Data security protection method for network resource compression package and storage medium
By preprocessing network resource compressed packets, conducting virtual attack resistance tests, and implementing environment-aware encryption, combined with anti-tampering verification data, the problems of inadequate data security protection and resource mismatch in existing technologies are solved, achieving flexible and reliable full lifecycle security protection.
Patent Information
- Application Number
- CN202511661537.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-13
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-11-13
AI Technical Summary
Existing technologies for data security protection of compressed network resource packets suffer from several drawbacks. The preprocessing stage is insufficient to completely eliminate residual sensitive information, and the technology is unable to intercept new types of malicious code. Fixed encryption strength and unified verification mechanisms result in inadequate protection of highly sensitive data and waste of low-value data resources. Furthermore, the lack of practical attack verification leads to problems such as inflated security protection and severe resource mismatch.
By preprocessing network resource compressed packages and conducting virtual attack resistance tests, we construct environment-aware dynamic encryption and anti-tampering verification data. We then combine the resistance test results to classify risks, dynamically adjust protection strategies, and provide computer-readable storage media to achieve end-to-end protection.
It achieves layered, dynamic, and adaptive security protection for network resource compressed data, improves the data's resistance to attacks and integrity, balances security protection strength with system resource consumption, and provides flexible and reliable full lifecycle security assurance.
Smart Images

Figure CN121125359A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data information transmission technology, and in particular to a data security protection method and storage medium for network resource compressed packages. Background Technology
[0002] Current data security protection technologies for compressed network resource packages have formed a multi-dimensional protection system. They employ symmetric encryption, asymmetric encryption, digital certificates, and full disk encryption to achieve static data protection. Access control mechanisms strictly constrain data flow, integrity verification methods ensure data immutability, malicious code detection schemes proactively identify and intercept potential threats, and key management technology ensures the security of the encryption system. Furthermore, by optimizing the process of compression before encryption and introducing hardware acceleration technology, the efficiency of large-scale data processing and real-time protection capabilities are significantly improved.
[0003] For example, Chinese invention patent CN118869295B discloses a network security protection method based on big data. The method includes the following steps: acquiring raw network traffic data through a data pipeline tool; dividing the raw network traffic data into time windows to obtain time window traffic data; performing cluster feature description analysis on the time window traffic data to obtain a traffic clustering label model; and generating a normal traffic baseline model based on the traffic clustering label model and the time window traffic data to obtain a normal traffic baseline model.
[0004] For example, Chinese invention patent CN112333157B discloses a network security protection method and platform based on big data. First, during an attack by a target attacking device on a target virtual application, it detects whether the target attacking device recognizes the target virtual application as running on a virtual computer. Second, if it detects that the target attacking device recognizes the target virtual application as running on a virtual computer, it retrieves historical data from a first target database. Then, based on the historical data, it determines whether the target virtual application will be recognized as running on a virtual computer in the next attack. Finally, if it is determined that the target virtual application will be recognized as running on a virtual computer, it runs the target virtual application through the target physical computer.
[0005] The aforementioned technologies suffer from at least the following technical problems: On the one hand, the preprocessing stage relies on simple rule-based desensitization and format conversion, which cannot completely eliminate the residual sensitive information or intercept new malicious code, thus creating a risk of data leakage; on the other hand, the fixed encryption strength and unified verification mechanism ignore the actual risk level of the data, resulting in insufficient protection for highly sensitive data and waste of low-value data resources. In addition, the lack of practical attack verification means that the protection effect is out of touch with real threat scenarios, ultimately leading to inflated security protection of compressed packages and serious resource mismatch. Summary of the Invention
[0006] To address the technical problems of inadequate security protection and severe resource mismatch in existing compressed file technologies, this invention provides a data security protection method and storage medium for network resource compressed files. The technical solution is as follows: On the one hand, a data security protection method for network resource compressed packages is provided, which includes: Step 1: Preprocess the network resource compressed package. Perform a virtual attack resistance test on the preprocessed package to obtain the resistance test results. Acquire the preprocessing parameters of the network resource compressed package and, based on the resistance test results, determine whether the network resource compressed package passes the initial data security protection check. The resistance test results reflect the attack resistance capability of the preprocessed compressed package in a real-world attack scenario. Step 2: Implement environment-aware dynamic encryption on the network resource compressed package that passes the initial data security protection check and encapsulate tamper-proof verification data to construct a secure compressed package with data security protection. Step 3: Monitor and acquire the data security protection encapsulation process parameters of the secure compressed package. Based on the resistance test results, classify the data security protection encapsulation results for risk. If the risk classification is no risk, the data security protection of the network resource compressed package is complete. If the risk classification is low or high risk, adjust the data protection of the network resource compressed package accordingly.
[0007] On the other hand, a computer-readable storage medium is provided, which stores at least one instruction, which is loaded and executed by a processor to implement any of the above-described methods for data security protection of network resource compressed packets.
[0008] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following: (1) This invention provides a data security protection method and storage medium for network resource compressed packets, and constructs a full-process protection system of preprocessing and initial inspection, dynamic encryption and encapsulation, and post-encapsulation risk adjustment, realizing the layering, dynamism, and adaptability of network resource compressed packet data security protection. Its core advantage lies in combining virtual attack testing and quantitative indicator evaluation. It not only filters high-risk data through pre-protection, but also strengthens core security capabilities through environment-aware encryption and anti-tampering encapsulation. Furthermore, it can dynamically adjust the protection strategy according to the risk level. While ensuring the security of data transmission and storage, it also takes into account the processing efficiency of data with different priorities, effectively balancing the strength of security protection and the consumption of system resources, and providing flexible and reliable full life cycle security protection for compressed packet data in complex network environments.
[0009] (2) The initial inspection mechanism, which combines preprocessing, virtual attack resistance testing, and compressed package attack resistance index assessment, achieves pre-screening and precise prevention of risks. The virtual attack test simulates real-world scenarios and exposes security vulnerabilities after preprocessing in advance; the comparison between the compressed package attack resistance index and its corresponding limit value provides a quantitative basis for the initial inspection. The secondary preprocessing mechanism can specifically compensate for security defects that fail the initial inspection by dynamically increasing the amount of redundant verification data and the number of hash iterations, thereby improving the data's resistance to tampering and cracking; while the warning and anomaly reporting mechanism ensures controllability under extreme risks, reduces the pressure of subsequent protection from the source, and builds a solid first line of defense for overall security protection.
[0010] (3) The environmentally-aware dynamic encryption and anti-tampering verification encapsulation implemented through the initial inspection of the compressed package significantly improves the core data protection capabilities. Environmentally-aware dynamic encryption incorporates real-time variables such as timestamps and device identifiers, enabling the same data to generate differentiated ciphertexts in different environments, greatly increasing the complexity of cracking by attackers; the anti-tampering verification data encapsulation provides rigid protection for data integrity and can effectively resist tampering attacks during transmission or storage. The combination of the two forms a two-layer protection of encryption and verification, which not only protects the data content from being stolen, but also ensures that the data is not illegally tampered with during circulation, thus building a high-strength security barrier for core data.
[0011] (4) By dynamically monitoring, classifying risks, and adaptively adjusting the encapsulation results, the security protection is made more refined and efficient. Based on the comparison between the encapsulation effectiveness index and its corresponding limit value, a differentiated strategy is adopted for different types of network resource compression packets: priority is given to ensuring the transmission efficiency and security of emergency data, and the risk is reduced by enhancing the verification structure; the encapsulation interval is optimized for routine data to improve the timeliness of anomaly monitoring; and parallel tasks are adjusted for low-priority data to balance stability and resource consumption. At the same time, the re-encapsulation and early warning mechanism further reduces the risk of ineffective encapsulation, ensuring that the protection measures and data security requirements are accurately matched, thereby improving the overall protection effectiveness while avoiding resource waste caused by over-protection. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This is a flowchart of a data security protection method for network resource compressed packages provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the initial inspection process for data security protection provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the secondary preprocessing and re-evaluation process provided in the embodiments of the present invention; Figure 4 This is a schematic diagram of the secure compressed package encapsulation verification and risk assessment process provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the compressed package encapsulation review and protection finalization process provided in the embodiments of the present invention. Detailed Implementation
[0014] The technical solution of the present invention will now be described with reference to the accompanying drawings.
