Data security protection method for network resource compression package and storage medium

By preprocessing network resource compressed packages and conducting virtual attack resistance tests, combined with environment-aware encryption and anti-tampering verification, a secure compressed package is constructed, which solves the problems of inflated data security protection and resource mismatch in existing technologies, and achieves flexible and reliable full lifecycle security protection.

CN121125359BActive Publication Date: 2026-02-17CSDN CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511661537.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-13
Publication Date
2026-02-17
Estimated Expiration
2045-11-13

AI Technical Summary

Technical Problem

Existing technologies for data security protection of compressed network resource packages suffer from several drawbacks. The preprocessing stage is insufficient to completely eliminate residual sensitive information, and the technology cannot intercept new types of malicious code. Fixed encryption strength and unified verification mechanisms result in inadequate protection of highly sensitive data and waste of low-value data resources. Furthermore, the lack of practical attack verification leads to problems such as inflated security protection and severe resource mismatch.

Method used

By preprocessing network resource compressed packages, conducting virtual attack resistance tests, performing initial checks based on the resistance test results, implementing environment-aware dynamic encryption and anti-tampering verification, constructing secure compressed packages, and adjusting protection strategies through dynamic monitoring and risk classification to achieve layered, dynamic, and adaptive security protection.

Benefits of technology

It achieves layered, dynamic, and adaptive data security protection for network resource compressed packets, improves the data's resistance to attacks and integrity, ensures data security during transmission and storage, optimizes the processing efficiency of data with different priorities, and avoids resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125359B_ABST
    Figure CN121125359B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data information transmission, and particularly discloses a data security protection method for a network resource compression package and a storage medium, wherein the network resource compression package is preprocessed first, then resistance test results are obtained through virtual attack resistance testing, and preliminary safety inspection is carried out, so that risks can be identified in advance, and the protection pertinence is improved; for the compression package that passes the preliminary inspection, environment-perception dynamic encryption is implemented, tamper-resistant check data is encapsulated to construct a safe compression package, and the anti-attack and tamper resistance of data in transmission and storage can be enhanced; subsequently, the encapsulation process parameters are monitored, risk classification processing is carried out in combination with the resistance test results, and if there is no risk, the protection is completed, and if there is a risk, the protection measures are adjusted, so that the dynamic adaptation of the protection is realized, over-protection or insufficient protection is avoided, the processing efficiency is considered while the data security is ensured, different scene requirements can be flexibly coped with, and reliable and safe protection of the whole process and multiple levels is provided for the network resource compression package.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data information transmission, in particular to a data security protection method for a network resource compression package and a storage medium. BACKGROUND

[0002] The current data security protection technology for network resource compression packages has formed a multi-dimensional protection system. Symmetric encryption, asymmetric encryption combined with digital certificates, and full-disk encryption are used to achieve static data protection. Access control mechanisms are used to strictly restrict data flow. Integrity checking methods are used to ensure data cannot be tampered with. Malicious code detection schemes are used to actively identify and block potential threats. Key management techniques are used to ensure the security of the encryption system. The process of compression followed by encryption is used for optimization. Hardware acceleration technology is introduced to significantly improve large-scale data processing efficiency and real-time protection capabilities.

[0003] For example, the Chinese invention patent with publication number CN118869295B discloses a network security protection method based on big data. The method includes the following steps: obtaining original network traffic data through a data pipeline tool; dividing time windows according to the original network traffic data to obtain time window traffic data; performing clustering feature description analysis according to the time window traffic data to obtain a traffic clustering label model; and generating a normal traffic baseline model according to the traffic clustering label model and the time window traffic data to obtain the normal traffic baseline model.

[0004] For example, the Chinese invention patent with publication number CN112333157B discloses a network security protection method and platform based on big data. First, in the process of a target attack device attacking a target virtual application, it is detected whether the target attack device identifies that the target virtual application runs on a virtual computer. Second, if it is detected that the target attack device identifies that the target virtual application runs on a virtual computer, target historical data is obtained from a first target database. Then, based on the target historical data, it is determined whether the target virtual application will be identified as running on a virtual computer when it is attacked next time. Finally, if it is determined that the target virtual application will be identified as running on a virtual computer, the target virtual application is run through a target physical computer.

[0005] The above-mentioned technology has at least the following technical problems: On the one hand, the preprocessing link relies on simple rule desensitization and format conversion, which cannot completely eliminate sensitive information residues and is difficult to intercept new malicious codes, forming a data leakage risk. On the other hand, fixed encryption strength and unified verification mechanism ignore the actual risk level of data, leading to insufficient protection of high-sensitive data and waste of low-value data resources. Moreover, the lack of real combat attack verification link makes the protection effect deviate from the real threat scenario, resulting in overestimation of compression package security protection and serious resource mismatch. SUMMARY

[0006] In order to solve the technical problems of high security protection and serious resource mismatch of compression package in the prior art, the embodiment of the present application provides a data security protection method for network resource compression package and a storage medium. The technical scheme is as follows:

[0007] On the one hand, the data security protection method for network resource compression package is provided, which comprises the following steps:

[0008] Step 1: performing a preprocessing operation on the network resource compression package, performing a virtual attack resistance test on the network resource compression package after the preprocessing operation is completed, thereby obtaining a resistance test result, acquiring preprocessing process parameters of the network resource compression package, and judging whether the network resource compression package passes the data security protection preliminary inspection in combination with the resistance test result; the resistance test result reflects the anti-attack ability of the compression package after preprocessing in the actual attack scene; Step 2: implementing environment-aware dynamic encryption on the network resource compression package that passes the data security protection preliminary inspection, and encapsulating tamper-resistant check data to build a secure compression package with data security protection; Step 3: monitoring and acquiring data security protection encapsulation process parameters of the secure compression package, and performing risk classification processing on the data security protection encapsulation result in combination with the resistance test result; if the risk of the data security protection encapsulation result is classified as no risk, the data security protection of the network resource compression package is completed; if the risk of the data security protection encapsulation result is classified as low risk or high risk, the data protection of the network resource compression package is adjusted.

[0009] On the other hand, a computer-readable storage medium is provided, and the storage medium stores at least one instruction, which is loaded and executed by a processor to implement any one of the above-mentioned data security protection methods for network resource compression package.

[0010] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:

[0011] (1) The present application provides a data security protection method for network resource compression package and a storage medium, and builds a whole-process protection system of preprocessing preliminary inspection-dynamic encryption encapsulation-encapsulation risk adjustment, realizes the layering, dynamic and self-adaptation of network resource compression package data security protection. The core advantage is to combine virtual attack test and quantitative index evaluation, which can filter high-risk data through pre-protection, strengthen core security capability through environment-aware encryption and tamper-resistant encapsulation, and dynamically adjust the protection strategy according to the risk level, which can balance the security protection strength and system resource consumption while ensuring the security of data transmission and storage, effectively balancing the security protection strength and system resource consumption, and providing flexible and reliable whole life cycle security protection for compression package data in complex network environment.

[0012] (2) Through the combination of preprocessing, virtual attack resistance test and compressed package attack resistance index evaluation, the pre-filtering and precise prevention and control of risks are realized. The virtual attack test simulates the actual combat scene, exposes the security short board after preprocessing in advance, and the comparison of the compressed package attack resistance index and its corresponding limit value provides a quantitative basis for the preliminary inspection. The secondary preprocessing mechanism can compensate for the security defects that do not pass the preliminary inspection by dynamically increasing the amount of redundant check data and the number of hash iterations, and improve the data tamper resistance and cracking resistance; and the warning and abnormal report mechanism ensures the controllability under extreme risk, reduces the subsequent protection pressure from the source, and builds the first line of defense for overall security protection.

[0013] (3) Through the environment perception dynamic encryption + tamper resistance check packaging of the compressed package in the preliminary inspection, the core data protection capability is significantly improved. The environment perception dynamic encryption integrates real-time variables such as time stamp and device identifier, so that the same data generates different ciphertexts in different environments, greatly increasing the cracking complexity of attackers; the packaging of tamper resistance check data provides a rigid guarantee for data integrity, which can effectively resist tampering attacks in the transmission or storage process. The combination of the two forms a double protection of encryption + check, which not only protects the data content from being stolen, but also ensures that the data is not illegally tampered with in the circulation, and builds a high-strength security barrier for core data.

