A network security inspection system based on big data
By comprehensively applying quantum anchoring acquisition, twin attack and defense simulation, neural symbol detection, optical quantum response, metaverse operation and maintenance, and Starlink collaborative auditing modules, the challenges of identity authentication, threat detection, and cross-domain auditing in network security inspections have been solved, achieving efficient network security defense and tracing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJINGNETENTSEC
- Filing Date
- 2025-08-15
- Publication Date
- 2026-07-28
AI Technical Summary
Existing network security inspection systems have security vulnerabilities in identity authentication, traditional methods are easily cracked by quantum computing, threat detection has a low detection rate for unknown attacks, cross-domain auditing has chaotic timing, and it is difficult to meet the needs of international collaborative defense.
The system employs a quantum anchoring acquisition module that integrates QKD and SDP technologies to generate quantum fingerprints, a twin attack and defense simulation module that uses the MARL engine to simulate attack and defense confrontations, a neural symbol detection module for dual-track threat detection, a photonic quantum response module to achieve physical network disconnection, a metaverse operation and maintenance module to provide immersive operation and maintenance, a Starlink collaborative audit module to achieve cross-time zone calibration, and a biometric anchoring module to construct a closed-loop permission system.
It achieves efficient identity authentication, accurate threat detection, cross-domain tracing, and access control, improving the overall defense capabilities of network security inspections, reducing false positive rates and timing issues, and meeting the needs of international collaborative defense.
Smart Images

Figure CN121239435B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically a network security inspection system based on big data. Background Technology
[0002] Cybersecurity inspection is a core component of ensuring the stable operation of digital infrastructure. With the deep integration of 5G, IoT, and the Industrial Internet, network nodes are growing exponentially, and the interconnection of heterogeneous devices has created complex security boundaries. Various new attack methods (such as quantum simulation attacks and cross-domain APT attacks) pose a serious challenge to traditional defense systems. Existing technologies have the following technical problems:
[0003] 1. The identity authentication system has fundamental security vulnerabilities. Relying on traditional methods such as passwords and digital certificates, it is easily cracked by quantum computing. Physical characteristics (such as MAC addresses) can be cloned, allowing malicious nodes to remain hidden in the network for a long time without being detected. Such identity forgery incidents occur frequently in key areas such as finance and energy, seriously threatening the security of core data.
[0004] 2. Threat detection suffers from a "black box dilemma." Purely data-driven AI models have a low detection rate for unknown attacks (such as zero-day exploits), and due to a lack of interpretability, they often make misjudgments in industrial control systems, leading to unplanned production line shutdowns and causing significant losses to enterprises.
[0005] 3. Cross-domain auditing suffers from time-series disorder. Events recorded by local clocks are difficult to accurately piece together cross-border attack chains. Evidence data from different jurisdictions cannot form a valid chain of evidence due to time calibration errors, resulting in an extremely low success rate of tracing the source and making it difficult to meet the needs of international collaborative defense. Summary of the Invention
[0006] The purpose of this invention is to provide a network security inspection system based on big data to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a network security inspection system based on big data, the system comprising:
[0008] Quantum Anchor Acquisition Module: It integrates QKD and SDP technologies to construct a dynamic encrypted channel, generate a quantum fingerprint bound to the physical characteristics of the device, and verify the identity of the node in real time; it adopts a distributed probe to adapt to heterogeneous networks, and generates a trusted data stream with quantum signature after preprocessing, providing basic data for the twin attack and defense simulation module;
[0009] Twin attack and defense simulation module: Based on trusted data stream, it constructs a digital twin that is synchronized with the physical network in real time. It simulates attack and defense confrontation through the MARL engine, generates potential attack paths and zero-day vulnerability impact predictions, and synchronizes the results to the neural symbol detection module to provide a dynamic rule base.
[0010] Neural Symbol Detection Module: Integrating neural networks and symbolic reasoning, it receives attack path features from the twin attack and defense simulation module and transforms them into symbolic rules. It uses a "dual-track parallel" mechanism to detect threats, optimizes the rule base for conflict results, and outputs accurately labeled threat information.
[0011] Optical quantum response module: Based on threat information, it divides the network domain through a reconfigurable optical switch array, physically disconnects deterministic threats, marks data packets of suspicious behavior, and outputs defense action data;
[0012] Metaverse Operations and Maintenance Module: Integrates defense action data, constructs a three-dimensional operations and maintenance space combined with XR technology, allows operations and maintenance personnel to control virtual nodes using BCI equipment, generates defense suggestions, simulates complex faults, and outputs operation logs;
[0013] Starlink Collaborative Audit Module: Based on satellites and edge nodes, it builds a space-ground audit system, receives operation logs, uses satellite timestamps to calibrate cross-time zone events, stores key events in a distributed ledger, and generates a chain of evidence for the biometric anchoring module to verify permissions.
[0014] Biometric Anchoring Module: Integrates permission data from the Starlink Collaborative Audit Module, binds the biometrics of maintenance personnel to the physical fingerprints of devices, requires dual verification for configuration changes, and freezes interfaces and triggers the calibration node of the quantum anchoring acquisition module to form a closed-loop defense.
[0015] Preferably, the quantum anchoring acquisition module includes:
[0016] (1) Core technologies and identity verification: Integrating quantum key distribution (QKD) and software-defined boundary (SDP) technologies to construct a dynamic encrypted acquisition channel; assigning a unique quantum fingerprint to each network node through a quantum random number generator, binding it with physical characteristics such as the electromagnetic radiation spectrum of the hardware chip to form an unforgeable identity identifier; using the quantum entanglement property to verify the node identity in real time during acquisition, and immediately triggering channel blocking if the fingerprint does not match;
[0017] Formula for calculating node identity credibility:
[0018]
[0019] In the formula: This represents the node's identity credibility (value [0, 1]), which is a weighted fusion result of quantum features and physical features. When this happens, the system triggers a channel blocking mechanism based on SDP technology, directly cutting off the access link of untrusted nodes;
[0020] This represents the quantum feature weight coefficient (default 0.6). Since quantum fingerprints are based on the quantum no-cloning principle, their anti-counterfeiting ability is better than that of physical features, hence the higher weight. When quantum channel interference is detected, the system will dynamically increase it to 0.8 to strengthen the verification priority of quantum features.
[0021] The quantum fingerprint matching degree is represented by the comparison result between the unique quantum state (such as the polarization direction of a photon) assigned to the node by the quantum random number generator and the preset template, with a value of [0, 1]. Real-time verification is achieved by utilizing the quantum entanglement property, and the matching degree is updated every 10ms to ensure the timeliness of identity authentication.
[0022] The physical feature matching degree refers to the comparison result of physical fingerprints such as the electromagnetic radiation spectrum of the device hardware and the chip serial number, with a value of [0, 1]. The distributed probe collects electromagnetic features through a spectrum analyzer and compares them with the pre-stored template to make up for the identity verification requirements when quantum communication is interrupted.
[0023] Function: To solve the problem of traditional single-password or MAC address authentication being easily forged, Rid can accurately quantify the trustworthiness of node identities by integrating both quantum and physical features; for example, when a node has a quantum fingerprint matching degree of 0.9 but a physical feature matching degree of 0.6, =0.6×0.9+0.4×0.6=0.78<0.8, the system judges it as a fake node and blocks the channel, providing a "zero-pollution" reliable data source for the twin attack and defense simulation module;
[0024] (2) Data acquisition architecture and data support: A distributed probe architecture is adopted to adapt to heterogeneous network environments such as Ethernet, 5G, and industrial bus; the granularity is dynamically adjusted through an adaptive sampling algorithm, the core link maintains microsecond-level sampling, and the edge nodes adopt event-triggered acquisition to balance data integrity and system overhead; after the acquired data is desensitized and format normalized, a trusted data stream with quantum signature is generated to provide basic data for the twin attack and defense simulation module and ensure that the simulation scenario is consistent with the physical network.
