Network security risk assessment method and system for remote sensing satellite ground transmission network
By integrating multi-source heterogeneous data and utilizing Bayesian networks and deep learning models, the risks of remote sensing satellite ground transmission networks are dynamically assessed, enabling real-time identification and collaborative attribution of cross-domain attacks, thus improving the real-time performance and accuracy of remote sensing satellite ground transmission networks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NAT SATELLITE METEOROLOGICAL CENT
- Filing Date
- 2025-10-10
- Publication Date
- 2026-04-21
AI Technical Summary
When facing cross-domain attacks, remote sensing satellite ground transmission networks suffer from insufficient cross-domain data fusion capabilities, lack of attack chain reasoning, and lagging risk governance. In particular, under dynamic network topology changes and high-latency communication environments, it is difficult to achieve real-time risk assessment and collaborative protection.
By integrating heterogeneous data from multiple sources to generate structured datasets, and combining Bayesian networks and deep learning models to dynamically assess risks, a security situation map is constructed to achieve cross-domain attack identification and collaborative tracing.
It improves the real-time performance, accuracy, and collaborative decision-making capabilities of remote sensing satellite ground transmission networks, and solves the problems of insufficient cross-domain data fusion capabilities, lack of attack chain reasoning, and lagging risk governance in traditional methods.
Smart Images

Figure CN121126358B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of remote sensing satellite network security technology, and in particular to a method and system for assessing network security risks of remote sensing satellite ground transmission networks. Background Technology
[0002] As a core infrastructure supporting global weather forecasting and disaster early warning, the remote sensing satellite ground transmission network bears the heavy responsibility of processing massive amounts of observational data in real time. The system's operating environment has significant unique characteristics: on the one hand, it needs to cope with highly dynamic changes in the satellite-to-ground link (including satellite orbit adjustments and ground station switching scenarios); on the other hand, it needs to overcome the challenge of ensuring data integrity under high-latency communication environments. The current technical system faces three core bottlenecks:
[0003] At the data fusion level, there is a serious problem of format heterogeneity between satellite telemetry data (such as dynamic parameters like signal strength and bit error rate) and ground station logs (containing discrete information such as operational behavior and protocol compliance). This data fragmentation leads to blind spots in analysis, typically manifested in the inability to establish an effective correlation between illegal command injection events at ground stations and space signal interference phenomena, making it difficult to fully identify cross-domain attack paths.
[0004] Regarding risk assessment mechanisms, existing solutions generally suffer from static limitations and delayed responses. Analysis models relying on fixed rule bases or single data sources struggle to adapt to dynamic changes in network topology (especially link reconfiguration caused by satellite orbit adjustments). This lack of adaptability leads to delays in threat identification, and a disconnect between response strategies and real-time risk levels, resulting in a significant decrease in protective effectiveness against low-frequency coordinated attacks.
[0005] Regarding attack attribution capabilities, existing technologies are weak in their ability to collaboratively track attacks in the space segment (such as signal jamming) and the ground segment (such as protocol cracking). Traditional log analysis tools lack cross-domain correlation capabilities, making it difficult to accurately locate the source of attacks. In addition, machine learning model update mechanisms are rigid and lack the ability to optimize dynamic probabilistic reasoning based on real-time data streams.
[0006] The core contradiction of existing technical solutions lies in the systemic disconnect between the need for dynamic environmental adaptability (requiring real-time fusion of multi-source heterogeneous data) and the need for responsive agility (requiring dynamic risk quantification and triggering tiered responses). Typical cases demonstrate that, when facing continuous coordinated attacks, due to the lack of a heterogeneous data fusion engine and dynamic probability model support, the system cannot effectively correlate cross-domain attack events, nor can it dynamically adjust protection strategies through real-time risk quantification.
[0007] Although Bayesian theory has theoretical advantages in the field of uncertainty reasoning (such as probabilistic modeling), its current applications are mostly limited to single scenarios such as spam filtering, and a complete technical system for multi-source data fusion and real-time risk decision-making across space and ground domains has not yet been formed.
[0008] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention
[0009] This invention provides a method for assessing network security risks in remote sensing satellite ground transmission networks, which improves the accuracy of cross-domain attack identification, achieves dynamic risk quantification assessment, and enhances the ability to trace collaborative attacks.
[0010] To achieve the above objectives, in a first aspect, the present invention provides a method for network security risk assessment of a remote sensing satellite ground transmission network, comprising: acquiring real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground coordination logs from the remote sensing satellite ground transmission network to generate a cleaned first dataset. Denoising the telemetry data in the first dataset to generate a denoised second dataset. Aligning the timestamps of the second dataset with those of the ground station operation logs in the first dataset to generate a time-synchronized third dataset. Merging the third dataset with the network traffic data and system log data in the first dataset to generate a structured fourth dataset. Extracting multi-dimensional feature vectors from the fourth dataset and using dimensionality reduction processing to generate a compressed feature vector set. Constructing a dynamic Bayesian network based on the feature vector set, calculating the risk probability distribution of each node, determining the risk assessment level of the network status, and generating the network communication status. Wherein, if the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded. Wherein, if the risk probability distribution exceeds a higher preset threshold, anomaly traffic is isolated and redundant communication links are enabled through a dynamic routing allocation algorithm, and the network communication status is updated. Based on the network communication status, Bayesian posterior probability inference is used to calculate the probability distribution of attack paths. Combined with the correlation analysis of satellite-ground collaborative logs in the first dataset, an attack chain report containing key nodes and risk propagation paths is generated. The parameters of the dynamic Bayesian network are periodically optimized and updated based on newly collected data.
[0011] Secondly, this invention provides a network security risk assessment system for a remote sensing satellite ground transmission network, comprising: a first generation module, a second generation module, a third generation module, a fourth generation module, a generation set module, a network communication status generation module, a report generation module, and an optimization and update module. The first generation module acquires real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground coordination logs from the remote sensing satellite ground transmission network to generate a cleaned first dataset. The second generation module performs denoising processing on the telemetry data in the first dataset to generate a denoised second dataset. The third generation module aligns the timestamps of the second dataset with those of the ground station operation logs in the first dataset to generate a time-synchronized third dataset. The fourth generation module merges the third dataset with the network traffic data and system log data in the first dataset to generate a structured fourth dataset. The generation set module extracts multi-dimensional feature vectors from the fourth dataset and uses dimensionality reduction processing to generate a compressed feature vector set. The network communication status generation module constructs a dynamic Bayesian network based on the feature vector set, calculates the risk probability distribution of each node, determines the risk assessment level of the network status, and generates the network communication status. If the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded. If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated using a dynamic routing allocation algorithm, redundant communication links are enabled, and the network communication status is updated. The report generation module calculates the attack path probability distribution based on the network communication status using Bayesian posterior probability inference, and combines this with correlation analysis of satellite-ground collaborative logs in the first dataset to generate an attack chain report containing key nodes and risk propagation paths. The optimization and update module periodically optimizes and updates the parameters of the dynamic Bayesian network based on newly collected data.
[0012] Compared with existing technologies, the network security risk assessment method and system for remote sensing satellite ground transmission networks according to the present invention integrates multi-source heterogeneous data to generate structured datasets, combines Bayesian networks and deep learning models to dynamically assess risks and construct security situation maps, and finally outputs collaborative governance suggestions. This solves the problems of insufficient cross-domain data fusion capabilities, lack of attack chain reasoning, and lagging risk governance in traditional methods, and has the advantages of improving real-time performance, accuracy, and collaborative decision-making capabilities. Attached Figure Description
[0013] Figure 1 This is a flowchart illustrating a method for assessing network security risks in a remote sensing satellite ground transmission network according to Embodiment 1 of the present invention.