[0014] (4) Through dynamic monitoring, risk classification and self-adaptive adjustment of the packaging results, the security protection is refined and efficient. Based on the comparison of the packaging effective index and its corresponding limit value, different types of network resource compressed packages are taken differential strategies: the transmission efficiency and security of emergency data are preferentially guaranteed, and the risk is reduced by enhancing the check structure; the packaging interval of regular data is optimized to improve the timeliness of abnormal monitoring; the low-priority data adjusts the parallel task to balance stability and resource consumption. At the same time, the re-packaging and early warning mechanism further reduces the risk of invalid packaging, ensures the precise matching of protection measures and data security needs, improves the overall protection effectiveness, and avoids resource waste caused by excessive protection. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creating laborious work.

[0016] Figure 1 is the data security protection method flowchart for network resource compressed package provided by the embodiment of the present application;

[0017] Figure 2is a data security protection preliminary inspection process schematic diagram provided by the embodiment of the present application;

[0018] Figure 3 is a secondary preprocessing and re-evaluation process schematic diagram provided by the embodiment of the present application;

[0019] Figure 4 is a security compressed package encapsulation verification and risk determination process schematic diagram provided by the embodiment of the present application;

[0020] Figure 5 is a compressed package encapsulation re-evaluation and protection finishing process schematic diagram provided by the embodiment of the present application. DETAILED DESCRIPTION

[0021] The technical solutions in the present application will be described below with reference to the drawings.

[0022] In the embodiments of the present application, the words such as "example", "for example" are used to represent as an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.

[0023] In order to make the technical problems, technical solutions and advantages of the present application clearer, the following will be described in detail with reference to the drawings and specific embodiments.

[0024] The embodiment of the present application provides a data security protection method for a network resource compressed package, such as Figure 1 As shown in the data security protection method flow chart for the network resource compressed package, the processing flow of the method can include the following steps:

[0025] Step one, the network resource compression package is preprocessed, the network resource compression package after preprocessing is tested for virtual attack resistance, the resistance test result is obtained, the preprocessing process parameters of the network resource compression package are obtained, and whether the network resource compression package passes the data security protection preliminary inspection is judged combined with the resistance test result. The resistance test result reflects the anti-attack ability of the compressed package after preprocessing in the actual attack scene. The above preprocessing operation of the network resource compression package specifically includes format normalization processing (such as correcting metadata), redundant data cleaning (such as removing invalid redundancy), sensitive information desensitization (such as replacing privacy and core data), integrity preliminary verification (verifying the integrity of the whole and block level data by comparing the hash value), anti-attack basic strengthening (adding basic verification header, lightweight encryption of directory items) and other steps. These operations aim to improve the format consistency, simplify redundancy, reduce the risk of sensitive information leakage, detect inherent defects and strengthen the basic anti-attack ability, provide standardized and low-risk basic samples for subsequent virtual attack resistance test, dynamic encryption and security packaging, and ensure the effectiveness and accuracy of the whole process security protection.

[0026] Step two, the network resource compression package that passes the data security protection preliminary inspection is implemented with environment-aware dynamic encryption, and the anti-tamper verification data is packaged to build a secure compression package with data security protection. The above anti-tamper verification data is packaged with a double-layer packaging structure. The outer layer is encrypted and protected by a dynamic encryption algorithm (such as a session key generated based on environmental parameters), and the inner layer is separately packaged with anti-tamper verification data (including block-level hash and associated mapping information) for the core data block in the compression package. The two-layer structure realizes cooperative protection through key association mechanism. The specific process of packaging anti-tamper verification data is as follows: generate a dedicated hash value (such as SHA-384) for each data block in the compression package and record its metadata, at the same time, generate an overall root hash value integrating all data block information combined with time stamp and random salt value, form multi-layer verification data; then, according to the structure of block-level verification of overall verification, attach the block-level verification data at the end of the corresponding data block, package the overall verification data in the tail special verification section and protect it through encryption signature, at the same time, establish the rigid association (such as embedding unique identifier and location index) between data block and verification data, and preset the dynamic verification trigger mechanism of reading, transmission, decompression and other links. In this way, the tampering behavior can be accurately identified by comparing the verification data with the original data, and the tampering position can be quickly located, the compression package can be locked immediately when an anomaly is found, ensuring the integrity of the data throughout the life cycle, and providing a reliable tampering monitoring basis for security protection.

[0027] Step three, monitor and obtain the data security protection encapsulation process parameters of the security compression package, and combine the resistance test results to classify the data security protection encapsulation results. If the risk classification of the data security protection encapsulation result is no risk, the data security protection of the network resource compression package is completed. If the risk classification of the data security protection encapsulation result is low risk or high risk, the data protection of the network resource compression package is adjusted.

[0028] Specifically, the preprocessing process parameters of the network resource compression package are obtained, and the specific analysis process is as follows: the preprocessing process parameters include the redundancy check data coverage ratio coefficient, the abnormal format filtering rate ratio coefficient and the sensitive field replacement rate ratio coefficient of the network resource compression package preprocessing process. By presetting the effect coefficient of each ratio coefficient in the protection database, the weight contribution value of each ratio coefficient to the compression package attack resistance index is quantified, and finally the weighted average fusion algorithm is adopted to obtain the compression package attack resistance index.

[0029] The redundancy check data coverage ratio coefficient refers to the ratio of the redundancy check data coverage rate of the network resource compression package preprocessing process to the defined redundancy check data coverage rate. The abnormal format filtering rate ratio coefficient refers to the ratio of the abnormal format filtering rate of the network resource compression package preprocessing process to the defined abnormal format filtering rate. The sensitive field replacement rate ratio coefficient refers to the ratio of the sensitive field replacement rate of the network resource compression package preprocessing process to the defined sensitive field replacement rate.

[0030] The compression package attack resistance index refers to the anti-attack basic ability of the network resource compression package after preprocessing operation at the static level. The specific evaluation method is as follows:

[0031] ;

[0032] ;

[0033] ;

[0034] ;

[0035] In the formula, CAI is a compression package attack resistance index, RCDCF is a redundancy check data coverage rate proportionality coefficient of a network resource compression package preprocessing process, RCDC is a redundancy check data coverage rate of the network resource compression package preprocessing process, DRCDC is a preset defined redundancy check data coverage rate in a protection database, AFFRF is an abnormal format filtering rate proportionality coefficient of the network resource compression package preprocessing process, AFFR is an abnormal format filtering rate of the network resource compression package preprocessing process, DAFFR is a preset defined abnormal format filtering rate in the protection database, SFRRF is a sensitive field replacement rate proportionality coefficient of the network resource compression package preprocessing process, SFRR is a sensitive field replacement rate of the network resource compression package preprocessing process, DSFRR is a preset defined sensitive field replacement rate in the protection database, fr is an effect coefficient corresponding to the redundancy check data coverage rate proportionality coefficient preset in the protection database, fa is an effect coefficient corresponding to the abnormal format filtering rate proportionality coefficient preset in the protection database, and fs is an effect coefficient corresponding to the sensitive field replacement rate proportionality coefficient preset in the protection database.

[0036] It should be explained that the redundancy check data coverage rate represents a coverage proportion of redundancy check data in overall data of a compression package, is used for measuring a protection range of a check mechanism on data, and is obtained by dividing a total amount of redundancy check data by a total data amount of the compression package and then multiplying by 100%; the abnormal format filtering rate represents a proportion of successfully identified and filtered abnormal format data of all abnormal format data, and is obtained by dividing a number of successfully filtered abnormal format data by a total number of detected abnormal format data and then multiplying by 100%; and the sensitive field replacement rate represents a proportion of a number of safely replaced sensitive fields in the compression package to a total amount of all sensitive fields, and is obtained by dividing a number of successfully replaced sensitive fields by a total number of identified sensitive fields and then multiplying by 100%.

