A ship scene-based switch and gateway cooperative security method and system

By generating a comprehensive feature matrix and a dynamic attack probability map, an adaptive defense strategy model is constructed, which solves the problems of insufficient global monitoring of the collaborative working status of switches and gateways and unified security management, and realizes dynamic, efficient and collaborative security protection of ship networks.

CN121333824BActive Publication Date: 2026-02-24SHANGHAI ZHONGCHUAN SDT-NERC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511870422.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-02-24
Estimated Expiration
2045-12-12

AI Technical Summary

Technical Problem

Existing technologies lack comprehensive monitoring of the collaborative working status of switches and gateways, fixed security policies are difficult to adapt to dynamic changes in ship networks, the ability to identify unknown threats is limited, there is a lack of coordination mechanisms between devices, and unified security management is difficult.

Method used

By generating a comprehensive feature matrix, constructing a credible threat feature vector, building a dynamic attack probability map, and inferring the diffusion path and scope of influence, collaborative security protection is achieved using an adaptive defense strategy model based on reinforcement learning.

Benefits of technology

It enables overall security situation awareness of ship networks, dynamically adjusts security strategies, improves the accuracy and response speed of threat identification, reduces the difficulty of unified security management, and enhances the collaborative protection capabilities between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333824B_ABST
    Figure CN121333824B_ABST
Patent Text Reader

Abstract

The application provides a ship scene-based switch and gateway cooperative security method and system, and relates to the technical field of ship network security. The method comprises the following steps: generating a comprehensive feature matrix according to real-time flow data of switches and gateways in a ship network; generating a threat feature vector with credibility based on the comprehensive feature matrix; constructing a dynamic attack probability atlas and inferring a diffusion path and an influence range according to the threat feature vector; and constructing a reinforcement learning-based adaptive defense strategy model based on the inference result of the dynamic attack probability atlas to realize cooperative security protection. The application significantly improves the accuracy and response speed of threat identification in the ship network, effectively shortens the control time of threat diffusion, and enhances the overall security and reliability of the ship network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of ship network security, in particular to a switch and gateway cooperative security method and system based on a ship scene. BACKGROUND

[0002] Modern ships are rapidly evolving towards intelligentization and networkization, and ship networks have become the core infrastructure for ensuring navigation safety and improving operational efficiency. Ship networks connect key devices such as navigation systems and power control systems, and also access various terminals required for daily office work and life of crew members. With the surge in external communication demand, satellite communication, wireless networks and other access methods are introduced, making ship networks interact frequently with external networks, blurring network boundaries and increasing security risks.

[0003] The closest prior art mainly focuses on the security protection of a single switch or gateway device in a ship network, and detects and filters incoming and outgoing traffic by deploying security rules on the device. For example, a port access control list is set on the switch to limit the access of devices with specific MAC addresses, and a firewall is deployed on the gateway to intercept external malicious connections according to preset port and protocol rules. In terms of structure, the security detection program mainly relies on the processor and storage unit of the device, and the security policies of each device are independently configured, lacking effective data interaction and coordination mechanism between devices. In terms of signal transmission, only the reception, detection and forwarding of traffic are performed within the device, and there is no real-time transmission of security-related information between different devices.

[0004] The existing technology mainly focuses on the protection of a single device or a local area, lacks global monitoring of the cooperative working state of switches and gateways, and fixed security policies are difficult to adapt to the dynamic changes of ship networks. It relies on static rule libraries, and has limited ability to identify unknown threats and variant attacks. The security policies of switches and gateways are independent of each other, lacking a coordination mechanism, and the protection response has a lag. Moreover, the heterogeneity of ship network devices increases the difficulty of unified security management, making it difficult to efficiently deploy and update security policies. SUMMARY

[0005] In view of the technical problems of the prior art, such as insufficient global monitoring of the cooperative working state of switches and gateways, difficulty of fixed security policies to adapt to the dynamic changes of ship networks, limited ability to identify unknown threats, lack of coordination mechanism between devices, and difficulty of unified security management, the present application provides a switch and gateway cooperative security method and system based on a ship scene, which realizes dynamic, efficient and cooperative security protection of ship networks.

[0006] To achieve the above purposes, the technical solution adopted by the present application is as follows: a switch and gateway cooperative security method based on a ship scene, the method comprising:

[0007] According to the real-time traffic data of the switches and the gateway in the ship network, a comprehensive feature matrix is generated;

[0008] Based on the comprehensive feature matrix, a threat feature vector with credibility is generated;

[0009] According to the threat feature vector, a dynamic attack probability graph is constructed and the diffusion path and the influence range are inferred;

[0010] Based on the inference result of the dynamic attack probability graph, an adaptive defense strategy model based on reinforcement learning is constructed to realize collaborative security protection.

[0011] On the other hand, the application also provides a switch and gateway collaborative security system based on a ship scene, which comprises a memory for storing computer program instructions and a processor for executing program instructions, wherein when the computer program instructions are executed by the processor, the system is triggered to execute the above-mentioned switch and gateway collaborative security method based on a ship scene.

[0012] Compared with the prior art, the application has the following beneficial effects:

[0013] The application solves the problem of insufficient global monitoring of the collaborative working state of switches and gateways in the prior art, and through the collection and analysis of real-time traffic data, realizes the overall security situation awareness of the ship network and enhances the collaborative protection capability between devices.

[0014] In view of the dynamic change characteristics of the ship network, the application can dynamically adjust the security strategy, effectively cope with unknown threats and variant attacks, improve the flexibility and response speed of security protection, and overcome the limitation that the fixed security strategy in the prior art is difficult to adapt to the dynamic change of the network.

[0015] By generating a threat feature vector with credibility, the application can more accurately identify potential threats in the network, reduce false positives and false negatives, improve the accuracy and reliability of threat identification, and solve the problem that the prior art has limited unknown threat identification capability.

[0016] Using the dynamic attack probability graph, the application can predict the diffusion path and the influence range of the attack, provide forward-looking decision support for security protection, and help to take preventive measures in advance to reduce the loss caused by the attack.

[0017] This invention achieves centralized management and efficient deployment and updating of security policies for heterogeneous devices in ship networks through a unified framework, reducing the difficulty of unified security management and improving management efficiency. Experimental verification shows that after adopting the ship-based switch and gateway collaborative security method of this invention, the accuracy of threat identification in ship networks is significantly improved, the threat propagation control time is greatly shortened, and the secure operation of ship networks is effectively guaranteed, demonstrating the superior performance of this method in practical applications.

[0018] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0019] Figure 1 This is a flowchart of a collaborative security method for switches and gateways based on a ship scenario according to the present invention;

[0020] Figure 2 This is a flowchart of the method for generating a comprehensive feature matrix according to the present invention;

[0021] Figure 3 This is a flowchart of the method for generating threat feature vectors according to the present invention;

[0022] Figure 4 This is a flowchart of the method for constructing and inferring dynamic attack probability graphs according to the present invention;

[0023] Figure 5 This is a flowchart of the method for generating and executing adaptive defense strategies according to the present invention. Detailed Implementation

[0024] To enable those skilled in the art to better understand the technical solutions of this invention, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings, so as to more clearly understand the purpose, features and advantages of this invention. It should be understood that the embodiments shown in the drawings are not intended to limit the scope of this invention, but are only for illustrating the essential spirit of the technical solutions of this invention. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this invention.