[0025] This module does not simply apply quantum key technology, but integrates quantum random number generation, physical feature extraction, and distributed probe architecture to form an integrated trusted data source construction solution of 'identity verification-data acquisition-encrypted transmission'. Its collaborative design of dynamic encryption channel and adaptive sampling solves the problem of 'difficulty in balancing data integrity and acquisition efficiency' in heterogeneous network environments.
[0026] Preferably, the twin attack and defense simulation module includes:
[0027] (1) Digital twin construction: Based on the reliable data provided by the quantum anchor acquisition module, a digital twin that is synchronized with the physical network in real time is constructed; through digital thread technology, dynamic attributes such as network topology, device status, and traffic characteristics are mapped to form a virtual image that is updated in milliseconds, accurately replicating the operating status of the physical network;
[0028] (2) Attack and defense simulation and data output: The module has a built-in multi-agent reinforcement learning (MARL) engine, in which the "attack agent" simulates hacker tactics with reference to the MITRE ATT&CK framework, and the "defense agent" simulates the system defense strategy. The two continuously engage in combat simulation in twin space; potential attack paths are automatically generated and key defense nodes are marked. For undisclosed 0-day vulnerabilities, the spread speed and damage threshold are predicted through simulation algorithms. The simulation results are synchronized to the neural symbol detection module in real time, providing a dynamically updated detection rule base, realizing a closed loop from virtual pre-simulation to actual defense;
[0029] Attack path risk value calculation formula:
[0030]
[0031] In the formula: This represents the overall risk value of the attack path. The higher the value, the more likely the path is to be exploited by hackers. It is used to filter high-risk links from multiple virtual simulation paths. );
[0032] This indicates the number of nodes included in the path. For example, an attack chain from an edge IoT device to the core database might contain four nodes: an IoT node, a switch, an application server, and a database. );
[0033] Indicates the first The vulnerability index of each node, based on the CVSS score mapping (e.g., CVSS=9.0 maps to...). The system is dynamically updated by combining real-time node vulnerability information (such as whether there are unpatched CVE-2024-XXX vulnerabilities) with the digital twin.
[0034] Represents the weight of the hop count, the hop number The fewer the number of hops from a node to the target node, the higher the weight (e.g., a 1-hop node). 3-hop node This reflects the principle of "risk amplification near core nodes";
[0035] This represents the probability of a node being compromised, based on simulation results from the MARL engine and combined with historical attack data statistics (e.g., if the probability of a certain type of IoT device being successfully compromised is 0.8, then...). );
[0036] Purpose: To quantify and assess the threat level of attack paths within a digital twin. For example, in simulations targeting zero-day vulnerabilities, if a certain path... =0.9、 =0.8、 =0.7 (n=1), then =0.9×0.8×0.7=0.504, the system judges it as medium risk; if n=2 and the second node V=0.8, L=1.0, T=0.9, then the total risk =0.504+0.8×1.0×0.9=1.224, triggering a high-risk warning, and synchronizing to the neural symbol detection module to update the rule base.
[0037] Preferably, the neural symbol detection module includes:
[0038] (1) Technology integration and rule transformation: break through the "black box dilemma" of traditional AI detection, integrate neural network and symbolic logic reasoning, receive the attack path features output by the twin attack and defense simulation module, and transform them into interpretable symbolic rules, such as "when port 445 is continuously connected and the process name contains a random string, it is determined to be ransomware propagation", and embed the feature extraction layer of the deep learning model.
[0039] (2) Dual-track detection and result application: The detection process adopts a "dual-track parallel" mechanism. The neural network layer captures abnormal behaviors such as traffic mutation and protocol distortion through spatiotemporal features. The symbolic reasoning layer verifies the integrity of the attack logic based on expert rules, such as whether it meets the "scan-penetration-privilege escalation-lateral movement" chain. For cases with conflicting judgment results, the rule correction engine is activated to optimize the rule base. The detection results accurately mark the threat type and stage, providing a basis for differentiated handling for the quantum response module.
[0040] Dual-track detection overall confidence formula:
[0041]
[0042] In the formula: This indicates the overall confidence level of threat detection, used to distinguish between "certain threats" (…). "Suspicious behavior" This provides a basis for the processing of the photonic quantum response module;
[0043] This represents the neural network weights (default 0.5). When detecting new and unknown threats, the system automatically increases the weights to 0.7 to enhance the neural network's ability to capture abnormal patterns; when detecting known threats, the weights decrease to 0.3, prioritizing symbolic rules.
[0044] This represents the confidence level of the neural network, output by a spatiotemporal feature extraction network (such as ST-GCN), reflecting the probability of identifying abnormal behaviors such as sudden traffic changes and protocol malformations; for example, when a host is detected to have a 100-fold increase in port scans within 5 minutes, ;
[0045] This represents the confidence level of symbolic reasoning, based on rules derived from attack path characteristics synchronized from the twin attack-defense simulation module, such as "port 445 external connection + random process name → ransomware". It verifies the completeness of the attack logic chain, and a perfect match to the rules is achieved. When key links are missing ;
[0046] This represents the rule matching degree correction coefficient. For example, if a certain behavior matches "port 445 external connection" but the process name is not random, then... This reduces the contribution value of symbolic reasoning;
[0047] Function: To solve the "black box" problem in traditional AI detection, for example, neural networks misclassifying the encryption behavior of normal software as malicious. =0.9), but symbolic reasoning found that it does not satisfy the "lateral movement" stage ( =0.2, δ=1.0), then =0.5×0.9+0.5×0.2×1.0=0.55<0.9, the system judges it as suspicious behavior, avoids false blocking, and reflects the dual-track advantage of "feature learning + logic verification".
[0048] Preferably, the photonic quantum response module includes:
[0049] (1) Physical layer defense architecture: Based on the threat location results of the neural symbol detection module, a light-controlled defense system is constructed. A reconfigurable optical switch array is used to build a physical isolation channel. The network is divided into three logical domains: trusted zone, suspicious zone, and isolated zone. Data transmission between domains must be verified by quantum entanglement state to ensure the effectiveness of isolation.
[0050] (2) Threat handling and log synchronization: When a known deterministic threat such as ransomware is detected, the optical switch is activated by quantum key to deflect the optical transmission path of the infected node to the isolation zone, achieving microsecond-level physical layer network disconnection; for suspicious behaviors such as abnormal traffic with unknown characteristics, the "photon silence" mode is activated, and data packets are marked by optical signal modulation technology for subsequent analysis. The execution log of the response action is synchronized to the metaverse operation and maintenance module in real time, providing operation and maintenance personnel with a visual defense operation backtracking interface;
[0051] This module combines the physical isolation of the reconfigurable optical switch array with quantum entanglement state verification to achieve differentiated defense of 'physical network disconnection for deterministic threats + photon tagging of suspicious behavior'. The linkage between its optical control defense system and quantum key activation mechanism overcomes the defect of traditional software firewalls that 'logical isolation is easily bypassed'. This integration of physical and quantum technologies is innovative.
[0052] Formula for the utility value of a defense strategy:
[0053]
[0054] In the formula: This represents the utility value of the defense strategy, used to select the optimal solution from strategies such as "physical network disconnection," "photon silencing," and "traffic mirroring." The most important strategy is executed first;
[0055] Indicates the success rate of threat blocking, and the physical network disconnection (by deflecting the path via an optical switch). Photon silencing (labeling data packets) Because the latter could be circumvented by attackers;
[0056] Represents the asset value coefficient, from the core database. Edge sensor This reflects the differentiated allocation of defense resources;
[0057] This indicates a response delay; physical network disconnection relies on the mechanical action of an optical switch. Photon silencing is based on optical signal modulation. It meets the requirement of "microsecond-level response";
[0058] This indicates the cost of defense; physically disconnecting the network requires the use of optical switch resources. Photon silencing consumes low resources. ;
[0059] Function: To enable intelligent decision-making for physical layer defense, for example, against known ransomware targeting core databases. =1.0), the U for physical network disconnection is (0.99×1.0) / (50×0.8)=0.02475, and the U for photon silence is (0.85×1.0) / (10×0.2)=0.425, but because The system ultimately chose to physically disconnect the network (although the CPU is low, it can completely block it), reflecting the "security first" strategy logic.
