execution module, a spatiotemporal tag embedding and graph construction module, and an abnormal data tracing and query module. The multi-dimensional node health assessment module is used to collect multi-dimensional data on the hardware, software and communication status of distributed nodes in the network and calculate their health status. The node-level self-healing execution module is used to perform different levels of self-healing operations based on the node health assessment results. The spatiotemporal tag embedding and graph construction module is used to embed spatiotemporal tags into data packets and construct a spatiotemporal correlation graph for data transmission; The abnormal data tracing and query module is used to trace the transmission path of abnormal data and analyze the suspiciousness of nodes based on the spatiotemporal correlation graph.
[0022] Furthermore, the multi-dimensional node health assessment module performs multi-dimensional data collection and health calculation on distributed nodes in the network, involving three aspects: hardware, software, and communication status. The hardware status assessment focuses on CPU utilization, memory usage, and temperature; the software status focuses on vulnerability repair rate and process anomaly rate; and the communication status uses packet loss rate and retransmission count as indicators. By setting a weight ratio of 30% for hardware, 40% for software, and 30% for communication, a health score of 0 to 100 is calculated. At the same time, an improved PBFT distributed consensus algorithm is used to ensure the consistency of the assessment results of each node, with the node consensus reaching time not exceeding 800ms. The health status is divided into three levels: healthy, sub-healthy, and abnormal, corresponding to health scores above 80, 60-79, and below 60, respectively.
[0023] The node-level self-healing execution module performs tiered processing on nodes in abnormal states based on the node health assessment results. When the node health score is between 50 and 60, critical processes are automatically restarted within 5 seconds. When the health score is between 40 and 50, incremental firmware updates are performed with an update data volume not exceeding 100KB. If the health score is below 40, the abnormal node is isolated and a backup node is started with a switchover time not exceeding 100ms. Through this tiered operation, corresponding measures are taken for different degrees of abnormality, improving node recovery efficiency.
[0024] The spatiotemporal tag embedding and graph construction module embeds spatiotemporal tags into each transmitted data packet. The tags include information such as the sending timestamp, geographical coordinates, node ID, and a list of neighboring node IDs. Based on this tag information, a dynamically updated spatiotemporal correlation graph of data transmission is constructed. In terms of storage, a distributed hash table is used to store tag and path information, which can support fast query of historical data within 30 days, with a query response time of no more than 1 second, providing convenience for recording data transmission trajectories and subsequent queries.
[0025] When the abnormal data tracing module detects tampered or forged abnormal data, it uses a spatiotemporal correlation graph to trace the complete transmission path of the data and analyzes the suspiciousness of each node. The calculation of node suspiciousness combines the data packet dwell time deviation rate, forwarding path deviation, and historical anomaly count, with weights of 0.3, 0.4, and 0.3 respectively, ultimately obtaining a suspiciousness value of 0% to 100%. Nodes with a suspiciousness of not less than 70% are listed as key tracing targets. The accuracy of the tracing process is not less than 96%, and a tracing report containing the node's abnormal time, path deviation value, and historical records is generated, achieving accurate tracking of abnormal data.
[0026] The evaluation results of the multi-dimensional node health assessment module provide an operational basis for the node hierarchical self-healing execution module. The latter takes corresponding self-healing measures based on the abnormality level determined by the former to quickly handle node abnormalities. The spatiotemporal tag embedding and graph construction module provides a data foundation for the abnormal data tracing and query module. The spatiotemporal correlation graph it constructs makes it possible to trace back the abnormal data transmission path. The four modules work together to form a complete control process from node health assessment and abnormal handling to data tracing, which improves the comprehensiveness and effectiveness of network communication security control.
[0027] Example 2, please refer to Figure 2 As shown: Based on Embodiment 1, a network communication security management and control system adapted to communication products, wherein the evaluation dimensions of the node health multi-dimensional evaluation module include hardware status, software status and communication status; Hardware status assessment metrics include CPU utilization, memory usage, and temperature; Software status assessment metrics include vulnerability patching rate and process anomaly rate; The evaluation metrics for communication status include packet loss rate and number of retransmissions; A health score ranging from 0 to 100 is calculated using a weighting of 30% for hardware, 40% for software, and 30% for communication. The formula for calculating the health score is as follows: ; Where H is the node health score, α is the hardware status weight coefficient, and H w β is the hardware state evaluation value, β is the software state weighting coefficient, and S w Here, λ is the software state evaluation value, and C is the communication state weighting coefficient. m For communication status evaluation values, α is 0.3, β is 0.4, λ is 0.3, and H... w S w C m The values of are all in the range of 0 to 100, and the values of H are in the range of 0 to 100.
