Dynamic reverse verification network security system driven by artificial intelligence and network security method
By using an AI-driven dynamic reverse verification network security system, which combines AI behavior analysis and dynamic verification mechanisms to generate unique verification strings and integrate them with the content delivery network, the system addresses the shortcomings of traditional network security systems in responding to new and internal threats, achieving rapid response and comprehensive network security defense.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ECCOM INTELLIGENCE CO LTD
- Filing Date
- 2025-10-27
- Publication Date
- 2026-05-01
AI Technical Summary
Traditional cybersecurity systems have limited capabilities in dealing with new and complex cyber threats, especially attacks from within organizations, and traditional verification methods are vulnerable to attack, necessitating more secure and dynamic verification mechanisms.
An AI-driven dynamic reverse verification network security system is adopted, which combines AI-driven behavioral analysis and dynamic verification mechanisms to enhance security by generating unique 32-byte verification strings (au strings), integrates a content delivery network (CDN) to mitigate large-scale DDoS attacks, uses AI to monitor user behavior patterns to identify internal threats, and initiates a layered defense response.
It provides comprehensive defense against both external and internal threats, enables rapid response to and mitigation of cyberattacks, enhances the security and availability of enterprise networks, and offers a dynamic, adaptable, and robust cybersecurity solution.
Smart Images

Figure CN121966908A_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to network security systems, and more specifically, to an AI-driven dynamic reverse engineering verification network security system and method. This AI-driven network security solution aims to proactively detect and respond to various network threats. The invention utilizes advanced machine learning techniques and innovative verification mechanisms to enhance the security posture of enterprise network environments. Background Technology
[0002] In today's digital environment, organizations increasingly rely on sophisticated network infrastructures to support their operations, store sensitive data, and facilitate communications. At the same time, cyber threats are increasing in both frequency and complexity, posing significant risks to the integrity, confidentiality, and availability of critical information systems.
[0003] Traditional cybersecurity measures primarily employ rule-based systems, such as firewalls and intrusion detection systems (IDS), which rely on predefined signatures and static rules to identify and block malicious activity. While these systems are effective at mitigating known threats, they have significant limitations in addressing emerging and sophisticated attack vectors. Specifically, rule-based approaches often struggle to detect novel or highly targeted attacks that do not conform to existing signatures, leading to delayed or inadequate responses to such threats.
[0004] Furthermore, traditional cybersecurity solutions often focus on external threats, neglecting the potential risks of internal threats—namely, malicious or unintentional behavior by authorized users within the organization. Detecting internal threats is inherently challenging due to users' legitimate access rights, and it is difficult to distinguish between normal and malicious activity based solely on predefined rules.
[0005] Distributed Denial-of-Service (DDoS) attacks are a prime example of the evolving nature of network threats. These attacks overwhelm network resources with excessive traffic, rendering services unavailable to legitimate users. Traditional mitigation strategies, such as rate limiting and traffic filtering, may be insufficient to handle large-scale or high-volume DDoS attacks, necessitating more robust and adaptive defense mechanisms.
[0006] Connection-oriented attacks, including Slow HTTP and Challenge Collapsar (CC) attacks, further complicate the cybersecurity landscape. These attacks exploit vulnerabilities in network protocols and application layers to establish persistent connections that exhaust server resources. Detecting and mitigating such attacks requires continuous monitoring and dynamic response strategies, exceeding the capabilities of static, rule-based systems.
[0007] To address these challenges, there is a growing demand for cybersecurity solutions that combine advanced analytics and adaptive learning capabilities. Artificial intelligence and machine learning offer promising approaches to enhance threat detection and response by analyzing massive amounts of data, identifying anomalous patterns, and adapting in real time to emerging and evolving threats. Behavioral analytics is a key component of AI-driven cybersecurity, focusing on understanding normal user and network behavior to identify anomalies that may indicate malicious activity.
[0008] Furthermore, robust authentication mechanisms are crucial for ensuring secure network access and preventing unauthorized access. Traditional authentication methods, such as static passwords and token-based systems, are vulnerable to various attacks, including credential theft and replay attacks. Therefore, innovative authentication algorithms that generate dynamic and unique identifiers can significantly improve security by making it more difficult for attackers to predict or reuse authentication credentials.
[0009] Despite advancements in artificial intelligence and machine learning, integrating these technologies into a comprehensive cybersecurity framework remains a complex task. Effective AI-driven cybersecurity solutions must tightly integrate data collection, behavioral analysis, threat detection, and response mechanisms, while ensuring scalability, compatibility with existing systems, and minimal disruption to legitimate cyber activities.
[0010] Therefore, existing cybersecurity systems face significant challenges in adapting to the rapidly evolving threat environment. Rule-based approaches have limited capabilities in detecting and responding to new and complex attacks, particularly those originating from within organizations. Furthermore, traditional verification methods are increasingly vulnerable to advanced attack techniques, necessitating more secure and dynamic verification mechanisms. Clearly, a comprehensive cybersecurity solution is needed that leverages artificial intelligence and machine learning to provide proactive threat detection, robust verification, and a comprehensive defense strategy capable of responding to both external and internal threats in real time. Summary of the Invention
[0011] This invention provides an AI-driven dynamic reverse verification network security system and method. The network security system utilizes artificial intelligence (AI) and a novel reverse verification algorithm (RAA) to proactively detect and respond to network security threats in the network environment. Aiming to overcome the limitations of traditional rule-based security measures, this network security system integrates AI-driven behavioral analysis and dynamic verification mechanisms, thereby enhancing the security posture of enterprise networks against external and internal threats.
