Communication method and system based on big data

By deploying data acquisition modules and building a big data security protection system at network nodes, and utilizing herd immunity linkage mechanisms and dynamic protection strategies, the shortcomings of traditional network communication security protection technologies have been addressed. This has enabled real-time, precise, and multi-layered defense of the network system, enhancing its anti-attack capabilities and stability.

CN121125255APending Publication Date: 2025-12-12CHONGQING QINGYI TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511335555.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Traditional network communication security protection technologies lack real-time and dynamic adjustment capabilities, making it difficult to form a multi-layered defense system, cope with large-scale distributed attacks, and are inefficient in processing massive amounts of data, failing to accurately identify security threats.

Method used

By deploying data acquisition modules at communication network nodes to collect multi-dimensional data in real time, a big data-based security protection system is constructed. This system employs a herd immunity linkage mechanism and dynamic protection strategy adjustments, utilizes big data analysis algorithms to assess node security status, and coordinates protection strategies through a central management server to achieve adaptive protection of the network system.

Benefits of technology

It significantly improves the network system's resistance to attacks and stability, enables accurate security assessment and timely protection of network nodes, and enhances the overall protection efficiency and accuracy of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125255A_ABST
    Figure CN121125255A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and system based on big data, and relates to the technical field of network communication security, and the method comprises the following components: a data collection step, a data preprocessing step, a security state analysis step, a population immune linkage mechanism construction step and a dynamic protection strategy adjustment step. According to the invention, through constructing a group immune linkage mechanism, cooperative adjustment of security protection strategies among the nodes is realized, when one node is attacked, the node can take defensive measures, and the connected nodes can also automatically adjust the protection strategies according to the received security state information to form a group immune effect; the central management server adopts a strategy optimization algorithm based on the game theory to coordinate the security protection strategy of the whole network and ensure that the network system can maintain the optimal protection state under various network environments and attack conditions, and the linkage mechanism and the optimization strategy significantly enhance the overall anti-attack capability and stability of the network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication security technology, specifically to a communication method and system based on big data. Background Technology

[0002] With the rapid development of Internet technology, network communication has become an important cornerstone of information exchange in modern society. From personal daily communication to enterprise-level data transmission, the widespread application of network communication has greatly promoted the flow and sharing of information. However, with the expansion of network scale and the increase in complexity, network communication security issues have become increasingly prominent. Security threats such as hacker attacks, virus propagation, and data leaks are emerging one after another, seriously threatening personal privacy, corporate interests, and even national security.

[0003] Traditional network communication security technologies primarily rely on pre-set rules and signature databases to identify and block known threats. This passive defense approach has limited effectiveness against unknown threats and zero-day attacks. Specifically, the shortcomings of traditional technologies are mainly reflected in the following aspects: First, they lack real-time and dynamic adjustment capabilities, failing to adjust protection strategies in a timely manner according to changes in the network environment and the evolution of attack strategies; second, their protection methods are singular, making it difficult to form a multi-layered defense system, easily leaving opportunities for attackers; third, traditional technologies often struggle to effectively cope with large-scale distributed attacks, leading to service interruptions or data leaks; finally, traditional technologies are inefficient when processing massive amounts of data, making it difficult to extract valuable security information from complex data, thus limiting the accuracy and effectiveness of security protection.

