A network proactive security protection method and device based on flow integrity verification
By constructing a flow set and consistency baseline for communication flows in the TSN network, and generating flow integrity information for multi-dimensional anomaly detection, the integrity verification problem at the link layer of the TSN network is solved, enabling real-time proactive security protection of communication flows and improving the security and robustness of the network.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- COMP APPL TECH INST OF CHINA NORTH IND GRP
- Filing Date
- 2026-05-08
- Publication Date
- 2026-06-02
AI Technical Summary
Existing TSN networks lack the ability to verify the integrity of communication flows at the link layer, making it difficult to cope with sophisticated attacks in complex environments. Furthermore, centralized detection response speed is insufficient, failing to meet the security protection requirements of vehicle and industrial control systems for millisecond-level latency.
By constructing a stream set and consistency baseline for communication streams, stream integrity information is generated and transmitted. The receiving end performs multi-dimensional anomaly judgment and triggers proactive security protection, including content consistency verification, timing consistency and synchronization offset verification, to achieve real-time protection and adaptive policy adjustment on the network side.
Without altering the existing TSN protocol architecture, it achieves multi-dimensional modeling and verification of communication flow behavior, rapidly identifies abnormal flows, improves network security and robustness under complex operating conditions, and meets the requirements of real-time performance and determinism.
Smart Images

Figure CN122137693A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication network security technology, and in particular to a network proactive security protection method and apparatus based on flow integrity verification. Background Technology
[0002] With the rapid development of vehicle integrated electronic systems, electronic devices, and the Industrial Internet, the scale and real-time requirements of internal system information interaction are continuously increasing. Network architecture is evolving from traditional multi-bus, distributed control modes to a unified communication architecture centered on Ethernet. In this evolution, communication networks not only need to carry the concurrent transmission of multi-source sensing data, control commands, and status information, but also must ensure deterministic latency, reliable bandwidth, and precise time synchronization capabilities under complex electromagnetic environments and highly dynamic operating conditions. Time-Sensitive Networking (TSN), as an important component of the IEEE 802.1 series of standards, endows Ethernet with deterministic communication capabilities by introducing mechanisms such as time synchronization, traffic shaping, and queue scheduling, and has become a key foundational technology for vehicle networks, electronic networks, and industrial control networks.
[0003] Existing TSN architectures primarily rely on the Per-Stream Filtering and Policing (PSFP) mechanism defined by IEEE 802.1Qci at the link layer to constrain bandwidth, gate control, and discard abnormal frames. While this mechanism can ensure network real-time performance and link stability to some extent, its security capabilities mainly manifest as passively intercepting data frames that do not conform to pre-configured rules, lacking a deep semantic understanding of the communication flow behavior itself. In highly connected automotive integrated electronic systems and industrial Ethernet environments, with the increase in the number of external interfaces, enhanced inter-domain communication, and the continuous expansion of the network attack surface, PSFP, which relies solely on static rule configuration, is insufficient to effectively address emerging security threats such as flow content spoofing, legitimate flow replay, time window spoofing, and sophisticated covert attacks conforming to bandwidth models.
[0004] Furthermore, the criteria for PSFP (Power Sweep Filtering) primarily focus on superficial characteristics such as bandwidth, rate, and gating time. Its design prioritizes traffic shaping and real-time performance assurance, rather than security verification of communication flow integrity. When attackers can construct data flows that meet bandwidth and periodic constraints, existing mechanisms struggle to distinguish between legitimate and malicious flows in terms of content continuity, temporal consistency, and session freshness. In addition, PSFP typically relies on centralized configuration and operates with static parameters, lacking the ability to adaptively identify evolving flow behavior and failing to trigger rapid, distributed proactive protection actions upon anomaly detection, thus limiting its effectiveness in security-sensitive scenarios.
[0005] While existing research attempts to combine software-defined networking (SDN) controllers or centralized network management systems for statistical analysis and anomaly detection of TSN network operation status, these solutions mostly rely on periodic data reporting and centralized decision-making. Response speed is limited by control link and computational latency, making it difficult to meet the millisecond-level or even lower latency security requirements of automotive and industrial control systems. Furthermore, centralized analysis methods often focus on macroscopic traffic characteristics, making it difficult to achieve fine-grained integrity verification and real-time handling of individual communication flows at the link layer.