[0012] The cybersecurity system includes an AI-driven behavioral analytics module that collects comprehensive network data, including traffic logs, geographic information, network parameters, timestamps, and device information. By employing machine learning algorithms, the system models normal network behavior and identifies anomalies that may indicate potential threats. This continuous, real-time analysis enables the cybersecurity system to adapt to emerging and evolving threats, ensuring ongoing protection against emerging cyber risks.
[0013] In one embodiment, the network security system provides a reverse verification algorithm that generates a unique 32-byte verification string, hereinafter referred to as the au string. This verification string consists of a spoofed timestamp, a set of random hexadecimal numbers, and a search string derived from an ASCII random string table. The reverse verification algorithm enhances security by making the au string resistant to prediction and replay attacks, ensuring that each verification attempt is both unique and time-constrained. This dynamic verification mechanism complements existing verification methods, providing an additional layer of verification based on behavioral and activity analysis.
[0014] Upon detecting abnormal patterns or authentication failures, the network security system initiates a layered defense response. This multi-layered approach includes packet filtering to remove malicious data, automatically blocking suspicious IP addresses through updated blacklists, and executing custom scripts written in Python, Bash, or C / C++ to proactively neutralize identified threats. Furthermore, the network security system integrates Content Delivery Networks (CDNs) to mitigate traffic-driven distributed denial-of-service attacks by distributing network load, thereby maintaining service availability during large-scale attacks.
[0015] In addition to defending against external threats, the cybersecurity system leverages AI-driven analytics to monitor user behavior patterns, effectively identifying anomalies that may indicate internal threats. By addressing both external and internal security risks, this cybersecurity system provides a comprehensive defense mechanism to protect sensitive data and maintain operational continuity. Dynamically generated AU strings serve as supplementary verification tokens, providing request-based authentication and enhancing overall security measures.
[0016] The effectiveness of a cybersecurity system is demonstrated by its ability to autonomously activate defense mechanisms shortly after an attack is detected (e.g., within seconds), such as successfully mitigating a major DDoS attack. All detected threats and response actions are logged for auditing purposes, promoting continuous improvement of security protocols and ensuring accountability.
[0017] In summary, this invention represents a significant advancement in cybersecurity technology by integrating AI-driven behavioral analysis, novel verification algorithms, and a layered defense mechanism. This comprehensive approach not only addresses the shortcomings of traditional security systems but also provides a dynamic, adaptable, and robust solution capable of defending against both known and emerging cyber threats. The invention's modular design, scalability, and compatibility with existing infrastructure make it a versatile and effective tool for enhancing the security of enterprise network environments.
[0018] To make the above features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0019] Various embodiments will now be described with reference to the accompanying drawings, which are illustrative and not intended to limit the scope in any way, wherein similar reference numerals denote similar components, and the figures are simply explained below: Figure 1 The diagram shown is an architecture diagram of one embodiment of the network security system of the present invention.
[0020] Figure 2 The diagram shown is an architecture diagram of one embodiment of the data collection module of the present invention.
[0021] Figure 3 The diagram shown is an architecture diagram of one embodiment of the AI analysis engine of the present invention.
[0022] Figure 4 The illustration shows one embodiment of the verification string generated by the verification algorithm of the present invention.
[0023] Figure 5A The diagram illustrates a flowchart of generating a verification string, representing one embodiment of the verification algorithm of the present invention.
[0024] Figure 5B The diagram illustrates a flowchart of the sub-steps for generating a verification string, representing one embodiment of the verification algorithm of the present invention.
[0025] Figure 6A The diagram illustrates a flowchart of one embodiment of the verification algorithm of the present invention for verifying a verification string.
[0026] Figure 6B The diagram illustrates a sub-step flowchart of one embodiment of the verification algorithm of the present invention for verifying a verification string.
[0027] Figure 7 The diagram shown is an architectural diagram of one embodiment of the defense response module of the present invention.
[0028] Figure 8The diagram illustrates the operation flow of one embodiment of the network security system of the present invention. Detailed Implementation
[0029] This invention relates to a network security system, specifically an AI-driven dynamic reverse authentication network security system and method. This network security system integrates artificial intelligence and a novel reverse authentication algorithm (RAA) to proactively detect, analyze, and respond to various network threats in an enterprise network environment. This detailed description elucidates the components and operational processes of this network security system, enabling those skilled in the art to understand and implement the invention.
[0030] Please refer to Figure 1 , Figure 1 The diagram illustrates an architecture of one embodiment of the network security system of the present invention. The network security system 100 is structured as a modular and scalable platform, comprising multiple interconnected components: a data collection module 110, an AI analysis engine 120, a verification module 130 with a reverse verification algorithm 132, and a defense response module 140. Each component is designed to operate independently and collaboratively, ensuring comprehensive protection against network threats while maintaining high performance and adaptability.
[0031] Please refer to the following at the same time Figure 2 , Figure 2 The diagram illustrates an architecture of one embodiment of the data collection module of the present invention. The data collection module 110 is responsible for collecting a wide range of network data required for analysis and threat detection. The data collection module 110 is continuously operational to ensure the availability of real-time data. This data collection module 110 collects various types of data, including a network traffic log 112 to capture inbound and outbound traffic details such as source and destination IP addresses, port numbers, protocols, and packet sizes. Furthermore, it collects geographic information via IP geolocation service 114 to determine the geographical location of connected entities. Additionally, a network parameter monitoring tool 116 is used to monitor various network parameters such as latency, throughput, and error rate. Moreover, the data collection module 110 records the precise time information of each network event via timestamp 118 and uses a device information collection module 117 to collect device information, including MAC addresses, operating systems, and device configurations.