[0014] Figure 2This is a schematic diagram of the network security risk assessment system for a remote sensing satellite ground transmission network according to Embodiment 2 of the present invention. Detailed Implementation
[0015] The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the present invention and not intended to limit the scope of the invention. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the embodiments of the present invention, and not all structures.
[0016] To facilitate understanding, the main implementation concepts of the various embodiments of the present invention will be briefly described first.
[0017] In traditional remote sensing satellite ground transmission network security assessment systems, insufficient multi-source heterogeneous data fusion capabilities make it difficult to trace cross-domain attack paths. The contradiction between dynamic network topology changes and static risk assessment models exacerbates response delays, and the lack of real-time probabilistic inference mechanisms prevents accurate quantification of risk levels. Specifically, satellite telemetry data and ground operation logs cannot establish joint analysis models due to format heterogeneity. For example, illegal command injection events at ground stations and abnormal signal strength in the space segment cannot be correlated through timestamp alignment, allowing attackers to exploit data fragmentation to hide attack chains in cross-domain collaborative attacks. Simultaneously, when ground station switching caused by satellite orbit adjustments leads to dynamic changes in network topology, detection mechanisms based on fixed rule bases cannot update node dependencies in real time, causing threat identification delays exceeding the system's tolerance threshold in low-frequency collaborative attack scenarios.
[0018] For example, during satellite transit when ground stations perform orbit switching operations, the time series of network traffic data and the period of telemetry signals experience timestamp offsets due to differences in sampling frequencies. This causes abnormal packet loss rates and fluctuations in satellite terminal status to be analyzed asynchronously. At this time, attackers can inject malicious commands disguised as legitimate protocols, triggering ground station response delays and interfering with the stability of the satellite-to-ground link. However, because the risk assessment model does not integrate system log status fields and traffic peak characteristics, it cannot identify cross-protocol layer attacks through dynamic probability distribution, resulting in abnormal traffic continuously penetrating to core nodes.
[0019] If the aforementioned issues are not addressed, coordinated attacks across space and ground segments will remain hidden in data silos for a long time. Attackers can gradually infiltrate critical nodes through low-frequency, dispersed malicious operations, ultimately causing the interruption of space-to-ground communication links or the leakage of sensitive meteorological data. Because the system cannot quantify risk levels in real time, it is difficult to trigger a tiered response mechanism. This results in abnormal traffic not being isolated before reaching the damage threshold, and redundant communication links failing to be activated in a timely manner, causing delays in the transmission of observational information or irreversible damage to core services.
[0020] To address the aforementioned challenges, this invention first considers breaking down the format barriers between satellite telemetry data and ground operation logs by establishing a unified time benchmark to achieve cross-domain data correlation analysis. To resolve the issue of risk assessment model lag caused by dynamic network topology changes, it explores a dynamic network construction method based on probabilistic reasoning, enabling node dependencies to be updated in real-time with ground station switching. Simultaneously, a hierarchical response mechanism is designed, matching risk probability distributions with different thresholds to trigger differentiated protection strategies and improve response agility. By comparing the real-time performance differences between traditional static rule bases and dynamic Bayesian networks, it is found that the latter can capture node state transition patterns through conditional probability distributions, making it more suitable for handling uncertain risks in high-latency communication environments. Furthermore, by combining multi-source data fusion technology, network traffic, system logs, and denoised telemetry data are mapped to a unified feature space, forming a basis for quantifiable analysis.
[0021] Example 1, Figure 1 This is a flowchart illustrating a network security risk assessment method for a remote sensing satellite ground transmission network according to Embodiment 1 of the present invention. Figure 1 As shown, Embodiment 1 provides a method for assessing network security risks in a remote sensing satellite ground transmission network, including:
[0022] Step S100: Obtain real-time operation data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs from the remote sensing satellite ground transmission network to generate the first cleaned dataset;
[0023] Step S200: Denoise the telemetry data in the first dataset to generate a denoised second dataset;
[0024] Step S300: Align the timestamps of the ground station operation logs in the second dataset with those in the first dataset to generate a time-synchronized third dataset;
[0025] Step S400: Merge the third dataset with the network traffic data and system log data in the first dataset to generate a fourth dataset in a structured format;
[0026] Step S500: Extract multidimensional feature vectors from the fourth dataset and generate a compressed feature vector set by dimensionality reduction processing;
[0027] Step S600: Construct a dynamic Bayesian network based on the feature vector set, calculate the risk probability distribution of each node, determine the risk assessment level of the network state, and generate the network communication state.
[0028] If the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded.
[0029] If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated and redundant communication links are enabled through a dynamic routing allocation algorithm, and the network communication status is updated.
[0030] Step S700: Based on the network communication status, Bayesian posterior probability inference is used to calculate the probability distribution of attack paths. Combined with the satellite-ground collaborative log correlation analysis in the first dataset, an attack chain report containing key nodes and risk propagation paths is generated.
[0031] Step S800: Periodically optimize and update the parameters of the dynamic Bayesian network based on the newly acquired data.
[0032] Specifically, this invention constructs a closed-loop system through the above steps: It collects multi-source heterogeneous data (real-time operation, historical events, ground station logs, network traffic, system logs, and satellite-ground collaborative logs), cleans invalid records to generate a first dataset, providing a clean foundation for subsequent processing. Wavelet denoising is applied to telemetry data (such as signal strength) to filter out space environment or equipment noise, generating a second dataset and solving the difficulties of traditional data correlation. The timestamps of telemetry data and ground station logs are aligned, and time deviations are adjusted through interpolation to generate a time-synchronized third dataset, ensuring consistent time references for cross-domain data. The third dataset is fused with network traffic and system logs to generate a structured fourth dataset, breaking down the data format barriers between satellite and ground. Multi-dimensional features (such as signal period and packet loss rate) are extracted and dimensionality reduced to generate compressed feature vectors, reducing computational complexity. A dynamic Bayesian network is constructed based on the feature vectors to calculate node risk probabilities and classify them into levels (low / medium / high), triggering graded responses (alarms, traffic isolation, enabling redundant links) and generating network communication status. By inferring attack paths using Bayesian posterior probabilistic reasoning and combining satellite-ground collaborative logs to locate key nodes and propagation paths, an attack chain report is generated. Finally, by periodically collecting new data and updating the dynamic Bayesian network parameters, the model achieves adaptive optimization and continuous evolution. The entire process, through dynamic probabilistic reasoning, multi-source data fusion, and hierarchical response, solves the problems of cross-domain data fragmentation, delayed risk assessment, and weak attack attribution capabilities found in traditional methods, thus improving real-time performance and accuracy.
[0033] In this embodiment, step S100 includes: querying and extracting real-time operation data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs containing timestamps from the database associated with the remote sensing satellite ground transmission network; using regular expressions to match the feature fields of invalid records, deleting records with null values or incorrect formats, and generating a cleaned first dataset.
[0034] Specifically, multi-source heterogeneous data is queried and extracted from the remote sensing satellite ground transmission network association database. This includes real-time operational data (such as satellite signal parameters), historical security event data (past attack records), ground station operation logs (command and permission changes), network traffic data (data packet distribution), system log data (equipment alarms), and satellite-ground collaboration logs (interaction event sequences). All data retains timestamps to support subsequent time correlation analysis. Regular expression matching technology is used to filter invalid records based on their characteristic fields (such as null values and format errors), removing noisy data to ensure data integrity and standardization. Finally, a cleaned, structured, high-quality first dataset is generated, providing a reliable foundation for subsequent telemetry denoising, time alignment, and multi-source fusion, solving the analytical blind spots caused by data fragmentation in traditional methods.