[0006] Therefore, without disrupting the existing TSN protocol system and network architecture, how to introduce a communication flow-oriented integrity verification mechanism at the link layer, enhance the joint perception capability of content, timing and synchronization consistency, and further realize proactive security protection and adaptive strategy adjustment on the network side has become a key technical problem that urgently needs to be solved in the field of integrated electronic system network security. Summary of the Invention
[0007] Based on the above analysis, the embodiments of the present invention aim to provide a network proactive security protection method and apparatus based on flow integrity verification, in order to solve the problems of existing TSN mainly relying on static rule filtering at the link layer and lacking communication flow integrity verification capabilities.
[0008] On the one hand, this invention proposes a proactive network security protection method based on flow integrity verification, the method comprising: Construct a flow set consisting of all communication flows in the time-sensitive network, and a consistency baseline for each communication flow under normal operating conditions; The network node on the sending side generates the flow integrity information of the data frame to be sent in the data stream, and injects the flow integrity information along with the data frame into the time-sensitive network for transmission; The receiving network node performs multi-dimensional anomaly judgment on the communication stream based on the received data frame and the consistency baseline and flow integrity information. If an anomaly is found, the corresponding multi-dimensional anomaly result of the data stream is output. The receiving network node makes a comprehensive anomaly judgment on the communication flow based on the multi-dimensional anomaly results of the data flow. If the comprehensive anomaly judgment result is anomaly, it triggers proactive security protection.
[0009] Based on the above method, the present invention also makes the following improvements: Furthermore, the stream integrity information includes content integrity information and temporal correlation information.
[0010] Furthermore, the network node on the sending side generates content integrity information for the data frames to be sent in the data stream by performing the following operations: Extract content association information that characterizes the features of the frame content from the payload content of the data frame to be sent; The content association information is associated with the content integrity information of the communication stream in the previous data frame to form the content integrity information of the current data frame.
[0011] Furthermore, the network node on the sending side generates timing association information for the data frames to be sent in the data stream by performing the following operations: Based on the transmission time of the data frame to be sent and the periodic parameters of the communication stream, corresponding timing association information is generated.
[0012] Furthermore, the multi-dimensional anomaly detection includes content consistency verification, communication stream timing consistency verification, and synchronization offset verification. The multidimensional anomaly results include consistency verification failure results and / or timing verification failure results.
[0013] Furthermore, the content consistency check is performed as follows: The receiving network node performs a consistency check on the content association between consecutive data frames of the communication flow based on the consistency baseline of the communication flow and the flow integrity information carried by the data frame. If the consistency check fails, there is an anomaly, and the consistency check failure result is output.
[0014] Furthermore, the communication stream timing consistency and synchronization offset verification are performed as follows: The receiving network node sequentially performs timing consistency verification and synchronization offset verification based on flow integrity information on the communication flow. If the timing consistency verification or synchronization offset verification fails, an anomaly is found, and the timing verification failure result is output.
[0015] Furthermore, the network node at the receiving end performs a comprehensive anomaly determination of the communication flow based on the multi-dimensional anomaly results of the communication flow, and executes: Based on the content anomaly flag in the content consistency verification failure result and the timing anomaly flag in the timing verification failure result, calculate the comprehensive anomaly judgment result of the corresponding data frame; If the combined anomaly determination results of multiple consecutive data frames are all higher than the anomaly trigger threshold, the corresponding communication flow enters an abnormal operation state and triggers network-side proactive security protection.
[0016] Furthermore, the method also includes: After completing the proactive security protection of the communication flow, the consistency baseline and the proactive security protection strategy are adaptively updated based on the feedback of the data flow's operating status.
[0017] On the other hand, the present invention also provides a network proactive security protection device based on flow integrity verification, the device comprising: The baseline building module is used to build a set of all communication flows in a time-sensitive network, as well as a consistent baseline for each communication flow under normal operating conditions. The flow integrity information generation module is used to control the network nodes on the sending side to generate flow integrity information of the data frames to be sent in the data stream, and inject the flow integrity information along with the data frames into the time-sensitive network for transmission; The anomaly detection module is used to control the network nodes on the receiving side to perform multi-dimensional anomaly detection on the communication stream based on the received data frames, and if an anomaly is found, the multi-dimensional anomaly result of the corresponding data stream is output. The security protection trigger module is used to control the network node at the receiving end to make a comprehensive anomaly judgment on the communication flow based on the multi-dimensional anomaly results of the data flow. If the comprehensive anomaly judgment result is an anomaly, it triggers active security protection.