[0032] The data collection module 110 achieves this through a combination of passive monitoring, active probing, and API integration. Passive monitoring utilizes technologies such as Network Test Access Points (NTAPs) and port mirroring to observe traffic without interfering with network operation, while active probing sends test packets to measure network performance and detect anomalies. The data collection module 110 also interfaces with existing network devices and security systems via API to aggregate logs and alerts. Collected data is managed using real-time data processing through stream processing frameworks to handle high-speed data and is securely stored in an encrypted database 160 with strict access controls to ensure data integrity and confidentiality. Data retention policies are implemented in accordance with organizational policies and regulations, ensuring data is retained for configurable periods as needed.
[0033] Please refer to the following at the same time Figure 1 and Figure 3 , Figure 3 The diagram illustrates an architecture of one embodiment of the AI analysis engine of the present invention. The AI analysis engine 120 uses machine learning algorithms to identify potential threats from data collected by the data collection module 110. The AI analysis engine 120 utilizes various machine learning models 122, including behavioral modeling based on historical data to build normal network and user behavior, and using unsupervised learning algorithms such as cluster analysis and autoencoders to identify anomalies deviating from established behavioral patterns. Predictive analysis also uses supervised learning models trained on labeled datasets to predict potential threats based on observed metrics.
[0034] In this embodiment, the data preprocessing module 124 within the AI analysis engine 120 includes standardizing the raw data into a format suitable for analysis, extracting relevant features such as access frequency, access time, and data transmission volume, and applying dimensionality reduction techniques such as Principal Component Analysis (PCA) to reduce data complexity without losing important information. Real-time analysis is facilitated through streaming processing technologies like Apache Kafka and Apache Flink, enabling the network security system 100 to perform analysis as data is collected. A feedback loop is established to continuously update the machine learning model based on new data and feedback from the defense response module, ensuring that the machine learning model 122 remains up-to-date and effective.
[0035] The AI analytics engine 120 categorizes threats into various types, including external threats from outside the network, such as distributed denial-of-service (DDoS) attacks, malware infiltration, and phishing attacks; internal threats involving malicious or unintentional behavior of authorized users, identified through behavioral biases; and zero-day attacks that identify previously unknown vulnerabilities, identified by recognizing anomalous patterns that do not conform to known signatures. Additionally, the AI analytics engine 120 includes an AI auditor component 126 that deeply analyzes user behavior patterns to detect internal threats. It monitors user activity to identify anomalous access patterns, such as access outside normal working hours or attempts to access atypical resources, and alerts administrators to potential privilege escalation or unauthorized access attempts.
[0036] Please refer to the following at the same time Figure 1 and Figure 4 , Figure 4 The illustration shows one embodiment of the verification string generated by the verification algorithm of the present invention. Verification module 130 implements reverse verification algorithm 132 to enhance security through a dynamic and robust verification mechanism. In this embodiment, reverse verification algorithm 132 generates a unique 32-byte verification string (in... Figure 4 The string au (hereinafter referred to as au string 10) is designed to be time-sensitive and resistant to prediction and replay attacks. au string 10 consists of a fake timestamp 12 (12 bytes), a random string 14 consisting of a set of random hexadecimal numbers 12 bytes, and a search string 16 derived from the ASCII random string table 16 (8 bytes).
[0037] The generation of the au string 10 involves multiple complex steps to ensure its uniqueness and security. The following is a brief overview of the detailed process for generating the verification string in one embodiment. Please refer to... Figure 5A , Figure 5A The diagram illustrates a flowchart of generating a verification string, representing one embodiment of the verification algorithm of the present invention.
[0038] Step S110: Generate random hexadecimal numbers As shown in step S110, the generation process begins by generating four random hexadecimal numbers within a specified range to form a random string 14. The specified range for each random hexadecimal number (here labeled r1_hex, r2_hex, r3_hex, r4_hex) is 0x100 to 0xF00 (i.e., 256 to 3840 in decimal) to ensure sufficient randomness and complexity.
[0039] example: r1_hex = random_range(0x100, 0xF00) = 'e04' r2_hex = random_range(0x100, 0xF00) = 'a62' r3_hex = random_range(0x100, 0xF00) = '1c3' r4_hex = random_range(0x100, 0xF00) = 'd09' These random hexadecimal numbers provide the necessary base of randomness for spoofing timestamps and generating search strings.
[0040] Step S120: Obtain and convert the current timestamp In step S120, the decimal form of the current timestamp is obtained (labeled ts_dec here). For example, consider GMT time: Saturday, June 4, 2022, 02:14:30 AM: ts_dec = 1654308870 Then, convert this decimal timestamp to its hexadecimal representation (labeled ts_hex here): ts_hex = dec_to_hex(ts_dec) = '629ac006' Step S130: Use two's complement arithmetic to spoof the timestamp As shown in step S130, the timestamp is disguised by applying two's complement arithmetic, which enhances security because it obscures the actual timestamp value. Two's complement arithmetic is performed using a maximum 32-bit unsigned integer value (0xFFFFFFFF): ts_hex_com = 0xFFFFFFFF - ts_hex = 0xFFFFFFFF - '629ac006' = '9d653ff9' Then, the two's complement timestamp (labeled ts_hex_com here) is split into four independent bytes for further processing. These four bytes are as follows: ts_hex_com_1 = '9d' ts_hex_com_2 = '65' ts_hex_com_3 = '3f' ts_hex_com_4 = 'f9' Step S140: Combine the random number with the fake timestamp component In step S140, the addition operation is performed by adding each random hexadecimal number to the corresponding byte of the two's complement timestamp. This process further disguises the timestamp and integrates randomness into the timestamp component.
