Network data security testing methods and systems based on big data
By employing a big data-based network data security testing method that combines encryption and speed loss coefficients, the strength and coverage of sniffing signals are detected, and the defect deformation level of the encryption module is quantified. This solves the problem that existing technologies cannot fully quantify the impact of sniffing interference and encryption defects, and enables rapid tracing and precise control of network data security risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 合肥理微大数据有限公司
- Filing Date
- 2026-03-24
- Publication Date
- 2026-05-26
AI Technical Summary
Existing network data security testing methods cannot fully quantify the combined impact of sniffing interference and encryption flaws, making it difficult to quickly identify the specific locations and risk levels of data leaks, and thus failing to meet the needs of network data security protection and rapid response.
The network data security testing method based on big data collects initial security test data and real-time transmission rate, combines historical network data to calculate the encryption loss coefficient and speed loss coefficient, detects the sniffing signal strength and coverage, quantifies the defect deformation level of the encryption module, and outputs security leakage early warning and location results.
It enables rapid tracing and precise control of network data security risks, identifies the specific location and risk level of data leaks, improves the objectivity and reliability of security testing, shortens the response time from anomaly discovery to location and handling, and reduces the risk of data leaks.
Smart Images

Figure CN121907618B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network data security technology, and more specifically, to a network data security testing method and system based on big data. Background Technology
[0002] While encryption protocols in network data transmission environments ensure data confidentiality, they render traditional detection methods ineffective. Attackers exploit encryption features to conceal sniffing attacks, posing a hidden threat to data transmission in encrypted segments. Existing security testing relies on single indicators or partial data, making it difficult to comprehensively quantify the combined impact of sniffing interference and encryption flaws. Abnormal fluctuations in network transmission rates can trigger data breaches. Traditional methods lack the ability to quantify the correlation between rate changes and breaches, failing to distinguish between basic security conditions and abnormal impacts, leading to biased test results. Furthermore, traditional testing struggles to quickly identify the specific locations and risk levels of data breaches, thus failing to meet the practical needs of network data security protection and rapid response. Summary of the Invention
[0003] In view of the shortcomings of existing technologies, the purpose of this invention is to provide a network data security testing method and system based on big data.
[0004] To achieve the above objectives, the present invention provides the following technical solution:
[0005] A network data security testing method based on big data, which includes the following steps:
[0006] Collect initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link;
[0007] Based on historical network data, we obtained the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change.
[0008] Extract the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtain the current rate variation value based on the link transmission rate and the rate threshold, and obtain the leakage rate loss value based on the rate loss coefficient and the current rate variation value.
[0009] The sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level are detected, and the effective processing sniffing value is obtained based on the sniffing signal strength and sniffing coverage.
[0010] Based on historical network data and effective processing of sniffed values, the defect deformation level of the encryption module is obtained; the leakage loss value is obtained according to the loss coefficient and the defect deformation level; and the actual security test data is obtained according to the leakage rate loss value, the leakage loss value, and the initial security test data.
[0011] Output security leak warning and location results based on actual security test data.
[0012] Preferably, the encryption vulnerability coefficient related to the encryption defect level and the rate loss coefficient related to the rate change are obtained based on historical network data, specifically including the following steps:
[0013] The historical defect levels corresponding to the data encryption modules are extracted from historical network data, and the historical leakage and loss values of the historical defect levels affecting the historical test data links are extracted.
[0014] The density loss coefficient is obtained by comparing the historical leakage density loss value with the historical defect level.
[0015] Extract historical abnormal rate values from historical network data, where the transmission rate exceeds the rate threshold.
[0016] The historical rate change amplitude is obtained by subtracting the historical abnormal rate value and the rate threshold.
[0017] Historical leakage rate loss values of historical test data links are extracted from historical network data, reflecting the impact of historical rate change amplitudes on historical rate loss values.
[0018] The rate loss coefficient is obtained by comparing the historical leakage rate loss value with the historical rate change amplitude.
[0019] Preferably, the current rate variation value is obtained based on the link transmission rate and the rate threshold, specifically including the following steps:
[0020] The link transmission rate corresponding to several rate segments in a continuous transmission period is divided into multiple segmented rates.
[0021] The average value of the segmented rate is obtained by calculating the mean of the rates of each segment.
[0022] The average segmented rate that exceeds the rate threshold is marked as the target segmented rate value;
[0023] The difference between the target segment rate value and the rate threshold is used to obtain the rate difference of each segment.
[0024] The current rate variation value is obtained by summing up all segment rate differences.
[0025] Preferably, the leakage rate loss value is obtained based on the rate loss coefficient and the current rate variation value, specifically including the following steps:
[0026] The rate anomaly impact factor is obtained by fusing the rate loss coefficient with the weight corresponding to the current rate variation value.
[0027] The rate influence factor is obtained by normalizing the rate anomaly influence factor.
[0028] The leakage rate loss value is obtained by hierarchically associating the rate influence factor with the current rate variation value.
[0029] Preferably, the effective processed sniffing value is obtained based on the sniffing signal strength and sniffing coverage area, specifically including the following steps:
[0030] Capture sniffing signals for encrypted segments corresponding to the encryption vulnerability level;
[0031] The sniffing signal strength is divided into different levels based on the degree of interference of the sniffing signal on the data transmission of the encrypted segment, and the degree of influence of the strength corresponding to each level is determined.
[0032] The sniffing coverage of the encrypted section corresponding to the encryption defect level is detected, the length of the encrypted section covered by the sniffing signal and the key transmission nodes are determined, and the security impact boundary of the sniffing coverage on the encrypted section data is clarified based on the length of the encrypted section and the key transmission nodes.
[0033] The influence weights of the sniffing signal strength and the sniffing coverage area are determined based on the degree of influence of the intensity and the security impact boundary.
[0034] The sniffing signal strength is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing signal strength, and the sniffing coverage is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing coverage.
[0035] By integrating the weighted influence value of the sniffing signal strength with the weighted influence value of the sniffing coverage area, an effective processed sniffing value is obtained.
[0036] Preferably, the defect deformation level of the encryption module is obtained based on historical network data and effective processing of sniffed values, specifically including the following steps:
[0037] The historical deformation defect level of the data encryption module is extracted from historical network data, which is affected by the historical effective sniffing values on defect changes.