[0037] The defined redundancy check data coverage rate represents a minimum value of the redundancy check data coverage rate in a specified range; the defined abnormal format filtering rate represents a minimum value of the abnormal format filtering rate in the specified range; and the defined sensitive field replacement rate represents a minimum value of the sensitive field replacement rate in the specified range.

[0038] An increase in a ratio of the redundancy check data coverage rate to the corresponding defined value indicates that an actual redundancy check coverage range far exceeds a basic security standard, and data tamper resistance and repair capability are significantly enhanced, which reduces misjudgments caused by data damage in the abnormal format filtering process, reduces interference factors of the filtering mechanism, and thus makes a ratio of the abnormal format filtering rate to the corresponding defined value more likely to increase; at the same time, the probability of exposure of sensitive fields due to data loss is also reduced, a more stable environment is provided for sensitive information replacement, and thus a ratio of the sensitive field replacement rate to the corresponding defined value tends to increase, and finally the compression package attack resistance index is increased.

[0039] The effect coefficient corresponding to the redundancy check data coverage ratio coefficient indicates that when the redundancy check data coverage ratio coefficient changes by a unit amplitude, the compression package attack resistance index will change by a corresponding amplitude. The effect coefficient corresponding to the abnormal format filtering rate ratio coefficient indicates that when the abnormal format filtering rate ratio coefficient changes by a unit amplitude, the compression package attack resistance index will change by a corresponding amplitude. The effect coefficient corresponding to the sensitive field replacement rate ratio coefficient indicates that when the sensitive field replacement rate ratio coefficient changes by a unit amplitude, the compression package attack resistance index will change by a corresponding amplitude. The protection database stores the mapping relationship between the redundancy check data coverage ratio coefficient and its corresponding effect coefficient, the mapping relationship between the abnormal format filtering rate ratio coefficient and its corresponding effect coefficient, and the mapping relationship between the sensitive field replacement rate ratio coefficient and its corresponding effect coefficient. For example, the redundancy check data coverage ratio coefficient, the abnormal format filtering rate ratio coefficient, and the sensitive field replacement rate ratio coefficient are input into the protection database. The protection database generates the corresponding effect coefficient of the redundancy check data coverage ratio coefficient, the effect coefficient of the abnormal format filtering rate ratio coefficient, and the effect coefficient of the sensitive field replacement rate ratio coefficient based on the preset mapping rule. The numerical range of each type of effect coefficient is strictly controlled between 0 and 1.

[0040] Specifically, the resistance test result is used to determine whether the network resource compression package passes the data security protection preliminary inspection. The specific determination process is as follows: the resistance test result refers to the compression package virtual attack resistance score obtained after the network resource compression package completes the virtual attack resistance test. Based on the deviation value of the compression package virtual attack resistance score and the compression package virtual attack resistance score limit value, the correction coefficient of the compression package attack limit value is matched, so as to correct the compression package attack limit value. The compression package attack limit value in the following text is the corrected compression package attack limit value.

[0041] The virtual attack resistance test is based on the simulation of actual combat ideas. Through the built simulation attack environment, the preset attack algorithm library is used to cover common network attack types such as brute force cracking, data tampering, replay attack, malicious code injection, etc. The preprocessed compression package is launched multi-dimensional and step-by-step virtual attack. During the test, the system will monitor the state change of the compression package under attack in real time, such as whether the data integrity is damaged, whether the encryption layer is penetrated, whether the check mechanism is invalid, etc. According to the preset scoring rules such as the type of attack resistance, attack intensity, defense response speed, etc., a quantitative score is generated, that is, the compression package virtual attack resistance score. The above-mentioned preset scoring rules are the standards for converting the performance of the compression package in virtual attack into a quantitative score, mainly from the ability to resist attack and the performance in response to attack.

[0042] For example, the base score can be set to 100 points, in terms of the type of attack resistance, 10 points for successfully resisting brute force attacks, 15 points for resisting data tampering, 12 points for resisting replay attacks, and 18 points for resisting malicious code injection. If a certain attack is not resisted, the corresponding score will be deducted; in terms of attack strength, 10 points for remaining stable under low-intensity attacks, 15 points for remaining stable under medium-intensity attacks, and 20 points for remaining stable under high-intensity attacks. When the intensity increases, 5 points will be deducted for minor abnormalities, and 15 points will be deducted for serious abnormalities; in terms of defense response speed, 10 points for responding and intercepting attacks within 1 second, 5 points for responding and intercepting attacks within 1-3 seconds, and 10 points for not responding within 3 seconds.

[0043] The deviation value of the compression package virtual attack resistance score and the compression package virtual attack resistance score limit value matches the correction coefficient of the compression package attack resistance limit value, specifically: , The deviation value of the compression package virtual attack resistance score and the compression package virtual attack resistance score limit value is marked as the score deviation value, S is the compression package virtual attack resistance score, and the maximum value is 1, S0 is the compression package virtual attack resistance score limit value, a preset score deviation value-correction coefficient mapping table in the protection database is input into the database, and the corresponding correction coefficient is matched. The correction coefficient is brought into the formula , and the corrected compression package attack resistance limit value is obtained, wherein S1 is the corrected compression package attack resistance limit value, T0 is the compression package attack resistance limit value, and K is the matched correction coefficient. Through dynamic correction, the limit value will automatically adjust with the deviation of the actual score, thereby reducing false positives from the root. The correction coefficient matched based on the deviation value corrects the compression package attack resistance limit value, so that the security evaluation standard can break free from the static and rigid limitations and dynamically adapt to the actual security level. This mechanism can avoid false positives caused by excessively high or low standards. When the compression package attack resistance ability significantly improves, the limit value is adjusted upward to reflect the true protection strength and prevent the standard from being too low to cover up risks. When the ability decreases, the limit value is adjusted downward to avoid unnecessarily increasing the preprocessing cost due to the excessively high standard.

[0044] As Figure 2 shown in the data security protection preliminary inspection process schematic diagram provided by the embodiments of the present application, after the process starts, the network resource compression package is preprocessed, and the resistance test results and the attack resistance index thereof are obtained; then the compression package attack resistance limit value is corrected according to the resistance test results; finally, the compression package attack resistance index and the compression package attack resistance limit value are compared. If the compression package attack resistance index is not lower than the compression package attack resistance limit value, the data security protection preliminary inspection is passed, and the construction of the secure compression package is entered; otherwise, the secondary preprocessing mechanism is triggered.

[0045] The obtained compression package attack resistance index is compared with a compression package attack resistance limit value, which represents the minimum value of the compression package attack resistance index within a specified range. When the compression package attack resistance index is not lower than the compression package attack resistance limit value, it is determined that the network resource compression package passes the initial data security protection check, and the network resource compression package is subjected to environment-aware dynamic encryption. When the compression package attack resistance index is lower than the compression package attack resistance limit value, it is determined that the network resource compression package does not pass the initial data security protection check, triggering a secondary preprocessing mechanism.

[0046] The above-mentioned environment-aware dynamic encryption of the network resource compression package is a high-level protection method that dynamically adjusts the encryption logic in combination with real-time environmental parameters. Specifically, this encryption method collects environmental variables in which the compression package is located in real time, including but not limited to the current timestamp, device hardware identifier, and network environment parameters, and incorporates these dynamic variables as salt values (a technique in the field of cryptography and data security that enhances encryption security by introducing randomization information to avoid the same plaintext producing the same ciphertext after encryption, thereby resisting targeted attacks such as rainbow table attacks) into the key generation or encryption operation steps of the encryption algorithm. For example, the same original compression package will generate significantly different ciphertexts in different times, different devices, or different network environments. Even if an attacker intercepts the ciphertext at a certain time, it is impossible to decrypt it in other environments by reusing the ciphertext or key, because the dynamic changes in environmental variables cause the encryption logic to be always in a dynamic updating state. The advantage of this encryption method is that it breaks through the limitations of traditional static encryption where the same key corresponds to fixed ciphertext. Through the randomness and uniqueness of environmental factors, it is difficult for attackers to obtain the original data through brute force cracking or ciphertext comparison, further strengthening the security protection capability of the compression package that passes the initial check during transmission and storage, and laying a dynamic security foundation for subsequent tamper-resistant packaging.