[0025] Unless the context requires otherwise, throughout the specification and claims, the word “comprising” and its variations, such as “including” and “having”, shall be understood to have an open, inclusive meaning, that is, to be interpreted as “including, but not limited to”.

[0026] Throughout this specification, references to "an embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Therefore, the appearance of "in an embodiment" or "an embodiment" in various places throughout the specification does not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic may be combined in any manner in one or more embodiments.

[0027] The singular forms “a” and “the” used in this specification and the appended claims include plural references unless otherwise expressly stated herein. It should be noted that the term “or” is generally used to mean “and / or” unless otherwise expressly stated herein.

[0028] In the following description, in order to clearly demonstrate the structure and working method of the present invention, a number of directional terms will be used. However, terms such as "front", "back", "left", "right", "outside", "inside", "outward", "inward", "up", and "down" should be understood as convenient terms and not as limiting terms.

[0029] The implementation details of the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. The following content is only for the convenience of understanding the implementation details and is not necessary for implementing this solution.

[0030] In the field of marine network security technology, although existing technologies employ a series of security protection measures for individual switches or gateway devices in marine networks, such as deploying security rules on the devices to detect and filter traffic, restricting access and blocking malicious connections by setting port access control lists and deploying firewalls, and relying on the device's own processor and storage units to run security detection programs, with each device's security policy configured independently, the increasing intelligence and networking of ships has led to increasingly complex security challenges for marine networks. Existing technologies have many significant shortcomings, such as a lack of global monitoring of the collaborative working status of switches and gateways, the inability of fixed security policies to cope with dynamic changes in marine networks, limited ability to identify unknown threats and mutated attacks relying on static rule bases, and the independent security policies of switches and gateways resulting in delayed protection responses. Furthermore, the high heterogeneity of marine network devices increases the difficulty of unified security management. Against this backdrop, to effectively solve the above-mentioned technical problems and achieve dynamic, efficient, and collaborative security protection for marine networks, this invention provides a method and system for collaborative security of switches and gateways based on marine scenarios.

[0031] Example 1

[0032] To address the aforementioned problems in existing technologies, this invention provides a collaborative security method for switches and gateways in a shipboard scenario, such as... Figure 1 As shown, the method specifically includes the following steps:

[0033] S1. Generate a comprehensive feature matrix based on the real-time traffic data of switches and gateways in the ship network.

[0034] Based on real-time traffic data from switches and gateways in the ship's network, multi-dimensional parameters of network transmission status are integrated. Switches and gateways are key devices in the ship's network, and their real-time traffic data can reflect the actual operating status of the network, providing a real and reliable data foundation for subsequent analysis.

[0035] By integrating multi-dimensional parameters of network transmission status, a comprehensive feature matrix is ​​generated, such as... Figure 2 As shown, this step specifically includes:

[0036] S1-1 Real-time traffic data preprocessing

[0037] Real-time traffic data (including packet type, source and destination addresses, port numbers, and transmission rates) collected from multiple ports of switches and gateways undergoes timestamp calibration and outlier removal. A sliding window-based multi-source data alignment mechanism is employed to eliminate port sampling frequency differences, resulting in a time-synchronized multi-source traffic sequence. This preprocessing of real-time traffic data ensures consistency in time and source, providing reliable data for accurate network status analysis.

[0038] In some examples, switches and gateways in a ship's network may be located in different places and operate independently, which can lead to discrepancies in the timestamps of the real-time traffic data they collect. This time inconsistency can severely affect subsequent analysis and correlation of network events. For example, when analyzing a network attack, if the timestamps of related data packets collected from different ports are inaccurate, it is impossible to accurately reconstruct the attack's initiation time, propagation path, and scope of impact, making it difficult to formulate effective defense strategies. To solve this problem, high-precision time synchronization technology can be used to calibrate the timestamps of all collected real-time traffic data. Specifically, a high-precision time synchronization server is deployed in the ship's network. This server obtains accurate time information through the Global Positioning System (GPS) or other high-precision time sources and uses it as a reference time. After collecting real-time traffic data, switches and gateways communicate with the time synchronization server to correct their collected timestamps to be consistent with the reference time, thereby ensuring that all collected real-time traffic data has a high degree of consistency and accuracy in the time dimension.

[0039] In some examples, during the actual operation of ship networks, various factors such as equipment failure, network interference, and malicious attacks may lead to outliers in the collected real-time traffic data. These outliers may deviate from the normal data distribution range, severely interfering with subsequent data analysis and model training, resulting in inaccurate analysis results or degraded model performance. To effectively remove these outliers, this invention employs a method combining statistical analysis and machine learning. First, statistical analysis is performed on the collected real-time traffic data, calculating its mean, standard deviation, and other statistics, and determining the distribution range of normal data based on the principle of normal distribution. Data exceeding this distribution range is marked as potential outliers. Then, machine learning algorithms, such as Isolation Forest, are used to further analyze and judge these potential outliers. The Isolation Forest algorithm constructs isolated trees by randomly partitioning the feature space. Because outliers differ from the normal data distribution, they are usually isolated within a fewer partitions and thus identified as outliers. This method can accurately and efficiently remove outliers from real-time traffic data, improving data quality and reliability.

[0040] In some examples, the sampling frequencies of different ports on switches and gateways may differ due to factors such as device performance and network load when collecting real-time traffic data. This difference in sampling frequency causes the data collected from different ports to be out of sync in time, making subsequent data fusion and analysis difficult. For example, when performing network traffic trend analysis, if the data from different ports are not synchronized in time, it is impossible to accurately calculate the total traffic within a certain time period, thus affecting the judgment of the network operating status. To eliminate the port sampling frequency difference and achieve time alignment of multi-source data, we adopt a multi-source data alignment mechanism based on a sliding window. The specific steps are as follows:

[0041] (1) Determine the sliding window size: Select an appropriate sliding window size based on the actual operation of the ship network and the frequency of data acquisition. The selection of the sliding window size needs to take into account the real-time and accuracy requirements of the data. If the window is too large, it may cause delays in data alignment, while if the window is too small, it may increase the computational complexity.

[0042] (2) Data Buffering and Alignment: Real-time traffic data collected from different ports are stored in different buffers. Then, using the data from one port as a baseline, data from other ports are searched within its corresponding time range using a sliding window method. For data from other ports found within the sliding window, they are aligned with the baseline port data; for data not found within the sliding window, interpolation is performed using a certain interpolation algorithm to fill in the missing data.

[0043] (3) Dynamic adjustment and optimization: In actual operation, the port sampling frequency may change dynamically due to changes in the network environment and fluctuations in equipment status. Therefore, it is necessary to monitor the sampling frequency of each port in real time and dynamically adjust the size of the sliding window and the parameters of the interpolation algorithm according to the monitoring results to ensure that the multi-source data can always maintain accurate time alignment.

[0044] S1-2, Feature Extraction and Screening

[0045] Protocol parsing is performed on real-time traffic data collected from multiple ports to extract header field information from the transport and network layers, and a protocol feature library containing protocol type, TTL value and checksum is established. A feature selection algorithm based on information gain is used to select key protocol features from the protocol feature library that contribute more than a preset threshold to threat identification. The selected key protocol features are then concatenated with the original traffic data to form a fused dataset.