[0041] Calculation example: ts_1_hex = r1_hex + ts_hex_com_1 = 'e04' + '9d' = 'ea1' ts_2_hex = r2_hex + ts_hex_com_2 = 'a62' + '65' = 'ac7' ts_3_hex = r3_hex + ts_hex_com_3 = '1c3' + '3f' = '202' ts_4_hex = r4_hex + ts_hex_com_4 = 'd09' + 'f9' = 'e02' These results form fake timestamp components (labeled here as ts_1_hex, ts_2_hex, ts_3_hex, ts_4_hex), which are part of the au string 10.
[0042] Step S150: Read the ASCII random string table As shown in step S150, an ASCII random string table is read to derive the search string 16. This ASCII random string table is generated using a script (e.g., random_ascii.sh) and contains multiple rows (ascii_row_max) of random ASCII characters. In this example, the table consists of 10 rows, as shown below.
[0043] Example of an ASCII random string table: 1. '2UsXfDVurbd1ENveR74AqW8poBknOHa5JPxl3TzLFM9gyK6SIQiwYmtZG0Ccjh' 2. 'ytdzv46KqkBfjlMsZcGVDX8YrhO9AWTL53CJgEQIUe1pxmRSoaibwnu72NHFP0' 3. 'VmNwBLv74UC15HkSf3Mry2czOZ0oY6DEjeKgJTWqGiIsd8hXnPbF9AxulRpQat' 4. 'U21uglxzZ5bahGvCEecpjNInPMBLwkJQ78t3TWOyKd6YrDfmFRHSoXsV94Aq0i' 5. 'gkqlX1eSByAK4rUvGLxY0IjFZWh7oniV8zuMOQfb6T5p2mNw9sRtcHEdPaCJD3' 6. 'SOLG9DJrlvmE6cMwP0n2BRzNadH8AVtoUk37Y5bXig1eyhWsqKCTZp4QxFfIju' 7. 'WTSw4eAmRGjXzMJdYEDhBkV3QC5IbUpHfcrnl7uxOta1sZyiKgvF9806LqPN2o' 8. 'aspmYN8jcDA97vtGVBwFqTL4gJdQ02KnPbXezIZhWok536uyHrUiSxlCEO1MRf' 9. 'xUQ7lJKLHjab8CwWu26Vn13eYdiBTvOpI9Fy5McPXzDrgN4AfZokshtmqGR0SE' 10. 'wovSsRFIzhBAWyTq5XjH20MLtr4euQm9l1gVYE8bfx7Ud6DZJcKGiaCPN3Okpn' It is worth noting that, for security reasons, the ASCII random string table can be updated as needed by generating new data using the random_ascii.sh script. Both server-side (e.g., SWAF NA) and client-side scripts (e.g., JavaScript) must update the table simultaneously to maintain synchronization.
[0044] Step S160: Determine the source line of ASCII data In step S160, it is determined which row in the ASCII random string table will be used to generate search string 16. This is calculated using the first random hexadecimal number (r1_hex) mentioned above.
[0045] Calculation example: Convert r1_hex to decimal: r1_dec = hex_to_dec(r1_hex) = hex_to_dec('e04') = 3588 Determine the number of rows in the table: ascii_row_max = 10 Calculate the row index: ascii_row = r1_dec % ascii_row_max = 3588 % 10 = 8 Modulo operations ensure that row indexes are within the range of the table. Then the selected behavior: ascii_data_source = ascii_table[ascii_row] = ascii_table[8] Example ASCII data source (line 8): 'aspmYN8jcDA97vtGVBwFqTL4gJdQ02KnPbXezIZhWok536uyHrUiSxlCEO1MRf' Step S170: Identify the position of the predetermined character As shown in step S170, the system identifies the positions of predetermined characters in the selected ASCII data source. These characters are used as constants in the search string calculation. In this embodiment, the predetermined characters are 'H', 'I', 'D', and 'E', representing the word "HIDE".
[0046] Calculation example: s1_pos_dec = Position of 'H' in ascii_data_source = 49 (index based on 1) s2_pos_dec = the position of 'I' in ascii_data_source = 38 s3_pos_dec = the position of 'D' in ascii_data_source = 10 s4_pos_dec = The position of 'E' in ascii_data_source = 57 Next, convert the position to hexadecimal: s1_pos_hex = dec_to_hex(s1_pos_dec) = dec_to_hex(49) = '31' s2_pos_hex = dec_to_hex(s2_pos_dec) = dec_to_hex(38) = '26' s3_pos_hex = dec_to_hex(s3_pos_dec) = dec_to_hex(10) = '0a' s4_pos_hex = dec_to_hex(s4_pos_dec) = dec_to_hex(57) = '39' Step S180: Calculate the search string component In step S180, the system performs addition using the position of a predetermined character and the corresponding random hexadecimal number, and uses these results to generate the search string 16.