[0047] Further, the secondary preprocessing mechanism is triggered, and the specific analysis process is as follows: based on the compression package attack resistance index and the compression package attack resistance limit value, an attack resistance comprehensive deviation value is obtained, a redundant check data amount increasing coefficient is matched based on the attack resistance comprehensive deviation value, thereby increasing the redundant check data amount of the network resource compression package that does not pass the initial data security protection check, and a hash calculation iteration number increasing coefficient is matched based on the attack resistance comprehensive deviation value, thereby increasing the hash calculation iteration number of the network resource compression package that does not pass the initial data security protection check.

[0048] The anti-attack comprehensive deviation value refers to the anti-attack limit value of the compressed package minus the anti-attack index of the compressed package. The specific matching process is that the redundancy check data amount increasing coefficient corresponding to each anti-attack comprehensive deviation value interval in the protection database is preset, the obtained anti-attack comprehensive deviation value is input into the database, and the redundancy check data amount increasing coefficient corresponding to the interval of the anti-attack comprehensive deviation value can be matched by the database. The redundancy check data amount increasing coefficient obtained is multiplied by the original redundancy check data amount, and the obtained result is the redundancy check data amount that needs to be adjusted. The redundancy check data amount increasing coefficient is greater than 1, indicating that the redundancy check data amount needs to be increased by a multiple value. The redundancy check data amount increasing coefficient is matched based on the anti-attack comprehensive deviation value, and the redundancy check data amount is increased. The core benefit is to improve the anti-tampering and fault tolerance of the data. When the anti-attack index of the compressed package does not reach the limit value, the greater the deviation value, the higher the risk of data being tampered with or damaged during transmission or storage. By dynamically increasing the redundancy check data amount, more redundancy information for checking and repairing can be included in the data. Even if part of the data block is tampered with or lost, the system can quickly identify the exception and complete the repair based on the expanded redundancy data, greatly reducing the security risk caused by the damage of data integrity. At the same time, this on-demand increasing method avoids the waste of resources caused by excessive redundancy data, and accurately matches the protection strength with the actual risk.

[0049] The anti-attack comprehensive deviation value is matched to obtain a hash calculation iteration number increasing coefficient. The specific matching process is that the anti-attack comprehensive deviation value is divided by the anti-attack limit value of the compressed package, and the obtained result is percentage. The matching of the hash calculation iteration number increasing coefficient is realized through a preset nonlinear function. The hash calculation iteration number increasing coefficient is greater than 1, indicating that the hash calculation iteration number needs to be increased by a multiple value. The hash calculation iteration number increasing coefficient is matched based on the anti-attack comprehensive deviation value, and the iteration number is increased. This can significantly enhance the anti-cracking ability of the data. The hash calculation iteration number is positively correlated with the cracking difficulty. The more the iteration number, the higher the computing power and time cost required by the attacker to obtain the original data through brute force cracking. When the anti-attack index of the compressed package is insufficient, the deviation value reflects the weakness of the current hash protection. The greater the deviation, the more difficult it is to resist potential attacks with the existing iteration number. By dynamically improving the iteration number, the cracking threshold of the attacker can be directly increased, especially for the brute force cracking method that relies on computing power to form an effective deterrent. In addition, this adjustment method avoids excessive consumption of system resources while ensuring security, achieving a balance between protection efficiency and security.

[0050] In one specific example embodiment, the nonlinear function is:

[0051] ;

[0052] wherein k2 is a hash calculation iteration number increasing coefficient, is an anti-attack comprehensive deviation value, d1, d2, and d3 are constant terms of slight deviation, moderate deviation, and severe deviation, respectively; m1, m2, and m3 are linear coefficients of the slight deviation section, the moderate deviation section, and the severe deviation section, respectively, and the specific values of the linear coefficients are determined by the relevant professional technicians in the art; the above Q is the demarcation value between slight deviation and moderate deviation, and the above P is the demarcation value between moderate deviation and severe deviation; the anti-attack comprehensive deviation value obtained is substituted into the above nonlinear function, and the corresponding hash calculation iteration number increasing coefficient is obtained; the hash calculation iteration number increasing coefficient obtained is multiplied by the original hash calculation iteration number, and the result obtained is the hash calculation iteration number that needs to be adjusted. Update the function parameters regularly according to historical cracking cases: if the compressed package in a certain deviation interval is cracked multiple times, the function slope of the corresponding interval will be adjusted upwards (such as the slope of the moderate deviation section from 0.002 to 0.003), to ensure that the coefficient matches the actual attack strength more closely. The segmented function is used to match the hash calculation iteration number increasing coefficient, which can not only adopt a differentiated amplification strategy according to different orders of magnitude of the anti-attack comprehensive deviation value, but also can reduce the waste of computing power by linear amplification for slight deviation, balance safety and efficiency by quadratic function for moderate deviation, and quickly strengthen the short board by exponential amplification for severe deviation. In addition, the function characteristics can be flexibly embedded to control the upper limit of the amplification to prevent excessive consumption of resources, and it is also convenient to dynamically optimize the parameters of each segment combined with actual attack data, to adjust the iteration amplification in a targeted manner to respond to changes in attack patterns, and ultimately realize the unity of deviation adaptability, resource controllability, and strategy adaptability.

[0053] As Figure 3 , the secondary pretreatment and reevaluation process provided by the embodiments of the present application is shown in the schematic diagram, when the compressed package does not pass the data security protection preliminary inspection, the secondary pretreatment mechanism is triggered; based on the anti-attack comprehensive deviation value, the amount of redundant check data and the hash calculation iteration number are increased; then the anti-attack reevaluation index of the compressed package is obtained, and the anti-attack reevaluation index of the compressed package is compared with the anti-attack limit value of the compressed package, if the anti-attack reevaluation index of the compressed package is not lower than the anti-attack limit value of the compressed package, a safe compressed package is constructed and the compressed package packaging effective index is obtained, otherwise the pretreatment process is warned, an abnormal analysis report is pushed, and the process is ended.

[0054] The anti-attack index of the compressed package after secondary pretreatment is obtained, which is marked as the anti-attack reevaluation index of the compressed package, and it is judged whether the pretreatment process of the network resource compressed package is warned.

[0055] Specifically, whether to give a warning to the preprocessing process of the network resource compression package is determined, and the specific determination process is: comparing the compression package anti-attack re-evaluation index with the compression package anti-attack limit value; when the compression package anti-attack re-evaluation index is not lower than the compression package anti-attack limit value, it is determined that no warning is given to the preprocessing process of the network resource compression package; when the compression package anti-attack re-evaluation index is lower than the compression package anti-attack limit value, it is determined that the preprocessing process of the network resource compression package is warned, and a preprocessing exception analysis report is pushed.

[0056] It should be explained that the above warning of the preprocessing process of the network resource compression package means that the security management terminal sends a warning message to clearly inform that the current preprocessing process cannot make the compression package meet the basic security standard, and marks the warning level; the above pushing of the preprocessing exception analysis report includes three parts: one is the comparison of basic data, which clearly lists the key parameters (such as redundancy check data coverage) before and after preprocessing, and intuitively presents the quantitative gap of unmet standard; two is the positioning of abnormal link, which identifies the key steps (such as redundancy check algorithm call failure) that may cause security defects by backtracking the preprocessing process log, and marks the influence weight of each link on the re-evaluation index; three is the optimization suggestion, which combines historical cases and successful preprocessing schemes of similar compression packages to propose targeted improvement direction.

[0057] In one specific example embodiment, by implementing environment-aware dynamic encryption and anti-tamper check packaging on compression packages that pass the preliminary inspection, the data core protection capability is significantly improved. Environment-aware dynamic encryption integrates real-time variables such as time stamp and device identification to ensure that the same data generates unique ciphertext in different environments, greatly improving the difficulty and cost of attackers to crack; at the same time, anti-tamper check packaging provides rigid protection for data integrity, effectively resisting malicious tampering during transmission or storage. The two together build a double-layer protection system of encryption anti-theft + check integrity: not only prevent unauthorized theft of core data content, but also ensure the integrity and authenticity of data in the whole process of circulation.