[0046] In some examples, real-time traffic data collected from multiple ports contains multiple network packets transmitted according to a certain protocol. Protocol parsing aims to dissect these packets and extract information from the transport and network layer header fields, which is crucial for understanding the nature of network communication and identifying potential threats. The transport layer is responsible for end-to-end communication, commonly using TCP and UDP protocols. TCP header fields include source / destination port numbers, sequence numbers, acknowledgment numbers, window size, and flags; parsing these reveals connection status and data transmission reliability. UDP header fields include source / destination port numbers, length, and checksum, suitable for scenarios with high real-time requirements and low reliability requirements; parsing provides basic port and data integrity verification information. The network layer is responsible for transmitting packets from the source host to the destination host; the IP protocol is central. IP header fields include version, header length, differentiated services, total length, identifiers, flags, fragment offset, time-to-live (TTL), protocol, header checksum, source IP address, and destination IP address. The Time-To-Live (TTL) value limits the lifespan of a data packet in the network. The TTL value is decremented by 1 with each router it passes through. When the TTL value reaches 0, the packet is discarded. This effectively prevents packets from looping indefinitely through the network. The header checksum is used to detect errors in the IP header during transmission. By parsing these fields, information such as the packet's transmission path, priority, integrity, and the transport layer protocol used can be obtained.

[0047] In some examples, the transport layer and network layer header field information extracted through the above protocol parsing is rather scattered. To facilitate subsequent feature selection and analysis, this information is integrated into a unified protocol feature library. The protocol feature library is a structured data collection that stores protocol features extracted from multiple data packets according to certain rules and formats.

[0048] In the protocol signature database, features are categorized and stored according to their type and function. For example, port-related features (source port number, destination port number) can be stored in one category, connection-state-related features (TCP flags) in another, and packet transmission path-related features (source IP address, destination IP address, TTL value) in yet another. This categorized storage method helps improve the management efficiency and query speed of the protocol signature database. Furthermore, as the network environment changes and new network protocols emerge, the protocol signature database needs continuous updating and maintenance to ensure its effectiveness and usability.

[0049] In some examples, the protocol feature library contains a large number of protocol features, but not all features are equally important for threat identification. To improve the efficiency and accuracy of threat identification, an information gain-based feature selection algorithm is used to filter key features from the protocol feature library whose contribution to threat identification is higher than a preset threshold. Information gain is an indicator used to measure the degree of influence of a feature on the classification result. It assesses the importance of a feature by calculating the change in information entropy when the feature is present or absent. Information entropy is an indicator of information uncertainty. For a classification problem, the lower the information entropy, the lower the uncertainty of the data, and the better the classification effect. When a feature is added to the classification model, if it can significantly reduce the information entropy, it indicates that the feature has a significant impact on the classification result, i.e., it has high information gain.

[0050] Key features contributing more than a preset threshold to threat identification are selected from the protocol feature library. This process involves: First, calculating the information gain of each feature in the library. For each feature, its value is used as a partitioning criterion to divide the dataset into multiple subsets. Then, the information entropy of each subset and the weighted average information entropy after partitioning are calculated. The information gain equals the information entropy of the original dataset minus the weighted average information entropy after partitioning. Next, features are sorted in descending order of their calculated information gain values. Finally, features with information gain values ​​higher than a preset threshold are selected as key features. These key features can more effectively reflect anomalies in network traffic and are of significant value for threat identification.

[0051] In some examples, the filtered key protocol features are concatenated with the original traffic data to combine key protocol-level information with basic traffic statistics, forming a more comprehensive and richer fused dataset. This fused dataset can describe network transmission status from multiple perspectives, providing stronger support for subsequent network threat identification. Feature concatenation can be performed in various ways, such as horizontal concatenation and vertical concatenation. Horizontal concatenation adds key protocol features as new columns to the original traffic data table, so that each row contains both original traffic statistics (such as packet type, transmission rate, etc.) and key protocol-level features (such as protocol type, TTL value, etc.). Vertical concatenation combines data with different features according to certain rules to form a new feature vector. This embodiment uses horizontal concatenation because it maintains a clear data structure, facilitating subsequent processing and analysis.

[0052] The fused dataset combines basic information from the original traffic data with deeper information from key protocol features, improving the richness and completeness of the data and enabling a more comprehensive reflection of network transmission status. It also enhances the expressive power of features, making the correlations between different features more obvious, which helps to discover potential network threats. Furthermore, it provides higher-quality data input for subsequent model training and threat identification, thereby improving the accuracy and reliability of the model.

[0053] Through the above operations of protocol parsing, establishing a protocol feature library, feature selection, and feature concatenation of real-time traffic data collected from multiple ports, a fused dataset was formed, laying a solid foundation for the subsequent generation of a comprehensive feature matrix.

[0054] S1-3, Preliminary Comprehensive Feature Representation

[0055] The multi-source traffic sequences are input into a deep belief network. The data layer uses a restricted Boltzmann machine to capture the low-level features of the traffic data, and the feature layer uses a greedy layer-by-layer training algorithm to extract high-level abstract features, thus obtaining a preliminary comprehensive feature representation.

[0056] Specifically, the time-synchronized multi-source traffic sequences obtained through preprocessing are first input into a deep belief network (DBN). A powerful deep learning model, the DBN consists of multiple stacked Restricted Boltzmann Machines (RBMs) and can automatically learn different levels of feature representations from the raw data. At the data layer, a Restricted Boltzmann Machine is used to capture the low-level features of the traffic data. A Restricted Boltzmann Machine is a two-layer neural network containing visible and hidden layers, with fully connected neurons between layers and no connections within layers. Through unsupervised learning on the input multi-source traffic sequence data, it can uncover hidden low-level patterns and structural information in the data, such as the basic distribution patterns of data packets and the preliminary correlation features between traffic flows across different ports. These low-level features are the most fundamental feature representations of the traffic data, laying the foundation for the extraction of subsequent higher-level features.

[0057] Next, a greedy layer-by-layer training algorithm is applied to the feature layer to extract high-level abstract features. The greedy layer-by-layer training algorithm is an effective deep learning training strategy. It employs a layer-by-layer training approach: first, the first layer of the Restricted Boltzmann Machine (RBM) is trained; then, the output of its hidden layers is used as the input to the second layer, and so on, training upwards layer by layer. In this way, each layer learns more complex and abstract features based on the previous layer. For example, after the low-level feature extraction from the data layer, the feature layer can further mine high-level features related to network attack behavior in the traffic data, such as abnormal traffic patterns and unique feature combinations exhibited by specific types of attacks. These high-level abstract features can more accurately reflect the essential characteristics of network transmission status and have higher value for subsequent threat identification.

[0058] After processing at the data and feature layers, a preliminary comprehensive feature representation is obtained. This preliminary comprehensive feature representation integrates multiple feature information from the bottom to the top layers, including both the basic statistical features of traffic data and abstract features closely related to network threats. This provides strong support for the subsequent generation of a more comprehensive and accurate comprehensive feature matrix, thus enabling it to be more effectively used for threat detection and identification in the collaborative security protection of switches and gateways in ship networks.

[0059] S1-4, Weighted Integration Features

[0060] By using association rule mining algorithms, the correlation coefficients between data from different ports are calculated. Based on the coefficients, the preliminary comprehensive features are weighted and integrated to highlight the role of key port data in threat identification, resulting in a weighted comprehensive feature representation.

