Network chip security detection method and device, electronic equipment, medium and product

By combining multi-dimensional feature collaboration and multi-unit linkage detection, the digital network signals of the network chip are acquired, multi-dimensional features are extracted, and a full-domain security assessment is performed. This solves the problem that existing technologies cannot identify new unknown attacks and provide real-time protection, and achieves accurate security detection and real-time protection for network chips.

CN121727809APending Publication Date: 2026-03-24中国移动通信集团云南有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing network chip security detection technologies rely on the manual summarization and recording of known attack cases, which is lagging, cannot effectively identify new and unknown attacks, and cannot meet real-time security protection requirements.

Method used

By combining multi-dimensional feature collaboration and multi-unit linkage detection, the digital network signals of the network chip are obtained, and statistical features, protocol features and deep detection features are extracted. Combined with anomaly detection, attack identification and vulnerability detection units, the overall security assessment of the network chip is realized.

Benefits of technology

It enables accurate identification of abnormal traffic, network attacks, and chip vulnerabilities in network chips, improving the accuracy and real-time performance of security detection, building a closed-loop protection across the entire link, and meeting real-time security protection needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121727809A_ABST
    Figure CN121727809A_ABST
Patent Text Reader

Abstract

The invention discloses a network chip security detection method and device, electronic equipment, a medium and a product. The method comprises the following steps: acquiring a digital network signal of a network chip to be detected, and extracting features of the digital network signal to obtain statistical features, protocol features and deep detection features; determining an anomaly detection result according to the anomaly detection unit, the statistical features and the protocol features; determining an attack recognition result according to the attack recognition unit, the deep detection feature and the protocol feature; determining a vulnerability detection result according to the vulnerability detection unit, the deep detection feature and the protocol feature; and determining a security defense decision corresponding to the to-be-detected network chip according to the anomaly detection result, the attack recognition result and the vulnerability detection result. According to the technical scheme, abnormal traffic, network attacks and chip vulnerabilities are accurately identified through multi-dimensional feature cooperation and multi-unit linkage detection, so that the effect of carrying out global research and judgment on the security risk of the network chip is achieved, and the security detection precision of the network chip is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security detection, and in particular to a network chip security detection method and device, electronic equipment, medium and product. BACKGROUND

[0002] With the rapid rise of digital economy and the deep popularization of new generation information technology, the complexity of network communication architecture and the scale of data transmission grow exponentially. As the core hardware carrier of communication network data forwarding, protocol processing and service bearing, the security protection capability of network chip has become a key barrier to ensure the stable operation of network. At the same time, network attack technology continues to iterate, and attack means presents the characteristics of concealment, diversification and intelligence, which puts forward high requirements for the security monitoring and defense system of network chip.

[0003] In related technologies, network chip security detection usually adopts a rule-based detection mechanism. This kind of scheme matches and verifies the running data and transmission traffic of network chip through a pre-defined attack feature library, traffic anomaly rule and protocol behavior. However, this detection method has significant limitations: first, the update of rule library depends on the manual induction and input of known attack cases, which has obvious lag and cannot effectively identify new unknown attacks, making it difficult to respond to sudden security threats; second, this scheme needs to invest a lot of manpower cost for rule maintenance and update, and when facing complex and variable network environment, the response efficiency of manual intervention is low, which cannot meet the needs of real-time security protection. SUMMARY

[0004] The present application provides a network chip security detection method, device, electronic equipment, medium and product, which accurately identifies abnormal traffic, network attacks and chip vulnerabilities through multi-dimensional feature cooperation and multi-unit linkage detection, and realizes global judgment of network chip security risks by fusing multi-dimensional security data of abnormal detection results, attack identification results and vulnerability detection results, thereby improving the precision of network chip security detection.

[0005] According to an aspect of the present application, a network chip security detection method is provided, which comprises:

[0006] Obtaining a digital network signal of a network chip to be detected, and extracting features from the digital network signal to obtain statistical features, protocol features and deep detection features corresponding to the digital network signal;

[0007] Determining an abnormal detection result corresponding to the network chip to be detected according to an abnormal detection unit, the statistical features and the protocol features; and

[0008] determine an attack identification result corresponding to the network chip to be detected according to the attack identification unit, the deep detection feature and the protocol feature; and

[0009] determine a vulnerability detection result corresponding to the network chip to be detected according to the vulnerability detection unit, the deep detection feature and the protocol feature;

[0010] determine a security defense decision corresponding to the network chip to be detected according to the anomaly detection result, the attack identification result and the vulnerability detection result.

[0011] According to another aspect of the present application, a network chip security detection device is provided, which comprises:

[0012] a signal feature extraction module, configured to acquire a digital network signal of a network chip to be detected, and perform feature extraction on the digital network signal to obtain statistical features, protocol features and deep detection features corresponding to the digital network signal;

[0013] an anomaly detection module, configured to determine an anomaly detection result corresponding to the network chip to be detected according to an anomaly detection unit, the statistical features and the protocol features; and

[0014] an attack identification module, configured to determine an attack identification result corresponding to the network chip to be detected according to an attack identification unit, the deep detection features and the protocol features; and

[0015] a vulnerability detection module, configured to determine a vulnerability detection result corresponding to the network chip to be detected according to a vulnerability detection unit, the deep detection features and the protocol features;

[0016] a defense decision determination module, configured to determine a security defense decision corresponding to the network chip to be detected according to the anomaly detection result, the attack identification result and the vulnerability detection result.

[0017] According to another aspect of the present application, an electronic device is provided, which comprises:

[0018] at least one processor; and

[0019] a memory connected with the at least one processor in communication; wherein

[0020] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the network chip security detection method according to any one of the embodiments of the present application.

[0021] According to another aspect of the present application, there is provided a computer readable storage medium storing computer instructions for causing a processor to implement the network chip security detection method according to any of the embodiments of the present application when executed.

[0022] According to another aspect of the present application, there is provided a computer program product comprising a computer program for implementing the network chip security detection method according to any of the embodiments of the present application when executed by a processor.

[0023] The technical scheme of the embodiment of the application realizes multi-dimensional feature full-coverage extraction of the digital network signal from the surface statistical law, protocol compliance attribute to the application layer deep service logic, provides accurate and comprehensive feature input for subsequent anomaly detection, attack identification and vulnerability detection of the to-be-detected network chip, and lays a foundation for multi-dimensional collaborative security detection. Further, the anomaly detection result corresponding to the to-be-detected network chip is determined according to the anomaly detection unit, statistical feature and protocol feature, the collaborative input of the statistical feature (surface flow rule) and the protocol feature (protocol compliance attribute) is realized, the analysis capability of the anomaly detection unit is combined, accurate identification and rapid determination of the network chip flow anomaly are realized, and strong pertinence and high reliability trigger basis for subsequent basic anomaly defense decision is provided. Further, the attack identification result corresponding to the to-be-detected network chip is determined according to the attack identification unit, deep detection feature and protocol feature, the application layer deep logic analysis capability of the deep detection feature and the compliance verification advantage of the protocol feature are relied on, the analysis function of the attack identification unit is combined, accurate identification and positioning of the attack type and attack feature of the network chip are realized, and core and reliable technical basis for subsequent targeted attack defense decision is provided. Further, the vulnerability detection result corresponding to the to-be-detected network chip is determined according to the vulnerability detection unit, deep detection feature and protocol feature, the application layer deep logic targeting of the deep detection feature and the protocol layer compliance verification capability of the protocol feature are used, the double-technology collaborative detection function of the vulnerability detection unit is combined, accurate positioning and comprehensive detection of the target software vulnerability of the network chip are realized, and core basis with pertinence and implementability for subsequent vulnerability repair decision is provided. Further, the security defense decision corresponding to the to-be-detected network chip is determined according to the anomaly detection result, attack identification result and vulnerability detection result, the multi-dimensional security data of the anomaly detection result, attack identification result and vulnerability detection result are fused, global research and judgment of the network chip security risk are realized, accurate and targeted security defense decision is output, a closed-loop protection from risk detection to decision generation is formed, and the operation safety of the network chip is comprehensively ensured.The technical scheme of the embodiment of the present application solves the technical problems that manual induction and input relying on known attack cases in the related art have obvious hysteresis, cannot effectively identify new unknown attacks, and cannot meet the needs of real-time security protection, and through multi-dimensional feature cooperation and multi-unit linkage detection, abnormal traffic, network attacks and chip vulnerabilities are accurately identified, and through fusion of multi-dimensional security data of abnormal detection results, attack identification results and vulnerability detection results, global research and judgment of network chip security risks are realized, the precision of network chip security detection is improved, the real-time and comprehensiveness of security detection are taken into account, a full-link closed-loop protection from feature extraction to multi-dimensional detection to accurate decision is constructed, and the real-time security protection needs of the network chip are effectively met.

[0024] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0026] Figure 1 is a flow chart of a network chip security detection method according to the first embodiment of the present application;

[0027] Figure 2 is a flow chart of a network chip security detection method according to the second embodiment of the present application;

[0028] Figure 3 is a structural schematic diagram of a network chip security detection system according to the third embodiment of the present application;

[0029] Figure 4 is a structural schematic diagram of a network chip security detection device according to the fourth embodiment of the present application;

[0030] Figure 5 is a structural schematic diagram of an electronic device for implementing the network chip security detection method of the embodiment of the present application. DETAILED DESCRIPTION

[0031] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0033] Example 1

[0034] Figure 1 This is a flowchart of a network chip security detection method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations involving security detection of network chips. The method can be executed by a network chip security detection device, which can be implemented in hardware and / or software and can be configured in a terminal and / or server. Figure 1 As shown, the method includes:

[0035] S110. Acquire the digital network signal of the network chip to be tested, and extract features from the digital network signal to obtain the statistical features, protocol features and deep detection features corresponding to the digital network signal.