[0038] The historical level deformation value is obtained by performing a difference calculation between the historical deformation defect level and the corresponding historical defect level.
[0039] The sniffing deformation level factor is obtained by comparing the historical level deformation value with the historical effective sniffing value.
[0040] The defect deformation level of the data encryption module is obtained based on the sniffing deformation level factor and the effective processing of sniffing values.
[0041] Preferably, the leakage density value is obtained based on the density coefficient and the defect deformation level, specifically including the following steps:
[0042] The density loss coefficient is calibrated by performing an adaptation calibration.
[0043] The defect deformation level is decomposed into a hierarchical structure to obtain the basic failure level and the derived failure level of the encryption module; wherein, the basic failure level corresponds to the inherent defect level of the encryption module, and the derived failure level corresponds to the degree of chain failure caused by the basic failure.
[0044] The calibrated security loss coefficient is correlated with the basic failure level and the derived failure level to obtain the basic security loss component and the derived security loss component; wherein, the basic security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the inherent defects of the encryption module, and the derived security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the chain failure.
[0045] The leakage loss value is obtained by fusing the basic loss component and the derived loss component.
[0046] Preferably, the actual safety test data is obtained based on the leakage rate loss value, leakage density loss value, and initial safety test data, specifically including the following steps:
[0047] Based on the leakage rate loss value and leakage density loss value, retain the initial security test data that reflects the basic security status of the target data link to obtain the initial security test status data;
[0048] The initial safety test status data is correlated with the leakage rate loss value and leakage density loss value to obtain the initial correlation data;
[0049] Actual security test data is obtained based on the leakage rate loss value reflecting the impact of rate fluctuation leakage, the leakage security loss value reflecting the impact of encryption defect leakage, and the initial security data reflecting the basic security status.
[0050] Preferably, the output of security leak warning and location results based on actual security test data specifically includes the following steps:
[0051] Based on actual security test data, characteristic segments representing link transmission anomalies are obtained;
[0052] The range of encrypted segments with data transmission anomalies is obtained based on the correspondence between feature segments and encrypted segments.
[0053] Based on the effective processing of sniffing values, the abnormal distribution of sniffing signals within the encrypted section is investigated, and the link points interfering with the sniffing signals are obtained;
[0054] Determine whether a link location is a target location for data leakage based on the level of defect deformation.
[0055] Based on the location information of the target point and the degree of correlation with the leak, a security leak early warning and location result is generated, which includes the specific location and risk level.
[0056] A network data security testing system based on big data includes:
[0057] Acquisition module: Acquires initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link;
[0058] The first processing module obtains the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change based on historical network data.
[0059] The second processing module extracts the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtains the current rate variation value based on the link transmission rate and the rate threshold, and obtains the leakage rate loss value based on the rate loss coefficient and the current rate variation value.
[0060] Detection and processing module: detects the sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level, and obtains the effective processing sniffing value based on the sniffing signal strength and sniffing coverage.
[0061] The third processing module: Based on historical network data and effectively processed sniffing values, it obtains the defect deformation level of the encryption module; based on the security loss coefficient and defect deformation level, it obtains the leakage security loss value; based on the leakage rate loss value, the leakage security loss value, and the initial security test data, it obtains the actual security test data.
[0062] Output module: Outputs security leak warning and location results based on actual security test data.
[0063] Compared with the prior art, the present invention has the following beneficial effects:
[0064] This invention introduces encryption loss coefficients and rate loss coefficients, and combines them with historical network data to quantify encryption defects and rate fluctuations. This makes the leakage rate loss value and leakage encryption loss value more closely reflect the actual network environment, improving the objectivity and reliability of the test data. Through anomaly extraction of real-time transmission rates, weighted integration of sniffing signal strength and coverage, and hierarchical decomposition of defect deformation levels, it isolates the basic security status and abnormal influencing factors from network data, thereby obtaining actual security test data. This data comprehensively reflects the true operating status of the link, avoiding misjudgments caused by single indicators or partial data, enabling the characterization of data leakage risks, improving security testing and early warning efficiency, shortening the response time from anomaly discovery to location and handling, and achieving rapid tracing and precise control of network data security risks. It not only identifies the specific location and risk level of data leakage but also provides actionable measures for network security operations and maintenance, effectively reducing data leakage risks and thus improving overall network data security protection capabilities. Attached Figure Description
[0065] Figure 1 A schematic diagram illustrating the steps of a network data security testing method based on big data is provided for embodiments of the present invention.
[0066] Figure 2 A schematic diagram of a network data security testing system based on big data is provided for embodiments of the present invention. Detailed Implementation
[0067] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0068] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0069] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places throughout this specification does not necessarily refer to the same embodiment, nor is it a single embodiment or an embodiment selectively excluded from other embodiments.
[0070] Reference Figures 1-2 As shown.
[0071] The embodiments further illustrate the network data security testing method and system based on big data proposed in this invention.
[0072] A network data security testing method based on big data, which includes the following steps:
[0073] Collect initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link;
[0074] Based on historical network data, we obtained the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change.
[0075] Extract the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtain the current rate variation value based on the link transmission rate and the rate threshold, and obtain the leakage rate loss value based on the rate loss coefficient and the current rate variation value.
[0076] The sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level are detected, and the effective processing sniffing value is obtained based on the sniffing signal strength and sniffing coverage.
[0077] Based on historical network data and effective processing of sniffed values, the defect deformation level of the encryption module is obtained; the leakage loss value is obtained according to the loss coefficient and the defect deformation level; and the actual security test data is obtained according to the leakage rate loss value, the leakage loss value, and the initial security test data.
[0078] Output security leak warning and location results based on actual security test data.
[0079] The encryption loss coefficient related to the encryption vulnerability level and the rate loss coefficient related to rate change are obtained based on historical network data, specifically including the following steps:
[0080] The historical defect levels corresponding to the data encryption modules are extracted from historical network data, and the historical leakage and loss values of the historical defect levels affecting the historical test data links are extracted.
[0081] The density loss coefficient is obtained by comparing the historical leakage density loss value with the historical defect level.
[0082] Extract historical abnormal rate values from historical network data, where the transmission rate exceeds the rate threshold.
[0083] The historical rate change amplitude is obtained by subtracting the historical abnormal rate value and the rate threshold.
[0084] Historical leakage rate loss values of historical test data links are extracted from historical network data, reflecting the impact of historical rate change amplitudes on historical rate loss values.