[0061] Association rule mining is a data mining technique that can discover associations and correlations between items in large amounts of data. In the ship network scenario of this invention, it is applied to the processing of preliminary comprehensive feature representation, aiming to deeply explore the intrinsic connections between data from different ports. Specifically, the association rule mining algorithm is first used to calculate the correlation coefficient between data from different ports. This algorithm traverses the entire dataset corresponding to the preliminary comprehensive feature representation, analyzing the frequency and patterns of simultaneous occurrence or occurrence of data from various ports in traffic transmission. Through complex statistical analysis and pattern matching, a correlation coefficient is calculated for each pair of port data. The magnitude of this coefficient reflects the degree of correlation between the two pairs of port data. For example, if the data from two ports frequently exhibit abnormal changes simultaneously under normal network communication and potential threat scenarios, their correlation coefficient will be high; conversely, if the changes in the data from two ports are independent, their correlation coefficient will be low.

[0062] After obtaining the correlation coefficients between data from different ports, the features in the preliminary comprehensive feature representation are weighted and integrated based on these coefficients. The purpose of weighted integration is to highlight the role of key port data in threat identification. In ship networks, certain ports may have higher value for threat identification due to their important communication tasks or their greater vulnerability to attack. By weighting the correlation coefficients, the features corresponding to these key port data can be strengthened in the comprehensive feature representation. Specifically, each feature is multiplied by its correlation coefficient with the corresponding port data to obtain the weighted feature value. In this way, the features corresponding to port data with high correlation coefficients will have a greater weight in the comprehensive feature representation, thus playing a more important role in the subsequent threat identification process.

[0063] After calculation and weighted integration by the association rule mining algorithm, a weighted comprehensive feature representation is finally obtained. This weighted comprehensive feature representation not only includes multi-dimensional information of the original traffic data and protocol features, but also highlights the role of key port data through association analysis. It can more comprehensively and accurately reflect the transmission status and potential threats of switches and gateways in the ship network, providing stronger support for subsequent threat identification and security protection.

[0064] S1-5. Generate a low-dimensional comprehensive feature matrix

[0065] The weighted composite features are input into the principal component analysis model to calculate the covariance matrix. The Jacobi iteration method is used to solve for the eigenvalues ​​and eigenvectors of the covariance matrix. The number of principal components is determined based on the contribution rate of the eigenvalues. The weighted composite features and the feature transformation matrix are multiplied together. Dimensionality is reduced by linear transformation to remove redundant features and retain core information, generating a low-dimensional composite feature matrix containing information on data packet type, source and destination addresses, port numbers, and transmission rates.

[0066] After obtaining the weighted comprehensive feature representation, to further optimize the feature data and improve the efficiency and accuracy of subsequent safety analysis, principal component analysis (PCA) is used to reduce the dimensionality of the weighted comprehensive features, generating a low-dimensional comprehensive feature matrix. PCA is a commonly used data dimensionality reduction technique. Its core objective is to reduce the dimensionality of the data and remove redundant features while preserving as much original data information as possible, thereby reducing computational complexity and improving data interpretability. In the ship network scenario of this invention, although the weighted comprehensive features have undergone a series of processing steps, they may still have high data dimensionality and correlations between some features. These problems increase the computational burden of subsequent safety analysis and may even affect the accuracy of the analysis results. Therefore, using PCA for dimensionality reduction is essential.

[0067] Specifically, the weighted composite features are first input into the principal component analysis model. The first step of the model is to calculate the covariance matrix. The covariance matrix describes the correlation between features. By calculating the covariance between each feature and other features, a matrix reflecting the degree of correlation between features can be obtained. The calculation of the covariance matrix is ​​based on the weighted composite feature data, taking into account the changing trends and mutual influences between different features.

[0068] After obtaining the covariance matrix, the Jacobi iteration method is used to solve for its eigenvalues ​​and eigenvectors. The Jacobi iteration method is an efficient numerical computation method that iteratively updates the matrix elements, gradually transforming the covariance matrix into a diagonal matrix, thereby obtaining its eigenvalues ​​and corresponding eigenvectors. The eigenvalues ​​reflect the amount of information contained in each principal component, while the eigenvectors determine the direction of the principal components.

[0069] Next, the number of principal components is determined based on the contribution rate of the eigenvalues. The contribution rate refers to the proportion of information contained in the eigenvector corresponding to each eigenvalue relative to the total information. By calculating the contribution rate of each eigenvalue and sorting them in descending order, the eigenvectors corresponding to the top few eigenvalues ​​whose cumulative contribution rate reaches a certain threshold (e.g., 85%-95%) are selected as principal components. This effectively reduces the dimensionality of the data while retaining most of the core information.

[0070] After determining the number of principal components, the weighted composite features are multiplied by the feature transformation matrix. The feature transformation matrix is ​​a matrix composed of the eigenvectors corresponding to the selected principal components. Through matrix multiplication, the original high-dimensional weighted composite features can be mapped to a low-dimensional space, completing the linear transformation dimensionality reduction process.

[0071] After the linear transformation and dimensionality reduction processes described above, redundant features in the weighted composite features were successfully removed, while core information was retained. This resulted in a low-dimensional composite feature matrix containing packet type, source and destination addresses, port numbers, and transmission rates. This low-dimensional composite feature matrix not only has lower dimensionality, facilitating subsequent calculations and analysis, but also accurately reflects the transmission status and potential threats of switches and gateways in the ship's network, providing strong data support for subsequent threat identification, security assessment, and decision-making.

[0072] Step S1 collects real-time traffic data from switches and gateways, integrates multi-dimensional parameters to generate a comprehensive feature matrix, and can fully capture subtle changes in network transmission, breaking through the limitations of traditional single-indicator monitoring and covering a variety of potential threat signs.

[0073] S2. Based on the comprehensive feature matrix, generate a threat feature vector with credibility. For example... Figure 3 As shown, this step specifically includes:

[0074] S2-1. Input the comprehensive feature matrix into the stacked autoencoder to obtain the deep feature representation.

[0075] Using the comprehensive feature matrix as input data, a hierarchical Bayesian model is introduced. This model possesses a hierarchical structure and probabilistic reasoning capabilities, enabling statistical modeling of abnormal patterns in network transmission states. It can analyze data from different levels to identify complex anomaly patterns in the comprehensive feature matrix, such as anomaly correlations between different network layers and the changing trends of anomaly patterns over time.

[0076] To further extract deeper information from the comprehensive feature matrix, it is input into a stacked autoencoder. The stacked autoencoder, through a multi-layered nonlinear mapping mechanism, progressively transforms the original features into a latent variable space. In this process, each layer employs sparse regularization constraints. These constraints encourage the model to learn more representative and sparse feature representations, avoiding overfitting and interference from redundant information, ultimately yielding deep feature representations. Compared to the original features, these deep feature representations more accurately characterize the essential features of network transmission.

[0077] S2-2. After constructing a probability model, preliminary statistical characteristic representations are obtained.

[0078] Based on the obtained deep feature representations, a probabilistic model based on Naive Bayes is constructed. Considering that network transmission states contain both discrete features, such as network protocol type and data packet type, and continuous features, such as data packet size and transmission time interval, a hybrid model combining multinomial and Gaussian distributions is adopted. This hybrid model fully leverages the advantages of both distributions, accurately modeling both discrete and continuous features respectively, thereby capturing the inherent patterns of discrete and continuous features in network transmission states and obtaining preliminary statistical feature representations. These preliminary statistical feature representations provide a quantitative description of network transmission states from a probabilistic perspective.

[0079] S2-3. Estimate the uncertainty and obtain the statistical characteristic distribution with confidence range.