[0015] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.
[0016] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0017] This invention provides a data security protection method for compressed network resource packets, such as... Figure 1 The flowchart shown illustrates a data security protection method for compressed network resource packages. The processing flow of this method may include the following steps: Step 1: Preprocess the network resource compressed package. After preprocessing, perform a virtual attack resistance test on the compressed package to obtain the resistance test results. Obtain the preprocessing parameters of the network resource compressed package and, based on the resistance test results, determine whether the compressed package passes the initial data security protection check. The resistance test results reflect the attack resistance capability of the preprocessed compressed package in a real-world attack scenario. The preprocessing operations specifically include format standardization (e.g., correcting metadata), redundant data cleanup (e.g., removing invalid redundancy), sensitive information desensitization (e.g., replacing privacy and core data), preliminary integrity verification (verifying overall and block-level data integrity through hash value comparison), and basic attack resistance enhancement (adding basic verification headers and lightweight encryption of directory entries). These operations aim to improve the format consistency of the compressed package, reduce redundancy, lower the risk of sensitive information leakage, identify inherent defects, and strengthen basic attack resistance capabilities. This provides a standardized, low-risk basic sample for subsequent virtual attack resistance testing, dynamic encryption, and secure encapsulation, ensuring the effectiveness and accuracy of the entire security protection process.
[0018] Step 2: Implement environment-aware dynamic encryption on network resource compressed packages that pass the initial data security protection inspection, and encapsulate tamper-proof verification data to construct a secure compressed package with data security protection. The above-mentioned encapsulation of tamper-proof verification data adopts a two-layer encapsulation structure. The outer layer uses a dynamic encryption algorithm (such as a session key generated based on environmental parameters) to encrypt and protect the entire compressed package. The inner layer encapsulates tamper-proof verification data (including block-level hash and association mapping information) separately for the core data blocks in the compressed package. The two layers achieve collaborative protection through a key association mechanism. The specific process of encapsulating tamper-proof verification data is as follows: Generate a unique hash value (such as SHA-384) for each data block in the compressed package and record its metadata. At the same time, combine the timestamp and random salt value to generate an overall root hash value that integrates all data block information to form multi-layer verification data. Then, according to the structure of block-level verification and overall verification, attach the block-level verification data to the end of the corresponding data block. The overall verification data is encapsulated in a dedicated verification segment at the end and protected by encrypted signature. At the same time, establish a rigid association between the data block and the verification data (such as embedding a unique identifier and location index), and preset dynamic verification triggering mechanisms for reading, transmission, decompression and other links. In this way, it can accurately identify tampering behavior by comparing the verification data with the original data, quickly locate the tampering location, and immediately lock the compressed package when an anomaly is detected, ensuring the integrity of the data throughout its entire lifecycle and providing a reliable basis for tampering monitoring for security protection.
[0019] Step 3: Monitor and obtain the data security protection encapsulation process parameters of the secure compressed package, and classify the risk of the data security protection encapsulation result in combination with the resistance test results. If the risk of the data security protection encapsulation result is classified as no risk, the data security protection of the network resource compressed package is completed. If the risk of the data security protection encapsulation result is classified as low risk or high risk, the data protection of the network resource compressed package is adjusted.
[0020] Specifically, the preprocessing parameters of the network resource compressed package are obtained. The specific analysis process is as follows: the preprocessing parameters include the redundancy check data coverage ratio coefficient, the abnormal format filtering ratio coefficient, and the sensitive field replacement ratio coefficient of the network resource compressed package preprocessing process. By presetting the effect coefficient of each ratio coefficient in the protection database, the weight contribution value of each ratio coefficient to the compressed package anti-attack index is quantified. Finally, the weighted average fusion algorithm is used to obtain the compressed package anti-attack index.
[0021] The aforementioned redundancy check data coverage ratio coefficient refers to the ratio of the redundancy check data coverage rate in the network resource compressed packet preprocessing process to the defined redundancy check data coverage rate; the aforementioned abnormal format filtering rate ratio coefficient refers to the ratio of the abnormal format filtering rate in the network resource compressed packet preprocessing process to the defined abnormal format filtering rate; the aforementioned sensitive field replacement rate ratio coefficient refers to the ratio of the sensitive field replacement rate in the network resource compressed packet preprocessing process to the defined sensitive field replacement rate.
[0022] The compressed package anti-attack index refers to the basic anti-attack capability of the pre-processed network resource compressed package at the static level. The specific evaluation method is as follows: ; ; ; ; In the formula, CAI is the anti-attack index of compressed packets, RCDCF is the redundancy check data coverage ratio coefficient of the network resource compressed packet preprocessing process, RCDC is the redundancy check data coverage of the network resource compressed packet preprocessing process, DRCDC is the redundancy check data coverage preset in the protection database, AFFRF is the abnormal format filtering rate ratio coefficient of the network resource compressed packet preprocessing process, AFFR is the abnormal format filtering rate of the network resource compressed packet preprocessing process, DAFFR is the redundancy format filtering rate preset in the protection database, SFRRF is the sensitive field replacement rate ratio coefficient of the network resource compressed packet preprocessing process, SFRR is the sensitive field replacement rate of the network resource compressed packet preprocessing process, DSFRR is the redundancy field replacement rate preset in the protection database, fr is the effect coefficient corresponding to the redundancy check data coverage ratio coefficient preset in the protection database, fa is the effect coefficient corresponding to the abnormal format filtering rate ratio coefficient preset in the protection database, and fs is the effect coefficient corresponding to the sensitive field replacement rate ratio coefficient preset in the protection database.
[0023] It should be explained that the above-mentioned redundancy check data coverage rate represents the proportion of redundant check data in the overall data of the compressed package, used to measure the protection scope of the check mechanism for the data. It is obtained by dividing the total amount of redundant check data by the total amount of data in the compressed package and then multiplying by 100%. The above-mentioned abnormal format filtering rate is the proportion of abnormal format data that the system successfully identifies and filters out out of the total amount of all abnormal format data. It is obtained by dividing the number of successfully filtered abnormal format data entries by the total number of detected abnormal format data entries and then multiplying by 100%. The above-mentioned sensitive field replacement rate represents the proportion of the number of sensitive fields in the compressed package that have been safely replaced out of the total number of all sensitive fields. It is obtained by dividing the number of successfully replaced sensitive fields by the total number of identified sensitive fields and then multiplying by 100%.
[0024] The above definition of redundant check data coverage rate indicates the minimum value of redundant check data coverage within the specified range; the above definition of abnormal format filtering rate indicates the minimum value of abnormal format filtering rate within the specified range; the above definition of sensitive field replacement rate indicates the minimum value of sensitive field replacement rate within the specified range.
[0025] An increase in the ratio of redundancy check data coverage to its corresponding threshold value indicates that the actual redundancy check coverage far exceeds the basic security standard, and the data's resistance to tampering and repair capabilities are significantly enhanced. This reduces misjudgments caused by data corruption during abnormal format filtering, reduces interference factors in the filtering mechanism, and makes it easier to increase the ratio of abnormal format filtering rate to its corresponding threshold value. At the same time, it also reduces the probability of sensitive fields being exposed due to data loss, providing a more stable environment for sensitive information replacement, thus making the ratio of sensitive field replacement rate to its corresponding threshold value tend to increase, ultimately increasing the compressed package's resistance to attack index.
[0026] The effect coefficients corresponding to the aforementioned redundancy check data coverage ratio coefficients indicate that when the redundancy check data coverage ratio coefficient changes by a unit magnitude, the compressed package's anti-attack index will change accordingly. Similarly, the effect coefficients corresponding to the aforementioned abnormal format filtering ratio coefficients indicate that when the abnormal format filtering ratio coefficient changes by a unit magnitude, the compressed package's anti-attack index will change accordingly. The effect coefficients corresponding to the aforementioned sensitive field replacement ratio coefficients indicate that when the sensitive field replacement ratio coefficient changes by a unit magnitude, the compressed package's anti-attack index will change accordingly. The protection database stores the mapping relationships between the redundancy check data coverage ratio coefficients and their corresponding effect coefficients, the abnormal format filtering ratio coefficients and their corresponding effect coefficients, and the sensitive field replacement ratio coefficients and their corresponding effect coefficients. For example, when the redundancy check data coverage ratio coefficients, abnormal format filtering ratio coefficients, and sensitive field replacement ratio coefficients are input into the protection database, the protection database generates the corresponding effect coefficients based on preset mapping rules, and the numerical range of each effect coefficient is strictly controlled between 0 and 1.