[0028] The multi-dimensional node health assessment module adopts an improved PBFT distributed consensus algorithm to ensure the consistency of the health assessment results of each node. The node consensus time does not exceed 800ms, and the health status is divided into three levels. A healthy state is defined as a health score of 80 or above; a sub-healthy state is defined as a health score of 60 to 79; and an abnormal state is defined as a health score of 60 or below.
[0029] Furthermore, in terms of hardware status assessment, CPU utilization is obtained by reading the processor usage statistics of the node's operating system in real time. Its value is the percentage of time the CPU is not idle within a unit of time. Memory utilization is determined by calculating the ratio of used memory capacity to total memory capacity. Temperature is collected in real time by the node's built-in temperature sensor at a frequency of once per second to ensure timely capture of temperature changes. In software status assessment, the vulnerability remediation rate refers to the percentage of security vulnerabilities that have been remediated on a node relative to the total number of vulnerabilities detected by the system. The system periodically scans the node software to update vulnerability information. The process anomaly rate is obtained by continuously monitoring the process status of the running nodes, counting the number of abnormal processes such as abnormal termination and resource abuse, and then dividing by the total number of processes currently running on the node.
[0030] In communication status assessment, the packet loss rate is calculated by dividing the difference between the total number of data packets sent and the total number of data packets acknowledged by the receiver within a certain period of time by the total number of data packets sent. The retransmission count is calculated by recording the number of times data packets are retransmitted due to transmission failure, and accumulating the total retransmission amount per unit time.
[0031] The multi-dimensional node health assessment module uses a weighting of 30% for hardware, 40% for software, and 30% for communication to calculate the health score. The formula for calculating the health score is as follows: .
[0032] To ensure consistency in health assessment results across nodes, the module employs an improved PBFT distributed consensus algorithm. By optimizing the communication process of consensus nodes and reducing redundant interactions, the consensus time is controlled to within 800ms. Based on health scores, node health status is categorized into three levels: a score of 80 or above indicates a healthy state, 60-79 indicates a sub-healthy state, and below 60 indicates an abnormal state. Example 3, please refer to Figure 3 As shown: Based on Embodiment 1, a network communication security management and control system adapted to communication products is provided, in which the node hierarchical self-healing execution module performs hierarchical processing on nodes in abnormal states. When the health level is 50-60, critical processes will be automatically restarted, and the restart time will not exceed 5 seconds. When the health score is 40-50, perform an incremental firmware update and the update data size does not exceed 100KB. When the health score is below 40, the abnormal node is isolated and a backup node is started, with a switchover time of no more than 100ms.
[0033] Furthermore, when the node health score is 50-60, the node hierarchical self-healing execution module determines that the node is in a slightly abnormal state and automatically starts the critical process restart mechanism. The identification of critical processes is based on the node's preset configuration and usually includes processes responsible for core functions such as data forwarding, security verification, and node communication. During the restart process, the network communication security management system first suspends the target process through the process management interface, releases the resources it occupies, and then restarts the process and verifies its running status to ensure a successful restart. The entire process is strictly controlled within 5 seconds.
[0034] When a node's health score is between 40 and 50, the node's hierarchical self-healing execution module determines that the node has a serious software-level problem and performs an incremental firmware update. Before the incremental update, the network communication security management system compares the node's current firmware version with the latest version, extracting only the code snippets and configuration information that need to be updated to reduce the amount of data transmission and ensure that the update data volume does not exceed 100KB. The update data is transmitted to the node through an encrypted channel. After receiving the data, the node verifies it and performs the update operation after confirming that the data is complete and correct. After the update is completed, the relevant services are automatically restarted to apply the new firmware.
[0035] When a node's health score falls below 40, the node hierarchical self-healing execution module determines that the node's abnormality level is high and may pose a threat to network security. It immediately initiates an isolation and switching mechanism. The network communication security management and control system first cuts off the abnormal node's communication connection with other nodes through the network access control list, marking it as isolated to prevent the abnormality from spreading. At the same time, it starts a preset backup node. The backup node is normally in standby mode and can quickly load the operating environment and configuration information. It establishes a connection with surrounding nodes through a quick handshake. The entire switching process takes no more than 100ms, ensuring the continuity of network services.
[0036] Example 4, please refer to Figure 4 As shown: Based on Embodiment 1, a network communication security management and control system adapted to communication products is provided. The spatiotemporal tag embedding and graph construction module embeds a spatiotemporal tag containing a sending timestamp, geographical coordinates, node ID, and a list of adjacent node IDs for each transmitted data packet, and constructs a dynamically updated spatiotemporal correlation graph of data transmission based on the tag information.