[0080] Based on the preliminary statistical feature representation, the posterior probability and likelihood value of each feature point are calculated. The posterior probability reflects the probability that a feature point belongs to a certain state given the observed data; the likelihood value measures the probability of the observed data being in a given feature point state. Using the Markov chain Monte Carlo algorithm, the uncertainty of the model is estimated. Random sampling is performed in a complex probability space, and through the analysis of a large number of samples, the uncertainty of the model is accurately estimated, thus obtaining a statistical feature distribution with confidence range. This statistical feature distribution with confidence range not only provides the statistical feature values ​​of the feature points but also clarifies the reliability of these feature values, providing comprehensive and reliable information for subsequent anomaly detection.

[0081] S2-4. Detect anomaly scores and filter out anomalous feature points to generate threat feature vectors.

[0082] To more accurately detect anomalies in network transmission, the statistical feature distribution is divided into multiple feature subsets, each corresponding to different time periods of network transmission. Network transmission states may differ across time periods; for example, network traffic and anomaly patterns may vary between peak and off-peak hours. A parallel isolated forest algorithm is used to independently train each subset, generating multiple anomaly detection base models. This algorithm is efficient and accurate, quickly identifying anomalous feature points in each subset. Then, a stacking ensemble learning strategy is employed to weight and fuse the anomaly scores output by each base model. The weight coefficients are dynamically adjusted based on the number of samples in each time period, with larger weights for periods with more samples and smaller weights for periods with fewer samples. This ensures that the importance of data from different time periods is fully considered, resulting in a comprehensive anomaly score. Finally, an adaptive threshold algorithm is used to determine a dynamic threshold based on the distribution characteristics of the comprehensive anomaly score, replacing the preset confidence threshold. The dynamic threshold automatically adjusts according to the actual data distribution, offering greater flexibility and accuracy. By comparing the dynamic threshold with the overall score, anomaly feature points are selected, ultimately generating a threat feature vector with confidence level. These credible threat feature vectors can clearly indicate potential threats in network transmissions and their credibility, providing strong decision support for network security managers.

[0083] This step processes the comprehensive feature matrix using a hierarchical Bayesian model, which can deeply analyze network anomaly patterns and generate credible threat feature vectors to help managers identify the true extent of threats and avoid wasting protection resources.

[0084] S3. Based on the threat feature vector, construct a dynamic attack probability map and infer the diffusion path and scope of impact. For example... Figure 4 As shown, this step specifically includes:

[0085] S3-1. Map the threat feature vector to physical nodes to generate a preliminary dynamic attack probability map.

[0086] First, based on the threat feature vector with credibility generated in step S2, and combined with the actual topological connections of the ship network, each threat feature point is accurately mapped to the physical node coordinates of the network. Then, Bayesian estimation is used to perform probability interpolation on the discrete threat feature points, thereby generating a preliminary dynamic attack probability map. This map can initially present the distribution of the probability of attacks on each node in the network.

[0087] S3-2. The preliminary dynamic attack probability map is dynamically corrected to obtain a dynamic attack probability map that evolves over time.

[0088] However, the ship network environment is complex and ever-changing, and attack patterns also change over time. Therefore, it is necessary to further dynamically revise the initially generated dynamic attack probability map. Here, we combine time series information, adopt a Hidden Markov Model, and fully refer to historical attack diffusion data. Based on the evolution of network states at different times and the patterns of historical attack modes, we dynamically adjust the attack probability map to accurately reflect the dynamic attack probability situation evolving over time, resulting in a more timely and accurate dynamic attack probability map. The Hidden Markov Model used is a statistical model based on the Markov property (i.e., the probability distribution of the next state of the system depends only on the current state and is independent of past states). It describes the dynamic evolution of the system between different states through a state transition probability matrix and is often used to model, predict, and analyze stochastic processes with no aftereffects.

[0089] S3-3. Construct a probabilistic graphical model based on a dynamic attack probability graph that evolves over time.

[0090] After obtaining the dynamic attack probability map that evolves over time, it is input into a Bayesian network. A probabilistic graphical model is constructed based on the topology of the ship network. In this model, nodes represent critical interfaces of network devices, and edges represent data transmission paths. Utilizing the structure and characteristics of the probabilistic graphical model, a conditional probability table is constructed to accurately capture the attack propagation dependencies between nodes. The conditional probability table describes the probability that other related nodes will be attacked if a certain node is attacked, thus obtaining an initial inference of attack propagation. This initial inference is presented in the form of an attack probability map, initially revealing the direction of attack propagation in the network and the range of nodes that may be affected. For example, if a server interface node is attacked, the probability that the connected switch interface nodes will be attacked can be inferred from the conditional probability table, thus reflecting the possible propagation paths of the attack on the attack probability map.

[0091] S3-4. Predict diffusion paths based on state-space models.

[0092] To more accurately predict the spread path and impact range of attacks, the attack probability map in the initial inference results is converted into a state-space model. The state vector encompasses key information such as the attack node location, spread rate, and impact intensity, while the observation vector is the real-time threat feature vector. A Kalman filter algorithm is used to recursively estimate the state vector, and through iterative calculations, the mean and covariance matrix of the attack state at the next time step are predicted. Simultaneously, the statistical characteristics of process noise and observation noise are fully considered to optimize the prediction accuracy, making the prediction results more reliable. The state-space model is a mathematical framework describing the dynamic behavior of a system. It models the system's evolution process by defining the system's states, inputs, outputs, and the dynamic relationships between them. In the scenario of ship network attack prediction, the state-space model is used to describe the dynamic propagation of attacks in the network, including how the attack spreads from one node to other nodes, the speed of spread, and the degree of impact. Both the state vector and the observation vector are important components of the state-space model, working together within the model's framework to achieve accurate prediction of the attack state.

[0093] Furthermore, the state vector encompasses crucial information describing the internal state of the system. In ship network attack prediction, the state vector includes key information such as the location of the attacking node, the spread rate, and the intensity of its impact. This information comprehensively reflects the current state of the attack. For example, the location of the attacking node clarifies the source or current active point of the attack; the spread rate reflects how fast the attack propagates in the network; and the intensity of its impact indicates the extent of damage caused to network devices. The state vector is the foundation for state estimation and prediction in state-space models. State-space models track the evolution of the attack state through recursive estimation of the state vector. When recursively estimating the state vector using the Kalman filter algorithm, the state vector at the next moment is predicted based on the current state vector and the dynamic characteristics of the system. For example, if the location and spread rate of the attacking node at the current moment are known, combined with the network topology and attack propagation patterns, the possible node locations and spread rates of the attack at the next moment can be predicted.

[0094] Furthermore, the observation vector is an information vector obtained from outside the system in the state-space model. In ship network attack prediction, it is defined as a real-time threat feature vector. These feature vectors contain various attack-related information monitored in real time in the network, such as abnormal traffic patterns, the frequency of specific types of attack packets, and abnormal device behavior. The observation vector provides indirect information about the actual state of the system and is an important way for the model to understand the external attack situation. Since the estimation of the state vector may have errors, while the observation vector reflects the actual observation of the system, by comparing the observation vector with the predicted value of the state vector, the Kalman filter algorithm can be used to update and correct the state vector, thereby improving the accuracy of the prediction. For example, if the observation vector shows that a node has an abnormal traffic pattern, but the current state vector estimate does not consider that node to be under attack, then the state vector can be adjusted based on the information in the observation vector to make it more consistent with the actual situation.

[0095] S3-5, Generate diffusion prediction results.