[0027] Specifically, the determination of whether a network resource compressed package passes the initial data security protection inspection is based on the resistance test results. The specific determination process is as follows: The resistance test result refers to the virtual attack resistance score of the compressed package obtained after the network resource compressed package completes the virtual attack resistance test. Based on the deviation between the virtual attack resistance score and the limit value of the virtual attack resistance score, a correction coefficient for the limit value of the compressed package is matched, thereby correcting the limit value of the compressed package. The limit value of the compressed package in the following text refers to the corrected limit value of the compressed package.
[0028] The aforementioned virtual attack resistance test, based on a simulated real-world approach, utilizes a pre-built simulated attack environment and a pre-defined attack algorithm library covering common network attack types, such as brute-force attacks, data tampering, replay attacks, and malicious code injection, to launch multi-dimensional, tiered virtual attacks on pre-processed compressed files. During the test, the system monitors the compressed file's state changes under attack in real time, such as whether data integrity is compromised, whether encryption layers are penetrated, and whether verification mechanisms fail. Based on pre-defined scoring rules, such as the type of attack resisted, attack intensity, and defense response speed, a quantitative score is generated—the compressed file's virtual attack resistance score. These pre-defined scoring rules are standards for converting the compressed file's performance in virtual attacks into a quantitative score, primarily based on dimensions such as attack resistance capability and attack response performance.
[0029] For example, a base score of 100 points can be set. In terms of the types of attacks resisted, 10 points are awarded for successfully resisting brute-force attacks, 15 points for resisting data tampering, 12 points for resisting replay attacks, and 18 points for resisting malicious code injection. If a certain type of attack is not resisted, the corresponding points will be deducted. In terms of attack intensity, 10 points are awarded for maintaining stability under low-intensity attacks, 15 points for maintaining stability under medium-intensity attacks, and 20 points for maintaining stability under high-intensity attacks. 5 points are deducted for minor anomalies when the intensity is upgraded, and 15 points are deducted for serious anomalies. In terms of defense response speed, 10 points are awarded for responding to and intercepting attacks within 1 second, 5 points are awarded for responding and intercepting attacks within 1-3 seconds, and 10 points are deducted for failure to respond within 3 seconds.
[0030] The correction coefficient for the compressed package attack resistance threshold value is determined by matching the deviation between the compressed package virtual attack resistance score and the compressed package virtual attack resistance score threshold value. Specifically: , The deviation between the virtual attack resistance score of the compressed package and its threshold value is denoted as the score deviation value. S represents the virtual attack resistance score of the compressed package, with a maximum value of 1. S0 represents the threshold value of the virtual attack resistance score of the compressed package. A preset score deviation value-correction coefficient mapping table is used in the protection database. The obtained score deviation value is input into the database, and the database can match the corresponding correction coefficient. The correction coefficient is then substituted into the formula. The corrected anti-attack threshold value of the compressed package can be obtained by formulating S1, T0, and K, where S1 is the corrected anti-attack threshold value, T0 is the compressed package anti-attack threshold value, and K is the matched correction coefficient. Through dynamic correction, the threshold value will automatically adjust according to the deviation of the actual score, reducing misjudgment at the source. Correcting the anti-attack threshold value of the compressed package based on the deviation value and matching the correction coefficient allows the security assessment standard to break away from the limitations of static rigidity and achieve dynamic adaptation to the actual security level. This mechanism can avoid misjudgment caused by standards that are too high or too low. When the anti-attack capability of the compressed package is significantly improved, the threshold value is adjusted upward to reflect the true protection strength and prevent the standard from being too low to cover up the risk; when the capability decreases, the threshold value is adjusted downward accordingly to avoid the standard being too strict and increasing unnecessary preprocessing costs.
[0031] like Figure 2 As shown in the schematic diagram of the data security protection preliminary inspection process provided in this embodiment of the invention, after the process starts, the network resource compressed package is preprocessed first, and its resistance test results and resistance index are obtained at the same time; then, the resistance limit value of the compressed package is corrected according to the resistance test results; finally, the resistance index of the compressed package is compared with the resistance limit value of the compressed package. If the resistance index of the compressed package is not lower than the resistance limit value of the compressed package, the data security protection preliminary inspection is passed and the process of building a secure compressed package is entered; otherwise, a secondary preprocessing mechanism is triggered.
[0032] The obtained anti-attack index of the compressed package is compared with the anti-attack threshold value of the compressed package, which represents the minimum value of the anti-attack index within a specified range. When the anti-attack index of the compressed package is not lower than the anti-attack threshold value, it is determined that the network resource compressed package has passed the initial data security protection inspection, and environmental-aware dynamic encryption is implemented on the network resource compressed package. When the anti-attack index of the compressed package is lower than the anti-attack threshold value, it is determined that the network resource compressed package has failed the initial data security protection inspection, and a secondary preprocessing mechanism is triggered.
[0033] The aforementioned environment-aware dynamic encryption of network resource compressed packages is an advanced protection method that dynamically adjusts the encryption logic based on real-time environmental parameters. Specifically, this encryption method collects environmental variables of the compressed package in real time, including but not limited to the current timestamp, device hardware identifier, and network environment parameters. These dynamic variables are then incorporated into the key generation or encryption operation of the encryption algorithm as salt values (a technique in cryptography and data security that enhances encryption security by introducing randomization information to prevent identical original data from generating the same ciphertext after encryption, thereby resisting targeted cracking attacks such as rainbow tables). For example, the same original compressed package can generate significantly different ciphertexts at different times, on different devices, or under different network environments. Even if an attacker intercepts the ciphertext at a certain moment, they cannot decrypt it in other environments by reusing the ciphertext or key. This is because the dynamic changes in environmental variables cause the encryption logic to be constantly updated. The advantage of this encryption method is that it breaks through the limitation of the same key corresponding to fixed ciphertext in traditional static encryption. By using the randomness and uniqueness of environmental factors, it makes it difficult for attackers to obtain the original data through brute-force attacks, ciphertext comparisons, etc. It further strengthens the security protection capabilities of the compressed package that has passed the initial inspection during transmission and storage from the encryption layer, laying a dynamic security foundation for subsequent anti-tampering encapsulation.
[0034] Furthermore, a secondary preprocessing mechanism is triggered. The specific analysis process is as follows: based on the anti-attack index and the anti-attack limit of the compressed package, the comprehensive anti-attack deviation value is obtained. Based on the comprehensive anti-attack deviation value, a redundant verification data volume amplification coefficient is matched, thereby increasing the redundant verification data volume of the network resource compressed package that failed the initial data security protection inspection. Based on the comprehensive anti-attack deviation value, a hash calculation iteration number amplification coefficient is matched, thereby increasing the hash calculation iteration number of the network resource compressed package that failed the initial data security protection inspection.
[0035] The aforementioned acquisition of the comprehensive anti-attack deviation value refers to subtracting the anti-attack index of the compressed package from its anti-attack threshold. The specific matching process for determining the redundant verification data volume increase factor based on the comprehensive anti-attack deviation value is as follows: The protection database has preset redundant verification data volume increase factors corresponding to each anti-attack comprehensive deviation value interval. The obtained comprehensive anti-attack deviation value is input into the database, and the database can match the redundant verification data volume increase factor for the interval corresponding to the comprehensive anti-attack deviation value. Multiplying the obtained redundant verification data volume increase factor by the original redundant verification data volume yields the required amount of redundant verification data. A redundant verification data volume increase factor greater than 1 indicates that the redundant verification data volume needs to be increased by a certain factor. The core advantage of matching the redundant verification data volume increase factor based on the comprehensive anti-attack deviation value and increasing the redundant verification data volume is to specifically improve the data's resistance to tampering and fault tolerance. When the compressed package's anti-attack index does not reach the threshold, a larger deviation value means a higher risk of data being tampered with or damaged during transmission or storage. By dynamically increasing the amount of redundant verification data, more redundant information for verification and repair can be included in the data. Even if some data blocks are tampered with or lost, the system can quickly identify anomalies and complete repairs with the expanded redundant data, greatly reducing the security risks caused by compromised data integrity. At the same time, this on-demand approach avoids the waste of resources caused by excessive redundant data, ensuring that the protection strength is precisely matched with the actual risks.