[0018] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects: This invention proposes a network proactive security protection method and device based on flow integrity verification. It is designed for time-sensitive network environments in vehicle integrated electronic systems, electronic networks and industrial Ethernet. Without changing the existing TSN protocol system and scheduling mechanism, it can quickly identify and proactively protect abnormal communication flows through multi-dimensional modeling and continuous verification of communication flow behavior, thereby improving the security, determinism and operational robustness of the network under complex operating conditions.
[0019] Specifically, the proactive security protection method provided by this invention takes communication flows as the basic protection object and constructs a link-layer-oriented flow integrity verification mechanism based on the content consistency, timing consistency, and time synchronization characteristics of the flow during transmission. By introducing integrity information associated with flow behavior during data frame transmission, the network side can continuously verify the consistency of the communication flow's transmission behavior within different time windows, thereby overcoming the limitations of traditional methods that rely solely on bandwidth, rate, and gating parameters for judgment. Furthermore, this method can effectively identify sophisticated attacks where surface traffic characteristics meet configuration requirements but content association, timing evolution, or synchronization behavior exhibits anomalies, providing a higher-dimensional basis for network security protection.
[0020] Furthermore, this invention introduces a proactive security protection mechanism based on flow integrity verification, enabling the network to take immediate action at the link layer upon detecting abnormal communication flows. Therefore, this method no longer relies on post-event analysis by centralized control nodes, but instead directly triggers protective actions such as rate limiting, isolation, enhanced discarding, or policy adjustments through real-time determination of abnormal behavior by the network side. This suppresses the propagation of abnormal flows within millisecond timescales, reducing their impact on critical business communications. By tightly integrating detection and handling, this invention forms a closed-loop network security protection process, significantly improving the system's responsiveness to dynamic attack scenarios.
[0021] Furthermore, the method of this invention supports continuous awareness of network operating status and adaptive updates to security policies. Through the convergence and analysis of abnormal events and their handling results, the flow judgment threshold and protection strategies can be dynamically adjusted based on changes in network load, evolution of attack characteristics, and differences in service importance, thereby continuously optimizing security capabilities as the system operates. Therefore, this invention not only meets the basic requirements of time-sensitive networks for real-time performance and determinism but also provides an adaptive proactive security protection solution for integrated electronic systems in complex electromagnetic environments and multi-attack surface application scenarios.
[0022] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description
[0023] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts. Figure 1 This is a flowchart of the network proactive security protection method based on flow integrity verification provided in Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the network active security protection device based on flow integrity verification provided in Embodiment 2 of the present invention. Detailed Implementation
[0024] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.
[0025] Specific embodiment 1 of the present invention discloses a network proactive security protection method based on flow integrity verification, the flowchart of which is as follows: Figure 1As shown, the specific explanation is as follows.
[0026] Step S1: Construct a flow set consisting of all communication flows in the time-sensitive network, and a consistency baseline for each communication flow under normal operating conditions.
[0027] Step S11: Construct a stream set consisting of all communication streams participating in time-sensitive communication in the time-sensitive network.
[0028] In the specific implementation process, a unified model is performed on all communication flows involved in key protection of time-sensitive communications in the time-sensitive network, and a flow set composed of all communication flows is constructed. ,in, Indicates the first communication flow, This represents the total number of communication flows. This set of flows forms the basis of the constraint set for subsequent integrity verification and proactive protection.
[0029] Step S12: Construct a set of security profile parameters for each communication stream.
[0030] Specifically, for each communication flow, a corresponding security profile parameter set is constructed based on the service type, real-time requirements, and security sensitivity. Preferably, in this embodiment, the security profile parameter set includes at least a period parameter, a bandwidth constraint parameter, and a time consistency judgment threshold.
[0031] For example, the first communication flow Security profile parameter set include: Periodic parameters Also known as the communication period or expected transmission interval, it is used to characterize the periodicity or transmission rhythm of the communication flow in the time dimension. Bandwidth constraint parameters Also known as bandwidth or rate constraint parameters, these parameters are used to limit the resource usage of communication flows at the link layer. Time consistency determination threshold Used to constrain the allowable time offset range of communication streams during transmission; : Used to unify the triggering conditions for subsequent multidimensional anomaly determination.