[0047] Sub-steps (please also refer to...) Figure 5B ): Step S182: Identifier Meta Location: s1_pos_dec = Position of 'H' in ascii_data_source = 49 (index based on 1) s2_pos_dec = the position of 'I' in ascii_data_source = 38 s3_pos_dec = the position of 'D' in ascii_data_source = 10 s4_pos_dec = The position of 'E' in ascii_data_source = 57 Step S184: Convert the position to hexadecimal: s1_pos_hex = dec_to_hex(s1_pos_dec) = dec_to_hex(49) = '31' s2_pos_hex = dec_to_hex(s2_pos_dec) = dec_to_hex(38) = '26' s3_pos_hex = dec_to_hex(s3_pos_dec) = dec_to_hex(10) = '0a' s4_pos_hex = dec_to_hex(s4_pos_dec) = dec_to_hex(57) = '39' Step S186: Perform addition operation: s1_rand_hex = r1_hex + s1_pos_hex = 'e04' + '31' = 'e35' s2_rand_hex = r2_hex + s2_pos_hex = 'a62' + '26' = 'a88' s3_rand_hex = r3_hex + s3_pos_hex = '1c3' + '0a' = '1cd' s4_rand_hex = r4_hex + s4_pos_hex = 'd09' + '39' = 'd42' Step S188: Extract specific hexadecimal numbers: The last two digits of s1_hex = s1_rand_hex = 'e35' → '35' The last two digits of s2_hex = s2_rand_hex = 'a88' → '88' The last two digits of s3_hex = s3_rand_hex = '1cd' → 'cd' The last two digits of s4_hex = s4_rand_hex = 'd42' → '42' Step S189: Assemble the recalculated search string: s_cal_rand_hex = s1_hex || s2_hex || s3_hex || s4_hex = '35' || '88'|| 'cd' || '42' = '3588cd42' Step S190: Assemble the au string As shown in step S190, the final au string 10 is generated by a concatenation component, which includes a random hexadecimal number (random string 14), a fake timestamp component (fake timestamp 12), and a search string component (search string 16).
[0048] Assemble random strings: random_string = r1_hex || r2_hex || r3_hex || r4_hex = 'e04' || 'a62'|| '1c3' || 'd09' = 'e04a621c3d09' Assemble a fake timestamp: timestamp_string = ts_1_hex || ts_2_hex || ts_3_hex || ts_4_hex = 'ea1' || 'ac7' || '202' || 'e02' = 'ea1ac7202e02' Assemble the au string: au_string = random_string || timestamp_string || search_string = 'e04a621c3d09' || 'ea1ac7202e02' || '3588cd42' ='e04a621c3d09ea1ac7202e023588cd42' In this embodiment, the "au" string is a 32-byte hexadecimal string using all lowercase letters, conforming to specifications and ensuring consistency and ease of parsing. Furthermore, two's complement arithmetic (based on 0xFFFFFFFF) is used to disguise the timestamp, making it difficult for attackers to extract time information. To enhance security, the ASCII random string table can be changed periodically. The server and client must update this table simultaneously to maintain synchronization. Additionally, although 'HIDE' is used in this embodiment, predetermined characters can be changed for security purposes without altering the core algorithm, provided that the server and client synchronously reflect these changes.
[0049] In this embodiment, the verification process is designed to carefully reconstruct and verify each component of the au string 10, namely the spoofed timestamp 12, the random string 14, and the search string 16, which were generated during the verification string creation process. This process ensures that the au string 10 is authentic and undisturbed, thereby preventing unauthorized access and replay attacks. The following details the steps involved in verifying the verification string. Please refer to... Figure 1 and Figure 6A , Figure 6A The diagram illustrates a flowchart of one embodiment of the verification algorithm of the present invention for verifying a verification string.
[0050] Step S210: Extract random hexadecimal numbers As shown in step S210, the verification process begins by disassembling the received au string 10 to extract a random string 14, which is then decomposed into four random hexadecimal numbers (e.g., ...). Figure 6A It consists of r1_hex, r2_hex, r3_hex, and r4_hex.
[0051] Step S220: Extract the fake timestamp component As shown in step S220, the verification process extracts components of the fake timestamp 12 from the string "au" 10 (such as...). Figure 6A The components shown are ts_1_hex, ts_2_hex, ts_3_hex, and ts_4_hex. These components are formed by adding a random hexadecimal number to a portion of a two's complement timestamp during the generation process.
[0052] Step S230: Perform reverse addition to restore the two's complement timestamp component In step S230, the system performs a reverse addition operation to restore the two's complement timestamp component (such as...). Figure 6AThe numbers shown are ts_hex_com_1, ts_hex_com_2, ts_hex_com_3, and ts_hex_com_4. This is achieved by subtracting the corresponding random hexadecimal number from the fake timestamp component.
[0053] Calculation example: ts_hex_com_1 = ts_1_hex - r1_hex = 'ea1' - 'e04' = '9d' ts_hex_com_2 = ts_2_hex - r2_hex = 'ac7' - 'a62' = '65' ts_hex_com_3 = ts_3_hex - r3_hex = '202' - '1c3' = '3f' ts_hex_com_4 = ts_4_hex - r4_hex = 'e02' - 'd09' = 'f9' These calculations reconstruct the two's complement timestamp (e.g.) Figure 6A The bytes shown in ts_hex_com will be used to reconstruct the original timestamp.
[0054] Step S240: Reconstruct the two's complement timestamp As shown in step S240, the two's complement timestamp components are concatenated to form a complete two's complement timestamp (e.g., ...). Figure 6A (as shown in ts_hex_com).
[0055] Series example: ts_hex_com = ts_hex_com_1 || ts_hex_com_2 || ts_hex_com_3 || ts_hex_com_4 = '9d' || '65' || '3f' || 'f9' = '9d653ff9' Step S250: Restore the original timestamp In step S250, the original timestamp is restored by removing the two's complement spoofing (e.g., Figure 6A (as shown in ts_hex). This is achieved by calculating the two's complement of the timestamp.
[0056] Calculation example: ts_hex =0xFFFFFFFF - ts_hex_com = 0xFFFFFFFF - '9d653ff9' = '629ac006' Then, convert the hexadecimal timestamp back to its decimal form (e.g., ...). Figure 6A The ts_dec value is shown to represent the actual time.