[0036] The above-mentioned method matches the hash calculation iteration increase factor based on the comprehensive anti-attack deviation value. The specific matching process is as follows: divide the comprehensive anti-attack deviation value by the compressed package's anti-attack threshold, then percentage the result, and use a preset non-linear function to match the hash calculation iteration increase factor. A hash calculation iteration increase factor greater than 1 indicates that the hash calculation iteration count needs to be increased by a certain factor. Matching the hash calculation iteration increase factor based on the comprehensive anti-attack deviation value and increasing the iteration count significantly enhances the data's resistance to cracking. The hash calculation iteration count is positively correlated with the cracking difficulty; the more iterations, the higher the computing power and time cost required for attackers to obtain the original data through brute-force attacks. When the compressed package's anti-attack index is insufficient, the deviation value reflects the weakness of the current hash protection: the larger the deviation, the more insufficient the current iteration count is to resist potential attacks. By dynamically increasing the iteration count, the cracking threshold for attackers can be directly increased, especially effectively deterring brute-force attacks that rely on computing power. Furthermore, this adjustment method avoids excessive consumption of system resources while ensuring security, achieving a balance between protection efficiency and security.
[0037] In a specific example embodiment, the above nonlinear function is: ; Where k2 is the factor that increases the number of hash calculation iterations. The comprehensive anti-attack deviation value is defined as follows: d1, d2, and d3 are constant terms for slight deviation, moderate deviation, and severe deviation, respectively; m1, m2, and m3 are linear coefficients for the slight deviation segment, moderate deviation segment, and severe deviation segment, respectively. The specific values of the linear coefficients are determined by relevant professionals in this field. Q is the boundary value between slight and moderate deviation, and P is the boundary value between moderate and severe deviation. Substituting the obtained comprehensive anti-attack deviation value into the above nonlinear function yields the corresponding hash calculation iteration increase factor. Multiplying the obtained hash calculation iteration increase factor by the original hash calculation iteration number gives the result of adjusting the hash calculation iteration number to the desired level. The function parameters are updated regularly based on historical cracking cases: if a compressed file within a certain deviation range is cracked multiple times, the slope of the function in the corresponding range will be increased (e.g., the slope of the moderate deviation segment increases from 0.002 to 0.003) to ensure that the coefficient matching is more in line with the actual attack intensity. The piecewise function matching hash calculation iteration number is used to increase the coefficient, which can adopt a differentiated amplification strategy according to different magnitudes of the comprehensive anti-attack deviation value. For slight deviations, linear amplification is used to reduce computing power waste; for moderate deviations, quadratic function is used to balance security and efficiency; and for severe deviations, exponential amplification is used to quickly strengthen the shortcomings. It can also flexibly embed security and efficiency constraints through function characteristics, control the upper limit of the amplification to prevent excessive resource consumption. It also makes it easy to dynamically optimize the parameters of each segment in combination with actual attack data, and adjust the iteration amplification in a targeted manner to respond to changes in attack patterns, ultimately achieving a unity of deviation adaptability, resource controllability, and strategy adaptability.
[0038] like Figure 3 As shown in the schematic diagram of the secondary preprocessing and re-evaluation process provided in this embodiment of the invention, when the compressed package fails the initial data security protection check, the secondary preprocessing mechanism is triggered; based on the comprehensive anti-attack deviation value, the amount of redundant verification data and the number of hash calculation iterations are increased; then, the anti-attack re-evaluation index of the compressed package is obtained, and the anti-attack re-evaluation index of the compressed package is compared with the anti-attack threshold value of the compressed package. If the anti-attack re-evaluation index of the compressed package is not lower than the anti-attack threshold value of the compressed package, a secure compressed package is constructed and the effective index of compressed package encapsulation is obtained; otherwise, an early warning is issued for the preprocessing process, an anomaly analysis report is pushed, and the process ends.
[0039] Obtain the attack resistance index of the compressed package after secondary preprocessing, mark it as the attack resistance reassessment index of the compressed package, and determine whether to issue an early warning for the preprocessing process of network resource compressed packages.
[0040] Specifically, the process for determining whether to issue an early warning for the preprocessing of network resource compressed packets involves the following steps: comparing the packet's anti-attack reassessment index with the packet's anti-attack threshold; if the packet's anti-attack reassessment index is not lower than the packet's anti-attack threshold, it is determined that no early warning will be issued for the preprocessing of network resource compressed packets; if the packet's anti-attack reassessment index is lower than the packet's anti-attack threshold, it is determined that an early warning will be issued for the preprocessing of network resource compressed packets, and a preprocessing anomaly analysis report will be pushed out.
[0041] It needs to be explained that the aforementioned early warning for the preprocessing of network resource compressed packages refers to the security management terminal sending an early warning message, clearly informing the user that the current preprocessing process cannot make the compressed package meet the basic security standards, and indicating the warning level; the aforementioned push of the preprocessing anomaly analysis report includes three parts: first, a comparison of basic data, clearly listing the key parameters before and after preprocessing (such as redundancy check data coverage), intuitively presenting the quantitative gap that did not meet the standards; second, the location of the abnormal link, identifying the key steps that may lead to security defects (such as the failure of the redundancy check algorithm call) by tracing back the preprocessing full process log, and marking the impact weight of each link on the re-evaluation index; and third, optimization suggestions, proposing targeted improvement directions based on historical cases and successful preprocessing solutions for similar compressed packages.
[0042] In a specific example embodiment, by implementing environment-aware dynamic encryption and anti-tampering verification encapsulation on compressed packages that pass initial inspection, the core data protection capability is significantly enhanced. Environment-aware dynamic encryption integrates real-time variables such as timestamps and device identifiers, ensuring that the same data generates unique ciphertext in different environments, greatly increasing the difficulty and cost for attackers to crack it. Simultaneously, anti-tampering verification encapsulation provides rigid protection for data integrity, effectively resisting malicious tampering during transmission or storage. Together, these two elements construct a two-layer protection system: encryption to prevent theft and verification to ensure integrity. This not only strictly prevents unauthorized theft of core data content but also ensures the integrity and authenticity of data throughout its entire flow.
[0043] Furthermore, the data security protection packaging results are combined with the resistance test results for risk classification. The specific analysis process is as follows: Based on the deviation between the virtual attack resistance score of the compressed package and the limit value of the virtual attack resistance score of the compressed package, the correction coefficient of the effective limit value group of the compressed package is matched, thereby correcting the effective limit value group of the compressed package. The effective limit value group of the compressed package in the following text, namely the effective first-class limit value and the effective second-class limit value of the compressed package, are both corrected effective first-class limit values and effective second-class limit values of the compressed package. The effective limit value group of the compressed package includes the effective first-class limit value and the effective second-class limit value of the compressed package. The effective first-class limit value of the compressed package is used to classify the data security protection packaging results into no risk and low risk, and the effective second-class limit value of the compressed package is used to classify the data security protection packaging results into low risk and high risk.