[0037] The spatiotemporal tag embedding and graph construction module uses a distributed hash table to store tag and path information, supports fast querying of historical data within 30 days, and the query response time is no more than 1 second.
[0038] Furthermore, the generation and embedding of spatiotemporal tags are closely integrated with the transmission characteristics of data packets. The sending timestamp uses millisecond precision and is generated by the local clock of the data packet sending node to ensure accurate recording of the time when the data is sent. The geographical coordinates are obtained through the node's built-in positioning module. If the node does not have positioning capabilities, the location information of the gateway to the network it accesses is used instead. The node ID is a unique identifier assigned to each node in the network. It is generated and written to the node configuration file during the initialization of the network communication security management system. The list of neighboring node IDs is obtained by the node in real time by scanning the surrounding communicable nodes and is dynamically updated as the node's connection status changes. The construction of the spatiotemporal correlation graph of data transmission is based on tag information. The network communication security management and control system records the transmission path of each data packet in chronological order, uses the node ID as the vertex of the graph, and the forwarding relationship of data packets between nodes as the edge between vertices. The attributes of the edge include information such as forwarding time and forwarding direction. The graph adopts an incremental update method. Whenever a new data packet is transmitted or the node connection status changes, the network communication security management and control system updates the vertices and edges in the graph in real time to ensure that the graph can accurately reflect the current data transmission topology of the network. To support efficient data querying and storage, the spatiotemporal tag embedding and graph construction module uses a distributed hash table to store tag and path information. The distributed hash table hashes the data by keywords and distributes it across multiple nodes. Each node is responsible for storing a portion of the data and maintaining routing information with other nodes. This storage method not only improves data reliability and scalability but also enables rapid response to query requests. The network communication security management system sets a data retention period of 30 days, regularly cleans up historical data that has exceeded the retention period, and prevents data loss through a data backup mechanism, ensuring that the query response time for historical data within 30 days does not exceed 1 second.
[0039] Example 5, please refer to Figure 5 As shown: Based on Embodiment 1, a network communication security management and control system adapted to communication products, when the abnormal data tracing and query module detects tampered or forged data, traces the complete data transmission path through a spatiotemporal correlation graph, calculates the suspiciousness of each node, and determines the suspiciousness based on the data packet dwell time deviation rate, forwarding path deviation, and historical anomaly count. The calculation formula is as follows: ; Where S is the node suspiciousness, ω1 is the dwell time deviation rate weight, T is the data packet dwell time deviation rate at the node, ω2 is the forwarding path deviation weight, P is the forwarding path deviation, ω3 is the historical anomaly count weight, and H is the normalized value of the node's historical anomaly count. ω1 takes the value of 0.3, ω2 takes the value of 0.4, ω3 takes the value of 0.3, T, P, and H all range from 0% to 100%, and S ranges from 0% to 100%.
[0040] The abnormal data tracing and query module lists nodes with a suspicion level of no less than 70% as key tracing targets, with an accuracy rate of no less than 96% in the tracing process, and generates a tracing report that includes the abnormal time of the node, path deviation value, and historical records.
[0041] Furthermore, the detection of abnormal data is accomplished by the real-time data verification mechanism of the network communication security management and control system. By comparing the verification value, digital signature and preset value of the data packet, abnormal data packets with compromised data integrity or authenticity are detected. Once abnormal data is detected, the abnormal data tracing and query module immediately calls the spatiotemporal correlation graph and traces its transmission path backward from the receiving node of the abnormal data. Based on the information recorded in the graph, the previous hop forwarding node is searched in sequence until the initial sending node of the data is traced back, thus completely restoring the propagation trajectory of the data in the network.
[0042] The calculation of node suspiciousness comprehensively considers several key factors. The dwell time deviation rate is the percentage difference between the actual dwell time of a data packet at a node and the average dwell time of the node when processing similar data. A larger deviation indicates more abnormal data processing behavior. The forwarding path deviation rate calculates the degree of difference between the actual forwarding path of the data packet and the conventional forwarding path for that type of data; a larger difference indicates a higher probability of the node deviating from normal behavior. The historical anomaly frequency normalization value is obtained by dividing the number of past anomalies of the node by the maximum historical anomaly frequency of nodes in the network, yielding a normalized result of 0% to 100%, reflecting the node's historical anomaly tendency. These three factors are substituted into the formula with weights of 0.3, 0.4, and 0.3, respectively. The node suspicion level S is calculated.