[0004] In view of the shortcomings of traditional network communication security protection technologies, the present invention proposes a communication method and system based on big data, which is of particular importance. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a communication method and system based on big data. It can build an intelligent and adaptive security protection system by collecting and analyzing multi-dimensional data of network nodes in real time. This method and system not only realize the accurate assessment of the security status of network nodes, but also significantly improve the overall anti-attack capability and stability of the network system through herd immunity linkage mechanism and dynamic protection strategy adjustment.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: On one hand, a communication method based on big data, the specific steps of which are as follows: Data acquisition steps: Deploy data acquisition modules at each node in the communication network to collect various types of data from the network nodes, including node operating status data, security log data, and inter-node communication data. Transmit the collected data to the data storage center for storage. Data preprocessing steps: Preprocess the data stored in the data storage center, including data cleaning to remove duplicate, erroneous and incomplete data; data standardization to convert data of different formats and ranges into a unified standard format; and data integration to integrate data from different data sources for subsequent analysis. Security status analysis steps: Utilize big data analysis algorithms to analyze preprocessed data, assess the security status of network nodes, establish a security assessment model, and calculate the security score of nodes based on various data indicators. When a node's CPU utilization is too high and abnormal network traffic occurs, the node's security score is reduced. When a node's security log shows a large number of intrusion detection alarms, the security score is also reduced accordingly. The security score is used to determine whether a node is in a secure state, has security risks, or has been attacked. The steps for building a herd immunity linkage mechanism are as follows: Based on the security status of network nodes, a security protection linkage mechanism between nodes is built. When a node is detected to be under attack or has a security risk, the security status information of that node is sent to other nodes connected to it in real time. Other nodes automatically adjust their own security protection strategies based on the received information. At the same time, the security status information of the attacked node is uploaded to the central management server. The central management server coordinates the security protection strategies of each node based on the node security status information of the entire network to achieve herd immunity protection for the entire communication network. Dynamic protection strategy adjustment steps: Continuously monitor the security status of network nodes, and dynamically adjust the security protection strategies of nodes according to changes in the network environment and the evolution of attack situations. When new attack types appear in the network, the central management server updates the security assessment model and protection strategies in a timely manner, and distributes the updated strategies to each node to ensure that the communication network always maintains effective protection capabilities.

[0007] Furthermore, the operational status data in the data acquisition steps includes CPU utilization, memory usage, and network traffic; the security log data includes intrusion detection logs and virus scanning logs; and the inter-node communication data includes data packet sending and receiving status and communication frequency. Specifically, during data acquisition, CPU utilization is collected 10 times per second using a high-precision sensor chip; memory usage is collected every 30 seconds via an interface provided by the operating system kernel; network traffic is monitored and recorded in real-time using network packet capture tools to track the size and number of data packets entering and leaving the nodes; for security log data, intrusion detection logs are generated in real-time by the intrusion detection system deployed on the nodes, and relevant information is recorded immediately when abnormal network behavior is detected; virus scanning logs are recorded after each virus scan. The collection of inter-node communication data, including data packet sending and receiving status, is tracked in real-time using the network protocol stack; and communication frequency is obtained by counting the number of communications between nodes per unit time. These different data acquisition methods work together to ensure comprehensive and accurate acquisition of various types of network node data, providing a reliable data foundation for subsequent analysis and processing.

[0008] Furthermore, the data integration process in the data acquisition step employs a semantic mapping-based data fusion method. Specifically, for data from different data sources, a semantic ontology model is first constructed. This model establishes a unified semantic description framework by deeply analyzing and defining the semantic meaning, data structure, and interrelationships of data elements in each data source. Then, natural language processing technology is used to semantically parse the names and attribute descriptions of data elements, and corresponding semantic mapping rules are formulated. Based on these rules, data from different data sources are mapped to a unified semantic space, thereby achieving data fusion. When encountering a user ID from one data source and a customer number from another data source, semantic analysis determines that they both represent unique identifiers of users, and they are then mapped to a unified user identifier concept. This effectively solves the problem of semantic heterogeneity between different data sources, making the integrated data format unified and semantically clear, providing an accurate and usable data foundation for subsequent big data analysis.