[0058] Further, the data security protection packaging result is classified according to the resistance test result, and the specific analysis process is as follows: a correction coefficient of a compressed package packaging effective limit value group is matched based on a deviation value of the compressed package virtual attack resistance score and the compressed package virtual attack resistance score limit value, so as to correct the compressed package packaging effective limit value group. The compressed package packaging effective limit value group in the following is the corrected compressed package packaging effective first-class limit value and the compressed package packaging effective second-class limit value. The compressed package packaging effective limit value group includes the compressed package packaging effective first-class limit value and the compressed package packaging effective second-class limit value. The compressed package packaging effective first-class limit value is a numerical value for classifying the data security protection packaging result into no risk and low risk. The compressed package packaging effective second-class limit value is a numerical value for classifying the data security protection packaging result into low risk and high risk.

[0059] The correction coefficient of the compressed package packaging effective limit value group is matched based on the deviation value of the compressed package virtual attack resistance score and the compressed package virtual attack resistance score limit value. Specifically, a preset score deviation value-compressed package packaging effective first-class limit value correction coefficient mapping table and a score deviation value-compressed package packaging effective second-class limit value correction coefficient mapping table in the protection database are used. The obtained score deviation value is input into the database, and the corresponding compressed package packaging effective first-class limit value correction coefficient L1 or the compressed package packaging effective second-class limit value correction coefficient L2 can be matched in the database. The correction coefficient is brought into the formula , , and the corrected compressed package attack limit value can be obtained. In the formula, R1 is the corrected compressed package packaging effective first-class limit value, R2 is the corrected compressed package packaging effective second-class limit value, R 01 is the compressed package packaging effective first-class limit value, and R 02 is the compressed package packaging effective second-class limit value. The correction coefficient of the compressed package packaging effective limit value matched based on the deviation value of the compressed package virtual attack resistance score and the compressed package virtual attack resistance score limit value can dynamically synchronize the risk classification standard and the actual security capability of the compressed package: by adjusting the limit value with the deviation value, the risk is underestimated when the deviation value is positive, and the classification is too strict when the deviation value is negative, so as to ensure that the risk label is consistent with the actual situation. After correction, the hierarchical relationship is maintained, and the amplitude changes dynamically with the deviation, which can accurately expand or shrink the high-risk range, tilt the resources to the link that needs to be strengthened, and improve the response pertinence. At the same time, this mechanism can capture the change of the security level in real time, so that the classification standard automatically adapts to the network environment dynamics, and the security system tightens the defense line when the risk increases, and remains flexible when the security improves.

[0060] The compressed package encapsulation effective index is compared with the compressed package encapsulation effective limit value group; when the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class limit value, the risk of the data security protection encapsulation result is classified as no risk, and corresponding transmission queues are allocated based on different types of network resource compression packages; when the compressed package encapsulation effective index is between the compressed package encapsulation effective first-class limit value and the compressed package encapsulation effective second-class limit value, the risk of the data security protection encapsulation result is classified as low risk, and different optimization adjustments are made based on different types of network resource compression packages; when the compressed package encapsulation effective index is lower than the compressed package encapsulation effective second-class limit value, the risk of the data security protection encapsulation result is classified as high risk, and an invalid encapsulation adjustment process is triggered, that is, a standby encapsulation engine is called to re-encapsulate, the compressed package encapsulation effective index is re-acquired, and the compressed package encapsulation effective re-evaluation index is marked, and it is judged whether to perform abnormal early warning on the data protection of the network resource compression package.

[0061] It needs to be explained that the above-mentioned allocation of corresponding transmission queues based on different types of network resource compression packages refers to the combination of the business priority and processing demand of the network resource compression package, and the network resource compression package is divided into emergency class, regular class and low priority class; the emergency class network resource compression package usually involves high real-time requirement core business (such as emergency instructions), and needs to be preferentially guaranteed for transmission timeliness, so it is included in the priority transmission queue, which enjoys the highest bandwidth occupation right and processing priority, and can skip unnecessary transmission queuing link and directly enter the data sending channel, and has priority to obtain resource scheduling in network congestion, so as to ensure that the compression package completes transmission with the shortest delay and avoids affecting the emergency business due to transmission lag; the regular class network resource compression package covers daily business data (such as regular information interaction), and has moderate real-time requirement, but needs to ensure transmission stability, so it is included in the standard transmission queue, which adopts sequential scheduling mechanism, and transmits in turn according to the submission order when the bandwidth resource is sufficient, and maintains the basic transmission rate through dynamic bandwidth allocation when the resource is tight, which avoids occupying too many resources to affect the emergency class data, and ensures the normal progress of the regular business, balances the efficiency and resource fairness; the low priority class network resource compression package is mostly non-core and delayable data (such as historical log archiving), and has low transmission timeliness requirement, so it is included in the delay transmission queue, which only starts transmission in network idle period (such as when the bandwidth utilization is less than 30%), and the transmission rate is limited by the remaining resources, avoiding resource competition with high priority data. This peak-shaving transmission mode enables different types of network resource compression packages to obtain resource support matching their business value in the transmission link, ensuring the timeliness of emergency business and avoiding resource waste, and finally achieving the coordinated optimization of security protection and business efficiency.

[0062] Further, different optimization adjustments are made based on different types of network resource compression packages. The specific adjustment process is as follows: based on the compression package encapsulation effective index and the compression package encapsulation effective first limit value, the compression package encapsulation effective deviation value is obtained; the above-mentioned obtaining of the compression package encapsulation effective deviation value refers to subtracting the compression package encapsulation effective first limit value from the compression package encapsulation effective index.

[0063] When the network resource compression package type is the emergency type, the redundancy check data proportion increasing coefficient is matched based on the compression package encapsulation effective deviation value, so as to increase the redundancy check data in the network resource compression package encapsulation process and include it in the transmission queue corresponding to the emergency type network resource compression package; it needs to be explained that the above-mentioned matching of the redundancy check data proportion increasing coefficient based on the compression package encapsulation effective deviation value has the following specific matching process: the redundancy check data proportion increasing coefficient corresponding to each compression package encapsulation effective deviation value interval in the protection database is preset, the obtained compression package encapsulation effective deviation value is input into the protection database, and the protection database can match the redundancy check data proportion increasing coefficient corresponding to the compression package encapsulation effective deviation value interval, the obtained redundancy check data proportion increasing coefficient is multiplied by the original redundancy check data proportion, and the obtained result is the redundancy check data proportion that needs to be adjusted; the redundancy check data proportion increasing coefficient is greater than 1, indicating the value of the redundancy check data proportion that needs to be increased by a multiple; increasing the redundancy check data proportion can form a dynamic protection network in the data transmission process, so that even if part of the data is damaged due to sudden interference, it can be quickly repaired through the redundancy information, avoiding the influence of data loss on emergency services. This adjustment not only meets the core needs of the priority transmission of emergency data, but also balances safety and efficiency by increasing the redundancy on demand, ensuring the integrity and availability of data at critical moments, thereby improving the compression package encapsulation effective index.

[0064] When the network resource compression package type is the regular type, the check data package encapsulation interval reduction coefficient is matched based on the compression package encapsulation effective deviation value; so as to reduce the check data package encapsulation interval in the network resource compression package encapsulation process, and determine whether to trigger the invalid encapsulation adjustment process; the above-mentioned matching of the check data package encapsulation interval reduction coefficient based on the compression package encapsulation effective deviation value is realized by the dynamic weight adjustment method; the check data package encapsulation interval reduction coefficient is less than 1, indicating the value of the check data package encapsulation interval that needs to be reduced by a multiple; the check data package encapsulation interval reduction coefficient is multiplied by the original check data package encapsulation interval, and the check data package encapsulation interval that needs to be adjusted is obtained.