[0057] Conversion example: ts_dec = hex_to_dec('629ac006') = 1654308870 Step S260: Timestamp Verification As shown in step S260, the timestamp is verified to ensure it falls within the allowed time window, preventing replay attacks using expired au strings. The current time (e.g., ...) is obtained. Figure 6A The example shows now(), and the difference between now() and ts_dec is calculated.
[0058] Verification example: Allowable time difference (e.g.) Figure 6A The ts_diff_allow shown is set to 7200 seconds (i.e., 2 hours).
[0059] ts_flag = (now() - ts_dec) ≤ ts_diff_allow ?"true" : "false" If ts_flag is "true", the timestamp is considered valid; otherwise, the string au10 is rejected because the timestamp has expired.
[0060] Step S270: ASCII random string table retrieval In step S270, the data source for the ASCII random string table used in the generation process is recalculated. The extracted r1_hex value is used to determine a specific row in the ASCII random string table.
[0061] Calculation example: r1_dec = hex_to_dec(r1_hex) = hex_to_dec('e04') = 3588 ascii_row_max = the total number of rows in the ASCII table (e.g., 10 rows). ascii_row = r1_dec % ascii_row_max = 3588 % 10 = 8 Then, retrieve the ASCII data source from the table: ascii_data_source = ascii_table[ascii_row] = ascii_table[8] In this example, the ASCII data source is line 8 of the ASCII table: 'aspmYN8jcDA97vtGVBwFqTL4gJdQ02KnPbXezIZhWok536uyHrUiSxlCEO1MRf' Step S280: Recalculate the search string As shown in step S280, by recognizing predetermined characters (such as...) in the selected ASCII data source... Figure 6B The positions of 'H', 'I', 'D', and 'E' are shown, and addition is performed with the corresponding random hexadecimal numbers to reconstruct the search string 16.
[0062] Sub-steps (please also refer to...) Figure 6B ): S282: Identifier Meta Location: s1_pos_dec = Position of 'H' in ascii_data_source = 49 (index based on 1) s2_pos_dec = the position of 'I' in ascii_data_source = 38 s3_pos_dec = the position of 'D' in ascii_data_source = 10 s4_pos_dec = The position of 'E' in ascii_data_source = 57 S284: Convert position to hexadecimal: s1_pos_hex = dec_to_hex(s1_pos_dec) = dec_to_hex(49) = '31' s2_pos_hex = dec_to_hex(s2_pos_dec) = dec_to_hex(38) = '26' s3_pos_hex = dec_to_hex(s3_pos_dec) = dec_to_hex(10) = '0a' s4_pos_hex = dec_to_hex(s4_pos_dec) = dec_to_hex(57) = '39' S285: Perform addition operation: s1_rand_hex = r1_hex + s1_pos_hex = 'e04' + '31' = 'e35' s2_rand_hex = r2_hex + s2_pos_hex = 'a62' + '26' = 'a88' s3_rand_hex = r3_hex + s3_pos_hex = '1c3' + '0a' = '1cd' s4_rand_hex = r4_hex + s4_pos_hex = 'd09' + '39' = 'd42' S286: Extract specific hexadecimal digits: The last two digits of s1_hex = s1_rand_hex = 'e35' → '35' The last two digits of s2_hex = s2_rand_hex = 'a88' → '88' The last two digits of s3_hex = s3_rand_hex = '1cd' → 'cd' The last two digits of s4_hex = s4_rand_hex = 'd42' → '42' S287: Reassemble the recalculated search string: s_cal_rand_hex = s1_hex || s2_hex || s3_hex || s4_hex = '35' || '88'|| 'cd' || '42' = '3588cd42' Step S290: Extract the search string from the au string In step S290, the system extracts the search string from the received "au" string 10.
[0063] Extraction example: s_au_rand_hex = substring of the string au from position 24 to 31 (8 bytes) = '3588cd42' Step S300: Search for string verification As shown in step S300, the recalculated search string (s_cal_rand_hex) is compared with the search string (s_au_rand_hex) extracted from the au string.
[0064] Comparison examples: compare_flag = (s_cal_rand_hex == s_au_rand_hex) ? "true" : "false" If compare_flag is "true", the search string is considered valid.
[0065] Step S310: Final Verification Decision In step S310, the system makes a final verification decision based on the timestamp verification result (ts_flag) and the search string verification result (compare_flag).
[0066] Decision-making example: allow_flag = (ts_flag == "true"&&compare_flag == "true") ? "true" : "false" If allow_flag is "true", the verification is successful and the network request is allowed to continue. If it is "false", the verification fails and the request is rejected or additional security measures are initiated.
[0067] The verification process described above meticulously reconstructs each component of the au string "10" to ensure its authenticity. In summary, during this verification process, a random hexadecimal number is extracted directly from the au string. Next, the spoofed timestamp is reconstructed using inverse addition and two's complement spoofing, and then verified to be within the allowed time frame to prevent replay attacks. Then, the search string "16" is recalculated using the same algorithm as in the generation process to ensure that the au string "10" has not been tampered with. The final decision is based on the successful verification of the timestamp and the search string.
[0068] This verification process enhances resistance to replay attacks by verifying timestamps within an allowed time window, preventing the reuse of old AU strings. Furthermore, the use of random hexadecimal numbers and a dynamic ASCII random string table makes it extremely difficult for attackers to predict or copy valid AU strings. Moreover, a detailed comparison of recalculated values with extracted components ensures the integrity of the AU string.