[0060] Preferably, the metaverse operation and maintenance module includes:
[0061] (1) Construction of Operation and Maintenance Space: Integrate the defense action data of the quantum response module to construct a three-dimensional operation and maintenance space. Through XR technology, the network topology is mapped into an interactive meta-universe scene. Traffic flows in the form of light particles, and threat events are dynamically flashed with red alarm icons. Operation and maintenance personnel wear brain-computer interface (BCI) devices to enter the virtual space and can control virtual nodes through their thoughts.
[0062] (2) Assisted decision-making and data upload: The built-in intelligent assisted decision-making system generates defense suggestions based on historical operation and maintenance data, such as "enable port blocking for 192.168.1.5", predicts the operation intentions of operation and maintenance personnel through EEG signals and loads the relevant configuration interface in advance; for complex faults such as cross-domain APT attacks, a timeline-style simulation animation is generated to intuitively show the entire attack process, and operation and maintenance operation records are automatically desensitized and uploaded to the Starlink collaborative audit module as basic evidence for cross-border traceability;
[0063] Decision recommendation weighting formula:
[0064]
[0065] In the formula: This indicates the suggestion weight, used to sort operation and maintenance suggestions (such as "port blocking" and "traffic scrubbing"). The suggestion with the highest weight is highlighted first in the XR virtual scene.
[0066] This represents the historical similarity weight (default 0.6). When dealing with new types of attacks, the system adjusts it to 0.3 to reduce the impact of historical cases.
[0067] The similarity between scenarios is represented by the cosine similarity calculated between a feature vector (containing 128 parameters such as attack type, affected nodes, and traffic characteristics) and a historical case database. For example, the similarity between the current APT attack and a case from 2023 is... ;
[0068] The success rate is calculated based on historical operation data recorded by the Metaverse Operations and Maintenance module. For example, if the success rate of "port blocking" in similar scenarios is 0.9, then... ;
[0069] Purpose: To improve the operational efficiency of handling complex faults. For example, in a cross-domain attack scenario, "traffic scrubbing" is recommended. =0.7, Ps=0.8, then W=0.6×0.7+0.4×0.8=0.74; "honeypot trap" =0.5, Ps=0.6, then W=0.54. In XR scenarios, the system prioritizes "traffic cleaning" and uses brain-computer interface to predict the intentions of maintenance personnel and preload the configuration interface.
[0070] Preferably, the Starlink collaborative audit module includes:
[0071] (1) Construction of the space-ground audit system: Based on the low-orbit satellite network and edge computing nodes, an integrated space-ground audit system is constructed to break through the geographical limitations of traditional audit systems; the operation logs of the metaverse operation and maintenance module are received, and the absolute time sequence calibration of cross-time zone events is achieved by combining satellite timestamps (error less than 10 nanoseconds) to ensure the consistency of the timeline of cross-border attack chains.
[0072] Cross-domain event timing consistency formula:
[0073]
[0074] In the formula: This indicates time synchronization error, used to verify the timing validity of cross-border attack events. When the error exceeds the limit, satellite time calibration is triggered.
[0075] It represents satellite timestamps, using UTC standard time provided by low-Earth orbit satellite networks, with an accuracy of 1ns, and achieves time synchronization of global nodes through inter-satellite links;
[0076] This represents the local node timestamp, the time the event occurred as recorded by the network device. It may contain errors due to clock drift, such as daily drift at edge nodes. ns;
[0077] This represents the transmission delay compensation value, calculated based on satellite orbital parameters (such as altitude and azimuth), indicating the signal propagation time. For example, when the satellite zenith angle is 30°, ;
[0078] Indicates the maximum permissible error (default 10ns) to ensure intercontinental audit events (such as Southeast Asian scaffolding outsourcing). The timeline of the attack on North American data centers is unambiguous.
[0079] Function: To solve the problem of inconsistent geographical and temporal records in traditional auditing systems. For example, in a transnational attack, the Southeast Asian node recorded the time... =10:00:00.000000000, Satellite Time =10:00:00.000000050, =50ns, then The system triggers time calibration, and after correction, it ensures that the timing logic of the attack chain "packet sending → intrusion → data leakage" is traceable, providing a reliable basis for the operation time of the biometric anchoring module;
[0080] (2) Audit Mechanism and Output: The audit process adopts distributed ledger technology to synchronize the hash values of key events such as cross-border data transmission and changes in defense strategies to global nodes to ensure that the records are tamper-proof; for network attacks involving multiple countries, audit segments from different regions are retrieved through inter-satellite links to automatically splice the complete attack path, such as the penetration process from Southeast Asian jump servers to North American data centers; the audit results generate a standardized chain of evidence to provide the basis for verifying the operation permissions of the biometric anchoring module, and at the same time support the connection with international judicial evidence collection platforms.
[0081] Preferably, the biometric anchoring module includes:
[0082] (1) Trust Root Mechanism Construction: The permission data of the Starlink Collaborative Audit Module is integrated with biometric features to construct a “human-machine” binding security mechanism; the biometric features of the operation and maintenance personnel, such as iris and brainprint, are encrypted and bound to the physical fingerprints such as the motherboard serial number and firmware hash of the managed equipment, and stored in the quantum encryption database to ensure that the associated information cannot be tampered with;
[0083] Formula for validity of binding relationship:
[0084]
[0085] In the formula: This indicates the binding validity value, used to control device configuration permissions. Operations are allowed when the time is right, otherwise the interface is frozen, reflecting the core mechanism of "human-machine" binding;
[0086] This indicates the biometric matching degree, which is the result of comparing features collected by an iris scanner or EEG sensor with pre-stored templates in a quantum encryption database. For example, if the iris feature point matching rate is 98%, then... ;
[0087] This indicates the physical fingerprint matching degree of the device, which is the comparison result between the device's motherboard serial number, firmware hash, and binding record. For example, if the hash value of a certain server matches completely, then... Partial alteration ;
[0088] This indicates the permission verification result. The Starlink Collaborative Audit Module verifies operation permissions based on the distributed ledger (e.g., administrator role is 1, visitor role is 0) to ensure that "authorized personnel operate authorized devices".
[0089] Function: To build the underlying trust root of the system, for example, the iris matching score of maintenance personnel. =0.99, Device Physical Fingerprint =1.0, permissions =1, then =min(0.99, 1.0)×1=0.99≥0.95, so modifying the firewall rules is allowed; if =0.9 (equipment replaced), then =0.9×1=0.9<0.95, the system freezes the operation and triggers the quantum anchoring acquisition module to recalibrate the node identity, completely eliminating unauthorized configuration changes;
[0090] (2) Permission verification and closed-loop defense: Any configuration change operation (such as modifying firewall rules) must be verified by two verifications. The device verifies the matching degree between the biometrics of the operation initiator and the pre-stored template, and the cloud verifies the legality of the operation permission through the Starlink collaborative audit module. For abnormal operations such as unauthorized personnel access, the relevant device configuration interface is immediately frozen, and the quantum anchoring collection module is triggered to recalibrate the node identity, forming a closed-loop defense from identity authentication to permission control, and completely eliminating unauthorized internal operations and permission abuse.