[0009] Furthermore, the data cleaning process in the data preprocessing step adopts an outlier identification and repair approach. In this process, the original data is first analyzed as a whole to calculate the mean, which reflects the central tendency of the data. Simultaneously, the standard deviation is calculated to measure the dispersion of the data. Based on the mean and standard deviation, the criteria for identifying outliers are determined. When a data point significantly deviates from the overall distribution characteristics of the data, i.e., exceeds the range centered on the mean and a multiple of the standard deviation, it is identified as an outlier. For identified outliers, a repair strategy is adopted. If the outlier is greater than the mean plus a multiple of the standard deviation, it is corrected to the mean plus that multiple of the standard deviation; if the outlier is less than the mean minus a multiple of the standard deviation, it is corrected to the mean minus that multiple of the standard deviation. Data points within the normal range remain unchanged. In this way, outliers in the data can be automatically identified and repaired, avoiding adverse effects on subsequent analysis results due to abnormal data, improving data quality and reliability, and providing accurate data support for network node security status analysis.

[0010] Furthermore, the data standardization step employs an improved nonlinear mapping standardization method. During standardization, the mean of the original data is first calculated as a key reference indicator. Then, adjustment parameters are determined based on the data fluctuation range. Specifically, a larger adjustment parameter is set when the data range is small, and a smaller adjustment parameter is set when the range is large. Through this adjustment mechanism, the original data is converted into data in a unified standard format according to a nonlinear mapping relationship. This standardization method is particularly suitable for data scenarios with extreme values, making data of different formats and ranges more conducive to the application of subsequent big data analysis algorithms after standardization. This improves the accuracy and effectiveness of the analysis results, thereby laying a solid data foundation for subsequent operations such as network node security status assessment.

[0011] Furthermore, the security status analysis step employs a security assessment algorithm based on multi-index fusion, and the security score calculation formula is as follows: in Assess the security of nodes. To assess the number of indicators, For the first The weight of each indicator, For the first The scoring function for each indicator, For the first The actual value of each indicator, weight The determination of the weights was achieved using a combination of the Analytic Hierarchy Process (AHP) and the entropy weight method. First, ten cybersecurity experts were invited to score each indicator based on its importance to the node's security status, constructing a judgment matrix. Initial weights were calculated using the AHP method. Then, the entropy weight method was used to adjust the initial weights based on the entropy values ​​of each indicator, ensuring that the weights reflect both expert experience and the information content of the data itself. The scoring function... The design should be tailored to the characteristics of different metrics, such as CPU utilization. hour, When 60% hour, ,when hour, This algorithm integrates multiple indicators and scientifically determines weights and scoring functions, enabling it to comprehensively and accurately assess the security status of network nodes and provide a reliable basis for subsequent security protection coordination.

[0012] Furthermore, in the security protection linkage mechanism between nodes in the security status analysis step, when other nodes receive the security status information of the attacked node, they adopt a protection strategy adjustment algorithm based on risk propagation prediction. This algorithm first constructs a risk propagation model through historical attack data and the connection relationships between nodes, with the following formula: in In order to be in Time Node Subject to node The probability of the attack propagating. In order to be in Time Node Subject to node The probability of the attack propagating and affecting [the target population]. This is the probability decay coefficient. The propagation impact coefficient, For nodes With nodes The strength of the connection between them The value is 0.8. The value is 0.2. The specific values ​​are determined based on factors such as communication frequency and data transmission volume between nodes. ,in For nodes With nodes Communication frequency, For nodes With nodes Data transmission volume, For nodes The total number of connected nodes. Based on the predicted risk probability, the nodes automatically adjust their protection strategies, such as when... At that time, node Will be from the node Deep inspection of data packets in the direction of travel is performed, and restrictions are placed on nodes. The communication traffic is 50% of the normal traffic. This algorithm can predict the spread trend of attacks in advance, enabling nodes to adjust their protection strategies more effectively and improve the overall anti-attack capability of the network.