[0036] The network chip under test (DUT) can be a hardware integrated circuit with core communication functions such as network data forwarding, protocol parsing, and service instruction execution. It is the core hardware foundation for building wired or wireless network devices and realizing data communication between or within devices. The security status of the DUT directly affects the stability and confidentiality of the entire network communication. It can be understood that in the field of network communication, the DUT, as the core hardware carrier for communication network data forwarding, protocol processing, and service carrying, has its security protection capabilities become a key barrier to ensure stable network operation. DUT communication is widely used in routers, switches, network interface cards (NICs), servers, IoT devices, and vehicle communication systems. Optionally, the DUT may include Ethernet chips, fiber optic communication chips, bus communication and interface control chips, NIC chips, mobile network chips, wireless communication chips, IoT wireless chips, and positioning and navigation chips. Digital network signals can refer to the digitized discrete signals generated by the DUT during data transmission and processing, formed after signal preprocessing. Digital network signals can carry network data, communication instructions, and chip operating status information in the form of binary bit streams. Digital network signals can be the core data carrier connecting the chip hardware operating status with subsequent intelligent analysis. Feature extraction can be a critical information extraction operation performed on digital network signals. It can utilize techniques such as statistical analysis, protocol parsing, and deep packet inspection to extract core data dimensions with security analysis value from raw digital signals.

[0037] Statistical features refer to quantitative indicators extracted from digital network signals through statistical analysis algorithms, reflecting the overall distribution pattern of signal data. Statistical features may include, but are not limited to, data mean, variance, standard deviation, traffic fluctuation amplitude, and data packet length distribution range. Protocol features refer to features extracted from digital network signals through protocol parsing techniques, reflecting the compliance of network communication protocols. Protocol features may include, but are not limited to, the protocol type of the data packet, protocol version, protocol field format, protocol interaction process integrity, and protocol resource value compliance. Deep detection features refer to deep information extracted through in-depth analysis of the application layer payload of data packets in digital network signals, such as application layer instruction logic, business interaction rules, data packet payload content characteristics, and application layer protocol defect triggering conditions.

[0038] In practical applications, network chip security detection typically relies only on shallow detection features at the transport and network layers. This approach may fail to identify covert attacks (such as SQL injection and malicious code) and traffic triggered by protocol logic vulnerabilities in application layer payloads, and it may also struggle to detect the insidious penetration of advanced threats such as APTs. Furthermore, it is prone to false positives and false negatives due to limitations in feature dimensions, and it cannot protect against security risks at the data content level.

[0039] To address the above issues, this embodiment employs deep detection feature extraction of the digital network signal of the network chip under test, and performs in-depth analysis of the application layer payload of data packets within the digital network signal. Furthermore, security detection of the network chip under test can be performed based on the extracted deep detection features, thereby improving the accuracy of security detection.

[0040] In this embodiment, the digital network signal can be obtained by preprocessing the original network signal of the network chip to be detected.

[0041] Optionally, acquiring the digital network signal of the network chip under test includes: acquiring the original network signal transmitted by the network chip under test; performing signal processing on the original network signal to obtain the processed analog network signal, and performing signal modulation on the analog network signal to obtain the digital network signal to be processed; and preprocessing the digital network signal to obtain the digital network signal of the network chip under test.

[0042] The raw network signal can refer to the initial signal directly acquired from the physical transmission interface of the network chip under test, without any manual processing. The signal form of the raw network signal can include electrical signals (such as carrier signals transmitted via twisted-pair cables) and / or optical signals (such as optical pulse signals transmitted via optical fibers). The raw network signal can contain service data and / or communication data transmitted by the network chip under test. Signal processing can refer to basic physical-level optimization operations performed on the raw network signal. Signal processing can be used to improve the purity and effective strength of the raw network signal, laying the foundation for subsequent digital conversion. Optionally, signal processing includes at least one of signal amplification and signal filtering. Signal amplification can be understood as the strength enhancement operation performed on the raw network signal through a signal gain circuit to compensate for signal attenuation during transmission or acquisition, ensuring that the signal strength meets the threshold requirements for subsequent filtering, adjustment, and other processing. Signal filtering can refer to the use of low-pass, high-pass, band-pass, or band-stop filters to filter out noise, interference, and other invalid components in the raw network signal, retaining only the effective signal frequency bands with communication value, thereby improving the signal-to-noise ratio. Analog network signals refer to non-digital network signals that retain continuous waveform characteristics even after processing such as signal amplification and filtering. The amplitude and frequency of analog network signals can change continuously over time, representing an intermediate form of the original network signal after initial optimization. Signal modulation refers to the digitization operation performed on analog network signals, converting continuous analog network signals into discrete binary digital signals through sampling, quantization, and encoding processes. The digital network signal to be processed refers to the digitized network signal initially formed after signal modulation. This signal can also be a digital network signal awaiting preprocessing. Preprocessing refers to the digitization optimization operation performed on the digital network signal to be processed. Preprocessing can improve data quality, standardize digital formats, and assign digital analysis labels to meet the needs of subsequent feature extraction and intelligent analysis. Optionally, preprocessing includes at least one of data cleaning and data normalization. Data cleaning can be understood as removing invalid, erroneous, and duplicate data records from the digital network signal to be processed (such as garbled data generated by interference during acquisition, and redundant data packets transmitted repeatedly) to ensure the validity and accuracy of the data. Data normalization refers to scaling different dimensions of data (such as signal amplitude and data packet length) in a digital network signal to a uniform numerical range (such as the [0,1] interval). Data normalization can be used to eliminate the dimensional differences between different feature dimensions, facilitating comparative analysis by subsequent algorithms.

[0043] In one embodiment, during the operation of the network chip under test, the network signals generated by the network chip during operation can be acquired to obtain the raw network signals transmitted by the network chip under test. Further, the raw network signals can be amplified and filtered to obtain processed raw network signals, which are then used as analog network signals. Further, the analog network signals can be modulated to perform digital conversion, and the resulting digitized network signal is used as the digital network signal to be processed. Further, the data network signal to be processed can be preprocessed, and the preprocessed digitized network signal is used as the digital network signal for security testing of the network chip under test.

[0044] In this embodiment, after obtaining the digital network signal of the network chip to be detected, feature extraction can be performed on the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal.

[0045] In this embodiment, feature extraction of digital network signals may include at least one of the following: providing the digital network signals to a feature extraction unit to obtain output statistical features, protocol features, and deep detection features; performing statistical analysis on the digital network signals to obtain statistical features; performing protocol parsing on the digital network signals to obtain protocol features; and performing deep feature extraction on the digital network signals to obtain deep detection features. One of these feature extraction methods will be described in detail below.

[0046] Optionally, feature extraction is performed on the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal. This includes: performing statistical analysis on the digital network signal to obtain statistical features corresponding to the digital network signal; determining the network protocol type to which the digital network signal belongs, and extracting protocol features corresponding to the digital network signal from pre-stored protocol type information based on the network protocol type; and performing application layer deep analysis on the digital network signal to obtain deep detection features corresponding to the digital network signal.

[0047] Statistical analysis refers to the quantitative analysis of numerical data (such as packet length, signal amplitude, and traffic transmission efficiency) of digital network signals. Statistical analysis uses mathematical statistical algorithms to calculate the distribution patterns and dispersion of signal data. Optionally, statistical characteristics include at least one of the following: mean, variance, and standard deviation. The mean can refer to the average value of a certain data dimension of the digital network signal (such as the number of packets per unit time or the average length of packets). The mean can be used to characterize the level of concentration of network signal data under that data dimension and is a basic indicator for judging whether network traffic deviates from the normal baseline. The variance can refer to the average of the sum of squares of the deviations of each network signal data value from the mean under a certain data dimension of the digital network signal. The variance can be used to characterize the dispersion of network signal data under that data dimension; a larger variance indicates more severe data fluctuations and is a core indicator for identifying sudden anomalies in network traffic. The standard deviation is the arithmetic square root of the variance. Compared to variance, the standard deviation can more intuitively reflect the dispersion of a certain data dimension of the digital network signal.

[0048] The network protocol type refers to the category of network protocols corresponding to the data carried by the digital network signal. Network protocol types can encompass protocols at different layers, such as the transport layer (TCP / UDP), network layer (IP / ICMP), and application layer (HTTP / FTP / MQTT). The network protocol type serves as a core identifier distinguishing signal service attributes and communication logic. Pre-stored protocol type correspondence information refers to a protocol feature database pre-created and stored by the system, containing standard features corresponding to different network protocol types (such as protocol field format, field length threshold, protocol interaction flow, and protocol-specific identifiers). Protocol type correspondence information can be used to characterize the correspondence between network protocol types and protocol features. Protocol features refer to characteristics reflecting protocol compliance, extracted from the pre-stored protocol type correspondence information based on the network protocol type of the digital network signal.

[0049] Application layer deep parsing refers to the deep analysis operation performed on the application layer payload content and business interaction logic, penetrating the transport and network layers of digital network signals. Application layer deep parsing can extract hidden information such as application layer instructions, business data formats, and protocol defect triggering conditions. Deep detection features refer to the features obtained through application layer deep parsing that reflect the application layer business logic and potential security risks of digital network signals. Deep detection features can cover application layer instruction anomalies, malicious payload content identifiers, and protocol logic defect triggering parameters.