[0091] The beneficial effects of this invention are as follows:
[0092] 1. This invention utilizes a dual authentication mechanism that binds quantum fingerprints to device physical features, combined with a "human-machine" binding security mechanism built using a biometric anchoring module. This forms a closed-loop defense system from node identity verification to operation and maintenance permission control, completely solving the problems of traditional passwords or digital certificates being easily forged and crackable by quantum computing. Unlike the limitations of single authentication methods in existing technologies, the collaborative design of dynamic encryption channels and distributed probe architecture can adapt to heterogeneous network environments and balance data integrity and system overhead through adaptive sampling, providing a "zero-pollution" trusted data foundation for subsequent modules. This blocks malicious node access from the source, and its linkage mechanism of dual authentication and permission closed loop breaks through the bottleneck of isolated application of traditional identity authentication technologies.
[0093] 2. This invention achieves synergy through a dual-track mechanism of digital twin attack and defense simulation and neural symbol detection, enabling early identification of potential attack paths and the impact range of zero-day vulnerabilities, overcoming the limitations of traditional detection methods that rely on historical data. Specifically, the multi-agent reinforcement learning engine of the digital twin attack and defense simulation module pre-simulates attack paths in virtual space, dynamically generating symbolic rules. This, combined with the feature capture capabilities of the neural network and the logical verification advantages of symbolic reasoning in the neural symbol detection module, significantly reduces the false positive rate. This proactive defense logic of "virtual pre-simulation - dynamic rules - dual-track verification" differs from existing single-mode approaches of purely data-driven AI or purely rule-driven detection. It can accurately label threat types and stages, and provide interpretable decision-making basis for defense responses, effectively solving problems such as the difficulty in predicting complex attacks and "black box" false positives in AI detection. Its technological integration approach is highly innovative.
[0094] 3. The integrated space-ground auditing system of this invention solves the problems of cross-time zone time sequence disorder and cross-border source tracing difficulties in traditional auditing by combining satellite timestamp calibration and distributed ledger technology with the physical layer defense of the quantum response module, ensuring the integrity and traceability of the attack chain timeline and evidence chain. The immersive scenario and intelligent auxiliary decision-making of the metaverse operation and maintenance visualize the complex network state, and improves operational efficiency and shortens the fault handling time by combining brain-computer interface. The permission data fusion of the biometric anchoring module and the Starlink collaborative auditing module realizes precise permission control and eliminates the risk of unauthorized operation. This full-link design of "cross-domain time sequence calibration - physical isolation defense - immersive operation and maintenance - permission linkage" breaks through the limitations of the isolated operation of each functional module in traditional network security inspection, forming an integrated system covering attack prediction, defense response, source tracing audit, and permission control. Its overall technical effect far exceeds the sum of the individual effects of each module. Attached Figure Description
[0095] Figure 1 This is a flowchart of the network security inspection system based on big data according to the present invention. Detailed Implementation
[0096] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0097] like Figure 1 As shown in the figure, this embodiment of the invention provides a network security inspection system based on big data, the system comprising:
[0098] Quantum Anchor Acquisition Module: It integrates QKD and SDP technologies to construct a dynamic encrypted channel, generate a quantum fingerprint bound to the physical characteristics of the device, and verify the identity of the node in real time; it adopts a distributed probe to adapt to heterogeneous networks, and generates a trusted data stream with quantum signature after preprocessing, providing basic data for the twin attack and defense simulation module;
[0099] Twin attack and defense simulation module: Based on trusted data stream, it constructs a digital twin that is synchronized with the physical network in real time. It simulates attack and defense confrontation through the MARL engine, generates potential attack paths and zero-day vulnerability impact predictions, and synchronizes the results to the neural symbol detection module to provide a dynamic rule base.
[0100] Neural Symbol Detection Module: Integrating neural networks and symbolic reasoning, it receives attack path features from the twin attack and defense simulation module and transforms them into symbolic rules. It uses a "dual-track parallel" mechanism to detect threats, optimizes the rule base for conflict results, and outputs accurately labeled threat information.
[0101] Optical quantum response module: Based on threat information, it divides the network domain through a reconfigurable optical switch array, physically disconnects deterministic threats, marks data packets of suspicious behavior, and outputs defense action data;
[0102] Metaverse Operations and Maintenance Module: Integrates defense action data, constructs a three-dimensional operations and maintenance space combined with XR technology, allows operations and maintenance personnel to control virtual nodes using BCI equipment, generates defense suggestions, simulates complex faults, and outputs operation logs;
[0103] Starlink Collaborative Audit Module: Based on satellites and edge nodes, it builds a space-ground audit system, receives operation logs, uses satellite timestamps to calibrate cross-time zone events, stores key events in a distributed ledger, and generates a chain of evidence for the biometric anchoring module to verify permissions.
[0104] Biometric Anchoring Module: Integrates permission data from the Starlink Collaborative Audit Module, binds the biometrics of maintenance personnel to the physical fingerprints of devices, requires dual verification for configuration changes, and freezes interfaces and triggers the calibration node of the quantum anchoring acquisition module to form a closed-loop defense.
[0105] The quantum anchoring acquisition module includes:
[0106] (1) Core technologies and identity verification: Integrating quantum key distribution (QKD) and software-defined boundary (SDP) technologies to construct a dynamic encrypted acquisition channel; assigning a unique quantum fingerprint to each network node through a quantum random number generator, binding it with physical characteristics such as the electromagnetic radiation spectrum of the hardware chip to form an unforgeable identity identifier; using the quantum entanglement property to verify the node identity in real time during acquisition, and immediately triggering channel blocking if the fingerprint does not match;
[0107] The quantum random number generator generates 128-bit quantum random numbers via the BB84 protocol, which are then bound to the Fourier transform characteristics of the electromagnetic radiation spectrum of the device hardware (sampling frequency 1MHz) to form a quantum fingerprint. Quantum entanglement verification is achieved by distributing entangled photon pairs with a wavelength of 1550nm, and is updated every 10ms by comparing the polarization states of the photons. Values are used to ensure the timeliness and accuracy of verification.
[0108] Formula for calculating node identity credibility:
[0109]
[0110] In the formula: This represents the node's identity credibility (value [0, 1]), which is a weighted fusion result of quantum features and physical features. When this happens, the system triggers a channel blocking mechanism based on SDP technology, directly cutting off the access link of untrusted nodes;
[0111] This represents the quantum feature weight coefficient (default 0.6). Since quantum fingerprints are based on the quantum no-cloning principle, their anti-counterfeiting ability is better than that of physical features, hence the higher weight. When quantum channel interference is detected, the system will dynamically increase it to 0.8 to strengthen the verification priority of quantum features.
[0112] The quantum fingerprint matching degree is represented by the comparison result between the unique quantum state (such as the polarization direction of a photon) assigned to the node by the quantum random number generator and the preset template, with a value of [0, 1]. Real-time verification is achieved by utilizing the quantum entanglement property, and the matching degree is updated every 10ms to ensure the timeliness of identity authentication.
[0113] The physical feature matching degree refers to the comparison result of physical fingerprints such as the electromagnetic radiation spectrum of the device hardware and the chip serial number, with a value of [0, 1]. The distributed probe collects electromagnetic features through a spectrum analyzer and compares them with the pre-stored template to make up for the identity verification requirements when quantum communication is interrupted.
[0114] Function: To solve the problem of traditional single-password or MAC address authentication being easily forged, Rid can accurately quantify the trustworthiness of node identities by integrating both quantum and physical features; for example, when a node has a quantum fingerprint matching degree of 0.9 but a physical feature matching degree of 0.6, =0.6×0.9+0.4×0.6=0.78<0.8, the system judges it as a fake node and blocks the channel, providing a "zero-pollution" reliable data source for the twin attack and defense simulation module;
[0115] (2) Data acquisition architecture and data support: A distributed probe architecture is adopted to adapt to heterogeneous network environments such as Ethernet, 5G, and industrial bus; the granularity is dynamically adjusted through an adaptive sampling algorithm, the core link maintains microsecond-level sampling, and the edge nodes adopt event-triggered acquisition to balance data integrity and system overhead; after the acquired data is de-identified and format normalized, a trusted data stream with quantum signature is generated to provide basic data for the twin attack and defense simulation module and ensure that the simulation scenario is consistent with the physical network;
[0116] The adaptive sampling algorithm of the distributed probe dynamically adjusts according to the network load. When the core link traffic accounts for more than 70%, the sampling granularity is automatically adjusted from the microsecond level to the 10 microsecond level. The event-triggered collection of edge nodes uses abnormal port access and traffic changes as trigger conditions to ensure that no key data is missed.