[0069] Please refer to Figure 1 and Figure 7 , Figure 7 The diagram illustrates an architecture of one embodiment of the defense response module of the present invention. Upon detection of a threat or verification failure, the defense response module 140 is activated to implement a multi-layered defense strategy. This defense response module 140 includes a packet filtering component 142, an IP address blocking component 144, an active threat neutralization component 146, and a Content Delivery Network (CDN) integration component (hereinafter referred to as CDN integration component 148).
[0070] Packet filtering component 142 involves deep packet inspection (DPI), analyzing malicious content in packet headers and payloads, protocol anomaly detection to identify deviations from standard protocol behavior, and signature-based filtering to block packets matching known malicious signatures. IP address blocking component 144 is implemented through a dynamic blacklist, automatically adding suspicious IP addresses to the blacklist based on threat intelligence and AI analysis. Furthermore, IP address blocking component 144 also includes geographic IP blocking functionality, restricting access from specific geographic locations when necessary.
[0071] The proactive threat neutralization component 146 is executed by custom scripts written in languages such as Python, Bash, or C / C++. These scripts respond to threats by terminating malicious processes, isolating infected devices, or performing other pre-defined security actions. This automated response workflow coordinates complex response actions without human intervention, enabling rapid and effective threat mitigation.
[0072] CDN integration component 148 plays a critical role in mitigating large-scale DDoS attacks by distributing network load across the content delivery network. Working in conjunction with CDN edge server 20, network security system 100 can filter malicious traffic before it reaches the origin server, leveraging the CDN's high bandwidth capabilities to absorb excess traffic and maintain service availability during large-scale attacks. This network security system 100 is designed to be highly scalable and compatible with existing network infrastructure. It operates in a virtual machine architecture compatible with mainstream Linux environments and hyper-converged infrastructure (HCI), allowing for dynamic resource allocation based on network load to ensure optimal performance. Network security system 100 supports an active-active operational mode, where multiple virtual machines run simultaneously to provide load balancing and fault tolerance, thereby improving reliability and performance. This configuration ensures high availability, prevents single points of failure, and allows the system to continue operating during maintenance or unexpected downtime.
[0073] It facilitates integration with existing systems through standard interfaces (such as APIs and standard protocols), enabling it to communicate seamlessly with Web Application Firewalls (WAFs) and other security systems. Custom interfaces are also supported for customized integration with proprietary systems as needed. The modular design of Network Security System 100 ensures that each component can be updated or replaced without affecting the overall system, providing flexibility and ease of customization based on specific security needs. The modular architecture of Network Security System 100 allows organizations to deploy specific modules according to their security requirements, enhancing the system's adaptability to various environments and use cases.
[0074] In summary, the following is a comprehensive explanation of the operation process of the network security system 100. Please refer to... Figure 8 , Figure 8 The diagram illustrates the operational flow of one embodiment of a network security system. First, as shown in step S410, the network security system 100's operation begins with continuous data collection and analysis, with the data collection module 110 gathering comprehensive network data. Then, as shown in step S420, the AI analysis engine 120 processes the data in real time to detect anomalies. When a network request is received, as shown in step S430, the verification module 130 uses a reverse verification algorithm to generate or verify the au string. Next, step S440 is executed; if verification is successful, the request is allowed to continue (step S450); if verification fails, the defense response module 140 is triggered (step S460).
[0075] In the above scenario, if the AI analysis engine 120 identifies an unusual pattern, the threat type is categorized as external, internal, or zero-day threat. The defense response module 140 then initiates appropriate actions, such as filtering malicious packets, blocking suspicious IP addresses, executing custom scripts to neutralize the threat, and enabling CDN services if necessary. Throughout the process, the network security system 100 continuously learns and adapts by updating the AI model based on new data and defense response results. For compliance and further analysis, the network security system 100 maintains logs and audit trails to ensure continuous improvement of security protocols and maintain accountability. In this embodiment, the network security system 100 is primarily developed using C / C++ to ensure efficient execution of performance-critical operations. It supports writing custom scripts using languages such as Python and Bash, allowing for flexible and rapid development of threat neutralization responses. The network security system 100 is compatible with mainstream Linux distributions, including Ubuntu and CentOS, facilitating widespread deployment in diverse environments. Performance indicators show that the network security system 100 can handle large volumes of network traffic with minimal latency and initiate defense mechanisms within seconds of threat detection. Scalability is achieved through horizontal scaling, which involves adding more virtual machines to handle increased workloads, ensuring that the system can grow with the organization's needs without compromising performance.
[0076] Security measures within the network security system 100 include the use of TLS / SSL for secure communication between components, role-based access control managed by a security management system, and detailed audit logs to maintain a comprehensive record of all activities. These measures ensure secure data processing and make the system resilient to potential intrusions. In some embodiments, the network security system 100 complies with data protection regulations such as GDPR or HIPAA, securely processes sensitive data, and has the capability to be configured to comply with specific regulatory requirements. This includes implementing data retention policies, encryption standards, and access controls to comply with organizational and legal standards.