[0085] The rate loss coefficient is obtained by comparing the historical leakage rate loss value with the historical rate change amplitude.
[0086] Extract the historical defect level corresponding to the data encryption module from historical network data. At the same time, extract the historical leakage loss value of the impact of the historical defect level on the historical test data link. Ratio the historical leakage loss value with the historical defect level to obtain the loss coefficient related to the encryption defect level. For example, if the historical defect level of a certain encryption module is level 6, and then the data link leakage caused by this level of defect in historical tests is obtained by statistical analysis of historical network data, the quantitative value is 36. This value is the historical leakage loss value. The historical leakage loss value is equal to the historical leakage quantification result corresponding to the historical defect level. In this scenario, the historical leakage loss value = 36, then the loss coefficient = 36 ÷ 6 = 6.
[0087] Extract historical abnormal rate values from historical network data that have a transmission rate greater than the rate threshold. Calculate the difference between the historical abnormal rate value and the rate threshold to obtain the historical rate change amplitude. For example, if the rate threshold is 80 megabits per second and the historical abnormal rate value is 120 megabits per second, then the historical rate change amplitude = 120 - 80 = 40 megabits per second.
[0088] The historical leakage rate loss value is extracted from historical network data to determine the impact of historical rate change amplitude on historical test data links. For example, historical abnormal rate values with transmission rates exceeding the rate threshold are extracted from historical network data, and the difference between these values and the rate threshold is calculated to obtain the historical rate change amplitude. Finally, the actual impact of this amplitude on the historical test data links is quantified and statistically analyzed. First, the rate threshold is determined to be 80 Mbps. The historical abnormal rate value extracted from historical data is 120 Mbps. By calculating the difference, the historical rate change amplitude is found to be 40 Mbps. The quantified value of the data link leakage caused by this historical rate change amplitude in historical tests is 20, which is the historical leakage rate loss value. The rate loss coefficient is obtained by comparing the historical leakage rate loss value with the historical rate change amplitude, i.e., rate loss coefficient = 20 ÷ 40 = 0.5.
[0089] The current rate variation is obtained based on the link transmission rate and the rate threshold, specifically including the following steps:
[0090] The link transmission rate corresponding to several rate segments in a continuous transmission period is divided into multiple segmented rates.
[0091] The average value of the segmented rate is obtained by calculating the mean of the rates of each segment.
[0092] The average segmented rate that exceeds the rate threshold is marked as the target segmented rate value;
[0093] The difference between the target segment rate value and the rate threshold is used to obtain the rate difference of each segment.
[0094] The current rate variation value is obtained by summing up all segment rate differences.
[0095] The link transmission rate of a continuous transmission period is divided into several rate segments to obtain multiple segmented rates. For example, a 10-minute continuous transmission period is divided into 2-minute segments, resulting in 5 segmented rates: 110 Mbps, 120 Mbps, 90 Mbps, 130 Mbps, and 100 Mbps. Then, the average of each segmented rate is calculated to obtain the average segmented rate: Average Segmented Rate = (110 + 120 + 90 + 130 + 100) ÷ 5 = 110 Mbps. Segments exceeding the rate threshold are then... The average segment rate is marked as the target segment rate value. Assuming the rate threshold is 100 megabits per second, the target segment rate values are 110 megabits per second, 120 megabits per second, and 130 megabits per second. The difference between the target segment rate value and the rate threshold is calculated to obtain the segment rate difference value, i.e., 110-100=10 megabits per second, 120-100=20 megabits per second, and 130-100=30 megabits per second. Finally, the current rate variation value is obtained by summing all the segment rate differences, which is 10+20+30=60 megabits per second.
[0096] The leakage rate loss value is obtained based on the rate loss coefficient and the current rate variation value, specifically including the following steps:
[0097] The rate anomaly impact factor is obtained by fusing the rate loss coefficient with the weight corresponding to the current rate variation value.
[0098] The rate influence factor is obtained by normalizing the rate anomaly influence factor.
[0099] The leakage rate loss value is obtained by hierarchically associating the rate influence factor with the current rate variation value.
[0100] First, the rate anomaly impact factor is obtained by fusing the rate loss coefficient with the weight corresponding to the current rate variation value. For example, if the rate loss coefficient is 0.5 and the weight corresponding to the current rate variation value is 0.6, then the rate anomaly impact factor = 0.5 × 0.6 = 0.3.
[0101] The rate anomaly impact factor is obtained by normalizing the rate anomaly impact factor. Assuming the normalization coefficient is 10, the rate impact factor = 0.3 × 10 = 3. Finally, the rate impact factor and the current rate variation value are processed through hierarchical correlation to obtain the leakage rate loss value. The current rate variation value is 60 megabits per second, so the leakage rate loss value = 3 × 60 = 180, thus quantifying the risk of data leakage caused by rate anomalies.
[0102] The effective processed sniffing value is obtained based on the sniffing signal strength and sniffing coverage area, specifically including the following steps:
[0103] Capture sniffing signals for encrypted segments corresponding to the encryption vulnerability level;
[0104] The sniffing signal strength is divided into different levels based on the degree of interference of the sniffing signal on the data transmission of the encrypted segment, and the degree of influence of the strength corresponding to each level is determined.
[0105] The sniffing coverage of the encrypted section corresponding to the encryption defect level is detected, the length of the encrypted section covered by the sniffing signal and the key transmission nodes are determined, and the security impact boundary of the sniffing coverage on the encrypted section data is clarified based on the length of the encrypted section and the key transmission nodes.
[0106] The influence weights of the sniffing signal strength and the sniffing coverage area are determined based on the degree of influence of the intensity and the security impact boundary.
[0107] The sniffing signal strength is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing signal strength, and the sniffing coverage is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing coverage.
[0108] By integrating the weighted influence value of the sniffing signal strength with the weighted influence value of the sniffing coverage area, an effective processed sniffing value is obtained.
[0109] The system captures all sniffing signals within the corresponding encrypted segment for each encryption vulnerability level. Encrypted segments with different vulnerability levels exhibit distinct differences in their resistance to sniffing; segments with higher vulnerability levels are more likely to become targets for sniffing attacks. Therefore, the system identifies the encrypted segment that perfectly matches the current encryption vulnerability level and continuously collects all sniffing signals present in the link throughout the entire data transmission cycle of that segment. This approach avoids introducing invalid interference signals from non-target segments and also prevents the detection of hidden sniffing signals within the target segment. When an encrypted segment of a data transmission link is determined to have a level 2 encryption vulnerability, the system locates the encrypted segment corresponding to that level 2 vulnerability and completely captures all sniffing signals within that link segment.