[0117] Distributed probes are deployed in a 'core-edge' hierarchy. High-density probes (3-5 per node) are deployed on core network nodes (such as data center switches), while lightweight probes (1 shared by 10-20 devices) are deployed on edge devices (such as IoT terminals). Data communication between probes is achieved through encrypted tunnels (based on the ChaCha20 algorithm) to prevent data tampering during the collection process.
[0118] The data masking process uses a combination of static masking and dynamic masking. Static masking performs hash replacement on fixed sensitive fields (such as IP address and device serial number), while dynamic masking generates temporary identifiers for user identification information (such as account ID) in real-time traffic according to the session period. The pre-processed data needs to be verified by quantum signature (if the verification fails, the data will be collected again).
[0119] The twin attack and defense simulation module includes:
[0120] (1) Digital twin construction: Based on the reliable data provided by the quantum anchor acquisition module, a digital twin that is synchronized with the physical network in real time is constructed; through digital thread technology, dynamic attributes such as network topology, device status, and traffic characteristics are mapped to form a virtual image that is updated in milliseconds, accurately replicating the operating status of the physical network;
[0121] The real-time synchronization between the digital twin and the physical network adopts an incremental update + full verification mechanism. Incremental data (such as changes in device status and traffic fluctuations) is synchronized every 20ms, and full data verification (comparing the consistency of topology and node configuration) is performed every 5 minutes. Remodeling is triggered when the synchronization error exceeds 5%.
[0122] (2) Attack and defense simulation and data output: The module has a built-in multi-agent reinforcement learning (MARL) engine, in which the "attack agent" simulates hacker tactics with reference to the MITRE ATT&CK framework, and the "defense agent" simulates the system defense strategy. The two continuously engage in combat simulation in twin space; potential attack paths are automatically generated and key defense nodes are marked. For undisclosed 0-day vulnerabilities, the spread speed and damage threshold are predicted through simulation algorithms. The simulation results are synchronized to the neural symbol detection module in real time, providing a dynamically updated detection rule base, realizing a closed loop from virtual pre-simulation to actual defense;
[0123] The attacking agent refers to the 12 core tactics in the MITRE ATT&CK framework (such as initial access, execution, persistence, etc.), with each tactic corresponding to 5-8 simulated attack techniques; the defending agent simulates system defense strategies including port blocking, traffic filtering, vulnerability patch push, etc., and the attack and defense status is updated every 50ms during the confrontation with the attacking agent.
[0124] The simulation algorithm takes the attack surface of the vulnerability (such as affected ports and protocols), the exposure time of the target device, and the connectivity of the network topology as input variables. It generates 1,000 propagation paths through Monte Carlo simulation and uses the percentage of nodes covered by the path as the basis for determining the damage threshold. The simulation results retain the upper limit of the 95% confidence interval.
[0125] Attack path risk value calculation formula:
[0126]
[0127] In the formula: This represents the overall risk value of the attack path. The higher the value, the more likely the path is to be exploited by hackers. It is used to filter high-risk links from multiple virtual simulation paths. );
[0128] This indicates the number of nodes included in the path. For example, an attack chain from an edge IoT device to the core database might contain four nodes: an IoT node, a switch, an application server, and a database. );
[0129] Indicates the first The vulnerability index of each node, based on the CVSS score mapping (e.g., CVSS=9.0 maps to...). The system is dynamically updated by combining real-time node vulnerability information (such as whether there are unpatched CVE-2024-XXX vulnerabilities) with the digital twin.
[0130] Represents the weight of the hop count, the hop number The fewer the number of hops from a node to the target node, the higher the weight (e.g., a 1-hop node). 3-hop node This reflects the principle of "risk amplification near core nodes";
[0131] This represents the probability of a node being compromised, based on simulation results from the MARL engine and combined with historical attack data statistics (e.g., if the probability of a certain type of IoT device being successfully compromised is 0.8, then...). );
[0132] The reward function for the attacking agent is based on the vulnerability index of the penetrated node. With hop count weight The product design, the penalty function of the defensive agent and the probability of node penetration Positive correlation; the agent decision-making model is optimized through 1000 iterations of training.
[0133] Purpose: To quantify and assess the threat level of attack paths within a digital twin. For example, in simulations targeting zero-day vulnerabilities, if a certain path... =0.9、 =0.8、 =0.7 (n=1), then =0.9×0.8×0.7=0.504, the system judges it as medium risk; if n=2 and the second node V=0.8, L=1.0, T=0.9, then the total risk =0.504+0.8×1.0×0.9=1.224, triggering a high-risk warning, and synchronizing to the neural symbol detection module to update the rule base.
[0134] The neural symbol detection module includes:
[0135] (1) Technology integration and rule transformation: break through the "black box dilemma" of traditional AI detection, integrate neural network and symbolic logic reasoning, receive the attack path features output by the twin attack and defense simulation module, and transform them into interpretable symbolic rules, such as "when port 445 is continuously connected and the process name contains a random string, it is determined to be ransomware propagation", and embed the feature extraction layer of the deep learning model.
[0136] When extracting symbol rules from attack path features, the features are first structured to extract key elements such as port number, process name, and behavior sequence. Then, they are converted into rules in the form of 'condition → conclusion' through logical expressions, such as '(port 445 external connection) and (process name containing 8-character random string) → ransomware propagation'.
[0137] (2) Dual-track detection and result application: The detection process adopts a "dual-track parallel" mechanism. The neural network layer captures abnormal behaviors such as traffic mutation and protocol distortion through spatiotemporal features. The symbolic reasoning layer verifies the integrity of the attack logic based on expert rules, such as whether it meets the "scan-penetration-privilege escalation-lateral movement" chain. For cases with conflicting judgment results, the rule correction engine is activated to optimize the rule base. The detection results accurately mark the threat type and stage, providing a basis for differentiated handling for the quantum response module.
[0138] When the rule correction engine handles cases with conflicting judgment results, it first compares the feature differences between the neural network layer and the symbolic reasoning layer, and then combines the correct judgment results of similar cases in historical detection data. Through weighted iterative optimization, it optimizes the threshold parameters in the rule base to ensure rule adaptability.
[0139] Spatiotemporal feature capture uses a 3-layer ST-GCN (Spatiotemporal Graph Convolutional Network). The input is a traffic feature matrix within a 10-minute window (including packet length, protocol type, source and destination IP, etc.). Local spatiotemporal features are extracted through two convolutional layers, and anomaly probability is output by one fully connected layer. The activation function is LeakyReLU (slope 0.01).
[0140] The rule base adopts a tree-like storage structure. The root node represents the threat type (such as ransomware or APT attack), the child nodes represent the attack stage (such as scanning or penetration), and the leaf nodes represent specific characteristics (such as port or process name). The priority of the rules is sorted according to 'attack success rate × scope of impact', and high-priority rules (top 20%) are given priority in inference.
[0141] Dual-track detection overall confidence formula:
[0142]
[0143] In the formula: This indicates the overall confidence level of threat detection, used to distinguish between "certain threats" (…). "Suspicious behavior" This provides a basis for the processing of the photonic quantum response module;
[0144] This represents the neural network weights (default 0.5). When detecting new and unknown threats, the system automatically increases the weights to 0.7 to enhance the neural network's ability to capture abnormal patterns; when detecting known threats, the weights decrease to 0.3, prioritizing symbolic rules.