[0050] In one embodiment, after acquiring the digital network signal of the network chip to be detected, statistical analysis can be performed on the digital network signal to obtain statistical features corresponding to the digital network signal; and the network protocol type to which the digital network signal belongs can be determined, and the protocol features corresponding to the digital network signal can be extracted from the pre-stored protocol type corresponding information based on the network protocol type; and the application layer deep analysis can be performed on the digital network signal to obtain deep detection features corresponding to the digital network signal.

[0051] S120. Determine the anomaly detection result corresponding to the network chip to be detected based on the anomaly detection unit, statistical characteristics, and protocol characteristics.

[0052] The anomaly detection unit can refer to an algorithm module or neural network model capable of detecting anomalies in network traffic based on received statistical and protocol features. Optionally, the anomaly detection unit may include at least one of a multi-algorithm module integrating the Isolation Forest algorithm and the Support Vector Machine algorithm, and / or anomaly detection models, etc. The anomaly detection model can be trained on a machine learning model using the statistical and protocol features of sample network signals and actual anomaly detection results. For a multi-algorithm module integrating the Isolation Forest algorithm and the Support Vector Machine algorithm, statistical and protocol features can be used as inputs, and a weighted fusion algorithm can be used to output a comprehensive anomaly score and a judgment result. The anomaly detection result can refer to the security status judgment data of the network traffic corresponding to the network chip under test, output by the anomaly detection unit. The anomaly detection result may include at least one of the following: a comprehensive anomaly score, anomaly threshold comparison results, and basic feature identifiers of the anomaly traffic (such as "abnormal protocol field value" or "traffic fluctuation exceeding limits").

[0053] Optionally, the anomaly detection model includes an anomaly detection model; determining the anomaly detection result corresponding to the network chip under test based on the anomaly detection unit, statistical features, and protocol features, including: providing statistical features and protocol features to the anomaly detection model to obtain the output anomaly detection result corresponding to the network chip under test.

[0054] The anomaly detection model can be a machine learning model trained on sample data, capable of determining network traffic anomalies. This model can directly receive statistical and protocol features and output anomaly detection results. The model can be trained using the statistical and protocol features of sample network signals and actual anomaly detection results. Sample network signals refer to historical network signal data used to train the model, originating from the same digital network signals of the network chip under test. This data includes signal data corresponding to normal traffic and various known abnormal traffic types, serving as the foundational samples for the model to learn its anomaly detection logic. Actual anomaly detection results refer to the actual security status labeling data corresponding to the sample network signals. This includes "normal / abnormal" labels or specific anomaly type labels assigned to the sample network signals manually or automatically, forming the core label data for supervised / semi-supervised training of the model.

[0055] In one embodiment, after obtaining the statistical and protocol features corresponding to the digital network signal, the statistical and protocol features can be provided to the pre-trained anomaly detection model. The anomaly detection model performs network traffic anomaly detection based on the received statistical and protocol features and outputs the anomaly detection result corresponding to the network chip under test.

[0056] Optionally, the anomaly detection unit includes an algorithm module integrating the isolated forest algorithm and the support vector machine algorithm; determining the anomaly detection result corresponding to the network chip to be detected based on the anomaly detection unit, statistical features, and protocol features includes: processing the statistical features and protocol features according to the isolated forest algorithm to obtain a first anomaly detection result; and processing the statistical features and protocol features according to the support vector machine algorithm to obtain a second anomaly detection result; and determining the anomaly detection result corresponding to the network chip to be detected based on the first anomaly detection result and the second anomaly detection result.

[0057] The algorithm module integrating the Isolation Forest algorithm and the Support Vector Machine (SVM) algorithm can be a functional module that integrates and encapsulates the Isolation Forest algorithm and the SVM algorithm. This algorithm module can execute the computational logic of the two algorithms synchronously or distributedly, outputting corresponding sub-anomaly detection results. The Isolation Forest algorithm can be understood as an unsupervised anomaly detection algorithm based on an ensemble tree structure. The Isolation Forest algorithm can calculate the average path length of data points by constructing an isolated forest, thereby outputting anomaly detection results that characterize the degree of network traffic anomalies. Its core logic is that "abnormal data is more easily isolated quickly." The SVM algorithm can be an unsupervised anomaly detection algorithm based on hyperplane boundary learning, used to process statistical and protocol features, and output anomaly detection results by calculating decision function values. Its core logic is that "learning the boundaries of normal data and determining abnormal data that deviates from the boundaries." Optionally, the SVM algorithm includes at least one of single-class SVM, binary-class SVM, and multi-class SVM.

[0058] The first anomaly detection result can refer to the sub-anomaly detection result output by the Isolation Forest algorithm after processing statistical and protocol features. The first anomaly detection result can be represented by an anomaly score; the closer the anomaly score is to 1, the higher the probability of anomaly in the network traffic. The second anomaly detection result can refer to the sub-anomaly detection result output by the Support Vector Machine algorithm after processing statistical and protocol features. The second anomaly detection result can be represented by a decision function value; the smaller the function value, the more likely it is to be considered abnormal traffic.

[0059] In this embodiment, determining the anomaly detection result corresponding to the network chip to be detected based on the first anomaly detection result and the second anomaly detection result may include at least one of the following: processing the first anomaly detection result and the second anomaly detection result using a weighted fusion algorithm to obtain the anomaly detection result; or processing the first anomaly detection result and the second anomaly detection result using an averaging operation to obtain the anomaly detection result.

[0060] Optionally, the anomaly detection result corresponding to the network chip to be detected is determined based on the first anomaly detection result and the second anomaly detection result, including: determining the first weight corresponding to the first anomaly detection result and the second weight corresponding to the second anomaly detection result; and processing the first anomaly detection result, the first weight, the second anomaly detection result and the second weight through a weighted fusion algorithm to obtain the anomaly detection result corresponding to the network chip to be detected.

[0061] The first weight can refer to a quantization coefficient assigned to the first anomaly detection result, used to measure its importance in the final anomaly detection result. The value of the first weight is usually determined based on the accuracy of historical detection data and / or scenario adaptability (e.g., if the Isolation Forest algorithm performs better in identifying traffic fluctuation anomalies, the first weight can be set to a higher value). The second weight can refer to a quantization coefficient assigned to the second anomaly detection result, which can be used to measure the contribution of the support vector machine algorithm's output to the final judgment. The value of the second weight can match the detection accuracy of the support vector machine algorithm in a specific scenario (e.g., if the support vector machine algorithm is more accurate in identifying protocol field anomalies, the second weight can be appropriately increased). The first and second weights usually satisfy a normalization constraint that the weight sum is 1. The weighted fusion algorithm can refer to an algorithm module used to integrate the first anomaly detection result, the second anomaly detection result, and their corresponding weights.

[0062] In practical applications, security testing of network chips typically employs rule-based detection mechanisms. These solutions use predefined attack signature databases, traffic anomaly rules, and protocol behavior metrics to match and verify the network chip's operational data and transmission traffic. Alternatively, an anomaly detection algorithm can be used to detect anomalies in the network traffic of the network chip. However, this security testing approach may suffer from low anomaly detection accuracy, an inability to effectively identify new and unknown attacks, and difficulty in responding to sudden security threats.

[0063] To address the above issues, this embodiment combines the Isolation Forest algorithm and Support Vector Machine (SVM) to more accurately identify abnormal traffic. The Isolation Forest algorithm isolates data points using random features and segmentation values; the SVM algorithm learns a boundary containing only normal data. By weighted fusion of the anomaly detection results from these two algorithms, a more comprehensive anomaly detection result can be obtained, thereby improving the accuracy of anomaly detection.

[0064] In one embodiment, statistical features and protocol features can be processed using the isolated forest algorithm to obtain a first anomaly detection result; and statistical features and protocol features can be processed using the support vector machine algorithm to obtain a second anomaly detection result. Further, a first weight corresponding to the first anomaly detection result and a second weight corresponding to the second anomaly detection result are determined. Further, the product between the first anomaly detection result and the first weight can be determined to obtain a first result to be superimposed; and the product between the second anomaly detection result and the second weight can be determined to obtain a second result to be superimposed. Then, the first result to be superimposed and the second result to be superimposed are added together, and the result obtained is taken as the anomaly detection result corresponding to the network chip to be detected.

[0065] S130. Determine the attack identification result corresponding to the network chip to be detected based on the attack identification unit, deep detection features, and protocol features.

[0066] The attack identification unit can refer to an algorithm module or neural network model capable of accurately classifying the attack type (such as DDoS, SQL injection, malformed packet attacks, etc.) of abnormal traffic based on received deep detection features and protocol features. In other words, the attack identification unit can be used to identify the attack type (i.e., the attack type of abnormal traffic) of the network attack received by the network chip under test based on the deep detection features and protocol features of the digital network signal. Optionally, the attack identification unit can include at least one of an algorithm module based on an attack identification algorithm and an attack identification model, wherein the attack identification model can be trained on a machine learning model using the deep detection features and protocol features of the sample network signal and the actual attack type. The attack identification result can refer to the specific attack attribute determination data for abnormal traffic output by the attack identification unit. The attack identification result can include at least one of the following: attack type, attack traffic feature identifier, and preliminary attack origin determination information.