[0035] In this embodiment, step S200 includes: setting the decomposition level and basis function of discrete wavelet transform; decomposing the signal using wavelet transform for the telemetry data in the first dataset to obtain high-frequency components and low-frequency components; calculating the energy value of the high-frequency components, and determining it as a noise signal if it exceeds a preset noise threshold; extracting the low-frequency components and filtering out the noise signal to generate a denoised second dataset.
[0036] Specifically, the telemetry data (such as satellite signal strength and bit error rate) in the first dataset is denoised using discrete wavelet transform: First, the decomposition level (e.g., 3 levels) and basis function (e.g., db4 wavelet) are set to determine the precision of signal decomposition; then, the telemetry signal is decomposed into high-frequency components (representing noise or abrupt changes) and low-frequency components (representing the trend of effective signals); the energy value of the high-frequency components is calculated, and if it exceeds a preset noise threshold (e.g., the upper limit of interference energy based on historical data statistics), it is determined to be a noise signal and filtered out; finally, the low-frequency components are extracted to reconstruct the signal, generating the denoised second dataset. This process can effectively suppress the impact of space environment interference (such as ionospheric disturbances and solar storms) or equipment noise on the data, solving the problem in traditional methods where satellite telemetry data and ground operation logs cannot be correlated due to noise (e.g., illegal ground station commands and space signal anomalies cannot be synchronously identified), providing clean and reliable basic data for subsequent timestamp alignment, multi-source data fusion, and dynamic risk modeling, and improving the accuracy of cross-domain attack identification and real-time risk assessment.
[0037] In this embodiment, step S300 includes:
[0038] Step S301: Check whether there is a discrepancy between the timestamp of the second dataset and the timestamp of the ground station operation log in the first dataset, wherein the timestamp of the ground station operation log is marked with reference to the satellite data transmission time;
[0039] If there is a discrepancy, the timestamps are aligned using linear interpolation.
[0040] If there is no deviation, the original timestamp is directly retained;
[0041] Step S302: Merge the second dataset with timestamp alignment, the ground station operation log, and the network traffic data and system log data in the first dataset to generate a time-synchronized third dataset.
[0042] Specifically, the process first checks for discrepancies between the timestamps of the denoised telemetry data (second dataset) and the ground station operation logs (from the first dataset). This means that even though the timestamps in the ground station operation logs are referenced to the satellite data transmission time, slight time misalignments can occur due to satellite orbit adjustments, ground station switching, or differences in sampling frequencies. If discrepancies exist, linear interpolation is used to complete or adjust the time series, ensuring a strict temporal correspondence between satellite signal status (e.g., signal strength fluctuations) and ground station operational behaviors (e.g., command transmission, permission changes). If no discrepancies exist, the original timestamps are retained. Subsequently, the aligned telemetry data, ground station operation logs, and network traffic data (e.g., packet distribution, session anomaly) and system log data (e.g., device alarms, link interruption records) from the first dataset are merged to generate a time-synchronized structured third dataset. This process solves the problem in traditional methods where timestamp misalignment prevents the correlation analysis of "illegal ground station command injection" and "space signal interference," providing a unified time reference for subsequent feature extraction, dynamic Bayesian network modeling, and attack path tracing, ensuring the real-time performance and accuracy of cross-domain attack identification.
[0043] In this embodiment, step S400 includes: based on the third dataset, using relational database association operations, mapping the time series of network traffic data and the status fields of system log data in the first dataset with the telemetry data and ground station operation logs in the third dataset to generate a fourth dataset in a structured format.
[0044] Specifically, step S400 achieves deep fusion of multi-source data through relational database join operations: Based on a time-synchronized third dataset (containing denoised telemetry data and ground station operation logs with aligned timestamps), the network traffic data (such as packet time series and session anomaly rate) and system log data (such as device online status and alarm type) in the first dataset are mapped to the telemetry data (signal strength and bit error rate) and ground station operation logs (command type and permission change records) in the third dataset. Specifically, using the database join operation, associated fields are matched by timestamp or event ID (e.g., associating satellite signal status at the same time point with ground station command transmission records, or associating network traffic peaks with system device alarm status), integrating multi-dimensional information such as satellite dynamic parameters, ground operation behavior, network traffic characteristics, and system operating status to generate a structured fourth dataset. The above steps break down the format barriers between satellite telemetry data and ground logs, unifying heterogeneous data into structured tables with consistent time dimensions and closely related attributes. This provides a complete and standardized data foundation for subsequent feature extraction (such as signal periodic fluctuations and command conflict frequency), dynamic Bayesian network modeling, and attack path tracing, solving the problem of difficulty in identifying cross-domain attacks caused by data fragmentation in traditional methods.
[0045] In this embodiment, step S500 includes: extracting signal period, data packet loss rate, instruction frequency, change frequency, alarm count, interruption time, and traffic peak from the fourth dataset to generate a basic multidimensional feature vector; decomposing the signal period feature using a time series analysis method to calculate periodic fluctuation feature values, and merging the periodic fluctuation feature values into the basic multidimensional feature vector to generate a first enhanced feature vector; checking whether the data packet loss rate exceeds a preset loss rate threshold: if it exceeds, calculating the correlation coefficient between the alarm count and the interruption time using a sliding window method, and merging the correlation coefficient as a new feature into the first enhanced feature vector to generate a second enhanced feature vector; if it does not exceed, directly retaining the first enhanced feature vector as the second enhanced feature vector; and using a principal component analysis algorithm to perform dimensionality reduction processing on the second enhanced feature vector to generate a compressed feature vector set.
[0046] Specifically, firstly, basic multidimensional features are extracted from the structured fourth dataset, including core indicators such as satellite signal period, network packet loss rate, ground station command frequency, permission change frequency, system alarm count, link interruption time, and traffic peak, forming a set of key parameters covering both the space and ground segments. Then, for the signal period characteristics, time series decomposition methods (such as STL decomposition) are used to extract trend, seasonal, and residual terms, calculating enhanced features such as period fluctuation amplitude and frequency stability, which are then merged into the basic vector to generate the first enhanced feature vector to capture the dynamic changes in satellite signals. For scenarios with abnormal packet loss rates, If the threshold is exceeded (e.g., 5%), the Pearson correlation coefficient between the number of alarms and the interruption time is calculated using a sliding window to quantify the correlation anomalies caused by network congestion or attack behavior. This coefficient is then incorporated into the vector as a new feature to generate a second enhanced feature vector, strengthening the characterization of low-frequency coordinated attacks (such as the correlation between space segment signal interference and ground segment traffic surges). Finally, Principal Component Analysis (PCA) is used to reduce the dimensionality of the second enhanced vector. Orthogonal transformation is used to retain principal components with a cumulative variance contribution rate exceeding 95%, generating a compressed feature set. This eliminates collinearity between features and reduces the computational complexity of the dynamic Bayesian network. Step S500 solves the problems of high feature dimensionality, strong noise interference, and weak cross-domain correlation in traditional methods, providing low-redundancy and high-representational input data for risk probability calculation, ensuring that subsequent modeling can accurately quantify dynamic security risks in a space-ground coordinated environment.
[0047] In this embodiment, the process of constructing a dynamic Bayesian network based on a set of feature vectors, calculating the risk probability distribution of each node, determining the risk assessment level of the network state, and generating the network communication state includes: defining node variables of the dynamic Bayesian network from the set of feature vectors, including satellite terminal state, ground station response, and attack event probability; using the K2 algorithm to learn the dependencies between nodes and generate an initial network topology; calculating the conditional probability distribution P(X|Y) between nodes based on the initial network topology, where X represents the node state and Y represents the parent node state, to obtain the joint probability distribution; introducing a time window to segment the set of feature vectors, calculating the state transition probability, and optimizing the dynamic Bayesian network; sampling and calculating the marginal probability P(X) of each node using the Monte Carlo method to obtain the risk probability distribution; sorting according to the risk probability values, mapping to a preset risk assessment level table, and outputting the risk assessment level of the network state; and generating link quality indicators and traffic isolation markers based on the risk assessment levels to construct the network communication state.