[0032] It's important to note that constructing security profile parameters is not simply replicating network scheduling parameters. Instead, it involves abstracting the behavioral characteristics that communication flows should exhibit under normal operating conditions at the methodological level. This abstraction simultaneously covers bandwidth characteristics, timing characteristics, and the sensitivity information required for subsequent security assessments. Once the security profile parameter set is completed, it can guide subsequent communication flow integrity verification, anomaly detection, and the execution of proactive protection strategies. By introducing the security profile modeling process, the network side can establish clear and quantifiable reference benchmarks for the normal behavior of communication flows, thereby avoiding the problem of scattered or conflicting judgment criteria in subsequent steps.
[0033] Step S13: Based on the security profile parameter set of each communication flow, establish a consistency baseline for the corresponding communication flow under normal operating conditions.
[0034] Specifically, in this embodiment, based on the periodic parameters and bandwidth constraint parameters of each communication flow, the allowable transmission rhythm and resource consumption range of the corresponding communication flow at the link layer are constrained, thereby forming a constraint range defined by the periodic parameters and bandwidth constraint parameters of the communication flow. When the communication flow is in normal operation, if the communication flow meets the constraint range within multiple consecutive time windows, it is determined that the communication flow is currently in a consistency baseline state. A consistency baseline for the communication flow in normal operation is constructed for subsequent integrity verification and anomaly detection as a comparison reference. In this embodiment, the consistency baseline of the communication flow under normal operating conditions is used to characterize the behavioral characteristics of the communication flow under normal operating conditions. It includes at least the content evolution characteristics, temporal distribution characteristics, and time synchronization offset characteristics of the communication flow, which provides a multi-dimensional reference for subsequent integrity verification and anomaly determination.
[0035] It should be noted that in this embodiment, constraint initialization is not only used to limit the instantaneous behavior of communication flows, but also serves as a reference benchmark for subsequent security determinations. Therefore, after the method starts or parameters are updated, it is necessary to continuously collect the frame arrival time and bandwidth usage of each communication flow during its transmission process under normal conditions, and verify whether it stably conforms to the constraint range defined by the periodic parameters and bandwidth constraint parameters. In other words, by introducing a consistency baseline establishment process in the early stages of the method, this embodiment can effectively avoid misjudgments that may arise from directly performing anomaly detection in the absence of a reference state. This consistency baseline is not a static rule, but a dynamic reference that can be continuously verified and updated during method execution. This allows subsequent steps to conduct integrity verification and proactive protection determinations based on a clear distinction between "normal behavior fluctuations" and "abnormal behavior deviations," thereby improving the overall stability and practicality of the method.
[0036] Step S2: The network node on the sending side generates the flow integrity information of the data frame to be sent in the data stream, and injects the flow integrity information along with the data frame into the time-sensitive network for transmission.
[0037] This embodiment generates flow integrity information for subsequent verification based on key behavioral characteristics during communication stream transmission, and injects this information into the network for transmission along with the data frames. It should be noted that flow integrity information is not a single static identifier, but rather a composite of information reflecting the content evolution and temporal characteristics during continuous transmission of the communication stream. Flow integrity information includes content integrity information and temporal correlation information.
[0038] Step S21: Extract content association information that characterizes the frame content features from the payload content of the data frame to be sent; associate the content association information with the content integrity information of the communication flow in the previous data frame to form the content integrity information of the current data frame.
[0039] Specifically, when the network node on the sending side sends the first... communication flow The first in Data frames At that time, it is first based on the data frame The payload content extraction function extracts content association information that characterizes the frame content features, and then integrates this content association information with the communication stream in the previous data frame. The content integrity information generated in the middle is correlated to form a data frame with the current data frame. And the content integrity information associated with the historical transmission behavior of the communication stream.
[0040] This method enables communication streams to form stable content associations between consecutive data frames, thereby ensuring that the content evolution of the communication stream is continuous and predictable under normal operating conditions.
[0041] Step S22: Generate corresponding timing association information based on the transmission time of the data frame to be sent and the periodic parameters of the communication stream.
[0042] Specifically, to ensure that integrity information accurately reflects the transmission behavior of the communication flow in the time dimension, this embodiment also introduces timing association information related to the timing characteristics of the communication flow when generating integrity information. This timing association information is used to characterize the time window or transmission stage to which the data frame belongs. Its generation process is related to the periodic parameters of the communication flow and the sending (or arrival) time of the current data frame, so that data frames in different time windows have distinguishable timing characteristics at the integrity information level, thereby avoiding the communication flow being misjudged as legitimate transmission when replayed across time windows or when timing is disordered.