[0145] This represents the confidence level of the neural network, output by a spatiotemporal feature extraction network (such as ST-GCN), reflecting the probability of identifying abnormal behaviors such as sudden traffic changes and protocol malformations; for example, when a host is detected to have a 100-fold increase in port scans within 5 minutes, ;
[0146] This represents the confidence level of symbolic reasoning, based on rules derived from attack path characteristics synchronized from the twin attack-defense simulation module, such as "port 445 external connection + random process name → ransomware". It verifies the completeness of the attack logic chain, and a perfect match to the rules is achieved. When key links are missing ;
[0147] This represents the rule matching degree correction coefficient. For example, if a certain behavior matches "port 445 external connection" but the process name is not random, then... This reduces the contribution value of symbolic reasoning;
[0148] Function: To solve the "black box" problem in traditional AI detection, for example, neural networks misclassifying the encryption behavior of normal software as malicious. =0.9), but symbolic reasoning found that it does not satisfy the "lateral movement" stage ( =0.2, δ=1.0), then =0.5×0.9+0.5×0.2×1.0=0.55<0.9, the system judges it as suspicious behavior, avoids false blocking, and reflects the dual-track advantage of "feature learning + logic verification".
[0149] The photonic quantum response module includes:
[0150] (1) Physical layer defense architecture: Based on the threat location results of the neural symbol detection module, a light-controlled defense system is constructed. A reconfigurable optical switch array is used to build a physical isolation channel. The network is divided into three logical domains: trusted zone, suspicious zone, and isolated zone. Data transmission between domains must be verified by quantum entanglement state to ensure the effectiveness of isolation.
[0151] The Trusted Zone includes core databases and critical business servers, with admission criteria being a node identity trustworthiness Rid ≥ 0.9 and no abnormal behavior within 30 days; the Suspicious Zone includes edge computing nodes and non-core terminals, allowing limited external connections (such as accessing only designated ports); the Isolation Zone is an independent physical network segment, allowing only data reception (prohibiting active packet sending), with deep packet inspection (DPI) enabled on the inter-domain gateway.
[0152] The quantum entangled state verification process uses four pairs of entangled photon pairs (horizontal / vertical polarization states). The sender performs random basis measurements on the photons, and the receiver compares the results with the same basis measurements. If the matching degree is ≥90%, the verification is successful; otherwise, it is judged as illegal data and discarded. The verification time is controlled within 1μs to avoid affecting the data transmission efficiency.
[0153] The reconfigurable optical switch array uses a 2×2 MEMS optical switch. The optical switch driving circuit is activated by a quantum key (AES-256 encryption). The driving signal is converted by photoelectric conversion to control the deflection of the optical switch, realizing physical isolation between the trusted area, the suspicious area, and the isolated area. Before the data transmission between the domains, the verification is completed by the Bell base measurement of the quantum entangled state.
[0154] (2) Threat handling and log synchronization: When a known deterministic threat such as ransomware is detected, the optical switch is activated by quantum key to deflect the optical transmission path of the infected node to the isolation zone, achieving microsecond-level physical layer network disconnection; for suspicious behaviors such as abnormal traffic with unknown characteristics, the "photon silence" mode is activated, and data packets are marked by optical signal modulation technology for subsequent analysis. The execution log of the response action is synchronized to the metaverse operation and maintenance module in real time, providing operation and maintenance personnel with a visual defense operation backtracking interface;
[0155] The photon silent mode marks suspicious data packets by amplitude modulation (modulation depth 30%) of the optical signal. The marking information includes threat level and detection timestamp. The response action log is synchronized in real time in JSON format, and the fields include handling type, involved node IP, execution time, and operator identifier.
[0156] Formula for the utility value of a defense strategy:
[0157]
[0158] In the formula: This represents the utility value of the defense strategy, used to select the optimal solution from strategies such as "physical network disconnection," "photon silencing," and "traffic mirroring." The most important strategy is executed first;
[0159] Indicates the success rate of threat blocking, and the physical network disconnection (by deflecting the path via an optical switch). Photon silencing (labeling data packets) Because the latter could be circumvented by attackers;
[0160] Represents the asset value coefficient, from the core database. Edge sensor This reflects the differentiated allocation of defense resources;
[0161] This indicates a response delay; physical network disconnection relies on the mechanical action of an optical switch. Photon silencing is based on optical signal modulation. It meets the requirement of "microsecond-level response";
[0162] This indicates the cost of defense; physically disconnecting the network requires the use of optical switch resources. Photon silencing consumes low resources. ;
[0163] Function: To enable intelligent decision-making for physical layer defense, for example, against known ransomware targeting core databases. =1.0), the U for physical network disconnection is (0.99×1.0) / (50×0.8)=0.02475, and the U for photon silence is (0.85×1.0) / (10×0.2)=0.425, but because The system ultimately chose to physically disconnect the network (although the CPU is low, it can completely block it), reflecting the "security first" strategy logic.
[0164] The metaverse operation and maintenance module includes:
[0165] (1) Construction of Operation and Maintenance Space: Integrate the defense action data of the quantum response module to construct a three-dimensional operation and maintenance space. Through XR technology, the network topology is mapped into an interactive meta-universe scene. Traffic flows in the form of light particles, and threat events are dynamically flashed with red alarm icons. Operation and maintenance personnel wear brain-computer interface (BCI) devices to enter the virtual space and can control virtual nodes through their thoughts.
[0166] The three-dimensional operation and maintenance space constructed by XR technology is based on the network topology map, mapping devices such as routers and switches into interactive three-dimensional models. The color of the streaming particles of traffic is distinguished according to the protocol type (e.g., blue for TCP and green for UDP), and the flashing frequency of the red alarm icon for threat events is positively correlated with the threat level.
[0167] Interactive 3D operation and maintenance space: Virtual nodes support 'zoom-rotate-associative query' operations. Double-clicking a node expands the device details (such as CPU usage and vulnerability list). Dragging a node adjusts the topology connection relationship (the system automatically verifies the legality of the connection). The density of traffic stream particles is positively correlated with the actual bandwidth usage (1Gbps corresponds to 1000 particles / second). Abnormal traffic (such as sudden SYN packets) particles flash red.
[0168] (2) Assisted decision-making and data upload: The built-in intelligent assisted decision-making system generates defense suggestions based on historical operation and maintenance data, such as "enable port blocking for 192.168.1.5", predicts the operation intentions of operation and maintenance personnel through EEG signals and loads the relevant configuration interface in advance; for complex faults such as cross-domain APT attacks, a timeline-style simulation animation is generated to intuitively show the entire attack process, and operation and maintenance operation records are automatically desensitized and uploaded to the Starlink collaborative audit module as basic evidence for cross-border traceability;
[0169] The brain-computer interface device collects the EEG signals of maintenance personnel (sampling rate 250Hz), extracts features related to attention concentration and operation intention, and loads the corresponding configuration interface in advance when the confidence of intention recognition exceeds 80%, with the interface loading delay controlled within 500ms.
[0170] Animation generation for complex faults: The timeline simulation is displayed in layers according to 'attack phase - affected nodes - defense actions', with key time points (accurate to milliseconds) and traffic change curves marked for each phase; it supports pause and rollback operations, and clicking on a node can view the log details of that node (such as alarm information and configuration change records). The animation data comes from the defense action logs of the quantum response module.
[0171] Decision recommendation weighting formula:
[0172]
[0173] In the formula: This indicates the suggestion weight, used to sort operation and maintenance suggestions (such as "port blocking" and "traffic scrubbing"). The suggestion with the highest weight is highlighted first in the XR virtual scene.
[0174] This represents the historical similarity weight (default 0.6). When dealing with new types of attacks, the system adjusts it to 0.3 to reduce the impact of historical cases.