[0048] Specifically, network node variables are defined from the compressed feature vector set, including satellite terminal status (e.g., signal strength, bit error rate), ground station response (e.g., command execution delay, legality of permission changes), and attack event probability (e.g., illegal command injection, possibility of traffic hijacking), to construct a cross-domain node system covering the space segment and the ground segment. Then, the K2 algorithm is used to learn the dependencies between nodes, and an initial directed acyclic graph topology is generated based on the conditional probability information in the feature vectors, clarifying the causal relationship between satellite status, ground operations, and attack events. Based on the initial topology, the conditional probability distribution P(X|Y) between nodes (X is the current node state, Y is the parent node state) is calculated through maximum likelihood estimation, constructing a joint probability distribution model to capture static risk associations. A sliding time window (e.g., a 5-minute window) is introduced to segment the feature vector sequence, calculating the time transition probability of node states (e.g., duration of satellite signal anomalies). This approach optimizes the dynamic adaptability of the network topology, addressing the inability of traditional static Bayesian networks to capture temporal dependencies. It samples the joint probability distribution using the Monte Carlo method (e.g., 1000 simulations) to calculate the marginal probability P(X) of each node, generating a risk probability distribution (e.g., 30% probability of satellite terminal being controlled, 25% probability of ground station command tampering). Based on the risk probability values, the distribution is mapped to a preset risk level table (low / medium / high, with thresholds of 20% and 50% respectively), outputting the risk assessment level of the current network state. Finally, based on the risk level, link quality indicators (e.g., signal stability score) and traffic isolation markers (e.g., whether redundant links are enabled) are generated, constructing a network communication state that includes node risk status, link health, and defense strategies. This provides a quantitative basis for graded response (alarms, traffic isolation), solving the problems of lagging risk assessment and weak dynamic defense capabilities in traditional methods.
[0049] In this embodiment, triggering an alarm and recording an anomaly log if the risk probability distribution exceeds a preset threshold includes: determining whether the risk probability distribution exceeds a preset first-level threshold to obtain a first list of risk-exceeding nodes; if the first list of risk-exceeding nodes is not empty, triggering a real-time alarm according to the alarm priority and generating an alarm message sequence; recording the anomaly log to a preset storage space according to the alarm message sequence, checking whether the log storage capacity is sufficient, and generating a log recording completion status.
[0050] Specifically, when the risk probability distribution calculated by the dynamic Bayesian network exceeds a preset first-level threshold (e.g., 30%), the system first traverses all nodes, filters out nodes with excessive risk probabilities, and generates a first-level list of nodes with excessive risk. If this list is not empty, a real-time alarm is triggered according to a preset alarm priority rule (e.g., satellite terminal status takes precedence over ground station response), generating an alarm message sequence containing information such as node name, risk value, and time of exceeding the threshold, and pushing it to maintenance personnel via SMS, email, or system pop-ups. Subsequently, the system records the alarm message sequence in chronological order to a preset log storage space (e.g., a database or log file), while checking whether the current storage capacity meets the writing requirements—if the capacity is insufficient, it triggers automatic expansion or cleanup of expired logs to ensure complete retention of abnormal events. Finally, a log recording completion status (success / failure) is generated and fed back to the system monitoring module, forming a closed-loop process from risk detection to evidence retention. This mechanism, through real-time alarms and persistent log storage, solves the problems of delayed abnormal event detection and easy loss of attack evidence in traditional methods, providing a reliable basis for subsequent attack tracing and responsibility determination.
[0051] In this embodiment, the step of isolating abnormal traffic and enabling redundant communication links by using a dynamic routing allocation algorithm to generate an updated network communication state if the risk probability distribution exceeds a higher preset threshold includes: generating a second list of nodes with excessive risk if the risk probability distribution exceeds a preset secondary threshold; calculating traffic allocation weights using a dynamic routing allocation algorithm based on the second list of nodes with excessive risk, wherein isolation weights are assigned to nodes in the list and normal communication weights are assigned to other nodes, resulting in an updated traffic allocation table; enabling redundant communication links through the traffic allocation table, adjusting data packet transmission paths, isolating abnormal traffic, and determining a new communication link state; and updating the network communication state according to the new communication link state.
[0052] Specifically, when the risk probability distribution calculated by the dynamic Bayesian network exceeds a preset secondary threshold (e.g., 60%), the system first filters out nodes with excessive risk and generates a second list of nodes with excessive risk. Then, based on this list, it calls the dynamic routing allocation algorithm to calculate the traffic allocation weight according to the node risk status—assigning isolation weights (e.g., setting it to 0 to prohibit traffic from passing) to nodes with excessive risk and assigning normal communication weights (e.g., setting it to 1 to allow traffic transmission) to nodes with normal risk, generating an updated traffic allocation table. The traffic allocation table triggers the activation of redundant communication links (e.g., switching to a pre-configured backup satellite link or ground station backup channel), adjusting the data packet transmission path and guiding traffic that originally passed through nodes with excessive risk to normal nodes, thus achieving physical isolation of abnormal traffic. At the same time, it monitors the communication quality indicators of the new link (e.g., latency, packet loss rate), and after confirming that the link status is normal, it updates the link availability, traffic distribution, isolation node list, and other information to the network communication status, forming the latest status description that includes the execution results of defense measures, the current link health, and the list of risk nodes. This mechanism solves the problem of difficulty in quickly stopping damage after an attack spreads in traditional static defenses by dynamically adjusting routes and switching redundant links. It ensures that the remote sensing satellite ground transmission network can maintain core business communications when it suffers high-risk attacks, thus gaining a critical time window for attack chain disruption and system recovery.
[0053] In this embodiment, if the risk probability distribution exceeds a preset level three threshold, an emergency response protocol is activated and the system switches to a backup network environment; wherein the preset level three threshold is higher than the preset level two threshold.
[0054] If the risk probability distribution exceeds a preset three-level threshold (e.g., 85%), a third-risk-exceeding node list and a global risk comprehensive assessment result are generated. Based on the third-risk-exceeding node list, the current primary network environment is determined to be untrustworthy or facing irreversible damage risk, triggering the highest-level emergency response protocol. A network environment switching command is sent to all ground stations and on-orbit satellites through a secure command channel, terminating all non-core communication sessions of the current primary network and switching critical service flows (such as core remote control commands) to a pre-configured physically or logically isolated backup network environment. Simultaneously, based on the global risk comprehensive assessment result, an attack countermeasure plan is activated (e.g., releasing decoy data, injecting spoofed traffic to confuse attackers), and the security credentials and session keys of the primary network environment are reset synchronously. Finally, based on the link status and service recovery status of the backup network environment, a network-wide emergency response report is generated, including the emergency switching time, the scope of affected services, and the execution status of countermeasures, and the network communication status is updated to emergency operation mode.