[0067] Optionally, the attack identification unit includes an attack identification model; determining the attack identification result corresponding to the network chip to be detected based on the attack identification unit, deep detection features, and protocol features includes: providing the deep detection features and protocol features to the attack identification model to obtain the output attack identification result corresponding to the network chip to be detected.

[0068] The attack identification model can be a machine learning model trained on labeled samples. Based on deep detection features and protocol features of the input, the attack identification model can accurately classify and identify network attack types. The attack identification model can be a neural network model of any structure. Optionally, the model structure of the attack identification model includes at least one of convolutional neural networks, recurrent neural networks, attention mechanism models, and graph neural networks.

[0069] In one embodiment, the deep detection features and protocol features of the extracted digital network signals can be input into the attack identification model. Then, the attack identification model can identify and classify network attack types based on the received deep detection features and protocol features, and output the attack identification result corresponding to the detection result.

[0070] S140. Determine the vulnerability detection result corresponding to the network chip to be detected based on the vulnerability detection unit, deep detection features, and protocol features.

[0071] The vulnerability detection unit can refer to an algorithm module or intelligent analysis component capable of actively detecting and locating potential vulnerabilities in the relevant software of the network chip under test based on received deep detection features and protocol features. Optionally, the vulnerability detection unit may include an intelligent analysis component integrating fuzzing and symbolic execution technologies and / or an algorithm module integrating vulnerability detection algorithms. The vulnerability detection result can refer to the security defect judgment criteria for the relevant software of the network chip under test output by the vulnerability detection unit. The vulnerability detection result may include, but is not limited to, vulnerability location, triggering conditions, risk level, abnormal input sample characteristics, and vulnerability impact scope.

[0072] Optionally, the vulnerability detection unit includes an algorithm module that integrates a vulnerability detection algorithm; determining the vulnerability detection result corresponding to the network chip to be detected based on the vulnerability detection unit, deep detection features, and protocol features includes: processing the deep detection features and protocol features according to the vulnerability detection algorithm to obtain the vulnerability detection result corresponding to the network chip to be detected.

[0073] Optionally, the vulnerability detection unit includes a module integrating fuzzing logic and symbolic execution logic; determining the vulnerability detection result corresponding to the network chip under test based on the vulnerability detection unit, deep detection features, and protocol features includes: using fuzzing logic to perform fuzzing on the target software in the network chip under test based on deep detection features and protocol features to obtain a first vulnerability detection result; using symbolic execution logic to perform vulnerability detection on the target software in the network chip under test based on the first vulnerability detection result and deep detection features to obtain a second vulnerability detection result; and determining the vulnerability detection result corresponding to the network chip under test based on the first vulnerability detection result and the second vulnerability detection result.

[0074] S150. Determine the security defense decision corresponding to the network chip to be tested based on the anomaly detection results, attack identification results, and vulnerability detection results.

[0075] Security defense decisions can refer to a set of comprehensive security protection strategies generated based on the results of anomaly detection, attack identification, and vulnerability detection. These decisions can include three sub-decisions: anomaly defense decisions, attack defense decisions, and vulnerability remediation decisions. Security defense decisions can achieve end-to-end protection of "basic interception - precise defense - proactive remediation." In other words, security defense decisions determined based on anomaly detection, attack identification, and vulnerability detection results can intercept abnormal network traffic in the network chip under test; then, precise defense is applied to the abnormal network traffic based on the type of network attack; and finally, proactive remediation is performed on network vulnerabilities in the network chip under test caused by network attacks. Optionally, security defense decisions may include, but are not limited to, firewall rule adjustment instructions, intrusion prevention system proactive interception instructions, temporary vulnerability protection instructions, and security policy iteration instructions.

[0076] Optionally, security defense decisions corresponding to the network chip under test are determined based on anomaly detection results, attack identification results, and vulnerability detection results. This includes: determining anomaly defense decisions corresponding to the network chip under test based on anomaly detection results; determining attack defense decisions corresponding to the network chip under test based on the attack type when the attack identification results determine the type of network attack; and determining vulnerability remediation decisions corresponding to the network chip under test based on the network vulnerability when the vulnerability detection results determine the network vulnerability present in the network chip under test.

[0077] Anomaly defense decisions can refer to basic emergency protection strategies generated based on anomaly detection results. These decisions can be used to quickly block suspicious traffic and protect the basic operational resources of the network chip under test. Optionally, anomaly defense decisions include at least one of the following: adjusting firewall rules; restricting access permissions; or initiating a traffic limiting mechanism for the network chip under test. It can be understood that a firewall is the first line of defense for network security, used to control traffic entering and leaving the network. Based on anomaly detection results, firewall rules can be adjusted to restrict or block potential malicious traffic. Adjusting firewall rules includes creating new firewall rules, modifying existing firewall rules, or deleting inapplicable firewall rules. Adjusting firewall rules can refer to dynamically modifying the access control list of the firewall associated with the network chip under test, such as temporarily blocking the source IP or port of abnormal traffic, blocking non-compliant protocol communication links, and adding protocol field format verification rules. Adjusting firewall rules can achieve link-level interception of suspicious traffic. Restricting access permissions can refer to permission control measures implemented on the entity initiating abnormal traffic (such as a specific IP or device account), such as closing access permissions to the core modules (protocol parsing module, firmware management interface) of the network chip under test, reducing its communication priority, etc., thus blocking the penetration of abnormal behavior at the permission level. Enabling a traffic limiting mechanism means setting a peak threshold for the input / output traffic of the network chip under test. When abnormal traffic causes the chip's bandwidth and computing resources to approach saturation, the amount of data packets transmitted per unit time is automatically limited to prevent the network chip under test from being paralyzed due to resource exhaustion.

[0078] The network attack type can refer to the specific attack pattern targeting the network chip being tested, as clearly identified by the attack identification results. Optionally, network attack types include, but are not limited to, traffic-based attacks (DDoS), protocol-layer attacks (malformed data packets), application-layer attacks (SQL injection), and scanning attacks (port scanning). The network attack type can be the core basis for accurately matching attack defense strategies. Attack defense decisions can refer to attack protection strategies generated based on a clearly defined network attack type. Attack defense decisions can correspond to network attack types; that is, different network attack types can correspond to different attack defense strategies. Optionally, when the network attack type includes traffic-based attacks, the corresponding attack defense strategies include traffic scrubbing and filtering, dynamic traffic limiting, attack source link blocking, and multi-node collaborative traffic diversion; when the network attack type includes protocol layer attacks, the corresponding attack defense strategies include protocol field strengthening verification, protocol parsing anomaly circuit breaking, malformed packet signature database updates, and protocol version adaptation and hardening; when the network attack type includes application layer attacks, the corresponding attack defense strategies include application layer payload deep analysis, interface access parameter filtering, application layer protocol hardening, and attack behavior tracing and alarming; when the network attack type includes scanning attacks, the corresponding attack defense strategies include silent shutdown of unnecessary ports, port access frequency limitation, setting up spoofed ports, and port access identity verification.

[0079] Network vulnerabilities can refer to security flaws in the software (firmware, protocol parsing module) or hardware logic of the network chip being tested, as confirmed by vulnerability detection results. These flaws include buffer overflows, missing protocol field validations, and access control vulnerabilities. Vulnerability remediation strategies can refer to proactive protection and remediation strategies generated based on specific information about network vulnerabilities. Vulnerability remediation strategies can include temporary protective measures (such as blocking vulnerability-triggered traffic) and long-term remediation measures (such as pushing firmware patches and optimizing protocol parsing logic).

[0080] In one embodiment, upon obtaining anomaly detection results, attack identification results, and vulnerability detection results, the anomaly detection results can be analyzed to determine the corresponding anomaly defense strategy for the network chip under test, and the determined anomaly defense strategy can be triggered: blocking suspicious traffic links by adjusting firewall access control rules, restricting the access permissions of the abnormal traffic initiator to the chip's core modules, and / or initiating a traffic limiting mechanism on the chip to prevent its bandwidth and computing resources from being exhausted by abnormal traffic. Furthermore, the attack identification results can be analyzed to determine the type of network attack targeting the network chip under test. Further, based on the core characteristics of the network attack type, corresponding attack defense decisions can be generated: initiating traffic scrubbing for traffic-based attacks, strengthening protocol field verification for protocol-layer malformed packets, and intercepting malicious payloads for application-layer injection attacks. Additionally, the vulnerability detection results can be analyzed to identify network vulnerabilities present in the network chip under test. Further, based on the identified network vulnerabilities, corresponding vulnerability remediation strategies can be determined: on the one hand, issuing instructions to block vulnerability-triggered traffic to build a temporary protective barrier; on the other hand, pushing firmware patches and optimizing chip protocol verification logic to complete long-term vulnerability remediation. This ultimately forms a closed-loop security defense system that extends from basic emergency protection to precise attack interception and proactive vulnerability repair, ensuring the stable and secure operation of the network chips under test.

[0081] Optionally, based on the above technical solutions, the method further includes: generating security situation information corresponding to the network chip under test based on the anomaly detection results, attack identification results, and vulnerability detection results, and presenting the security situation information through a display interface.

[0082] Security posture information refers to a visualized, comprehensive, and multi-dimensional set of security status data generated by integrating anomaly detection results, attack identification results, and vulnerability detection results. This security posture information can be used to intuitively reflect the overall security status of the network chip under test. It may include at least one of the following: abnormal traffic distribution, risk heatmap, real-time attack types and levels, attack trend curves, its own vulnerability risk map, and overall security risk rating. The display interface refers to the human-computer interaction platform used to present the security posture information. It can be integrated into the operation and maintenance management platform of the network chip under test, the security testing terminal, and the mobile terminals of the operation and maintenance personnel. The display interface can support various presentation formats such as charts (e.g., risk heatmaps, attack trend curves), text alerts, and data panels, facilitating operation and maintenance personnel to intuitively grasp the security status of the network chip under test.