[0043] Preferably, in this embodiment, the timing association information includes the target time window, transmission stage, or period position to which the current data frame belongs, so that the network node on the receiving side can determine the time interval in which the data frame should appear under normal operating conditions based on the information.
[0044] Furthermore, to enhance the timeliness and replay resistance of integrity information during method execution, this embodiment can also introduce state association information reflecting the current running state or session stage of the communication flow when generating flow integrity information. This state association information is used to characterize the phased state changes of the communication flow during method execution, ensuring that the integrity information is not only associated with the content and timing of data frames, but also consistent with the running stage of the communication flow, thereby preventing attackers from bypassing subsequent verification steps by reusing historical integrity information over a long period.
[0045] In practical implementation, the aforementioned content-related information, timing-related information, and / or status-related information can be combined into the flow integrity information of the data frame and embedded in a predetermined field of the data frame or in a transmission unit associated with the data frame, so that it is transmitted as part of the communication flow behavior along with the data frame in a time-sensitive network. This embodiment, by introducing integrity information that is multidimensionally associated with the content, timing, and running status of the communication flow during the method execution process, provides a clear and implementable information foundation for subsequent consistency verification and anomaly determination steps of the communication flow integrity.
[0046] Step S3: The network node on the receiving side performs multi-dimensional anomaly judgment on the communication stream based on the received data frame and the consistency baseline and flow integrity information. If an anomaly exists, it outputs the multi-dimensional anomaly result of the corresponding data stream.
[0047] Preferably, in this embodiment, the multi-dimensional anomaly detection includes content consistency verification, communication flow timing consistency verification, and synchronization offset verification. Accordingly, the output multi-dimensional anomaly results include consistency verification failure results and / or timing verification failure results. The specific implementation process is described below.
[0048] Step S31: The network nodes (switching nodes / forwarding nodes / receiving devices) on the receiving side perform consistency checks on the content association between consecutive data frames of the communication flow based on the consistency baseline of the communication flow and the flow integrity information carried by the data frames. If the consistency check fails, there is an anomaly, and the consistency check failure result is output.
[0049] Specifically, this embodiment verifies the consistency of the content association between consecutive data frames in the communication stream to determine whether the content evolution of the communication stream conforms to the consistency baseline.
[0050] Specifically, when the receiving network node receives the first... communication flow The first in Data frames At that time, the stream integrity information carried by the data frame is obtained, that is: from the data frame The corresponding content association information is obtained by parsing, and the communication stream is read from the previous data frame. The integrity information recorded during processing serves as a reference input for the current consistency check.
[0051] In this step, content consistency verification is achieved by determining the relationship between the content association information of the current frame and the historical content integrity information. Specifically, based on the consistency baseline formed under normal operation of the communication flow, it is determined whether the content association information carried by the current data frame can be derived from the content integrity information of the previous data frame under the expected evolution rules. If so (i.e., the relationship between two adjacent data frames meets the expected continuity requirements), the communication flow is considered to be in a content-consistent state in the current data frame, and the content integrity information of the current data frame is updated. The consistency verification of the content association relationship between the communication flow and consecutive data frames passes. Conversely, if it is detected that the content association information of the current data frame cannot establish a reasonable association with the content integrity information of the previous data frame, or its change characteristics deviate significantly from the consistency baseline, it is determined that the communication flow has a content consistency anomaly in the current data frame, and the consistency verification of the content association relationship between the communication flow and consecutive data frames fails. The consistency verification failure result is output, including: the content anomaly identifier corresponding to the current data frame, and the occurrence location and time information of the corresponding anomaly event are recorded.
[0052] For example, in terms of content consistency verification, the first communication flow The first in Data frames Content integrity information Represented as: (1) in, Indicates the first communication flow The first in Data frames Content association information, Indicates the first communication flow The first in Data frames Content integrity information; This represents a content association mapping function for a communication stream, used to describe the evolutionary relationship between the contents of adjacent data frames. For a normal communication stream, this mapping function exhibits a stable evolutionary pattern between consecutive data frames.
[0053] In practice, a content consistency deviation metric function can be used for consistency verification. communication flow The first in Data frames Content consistency deviation measurement function Represented as: (2) in, Indicates the first communication flow The first in Data frames The expected content integrity information, that is, the expected content state derived from historical content integrity information and consistency baseline. When Exceeding the preset number communication flow Content consistency deviation threshold At that time, the communication flow is determined in the first... A content inconsistency anomaly occurred at one data frame.