[0044] The above-mentioned correction coefficients are derived from the deviation between the virtual attack resistance score of the compressed package and the limit value of the virtual attack resistance score of the compressed package, and the effective limit value group of the compressed package encapsulation is matched. Specifically, the protection database has a preset mapping table of score deviation value - effective Class I limit value correction coefficient of compressed package encapsulation and a mapping table of score deviation value - effective Class II limit value correction coefficient of compressed package encapsulation. The obtained score deviation value is input into the database, and the database can match the corresponding effective Class I limit value correction coefficient L1 or effective Class II limit value correction coefficient L2 of compressed package encapsulation. The correction coefficient is then substituted into the formula. , This yields the corrected anti-attack threshold value for the compressed package, where R1 is the corrected effective Type I threshold value for compressed package encapsulation, R2 is the corrected effective Type II threshold value for compressed package encapsulation, and R... 01 For the effective class of boundary values of compressed package encapsulation, R 02 This mechanism establishes effective Category II boundary values for compressed packet encapsulation. Based on the deviation between the compressed packet's virtual attack resistance score and its boundary value, a correction coefficient is generated for the effective boundary value of the compressed packet encapsulation. This allows the risk classification standard to dynamically synchronize with the actual security capabilities of the compressed packet. By adjusting the boundary value according to the deviation, it moves upwards synchronously when there is a positive deviation to avoid underestimating the risk, and downwards when there is a negative deviation to prevent overly strict classification, ensuring that the risk label is accurate. After correction, the hierarchical relationship is maintained, and the magnitude changes dynamically with the deviation. This allows for precise expansion or contraction of the high-risk range, directing resources towards areas requiring strengthening and improving the effectiveness of responses. Simultaneously, this mechanism can capture changes in security levels in real time, enabling the classification standard to automatically adapt to the dynamic network environment, allowing the security system to tighten defenses when risks escalate and remain flexible when security is improved.
[0045] The effective index of the compressed package encapsulation is compared with the effective threshold value group of the compressed package encapsulation. When the effective index of the compressed package encapsulation is not lower than the first-class effective threshold value of the compressed package encapsulation, the risk of the data security protection encapsulation result is classified as risk-free, and a corresponding transmission queue is allocated based on the different types of network resource compressed packages. When the effective index of the compressed package encapsulation is between the first-class effective threshold value and the second-class effective threshold value of the compressed package encapsulation, the risk of the data security protection encapsulation result is classified as low risk, and different optimization adjustments are made based on the different types of network resource compressed packages. When the effective index of the compressed package encapsulation is lower than the second-class effective threshold value of the compressed package encapsulation, the risk of the data security protection encapsulation result is classified as high risk, triggering the invalid encapsulation adjustment process, that is, calling the backup encapsulation engine to re-encapsulate, re-obtaining the effective index of the compressed package encapsulation, marking it as the effective re-evaluation index of the compressed package encapsulation, and determining whether to issue an abnormal warning for the data protection of the network resource compressed package.
[0046] It should be explained that the above-mentioned allocation of corresponding transmission queues based on different types of network resource compressed packets refers to classifying network resource compressed packets into emergency, regular, and low-priority categories based on their service priority and processing requirements. Emergency network resource compressed packets typically involve core services with high real-time requirements (such as emergency instructions), and their transmission timeliness must be prioritized. Therefore, they are included in the priority transmission queue, which enjoys the highest bandwidth usage and processing priority. It skips unnecessary transmission queuing steps and directly enters the data transmission channel. Furthermore, it receives priority resource scheduling during network congestion, ensuring that the compressed packets are transmitted with the shortest possible delay, avoiding disruption to emergency services due to transmission lag. Regular network resource compressed packets cover daily business data (… For data packets with moderate real-time requirements (such as routine information exchange) but needing to ensure transmission stability, they are included in a standard transmission queue. This queue uses an in-order scheduling mechanism, transmitting data sequentially according to the submission order when bandwidth resources are sufficient, and maintaining a basic transmission rate through dynamic bandwidth allocation when resources are scarce. This avoids consuming too many resources and affecting urgent data while ensuring the normal progress of routine business, balancing efficiency and resource fairness. Low-priority network resource compressed packets are mostly non-core, delayable data (such as historical log archives), with lower requirements for transmission timeliness. Therefore, they are included in a delayed transmission queue. This queue only initiates transmission during network idle periods (such as when bandwidth utilization is below 30%), and the transmission rate is limited by the remaining resources to avoid competing for resources with high-priority data. This off-peak transmission mode allows different types of network resource compressed packets to receive resource support matching their business value during transmission, ensuring the timeliness of urgent business while avoiding resource waste, ultimately achieving synergistic optimization of security protection and business efficiency.
[0047] Furthermore, different optimization adjustments are made based on different types of network resource compression packages. The specific adjustment process is as follows: based on the compression package encapsulation effectiveness index and the compression package encapsulation effectiveness first-class boundary value, the compression package encapsulation effectiveness deviation value is obtained; the above-mentioned obtaining the compression package encapsulation effectiveness deviation value refers to subtracting the compression package encapsulation effectiveness index from the compression package encapsulation effectiveness first-class boundary value.
[0048] When the network resource compressed package type is emergency, a redundancy check data ratio increase factor is matched based on the effective deviation value of the compressed package encapsulation. This increases the redundancy check data in the network resource compressed package encapsulation process and includes it in the transmission queue corresponding to the emergency network resource compressed package. It should be explained that the specific matching process for matching the redundancy check data ratio increase factor based on the effective deviation value of the compressed package encapsulation is as follows: The protection database presets the redundancy check data ratio increase factor corresponding to each range of effective deviation values for compressed package encapsulation. The obtained effective deviation values for compressed package encapsulation are input into the protection database, which then matches the redundancy check data ratio increase factor for the corresponding range. The obtained redundancy check data ratio increase factor is multiplied by the original redundancy check data ratio, and the result is the redundancy check data ratio that needs to be adjusted. A redundancy check data ratio increase factor greater than 1 indicates that the redundancy check data ratio needs to be increased by a certain factor. Increasing the redundancy check data ratio can form a dynamic protection network during data transmission. Even if sudden interference causes partial data corruption, it can be quickly repaired through redundant information, avoiding the impact of data loss on emergency services. This adjustment not only meets the core requirement of prioritizing the transmission of urgent data, but also balances security and efficiency by increasing redundancy as needed, ensuring the integrity and availability of data at critical moments, thereby improving the effectiveness of compressed package encapsulation.
[0049] When the network resource compression package type is regular, a verification data packet encapsulation interval reduction coefficient is matched based on the effective deviation value of the compression package encapsulation. This reduces the verification data packet encapsulation interval during the network resource compression package encapsulation process and determines whether an invalid encapsulation adjustment process is triggered. The matching process for the verification data packet encapsulation interval reduction coefficient based on the effective deviation value of the compression package encapsulation is implemented through a dynamic weight adjustment method. If the verification data packet encapsulation interval reduction coefficient is less than 1, it indicates the value of the verification data packet encapsulation interval that needs to be reduced by a factor. Multiplying the obtained verification data packet encapsulation interval reduction coefficient by the original verification data packet encapsulation interval yields the required adjusted verification data packet encapsulation interval.
[0050] In a specific example embodiment, the dynamic weight adjustment method is as follows: based on the effective deviation value (ΔE) of the compressed packet encapsulation, an encapsulation fluctuation coefficient (F) is introduced, wherein the encapsulation fluctuation coefficient is based on the standard deviation of the effective encapsulation index of at least the last 5 times, and a formula for reducing the encapsulation interval of the verification data packet is established: Wherein, K3 is the reduction coefficient for the encapsulation interval of the verification data packet, W1 is the weight corresponding to the effective deviation value of the compressed packet encapsulation, W2 is the weight corresponding to the encapsulation fluctuation coefficient, a is a constant, representing the basic adjustment parameter of the effective deviation value of the compressed packet encapsulation on the interval shrinkage amplitude, used to quantify the interval shrinkage force corresponding to each unit of effective deviation value of the compressed packet encapsulation, b is a constant, representing the benchmark value for calculating the encapsulation fluctuation coefficient, representing the benchmark ratio of interval shrinkage when the encapsulation is stable (F=0), c is a constant, representing the supplementary adjustment parameter of the encapsulation fluctuation on the interval shrinkage amplitude, used to quantify the additional shrinkage force corresponding to each unit of fluctuation, a, b, and c are determined by those skilled in the art; by substituting the obtained effective deviation value of the compressed packet encapsulation and the encapsulation fluctuation coefficient into the formula, the corresponding reduction coefficient for the encapsulation interval of the verification data packet can be obtained; when the encapsulation stability is poor (high), W2 dominates the calculation of K3, and the anomaly detection sensitivity is improved by shrinking the interval first; when the deviation is large (ΔE is high), W1 dominates, and the interval is forcibly shrunk to make up for the security shortcomings, taking into account both risk control and system stability. The advantage of dynamic weighting adjustment lies in its ability to manage the differentiated priorities of risk factors, allowing the adjustment of the data packet encapsulation interval to better align with the actual security needs of conventional compressed packets. By incorporating the effective deviation value and encapsulation fluctuation coefficient into the weight allocation, it prioritizes the core risk of deviation—when severe—by increasing its weight and enhancing security through interval reduction. Meanwhile, the secondary risk of encapsulation fluctuation is only moderately weighted when fluctuations are significant, avoiding excessive interference with efficiency. This approach emphasizes the control of core risks while achieving flexibility through dual-factor weighting, finding a precise balance between security gains and efficiency losses, and avoiding the rigidity of adjustments driven by a single factor.