[0077] This cybersecurity system is versatile and suitable for various industries requiring high security. In financial institutions, it protects sensitive financial data from sophisticated cyberattacks and detects fraudulent activities through behavioral analysis. Government agencies benefit from protecting critical infrastructure and confidential information while monitoring internal threats within secure networks. Large enterprise environments can leverage this cybersecurity system to provide comprehensive security for their extensive networks and enhance existing security frameworks with AI-driven analytics. Furthermore, cloud service providers can dynamically scale this cybersecurity system as part of their managed security services to handle varying multi-tenant loads and ensure robust protection for cloud services. This cybersecurity system offers several advantages over traditional cybersecurity systems. Unlike static rule-based systems, the AI analytics engine within the cybersecurity system adapts to new threats without manual updates, providing proactive and real-time threat detection and response. Comprehensive coverage of both external and internal threats ensures a holistic security solution that addresses a wide range of network risks. Dynamic verification provided by reverse engineering algorithms adds a layer of security that is difficult to bypass, significantly improving the resilience of the cybersecurity system against common attack vectors such as replay and predictive attacks. Moreover, the operational efficiency achieved through automated threat detection and response reduces the need for continuous manual monitoring, allowing security personnel to focus on more strategic tasks. For maintenance and updates, measures can be taken including regularly retraining the AI analytics engine with new data to improve accuracy and responsiveness to emerging threats. Regularly deploying software updates to patch vulnerabilities and enhance system functionality ensures that cybersecurity systems remain secure and in sync with the latest security advancements. Using configuration management tools like Ansible or Puppet maintains consistent deployment and configuration across virtual machines, promoting efficient and error-free system management.
[0078] In summary, the network security system is designed to be flexible and adaptable, allowing for various modifications and enhancements. The reverse verification algorithm can be modified to integrate different encryption technologies or adjust the length of the AU string to meet specific security requirements. It can also be integrated with Security Information and Event Management (SIEM) systems for centralized monitoring and management of security incidents. Furthermore, the network security system is adaptable to cloud environments such as AWS, Azure, or Google Cloud Platform, expanding its applicability and ensuring it meets the diverse needs of modern enterprises. This invention details a sophisticated network security system that combines AI-driven behavioral analytics with a novel reverse verification algorithm to provide robust protection against a wide range of cyber threats. Through real-time detection and response, dynamic verification, and tight integration with existing infrastructure, this invention fills a key gap in traditional network security approaches. Its modular design, scalability, and adaptability make it a valuable asset for organizations to enhance their security posture in an increasingly complex threat environment.
[0079] Although the present invention has been disclosed above with reference to embodiments, it is not intended to limit the present invention. Those skilled in the art can make appropriate modifications without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention shall be defined by the claims.
Claims
1. An artificial intelligence-driven dynamic reverse verification network security system for detecting and responding to threats in a network environment, characterized in that, The network security system includes: A data collection module is configured to collect network data, which includes timestamps; An AI analytics engine is configured to use behavioral analysis to process collected data in order to identify and display anomalous patterns of cybersecurity threats. A verification module implements a reverse verification algorithm to generate and verify a unique verification string, wherein the verification string includes: A random string, consisting of a set of random hexadecimal numbers generated within a specified range; A fake timestamp is generated by obtaining the current timestamp, converting the timestamp into the same base as the random number, and applying two's complement operation to mask the original value before combining it with the random string. A search string is generated as follows: A modulo operation is performed on a random value from the random string; a data row from an ASCII random string table is dynamically selected as the source; the position of a predetermined character in that data row is obtained; and the random value is added to the position to extract specific digits to form the search string; and A defense response module is configured to initiate a layered defense response when the abnormal pattern is detected or the verification fails.
2. The network security system according to claim 1, characterized in that, The reverse verification algorithm periodically updates the ASCII random string table to enhance security and prevent predictability.
3. The network security system according to claim 1, characterized in that, This verification module verifies an incoming network request by disassembling the received verification string to extract and verify the spoofed timestamp, the random string, and the search string. The steps include: The two's complement operation of the fake timestamp is reversed to restore the original timestamp, and the timestamp is verified to be within the allowed time difference range to prevent replay attacks. The search string is recalculated and compared with the search string extracted from the verification string to ensure integrity.
4. The network security system according to claim 1, characterized in that, The defense response module includes: A packet filtering component is used to remove malicious data; An IP address blocking component that blocks access from suspicious IP addresses by adding malicious sources to a blacklist; A proactive threat neutralization component, configured to execute at least one custom script to proactively neutralize identified threats; and A content delivery network integration component that mitigates traffic-based distributed denial-of-service attacks by distributing network traffic.
5. The network security system according to claim 1, characterized in that, The AI analytics engine also includes an AI auditor component, configured to perform in-depth analysis of user behavior patterns to detect insider threats.
6. A network security method, characterized in that, This network security method, executed automatically through a network security system, includes: A data collection module collects network data, which includes a timestamp. An AI analytics engine uses artificial intelligence-based behavioral analysis to analyze the collected data to identify and reveal abnormal patterns that indicate cybersecurity threats. A unique verification string is generated by a verification module using a reverse verification algorithm, wherein the verification string includes: A random string, consisting of a set of random hexadecimal numbers generated within a specified range; A fake timestamp is created by obtaining the current timestamp, converting it to hexadecimal, applying two's complement arithmetic, and then combining it with a random hexadecimal number through addition; and A search string is generated through the following steps: Based on the modulo operation of one of the random hexadecimal numbers, select one row of ASCII data source from an ASCII random string table; Identify the position of a predetermined character in the selected ASCII data source line; and The algorithm performs an addition operation on a random hexadecimal number and the identified position, and extracts a specific hexadecimal number to form a search string. The incoming network request is verified by dissecting the received verification string to extract and verify the spoofed timestamp, random hexadecimal numbers, and search string, including: The reverse spoofing operation is performed to restore the original timestamp and verify whether it is within the allowed time difference range to prevent replay attacks. Recalculate the search string and compare it with the search string extracted from the verification string to ensure integrity; When an abnormal pattern is detected or verification fails, a layered defense response is initiated by a defense response module.