[0055] Specifically, when the risk probability distribution calculated by the dynamic Bayesian network exceeds a preset third-level threshold (this threshold is higher than the second-level threshold, for example, set to 85%), it indicates that the network is facing catastrophic risks, such as coordinated attacks penetrating core nodes or a large-scale interruption threat to the satellite-to-ground links. The system first aggregates all nodes exceeding the threshold to generate a third-level risk-exceeding node list, and combines historical security event data with real-time status to conduct a comprehensive global risk assessment (such as calculating the expected time of critical service interruption and assessing the potential scope of data leakage). Subsequently, the system determines that the primary network environment is untrusted and automatically triggers the highest-level emergency response protocol: it broadcasts a switch command to all associated ground stations and on-orbit satellites via an encrypted secure command channel (such as using quantum key distribution technology to ensure command security), immediately suspends non-core communication sessions on the primary network to release resources and reduce the attack surface, and seamlessly switches critical remote control commands and other core services to a pre-configured backup network environment (such as backup satellite frequency bands or dedicated terrestrial fiber optic networks) that is physically or logically isolated from the primary network to ensure the continuity of core services. Furthermore, based on the global risk assessment results, the system automatically activates pre-set attack countermeasures, such as releasing decoy data to mislead attackers' tracking or injecting disguised traffic to disrupt attack chain analysis and provide trap data for subsequent forensics. Simultaneously, it performs a global reset of security credentials (such as digital certificates) and session keys in the primary network environment, thoroughly eliminating any credentials that attackers might steal. Finally, the system monitors the performance indicators of backup links (such as latency and bandwidth utilization) in real time, generates a detailed network-wide emergency response report, records the switching time, a list of affected services, and the execution status of countermeasures, and updates the network communication status to emergency operation mode, providing comprehensive evidence for manual intervention and post-incident review. This mechanism, through automated environment switching and proactive countermeasures, solves the problems of slow response and irreversible service interruption in extreme attack scenarios under traditional methods, ensuring the survival capability and rapid recovery foundation of the core services of the remote sensing satellite ground transmission network in the face of devastating attacks.
[0056] In this embodiment, step S700 includes: based on the network communication status, obtaining node communication data and event sequences from the satellite-ground collaborative log; using Bayesian posterior probability inference to calculate the attack probability distribution of each path, obtaining a path probability distribution table; based on the path probability distribution table, extracting initial attack entry features and lateral movement patterns, and determining the attack sequence by combining correlation analysis; and calculating the risk propagation weight W of the key nodes according to the identified key nodes of the attack sequence. k W k The propagation impact of node k in the attack chain is represented. The path probability distribution table and the attack sequence are integrated to generate an attack chain report containing the initial entry point, lateral movement path and key nodes.
[0057] Specifically, based on the network communication status (including risky nodes, link quality, and defense strategies) generated by the dynamic Bayesian network, node communication data (such as satellite-ground station interaction records) and event sequences (such as command execution and traffic forwarding) are extracted from the satellite-ground collaboration log. Bayesian posterior probability inference is used, combined with a prior attack pattern library, to calculate the posterior probability of each potential attack path (such as the probability of a path like "illegal ground station command injection → satellite signal hijacking → data backhaul tampering"), generating a path probability distribution table. Subsequently, through correlation analysis (such as temporal proximity and behavioral consistency), the initial attack entry point characteristics (the earliest controlled node) and lateral movement patterns (how the attack spreads between satellite and ground nodes) are extracted to determine the attack sequence (such as the step order of "ground station privilege escalation → satellite telemetry data forgery → ground receiver misleading"). Furthermore, the risk propagation weight W of key nodes is calculated. k (Based on the node's connectivity in the path, attack dwell time, and spread range), its driving effect on the attack chain is quantified; finally, the path probability distribution table, attack sequence, and key node weights are integrated to generate an attack chain report containing the initial entry point, lateral movement path, key nodes, and their propagation impact, providing security personnel with a complete picture of the attack (such as the attack source, spread path, and core target), supporting the optimization of defense strategies (such as prioritizing the hardening of high-weight nodes and blocking key propagation paths), and solving the problem that traditional methods can only detect single-point anomalies and cannot reconstruct the entire attack chain.
[0058] In this embodiment, step S800 includes:
[0059] According to the preset cycle, new real-time running data, network traffic data and system log data are collected, and steps S100 to S700 are repeated to obtain a new set of feature vectors as an incremental dataset.
[0060] Specifically, the system automatically collects new real-time operational data (such as satellite signal strength and bit error rate), network traffic data (data packet distribution and session anomaly rate), and system log data (equipment alarms and link status changes) from the remote sensing satellite ground transmission network at fixed time intervals (e.g., every 15 minutes). It then performs a complete data cleaning process (step S100), telemetry denoising (step S200), timestamp alignment (step S300), multi-source data fusion (step S400), feature extraction and dimensionality reduction (step S500), dynamic Bayesian network construction and risk assessment (step S600), and attack chain analysis (step S700), generating a new set of feature vectors isomorphic to historical data as the incremental dataset. This process, through periodic data reprocessing, ensures the consistency between incremental and existing data in the feature space, providing high-quality input for incremental model updates and solving the model aging problem caused by data drift in traditional methods.
[0061] Based on the incremental dataset, the prior probability and conditional probability tables of the dynamic Bayesian network are updated using an incremental learning algorithm.
[0062] Specifically, an incremental learning algorithm (such as the online expectation-maximization algorithm) is employed to dynamically adjust the prior probabilities (such as the basic probability of attack events) and conditional probability tables (such as the conditional distribution of ground station responses given satellite terminal status) of the dynamic Bayesian network based on new feature vectors in the incremental dataset. Specifically, by comparing the historical joint probability distribution with the likelihood function of the incremental data, node parameters are iteratively optimized to make the network probability distribution approximate the latest data features while preserving historical statistical regularities. This mechanism avoids the computational overhead of full retraining, ensuring that the model can adapt in real time to changes in network topology (such as ground station switching caused by satellite orbit adjustments) and new attack patterns (such as low-frequency coordinated attacks), thus improving the timeliness and accuracy of risk assessment.
[0063] The Markov Chain Monte Carlo (MCMC) method is used to sample and optimize the updated network parameters to improve the convergence efficiency of the model parameters for subsequent risk assessment.
[0064] Specifically, the network parameters (including prior probabilities and conditional probability tables) updated through incremental learning are sampled and optimized using Markov chain Monte Carlo methods (such as the Metropolis-Hastings algorithm): by constructing a Markov chain representing the posterior distribution of the parameters, a large number of sample sequences are generated to eliminate parameter biases caused by random fluctuations, enabling the network parameters to converge quickly to a stable optimal solution. This process significantly improves the convergence efficiency of model parameters after incremental updates (e.g., reducing the number of iterations by 50%), ensuring that the dynamic Bayesian network can efficiently and accurately calculate the node risk probability distribution in subsequent risk assessments, supporting downstream tasks such as real-time alerts, traffic isolation, and attack tracing, and solving the problems of parameter oscillation and slow convergence after model updates in traditional methods.
[0065] Based on the above analysis, it can be seen that through the periodic data collection, incremental learning, and MCMC optimization in step S800, the system achieves continuous self-optimization of dynamic Bayesian network parameters. This ensures the model's adaptability to the dynamic environment of the remote sensing satellite ground transmission network and maintains the real-time performance of risk assessment through efficient parameter convergence, ultimately improving the agility and accuracy of the overall security protection system. In a specific embodiment of the present invention, the network security risk assessment method for the remote sensing satellite ground transmission network of the present invention includes the following steps:
[0066] 1. Acquire real-time operational data and historical security event data of the remote sensing satellite ground transmission network, preprocess the data including cleaning, noise reduction, standardization and data fusion, and unify satellite telemetry data, ground station operation logs and communication protocol data into a structured format.