[0043] Example 6, please refer to Figure 6 As shown: Based on Embodiment 1, a network communication security management method adapted to communication products is provided. The network communication security management method includes the following steps: Step 1: Node health assessment, which involves collecting hardware, software, and communication status data from multiple dimensions, and then... Calculate health scores and classify health status; Step 2: Tiered self-healing process, performing critical process restarts, incremental firmware updates, or node switching operations according to the anomaly level; Step 3: Spatiotemporal tag embedding and graph construction, adding spatiotemporal tags to data packets and constructing a transmission path association graph; Step 4: Tracing the source of abnormal data, tracing the path back through the graph and following the... Calculate the suspiciousness of nodes and locate key targets for tracing.
[0044] Furthermore, step 1 is the node health assessment. After the network communication security management and control system is started, the monitoring agent of each node begins to collect hardware status data, software status data, and communication status data. The collection frequency is dynamically adjusted according to the data type. Hardware and communication data are collected once per second, and software data is collected once every 5 minutes. The collected data is uploaded to the assessment node, and a health score is calculated based on the weights of hardware (30%), software (40%), and communication (30%). Then, the node is divided into three states: healthy, sub-healthy, and abnormal, according to the score. The assessment results reach a consensus through the improved PBFT algorithm.
[0045] Step 2 is a tiered self-healing process. The evaluation results are synchronized to the node tiered self-healing execution module. For nodes in a healthy state, only routine monitoring is performed. For nodes in a sub-healthy state, the network communication security management system issues an early warning message to remind maintenance personnel to pay attention. For nodes in an abnormal state, corresponding operations are performed according to the health score range. Nodes with a score of 50-60 restart critical processes, nodes with a score of 40-50 perform incremental firmware updates, and nodes with a score below 40 are isolated and switched to a backup node to ensure that abnormal nodes recover or are isolated quickly.
[0046] Step 3 involves spatiotemporal tag embedding and graph construction. Before the data packet enters the network for transmission, the sending node embeds spatiotemporal tags containing the sending timestamp, geographic coordinates, node ID, and a list of neighboring node IDs. The tag information is transmitted along with the data packet. The receiving node extracts the tag information and uploads it to the graph construction node. The construction node updates the spatiotemporal association graph according to the time sequence and node association relationships, reflecting the changes in the data transmission path in real time.
[0047] Step 4 is to trace the source of abnormal data. When abnormal data is detected, the network communication security management system calls the spatiotemporal correlation map to trace its complete transmission path. For each node on the path, the data packet dwell time deviation rate, forwarding path deviation degree and normalized value of historical abnormal number are calculated. The suspiciousness of each node is obtained by substituting into the suspiciousness calculation formula. Nodes with a suspiciousness of not less than 70% are listed as key objects, and in-depth verification is carried out to generate a source tracing report, thus completing the source location of abnormal data.
[0048] Furthermore, the network communication security control medium includes a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, it implements the network communication security control method.
[0049] Furthermore, the computer-readable storage medium can be of various types, including but not limited to read-only memory, random access memory, hard disk, solid-state drive, optical disk and USB flash drive, etc. The computer program on the storage medium is stored in the form of binary files, which include code modules that implement node health assessment, hierarchical self-healing processing, spatiotemporal tag embedding and graph construction and abnormal data tracing functions.
[0050] When the processor executes the program, it loads each functional module sequentially by calling the operating system's interface functions. The program first initializes system parameters and establishes communication connections between nodes. Then, it starts a data acquisition thread to acquire node status data at a preset frequency. Next, it runs an evaluation algorithm to calculate a health score and triggers corresponding self-healing operations based on the score. Simultaneously, during data packet transmission, it calls a tag generation function to embed spatiotemporal tags and update the map data structure. When abnormal data is detected, it executes a source tracing algorithm to call stored historical data and map information to complete source localization.
[0051] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A network communication security management and control system adapted to communication products, characterized in that: The network communication security management and control system includes a multi-dimensional node health assessment module, a node hierarchical self-healing execution module, a spatiotemporal label embedding and graph construction module, and an abnormal data tracing and query module; The node health multi-dimensional assessment module is used to collect multi-dimensional data on the hardware, software and communication status of distributed nodes in the network and calculate their health. The node hierarchical self-healing execution module is used to perform different levels of self-healing operations based on the node health assessment results. The spatiotemporal tag embedding and graph construction module is used to embed spatiotemporal tags into data packets and construct a spatiotemporal correlation graph for data transmission; The abnormal data tracing and query module is used to trace the transmission path of abnormal data and analyze the suspiciousness of nodes based on the spatiotemporal correlation graph.