[0065] In a specific example embodiment, the dynamic weight adjustment method is as follows: based on the compression package encapsulation effective deviation value (ΔE), an encapsulation fluctuation coefficient (F) is introduced, wherein the encapsulation fluctuation coefficient is based on the standard deviation of the encapsulation effective index in the last 5 times, and the check data package encapsulation interval reduction coefficient formula is established as follows: wherein K3 is a check data package encapsulation interval reduction coefficient, W1 is a weight corresponding to a compressed package encapsulation effective deviation value, W2 is a weight corresponding to an encapsulation fluctuation coefficient, a is a constant, indicating a basic adjustment parameter of the interval shrinkage amplitude corresponding to the compressed package encapsulation effective deviation value, for quantifying the interval shrinkage intensity corresponding to each unit of the compressed package encapsulation effective deviation value, b is a constant, indicating a reference value of the encapsulation fluctuation coefficient calculation, representing the interval shrinkage reference proportion when the encapsulation is stable (F=0), and c is a constant, indicating a supplementary adjustment parameter of the interval shrinkage amplitude corresponding to the fluctuation, for quantifying the additional shrinkage intensity corresponding to each unit of the fluctuation, a, b, and c are determined by relevant technical personnel in the art; the obtained compressed package encapsulation effective deviation value and the encapsulation fluctuation coefficient are substituted into the formula, and the corresponding check data package encapsulation interval reduction coefficient is obtained; when the encapsulation stability is poor (high), W2 dominates K3 calculation, and the interval is preferentially shrunk to improve the abnormal monitoring sensitivity; when the deviation is large (ΔE is high), W1 dominates, and the interval is forced to shrink to make up for the security short board, and the risk control and system stability are considered. The advantage of the dynamic weight adjustment method is that it can realize differentiated priority management of risk factors, and make the adjustment of the check data package encapsulation interval more suitable for the actual security needs of the conventional compressed package. It can make the core risk of deviation obtain a higher weight when it is serious, and preferentially strengthen the safety by shrinking the interval; and only when the fluctuation is large, the weight of the auxiliary risk of the encapsulation fluctuation is moderately increased, so as to avoid excessive interference with the efficiency. It can highlight the control of the core risk, and realize the flexibility of adjustment through double-factor weighting, so as to find a precise balance between safety gain and efficiency loss, and avoid the rigidity of adjustment caused by single-factor driving.

[0066] If the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class limit value, it is determined that the invalid encapsulation adjustment process is not triggered, and the corresponding transmission queue of the conventional network resource compressed package is included; if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class limit value, it is determined that the invalid encapsulation adjustment process is triggered; when the network resource compressed package is of a conventional type, the check data package encapsulation interval reduction coefficient is matched based on the deviation value, and the encapsulation interval is shortened, which can enhance the abnormal monitoring sensitivity of the encapsulation process. The conventional compressed package needs to balance between safety and resource consumption, and shortening the check interval can more frequently check the encapsulated data, discover small abnormalities (such as data block misplacement) in the encapsulation process in a timely manner, facilitate correction before the problem is enlarged, and thus promote the rise of the compressed package encapsulation effective index.

[0067] When the network resource compression package type is a low priority class, the parallel task reduction amount is matched based on the compression package encapsulation effective deviation value, so as to reduce the parallel task amount of the network resource compression package encapsulation process, and it is judged whether the invalid encapsulation adjustment process is triggered; the above-mentioned parallel task reduction amount matched based on the compression package encapsulation effective deviation value, the specific matching process is that the parallel task reduction amount corresponding to each compression package encapsulation effective deviation value interval in the protection database is preset, the obtained compression package encapsulation effective deviation value is input into the database, and the corresponding parallel task reduction amount can be matched by the database. The original parallel task amount is reduced by the obtained parallel task reduction amount, and the obtained result is the parallel task amount that needs to be adjusted.

[0068] It is judged whether the invalid encapsulation adjustment process is triggered, and the specific judgment process is that the compression package encapsulation effective index is reacquired, if the compression package encapsulation effective index is not lower than the compression package encapsulation effective first-class limit value, it is judged that the invalid encapsulation adjustment process is not triggered, and the transmission queue corresponding to the low priority class network resource compression package is included, if the compression package encapsulation effective index is lower than the compression package encapsulation effective first-class limit value, it is judged that the invalid encapsulation adjustment process is triggered. When the network resource compression package type is a low priority class, the parallel task reduction amount is matched based on the deviation value and the parallel task amount is reduced, and the encapsulation stability can be improved by reducing resource competition. The low priority class compression package has a lower processing time requirement, reducing the parallel task amount can avoid resource conflicts (such as calculation resource allocation disorder) caused by simultaneous operation of multiple tasks, reduce encapsulation errors caused by resource competition, and thus improve the compression package encapsulation effective index.

[0069] As Figure 4 , the security compression package encapsulation verification and risk judgment process provided by the embodiment of the application is shown in the schematic diagram, and the process starts from constructing a security compression package and acquiring a compression package encapsulation effective index; the compression package encapsulation effective limit value group is corrected based on the resistance test result; then, the compression package encapsulation effective index is compared with the encapsulation effective limit value group, which is divided into three cases: if the compression package encapsulation effective index is greater than or equal to the compression package encapsulation effective first-class limit value, it is classified as no risk, and the transmission queue is allocated according to the compression package type to complete the protection; if it is between the compression package encapsulation effective first-class limit value and the compression package encapsulation effective second-class limit value, it is classified as low risk, and the type is optimized (emergency class increases redundancy verification, regular class shortens verification interval, and low priority parallel task), and the compression package encapsulation effective index is reacquired; if it is less than the compression package encapsulation effective second-class limit value, it is classified as high risk, and the invalid encapsulation adjustment process is triggered, and the standby engine is called to re-encapsulate.

[0070] Specifically, the method comprises the following steps: determining whether to perform an abnormal early warning on the data protection of the network resource compression package, and the specific determination process comprises the following steps: comparing the compression package encapsulation effective reevaluation index with the compression package encapsulation effective first-class boundary value; when the compression package encapsulation effective reevaluation index is not lower than the compression package encapsulation effective first-class boundary value, determining not to perform an abnormal early warning on the data protection of the network resource compression package; and when the compression package encapsulation effective reevaluation index is lower than the compression package encapsulation effective first-class boundary value, determining to perform an abnormal early warning on the data protection of the network resource compression package.

[0071] The abnormal early warning on the data protection of the network resource compression package refers to early warning and reminding through a security operation and maintenance terminal message.

[0072] Specifically, the method comprises the following steps: monitoring and obtaining data security protection encapsulation process parameters, and the specific analysis process comprises the following steps: the data security protection encapsulation process parameters comprise a data block encapsulation synchronization rate proportionality coefficient, a double-layer structure coupling degree proportionality coefficient and an encapsulation file volume expansion rate proportionality coefficient of the data security protection encapsulation process, and a compression package attack resistance terminal value is obtained; the effect coefficient of each proportionality coefficient and the compression package attack resistance terminal value in the protection database is preset, the weight contribution value of the proportionality coefficient to the compression package encapsulation effective index is quantified, and finally, a weighted average fusion algorithm is used to synthesize the compression package encapsulation effective index.

[0073] The data block encapsulation synchronization rate proportionality coefficient represents the ratio of the data block encapsulation synchronization rate of the data security protection encapsulation process to the defined data block encapsulation synchronization rate; the double-layer structure coupling degree proportionality coefficient represents the ratio of the double-layer structure coupling degree of the data security protection encapsulation process to the defined double-layer structure coupling degree; the encapsulation file volume expansion rate proportionality coefficient represents the ratio of the encapsulation file volume expansion rate of the data security protection encapsulation process to the defined encapsulation file volume expansion rate; and the compression package attack resistance terminal value represents the compression package attack resistance index of the network resource compression package finally passing the data security protection preliminary inspection.