[0067] 2. Based on the preprocessed data, extract satellite data transmission characteristics (such as signal strength fluctuations and data packet loss rate), ground station operation behavior characteristics (such as command sending frequency and permission change records), system log characteristics (such as equipment abnormal alarms and link interruption records), and network traffic characteristics (malicious code attack alarms and abnormal access behavior logs, etc.) to construct a multi-dimensional feature vector. Perform joint preprocessing on space signal interference characteristics (such as spectrum anomalies and sudden increases in bit error rate) and ground intrusion behavior characteristics (such as illegal command injection and abnormal permission changes).
[0068] 3. A dynamic Bayesian network model is used to model the multidimensional feature vectors. Network nodes are defined as types such as satellite terminals, ground station equipment, and attack event nodes. The dependency relationship between nodes is quantified through a conditional probability table to identify potential security risks.
[0069] Satellite terminal node: satellite signal integrity, channel encryption status, and space environment interference level;
[0070] Ground station equipment nodes: ground station identity authentication results, protocol compliance, and equipment vulnerability exposure;
[0071] Attack events include: data theft, denial of service, and malicious control.
[0072] 4. Calculate the risk probability of the current network state using a Bayesian inference algorithm, and generate a risk assessment level (low / medium / high) based on a preset threshold. For example:
[0073] Covert channel attacks: Abnormal packet distribution in satellite communication protocols;
[0074] Space-Ground Coordinated APT Attacks: Correlation Patterns of Long-Term Low-Frequency Attack Behaviors in Space and Ground Logs.
[0075] 5. Based on the risk assessment level, trigger adaptive response strategies, including issuing alarms, isolating high-risk nodes, adjusting access control policies, or starting backup systems.
[0076] 6. When conducting source tracing analysis of security incidents, attack paths are inferred based on Bayesian posterior probability, and risk sources are located by combining satellite-ground collaborative logs (such as satellite signal interference sources or illegal access points of ground stations).
[0077] Space segment attack paths: such as signal interference disguised as solar storms → telemetry data tampering;
[0078] Ground-based attack path: such as malicious firmware upgrade at ground station → satellite command hijacking.
[0079] 7. Periodically update the prior probability and conditional probability tables of the Bayesian network model through incremental learning, and optimize the parameter convergence efficiency using the Markov Chain Monte Carlo (MCMC) method.
[0080] Specifically, the preprocessing also includes data fusion, unifying heterogeneous data sources into a structured format and marking them with timestamps and event type labels; performing wavelet transform filtering on noise signals in satellite telemetry data; marking ground station operation logs with timestamps and event type labels, and synchronizing them with satellite data transmission time.
[0081] Specifically, the construction of the Bayesian network model includes: defining network nodes as types such as satellite terminals, ground station equipment, and attack event nodes; training the conditional probability distribution between nodes using historical remote sensing satellite network attack data; optimizing the network structure using the K2 algorithm, prioritizing the preservation of critical link dependencies between satellite, ground station, and application system; and dynamically adjusting the routing allocation strategy of the remote sensing satellite transmission network to isolate suspected malicious traffic in the face of periodic low-rate DDoS attacks.
[0082] Specifically, the dynamic adjustment of the adaptive response strategy is as follows: if the risk probability exceeds the first-level threshold (30%), a real-time alarm is triggered and a log is recorded; if the risk probability exceeds the second-level threshold (60%), abnormal traffic is automatically isolated or high-risk accounts are disabled, and redundant communication links are activated; if the risk probability exceeds the third-level threshold (85%), an emergency response protocol is activated and the system switches to a backup network environment.
[0083] Specifically, the source tracing analysis includes: calculating the probability distribution of attack paths based on Bayesian posterior probability; locating the initial attack entry point and lateral movement path by combining log correlation analysis; and generating a visual attack chain report, marking key nodes and risk propagation paths.
[0084] Specifically, the method is applied to an evaluation system, which includes: a data acquisition module, a feature extraction module, a modeling and analysis module, a response control module, a source tracing module, and a model optimization module. The data acquisition module collects network traffic, user behavior logs, and system status data in real time. The feature extraction module extracts multi-dimensional security features from the raw data and constructs feature vectors. The modeling and analysis module constructs a Bayesian network model and calculates the conditions and risk probabilities between nodes. The response control module executes adaptive response strategies based on risk assessment levels. The source tracing module uses Bayesian posterior reasoning to infer attack paths and generate source tracing reports. The model optimization module periodically updates Bayesian network parameters to improve the accuracy of risk prediction. The response control module supports policy priority configuration, allowing administrators to customize the mapping relationship between thresholds and response actions.
[0085] In a specific example, the process begins with data preprocessing: collecting satellite telemetry data (signal strength, bit error rate), ground station operation logs (command types, permission changes), and space environment data (ionospheric disturbance index); structuring the remote sensing satellite data to identify network security risks in signal communication; collecting heterogeneous data such as network traffic (NetFlow), user login logs, and system vulnerability scan results; cleaning invalid data, standardizing timestamps and protocol types, and generating a structured dataset. Feature extraction and modeling then proceed: extracting features such as abnormal satellite signal fluctuation cycles, ground station command conflict frequency, link interruption duration, traffic peaks, session anomaly degree, and permission change frequency; training a Bayesian network using historical attack data, defining node variables (such as satellite payload status, ground station authentication results, communication link stability, network device status, user permissions, and vulnerability exposure); and optimizing the network structure using the K2 algorithm to reduce redundant edges. Risk Assessment and Response: Real-time calculation of node risk probability, categorized into low / medium / high levels; if the following conditions are met simultaneously, an APT attack can be identified as ongoing: Satellite: Command verification failures occur for three consecutive orbital cycles; Ground: An operator account initiates high-frequency sensitive operations outside of working hours; Application: The performance resources required by the application's runtime environment exceed normal levels by more than 50%; If the risk probability > 85% (high), isolate suspicious IPs and activate the backup system; if the risk probability is between 30%-60% (medium), restrict sensitive operation permissions and notify the administrator. Attack Source Tracing: Based on alarm events, calculate the posterior probability distribution to infer the most likely attack path; infer attack paths (e.g., "solar storm → signal attenuation → data loss" or "ground station vulnerability exploitation → protocol tampering"); combine spectrum analyzer data and ground station access logs to generate a satellite-ground joint attack chain report. Space Segment Attack Location: Determine the area with the highest probability of interference source through posterior probability calculation; Ground Segment Attack Location: Combine Bayesian inference and blockchain audit logs to trace the initial propagation node of the malicious attack. Model optimization: The conditional probability table is updated weekly based on new security event data; the Markov chain Monte Carlo (MCMC) method is used to optimize the parameter convergence speed.
[0086] Based on the above analysis, compared with the prior art, the present invention has the following beneficial effects:
[0087] Dynamic adaptability: The risk model is updated in real time through Bayesian networks to improve the ability to detect unknown threats;
[0088] Precise Response: A tiered response strategy reduces false alarm rates and ensures priority protection for critical assets;
[0089] Highly efficient attribution: Posterior probabilistic reasoning shortens attack investigation time and improves security operation and maintenance efficiency;
[0090] Low computational overhead: The incremental learning mechanism reduces the consumption of model training resources and is suitable for large-scale network environments.