[0083] In one embodiment, a network security situation analysis algorithm can be used to process the anomaly detection results, attack identification results, and vulnerability detection results to obtain security situation information corresponding to the network chip under test, and the obtained security situation information can be presented on the display interface of the operation and maintenance management platform.

[0084] The technical solution of this invention acquires the digital network signal of the network chip under test and extracts features from the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal. This achieves full-coverage extraction of multi-dimensional features of the digital network signal, from surface statistical patterns and protocol compliance attributes to deep application-layer business logic. This provides accurate and comprehensive feature input for subsequent anomaly detection, attack identification, and vulnerability detection of the network chip under test, laying the foundation for multi-dimensional collaborative security detection. Furthermore, by determining the anomaly detection result corresponding to the network chip under test based on the anomaly detection unit, statistical features, and protocol features, and through the collaborative input of statistical features (surface traffic patterns) and protocol features (protocol compliance attributes), combined with the analytical capabilities of the anomaly detection unit, accurate identification and rapid judgment of network chip traffic anomalies are achieved. This provides a targeted and highly reliable triggering basis for subsequent basic anomaly defense decisions. Furthermore, by determining the attack identification results corresponding to the network chip under test based on the attack identification unit, deep detection features, and protocol features, and leveraging the application-layer deep logic parsing capabilities of deep detection features and the compliance verification advantages of protocol features, combined with the analysis functions of the attack identification unit, accurate identification and localization of the attack type and characteristics of the network chip can be achieved, providing a core and reliable technical basis for subsequent targeted attack defense decisions. Furthermore, by determining the vulnerability detection results corresponding to the network chip under test based on the vulnerability detection unit, deep detection features, and protocol features, and leveraging the application-layer deep logic targeting of deep detection features and the protocol-layer compliance verification capabilities of protocol features, combined with the dual-technology collaborative detection function of the vulnerability detection unit, accurate localization and comprehensive detection of target software vulnerabilities in the network chip can be achieved, providing a core basis that is both targeted and feasible for subsequent vulnerability remediation decisions. Furthermore, by determining the security defense decisions corresponding to the network chip under test based on anomaly detection results, attack identification results, and vulnerability detection results, and by integrating multi-dimensional security data from anomaly detection results, attack identification results, and vulnerability detection results, a comprehensive assessment of network chip security risks can be achieved, outputting precise and targeted security defense decisions, forming a closed-loop protection from risk detection to decision generation, and comprehensively ensuring the operational security of the network chip.The technical solution of this invention addresses the problems in related technologies that rely on manual summarization and input of known attack cases, which suffers from significant lag, cannot effectively identify new and unknown attacks, and cannot meet the needs of real-time security protection. By using multi-dimensional feature collaboration and multi-unit linkage detection, it accurately identifies abnormal traffic, network attacks, and chip vulnerabilities. Furthermore, by integrating multi-dimensional security data from anomaly detection results, attack identification results, and vulnerability detection results, it achieves a comprehensive assessment of network chip security risks, improving the accuracy of network chip security detection. It balances the real-time nature and comprehensiveness of security detection, constructing a closed-loop protection system from feature extraction to multi-dimensional detection to precise decision-making, effectively meeting the real-time security protection needs of network chips.

[0085] Example 2

[0086] Figure 2 This is a flowchart of a network chip security detection method provided in Embodiment 2 of the present invention. Based on the foregoing embodiments, the vulnerability detection unit includes an integrated module that integrates fuzzing logic and symbolic execution logic. Furthermore, step S140 is further refined. For specific implementation details, please refer to the technical solution of this embodiment. Technical terms that are the same as or similar to those in the above embodiments will not be repeated here. Figure 2 As shown, the method includes:

[0087] S210. Acquire the digital network signal of the network chip to be tested, and extract features from the digital network signal to obtain the statistical features, protocol features and deep detection features corresponding to the digital network signal.

[0088] S220. Determine the anomaly detection result corresponding to the network chip to be detected based on the anomaly detection unit, statistical characteristics, and protocol characteristics.

[0089] S230. Determine the attack identification result corresponding to the network chip to be detected based on the attack identification unit, deep detection features, and protocol features.

[0090] S240. Using fuzz testing logic, fuzz testing is performed on the target software in the network chip to be tested based on deep detection features and protocol features to obtain the first vulnerability detection result; wherein, the first vulnerability detection result includes abnormal input data.

[0091] In this embodiment, the vulnerability detection unit may include an integrated module that combines fuzzing logic and symbolic execution logic. The integrated module may be a functional module that encapsulates the test case generation and anomaly response detection logic of simulation testing with the path traversal and constraint solving logic of symbolic execution. The integrated module may have a built-in dual-logic collaborative scheduling interface (abnormal input data output by fuzzing can directly trigger symbolic execution). The integrated module may include software modules (such as software algorithm engines) or hardware modules (such as embedded chips).

[0092] Fuzzing logic can refer to the set of algorithmic logic encapsulated within an integrated module that implements simulation testing functionality. Fuzzing logic can include targeted test case generation logic based on deep detection features and protocol features, target software anomaly response detection logic, and anomaly input data filtering logic. Target software can refer to the core software components in the network chip to be tested that require vulnerability detection. Target software can include chip firmware, protocol parsing modules, operation and maintenance management interface programs, and application layer business processing subroutines. Fuzzing can refer to the initial vulnerability screening process driven by fuzzing logic, constructing targeted abnormal test cases based on deep detection features and protocol features, injecting them into the target software, and monitoring its abnormal responses (such as crashes, instruction execution anomalies, and data leaks). The first vulnerability detection result can refer to the initial vulnerability screening data output after fuzzing is completed. The first vulnerability detection can include abnormal input data that can trigger anomalies in the target software, along with basic information such as the type of abnormal response (e.g., module crash, verification failure) and the trigger time. Abnormal input data can refer to the core abnormal test case data in the first vulnerability detection results that can trigger abnormal responses in the target software, such as excessively long application layer protocol field messages, illegal instruction sequence request packets, and data packets with disordered protocol interaction logic.

[0093] Optionally, fuzzing logic is employed to perform fuzzing tests on the target software in the network chip to be tested based on deep detection features and protocol features to obtain a first vulnerability detection result. This includes: acquiring test input data, and generating a first test case based on deep detection features and protocol features; injecting the test input data and the first test case into the target software in the network chip to be tested for execution to generate the first vulnerability detection result.

[0094] Test input data refers to the basic benchmark test data used for vulnerability detection. It typically consists of legitimate, standard input data from the target software of the network chip under test (such as normal protocol messages conforming to protocol specifications, standard operation and maintenance instructions, and legitimate business request parameters). This data serves as a control group for vulnerability detection, verifying the stability of the target software in normal scenarios, and also as a basic template for generating abnormal test cases. Test input data can be randomly generated or collected historical runtime data. The first test case refers to specialized test data generated by selectively distorting the basic test data based on deep detection features and protocol characteristics. Examples include excessively long protocol field messages, illegal instruction sequence request packets, and data packets with disordered protocol interaction logic. This is the core test carrier used to trigger potential vulnerabilities in the target software. Injection refers to the operation of transmitting test input data and the first test case to the internal runtime environment of the software through legitimate input interfaces (such as protocol communication interfaces and operation and maintenance instruction interfaces). This is a preliminary execution step for vulnerability triggering testing. The first vulnerability detection result includes abnormal input data; abnormal input data includes test input data and / or the first test case. In other words, at least some of the test input data can be abnormal input data, and / or at least some of the test cases in the first test case can also be abnormal input data.

[0095] In one embodiment, a large amount of random, unstructured data can be randomly generated as test input data for the target software in the network chip under test. This data is compliance benchmark data that conforms to protocol specifications and business logic, and can serve as a basic control group for vulnerability detection. Furthermore, the legal thresholds, mandatory field lists, and interaction sequence specifications of protocol fields can be extracted from protocol features, and a first type of strategy (including boundary value, format error, and protocol field outlier strategies) can be generated based on the extracted information. Additionally, the core application-layer business logic, historical vulnerability triggering patterns, and abnormal instruction identifiers of the target software can be extracted from deep detection features, and a second type of strategy (including known vulnerability patterns and business logic anomaly strategies) can be generated based on the extracted information. Further, the test input data can be used as a template and modified according to the first and second types of strategies to generate a first test case with targeted vulnerability triggering capabilities (such as excessively long protocol field messages, illegal instruction sequence request packets, and data packets with disordered protocol interaction logic). Furthermore, test input data and the first test case can be synchronously injected into the target software's runtime environment through the target software's legitimate input interfaces (such as protocol communication interfaces and operation and maintenance command interfaces), driving the target software to load and execute the two types of data. During this process, the target software's runtime status can be monitored in real time, including whether there are abnormal responses such as module crashes, abnormal instruction execution, unauthorized data access, and verification mechanism failures. Finally, the first vulnerability detection result is generated based on the monitoring results. The core of this result includes abnormal input data that can trigger abnormalities in the target software (which may be the potentially defective part of the test input data, the first test case, or a combination of the two), along with basic information such as the specific type of abnormal response and the trigger time, providing a core basis for accurate vulnerability tracing in the subsequent symbolic execution stage.