[0096] Finally, reasonable attack propagation cessation conditions are set. The prediction process is immediately terminated when the predicted attack probability falls below a pre-set minimum threat threshold, or when the propagation path reaches the network boundary. At this point, the attack propagation path and its impact range within a finite time window are output, generating a complete and accurate dynamic attack probability map propagation prediction result, providing strong decision-making support for the security protection of ship networks.

[0097] S4. Based on the inference results of the attack probability graph, an adaptive defense strategy generation model based on reinforcement learning needs to be constructed to achieve collaborative security protection.

[0098] In implementing collaborative security protection between switches and gateways in a shipboard scenario, an adaptive defense strategy generation model based on reinforcement learning needs to be constructed to address the propagation prediction results of attack probability maps. This model dynamically generates multi-level defense rules that change with network transmission states through continuous interaction between a normal behavior simulator and a real-time attack identifier. Based on the matching results of real-time threat characteristics and defense rules, it achieves efficient collaborative security protection. Figure 5 As shown, this step specifically includes:

[0099] S4-1, Training a normal behavior simulator.

[0100] Specifically, a normal behavior simulator based on reinforcement learning is first trained using historical normal transmission data. This simulator employs a deep deterministic policy gradient algorithm, which combines the feature extraction capabilities of deep neural networks with the advantages of deterministic policy gradients in processing continuous action spaces. During training, the simulator treats the normal transmission state of the ship network as an environment, and the simulator itself acts as an agent interacting with the environment. Based on the current network state (such as current traffic characteristics, device connection status, etc.), the agent generates corresponding actions (i.e., generates simulated traffic) through a deep neural network. The environment provides corresponding rewards or penalties based on the agent's actions. Through continuous trial and error and learning, the agent gradually adjusts its strategy, ensuring that the generated simulated traffic closely resembles real normal ship network transmission traffic, providing a reliable benchmark for subsequent attack identification.

[0101] S4-2, Build a real-time attack identifier.

[0102] A real-time attack identifier based on a convolutional neural network is constructed. The identifier takes as input the diffusion prediction results of the attack probability map and normal behavior data generated by the simulator. Through continuous interactive learning, it accurately captures the boundary features between normal and abnormal states and outputs the identification results and their credibility, providing a key basis for the formulation of defense strategies.

[0103] S4-3, Generate multi-level defense rules.

[0104] Based on the output of the real-time attack identifier, a density clustering algorithm is used to divide the identification results into multiple levels. Combined with the dynamic changes in the attack probability map, multi-level defense rules are generated that adjust in real time according to network transmission status, including but not limited to warning, blocking, and isolation levels. These rules are dynamically adjusted according to the severity and spread trend of the threat to ensure the targeting and effectiveness of the defense measures. The density clustering algorithm, in particular, automatically divides data points into clusters based on their density distribution, without requiring a pre-specified number of clusters, making it suitable for handling non-spherically distributed abnormal data.

[0105] In some examples, based on density clustering results, abnormal traffic is divided into three initial levels: low risk, medium risk, and high risk, corresponding to candidate sets of rules for warning level, blocking level, and isolation level.

[0106] The classification is based on the average anomaly score within each cluster. In the formula, C For clusters, S i For the first i Abnormal scores at each point;

[0107] Cluster density: In the formula, Area represents the coverage area of ​​the cluster in the feature space;

[0108] Dynamically adjust thresholds: Based on historical attack data statistics, set score thresholds for low-risk, medium-risk, and high-risk attacks as follows: θ 1, θ 2, θ 3, and θ 1< θ 2< θ 3 (e.g.) θ 1 = 0.3, θ 2 = 0.6, θ (3=0.9), these values ​​can be flexibly adjusted according to the actual operation of the ship network, security requirements, and historical threat characteristics. The basis for setting this value is the statistical analysis of historical attack data of the ship network, combined with the collaborative protection capabilities of switches and gateways, and the degree of impact caused by threats. θ The setting of 1=0.3 corresponds to the score range of minor anomalies in historical data that have little impact on network operation and can be handled with just an early warning. These anomalies usually do not spread to critical equipment and can be prevented through real-time monitoring. θ The setting of 2=0.6 takes into account the historical scores of medium threat characteristics that may cause congestion on some non-critical ports and require blocking related traffic. If such threats are not intervened in time, they may affect non-core network services such as crew office work, and traffic transmission needs to be restricted through the cooperation of switches and gateways. θ The threshold of 3=0.9 represents a score indicating a high-risk threat that has historically caused serious consequences such as communication disruptions and data breaches affecting critical equipment. These threats spread rapidly and have a wide impact, requiring immediate isolation measures to prevent jeopardy of ship navigation safety. In actual operation, the threshold needs to be dynamically adjusted based on the attack probability map. For example, if the map shows a threat trending towards critical nodes, the corresponding threshold can be appropriately lowered to trigger defensive measures earlier. If the map shows a threat confined to non-core areas with no signs of spread, the threshold can be appropriately increased to avoid excessive defense consuming system resources.

[0109] Based on the above classification criteria, the anomaly level classification function is expressed as follows:

[0110]

[0111] In the formula, , These are the minimum density threshold and the maximum density threshold, respectively.

[0112] S4-4, Matching multi-level defense rules.

[0113] To ensure accurate matching of real-time threat features to multi-level defense rules, a dynamically optimized defense rule matching degree calculation model needs to be constructed. This model first extracts real-time threat features from multi-dimensional data sources, covering numerical attributes (such as attack frequency and traffic volume) and categorical attributes (such as threat level and attack type), and eliminates dimensional differences through normalization. Then, it semantically aligns the attribute parameters of the threat features with the condition terms of the multi-level defense rules. For numerical attributes, range mapping or threshold segmentation is used to achieve semantic approximate matching (e.g., dividing attack frequency into low, medium, and high intervals and calculating interval similarity). For categorical attributes, the matching degree is measured through hierarchical relationships or semantic associations (e.g., the similarity between "high-risk" and "medium-risk"). The model calculates the similarity (higher than "high-risk" and "low-risk") and generates a matching score matrix containing all threat features and rule combinations. Based on this, the model uses a weighted voting method for decision-making, where the weight of each rule is dynamically determined by its historical effectiveness probability. By statistically analyzing the ratio of the number of successful triggers of a rule in past defense cycles to the total number of triggers, rules with stable historical performance and high effectiveness probability are prioritized. At the same time, the weights are dynamically adjusted based on the severity of the real-time threat (e.g., assigning higher decision weights to high-threat features). Finally, through a closed-loop mechanism of "matching degree calculation - dynamic weight update - optimal rule selection", the model achieves accurate matching and adaptive optimization of defense rules, significantly improving the accuracy and response efficiency of the defense system.

[0114] S4-5. Execute the corresponding defense operations based on the defense level of the optimal matching rule.

[0115] Based on the defense level of the optimal matching rules, the collaborative interface between the switch and gateway is invoked to execute corresponding defense operations, such as port traffic limiting, packet redirection, or session blocking. Simultaneously, operation logs are recorded for subsequent rule optimization, forming a closed-loop defense system. Through these measures, efficient collaborative security protection between the switch and gateway in a shipboard scenario is achieved, effectively addressing dynamic threats and complex attacks in shipboard networks.

[0116] This embodiment provides a collaborative security method for switches and gateways in a ship-based scenario. The method collects and processes real-time traffic data from switches and gateways to generate a comprehensive feature matrix, then constructs a credible threat feature vector, and builds a dynamic attack probability map based on these vectors to infer attack paths and impact ranges. Finally, an adaptive defense strategy is generated through a reinforcement learning model to achieve efficient collaborative security protection for ship networks.