[0054] It should be noted that the consistency deviation metric function is used to uniformly quantify the degree of anomaly in the content association of communication streams. The aforementioned two scenarios, "inability to establish a reasonable association" and "deviation from the consistency baseline," both mathematically represent an increased deviation between the current content state and the expected state. Therefore, both can achieve unified anomaly identification by determining whether the deviation metric function result exceeds a preset threshold.
[0055] When a content consistency anomaly occurs, this embodiment generates a corresponding content anomaly identifier at the method level and records the location and time information of the anomaly event for multi-dimensional anomaly fusion judgment in subsequent steps. It should be noted that this step only verifies content consistency and generates an identifier; it does not directly trigger protective actions. Instead, the content anomaly identifier is used as one of the important inputs for subsequent comprehensive judgment. Through the above content consistency verification process, this embodiment can promptly identify abnormal behaviors such as tampering, insertion, or replay of communication stream content at the link layer, providing traceable and verifiable content-side evidence for subsequent proactive security protection.
[0056] Step S32: The network node on the receiving side performs timing consistency verification and synchronization offset verification on the communication flow based on flow integrity information in sequence. If the timing consistency verification or synchronization offset verification fails, there is an anomaly, and the timing verification failure result is output.
[0057] (1) Timing consistency verification This embodiment verifies the timing consistency of the communication flow by performing time-series consistency verification on the transmission behavior of the communication flow in the time dimension. It can determine whether the current data frame conforms to the consistency baseline of the corresponding communication flow in terms of transmission rhythm and time synchronization.
[0058] It should be noted that the timing consistency verification is based on the timing association information generated by the network node on the sending side in step S22 and carried with the data frame.
[0059] Specifically, when the receiving network node receives the first... communication flow The first in Data frames First, the corresponding timing association information is parsed from the data frame, and then the actual arrival time of the data frame is obtained.
[0060] Subsequently, based on the period parameters, reference start time, and allowable time offset range recorded in the consistency baseline, the target time window corresponding to the timing association information is determined. In other words, the receiving side does not solely rely on the period parameters to determine whether the current data frame has arrived correctly. Instead, it first uses the timing association information carried by the data frame to determine the time window or transmission phase to which it belongs, and then, based on the time constraints pre-established in the consistency baseline, obtains the target time interval that the data frame should fall into under normal operating conditions.
[0061] Based on this, the actual arrival time of the current data frame is compared with the target time window. If the actual arrival time falls within the corresponding target time window interval, and the deviation of the actual arrival time from the center or boundary position of the target time window does not exceed the preset allowable time offset range in the consistency baseline, then the current data frame is determined to meet the basic timing consistency requirements, and the timing consistency verification passes. Conversely, if the actual arrival time does not fall within the target time interval corresponding to the timing association information, or although it falls within the time interval, its time offset exceeds the allowable range, then the current data frame is determined to have a timing consistency anomaly.
[0062] (2) Synchronous offset verification For communication flows requiring timing consistency verification, perform synchronization offset verification based on flow integrity information.
[0063] Specifically, to enhance the ability to identify abnormal behaviors such as time spoofing, delay injection, and cross-cycle replay, this embodiment can also verify the synchronization offset based on the deviation between the actual arrival time and the theoretical expected arrival time of the current data frame after passing the timing consistency verification.
[0064] Specifically, based on the periodic parameters of the communication stream and its corresponding reference time position in the consistency baseline, the theoretical expected arrival time of the current data frame under normal operating conditions is determined, and the actual arrival time is compared with the theoretical expected arrival time. When the deviation between the two is within the allowable range, the data frame is considered to satisfy the synchronization offset constraint; otherwise, the data frame is considered to have an anomaly at the time synchronization level.
[0065] Specifically, by comparing the actual arrival time of the current data frame. With communication flow-based periodic parameters The determined expected arrival time is used to assess the time offset of the communication stream in the current data frame.
[0066] Regarding timing consistency and synchronization offset verification, this embodiment utilizes the periodic parameters of the communication stream. Construct an expected arrival time model. No. communication flow The first in Data frames Expected arrival time It can be represented as: (3) in, Indicates the first communication flow The reference start time can be determined by the consistency baseline establishment phase or the system initialization phase.