[0096] S250: Using symbolic execution logic, vulnerability detection is performed on the target software in the network chip to be detected based on abnormal input data and deep detection characteristics to obtain a second vulnerability detection result.

[0097] Symbolic execution logic refers to the set of algorithmic logic encapsulated within the integrated module that implements symbolic execution functionality. Symbolic execution logic may include path constraint construction logic based on abnormal input data, core code path traversal logic, and constraint solving and vulnerability location logic. Vulnerability detection refers to the precise vulnerability tracing and verification process conducted on target software under the drive of symbolic execution logic. Unlike the initial anomaly screening of fuzzing, this stage can locate the specific code location, triggering logic, and scope of impact of the vulnerability. Secondary vulnerability detection results refer to the precise vulnerability determination data output after symbolic execution. Secondary vulnerability detection results may include the specific code path of the vulnerability in the target software, the triggering core logic defects (such as buffer overflows and privilege escalation), the impact level of the vulnerability, and reproducibility conditions. Secondary vulnerability detection results can be used to supplement and improve the primary vulnerability detection results, and can supplement and improve the vulnerability root cause information lacking in the primary vulnerability detection results.

[0098] Optionally, symbolic execution logic is employed to perform vulnerability detection on the target software in the network chip under test based on abnormal input data and deep detection features to obtain a second vulnerability detection result. This includes: using a symbolic execution engine with symbolic values ​​as input, traversing multiple code branches in the target software based on abnormal input data and deep detection features, and determining the path segment constraints corresponding to each code branch; generating second test cases based on the path segment constraints corresponding to multiple code branches; injecting the second test cases into the target software for execution to obtain the second vulnerability detection result.

[0099] The symbolic execution engine refers to the specific runtime carrier of symbolic execution logic, a dedicated program module capable of symbolic value modeling, path constraint solving, and code branch traversal. Symbolic values ​​refer to abstract symbols used to replace specific numerical constants (e.g., s_len representing message length, s_cmd representing application-layer instructions). They do not need to be bound to fixed values ​​and can represent the range and relationships of input data through logical constraint expressions. Symbolic values ​​serve as the data source for the symbolic execution engine, driving it to perform code branch traversal. Code branches refer to different execution paths generated in the target software code due to conditional judgments (e.g., if-else, switch-case), such as the two code branches corresponding to protocol field length validation passing / failing, or the execution branches corresponding to application-layer instructions being valid / illegal; these are the objects traversed by the symbolic execution engine. Path segment constraints refer to the logical constraint expressions generated by the symbolic execution engine for each branch when traversing code branches. These expressions combine symbolic values ​​with conditional rules in the code (e.g., s_len > 256 represents a message length exceeding the limit, s_cmd ≠ a valid instruction set represents an invalid instruction). These constraints form the core basis for constructing the second test case. The second test case can refer to a precise verification case generated by the symbolic execution engine based on path segment constraints across multiple code branches. It can be used to target specific code branches of the target software to verify whether a real security vulnerability exists in that branch. The second test case differs from the first test case in the fuzzing phase, possessing greater precision and specificity.

[0100] In one embodiment, the symbolic execution engine is first activated. Abnormal input data output during the fuzzing phase (such as malformed messages triggering anomalies in the target software) is transformed into abstract symbolic values ​​as input to the symbolic execution engine. Simultaneously, based on the core business path identifiers of the target software extracted from deep detection features (such as key protocol parsing functions and operation and maintenance instruction permission verification branches) and vulnerability triggering parameter constraints, irrelevant code branches such as underlying drivers are filtered out, focusing only on high-risk code regions related to abnormal input. This drives the engine to simulate the execution process of the target software (such as network chip protocol parsing modules and firmware operation and maintenance programs). During the simulation, the symbolic execution engine can traverse multiple conditional code branches within the target software (such as the branch where `if(s_len≤256)` is parsed normally and `else` is handled abnormally), generating corresponding path segment constraints for each branch (such as length over-limit constraints for `s_len>256` and illegal instruction constraints for `s_cmd∈illegal instruction set`). Subsequently, the symbolic execution engine logically integrates and solves these path segment constraints to generate a second test case that can accurately trigger specific high-risk code branches. Furthermore, the second test case is injected into the target software's runtime environment through its legitimate input interface, driving the target software to load and execute the test case. At the same time, the software's running status is monitored in real time (such as whether specific vulnerability behaviors such as buffer overflow, privilege escalation, and data leakage are triggered). Finally, based on the monitoring results and execution logs, the second vulnerability detection result is integrated. This result includes precise source tracing information such as the specific code location of the vulnerability in the target software, the core logic defect that triggers it, the risk level, and the conditions for reproducibility, completing a deep judgment from the anomaly to the root cause of the vulnerability.

[0101] S260. Based on the first vulnerability detection result and the second vulnerability detection result, determine the vulnerability detection result corresponding to the network chip to be detected.

[0102] Optionally, based on the first vulnerability detection result and the second vulnerability detection result, a vulnerability detection result corresponding to the network chip to be detected is determined, including at least one of the following:

[0103] A weighted fusion algorithm is used to weight and fuse the first vulnerability detection result and the second vulnerability detection result to obtain the vulnerability detection result corresponding to the network chip to be detected.

[0104] The second vulnerability detection result is updated into the first vulnerability detection result to obtain the vulnerability detection result corresponding to the network chip to be detected.

[0105] In one embodiment, upon obtaining the second vulnerability detection result, the second vulnerability detection result can be updated into the first vulnerability detection result to improve the first vulnerability detection result, and the improved first vulnerability detection result can be determined as the vulnerability detection result corresponding to the network chip to be detected.

[0106] S270. Determine the security defense decision corresponding to the network chip to be tested based on the anomaly detection results, attack identification results, and vulnerability detection results.

[0107] The technical solution of this invention employs fuzz testing logic to perform fuzz testing on the target software in the network chip under test based on deep detection features and protocol features to obtain a first vulnerability detection result; wherein the first vulnerability detection result includes abnormal input data; employing symbolic execution logic to perform vulnerability detection on the target software in the network chip under test based on the abnormal input data and deep detection features to obtain a second vulnerability detection result; based on the first vulnerability detection result and the second vulnerability detection result, the vulnerability detection result corresponding to the network chip under test is determined. Through the directional initial screening of fuzz testing logic and the precise source tracing of symbolic execution logic, combined with the targeted guidance of deep detection features and protocol features, a comprehensive detection of known and unknown vulnerabilities in the target software of the network chip and precise location of their root causes are achieved, significantly improving the efficiency, coverage and reliability of vulnerability detection.

[0108] Example 3

[0109] Figure 3 This is a schematic diagram of a network chip security detection system provided in Embodiment 3 of the present invention. Figure 3 As shown, the system includes: a signal processing module, a data preprocessing module, a feature extraction module, an artificial intelligence analysis module, a security defense module, a system management and decision-making module, and a user interface module.

[0110] The signal processing module receives and initially processes the raw network signal, and then transmits the preprocessed signal to the data preprocessing module for further processing.

[0111] The signal processing module receives the raw network signals and performs preliminary processing on them to facilitate more effective analysis by subsequent modules. Specifically, this includes: Signal reception: Receiving network signals through the physical layer interface, which may include different types of transmission media such as fiber optics, coaxial cables, and twisted pairs. Signal amplification: Amplifying weak signals to ensure signal strength meets the requirements of subsequent processing. Filtering: Removing noise and interference from the signal using low-pass, high-pass, band-pass, or band-stop filters to improve signal quality. Modulation / demodulation: For analog signals, modulation and demodulation are required to convert them into digital signals for subsequent processing.

[0112] The data preprocessing module further processes the data output by the signal processing module to prepare high-quality data for the feature extraction module. This includes: data cleaning: removing invalid, erroneous, and duplicate data records; and data normalization: scaling the data to a fixed range, such as [0,1], to facilitate comparison of different features.

[0113] The feature extraction module extracts key features from the preprocessed data. These features are then fed into the artificial intelligence analysis module for anomaly detection, attack identification, and vulnerability discovery. The specific functions of the feature extraction module are as follows: Statistical feature extraction: Calculating statistical measures such as the mean, variance, and standard deviation of the data. Protocol feature extraction: Identifying the network protocol to which the data packets belong and extracting protocol-related features. Deep packet inspection (DPI): Performing deep parsing of the data packets to extract application-layer features and obtain deep detection features.

[0114] The artificial intelligence analysis module transmits the data to the system management and decision-making module for security incident management, situational awareness, and strategy optimization.

[0115] The user interface module interacts bidirectionally with the system management and decision-making module, providing administrators with an operation interface, system status display, report generation, and alarm notifications.

[0116] The artificial intelligence analysis module is internally configured with an anomaly detection submodule, an attack identification submodule, a vulnerability discovery submodule, and a model update and iteration submodule.

[0117] The anomaly detection submodule combines two different algorithms: a statistical isolated forest anomaly detection algorithm and a machine learning-based anomaly detection algorithm. The isolated forest algorithm isolates data points by randomly selecting features and split values; the single-class support vector machine algorithm is used for anomaly detection, learning a boundary that contains only positive examples. The isolated forest algorithm calculates the anomaly score for each data point, and the single-class support vector machine algorithm calculates the decision function value for each data point. The two scores are then weighted and summed to obtain the final anomaly score.

[0118] The attack identification submodule uses a convolutional neural network to extract features through convolutional and pooling layers, and then performs classification through a fully connected layer.