[0051] The determination of whether an invalid encapsulation adjustment process has been triggered is as follows: The effective encapsulation index of the compressed packet is re-acquired. If the effective encapsulation index is not lower than the first-class threshold value for effective encapsulation, the invalid encapsulation adjustment process is not triggered, and the packet is added to the transmission queue corresponding to the regular network resource compressed packet. If the effective encapsulation index is lower than the first-class threshold value for effective encapsulation, the invalid encapsulation adjustment process is triggered. When the network resource compressed packet type is regular, the packet encapsulation interval reduction coefficient is checked based on the deviation value, and the encapsulation interval is shortened, which can enhance the sensitivity of anomaly detection during the encapsulation process. Regular compressed packets need to strike a balance between security and resource consumption. Shortening the check interval allows for more frequent checks of the encapsulated data, timely detection of minor anomalies during the encapsulation process (such as data block misalignment), and facilitates correction before problems escalate, thereby driving up the effective encapsulation index of the compressed packet.
[0052] When the network resource compression package type is low priority, the amount of parallel task reduction is matched based on the effective deviation value of the compression package, thereby reducing the amount of parallel tasks in the network resource compression package encapsulation process, and determining whether the invalid encapsulation adjustment process is triggered. The specific matching process for matching the amount of parallel task reduction based on the effective deviation value of the compression package is as follows: the protection database presets the amount of parallel task reduction corresponding to each range of effective deviation value of compression package encapsulation. The obtained effective deviation value of compression package encapsulation is input into the database, and the database can match the corresponding amount of parallel task reduction. The original amount of parallel tasks is subtracted from the obtained amount of parallel task reduction, and the result is the amount of parallel tasks that need to be adjusted.
[0053] The determination of whether to trigger the invalid encapsulation adjustment process is as follows: The effective encapsulation index of the compressed packet is re-acquired. If the effective encapsulation index is not lower than the first-class threshold value for effective encapsulation, the invalid encapsulation adjustment process is not triggered, and the packet is added to the transmission queue corresponding to the low-priority network resource compressed packet. If the effective encapsulation index is lower than the first-class threshold value for effective encapsulation, the invalid encapsulation adjustment process is triggered. When the network resource compressed packet type is low-priority, the amount of parallel tasks is reduced based on the deviation value matching, thus reducing the amount of parallel tasks and improving encapsulation stability by reducing resource contention. Low-priority compressed packets have lower processing time requirements; reducing the amount of parallel tasks avoids resource conflicts caused by multiple tasks running simultaneously (such as disordered allocation of computing resources), reduces encapsulation errors caused by resource contention, and thus improves the effective encapsulation index of the compressed packet.
[0054] like Figure 4 The schematic diagram of the secure compressed package encapsulation verification and risk assessment process provided in this embodiment of the invention shows that the process begins with constructing a secure compressed package and obtaining the package encapsulation validity index; the package encapsulation validity threshold value group is corrected based on the resistance test results; then the package encapsulation validity index is compared with the package encapsulation validity threshold value group, and three cases are considered: if the package encapsulation validity index is greater than or equal to the first-class validity threshold value, it is classified as risk-free, and a transmission queue is allocated according to the package type to complete the protection; if it is between the first-class validity threshold value and the second-class validity threshold value, it is classified as low-risk, and optimization and adjustment are performed according to the type (adding redundant verification for emergency cases, shortening the verification interval for regular cases, and using low-priority parallel tasks), and the package encapsulation validity index is obtained again; if it is less than the second-class validity threshold value, it is classified as high-risk, triggering the invalid encapsulation adjustment process, and calling the backup engine to re-encapsulate.
[0055] Specifically, the process for determining whether to issue an anomaly warning for the data protection of network resource compressed packages is as follows: The effective re-evaluation index of the compressed package encapsulation is compared with the first-class threshold value for effective compressed package encapsulation. If the effective re-evaluation index is not lower than the first-class threshold value, it is determined that no anomaly warning will be issued for the data protection of network resource compressed packages; if the effective re-evaluation index is lower than the first-class threshold value, it is determined that an anomaly warning will be issued for the data protection of network resource compressed packages.
[0056] The aforementioned abnormal warning for data protection of network resource compressed packages refers to issuing warnings and reminders through security operation and maintenance terminal message notifications; the warning content includes basic information descriptions, abnormal quantitative data, etc.
[0057] Specifically, the data security protection packaging process parameters are monitored and acquired. The specific analysis process is as follows: The data security protection packaging process parameters include the data block packaging synchronization rate ratio coefficient, the dual-layer structure coupling ratio coefficient, and the packaging file volume expansion rate ratio coefficient. At the same time, the final value of the compressed package's anti-attack capability is acquired. By pre-setting the effect coefficients of each ratio coefficient and the final value of the compressed package's anti-attack capability in the protection database, their weight contribution value to the effective index of the compressed package packaging is quantified. Finally, a weighted average fusion algorithm is used to synthesize the effective index of the compressed package packaging.
[0058] The aforementioned data block encapsulation synchronization rate ratio coefficient represents the ratio of the data block encapsulation synchronization rate to the defined data block encapsulation synchronization rate during the data security protection encapsulation process; the aforementioned two-layer structure coupling ratio coefficient represents the ratio of the two-layer structure coupling degree to the defined two-layer structure coupling degree during the data security protection encapsulation process; the aforementioned encapsulated file volume expansion rate ratio coefficient represents the ratio of the encapsulated file volume expansion rate to the defined encapsulated file volume expansion rate during the data security protection encapsulation process; and the aforementioned compressed package anti-attack final value represents the anti-attack index of the compressed package that ultimately passes the initial data security protection inspection for network resource compressed packages.
[0059] The compression package effectiveness index represents the overall effectiveness of the secure compression package in ensuring data security after data security protection packaging. The specific evaluation method is as follows: ; ; ; ; In the formula, CPEEI is the effective index of compressed package encapsulation, CAI_z is the final value of compressed package anti-attack, DBESRF is the proportional coefficient of data block encapsulation synchronization rate in the data security protection encapsulation process, DBESR is the data block encapsulation synchronization rate in the data security protection encapsulation process, DDBESR is the preset defined data block encapsulation synchronization rate in the protection database, DSCDF is the proportional coefficient of the two-layer structure coupling degree in the data security protection encapsulation process, DSCD is the two-layer structure coupling degree in the data security protection encapsulation process, DDSCD is the preset defined two-layer structure coupling degree in the protection database, EFVERF is the proportional coefficient of the encapsulated file volume expansion rate in the data security protection encapsulation process, EFVER is the encapsulated file volume expansion rate in the data security protection encapsulation process, DEFVER is the preset defined encapsulated file volume expansion rate in the protection database, gd is the effect coefficient corresponding to the preset data block encapsulation synchronization rate proportional coefficient in the protection database, gf is the effect coefficient corresponding to the preset two-layer structure coupling degree proportional coefficient in the protection database, ge is the effect coefficient corresponding to the preset encapsulated file volume expansion rate proportional coefficient in the protection database, and gc is the effect coefficient corresponding to the preset compressed package anti-attack final value in the protection database.