[0013] Furthermore, in the herd immunity linkage mechanism construction step, when the central management server coordinates the security protection strategies of each node, a game theory-based strategy optimization algorithm is used, assuming that there are [various network parameters]. There are nodes, each node has A variety of optional security protection strategies, nodes Choose strategy The payoff function is: in For nodes Choose strategy For nodes The resulting impact and benefits For nodes Choose strategy To reduce costs, the central management server collects security status information and available strategies from each node, constructs a game matrix, and then uses the Nash equilibrium algorithm to find the strategy combination that maximizes the overall network benefit. In practical applications, through continuous iterative calculations, the optimal security protection strategy combination is obtained when adjusting the strategies of all nodes no longer increases the overall network benefit, and is then distributed to each node. This algorithm considers the mutual influence and interest relationships between nodes, enabling optimal coordination of the entire communication network security protection strategy and improving the network's protection efficiency and effectiveness.

[0014] Furthermore, the dynamic protection strategy adjustment process in the aforementioned dynamic protection strategy adjustment step employs a deep learning-based attack trend prediction algorithm to construct a long short-term memory network model. The input is historical security status data of network nodes, including past... Security scores, attack types, and attack strength information at each time step are output as future data. The attack trend prediction results at each time step are presented. The model is trained using the backpropagation algorithm, and the loss function is the mean squared error, as shown in the formula: in The number of training samples. For the actual attack trend value, The central management server updates the security assessment model and protection strategies in a timely manner based on the predicted attack trend values ​​when a change in the attack trend is predicted. When it is predicted that the probability of a new type of attack will increase significantly in the next week, the central management server updates the detection rules and protection strategies for the new type of attack in advance and distributes them to each node. This algorithm can use the powerful feature extraction and prediction capabilities of deep learning to accurately predict attack trends, enabling the network protection strategy to adapt to changes in the network environment in a timely manner and enhancing the security and stability of the network.

[0015] On the other hand, a big data-based communication system includes a data acquisition module, a data storage center, a data processing module, a central management server, and a node protection module. The data acquisition module is deployed at each node of the communication network to collect the network node's operating status data, security log data, and communication data between nodes, and transmits the collected data to the data storage center. The data storage center is used to store the collected network node data and to provide data support for data preprocessing and analysis. The data processing module preprocesses and analyzes the data stored in the data storage center, including data cleaning, standardization, integration, and using big data analysis algorithms to assess the security status of network nodes. The central management server receives security status information from network nodes, builds and coordinates security protection linkage mechanisms between nodes, dynamically adjusts security protection strategies according to changes in the network environment, and distributes the strategies to each node. The node protection module is deployed on each network node. Based on the received security protection policy, it protects the nodes and monitors the security status of the nodes in real time, feeding back the status information to the central management server.

[0016] Compared with existing technologies, this big data-based communication method and system has the following advantages: I. This invention achieves coordinated adjustment of security protection strategies among nodes by constructing a herd immunity linkage mechanism. When a node is attacked, not only will that node take defensive measures, but connected nodes will also automatically adjust their protection strategies based on the received security status information, forming a herd immunity effect. In addition, the central management server adopts a strategy optimization algorithm based on game theory to coordinate the security protection strategies of the entire network, ensuring that the network system can maintain the optimal protection status under various network environments and attack conditions. This linkage mechanism and optimization strategy significantly enhance the overall anti-attack capability and stability of the network system, effectively resisting various network attacks and ensuring the smooth operation of the communication network.

[0017] Second, this invention deploys data acquisition modules at various communication network nodes to collect and analyze network node operation status data, security log data, and inter-node communication data in real time. Utilizing big data analysis algorithms, it can accurately assess the security status of each node and establish a detailed security assessment model. When an attack or security risk is detected on a node, the system can immediately send the node's security status information to connected nodes in real time, enabling them to automatically adjust their security protection strategies. Simultaneously, the central management server dynamically coordinates the protection strategies of each node based on the overall network security status, ensuring the timeliness and relevance of protection measures, greatly improving the accuracy and real-time performance of network security protection.

[0018] Other advantages, objectives and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination or study, or may be learned from the practice of the invention. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0020] Figure 1 This is a flowchart illustrating a communication method based on big data. Figure 2 This is a flowchart of a communication system based on big data. Detailed Implementation

[0021] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided below.