2. The network communication security management and control system adapted to communication products according to claim 1, characterized in that: The evaluation dimensions of the node health multi-dimensional evaluation module include hardware status, software status, and communication status. Hardware status assessment metrics include CPU utilization, memory usage, and temperature; Software status assessment metrics include vulnerability patching rate and process anomaly rate; The evaluation metrics for communication status include packet loss rate and number of retransmissions; A health score ranging from 0 to 100 is calculated using a weighting of 30% for hardware, 40% for software, and 30% for communication. The formula for calculating the health score is as follows: ; Where H is the node health score, α is the hardware status weight coefficient, and H w β is the hardware state evaluation value, β is the software state weighting coefficient, and S w Here, λ is the software state evaluation value, and C is the communication state weighting coefficient. m For communication status evaluation values, α is 0.3, β is 0.4, λ is 0.3, and H... w S w C m The values of are all in the range of 0 to 100, and the values of H are in the range of 0 to 100.
3. The network communication security management and control system adapted to communication products according to claim 1, characterized in that: The multi-dimensional evaluation module for node health adopts an improved PBFT distributed consensus algorithm to ensure the consistency of the health evaluation results of each node. The node consensus time does not exceed 800ms, and the health status is divided into three levels. A healthy state is defined as a health score of 80 or above; a sub-healthy state is defined as a health score of 60 to 79; and an abnormal state is defined as a health score of 60 or below.
4. A network communication security management and control system adapted to communication products according to claim 1, characterized in that: The node hierarchical self-healing execution module performs hierarchical processing for nodes in abnormal states; When the health level is 50-60, critical processes will be automatically restarted, and the restart time will not exceed 5 seconds. When the health score is 40-50, perform an incremental firmware update and the update data size does not exceed 100KB. When the health score is below 40, the abnormal node is isolated and a backup node is started, with a switchover time of no more than 100ms.
5. A network communication security management and control system adapted to communication products according to claim 1, characterized in that: The spatiotemporal tag embedding and graph construction module embeds a spatiotemporal tag containing a sending timestamp, geographic location coordinates, node ID, and a list of neighboring node IDs for each transmission data packet, and constructs a dynamically updated spatiotemporal correlation graph of data transmission based on the tag information.
6. A network communication security management and control system adapted to communication products according to claim 1, characterized in that: The spatiotemporal tag embedding and graph construction module uses a distributed hash table to store tag and path information, supports fast querying of historical data within 30 days, and the query response time is no more than 1 second.
7. A network communication security management and control system adapted to communication products according to claim 1, characterized in that: When the abnormal data tracing and query module detects tampered or forged data, it traces the complete data transmission path through a spatiotemporal correlation graph and calculates the suspiciousness of each node. The suspiciousness is determined based on the data packet dwell time deviation rate, forwarding path deviation, and the number of historical anomalies. The calculation formula is as follows: ; Where S is the node suspiciousness, ω1 is the dwell time deviation rate weight, T is the data packet dwell time deviation rate at the node, ω2 is the forwarding path deviation weight, P is the forwarding path deviation, ω3 is the historical anomaly count weight, and H is the normalized value of the node's historical anomaly count. ω1 takes the value of 0.3, ω2 takes the value of 0.4, ω3 takes the value of 0.3, T, P, and H all range from 0% to 100%, and S ranges from 0% to 100%.
8. A network communication security management and control system adapted to communication products according to claim 1, characterized in that: The abnormal data tracing and query module lists nodes with a suspicion level of not less than 70% as key tracing targets, with an accuracy rate of not less than 96% in the tracing process, and generates a tracing report that includes the abnormal time of the node, path deviation value, and historical records.
9. A network communication security management method adapted to communication products, applicable to the network communication security management system adapted to communication products as described in any one of claims 1-8, characterized in that: Network communication security management methods include the following steps: Step 1: Node health assessment, which involves collecting hardware, software, and communication status data from multiple dimensions, and then... Calculate health scores and classify health status; Step 2: Tiered self-healing process, performing critical process restarts, incremental firmware updates, or node switching operations according to the anomaly level; Step 3: Spatiotemporal tag embedding and graph construction, adding spatiotemporal tags to data packets and constructing a transmission path association graph; Step 4: Tracing the source of abnormal data, tracing the path back through the graph and following the... Calculate the suspiciousness of nodes and locate key targets for tracing.
10. A network communication security management medium adapted to communication products, applicable to the network communication security management system adapted to communication products as described in any one of claims 1-8, characterized in that: The network communication security management medium includes a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, it implements the network communication security management method of claim 9.