[0175] The similarity between scenarios is represented by the cosine similarity calculated between a feature vector (containing 128 parameters such as attack type, affected nodes, and traffic characteristics) and a historical case database. For example, the similarity between the current APT attack and a case from 2023 is... ;
[0176] The success rate is calculated based on historical operation data recorded by the Metaverse Operations and Maintenance module. For example, if the success rate of "port blocking" in similar scenarios is 0.9, then... ;
[0177] Purpose: To improve the operational efficiency of handling complex faults. For example, in a cross-domain attack scenario, "traffic scrubbing" is recommended. =0.7, Ps=0.8, then W=0.6×0.7+0.4×0.8=0.74; "honeypot trap" =0.5, Ps=0.6, then W=0.54. In XR scenarios, the system prioritizes "traffic cleaning" and uses brain-computer interface to predict the intentions of maintenance personnel and preload the configuration interface.
[0178] The Starlink collaborative audit module includes:
[0179] (1) Construction of the space-ground audit system: Based on the low-orbit satellite network and edge computing nodes, an integrated space-ground audit system is constructed to break through the geographical limitations of traditional audit systems; the operation logs of the metaverse operation and maintenance module are received, and the absolute time sequence calibration of cross-time zone events is achieved by combining satellite timestamps (error less than 10 nanoseconds) to ensure the consistency of the timeline of cross-border attack chains.
[0180] Time calibration is triggered by a combination of active and passive methods. Active calibration occurs every 2 hours (by pushing standard time via the satellite-to-ground link), while passive calibration is triggered when a local clock drift of ≥5ns is detected. During calibration, the edge nodes temporarily cache event logs (up to 100 entries), and re-mark them according to the corrected time after calibration is completed.
[0181] Low-Earth orbit satellite networks and edge computing nodes exchange data via satellite-to-ground links (Ka band). Satellite timestamps are provided by satellite atomic clocks, and global node time synchronization is achieved via inter-satellite links (laser communication). Absolute time sequence calibration for cross-time zone events is completed by comparing satellite timestamps with local node timestamps, combined with transmission delay compensation values. The compensation values are calculated in real time based on satellite orbit parameters.
[0182] Cross-domain event timing consistency formula:
[0183]
[0184] In the formula: This indicates time synchronization error, used to verify the timing validity of cross-border attack events. When the error exceeds the limit, satellite time calibration is triggered.
[0185] It represents satellite timestamps, using UTC standard time provided by low-Earth orbit satellite networks, with an accuracy of 1ns, and achieves time synchronization of global nodes through inter-satellite links;
[0186] This represents the local node timestamp, the time the event occurred as recorded by the network device. It may contain errors due to clock drift, such as daily drift at edge nodes. ns;
[0187] This represents the transmission delay compensation value, calculated based on satellite orbital parameters (such as altitude and azimuth), indicating the signal propagation time. For example, when the satellite zenith angle is 30°, ;
[0188] Indicates the maximum permissible error (default 10ns) to ensure intercontinental audit events (such as Southeast Asian scaffolding outsourcing). The timeline of the attack on North American data centers is unambiguous.
[0189] Function: To solve the problem of inconsistent geographical and temporal records in traditional auditing systems. For example, in a transnational attack, the Southeast Asian node recorded the time... =10:00:00.000000000, Satellite Time =10:00:00.000000050, =50ns, then The system triggers time calibration, and after correction, it ensures that the timing logic of the attack chain "packet sending → intrusion → data leakage" is traceable, providing a reliable basis for the operation time of the biometric anchoring module;
[0190] (2) Audit Mechanism and Output: The audit process adopts distributed ledger technology to synchronize the hash values of key events such as cross-border data transmission and changes in defense strategies to global nodes to ensure that the records are tamper-proof; for network attacks involving multiple countries, audit segments from different regions are retrieved through inter-satellite links to automatically splice the complete attack path, such as the penetration process from Southeast Asian jump servers to North American data centers; the audit results generate a standardized chain of evidence to provide the basis for verifying the operation permissions of the biometric anchoring module, and at the same time support the connection with international judicial evidence collection platforms;
[0191] The distributed ledger uses the Practical Byzantine Fault Tolerance (PBFT) algorithm to achieve global node consensus. The hash values of key events are synchronized to each node every 100ms. When auditing network attacks involving multiple countries, the inter-satellite links retrieve audit segments from different regions in the order of the attack time and piece together the complete attack path by associating them through event IDs.
[0192] Key events include: cross-border data transfer (single batch ≥ 10GB), changes in defense strategies (such as firewall rule modifications), handling of high-risk vulnerabilities (CVSS ≥ 9.0), and abnormal logins (non-working hours + remote IP addresses); the event hash value is calculated using SHA-384 and includes the event content, timestamp, and operator ID, and the hash result is synchronized to ledger nodes in at least 5 different regions.
[0193] The biometric anchoring module includes:
[0194] (1) Trust Root Mechanism Construction: The permission data of the Starlink Collaborative Audit Module is integrated with biometric features to construct a “human-machine” binding security mechanism; the biometric features of the operation and maintenance personnel, such as iris and brainprint, are encrypted and bound to the physical fingerprints such as the motherboard serial number and firmware hash of the managed equipment, and stored in the quantum encryption database to ensure that the associated information cannot be tampered with;
[0195] The iris features of maintenance personnel are collected by a 3-megapixel infrared camera, and 1,024 feature points are extracted, encrypted with SHA-256, and then stored. The motherboard serial number and firmware hash of the device's physical fingerprint are read through the device's BIOS interface, and form key-value pairs with the biometric encrypted data. These are stored in a chain structure of the quantum encryption database to ensure that the association cannot be tampered with.
[0196] The quantum encryption database adopts a distributed cluster (3 master and 3 slave architecture), with master nodes deployed in the core data center and slave nodes distributed in different regions (to avoid single points of failure); data is stored in shards according to 'biometric ID + device fingerprint', each shard is encrypted with AES-256, and the key is dynamically generated by the quantum key distribution module (updated every 24 hours).
[0197] Formula for validity of binding relationship:
[0198]
[0199] In the formula: This indicates the binding validity value, used to control device configuration permissions. Operations are allowed when the time is right, otherwise the interface is frozen, reflecting the core mechanism of "human-machine" binding;
[0200] This indicates the biometric matching degree, which is the result of comparing features collected by an iris scanner or EEG sensor with pre-stored templates in a quantum encryption database. For example, if the iris feature point matching rate is 98%, then... ;
[0201] This indicates the physical fingerprint matching degree of the device, which is the comparison result between the device's motherboard serial number, firmware hash, and binding record. For example, if the hash value of a certain server matches completely, then... Partial alteration ;
[0202] This indicates the permission verification result. The Starlink Collaborative Audit Module verifies operation permissions based on the distributed ledger (e.g., administrator role is 1, visitor role is 0) to ensure that "authorized personnel operate authorized devices".
[0203] Function: To build the underlying trust root of the system, for example, the iris matching score of maintenance personnel. =0.99, Device Physical Fingerprint =1.0, permissions =1, then =min(0.99, 1.0)×1=0.99≥0.95, so modifying the firewall rules is allowed; if =0.9 (equipment replaced), then =0.9×1=0.9<0.95, the system freezes the operation and triggers the quantum anchoring acquisition module to recalibrate the node identity, completely eliminating unauthorized configuration changes;
[0204] (2) Permission verification and closed-loop defense: Any configuration change operation (such as modifying firewall rules) must be verified by two verifications. The device verifies the matching degree between the biometrics of the operation initiator and the pre-stored template, and the cloud verifies the legality of the operation permission through the Starlink collaborative audit module. For abnormal operations such as unauthorized personnel access, the relevant device configuration interface is immediately frozen, and the quantum anchoring collection module is triggered to recalibrate the node identity, forming a closed-loop defense from identity authentication to permission control, and completely eliminating unauthorized internal operations and permission abuse.
[0205] In dual authentication, the device verifies the biometric matching degree through the local biometric comparison library, and the cloud queries the operation permission record through the Starlink collaborative audit module. After both are verified, a temporary operation token is generated (valid for 5 minutes). When an abnormal operation occurs, the interface is frozen and the quantum anchoring acquisition module is triggered to re-execute the node identity verification process. The freeze can only be lifted after the verification is passed.