[0022] Example 1: A large financial institution's core business network connects a large number of terminal devices, database servers, and transaction systems. To ensure customer fund security and business continuity, this big data-based communication method is used to build a comprehensive protection system.

[0023] Data acquisition modules are deployed at all nodes within the network, including teller terminals, back-end database servers, and transaction gateways, to comprehensively collect operational status data from each node. This includes CPU processing load, memory usage, and network traffic entering and leaving the node; security log data, covering abnormal login attempts and suspicious command execution records captured by the intrusion detection system, as well as virus scan results and quarantine file logs generated by antivirus software; and communication data between nodes, such as details of data packet interactions between teller terminals and database servers, and communication frequencies between different transaction systems. All collected data is aggregated in real time and transmitted to the institution's dedicated data storage center for centralized storage.

[0024] Preprocessing of the massive amounts of data in the storage center involves several steps. First, data cleaning is performed to remove duplicate transaction logs, erroneous traffic data caused by equipment failures, and terminal status information with missing fields. Next, data integration is conducted using a semantic mapping-based data fusion method. This method maps heterogeneous data from terminal devices from different vendors and server systems of different versions into a consistent semantic space by constructing a unified semantic ontology model. Finally, data standardization is implemented using an improved nonlinear mapping standardization method. Based on the fluctuation characteristics of various data types, appropriate adjustment parameters are set to convert the originally inconsistent CPU utilization, transaction frequency, and other data into a unified standard format, laying the foundation for subsequent analysis.

[0025] Using a security assessment algorithm based on multi-index fusion, the formula is: in Assess the security of nodes. To assess the number of indicators, For the first The weight of each indicator, For the first The scoring function for each indicator, For the first The actual values ​​of each indicator are combined with the pre-processed complete data to assess the security status of each node, and a security assessment model that fits the characteristics of financial business is constructed. The model comprehensively considers multiple indicators such as the number of abnormal operations of terminal devices, the server's access permission change records, and the integrity of transaction data transmission. The security score of each node is calculated, and the score determines whether each node is in a normal security state, has potential risks, or has been attacked.

[0026] A tight security protection linkage mechanism is established between nodes. When a teller terminal is detected to be under phishing attack, its security status information is immediately synchronized to the database server, adjacent teller terminals, and transaction gateway that interact with it. Upon receiving the information, these related nodes quickly and automatically adjust their protection strategies. For example, the database server temporarily freezes some of the terminal's query permissions, adjacent terminals automatically initiate high-intensity real-time monitoring, and the transaction gateway adds a verification step to transaction requests from the terminal. Simultaneously, detailed information about the attacked node is uploaded to the central management server. The server integrates the security status of all nodes in the network and uses a game theory-based strategy optimization algorithm to coordinate the protection strategies of all nodes. Assuming there are [various network parameters]... There are nodes, each node has A variety of optional security protection strategies, nodes Choose strategy The payoff function is: in For nodes Choose strategy For nodes The resulting impact and benefits For nodes Choose strategy To reduce costs, the central management server collects security status information and available strategies from each node, constructs a game matrix, and then uses the Nash equilibrium algorithm to find the strategy combination that maximizes the overall network revenue. In practical applications, through continuous iterative calculations, the optimal security protection strategy combination is obtained when the strategy adjustments of all nodes no longer increase the overall network revenue. This combination is then distributed to each node to ensure that the core transaction system remains unaffected.