[0060] The aforementioned data block encapsulation synchronization rate refers to the degree to which the time consistency and logical correlation of multiple data blocks within the compressed package meet the standards during the encapsulation process (such as the embedding of verification information). It is obtained by statistically analyzing the proportion of data blocks that are synchronized and pass logical verification within a preset time window to the total number of data blocks. The aforementioned dual-layer structure coupling degree, for compressed packages using dual-layer encapsulation, refers to the collaborative protection strength of the two-layer structure. It is obtained by calculating the inverse ratio of the number of attacks that break through a single layer versus those that break through both layers simultaneously. The aforementioned encapsulated file volume expansion rate refers to the ratio of the difference between the volume of the compressed package after encapsulation (such as adding redundant verification) and the original compressed package volume. It is obtained by calculating the percentage of the difference between the encapsulated and original volumes to the original volume.
[0061] The above definition of data block encapsulation synchronization rate refers to the minimum value of data block encapsulation synchronization rate within the specified range; the above definition of two-layer structure coupling degree refers to the minimum value of two-layer structure coupling degree within the specified range; the above definition of encapsulation file volume expansion rate represents the maximum value of encapsulation file volume expansion rate within the specified range.
[0062] An increase in the ratio of the data block encapsulation synchronization rate to its corresponding threshold value indicates that the synchronization of the data block encapsulation is superior to the threshold standard, and the timing and logical connections between data blocks are more precise. This increases the ratio of the coupling degree of the two-layer structure to its corresponding threshold value, decreases the ratio of the encapsulated file size expansion rate to its corresponding threshold value, and increases the final value of the compressed package's resistance to attacks. Under other unchanged conditions, an increase in the proportional coefficient of the data block encapsulation synchronization rate means better synchronization of the data block encapsulation, tighter logical connections between data blocks, and a reduction in the risk of encapsulation failure due to asynchrony. This positively impacts the effective index of the compressed package encapsulation, increasing it. Under other unchanged conditions... In this case, an increase in the coupling ratio of the dual-layer structure indicates stronger synergy between the two protection layers and more efficient linkage between the two protection mechanisms, which can improve the overall ability to resist attacks. Therefore, it will drive an increase in the effective index of compressed package encapsulation. Under other unchanged conditions, an increase in the expansion rate of the encapsulated file size will increase the processing burden and reduce the encapsulation efficiency, which will lead to a decrease in the effective index of compressed package encapsulation. The overall trend is that the effect first increases and then decreases. Under other unchanged conditions, an increase in the final value of the compressed package's resistance to attacks directly reflects the improvement in the final resistance to attacks of the compressed package. As a core influencing factor, it will significantly drive an increase in the effective index of compressed package encapsulation.
[0063] The effect coefficients corresponding to the aforementioned data block encapsulation synchronization rate ratio coefficients indicate that when the data block encapsulation synchronization rate ratio coefficient changes by a unit magnitude, the effective index of the compressed package encapsulation will change accordingly. Similarly, the effect coefficients corresponding to the aforementioned two-layer structure coupling ratio coefficients indicate that when the two-layer structure coupling ratio coefficient changes by a unit magnitude, the effective index of the compressed package encapsulation will change accordingly. The effect coefficients corresponding to the aforementioned encapsulated file volume expansion rate ratio coefficients indicate that when the encapsulated file volume expansion rate ratio coefficient changes by a unit magnitude, the effective index of the compressed package encapsulation will change accordingly. Finally, the effect coefficients corresponding to the aforementioned compressed package anti-attack final value indicate that when the compressed package anti-attack final value changes by a unit magnitude, the effective index of the compressed package encapsulation will change accordingly.
[0064] The mapping relationships between the data block encapsulation synchronization rate ratio coefficient and its corresponding effect coefficient in the protection database, the mapping relationships between the dual-layer structure coupling ratio coefficient and its corresponding effect coefficient, the mapping relationships between the encapsulated file volume expansion rate ratio coefficient and its corresponding effect coefficient, and the mapping relationships between the final value of the compressed package's anti-attack capability and its corresponding effect coefficient.
[0065] For example, the data block encapsulation synchronization rate ratio coefficient, the dual-layer structure coupling ratio coefficient, the encapsulated file volume expansion rate ratio coefficient, and the compressed package anti-attack final value are input into the protection database. The protection database generates the corresponding effect coefficients for the data block encapsulation synchronization rate ratio coefficient, the dual-layer structure coupling ratio coefficient, the encapsulated file volume expansion rate ratio coefficient, and the compressed package anti-attack final value based on preset mapping rules. The numerical range of each effect coefficient is strictly controlled between 0 and 1.
[0066] In a specific example embodiment, this invention provides a data security protection method for compressed data packets in network resources. Its core advantages lie in: combining virtual attack testing with quantitative indicator evaluation to pre-filter high-risk data; significantly enhancing core data security capabilities through environment-aware dynamic encryption and tamper-proof encapsulation; and dynamically adjusting protection strategies based on real-time risk levels. This solution ensures the security of data transmission and storage while also considering the processing efficiency of data with different priorities, effectively balancing protection strength and system resource consumption, and providing flexible and reliable full lifecycle security protection for compressed data in complex network environments.
[0067] like Figure 5 As shown in the schematic diagram of the compressed package encapsulation re-evaluation and protection completion process provided in this embodiment of the invention, after re-obtaining the compressed package encapsulation validity index, the compressed package encapsulation validity index is first compared with the first-class validity limit value of the compressed package encapsulation. If the compressed package encapsulation validity index is not lower than the first-class validity limit value of the compressed package encapsulation, the protection is completed by allocating a queue according to the type. If the compressed package encapsulation validity index is less than the first-class validity limit value of the compressed package encapsulation, invalid encapsulation adjustment is triggered, the backup engine is called to re-encapsulate and obtain the compressed package encapsulation re-evaluation index. The compressed package encapsulation validity re-evaluation index is compared with the first-class validity limit value of the compressed package encapsulation again. If the compressed package encapsulation validity re-evaluation index is not lower than the first-class validity limit value of the compressed package encapsulation, the protection is completed. Otherwise, an abnormal warning for data protection is issued and the process ends.
[0068] The present invention provides a computer-readable storage medium storing at least one instruction, which is loaded and executed by a processor to implement any of the above-described methods for data security protection of network resource compressed packages.
[0069] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0070] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A data security protection method for network resource compressed packages, characterized in that, The method includes: Step 1: Perform preprocessing operations on the network resource compressed package, and conduct a virtual attack resistance test on the network resource compressed package after the preprocessing operation to obtain the resistance test results. Obtain the preprocessing process parameters of the network resource compressed package, and determine whether the network resource compressed package passes the initial data security protection inspection based on the resistance test results. The resistance test results reflect the anti-attack capability of the preprocessed compressed package in actual attack scenarios. Step 2: Implement environment-aware dynamic encryption on the network resource compressed packages that pass the initial data security protection inspection, and encapsulate tamper-proof verification data to build a secure compressed package with data security protection; Step 3: Monitor and obtain the data security protection encapsulation process parameters of the secure compressed package, and classify the risk of the data security protection encapsulation result in combination with the resistance test results. If the risk of the data security protection encapsulation result is classified as no risk, the data security protection of the network resource compressed package is completed. If the risk of the data security protection encapsulation result is classified as low risk or high risk, the data protection of the network resource compressed package is adjusted.
2. The data security protection method for network resource compressed packets according to claim 1, characterized in that, The specific analysis process for obtaining the preprocessing parameters of the network resource compressed package is as follows: The preprocessing parameters include the redundancy check data coverage ratio coefficient, the abnormal format filtering ratio coefficient, and the sensitive field replacement ratio coefficient of the network resource compressed package preprocessing process. By presetting the effect coefficient of each ratio coefficient in the protection database, the weight contribution value of each ratio coefficient to the compressed package anti-attack index is quantified. Finally, a weighted average fusion algorithm is used to obtain the compressed package anti-attack index, where the compressed package anti-attack index refers to the basic anti-attack capability of the network resource compressed package after preprocessing operations at the static level.