[0091] Example 2, Figure 2 This is a schematic diagram of the network security risk assessment system for a remote sensing satellite ground transmission network according to Embodiment 2 of the present invention, as shown below. Figure 2 As shown in Embodiment 2, a network security risk assessment system for a remote sensing satellite ground transmission network is provided, including: a first generation module 201, a second generation module 202, a third generation module 203, a fourth generation module 204, a generation set module 205, a network communication status generation module 206, a report generation module 207, and an optimization and update module 208. The first generation module 201 is used to acquire real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground coordination logs from the remote sensing satellite ground transmission network to generate a cleaned first dataset. The second generation module 202 is used to denoise the telemetry data in the first dataset to generate a denoised second dataset. The third generation module 203 is used to align the timestamps of the second dataset with the ground station operation logs in the first dataset to generate a time-synchronized third dataset. The fourth generation module 204 is used to fuse the third dataset with the network traffic data and system log data in the first dataset to generate a structured fourth dataset. The generation set module 205 is used to extract multi-dimensional feature vectors from the fourth dataset and use dimensionality reduction processing to generate a compressed feature vector set. The network communication status generation module 206 is used to construct a dynamic Bayesian network based on the feature vector set, calculate the risk probability distribution of each node, determine the risk assessment level of the network status, and generate the network communication status. If the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded. If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated using a dynamic routing allocation algorithm, redundant communication links are enabled, and the network communication status is updated. The report generation module 207 is used to calculate the attack path probability distribution based on the network communication status using Bayesian posterior probability inference, and, combined with the satellite-ground collaborative log correlation analysis in the first dataset, generate an attack chain report containing key nodes and risk propagation paths. The optimization and update module 208 is used to periodically optimize and update the parameters of the dynamic Bayesian network based on newly collected data.
[0092] In this embodiment, the system is also used to: query and extract real-time operation data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs containing timestamps from the database associated with the remote sensing satellite ground transmission network; use regular expressions to match the feature fields of invalid records, delete records with null values or incorrect formats, and generate a cleaned first dataset.
[0093] In this embodiment, the system is further configured to: set the decomposition level and basis functions of discrete wavelet transform; decompose the signal using wavelet transform for the telemetry data in the first dataset to obtain high-frequency components and low-frequency components; calculate the energy value of the high-frequency components, and determine it as a noise signal if it exceeds a preset noise threshold; extract the low-frequency components and filter out the noise signal to generate a denoised second dataset.
[0094] In this embodiment, the system is further configured to: check whether there is a discrepancy between the timestamp of the second dataset and the timestamp of the ground station operation log in the first dataset, wherein the timestamp of the ground station operation log is referenced and marked based on the satellite data transmission time; wherein, if there is a discrepancy, the timestamps are aligned using linear interpolation; wherein, if there is no discrepancy, the original timestamps are directly retained; and merge the timestamp-aligned second dataset, the ground station operation log, and the network traffic data and system log data in the first dataset to generate a time-synchronized third dataset.
[0095] In this embodiment, the system is further configured to: based on the third dataset, use relational database association operations to perform attribute mapping between the time series of network traffic data and the status fields of system log data in the first dataset and the telemetry data and ground station operation logs in the third dataset, thereby generating a fourth dataset in a structured format.
[0096] In this embodiment, the system is further configured to: extract signal period, packet loss rate, instruction frequency, change frequency, alarm count, interruption time, and traffic peak from the fourth dataset to generate a basic multidimensional feature vector; decompose the signal period feature using a time series analysis method to calculate periodic fluctuation feature values, and merge the periodic fluctuation feature values into the basic multidimensional feature vector to generate a first enhanced feature vector; check whether the packet loss rate exceeds a preset loss rate threshold: if it exceeds, calculate the correlation coefficient between the alarm count and the interruption time using a sliding window method, and merge the correlation coefficient as a new feature into the first enhanced feature vector to generate a second enhanced feature vector; if it does not exceed, directly retain the first enhanced feature vector as the second enhanced feature vector; and perform dimensionality reduction processing on the second enhanced feature vector using a principal component analysis algorithm to generate a compressed feature vector set.
[0097] In this embodiment, the process of constructing a dynamic Bayesian network based on a set of feature vectors, calculating the risk probability distribution of each node, determining the risk assessment level of the network state, and generating the network communication state includes: defining node variables of the dynamic Bayesian network from the set of feature vectors, including satellite terminal state, ground station response, and attack event probability; using the K2 algorithm to learn the dependencies between nodes and generate an initial network topology; calculating the conditional probability distribution P(X|Y) between nodes based on the initial network topology, where X represents the node state and Y represents the parent node state, to obtain the joint probability distribution; introducing a time window to segment the set of feature vectors, calculating the state transition probability, and optimizing the dynamic Bayesian network; sampling and calculating the marginal probability P(X) of each node using the Monte Carlo method to obtain the risk probability distribution; sorting according to the risk probability values, mapping to a preset risk assessment level table, and outputting the risk assessment level of the network state; and generating link quality indicators and traffic isolation markers based on the risk assessment levels to construct the network communication state.
[0098] In this embodiment, triggering an alarm and recording an anomaly log if the risk probability distribution exceeds a preset threshold includes: determining whether the risk probability distribution exceeds a preset first-level threshold to obtain a first list of risk-exceeding nodes; if the first list of risk-exceeding nodes is not empty, triggering a real-time alarm according to the alarm priority and generating an alarm message sequence; recording the anomaly log to a preset storage space according to the alarm message sequence, checking whether the log storage capacity is sufficient, and generating a log recording completion status.
[0099] In this embodiment, the step of isolating abnormal traffic and enabling redundant communication links by using a dynamic routing allocation algorithm to generate an updated network communication state if the risk probability distribution exceeds a higher preset threshold includes: generating a second list of nodes with excessive risk if the risk probability distribution exceeds a preset secondary threshold; calculating traffic allocation weights using a dynamic routing allocation algorithm based on the second list of nodes with excessive risk, wherein isolation weights are assigned to nodes in the list and normal communication weights are assigned to other nodes, resulting in an updated traffic allocation table; enabling redundant communication links through the traffic allocation table, adjusting data packet transmission paths, isolating abnormal traffic, and determining a new communication link state; and updating the network communication state according to the new communication link state.
[0100] In this embodiment, the system is further configured to: based on the network communication status, obtain node communication data and event sequences from the satellite-ground collaborative logs; use Bayesian posterior probability inference to calculate the attack probability distribution of each path, obtaining a path probability distribution table; based on the path probability distribution table, extract initial attack entry features and lateral movement patterns, and determine the attack sequence by combining correlation analysis; and calculate the risk propagation weight W of the key nodes based on the identified key nodes of the attack sequence. k Wk The propagation impact of node k in the attack chain is represented. The path probability distribution table and the attack sequence are integrated to generate an attack chain report containing the initial entry point, lateral movement path and key nodes.
[0101] In this embodiment, the system is further configured to: collect new real-time running data, network traffic data, and system log data according to a preset period, and repeat steps S100 to S700 to obtain a new set of feature vectors as an incremental dataset; update the prior probability and conditional probability table of the dynamic Bayesian network based on the incremental dataset using an incremental learning algorithm; and sample and optimize the updated network parameters using the Markov Chain Monte Carlo (MCMC) method to improve the convergence efficiency of model parameters for subsequent risk assessment.
[0102] The various variations and specific examples of the network security risk assessment method for remote sensing satellite ground transmission networks provided in Embodiment 1 are also applicable to the network security risk assessment system for remote sensing satellite ground transmission networks provided in this embodiment. Through the foregoing detailed description of a network security risk assessment method for a remote sensing satellite ground transmission network, those skilled in the art can clearly understand the implementation method of the network security risk assessment system for a remote sensing satellite ground transmission network in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.
[0103] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this invention disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this invention can be achieved, and this is not limited herein.
[0104] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.