[0027] The system continuously monitors the security status of all nodes across the network. As trading days change, such as the surge in trading volume during peak opening hours and the intensive backend operations during nighttime clearing periods, the network environment and potential attack patterns also change. At this time, a deep learning-based attack trend prediction algorithm is used. Through a constructed Long Short-Term Memory (LSTM) network model, it takes as input node security scores from multiple past time steps, historical attack types, and attack intensities, and outputs future attack trends. The attack trend prediction results at each time step are presented. The model is trained using the backpropagation algorithm, and the loss function is the mean squared error, as shown in the formula: in The number of training samples. For the actual attack trend value, The central management server updates the security assessment model and protection strategies in a timely manner based on the prediction results when the predicted attack trend changes. It predicts possible attack trends in the future. When the model predicts that the probability of a certain type of attack against the database server is increasing, the central management server will update the parameters of the security assessment model in a timely manner based on the prediction results and adjust the protection strategies of each node, such as increasing the log auditing frequency of the database server and strengthening the access control rules of terminal devices, to ensure that network protection is always synchronized with the attack situation.

[0028] Example 2: In the internal medical network of a large general hospital, this big data-based communication method is used to protect the communication security of the electronic medical record system, medical device terminals, and doctor-patient interaction platform, preventing the leakage of patient privacy information and the malicious manipulation of medical devices.

[0029] Data acquisition modules are deployed at key nodes of the hospital's internal network, including doctor workstations, nurse station terminals, medical equipment such as CT scanners, electronic medical record servers, and doctor-patient communication platform servers. These modules collect operational status data, such as CPU load on doctor workstations, memory usage of medical equipment, and network traffic changes between nodes; security log data, including login records outside of working hours, abnormal access to medical equipment blocked by the firewall, and suspicious file records detected by antivirus software; and communication data between nodes, such as data packet transmission between doctor workstations and the electronic medical record server, and the frequency with which medical equipment sends status information to the central monitoring system. All collected data is transmitted in real-time to the hospital's data storage center for storage.

[0030] The medical-related data in the storage center undergoes meticulous preprocessing. First, data cleaning is performed, removing duplicate electronic medical record access logs, erroneous device status data caused by network fluctuations, and incomplete doctor-patient interaction records. Next, data integration is conducted using a semantic mapping-based data fusion method. Data from different brands of medical devices and terminal systems from different departments, with varying formats, is integrated into a unified semantic description framework by analyzing the semantic meaning and structural relationships of data elements. Finally, data standardization is performed using an improved nonlinear mapping standardization method. Adjustment parameters are set based on the data range characteristics to convert medical device operating parameters, terminal operation frequencies, and other data into a unified standard format, facilitating subsequent comprehensive analysis.

[0031] A security assessment algorithm based on multi-indicator fusion is adopted. By combining the pre-processed complete data, the security status of each node is assessed, and a security assessment model that conforms to the medical industry standards is constructed. The model comprehensively considers multiple indicators such as the software operation compliance of the doctor's workstation, the firmware version security of medical devices, and the encryption status of electronic medical record data transmission. The security score of each node is calculated, and the score is used to determine whether each node is in a secure operating state, has a risk of information leakage, or has been subjected to malicious attacks.

[0032] An efficient security protection linkage mechanism is constructed among nodes. When a security risk of unauthorized access to the electronic medical record server is detected on a nursing station terminal, the terminal's security status information is pushed in real time to the connected electronic medical record server, other nursing station terminals, and the hospital's internal firewall. Upon receiving the information, these nodes immediately and automatically adjust their protection strategies. For example, the electronic medical record server temporarily restricts the terminal's medical record query scope, other nursing station terminals automatically display security warnings and strengthen user authentication, and the firewall adds deep packet inspection to the network connection initiated by the terminal. Simultaneously, the node's security status information is uploaded to the central management server. After the server aggregates the security status of all nodes in the network, it uses a game theory-based strategy optimization algorithm to integrate the optional protection strategies of each node and their costs and benefits, constructs a game matrix, and solves for the Nash equilibrium. This coordinates the protection strategies of all nodes, ensuring patient privacy without affecting normal medical operations.