[0074] The compression package encapsulation effective index represents the comprehensive efficiency of the secure compression package in guaranteeing data security after data security protection encapsulation, and the specific evaluation method is as follows:

[0075] ;

[0076] ;

[0077] ;

[0078] ;

[0079] In the formula, CPEEI is a compressed package effective index, CAI_z is a compressed package attack resistance final value, DBESRF is a data block encapsulation synchronization rate proportion coefficient of a data security protection encapsulation process, DBESR is a data block encapsulation synchronization rate of the data security protection encapsulation process, DDBESR is a preset defined data block encapsulation synchronization rate in a protection database, DSCDF is a double-layer structure coupling degree proportion coefficient of the data security protection encapsulation process, DSCD is a double-layer structure coupling degree of the data security protection encapsulation process, DDSCD is a preset defined double-layer structure coupling degree in the protection database, EFVERF is an encapsulation file volume expansion rate proportion coefficient of the data security protection encapsulation process, EFVER is an encapsulation file volume expansion rate of the data security protection encapsulation process, DEFVER is a preset defined encapsulation file volume expansion rate in the protection database, gd is an effect coefficient corresponding to the data block encapsulation synchronization rate proportion coefficient preset in the protection database, gf is an effect coefficient corresponding to the double-layer structure coupling degree proportion coefficient preset in the protection database, ge is an effect coefficient corresponding to the encapsulation file volume expansion rate proportion coefficient preset in the protection database, and gc is an effect coefficient corresponding to the compressed package attack resistance final value preset in the protection database.

[0080] The data block encapsulation synchronization rate refers to the time consistency and logical correlation compliance degree of a plurality of data blocks in a compressed package in an encapsulation process (such as embedding of check information), and is obtained by counting the proportion of data blocks that are synchronized and pass logical check in a preset time window; the double-layer structure coupling degree refers to the cooperative protection strength of two layers of structure for a compressed package using double-layer encapsulation, and is obtained by calculating the inverse ratio of the attack number proportion of separately breaking through a single layer and simultaneously breaking through two layers; and the encapsulation file volume expansion rate refers to the difference proportion of the volume of the compressed package after encapsulation (such as adding redundant check) and the volume of the original compressed package, and is obtained by calculating the percentage of the difference between the encapsulated volume and the original volume in the original volume.

[0081] The defined data block encapsulation synchronization rate refers to the minimum value of the data block encapsulation synchronization rate in a specified range; the defined double-layer structure coupling degree refers to the minimum value of the double-layer structure coupling degree in a specified range; and the defined encapsulation file volume expansion rate refers to the maximum value of the encapsulation file volume expansion rate in a specified range.

[0082] The increase of the ratio of the data block encapsulation synchronization rate to its corresponding defined value indicates that the synchronization of the data block encapsulation is better than the defined standard, and the timing and logical connection of each data block are more accurate, thereby increasing the ratio of the coupling degree of the double-layer structure to its corresponding defined value, reducing the ratio of the encapsulation file volume expansion rate to its corresponding defined value, and increasing the final attack resistance value of the compressed package; under the condition that other conditions remain unchanged, the increase of the proportion coefficient of the data block encapsulation synchronization rate means that the synchronization of the data block encapsulation is better, and the logical connection of each data block is more closely, which can reduce the risk of encapsulation failure caused by asynchronization, thereby positively affecting the effective index of the compressed package encapsulation and increasing it; under the condition that other conditions remain unchanged, the increase of the proportion coefficient of the coupling degree of the double-layer structure means that the synergy of the double-layer protection structure is stronger, and the linkage of the two-layer protection mechanism is more efficient, which can improve the overall attack resistance ability, and thus promote the increase of the effective index of the compressed package encapsulation; under the condition that other conditions remain unchanged, the increase of the proportion coefficient of the encapsulation file volume expansion rate will increase the processing burden and reduce the encapsulation efficiency, which will in turn reduce the effective index of the compressed package encapsulation, and the overall trend is first increasing and then decreasing; under the condition that other conditions remain unchanged, the increase of the final attack resistance value of the compressed package directly reflects the improvement of the final attack resistance ability of the compressed package, and as a core influencing factor, it will significantly promote the increase of the effective index of the compressed package encapsulation.

[0083] The effect coefficient corresponding to the proportion coefficient of the data block encapsulation synchronization rate indicates that when the proportion coefficient of the data block encapsulation synchronization rate changes by a unit amplitude, the effective index of the compressed package encapsulation will change by a corresponding amplitude; the effect coefficient corresponding to the proportion coefficient of the coupling degree of the double-layer structure indicates that when the proportion coefficient of the coupling degree of the double-layer structure changes by a unit amplitude, the effective index of the compressed package encapsulation will change by a corresponding amplitude; the effect coefficient corresponding to the proportion coefficient of the encapsulation file volume expansion rate indicates that when the proportion coefficient of the encapsulation file volume expansion rate changes by a unit amplitude, the effective index of the compressed package encapsulation will change by a corresponding amplitude; the effect coefficient corresponding to the final attack resistance value of the compressed package indicates that when the final attack resistance value of the compressed package changes by a unit amplitude, the effective index of the compressed package encapsulation will change by a corresponding amplitude.

[0084] The protection database stores the mapping relationship between the proportion coefficient of the data block encapsulation synchronization rate and the effect coefficient corresponding thereto, the mapping relationship between the proportion coefficient of the coupling degree of the double-layer structure and the effect coefficient corresponding thereto, the mapping relationship between the proportion coefficient of the encapsulation file volume expansion rate and the effect coefficient corresponding thereto, and the mapping relationship between the final attack resistance value of the compressed package and the effect coefficient corresponding thereto.

[0085] For example, the data block encapsulation synchronization rate proportion coefficient, the double-layer structure coupling degree proportion coefficient, the encapsulation file volume expansion rate proportion coefficient and the compressed package attack resistance terminal value are input into the protection database, the protection database generates the corresponding effect coefficient corresponding to the data block encapsulation synchronization rate proportion coefficient, the effect coefficient corresponding to the double-layer structure coupling degree proportion coefficient, the effect coefficient corresponding to the encapsulation file volume expansion rate proportion coefficient and the effect coefficient corresponding to the compressed package attack resistance terminal value based on the preset mapping rule, and the numerical range of each type of effect coefficient is strictly controlled between 0 and 1.

[0086] In one specific example embodiment, the present application provides a data security protection method for network resource compression packages, which has the following core advantages: combining virtual attack testing and quantitative index evaluation, pre-filtering high-risk data; significantly strengthening the core security capability of data through environment-aware dynamic encryption and tamper-resistant packaging; and dynamically adjusting the protection strategy based on real-time risk level. This scheme ensures the security of data transmission and storage while taking into account the processing efficiency of different priority data, effectively balancing protection strength and system resource consumption, and providing flexible and reliable full-life-cycle security protection for compression package data in complex network environments.

[0087] As Figure 5 The compression package encapsulation re-evaluation and protection finishing process provided by the embodiment of the present application is shown in the schematic diagram, after the compression package encapsulation effective index is reacquired, the compression package encapsulation effective index is first compared with the compression package encapsulation effective first-class limit value, if the compression package encapsulation effective index is not lower than the compression package encapsulation effective first-class limit value, then the protection is completed according to the type distribution queue; if the compression package encapsulation effective index is lower than the compression package encapsulation effective first-class limit value, then invalid encapsulation adjustment is triggered, the standby engine is called to re-encapsulate and obtain the compression package encapsulation re-evaluation index; the compression package encapsulation effective re-evaluation index is compared with the compression package encapsulation effective first-class limit value again, if the compression package encapsulation effective re-evaluation index is not lower than the compression package encapsulation effective first-class limit value, then the protection is completed, otherwise, data protection abnormality warning is triggered, and the process is ended.

[0088] The present application provides a computer-readable storage medium, the storage medium stores at least one instruction, the at least one instruction is loaded and executed by the processor to realize any one of the above-mentioned data security protection methods for network resource compression packages.

[0089] It should be understood that the term "and / or" herein merely describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone, wherein A and B can be singular or plural. In addition, the character " / " herein generally represents that the front and rear associated objects are in an "or" relationship, but can also represent an "and / or" relationship, which can be understood in combination with the context.