[0110] Based on the degree of interference of sniffing signals on encrypted data transmission, the strength of sniffing signals is divided into different levels, and the corresponding strength impact level of each level is determined. The security threat of sniffing signals stems from their ability to interfere with encrypted data transmission, rather than simply their physical signal strength. Therefore, the actual interference level is used as the criterion to establish a correspondence between interference level and strength level, completing the level matching and impact level assignment for each signal. When the sniffing signal can only capture data packet information in the encrypted segment and cannot interfere with the normal transmission of the data packets, the interference level is extremely low, and it is classified as level 1 strength, with a corresponding strength impact level set to 0.2. When the sniffing signal can intercept complete encrypted data packets, causing a slight delay in data packet transmission, the interference level is moderate, and it is classified as level 2 strength, with a corresponding strength impact level set to 0.5. When the sniffing signal can tamper with the transmission path of encrypted data packets, causing data packet loss or mistransmission, the interference level is extremely high, and it is classified as level 3 strength, with a corresponding strength impact level set to 0.9. This avoids the assessment error of judging security threats solely based on physical signal strength.
[0111] The sniffing coverage area of the target encrypted segment is detected to determine the length of the encrypted segment covered by the sniffing signal and the key transmission nodes. Based on the length of the encrypted segment and the key transmission nodes, the security impact boundary of the sniffing coverage area on the encrypted segment data is clarified. The security threat of sniffing attacks comes not only from the signal's interference capability but also from its coverage area. The longer the encrypted segment and the more key nodes covered, the more data can be stolen and the more transmission links are affected, resulting in a greater security threat. A full-link scan of the target encrypted segment is performed to detect and capture the actual physical length of the encrypted segment covered by the sniffing signal. At the same time, key transmission nodes within the coverage area are identified, including data encryption nodes, data forwarding nodes, and data verification nodes. These nodes directly determine the security of encrypted data transmission. The security impact boundary is determined based on the length of the covered segment and the number of key nodes. For example, if the sniffing signal only covers 10% of the encrypted segment and does not cover any key transmission nodes, the security impact boundary is limited to the non-core transmission segment, and its impact on data security is determined to be minimal. If the sniffing signal covers 60% of the encrypted segment and covers key transmission nodes of both data encryption nodes and data forwarding nodes, the security impact boundary is extended to the entire core encrypted transmission process, and its impact on data security is determined to be substantial.
[0112] The influence weights of the sniffing signal strength and sniffing coverage are determined based on the degree of influence and the security impact boundary. Weight allocation differentiates the actual contribution of signal strength and coverage to security threats in different scenarios, avoiding assessment errors caused by fixed weights. It strictly adheres to the following principles: For example, if the influence level is 0.9 (extremely high interference) and the security impact boundary is only in non-core transmission sections, the sniffing signal strength is assigned an influence weight of 0.7, and the sniffing coverage is assigned an influence weight of 0.3. If the security impact boundary covers the entire core encrypted transmission process, and the influence level is only 0.2 (extremely low interference), the sniffing coverage is assigned an influence weight of 0.8, and the sniffing signal strength is assigned an influence weight of 0.2. When the threat levels of the influence level and the security impact boundary are equal, they are assigned equal weights, i.e., an influence weight of 0.5.
[0113] The sniffing signal strength is matched with its corresponding influence weight to obtain the weighted influence value of the sniffing signal strength, and the sniffing coverage area is matched with its corresponding influence weight to obtain the weighted influence value of the sniffing coverage area. Specifically, the weighted influence value of the sniffing signal strength = sniffing signal strength value × corresponding influence weight. For example, if the sniffing signal strength value is 85 and the corresponding influence weight is 0.6, then the weighted influence value of the sniffing signal strength = 85 × 0.6 = 51. The formula for calculating the weighted influence value of the sniffing coverage area is: Weighted influence value of sniffing coverage area = sniffing coverage area value × corresponding influence weight. The sniffing coverage area value is a standardized value converted based on the proportion of the coverage segment length and the number of key nodes. For example, if the sniffing signal coverage area value is 60 and the corresponding influence weight is 0.4, then the weighted influence value of the sniffing coverage area = 60 × 0.4 = 24.
[0114] The effective sniffing value is obtained by integrating the weighted impact value of the sniffing signal strength and the weighted impact value of the sniffing coverage area. Effective sniffing value = weighted impact value of sniffing signal strength + weighted impact value of sniffing coverage area. If the weighted impact value of sniffing signal strength is 51 and the weighted impact value of sniffing coverage area is 24, then the final effective sniffing value = 51 + 24 = 75. The effective sniffing value is a comprehensive quantitative indicator that combines the actual interference capability and coverage area of the sniffing signal. The higher the value, the greater the security threat the sniffing signal poses to data transmission in encrypted segments. This improves the effectiveness of network data security testing.
[0115] The defect level of the encryption module is determined based on historical network data and effective processing of sniffed values, specifically including the following steps:
[0116] The historical deformation defect level of the data encryption module is extracted from historical network data, which is affected by the historical effective sniffing values on defect changes.
[0117] The historical level deformation value is obtained by performing a difference calculation between the historical deformation defect level and the corresponding historical defect level.
[0118] The sniffing deformation level factor is obtained by comparing the historical level deformation value with the historical effective sniffing value.
[0119] The defect deformation level of the data encryption module is obtained based on the sniffing deformation level factor and the effective processing of sniffing values.
[0120] The historical deformation defect levels of the data encryption module affected by historical effective sniffing values are extracted from historical network data. Simultaneously, the corresponding historical defect levels are extracted. Historical data serves as the basis for judging defect change patterns. Historical data from different periods of the same encryption module are filtered out, and the deformation defect levels resulting from interference by historical sniffing signals and the original defect levels of the encryption module before additional sniffing are separated. For example, if a data encryption module has a historical defect level of 2, after experiencing interference with a historical effective sniffing value of 5, its historical deformation defect level becomes 3. These two key values are extracted as analysis samples.