[0033] Continuous monitoring of the security status of each node in the network is crucial. As hospital treatment processes change, such as frequent patient data interaction during peak outpatient hours on weekdays and lower operating load of on-call equipment during holidays, the network environment and attack situations will also evolve. At this time, an attack trend prediction algorithm based on deep learning is used. Through the constructed long short-term memory network model, the node security scores, historical attack types (such as unauthorized access to electronic medical records, firmware tampering of medical devices, etc.) and attack intensity data from multiple past time steps are input to predict attack trends in the future. When the model predicts that attacks on on-call terminals may increase during holidays, the central management server will update the security assessment model in a timely manner based on the prediction results and dynamically adjust the protection strategies of each node, such as increasing the frequency of automatic screen locking of on-call terminals and strengthening the remote control permission review of medical devices, to ensure the continuous, secure and stable operation of the treatment network.

[0034] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content without departing from the scope of the technical solution of the present invention, and any simple modifications, alterations and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the technical solution of the present invention shall still fall within the scope of the technical solution of the present invention.

Claims

1. A communication method based on big data, characterized in that, The specific steps of this method are as follows: Data acquisition steps: Deploy data acquisition modules at various nodes in the communication network to collect various types of data from the network nodes, and transmit the collected data to the data storage center for storage; Data preprocessing steps: Preprocess the data stored in the data storage center, including data cleaning, removing duplicate, erroneous and incomplete data; Security status analysis steps: Utilize big data analysis algorithms to analyze the preprocessed data, assess the security status of network nodes, establish a security assessment model, calculate the security score of the node based on various data indicators, and determine whether the node is in a secure state, has security risks, or has been attacked through the security score. The steps for building a herd immunity linkage mechanism are as follows: Based on the security status of network nodes, a security protection linkage mechanism between nodes is built. When a node is detected to be under attack or has a security risk, the security status information of the node is sent to other nodes connected to it in real time. Other nodes automatically adjust their own security protection strategies based on the received information. At the same time, the security status information of the attacked node is uploaded to the central management server. The central management server coordinates the security protection strategies of each node based on the node security status information of the entire network. Dynamic protection strategy adjustment steps: Continuously monitor the security status of network nodes and dynamically adjust the security protection strategy of nodes according to changes in the network environment and the evolution of attack situations.

2. The communication method based on big data according to claim 1, characterized in that, The operational status data in the data acquisition steps includes CPU utilization, memory usage, and network traffic. The security log data includes intrusion detection logs and virus scanning logs. The inter-node communication data includes data packet sending and receiving status and communication frequency. Specifically, during data acquisition, CPU utilization is collected 10 times per second using a high-precision sensor chip. Memory usage is collected every 30 seconds via an interface provided by the operating system kernel. Network traffic is monitored and recorded in real-time using network packet capture tools to track the size and number of data packets entering and leaving the nodes. For security log data, intrusion detection logs are generated in real-time by the intrusion detection system deployed on the nodes, and relevant information is recorded immediately when abnormal network behavior is detected. Virus scanning logs are recorded after each virus scan. The inter-node communication data acquisition, including data packet sending and receiving status, is tracked in real-time using the network protocol stack, and the communication frequency is obtained by counting the number of communication sessions between nodes per unit time.

3. The communication method based on big data according to claim 1, characterized in that, The data integration process in the data acquisition step adopts a data fusion method based on semantic mapping. Specifically, for data from different data sources, a semantic ontology model is first constructed. This model establishes a unified semantic description framework by deeply analyzing and defining the semantic meaning, data structure, and interrelationships of data elements in each data source. Then, natural language processing technology is used to perform semantic parsing on the names and attribute descriptions of data elements, and corresponding semantic mapping rules are formulated. Based on these rules, data from different data sources are mapped to a unified semantic space.

4. The communication method based on big data according to claim 1, characterized in that, The data cleaning process in the data preprocessing step adopts an outlier identification and repair approach. In this process, the original data is first analyzed as a whole to calculate the mean, which reflects the central tendency of the data. At the same time, the standard deviation is calculated to measure the dispersion of the data. Based on the mean and standard deviation, the criteria for judging outliers are determined. When a data point deviates significantly from the overall distribution characteristics of the data, that is, exceeds the range centered on the mean and within a multiple of the standard deviation, it is judged as an outlier. For the identified outliers, a repair strategy is adopted.