[0119] The vulnerability discovery submodule tests the software by generating a large number of random or strategy-specific inputs. Symbolic execution uses symbols to replace specific values ​​for program execution.

[0120] The security defense module implements corresponding defense measures based on the output of the artificial intelligence analysis module to protect the network from potential threats. The internal configuration of the security defense module includes:

[0121] Firewall Adjustment: Firewalls are the first line of defense in network security, used to control traffic entering and leaving the network. Based on anomaly detection results from the AI ​​analysis module, firewall rules can be adjusted to restrict or block potential malicious traffic. This includes creating new rules, modifying existing rules, or deleting rules that are no longer applicable.

[0122] Intrusion Detection System (IDS): An IDS is a system that monitors network traffic and detects potential intrusion activities. It monitors network traffic in real time, identifies abnormal behavior, and logs this behavior for further analysis and investigation. IDS are typically tightly integrated with artificial intelligence analytics modules to improve the accuracy and efficiency of detection.

[0123] Intrusion Prevention System (IPS): An IPS is a proactive defense system that automatically takes measures to block attack traffic when it detects an attack, thereby preventing the attack from succeeding. IPS typically has higher protection capabilities, can respond in real time, and automatically block intrusion attempts, reducing the need for manual intervention.

[0124] The system management and decision-making module is responsible for the operation management and decision support of the entire system. The internal settings of the system management and decision-making module include:

[0125] Security Incident Management: The system management and decision-making module records, analyzes, alerts, and handles security incidents. This includes monitoring system logs, the security incident database, and the alarm system, as well as responding to and processing security incidents. In this way, administrators can promptly understand the system's security status and take appropriate measures.

[0126] Security Situation Awareness: The system management and decision-making module uses visualization technology to display the system's security status, helping administrators intuitively understand the system's security posture. This includes the distribution of security incidents, attack types, and attack frequencies. In this way, administrators can better understand the system's security situation and formulate more effective security strategies.

[0127] Security Policy Formulation: Based on system analysis results, the system management and decision-making module formulates and optimizes security policies. This includes developing new security policies, modifying existing policies, or deleting policies that are no longer applicable. In this way, administrators can ensure that the system can cope with constantly evolving security threats and maintain optimal security performance.

[0128] The user interface module provides an operation interface for administrators and serves as a bridge for interaction between the system and users. The user interface module internally includes:

[0129] Console Interface: The user interface module provides an operational interface for system configuration, monitoring, and management, enabling administrators to easily manage various aspects of the system. This includes configuring firewall rules, viewing security events, and monitoring network traffic.

[0130] Report generation: The user vulnerability discovery submodule utilizes "fuzz testing" technology. The specific steps are as follows: Input generation:

[0131] Random input: Generates a large amount of irregular random data (such as random byte streams or malformed data packets).

[0132] Specific strategy input: Generate targeted test cases based on known vulnerability patterns or protocol specifications (such as boundary values, format errors, and abnormal values ​​of protocol fields).

[0133] Test execution: Inject the generated input into the target software (such as network chip firmware, protocol parsing module) to simulate normal or abnormal call scenarios.

[0134] Anomaly monitoring: Monitors the software's running status and records abnormal behaviors such as crashes, memory leaks, timeouts, and assertion failures.

[0135] Vulnerability localization: Analyze the input test cases that trigger the anomaly, use debugging tools to locate the vulnerability (e.g., line of code, function call stack), and generate a vulnerability report. The interface module regularly generates security reports reflecting the system's operational status. These reports help administrators understand the system's security performance and evaluate the effectiveness of security policies.

[0136] Alarm notifications: The user interface module promptly notifies administrators of security incidents via email, SMS, and other means. This helps administrators respond to security threats in a timely manner and take appropriate measures.

[0137] In this invention, by combining the Isolation Forest and Support Vector Machine (SVM) algorithms, the artificial intelligence (AI) analysis module can more accurately identify abnormal traffic. The Isolation Forest algorithm isolates data points by randomly selecting features and segmentation values, while the SVM algorithm learns a boundary containing only normal data. By weighted summation of the results from these two algorithms, a more comprehensive anomaly score can be obtained, thereby improving the accuracy of anomaly detection. Using convolutional neural networks, the AI ​​analysis module can extract features from data packets and identify known attack patterns. Furthermore, through fuzz testing and symbolic execution techniques, potential security vulnerabilities can be discovered, providing a deeper security analysis for the system. The AI ​​analysis module can analyze network traffic in real time and transmit the detection results to the security defense module. Based on these results, the security defense module can implement measures such as firewall adjustments, intrusion detection, and defense systems to protect the network from potential threats.

[0138] In this invention, the analysis results from the artificial intelligence analysis module help the system management and decision-making module formulate and optimize security strategies. By recording, analyzing, and processing security events, the system management and decision-making module can help administrators understand the system's security status in a timely manner and take appropriate measures. The user interface module provides functions such as a console interface, report generation, and alarm notifications, enabling administrators to easily monitor and manage the system. This helps improve administrator efficiency and ensures the system operates efficiently and stably.

[0139] The beneficial effects of the artificial intelligence analysis module in this system are that it improves the system's security performance, enables real-time detection and response to security threats, and provides administrators with better system management and decision support.

[0140] Example 4

[0141] Figure 4 This is a schematic diagram of the structure of a network chip security detection device provided in Embodiment 4 of the present invention. Figure 4 As shown, the device includes: a signal feature extraction module 310, an anomaly detection module 320, an attack identification module 330, a vulnerability detection module 340, and a defense decision determination module 350. Specifically, the signal feature extraction module 310 acquires the digital network signal of the network chip under test and extracts features from the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal; the anomaly detection module 320 determines the anomaly detection result corresponding to the network chip under test based on the anomaly detection unit, the statistical features, and the protocol features; the attack identification module 330 determines the attack identification result corresponding to the network chip under test based on the attack identification unit, the deep detection features, and the protocol features; the vulnerability detection module 340 determines the vulnerability detection result corresponding to the network chip under test based on the vulnerability detection unit, the deep detection features, and the protocol features; and the defense decision determination module 350 determines the security defense decision corresponding to the network chip under test based on the anomaly detection result, the attack identification result, and the vulnerability detection result.

[0142] The technical solution of this invention acquires the digital network signal of the network chip under test and extracts features from the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal. This achieves full-coverage extraction of multi-dimensional features of the digital network signal, from surface statistical patterns and protocol compliance attributes to deep application-layer business logic. This provides accurate and comprehensive feature input for subsequent anomaly detection, attack identification, and vulnerability detection of the network chip under test, laying the foundation for multi-dimensional collaborative security detection. Furthermore, by determining the anomaly detection result corresponding to the network chip under test based on the anomaly detection unit, statistical features, and protocol features, and through the collaborative input of statistical features (surface traffic patterns) and protocol features (protocol compliance attributes), combined with the analytical capabilities of the anomaly detection unit, accurate identification and rapid judgment of network chip traffic anomalies are achieved. This provides a targeted and highly reliable triggering basis for subsequent basic anomaly defense decisions. Furthermore, by determining the attack identification results corresponding to the network chip under test based on the attack identification unit, deep detection features, and protocol features, and leveraging the application-layer deep logic parsing capabilities of deep detection features and the compliance verification advantages of protocol features, combined with the analysis functions of the attack identification unit, accurate identification and localization of the attack type and characteristics of the network chip can be achieved, providing a core and reliable technical basis for subsequent targeted attack defense decisions. Furthermore, by determining the vulnerability detection results corresponding to the network chip under test based on the vulnerability detection unit, deep detection features, and protocol features, and leveraging the application-layer deep logic targeting of deep detection features and the protocol-layer compliance verification capabilities of protocol features, combined with the dual-technology collaborative detection function of the vulnerability detection unit, accurate localization and comprehensive detection of target software vulnerabilities in the network chip can be achieved, providing a core basis that is both targeted and feasible for subsequent vulnerability remediation decisions. Furthermore, by determining the security defense decisions corresponding to the network chip under test based on anomaly detection results, attack identification results, and vulnerability detection results, and by integrating multi-dimensional security data from anomaly detection results, attack identification results, and vulnerability detection results, a comprehensive assessment of network chip security risks can be achieved, outputting precise and targeted security defense decisions, forming a closed-loop protection from risk detection to decision generation, and comprehensively ensuring the operational security of the network chip.The technical solution of this invention addresses the problems in related technologies that rely on manual summarization and input of known attack cases, which suffers from significant lag, cannot effectively identify new and unknown attacks, and cannot meet the needs of real-time security protection. By using multi-dimensional feature collaboration and multi-unit linkage detection, it accurately identifies abnormal traffic, network attacks, and chip vulnerabilities. Furthermore, by integrating multi-dimensional security data from anomaly detection results, attack identification results, and vulnerability detection results, it achieves a comprehensive assessment of network chip security risks, improving the accuracy of network chip security detection. It balances the real-time nature and comprehensiveness of security detection, constructing a closed-loop protection system from feature extraction to multi-dimensional detection to precise decision-making, effectively meeting the real-time security protection needs of network chips.

[0143] Optionally, the signal feature extraction module 310 includes: a raw signal acquisition unit, an information modulation unit, and an information preprocessing unit. The raw signal acquisition unit is used to acquire the raw network signal transmitted by the network chip under test; the information modulation unit is used to perform signal processing on the raw network signal to obtain an analog network signal, and to perform signal modulation on the analog network signal to obtain a digital network signal to be processed; wherein the signal processing includes at least one of signal amplification and signal filtering; the information preprocessing unit is used to preprocess the digital network signal to be processed to obtain the digital network signal of the network chip under test; wherein the preprocessing includes at least one of data cleaning and data normalization.