3. The data security protection method for network resource compressed packages according to claim 1, characterized in that, The process of determining whether a network resource compressed package passes the initial data security protection inspection by combining the resistance test results is as follows: The resistance test result refers to the virtual attack resistance score of the compressed package obtained after the network resource compressed package completes the virtual attack resistance test. Based on the deviation between the virtual attack resistance score of the compressed package and the limit value of the virtual attack resistance score of the compressed package, a correction coefficient for the limit value of the compressed package is matched, thereby correcting the limit value of the compressed package. The obtained anti-attack index of the compressed package is compared with the anti-attack threshold value of the compressed package, which represents the minimum value of the anti-attack index of the compressed package within a specified range. When the anti-attack index of the compressed package is not lower than the anti-attack threshold of the compressed package, it is determined that the network resource compressed package has passed the initial data security protection inspection, and at the same time, environment-aware dynamic encryption is implemented on the network resource compressed package. When the anti-attack index of the compressed package is lower than the anti-attack threshold, it is determined that the network resource compressed package has failed the initial data security protection inspection, triggering a secondary preprocessing mechanism.
4. The data security protection method for network resource compressed packages according to claim 3, characterized in that, The specific analysis process of the triggering secondary preprocessing mechanism is as follows: Based on the anti-attack index and the anti-attack threshold of the compressed package, the comprehensive anti-attack deviation value is obtained. Based on the comprehensive anti-attack deviation value, the redundant verification data volume increase coefficient is matched, thereby increasing the redundant verification data volume of the network resource compressed package that failed the initial data security protection inspection. Based on the comprehensive anti-attack deviation value, the hash calculation iteration number increase coefficient is matched, thereby increasing the hash calculation iteration number of the network resource compressed package that failed the initial data security protection inspection. Obtain the attack resistance index of the compressed package after secondary preprocessing, mark it as the attack resistance reassessment index of the compressed package, and determine whether to issue an early warning for the preprocessing process of network resource compressed packages.
5. The data security protection method for network resource compressed packets according to claim 4, characterized in that, The specific determination process for whether to issue an early warning during the preprocessing of network resource compressed packages is as follows: Compare the compressed file's anti-attack reassessment index with the compressed file's anti-attack threshold value; When the anti-attack re-evaluation index of the compressed package is not lower than the anti-attack threshold of the compressed package, it is determined that no warning will be given for the preprocessing of the network resource compressed package. When the anti-attack reassessment index of compressed packets falls below the anti-attack threshold of compressed packets, an early warning is issued for the preprocessing of network resource compressed packets, and a preprocessing anomaly analysis report is pushed.
6. The data security protection method for network resource compressed packages according to claim 1, characterized in that, The risk classification process for data security protection encapsulation results, which combines the resistance test results, is as follows: Based on the deviation between the virtual attack resistance score of the compressed package and the limit value of the virtual attack resistance score of the compressed package, a correction coefficient is matched to the effective limit value group of the compressed package encapsulation, thereby correcting the effective limit value group of the compressed package encapsulation. The effective limit value group of the compressed package encapsulation includes the first type of effective limit value of the compressed package encapsulation and the second type of effective limit value of the compressed package encapsulation. The first type of effective limit value of the compressed package encapsulation is a value used to classify the data security protection encapsulation result into no risk and low risk. The second type of effective limit value of the compressed package encapsulation is a value used to classify the data security protection encapsulation result into low risk and high risk. By analyzing the data security protection encapsulation process parameters of the secure compressed package, the effective encapsulation index of the compressed package is obtained, and the effective encapsulation index of the compressed package is compared with the effective limit value group of the compressed package. When the effective index of compressed package encapsulation is not lower than the first-class threshold value of effective compressed package encapsulation, the risk of the data security protection encapsulation result is classified as risk-free, and the corresponding transmission queue is allocated based on the different types of network resource compressed packages. When the effective index of compressed package encapsulation is between the first-class and second-class effective limits of compressed package encapsulation, the risk of the data security protection encapsulation result is classified as low risk, and different optimization adjustments are made based on different types of network resource compressed packages. When the effective index of compressed package encapsulation is lower than the second-class threshold value of effective compressed package encapsulation, the risk of the data security protection encapsulation result is classified as high risk, triggering the invalid encapsulation adjustment process. That is, the backup encapsulation engine is called to re-encapsulate, the effective index of compressed package encapsulation is obtained again, marked as the effective re-evaluation index of compressed package encapsulation, and it is determined whether to issue an abnormal warning for the data protection of network resource compressed packages.
7. The data security protection method for network resource compressed packets according to claim 6, characterized in that, The optimization and adjustment are performed based on different types of network resource compression packages. The specific adjustment process is as follows: Based on the effective index of compressed package packaging and the first-class boundary value of effective compressed package packaging, the effective deviation value of compressed package packaging is obtained. When the network resource compressed package type is emergency, the redundant verification data ratio increase coefficient is matched based on the effective deviation value of the compressed package encapsulation, thereby increasing the redundant verification data in the network resource compressed package encapsulation process and including it in the transmission queue corresponding to the emergency network resource compressed package. When the network resource compression package type is regular, the verification data packet encapsulation interval reduction coefficient is matched based on the effective deviation value of the compression package encapsulation, thereby reducing the verification data packet encapsulation interval in the network resource compression package encapsulation process, and determining whether the invalid encapsulation adjustment process is triggered. The specific determination process for whether the invalid encapsulation adjustment process is triggered is as follows: re-acquire the effective index of the compressed package encapsulation. If the effective index of the compressed package encapsulation is not lower than the first-class threshold value of the effective compressed package encapsulation, it is determined that the invalid encapsulation adjustment process is not triggered, and it is included in the transmission queue corresponding to the regular network resource compressed package. If the effective index of the compressed package encapsulation is lower than the first-class threshold value of the effective compressed package encapsulation, it is determined that the invalid encapsulation adjustment process is triggered. When the network resource compression package type is low priority, the amount of parallel task reduction is matched based on the effective deviation value of the compression package, thereby reducing the amount of parallel tasks in the network resource compression package encapsulation process, and determining whether the invalid encapsulation adjustment process is triggered. The specific determination process for whether the invalid encapsulation adjustment process is triggered is as follows: re-acquire the effective encapsulation index of the compressed package. If the effective encapsulation index of the compressed package is not lower than the first-class threshold value of the effective encapsulation of the compressed package, it is determined that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the low-priority network resource compressed package. If the effective encapsulation index of the compressed package is lower than the first-class threshold value of the effective encapsulation of the compressed package, it is determined that the invalid encapsulation adjustment process is triggered.
8. The data security protection method for network resource compressed packets according to claim 6, characterized in that, The specific process for determining whether to issue an abnormal warning for the data protection of network resource compressed packages is as follows: Compare the effective re-evaluation index of compressed package packaging with the first-class boundary value of effective compressed package packaging; When the effective re-evaluation index of compressed package encapsulation is not lower than the first-class threshold value of effective compressed package encapsulation, it is determined that no abnormal warning will be issued for the data protection of network resource compressed packages. When the effective re-evaluation index of compressed package encapsulation is lower than the first-class threshold value of effective compressed package encapsulation, an abnormal warning is issued for the data protection of network resource compressed packages.
9. The data security protection method for network resource compressed packets according to claim 1, characterized in that, The specific analysis process for monitoring and acquiring the data security protection encapsulation process parameters of the secure compressed package is as follows: The data security protection and encapsulation process parameters include the data block encapsulation synchronization rate ratio coefficient, the dual-layer structure coupling degree ratio coefficient, and the encapsulated file volume expansion rate ratio coefficient. At the same time, the final value of the compressed package's anti-attack capability is obtained. By pre-setting the effect coefficients of each ratio coefficient and the final value of the compressed package's anti-attack capability in the protection database, their weight contribution value to the effective index of the compressed package encapsulation is quantified. Finally, a weighted average fusion algorithm is used to synthesize the effective index of the compressed package encapsulation, whereby the effective index of the compressed package encapsulation represents the comprehensive effectiveness of the secure compressed package in ensuring data security after data security protection and encapsulation.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code, which can be invoked by a processor to execute the data security protection method for network resource compressed packages as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Big Data-Based Network Security Protection Methods and Platforms
CN112333157B
A network security protection method based on big data
CN118869295B
Network attack protection method and device, storage medium and electronic equipment
CN111314328A
Attack vulnerability detection method and device for ZIP encrypted compressed packet, equipment and medium
CN112580057A
Security assessment method and device for malicious code detection system
CN120124055A