5. The communication method based on big data according to claim 1, characterized in that, In the data preprocessing step, the data standardization adopts an improved nonlinear mapping standardization method. During the standardization process, the mean of the original data is first calculated as a key reference indicator. Then, the adjustment parameter is determined according to the fluctuation range of the data. Specifically, when the range of the data is small, a larger adjustment parameter is set, and when the range is large, a smaller adjustment parameter is set. Through this adjustment mechanism, the original data is converted into data in a unified standard format according to the nonlinear mapping relationship.

6. The communication method based on big data according to claim 1, characterized in that, The security status analysis step employs a security assessment algorithm based on multi-index fusion, and the security score calculation formula is as follows: in Assess the security of nodes. To assess the number of indicators, For the first The weight of each indicator, For the first The scoring function for each indicator, For the first The actual value of each indicator.

7. The communication method based on big data according to claim 1, characterized in that, In the security status analysis step's inter-node security protection linkage mechanism, when other nodes receive the security status information of the attacked node, they employ a protection strategy adjustment algorithm based on risk propagation prediction. This algorithm first constructs a risk propagation model using historical attack data and the connection relationships between nodes, with the following formula: in In order to be in Time Node Subject to node The probability of the attack propagating and affecting [the target population]. In order to be in Time Node Subject to node The probability of the attack propagating and affecting [the target population]. This is the probability decay coefficient. The propagation impact coefficient, For nodes With nodes The strength of the connection between them.

8. The communication method based on big data according to claim 1, characterized in that, When the central management server coordinates the security protection strategies of each node in the construction step of the herd immunity linkage mechanism, a game theory-based strategy optimization algorithm is used. This assumes that there are [various network parameters]. There are nodes, each node has A variety of optional security protection strategies, nodes Choose strategy The payoff function is: in For nodes Choose strategy For nodes The resulting impact and benefits For nodes Choose strategy To reduce costs, the central management server collects security status information and available strategies from each node, constructs a game matrix, and then uses the Nash equilibrium algorithm to find the strategy combination that maximizes the overall network benefit. In practical applications, through continuous iterative calculations, the optimal security protection strategy combination is obtained when the strategy adjustments of all nodes no longer increase the overall network benefit, and is then distributed to each node.

9. A communication method based on big data according to claim 1, characterized in that, The dynamic protection strategy adjustment process in the aforementioned steps employs a deep learning-based attack trend prediction algorithm to construct a long short-term memory network model. The input is historical security status data of the network nodes, including past... Security scores, attack types, and attack strength information at each time step are output as future data. The attack trend prediction results at each time step are presented. The model is trained using the backpropagation algorithm, and the loss function is the mean squared error, as shown in the formula: in The number of training samples. For the actual attack trend value, The attack trend value is predicted by the model. When the predicted attack trend changes, the central management server updates the security assessment model and protection strategy in a timely manner based on the prediction results.

10. A big data-based communication system, applicable to the big data-based communication method described in any one of claims 1-9, characterized in that, The system includes a data acquisition module, a data storage center, a data processing module, a central management server, and a node protection module. The data acquisition module is deployed at each node of the communication network to collect the network node's operating status data, security log data, and communication data between nodes, and transmits the collected data to the data storage center. The data storage center is used to store the collected network node data and to provide data support for data preprocessing and analysis. The data processing module preprocesses and analyzes the data stored in the data storage center, including data cleaning, standardization, integration, and using big data analysis algorithms to assess the security status of network nodes. The central management server receives security status information from network nodes, builds and coordinates security protection linkage mechanisms between nodes, dynamically adjusts security protection strategies according to changes in the network environment, and distributes the strategies to each node. The node protection module is deployed on each network node. Based on the received security protection policy, it protects the nodes and monitors the security status of the nodes in real time, feeding back the status information to the central management server.