[0121] The extracted historical deformation defect level is compared with the corresponding historical defect level to obtain the historical level deformation value. This quantifies the change in defect level caused by sniffing; the difference processing directly reflects the actual change in the encryption module's defect level caused by the sniffing signal. Historical level deformation value = historical deformation defect level - historical defect level. If the historical deformation defect level is 3 and the historical defect level is 2, then the historical level deformation value = 3 - 2 = 1, meaning the encryption module's defect level has increased by one level due to the historical sniffing.
[0122] The sniffing deformation level factor is obtained by comparing the historical level deformation value with the corresponding historical effective sniffing value. The sniffing deformation level factor is a parameter characterizing the degree of influence of a unit effective sniffing value on the defect level deformation, enabling standardized comparison of the influence degree under different scenarios. Sniffing deformation level factor = historical level deformation value / historical effective sniffing value. If the historical level deformation value is 1 and the historical effective sniffing value is 5, then the sniffing deformation level factor = 1 / 5 = 0.2, meaning that each unit of effective sniffing value increases the defect level of the encryption module by 0.2 units.
[0123] The defect deformation level of the data encryption module is obtained based on the sniffing deformation level factor and the current effective processed sniffing value. The influence of the current sniffing signal on the deformation level of the encryption module is quantified through correlation calculation between the factor and the real-time sniffing value: Defect deformation level = Sniffing deformation level factor × Effective processed sniffing value. If the effective processed sniffing value is 10 and the sniffing deformation level factor is 0.2, then the defect deformation level = 0.2 × 10 = 2, meaning the current data encryption module's defect undergoes two levels of deformation due to the sniffing effect.
[0124] The leakage density value is obtained based on the density coefficient and the defect deformation level, specifically including the following steps:
[0125] The density loss coefficient is calibrated by performing an adaptation calibration.
[0126] The defect deformation level is decomposed into basic failure level and derived failure level of the encryption module; the basic failure level corresponds to the degree of inherent defect of the encryption module, and the derived failure level corresponds to the degree of chain failure caused by the basic failure.
[0127] The calibrated security loss coefficient is correlated with the basic failure level and the derived failure level to obtain the basic security loss component and the derived security loss component. The basic security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the inherent defects of the encryption module, and the derived security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the chain of failures.
[0128] The leakage loss value is obtained by fusing the basic loss component and the derived loss component.
[0129] The compromise coefficient is calibrated to obtain a calibrated compromise coefficient. The goal of calibration is to ensure that the calibrated compromise coefficient matches the current defect deformation level perfectly with the actual security status of the current encrypted section. The original compromise coefficient is dynamically adjusted based on the encryption algorithm type, data transmission characteristics, and real-time characteristics of the defect deformation level of the current encrypted section. This ensures that the calibrated compromise coefficient matches the actual security risks of the current encrypted section. For example, if the original compromise coefficient is 0.3, the current defect deformation level of the encrypted section is 3, and the actual security status shows that the section's encryption anti-interference capability is weaker than the historical average, then the original compromise coefficient is calibrated upwards, resulting in a calibrated compromise coefficient of 0.4.
[0130] The current defect deformation level is decomposed hierarchically to obtain the basic failure level and the derived failure level of the encryption module. The basic failure level corresponds to the inherent defect degree of the encryption module, which is a native defect that exists in the module itself during design, deployment, or long-term operation, unaffected by external interference. The derived failure level corresponds to the cascading failure degree caused by the basic failure; it is a chain of defects caused by the encryption module's inherent defects leading to a decrease in its resistance to attacks, resulting in external sniffing attacks and network fluctuations. Based on the root cause, scope of impact, and risk transmission characteristics of the defects, the defect deformation level is decomposed in all dimensions. First, the inherent defects of the encryption module are separated and quantified as the basic failure level. Then, the additional cascading failures caused by the inherent defects are separated and quantified as the derived failure level. For example, if the current encryption module has a defect deformation level of 4, after disassembly, it is determined that the basic damage level corresponding to the inherent vulnerability of the encryption algorithm itself is 1.5. Due to the inherent vulnerability being sniffed and attacked, the encryption verification fails and the data forwarding vulnerability causes a chain of damage, resulting in a corresponding derivative damage level of 2.5. By disassembling the levels, the originally general defect level is broken down into two independent levels with different root causes.
[0131] The calibrated security vulnerability coefficient is correlated with the basic vulnerability level and the derived vulnerability level to obtain the basic security vulnerability component and the derived security vulnerability component. The basic security vulnerability component reflects the degree of security vulnerability corresponding to the data leakage risk caused by the inherent defects of the encryption module, while the derived security vulnerability component reflects the degree of security vulnerability corresponding to the data leakage risk caused by cascading failures. The correlation operation quantifies the security vulnerability impact corresponding to the two different levels of defects using the calibrated adaptation coefficients. The basic security vulnerability component = calibrated security vulnerability coefficient × basic vulnerability level, and the derived security vulnerability component = calibrated security vulnerability coefficient × derived vulnerability level. If the calibrated security vulnerability coefficient is 0.4, the basic vulnerability level is 1.5, and the derived vulnerability level is 2.5, then the basic security vulnerability component = 0.4 × 1.5 = 0.6, representing the degree of data leakage security vulnerability caused by the inherent defects of the encryption module, and the derived security vulnerability component = 0.4 × 2.5 = 1.0, representing the degree of data leakage security vulnerability caused by cascading failures triggered by the inherent defects.
[0132] The final leakage vulnerability value is obtained by fusing the basic vulnerability component and the derived vulnerability component. This fusion process integrates two vulnerability components from different sources into a comprehensive quantitative value that fully reflects the overall data leakage risk of the encryption module. The leakage vulnerability value = basic vulnerability component + derived vulnerability component. For example, if the basic vulnerability component is 0.6 and the derived vulnerability component is 1.0, then the final leakage vulnerability value = 0.6 + 1.0 = 1.6. This comprehensively covers the full-dimensional vulnerability impact of the encryption module, from its inherent defects to secondary chain reactions, and can characterize the degree of data leakage risk caused by the current encryption module's defects.