[0144] Optionally, the signal feature extraction module 310 includes: a statistical feature extraction unit, a protocol feature extraction unit, and a deep feature extraction unit. The statistical feature extraction unit performs statistical analysis on the digital network signal to obtain statistical features corresponding to the digital network signal; wherein the statistical features include at least one of mean, variance, and standard deviation. The protocol feature extraction unit determines the network protocol type to which the digital network signal belongs and extracts protocol features corresponding to the digital network signal from pre-stored protocol type correspondence information based on the network protocol type. The deep feature extraction unit performs application layer deep analysis on the digital network signal to obtain deep detection features corresponding to the digital network signal.

[0145] Optionally, the anomaly detection unit includes an algorithm module integrating the isolated forest algorithm and the support vector machine algorithm; the anomaly detection module 320 includes: a first detection result determination unit, a second detection result determination unit, and an anomaly detection result determination unit. The first detection result determination unit is used to process the statistical features and the protocol features according to the isolated forest algorithm to obtain a first anomaly detection result; the second detection result determination unit is used to process the statistical features and the protocol features according to the support vector machine algorithm to obtain a second anomaly detection result; the anomaly detection result determination unit is used to determine the anomaly detection result corresponding to the network chip to be detected based on the first anomaly detection result and the second anomaly detection result.

[0146] Optionally, the anomaly detection result determination unit is specifically used to determine a first weight corresponding to the first anomaly detection result and a second weight corresponding to the second anomaly detection result; and to process the first anomaly detection result, the first weight, the second anomaly detection result and the second weight through a weighted fusion algorithm to obtain an anomaly detection result corresponding to the network chip to be detected.

[0147] Optionally, the attack identification unit includes an attack identification model; the attack identification module 330 is specifically used to provide the deep detection features and the protocol features to the attack identification model in order to obtain the output attack identification result corresponding to the network chip to be detected.

[0148] Optionally, the vulnerability detection unit includes an integrated module that integrates fuzzing logic and symbolic execution logic; the vulnerability detection module 340 includes: a first detection result determination unit, a second detection result determination unit, and a vulnerability detection result determination unit. The first detection result determination unit is used to perform fuzzing on the target software in the network chip under test using fuzzing logic based on the deep detection features and the protocol features to obtain a first vulnerability detection result; wherein the first vulnerability detection result includes abnormal input data; the second detection result determination unit is used to perform vulnerability detection on the target software in the network chip under test using symbolic execution logic based on the abnormal input data and the deep detection features to obtain a second vulnerability detection result; the vulnerability detection result determination unit is used to determine the vulnerability detection result corresponding to the network chip under test based on the first vulnerability detection result and the second vulnerability detection result.

[0149] Optionally, the apparatus further includes a unit update module. The unit update module is used to acquire network attack samples and network vulnerability data, and update the anomaly detection unit and the attack identification unit based on the network attack samples and the network vulnerability data.

[0150] Optionally, the defense decision determination module 350 includes: an anomaly defense decision determination unit, an attack defense decision determination unit, and a vulnerability remediation decision determination unit. The anomaly defense decision determination unit is used to determine an anomaly defense decision corresponding to the network chip under test based on the anomaly detection result; wherein the anomaly defense decision includes at least one of the following: adjusting firewall rules; restricting access permissions; or initiating a traffic limiting mechanism for the network chip under test. The attack defense decision determination unit is used to determine an attack defense decision corresponding to the network chip under test based on the attack type determined according to the attack identification result. The vulnerability remediation decision determination unit is used to determine a vulnerability remediation decision corresponding to the network chip under test based on the network vulnerability identified according to the vulnerability detection result.

[0151] The network chip security detection device provided in this embodiment of the invention can execute the network chip security detection method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method.

[0152] Example 5

[0153] Figure 5 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0154] like Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0155] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0156] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as network chip security detection methods.

[0157] In some embodiments, the network chip security detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the network chip security detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the network chip security detection method by any other suitable means (e.g., by means of firmware).

[0158] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0159] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0160] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0161] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0162] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), target blockchain networks, and the Internet.

[0163] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0164] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication unit 19, or installed from storage unit 18, or installed from ROM 12. When the computer program is executed by processor 11, it performs the functions defined in the methods of the embodiments of the present invention.

[0165] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0166] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A network chip security detection method, characterized in that, include: The digital network signal of the network chip to be tested is acquired, and the digital network signal is subjected to feature extraction to obtain the statistical features, protocol features and deep detection features corresponding to the digital network signal. The anomaly detection result corresponding to the network chip to be detected is determined based on the anomaly detection unit, the statistical features, and the protocol features; and... The attack identification result corresponding to the network chip to be detected is determined based on the attack identification unit, the deep detection features, and the protocol features; and... The vulnerability detection result corresponding to the network chip to be detected is determined based on the vulnerability detection unit, the deep detection features, and the protocol features. Based on the anomaly detection results, the attack identification results, and the vulnerability detection results, a security defense decision is determined corresponding to the network chip to be detected.

2. The network chip security detection method according to claim 1, characterized in that, The acquisition of the digital network signal of the network chip to be detected includes: Collect the raw network signals transmitted by the network chip under test; The original network signal is processed to obtain an analog network signal, and the analog network signal is modulated to obtain a digital network signal to be processed; wherein, the signal processing includes at least one of signal amplification and signal filtering; The digital network signal to be processed is preprocessed to obtain the digital network signal of the network chip to be detected; wherein the preprocessing includes at least one of data cleaning and data normalization.

3. The network chip security detection method according to claim 1, characterized in that, The step of extracting features from the digital network signal to obtain statistical features, protocol features, and deep detection features corresponding to the digital network signal includes: Statistical analysis is performed on the digital network signal to obtain statistical characteristics corresponding to the digital network signal; wherein, the statistical characteristics include at least one of the mean, variance, and standard deviation; Determine the network protocol type to which the digital network signal belongs, and extract the protocol features corresponding to the digital network signal from the pre-stored protocol type correspondence information based on the network protocol type; The digital network signal is subjected to application-layer deep analysis to obtain deep detection features corresponding to the digital network signal.

4. The network chip security detection method according to claim 1, characterized in that, The anomaly detection unit includes an algorithm module that integrates the isolated forest algorithm and the support vector machine algorithm; The step of determining the anomaly detection result corresponding to the network chip to be detected based on the anomaly detection unit, the statistical features, and the protocol features includes: The statistical features and protocol features are processed using the isolated forest algorithm to obtain a first anomaly detection result; and, The statistical features and protocol features are processed using the support vector machine algorithm to obtain the second anomaly detection result; The anomaly detection result corresponding to the network chip to be detected is determined based on the first anomaly detection result and the second anomaly detection result.

5. The network chip security detection method according to claim 4, characterized in that, The step of determining the anomaly detection result corresponding to the network chip to be detected based on the first anomaly detection result and the second anomaly detection result includes: Determine a first weight corresponding to the first anomaly detection result and a second weight corresponding to the second anomaly detection result; The first anomaly detection result, the first weight, the second anomaly detection result, and the second weight are processed by a weighted fusion algorithm to obtain an anomaly detection result corresponding to the network chip to be detected.

6. The network chip security detection method according to claim 1, characterized in that, The attack identification unit includes an attack identification model; determining the attack identification result corresponding to the network chip to be detected based on the attack identification unit, the deep detection features, and the protocol features includes: The deep detection features and the protocol features are provided to the attack identification model to obtain the attack identification result corresponding to the network chip to be detected.

7. The network chip security detection method according to claim 1, characterized in that, The vulnerability detection unit includes an integrated module that integrates fuzz testing logic and symbolic execution logic; The step of determining the vulnerability detection result corresponding to the network chip to be detected based on the vulnerability detection unit, the deep detection features, and the protocol features includes: Using fuzz testing logic, fuzz testing is performed on the target software in the network chip to be tested based on the deep detection features and the protocol features to obtain a first vulnerability detection result; wherein, the first vulnerability detection result includes abnormal input data; Symbolic execution logic is used to perform vulnerability detection on the target software in the network chip under test based on the abnormal input data and the deep detection features, so as to obtain a second vulnerability detection result; Based on the results of the first and second vulnerability detections, the vulnerability detection results corresponding to the network chip to be detected are determined.

8. The network chip security detection method according to claim 1, characterized in that, Also includes: The system acquires network attack samples and network vulnerability data, and updates the anomaly detection unit and the attack identification unit based on the network attack samples and network vulnerability data.

9. The network chip security detection method according to claim 1, characterized in that, The step of determining the security defense decision corresponding to the network chip to be detected based on the anomaly detection result, the attack identification result, and the vulnerability detection result includes: Based on the anomaly detection results, an anomaly defense decision corresponding to the network chip under test is determined; wherein, the anomaly defense decision includes at least one of the following: adjusting firewall rules; restricting access permissions; or activating a traffic limiting mechanism for the network chip under test; If the type of network attack attacking the network chip to be detected is determined based on the attack identification result, an attack defense decision corresponding to the network chip to be detected is determined based on the type of network attack. If a network vulnerability is identified in the network chip to be tested based on the vulnerability detection results, a vulnerability remediation decision corresponding to the network chip to be tested is determined based on the network vulnerability.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the network chip security detection method as described in any one of claims 1-9.