[0117] Example 2

[0118] Taking a cargo ship's network as an example, the network includes multiple switches and gateways, connecting the navigation system, power control system, and crew office terminals, etc.

[0119] In practical application of this method, the real-time traffic data of the switch and gateway is first collected according to the steps, including packet type, source and destination addresses, port numbers, and transmission rates. This data is then timestamped and outlier removed. A sliding window mechanism is used to align multi-source data, resulting in a time-synchronized multi-source traffic sequence. Next, this data is input into a deep belief network to extract features. Association rule mining algorithms are used to calculate the correlation coefficients of data from different ports, which are then weighted and integrated. Finally, principal component analysis is performed to reduce dimensionality and generate a comprehensive feature matrix.

[0120] The comprehensive feature matrix is ​​input into a hierarchical Bayesian model, and a deep feature representation is obtained through a stacked autoencoder. A Naive Bayesian probabilistic model is then constructed. Uncertainty is estimated using a Markov chain Monte Carlo algorithm, and anomaly scores are detected and filtered using an isolation forest algorithm to generate a threat feature vector with credibility. For example, when a large number of abnormal data packets appear on a certain port, the model will calculate the probability and credibility of it belonging to an attack behavior.

[0121] Based on threat feature vectors and the ship network topology, threat feature points are mapped to physical nodes. Bayesian estimation is used for probability interpolation to generate a preliminary dynamic attack probability map, which is then dynamically corrected using time-series information and a Hidden Markov Model. The corrected map is input into a Bayesian network to construct a probabilistic graphical model, and a Kalman filter algorithm is used to predict the attack propagation path and impact range. If the map indicates that an attack may propagate from a certain switch port to the power control system gateway, traffic restrictions can be implemented on that link in advance.

[0122] Then, a normal behavior simulator is trained based on historical normal transmission data to generate simulated traffic; a real-time attack identifier is built, which learns the boundary features between normal and abnormal states through interaction with the simulator. Density clustering algorithm is used to segment the identification results, and multi-level defense rules are generated by dynamically changing the attack probability map. When a clear attack characteristic is identified, the switch and gateway work together to block attacks at multiple nodes. For example, if the gateway identifies an external malicious IP, it immediately notifies the switch to update the forwarding rules and reject all data packets from that IP, achieving collaborative security protection.

[0123] The present invention also provides a collaborative security system for switches and gateways based on a ship scenario. The system includes a memory for storing computer program instructions and a processor for executing the program instructions. When the computer program instructions are executed by the processor, the system is triggered to execute the aforementioned collaborative security method for switches and gateways based on a ship scenario.

[0124] This invention provides a collaborative security method and system for switches and gateways in shipboard scenarios, aiming to address the security challenges faced in the intelligent and networked development of modern ship networks. The method collects and analyzes real-time traffic data from switches and gateways, utilizing deep learning, association rule mining, and principal component analysis to generate a comprehensive feature matrix, thereby constructing a credible threat feature vector. Based on these vectors, the method further constructs a dynamic attack probability map, predicts attack propagation paths and impact ranges, and dynamically generates multi-level defense rules through a reinforcement learning model, achieving efficient collaborative security protection between switches and gateways. The system executes relevant program instructions through memory and a processor to trigger the implementation of the aforementioned security method. This invention significantly improves the accuracy and response speed of threat identification in shipboard networks, effectively shortens the control time for threat propagation, and enhances the overall security and reliability of shipboard networks.

[0125] Although the present invention has been described in detail with reference to the accompanying drawings and preferred embodiments, the invention is not limited thereto. Various equivalent modifications or substitutions can be made to the embodiments of the invention by those skilled in the art without departing from the spirit and essence of the invention. Such modifications or substitutions should all fall within the scope of the invention, or any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the invention should be covered within the protection scope of the invention. Therefore, the protection scope of the invention should be determined by the scope of the claims.

Claims

1. A method for ship scenario based switch and gateway collaborative security, characterized in that, The method comprises: generating a comprehensive feature matrix according to real-time traffic data of switches and gateways in a ship network; generating a threat feature vector with credibility based on the comprehensive feature matrix; constructing a dynamic attack probability graph and inferring a diffusion path and an influence range according to the threat feature vector; and constructing a reinforcement learning-based adaptive defense strategy model based on the inference result of the dynamic attack probability graph to realize collaborative security protection; wherein constructing a dynamic attack probability graph and inferring a diffusion path and an influence range according to the threat feature vector specifically comprises: According to the threat feature vector with credibility, each threat feature point is mapped into the physical node coordinates of the network in combination with the actual topological connection relationship of the ship network; then a Bayesian estimation method is used to carry out probability interpolation operation on the discrete threat feature points to generate a preliminary dynamic attack probability graph, and the preliminary dynamic attack probability graph presents the possibility distribution of each node in the network being attacked; In combination with time sequence information, a hidden Markov model is adopted, and historical attack diffusion data are referred to, and the preliminary dynamic attack probability graph is dynamically adjusted according to the evolution of network states at different times and the law of historical attack modes to obtain a dynamic attack probability graph evolving over time; After obtaining the dynamic attack probability graph evolving over time, the dynamic attack probability graph is input into a Bayesian network, a probabilistic graph model is constructed according to the topological structure of the ship network, in the probabilistic graph model, a node represents a key interface of a network device, and an edge represents a data transmission path; by using the structure and characteristics of the probabilistic graph model, a conditional probability table is constructed to accurately capture the attack propagation dependency relationship between nodes; wherein the conditional probability table describes the probability of other related nodes being attacked in the case of a certain node being attacked, and then an initial inference result of attack diffusion is obtained, which is presented in the form of an attack probability graph, and the initial inference result preliminarily reveals the propagation direction of the attack in the network and the range of nodes affected by the attack; In order to predict the diffusion path and the influence range of the attack, the attack probability graph in the initial inference result is converted into a state space model; wherein the state vector of the state space model covers key information such as attack node position, diffusion rate and influence strength; the observation vector is a real-time threat feature vector; by means of Kalman filtering algorithm, the state vector is recursively estimated, and by means of continuous iterative calculation, the mean value and the covariance matrix of the attack state at the next time are predicted; if there is an error in the estimation of the state vector, the observation vector reflects the actual observation of the system, and by comparing the observation vector with the predicted value of the state vector, the state vector is updated and corrected by using the Kalman filtering algorithm.

2. The method of claim 1, wherein, The method comprises: generating a comprehensive feature matrix according to real-time traffic data of switches and gateways in a ship network; generating a threat feature vector with credibility based on the comprehensive feature matrix; constructing a dynamic attack probability graph and inferring a diffusion path and an influence range according to the threat feature vector; and constructing a reinforcement learning-based adaptive defense strategy model based on the inference result of the dynamic attack probability graph to realize collaborative security protection; wherein constructing a dynamic attack probability graph and inferring a diffusion path and an influence range according to the threat feature vector specifically comprises: The real-time traffic data collected by the multiple ports of the switches and the gateways are subjected to timestamp calibration and outlier rejection processing; then a multi-source data alignment mechanism based on a sliding window is adopted to eliminate the differences in port sampling frequencies, and time-synchronized multi-source traffic sequences are obtained; Input the multi-source traffic sequence into a deep belief network, a data layer of the deep belief network uses a restricted Boltzmann machine to capture underlying features of the traffic data, and a feature layer uses a greedy layer-by-layer training algorithm to extract high-level abstract features, to obtain preliminary comprehensive features; An association rule mining algorithm is used to calculate an association coefficient between different port data, the preliminary comprehensive features are weighted and integrated according to the coefficient, the role of key port data in threat identification is highlighted, and weighted comprehensive features are obtained; The weighted comprehensive features are input into a principal component analysis model, a covariance matrix is calculated, the eigenvalues and eigenvectors of the covariance matrix are solved by using a Jacobi iteration method, the number of principal components is determined according to the contribution rate of the eigenvalues, the weighted comprehensive features are subjected to matrix multiplication with a feature transformation matrix, dimensionality reduction is performed through linear transformation, redundant features are removed, core information is retained, and a low-dimensional comprehensive feature matrix containing packet type, source and destination addresses, port numbers and transmission rate information is generated.