[0133] The actual security test data is obtained based on the leakage rate loss value, leakage density loss value, and initial security test data, specifically including the following steps:
[0134] Based on the leakage rate loss value and leakage density loss value, retain the initial security test data that reflects the basic security status of the target data link to obtain the initial security test status data;
[0135] The initial safety test status data is correlated with the leakage rate loss value and leakage density loss value to obtain the initial correlation data;
[0136] Actual security test data is obtained based on the leakage rate loss value reflecting the impact of rate fluctuation leakage, the leakage security loss value reflecting the impact of encryption defect leakage, and the initial security data reflecting the basic security status.
[0137] The initial security test data of the target data link is filtered and refined based on the leakage rate loss value and leakage security loss value, retaining only the valid data that truly reflects the basic security status of the target data link, thus obtaining the initial security test status data. The initial security test data is the raw security data obtained by fully collecting data from the target data link. This includes both the original basic security status data of the link under conditions of no external interference and no abnormal fluctuations, and abnormal interference data caused by transmission rate fluctuations and encryption module defects, which cannot directly reflect the link's true basic security level. The leakage rate loss value is a core indicator for quantifying the risk of data leakage caused by abnormal transmission rates, and the leakage security loss value is an indicator for quantifying the risk of data leakage caused by encryption module defects. Using these two indicators as the core screening criteria, invalid data interfered with by these two types of abnormal factors in the raw data is eliminated, retaining only the original basic security status data of the link without additional abnormal interference. For example, the initial security test data of the target data link includes the link encryption verification pass rate, data transmission packet loss rate, and data packet integrity verification value. Among them, abnormal values of packet loss rate affected by rate fluctuations and abnormal values of verification pass rate affected by encryption defects are all interference data that need to be removed. Based on the leakage rate loss value of 1.2 and the leakage encryption loss value of 1.6, the following are selected: encryption verification pass rate of 98% without abnormal interference, packet loss rate of 0.5% under normal transmission state, and data packet integrity verification value of 100% without tampering. These together constitute the initial security test status data.
[0138] The initial security test status data is associated with and bound one-to-one with the rate leakage loss value and the encryption leakage loss value, resulting in initial associated data. This association process matches and binds the basic security status data of the link with the corresponding two types of leakage risk impacts, ensuring that each set of basic security data corresponds to the rate leakage impact and encryption leakage impact of the same time period and link segment, avoiding evaluation errors caused by data misalignment. Strictly following the time sequence of data collection and the correspondence between link segments, each set of initial security test status data is matched with the rate leakage loss value of the corresponding collection period and the encryption leakage loss value of the corresponding encryption segment, forming an associated data set containing basic security status, rate leakage impact, and encryption leakage impact. For example, the initial security test status data is divided into 5 groups according to continuous transmission periods, each corresponding to one of the 5 continuous transmission periods of the link.
[0139] By combining the impact of rate fluctuation leakage reflected by the leakage rate loss value, the impact of encryption defect leakage reflected by the leakage security loss value, and the basic security status of the link reflected by the initial security test data, the initial correlated data is quantitatively integrated to obtain actual security test data that truly reflects the actual security status of the target data link. Actual security test data = initial security test status data + security impact value corresponding to the leakage rate loss value + security impact value corresponding to the leakage security loss value, which can intuitively realize the superposition of the basic security status and the two types of abnormal impacts. For example, if the basic security score of the link corresponding to a certain set of initial security test status data is 85 points, the security impact value of rate fluctuation converted from the leakage rate loss value corresponding to this set of data is -8 points, and the security impact value of encryption defect converted from the leakage security loss value is -12 points, then the actual security score corresponding to this set of actual security test data = 85 - 8 - 12 = 65 points. For example, if the initial security test data has a base packet loss rate of 0.5%, a rate fluctuation packet loss increment corresponding to the leakage rate loss value of 1.2%, and an encryption defect packet loss increment corresponding to the leakage encryption defect value of 0.8%, then the actual packet loss rate in the actual security test data = 0.5% + 1.2% + 0.8% = 2.5%. The final actual security test data not only fully preserves the basic security attributes of the link itself but also comprehensively covers the actual security impact caused by abnormal transmission rates and encryption module defects, reflecting the full-dimensional security status of the target data link during actual operation.
[0140] Based on actual security test data, the system outputs security leak warning and location results, specifically including the following steps:
[0141] Based on actual security test data, characteristic segments representing link transmission anomalies are obtained;
[0142] The range of encrypted segments with data transmission anomalies is obtained based on the correspondence between feature segments and encrypted segments.
[0143] Based on the effective processing of sniffing values, the abnormal distribution of sniffing signals within the encrypted section is investigated, and the link points interfering with the sniffing signals are obtained;
[0144] Determine whether a link location is a target location for data leakage based on the level of defect deformation.
[0145] Based on the location information of the target point and the degree of correlation with the leak, a security leak early warning and location result is generated, which includes the specific location and risk level.
[0146] Feature segments representing link transmission anomalies are extracted from actual security test data. The actual security test data covers the transmission status information of the target data link across all time periods and segments, including transmission rate, packet loss rate, encryption verification pass rate, and data packet integrity. Benchmark ranges for various indicators under normal link transmission conditions are established. The actual security test data is then divided into multiple consecutive data segments according to transmission time sequence. The indicator values of each data segment are compared with the normal benchmark range. Data segments whose indicator values deviate from the benchmark range and whose deviation exceeds a preset threshold are marked as feature segments representing link transmission anomalies. For example, if the link transmission data is divided into 20 consecutive data segments of fixed duration, and the benchmark range for normal transmission is set as a packet loss rate of less than 1% and an encryption verification pass rate of more than 98%, with a deviation threshold of twice the benchmark limit, the comparison reveals that the packet loss rate of the 8th to 10th data segments reaches 3.5%, and the encryption verification pass rate is only 82%. Both indicators deviate from the preset threshold, so these three data segments are marked as feature segments representing link transmission anomalies. This completes the initial location of abnormal data, narrowing the investigation scope from the entire link's data to specific abnormal data segments.