[0206] The biometric template is automatically updated every 90 days. When updating, the maintenance personnel need to re-collect biometric features (the similarity with the original template must be ≥95% to pass the test). If a person leaves the company, the system will immediately delete their biometric data and automatically unbind them from the associated devices (the operation will be recorded in the Starlink collaborative audit module).
[0207] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0208] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A network security inspection system based on big data, characterized in that: The system includes: Quantum anchoring acquisition module: It integrates quantum key distribution and software-defined boundary technology to construct a dynamic encrypted channel, generate a quantum fingerprint bound to the physical characteristics of the device, and adopts a distributed probe to adapt to a heterogeneous network. After preprocessing, it generates a trusted data stream with a quantum signature. Twin attack and defense simulation module: Based on trusted data stream, a digital twin synchronized with the physical network in real time is constructed. Through a multi-agent reinforcement learning engine, attack and defense simulation is performed, potential attack paths are generated, and simulation results are output. The neural symbol detection module integrates neural networks and symbolic logic reasoning. It receives attack path features and converts them into symbolic rules. The neural network layer captures abnormal behavior, the symbolic reasoning layer verifies the integrity of the attack logic, and outputs marked threat information. The optical quantum response module: Based on the tagged threat information, it establishes a physical isolation channel to physically disconnect deterministic threats from the network, marks data packets of suspicious behavior, and outputs defense action data; Metaverse Operations and Maintenance Module: Integrates defense action data, constructs a three-dimensional operations and maintenance space combined with XR technology, allows operations and maintenance personnel to control virtual nodes with their thoughts, generates defense suggestions through the decision-making system, generates simulation processes for complex faults, and outputs operation logs; Starlink Collaborative Audit Module: Based on satellites and edge nodes, it builds a space-ground audit system, receives operation logs, uses satellite timestamps to calibrate cross-time zone events, stores key events in a distributed ledger, and generates a chain of evidence. Biometric Anchoring Module: Binds the biometrics of maintenance personnel to the physical fingerprints of devices. Configuration changes require dual verification. In case of abnormal operation, the interface is frozen and the node is recalibrated.
2. The network security inspection system based on big data according to claim 1, characterized in that: The quantum anchoring acquisition module includes: (1) Core technology and identity verification: Integrating quantum key distribution and software-defined boundary technology, a dynamic encrypted acquisition channel is constructed. A unique quantum fingerprint is assigned to each network node through a quantum random number generator and bound to physical characteristics including the electromagnetic radiation spectrum of the hardware chip. During acquisition, the node identity is verified in real time using the quantum entanglement property. If the fingerprint does not match, the channel is blocked. (2) Data acquisition architecture and data support: A distributed probe architecture is adopted to adapt to heterogeneous network environments including Ethernet, 5G and industrial bus; the granularity is dynamically adjusted through an adaptive sampling algorithm, and the edge nodes adopt event-triggered acquisition. After the acquired data is preprocessed including desensitization and format normalization, a trusted data stream with quantum signature is generated to provide basic data for the twin attack and defense simulation module.
3. The network security inspection system based on big data according to claim 1, characterized in that: The twin attack and defense simulation module includes: (1) Digital twin construction: Based on trusted data flow, a digital twin that is synchronized with the physical network in real time is constructed. The dynamic attributes of network topology, device status and traffic characteristics are mapped through digital thread technology to form a virtual image that replicates the operating status of the physical network. (2) Attack and defense simulation and data output: The built-in multi-agent reinforcement learning engine simulates hacker tactics based on the MITREATT&CK framework, and the defense agent simulates the system defense strategy. The two continuously engage in combat simulation in twin space; potential attack paths are automatically generated and key defense nodes are marked. For undisclosed 0-day vulnerabilities, the spread speed and damage threshold are predicted by simulation algorithm. The simulation results are synchronized to the neural symbol detection module in real time.
4. The network security inspection system based on big data according to claim 1, characterized in that: The neural symbol detection module includes: (1) Technology integration and rule transformation: Integrate neural networks and symbolic logic reasoning, receive the attack path features output by the twin attack and defense deduction module, transform them into interpretable symbolic rules, and embed them into the feature extraction layer of the deep learning model; (2) Dual-track detection and result application: The detection process adopts a dual-track parallel mechanism. The neural network layer captures abnormal behaviors, including traffic mutation and protocol malformation, through spatiotemporal features. The symbolic reasoning layer verifies the integrity of the attack logic based on expert rules. For cases with conflicting judgment results, the rule correction engine is activated to optimize the rule base. The detection results are marked with threat type and stage.
5. The network security inspection system based on big data according to claim 1, characterized in that: The optical quantum response module includes: (1) Physical layer defense architecture: Based on the threat location results of the neural symbol detection module, a light-controlled defense system is constructed. A physical isolation channel is built using an optical switch array. The network is divided into three logical domains: trusted zone, suspicious zone, and isolated zone. Data transmission between domains needs to be verified by quantum entanglement. (2) Threat handling and log synchronization: When a deterministic threat, including known ransomware, is detected, the optical switch is activated by quantum key to deflect the optical transmission path of the infected node to the isolation zone, thereby achieving physical layer network disconnection; for suspicious behaviors with unknown characteristics, including abnormal traffic, the photon silent mode is activated, and data packets are marked by optical signal modulation technology, and the execution log of the response action is synchronized to the metaverse operation and maintenance module in real time.
6. The network security inspection system based on big data according to claim 1, characterized in that: The metaverse operation and maintenance module includes: (1) Construction of Operation and Maintenance Space: Integrate the defense action data of the quantum response module to construct a three-dimensional operation and maintenance space. Through XR technology, the network topology is mapped into an interactive meta-universe scene. Traffic flows in the form of light particles, and threat events are dynamically flashed by red alarm icons. Operation and maintenance personnel wear brain-computer interface devices to enter the virtual space and control virtual nodes through their thoughts. (2) Assisted decision-making and data upload: The built-in intelligent assisted decision-making system generates defense suggestions based on historical operation and maintenance data, predicts the operation intentions of operation and maintenance personnel through EEG signals and loads relevant configuration interfaces in advance; for complex faults including cross-domain APT attacks, it generates timeline-style simulation animations to show the entire attack process, and uploads operation and maintenance records to the Starlink collaborative audit module.
7. A network security inspection system based on big data according to claim 1, characterized in that: The Starlink collaborative audit module includes: (1) Construction of the space-ground audit system: Based on the low-orbit satellite network and edge computing nodes, an integrated space-ground audit system is constructed to receive the operation logs of the meta-universe operation and maintenance module and combine the satellite timestamp to realize the absolute time sequence calibration of cross-time zone events; (2) Audit Mechanism and Result Output: The audit process adopts distributed ledger technology to synchronize the hash values of key events, including cross-border data transmission and changes in defense strategies, to global nodes. For network attacks involving multiple countries, audit segments from different regions are retrieved through inter-satellite links to automatically splice the attack path. The audit results generate a standardized evidence chain to provide the basis for verifying the operation permissions of the biometric anchoring module.
8. A network security inspection system based on big data according to claim 1, characterized in that: The biometric anchoring module includes: (1) Trust Root Mechanism Construction: The permission data of the Starlink Collaborative Audit Module is integrated with biometrics to construct a human-machine binding security mechanism. The biometrics of the operation and maintenance personnel, including iris and brainprint, are encrypted and bound to the physical fingerprints of the managed devices, including motherboard serial number and firmware hash, and stored in the quantum encryption database. (2) Permission verification and closed-loop defense: Configuration change operations must be verified by two methods. The device verifies the matching degree between the biometrics of the operation initiator and the pre-stored template, and the cloud verifies the legality of the operation permission through the Starlink collaborative audit module. For abnormal operations, including unauthorized personnel access, the relevant device configuration interface is frozen and the quantum anchoring acquisition module is triggered to recalibrate the node identity.