3. The method of claim 2, wherein, Based on the comprehensive feature matrix, a threat feature vector with credibility is generated, specifically including: The comprehensive feature matrix is input into a stacked autoencoder, the stacked autoencoder gradually converts the original features to a latent variable space through a multi-layer nonlinear mapping mechanism, in this process, each layer uses sparse regularization constraints, which promote the model to learn more representative and sparse feature representations, avoid overfitting and interference of redundant information, and finally obtain deep feature representations; A probability model based on Naive Bayes is constructed for the deep feature representations, the probability model uses a mixture model of a multinomial distribution and a Gaussian distribution to model discrete features and continuous features respectively, so as to capture the inherent laws of discrete features and continuous features in network transmission states, to obtain preliminary statistical feature representations, which quantitatively describe the network transmission states from the perspective of probability; According to the preliminary statistical feature representations, the posterior probability and the likelihood value of each feature point are calculated, the posterior probability reflects the probability that the feature point belongs to a certain state under the condition that the observed data is known, and the likelihood value measures the possibility of the observed data under the given feature point state; the uncertainty of the probability model is estimated by using a Markov chain Monte Carlo algorithm, random sampling can be performed in a complex probability space, the uncertainty of the model is accurately estimated through analysis of a large number of samples, and a statistical feature distribution with a confidence range is obtained.

4. The method of claim 3, wherein, The generating a threat feature vector with credibility based on the comprehensive feature matrix further comprises: dividing the statistical feature distribution into a plurality of feature subsets, each feature subset corresponding to a different period of network transmission; independently training each feature subset using a parallel isolation forest algorithm to generate a plurality of anomaly detection base models; then, through a Stacking ensemble learning strategy, weighting and fusing the anomaly scores output by each of the anomaly detection base models, the weight coefficients being dynamically adjusted according to the sample quantity of each period of data, the weight corresponding to a period of data with a larger sample quantity being larger, and the weight corresponding to a period of data with a smaller sample quantity being smaller, to obtain a comprehensive anomaly score; finally, using an adaptive threshold algorithm, determining a dynamic threshold according to the distribution characteristics of the comprehensive anomaly score to replace the preset credibility threshold; the dynamic threshold can be automatically adjusted according to the distribution of actual data, and abnormal feature points are filtered out by comparison with the dynamic threshold to generate a threat feature vector with credibility.

5. The method of claim 4, wherein, The constructing a dynamic attack probability graph and inferring a diffusion path and an influence range according to the threat feature vector further comprises: setting reasonable attack diffusion stopping conditions; when the predicted attack probability is lower than a pre-set minimum threat threshold, or the diffusion path reaches the network boundary, immediately terminating the prediction process; at this time, outputting the attack diffusion path and the influence range within a limited time window to generate a diffusion prediction result of the dynamic attack probability graph.

6. The method of claim 5, wherein, The constructing an adaptive defense strategy model based on reinforcement learning based on the inference result of the dynamic attack probability graph to realize collaborative security protection specifically comprises: first, training a normal behavior simulator based on reinforcement learning based on historical normal transmission data, the simulator using a deep deterministic policy gradient algorithm that combines the feature extraction capability of a deep neural network and the processing advantage of a deterministic policy gradient for continuous action space; in the training process, the simulator regards the normal transmission state of the ship network as an environment, and the simulator itself as an agent interacting with the environment; the agent generates simulated traffic through a deep neural network according to the current network state, and the environment gives corresponding reward or punishment feedback according to the action of the agent; through continuous trial and error and learning, the agent gradually adjusts its own strategy, so that the generated simulated traffic can most closely resemble the real ship network normal transmission traffic, providing a comparison benchmark for subsequent attack recognition; then constructing a real-time attack recognizer based on a convolutional neural network, the real-time attack recognizer inputting the diffusion prediction result of the attack probability graph and the normal behavior data generated by the simulator, capturing the boundary features of normal and abnormal states through continuous interactive learning, and outputting the recognition result and its credibility.

7. The method of claim 6, wherein, Based on the recognition result of the real-time attack recognizer, using a density clustering algorithm to divide the recognition result into multiple levels, combining the dynamic change characteristics of the attack probability graph to generate multi-level defense rules that are adjusted in real time according to the network transmission state, the multi-level defense rules including pre-warning level, blocking level and isolation level rules; According to the density clustering result, the abnormal traffic is divided into three initial levels of low risk, medium risk and high risk, corresponding to the candidate set of warning level, blocking level and isolation level rules; The classification is based on the average anomaly score within each cluster. In the formula, C For clusters, S i For the first i Abnormal scores at each point; Cluster density: where Area is the footprint of the cluster in the feature space. Dynamic adjustment threshold: according to the historical attack data statistics, the score thresholds of low risk, medium risk and high risk are set as θ 1, θ 2, θ 3, and θ 1 θ 2 θ 3, respectively set as θ 1=0.3, θ 2=0.6, θ 3=0.9; Based on the division basis, the abnormal level division function is represented as: wherein , are the minimum and maximum density thresholds, respectively.

8. The method of claim 7, wherein, To ensure that the real-time threat features can be matched to the multi-level defense rules, a dynamically optimized defense rule matching degree calculation model is constructed. The calculation model first extracts real-time threat features from multi-dimensional data sources, covering numerical attributes and categorical attributes, and eliminates the dimension difference through normalization processing. Then, the attribute parameters of real-time threat features are semantically aligned with the condition items of multi-level defense rules. For numerical attributes, range mapping or threshold segmentation is used to realize semantic approximate matching. For categorical attributes, hierarchical relationship or semantic correlation is used to quantify the matching degree, and then a matching degree score matrix containing all real-time threat feature and rule combinations is generated. On this basis, the calculation model uses weighted voting method for decision-making, wherein the weight of each rule is dynamically determined by its historical effectiveness probability. By counting the ratio of the number of successful triggers to the total number of triggers of the rule in the past defense period, rules with stable historical performance and high effectiveness probability are preferentially selected, and the weight is dynamically adjusted in combination with the severity of real-time threat features. Finally, according to the defense level of the optimal matching rule, the cooperative interface of the switch and the gateway is called to execute the corresponding defense operation. At the same time, the operation log is recorded for subsequent rule optimization, forming a defense system.

9. A ship scenario based switch and gateway collaborative security system, the system comprising a memory for storing computer program instructions and a processor for executing the program instructions, wherein, When the computer program instructions are executed by the processor, the system triggers the execution of the ship scene based switch and gateway cooperative security method in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network security big data state evaluation method based on pattern recognition

    CN120301637A

  • AI-based network security system construction, operation and maintenance method, device and system and medium

    CN120639376A