[0147] The range of encrypted segments indicating data transmission anomalies is determined by the correspondence between characteristic segments and encrypted segments. During the link transmission process, data packets transmitted in each time period undergo encryption processing and forwarding within fixed encrypted segments in the link. A one-to-one mapping relationship is established between the data packet transmission sequence and the encrypted segments in the link, with each data segment corresponding to one or more fixed encrypted segments in the link. The corresponding encrypted segments in the mapping relationship are retrieved based on the transmission sequence of the abnormal characteristic segments. Then, the encrypted segments corresponding to all abnormal characteristic segments are summarized and merged to finally determine the range of encrypted segments indicating data transmission anomalies. For example, the 8th to 10th abnormal characteristic segments, through the time sequence mapping relationship, correspond to encrypted segments numbered 3 to 4 in the link. These two encrypted segments are responsible for the encryption processing and forwarding of all data packets in that time period. Therefore, encrypted segments 3 to 4 are designated as the range of encrypted segments indicating data transmission anomalies, thus narrowing the investigation scope from the entire link to two specific encrypted segments.
[0148] Based on the effective processing sniffing value, the abnormal distribution of sniffing signals within the encrypted segment is investigated, ultimately identifying the link points affected by sniffing interference. The effective processing sniffing value is a quantitative indicator that combines sniffing signal strength and coverage, reflecting the actual degree of interference at each link point. Each subdivided transmission point in the link corresponds to an effective processing sniffing value. Within the defined abnormal encrypted segment, all subdivided link points are scanned one by one, retrieving the effective processing sniffing value for each point. Then, the value of each point is compared with a preset sniffing anomaly threshold, and points with values exceeding the threshold are marked as link points affected by sniffing interference. When the effective processing sniffing value of a point exceeds a preset threshold, the point is determined to be an interfered point. For example, the preset abnormal threshold for the effective processing sniffing value is 30. There are 8 sub-link points in the encrypted section from 3 to 4, namely 3-1, 3-2, 3-3, 4-1, 4-2, 4-3, 4-4, and 4-5. After scanning and investigation, the effective processing sniffing value of point 3-2 is 52, and the effective processing sniffing value of point 4-3 is 47, both exceeding the abnormal threshold of 30. The effective processing sniffing values of the remaining points are all below 20 and do not meet the abnormal standard. Therefore, points 3-2 and 4-3 are marked as link points interfered with by sniffing signals, and the investigation scope is further narrowed from the encrypted section to the specific link points.
[0149] The system determines whether a link location is a target for data leakage based on its defect deformation level. The defect deformation level quantifies the change in the degree of defect of the encryption module after being affected by sniffing signals. A higher level indicates a more severe defect in the encryption module at that location, and a higher probability of data leakage. The system retrieves the defect deformation level of the encryption module corresponding to each sniffing interference point and compares it with a preset leakage judgment threshold. When the defect deformation level of a point is greater than or equal to the leakage judgment threshold, that point is determined to be a target for data leakage. For example, if the system's preset defect deformation level leakage judgment threshold is level 2, and the defect deformation level corresponding to point 3-2 is level 3, reaching and exceeding the leakage judgment threshold, while the defect deformation level corresponding to point 4-3 is level 1.2, not reaching the leakage judgment threshold, then point 3-2 is determined to be a target for data leakage, while point 4-3 is merely a point affected by sniffing signals but has not yet experienced data leakage.
[0150] Based on the location information of the target point and the degree of leakage correlation, a security leakage early warning and location result is generated, including the specific location and risk level. The location information of the target point includes the encrypted segment number, node number, physical address, and corresponding device information of the point in the link. The degree of leakage correlation is a quantitative indicator calculated by combining the defect deformation level and the effective processing sniffing value of the point, used to characterize the closeness of the connection between the point and the data leakage. The degree of leakage correlation = normalized value of defect deformation level × 0.6 + normalized value of effective processing sniffing value × 0.4. The corresponding risk level is divided according to the value of the degree of leakage correlation. When the degree of leakage correlation is greater than or equal to 0.7, it is judged as high risk; when the degree of leakage correlation is greater than or equal to 0.4 and less than 0.7, it is judged as medium risk; and when the degree of leakage correlation is less than 0.4, it is judged as low risk. Finally, the specific location information, risk level, corresponding defects, and sniffing indicator values of the point are integrated to generate a standardized security leakage early warning and location result. For example, if the target location is point 3-2, its specific location information is the 2nd forwarding node in the 3rd encrypted segment of the link, the physical address is XX-XX-XX-03-02, and the leakage correlation degree is 0.82, which belongs to the high-risk level, then a security leakage warning location result is generated, which includes the specific location of the point, the high-risk level, the corresponding defect deformation level 3, and the effective processing sniffing value of 52.
[0151] A network data security testing system based on big data includes:
[0152] Acquisition module: Acquires initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link;
[0153] The first processing module obtains the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change based on historical network data.
[0154] The second processing module extracts the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtains the current rate variation value based on the link transmission rate and the rate threshold, and obtains the leakage rate loss value based on the rate loss coefficient and the current rate variation value.
[0155] Detection and processing module: detects the sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level, and obtains the effective processing sniffing value based on the sniffing signal strength and sniffing coverage.
[0156] The third processing module: Based on historical network data and effectively processed sniffing values, it obtains the defect deformation level of the encryption module; based on the security loss coefficient and defect deformation level, it obtains the leakage security loss value; based on the leakage rate loss value, the leakage security loss value, and the initial security test data, it obtains the actual security test data.
[0157] Output module: Outputs security leak warning and location results based on actual security test data.
[0158] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0159] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0160] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A network data security testing method based on big data, characterized in that, The method includes the following steps: Collect initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link; Based on historical network data, we obtained the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change. Extract the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtain the current rate variation value based on the link transmission rate and the rate threshold, and obtain the leakage rate loss value based on the rate loss coefficient and the current rate variation value. The sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level are detected, and the effective processing sniffing value is obtained based on the sniffing signal strength and sniffing coverage. Based on historical network data and effective processing of sniffed values, the defect deformation level of the encryption module is obtained; the leakage loss value is obtained according to the loss coefficient and the defect deformation level; and the actual security test data is obtained according to the leakage rate loss value, the leakage loss value, and the initial security test data. Output security leak warning and location results based on actual security test data.
2. The network data security testing method based on big data according to claim 1, characterized in that, The encryption loss coefficient related to the encryption vulnerability level and the rate loss coefficient related to rate change are obtained based on historical network data, specifically including the following steps: The historical defect levels corresponding to the data encryption modules are extracted from historical network data, and the historical leakage and loss values of the historical defect levels affecting the historical test data links are extracted. The density loss coefficient is obtained by comparing the historical leakage density loss value with the historical defect level. Extract historical abnormal rate values from historical network data, where the transmission rate exceeds the rate threshold. The historical rate change amplitude is obtained by subtracting the historical abnormal rate value and the rate threshold. Historical leakage rate loss values of historical test data links are extracted from historical network data, reflecting the impact of historical rate change amplitudes on historical rate loss values. The rate loss coefficient is obtained by comparing the historical leakage rate loss value with the historical rate change amplitude.