Claims
1. A method for assessing network security risks in a remote sensing satellite ground transmission network, characterized in that, include: The first dataset is generated by acquiring real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs from the remote sensing satellite ground transmission network. The telemetry data in the first dataset is denoised to generate a denoised second dataset. Align the timestamps of the ground station operation logs in the second dataset with those in the first dataset to generate a time-synchronized third dataset; The third dataset is combined with the network traffic data and system log data in the first dataset to generate a fourth dataset in a structured format; Multidimensional feature vectors are extracted from the fourth dataset, and a compressed feature vector set is generated by dimensionality reduction processing. A dynamic Bayesian network is constructed based on the set of feature vectors, the risk probability distribution of each node is calculated, the risk assessment level of the network state is determined, and the network communication state is generated. Specifically, a dynamic Bayesian network is constructed based on the feature vector set, the risk probability distribution of each node is calculated, the risk assessment level of the network state is determined, and the network communication state is generated, including: The node variables of the dynamic Bayesian network are defined from the set of feature vectors, and the node variables include satellite terminal status, ground station response, and attack event probability; The K2 algorithm is used to learn the dependencies between nodes and generate the initial network topology. Based on the initial network topology, the conditional probability distribution P(X|Y) between nodes is calculated, where X represents the node state and Y represents the parent node state, thus obtaining the joint probability distribution. A time window is introduced to segment the feature vector set, the state transition probability is calculated, and the dynamic Bayesian network is optimized. The risk probability distribution is obtained by sampling and calculating the marginal probability P(X) of each node using the Monte Carlo method. Based on the risk probability values, sort them and map them to a preset risk assessment level table to output the risk assessment level of the network status; Based on the risk assessment level, link quality indicators and traffic isolation markers are generated to construct the network communication status. If the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded. If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated and redundant communication links are enabled through a dynamic routing allocation algorithm, and the network communication status is updated. Based on the network communication status, Bayesian posterior probability inference is used to calculate the probability distribution of attack paths. Combined with the correlation analysis of satellite-ground collaborative logs in the first dataset, an attack chain report containing key nodes and risk propagation paths is generated. The parameters of the dynamic Bayesian network are periodically optimized and updated based on newly acquired data.
2. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, The first cleaned dataset, generated by acquiring real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs from the remote sensing satellite ground transmission network, includes: Query and extract real-time operational data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaboration logs containing timestamps from the database associated with the remote sensing satellite ground transmission network; Regular expressions are used to match the feature fields of invalid records, delete records with empty values or incorrect formats, and generate the first cleaned dataset.
3. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, The telemetry data in the first dataset is denoised to generate a denoised second dataset, which includes: Set the decomposition hierarchy and basis functions for the discrete wavelet transform; For the telemetry data in the first dataset, wavelet transform is used to decompose the signal to obtain high-frequency and low-frequency components; Calculate the energy value of the high-frequency component; if it exceeds the preset noise threshold, it is determined to be a noise signal. Low-frequency components are extracted and noise signals are filtered out to generate a denoised second dataset.
4. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, Aligning the timestamps of the ground station operation logs in the second dataset with those in the first dataset, a time-synchronized third dataset is generated, comprising: Check whether there is a discrepancy between the timestamps of the second dataset and the timestamps of the ground station operation logs in the first dataset, wherein the timestamps of the ground station operation logs are referenced and marked based on the satellite data transmission time; If there is a discrepancy, the timestamps are aligned using linear interpolation. If there is no deviation, the original timestamp is directly retained; The second dataset, with timestamps aligned, the ground station operation logs, and the network traffic and system log data from the first dataset are merged to generate a third dataset with synchronized time.
5. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, The fourth dataset, generated by merging the third dataset with the network traffic data and system log data from the first dataset, includes the following: Based on the third dataset, relational database association operations are used to map the time series of network traffic data and the status fields of system log data in the first dataset to the telemetry data and ground station operation logs in the third dataset, generating a fourth dataset in a structured format.
6. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, Multidimensional feature vectors are extracted from the fourth dataset, and a compressed feature vector set is generated by dimensionality reduction processing, including: The signal period, data packet loss rate, instruction frequency, change frequency, alarm count, interruption time, and traffic peak are extracted from the fourth dataset to generate a basic multidimensional feature vector. The periodic features of the signal are decomposed using time series analysis to calculate periodic fluctuation feature values, and these periodic fluctuation feature values are merged into the basic multidimensional feature vector to generate a first enhanced feature vector. Check whether the packet loss rate exceeds a preset loss rate threshold: If the number of alarms exceeds the limit, the correlation coefficient between the number of alarms and the interruption time is calculated using the sliding window method. The correlation coefficient is then added as a new feature and merged into the first enhanced feature vector to generate the second enhanced feature vector. If the value does not exceed the limit, the first enhanced feature vector is directly retained as the second enhanced feature vector. The second enhanced feature vector is dimensionality reduced using the principal component analysis algorithm to generate a compressed feature vector set.
7. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 1, characterized in that, If the risk probability distribution exceeds a preset threshold, an alarm will be triggered and an anomaly log will be recorded, including: Determine whether the risk probability distribution exceeds a preset first-level threshold to obtain a first list of risk-exceeding nodes; If the first list of nodes exceeding the risk limit is not empty, then a real-time alarm is triggered according to the alarm priority, and an alarm message sequence is generated. Based on the alarm message sequence, record the abnormal logs to the preset storage space, check whether the log storage capacity is sufficient, and generate a log recording completion status.
8. The network security risk assessment method for remote sensing satellite ground transmission networks as described in claim 7, characterized in that, If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated and redundant communication links are enabled through a dynamic routing allocation algorithm, generating an updated network communication state including: If the risk probability distribution exceeds the preset secondary threshold, a second list of risk-exceeding nodes is generated; Based on the second list of nodes with excessive risk, a dynamic routing allocation algorithm is used to calculate the traffic allocation weight, in which isolation weight is assigned to the nodes in the list and normal communication weight is assigned to other nodes, resulting in an updated traffic allocation table. The traffic allocation table enables redundant communication links, adjusts data packet transmission paths, isolates abnormal traffic, and determines new communication link status. Update the network communication status based on the new communication link status.
9. A network security risk assessment system for a remote sensing satellite ground transmission network, based on the network security risk assessment method for a remote sensing satellite ground transmission network as described in any one of claims 1-8, characterized in that, The network security risk assessment system for the remote sensing satellite ground transmission network includes: The first generation module is used to obtain real-time operation data, historical security event data, ground station operation logs, network traffic data, system log data, and satellite-ground collaborative logs from the remote sensing satellite ground transmission network to generate the first cleaned dataset. The second generation module is used to denoise the telemetry data in the first dataset and generate a denoised second dataset. The third generation module is used to align the timestamps of the ground station operation logs in the second dataset with those in the first dataset to generate a time-synchronized third dataset. The fourth generation module is used to merge the network traffic data and system log data in the third dataset with the network traffic data and system log data in the first dataset to generate a fourth dataset in a structured format. The generation set module is used to extract multi-dimensional feature vectors from the fourth dataset and generate a compressed feature vector set by dimensionality reduction processing. A network communication status generation module is used to construct a dynamic Bayesian network based on the feature vector set, calculate the risk probability distribution of each node, determine the risk assessment level of the network status, and generate the network communication status. If the risk probability distribution exceeds a preset threshold, an alarm is triggered and an anomaly log is recorded. If the risk probability distribution exceeds a higher preset threshold, abnormal traffic is isolated and redundant communication links are enabled through a dynamic routing allocation algorithm, and the network communication status is updated. The report generation module is used to calculate the probability distribution of attack paths based on the network communication status using Bayesian posterior probability inference, and combine it with the satellite-ground collaborative log correlation analysis in the first dataset to generate an attack chain report containing key nodes and risk propagation paths. The optimization and update module is used to periodically optimize and update the parameters of the dynamic Bayesian network based on newly collected data.
Citation Information
Patent Citations
Context-aware privileged access control system for dynamic risk-based authorization
DE202025104640U1
Methods and Systems for Using Artificial Intelligence to Improve Space Launch Operations
US20250256864A1