[0090] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data security protection method for a network resource compression package, characterized in that, The method comprises: Step one, preprocessing operation is performed on the network resource compression package, virtual attack resistance test is performed on the network resource compression package after the preprocessing operation is completed, thereby obtaining the resistance test result, acquiring the preprocessing process parameters of the network resource compression package, and judging whether the network resource compression package passes the data security protection preliminary inspection in combination with the resistance test result, the resistance test result reflects the anti-attack ability of the compression package after preprocessing in the actual attack scene; Step two, for the network resource compression package that passes the data security protection preliminary inspection, environment-aware dynamic encryption is implemented, and tamper-proofing check data is packaged, and a secure compression package with data security protection is constructed; Step three, the data security protection packaging process parameters of the secure compression package are monitored and acquired, and the data security protection packaging result is risk classified in combination with the resistance test result, if the risk classification of the data security protection packaging result is no risk, the data security protection of the network resource compression package is completed, if the risk classification of the data security protection packaging result is low risk or high risk, the data protection of the network resource compression package is adjusted.

2. The data security protection method for the network resource compression package according to claim 1, characterized in that, The preprocessing process parameters of the network resource compression package are acquired, and the specific analysis process is as follows: The preprocessing process parameters include the redundancy check data coverage ratio coefficient, the abnormal format filtering rate ratio coefficient and the sensitive field replacement rate ratio coefficient of the network resource compression package preprocessing process, the effect coefficient of each ratio coefficient is preset in the protection database, the weight contribution value of each ratio coefficient to the compression package attack resistance index is quantified, and finally the compression package attack resistance index is obtained by using the weighted average fusion algorithm, wherein the compression package attack resistance index refers to the anti-attack basic ability of the network resource compression package after preprocessing operation in the static layer.

3. The data security protection method for the network resource compression package according to claim 2, characterized in that, The specific judgment process for judging whether the network resource compression package passes the data security protection preliminary inspection in combination with the resistance test result is as follows: The resistance test result refers to the compression package virtual attack resistance score obtained after the network resource compression package completes the virtual attack resistance test, the compression package attack resistance limit value is modified by matching the deviation value of the compression package virtual attack resistance score and the compression package virtual attack resistance score limit value, thereby modifying the compression package attack resistance limit value; The obtained compression package attack resistance index is compared with the compression package attack resistance limit value, the compression package attack resistance limit value represents the minimum value of the compression package attack resistance index in the specified range; When the compression package attack resistance index is not lower than the compression package attack resistance limit value, it is judged that the network resource compression package passes the data security protection preliminary inspection, and environment-aware dynamic encryption is implemented on the network resource compression package; When the compression package attack resistance index is lower than the compression package attack resistance limit value, it is judged that the network resource compression package does not pass the data security protection preliminary inspection, and the secondary preprocessing mechanism is triggered.

4. The data security protection method for the network resource compression package according to claim 3, characterized in that, The specific analysis process of triggering the secondary preprocessing mechanism is as follows: Based on the compression package anti-attack index and the compression package anti-attack limit value, the anti-attack comprehensive deviation value is obtained, the anti-attack comprehensive deviation value is matched to obtain the redundant check data amount increasing coefficient, so as to increase the redundant check data amount of the network resource compression package that does not pass the data security protection preliminary inspection, and the anti-attack comprehensive deviation value is matched to obtain the hash calculation iteration number increasing coefficient, so as to increase the hash calculation iteration number of the network resource compression package that does not pass the data security protection preliminary inspection; The compression package anti-attack index after secondary preprocessing is obtained, which is marked as the compression package anti-attack re-evaluation index, and it is judged whether the preprocessing process of the network resource compression package is prewarned.

5. The data security protection method for the network resource compression package according to claim 4, characterized in that, The specific judgment process of whether to prewarn the preprocessing process of the network resource compression package is as follows: The compression package anti-attack re-evaluation index is compared with the compression package anti-attack limit value; When the compression package anti-attack re-evaluation index is not lower than the compression package anti-attack limit value, it is judged that the preprocessing process of the network resource compression package is not prewarned; When the compression package anti-attack re-evaluation index is lower than the compression package anti-attack limit value, it is judged that the preprocessing process of the network resource compression package is prewarned, and a preprocessing abnormity analysis report is pushed.

6. The data security protection method for the network resource compression package according to claim 1, characterized in that, The specific analysis process of the risk classification processing of the data security protection packaging result combined with the resistance test result is as follows: Based on the deviation value of the compression package virtual attack resistance score and the compression package virtual attack resistance score limit value, the correction coefficient of the compression package packaging effective limit value group is matched, so as to modify the compression package packaging effective limit value group, the compression package packaging effective limit value group includes compression package packaging effective first-class limit value and compression package packaging effective second-class limit value, the compression package packaging effective first-class limit value is a numerical value for classifying the data security protection packaging result into no risk and low risk, and the compression package packaging effective second-class limit value is a numerical value for classifying the data security protection packaging result into low risk and high risk; By analyzing the data security protection packaging process parameters of the security compression package, the compression package packaging effective index is obtained, and the compression package packaging effective index is compared with the compression package packaging effective limit value group; When the compression package packaging effective index is not lower than the compression package packaging effective first-class limit value, the risk of the data security protection packaging result is classified as no risk, and the corresponding transmission queue is allocated based on different types of network resource compression packages; When the compression package packaging effective index is between the compression package packaging effective first-class limit value and the compression package packaging effective second-class limit value, the risk of the data security protection packaging result is classified as low risk, and different optimization adjustments are made based on different types of network resource compression packages; When the compression package packaging effective index is lower than the compression package packaging effective second-class limit value, the risk of the data security protection packaging result is classified as high risk, and the invalid packaging adjustment process is triggered, that is, the standby packaging engine is called to repackage, the compression package packaging effective index is reobtained and marked as the compression package packaging effective re-evaluation index, and it is judged whether to prewarn the data protection of the network resource compression package.

7. The data security protection method for the network resource compression package according to claim 6, characterized in that, The specific adjustment process of the different optimization adjustments based on different types of network resource compression packages is as follows: Based on the compressed package encapsulation effective index and the compressed package encapsulation effective first-class boundary value, a compressed package encapsulation effective deviation value is obtained; When the network resource compression package type is the emergency class, a redundant check data proportion increasing coefficient is matched based on the compressed package encapsulation effective deviation value, so as to increase the redundant check data in the network resource compression package encapsulation process, and the redundant check data is included in the transmission queue corresponding to the emergency class network resource compression package; When the network resource compression package type is the regular class, a check data package encapsulation interval reducing coefficient is matched based on the compressed package encapsulation effective deviation value, so as to reduce the check data package encapsulation interval in the network resource compression package encapsulation process, and it is judged whether to trigger the invalid encapsulation adjustment process; The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered; When the network resource compression package type is the low priority class, a parallel task reducing amount is matched based on the compressed package encapsulation effective deviation value, so as to reduce the parallel task amount in the network resource compression package encapsulation process, and it is judged whether to trigger the invalid encapsulation adjustment process; The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered.

8. The data security protection method for the network resource compression package according to claim 6, characterized in that, The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered. The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered. The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered. The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered.

9. The data security protection method for network resource compression package according to claim 1, characterized in that, The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered. The specific judgment process of whether to trigger the invalid encapsulation adjustment process is that: the compressed package encapsulation effective index is reacquired, if the compressed package encapsulation effective index is not lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is not triggered, and the compressed package is included in the transmission queue corresponding to the regular class network resource compression package, if the compressed package encapsulation effective index is lower than the compressed package encapsulation effective first-class boundary value, it is judged that the invalid encapsulation adjustment process is triggered.

10. A computer readable storage medium, characterized in that, The computer readable storage medium stores program codes, and the program codes can be invoked by the processor to execute the data security protection method for the network resource compression package according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Big Data-Based Network Security Protection Methods and Platforms

    CN112333157B

  • A network security protection method based on big data

    CN118869295B

  • Network attack protection method and device, storage medium and electronic equipment

    CN111314328A

  • Security assessment method and device for malicious code detection system

    CN120124055A