3. The network data security testing method based on big data according to claim 1, characterized in that, The current rate variation is obtained based on the link transmission rate and the rate threshold, specifically including the following steps: The link transmission rate corresponding to several rate segments in a continuous transmission period is divided into multiple segmented rates. The average value of the segmented rate is obtained by calculating the mean of the rates of each segment. The average segmented rate that exceeds the rate threshold is marked as the target segmented rate value; The difference between the target segment rate value and the rate threshold is used to obtain the rate difference of each segment. The current rate variation value is obtained by summing up all segment rate differences.
4. The network data security testing method based on big data according to claim 1, characterized in that, The leakage rate loss value is obtained based on the rate loss coefficient and the current rate variation value, specifically including the following steps: The rate anomaly impact factor is obtained by fusing the rate loss coefficient with the weight corresponding to the current rate variation value. The rate influence factor is obtained by normalizing the rate anomaly influence factor. The leakage rate loss value is obtained by hierarchically associating the rate influence factor with the current rate variation value.
5. The network data security testing method based on big data according to claim 1, characterized in that, The effective processed sniffing value is obtained based on the sniffing signal strength and sniffing coverage area, specifically including the following steps: Capture sniffing signals for encrypted segments corresponding to the encryption vulnerability level; The sniffing signal strength is divided into different levels based on the degree of interference of the sniffing signal on the data transmission of the encrypted segment, and the degree of influence of the strength corresponding to each level is determined. The sniffing coverage of the encrypted section corresponding to the encryption defect level is detected, the length of the encrypted section covered by the sniffing signal and the key transmission nodes are determined, and the security impact boundary of the sniffing coverage on the encrypted section data is clarified based on the length of the encrypted section and the key transmission nodes. The influence weights of the sniffing signal strength and the sniffing coverage area are determined based on the degree of influence of the intensity and the security impact boundary. The sniffing signal strength is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing signal strength, and the sniffing coverage is matched with the corresponding influence weight to obtain the weighted influence value of the sniffing coverage. By integrating the weighted influence value of the sniffing signal strength with the weighted influence value of the sniffing coverage area, an effective processed sniffing value is obtained.
6. The network data security testing method based on big data according to claim 5, characterized in that, The defect level of the encryption module is determined based on historical network data and effective processing of sniffed values, specifically including the following steps: The historical deformation defect level of the data encryption module is extracted from historical network data, which is affected by the historical effective sniffing values on defect changes. The historical level deformation value is obtained by performing a difference calculation between the historical deformation defect level and the corresponding historical defect level. The sniffing deformation level factor is obtained by comparing the historical level deformation value with the historical effective sniffing value. The defect deformation level of the data encryption module is obtained based on the sniffing deformation level factor and the effective processing of sniffing values.
7. The network data security testing method based on big data according to claim 1, characterized in that, The leakage density value is obtained based on the density coefficient and the defect deformation level, specifically including the following steps: The density loss coefficient is calibrated by performing an adaptation calibration. The defect deformation level is decomposed into a hierarchical structure to obtain the basic failure level and the derived failure level of the encryption module; wherein, the basic failure level corresponds to the inherent defect level of the encryption module, and the derived failure level corresponds to the degree of chain failure caused by the basic failure. The calibrated security loss coefficient is correlated with the basic failure level and the derived failure level to obtain the basic security loss component and the derived security loss component; wherein, the basic security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the inherent defects of the encryption module, and the derived security loss component reflects the degree of security loss corresponding to the risk of data leakage caused by the chain failure. The leakage loss value is obtained by fusing the basic loss component and the derived loss component.
8. The network data security testing method based on big data according to claim 7, characterized in that, The actual security test data is obtained based on the leakage rate loss value, leakage density loss value, and initial security test data, specifically including the following steps: Based on the leakage rate loss value and leakage density loss value, retain the initial security test data that reflects the basic security status of the target data link to obtain the initial security test status data; The initial safety test status data is correlated with the leakage rate loss value and leakage density loss value to obtain the initial correlation data; Actual security test data is obtained based on the leakage rate loss value reflecting the impact of rate fluctuation leakage, the leakage security loss value reflecting the impact of encryption defect leakage, and the initial security data reflecting the basic security status.
9. The network data security testing method based on big data according to claim 1, characterized in that, Based on actual security test data, the system outputs security leak warning and location results, specifically including the following steps: Based on actual security test data, characteristic segments representing link transmission anomalies are obtained; The range of encrypted segments with data transmission anomalies is obtained based on the correspondence between feature segments and encrypted segments. Based on the effective processing of sniffing values, the abnormal distribution of sniffing signals within the encrypted section is investigated, and the link points interfering with the sniffing signals are obtained; Determine whether a link location is a target location for data leakage based on the level of defect deformation. Based on the location information of the target point and the degree of correlation with the leak, a security leak early warning and location result is generated, which includes the specific location and risk level.
10. A network data security testing system based on big data, applied to the network data security testing method based on big data as described in any one of claims 1 to 9, characterized in that, include: Acquisition module: Acquires initial security test data, real-time transmission rate, and encryption vulnerability level of the target data link; The first processing module obtains the encryption loss coefficient related to the encryption defect level and the rate loss coefficient related to the rate change based on historical network data. The second processing module extracts the link transmission rate that is greater than the rate threshold from the real-time transmission rate, obtains the current rate variation value based on the link transmission rate and the rate threshold, and obtains the leakage rate loss value based on the rate loss coefficient and the current rate variation value. Detection and processing module: detects the sniffing signal strength and sniffing coverage of the encrypted section corresponding to the encryption defect level, and obtains the effective processing sniffing value based on the sniffing signal strength and sniffing coverage. The third processing module: Based on historical network data and effective processing of sniffed values, the defect deformation level of the encryption module is obtained; The leakage density loss value is obtained based on the density loss coefficient and the defect deformation level. The actual safety test data is obtained based on the leakage rate loss value, the leakage density loss value and the initial safety test data. Output module: Outputs security leak warning and location results based on actual security test data.