[0067] Based on this, the first is defined communication flow In the Data frames Time offset at for: (4) when ,in, For the first communication flow The time consistency threshold is used to determine if there is a synchronization offset anomaly in the data frame.
[0068] Therefore, in this embodiment, a timing anomaly flag is added to data frames that fail timing consistency verification or synchronization offset verification, resulting in a timing verification failure.
[0069] It should be noted that the aforementioned time window-based timing consistency verification and the synchronization offset verification in this step are independent of each other in terms of method: the former is used to determine whether the data frame falls into the correct time interval, and the latter is used to determine whether the time offset of the data frame in the correct time interval exceeds the allowable range.
[0070] If the time offset is within the allowable range specified by the time consistency threshold, the communication flow is considered to meet the synchronization offset constraint in the current frame; conversely, if the time offset is found to be continuous or significantly exceeding the allowable range, the communication flow is judged to have abnormal behavior in terms of time synchronization. When a time consistency anomaly or a synchronization offset anomaly occurs, this embodiment generates a corresponding time anomaly identifier in the method and records the time window and offset characteristics of the anomaly, providing a reference for the multi-dimensional anomaly fusion judgment in subsequent steps.
[0071] Therefore, in this embodiment, the key to timing consistency verification is not to abstractly compare "timing information" and "actual time," but rather to first determine the target time window where the current data frame should be located through timing association information, then determine whether it arrives on time within the correct window based on the actual arrival time, and further combine this with the allowed time offset range to complete synchronization offset verification. Using this method, clear and executable judgments can be made regarding abnormal transmission rhythms, abnormal window misalignment, early arrivals, late arrivals, and cross-cycle replays in the communication stream.
[0072] It is important to note that this step only verifies and generates an identifier for the behavior of the communication flow in the time dimension. It does not directly trigger protective measures. Instead, the timing anomaly identifier, along with the aforementioned content anomaly identifier, serves as an important basis for subsequent comprehensive judgment. Through the above timing consistency and synchronization offset verification process, this embodiment can identify abnormal behaviors of the communication flow such as cross-cycle replay, delay injection, and clock spoofing at the link layer, thereby further enhancing the network's ability to perceive complex attack scenarios.
[0073] Step S4: The network node at the receiving end performs a comprehensive anomaly determination on the communication flow based on the multi-dimensional anomaly results of the communication flow. If the comprehensive anomaly determination result is anomaly, it triggers proactive security protection.
[0074] Step S41: The network node at the receiving end makes a comprehensive anomaly determination of the communication flow based on the multi-dimensional anomaly results of the communication flow.
[0075] After completing the verification of communication flow content consistency, timing consistency and synchronization offset, this embodiment further performs a comprehensive analysis of the multi-dimensional anomaly identifiers generated in the aforementioned steps in order to achieve a unified anomaly determination of the overall operating status of the communication flow.
[0076] Specifically, for any communication flow in the communication flow set, the content anomaly identifiers in the content consistency verification failure results and the timing anomaly identifiers in the timing verification failure results are collected to construct an anomaly state description that reflects the comprehensive behavioral characteristics of the communication flow in the current running cycle.
[0077] In this step, the comprehensive anomaly determination is not based on the instantaneous occurrence of a single anomaly identifier, but rather on the anomaly evolution characteristics of the communication flow within continuous data frames and time windows. Specifically, based on the consistency baseline formed under normal communication flow conditions, the frequency, duration, and combination characteristics of content anomaly identifiers and timing anomaly identifiers are comprehensively analyzed to distinguish between occasional disturbances and persistent or systematic anomalies. When multidimensional anomaly identifiers show a stable correlation in the time dimension or frame sequence dimension, or when their evolution characteristics significantly deviate from the consistency baseline, the communication flow can be determined to have entered an abnormal operating state.
[0078] To avoid misjudgments caused by single-dimensional anomalies, this embodiment introduces multi-dimensional correlation constraints in the comprehensive anomaly determination process: confirmation of an abnormal communication flow status is triggered only when the content anomaly identifier and the timing anomaly identifier form a synergistic relationship within the correlation window, or when either anomaly identifier continuously exceeds the expected range. Through this mechanism, this method can effectively suppress false alarms caused by instantaneous jitter, link disturbances, or occasional load changes while maintaining high sensitivity to covert attacks.
[0079] In the comprehensive anomaly determination stage, this embodiment further constructs a multi-dimensional anomaly scoring function to integrate the comprehensive anomaly determination results of content anomalies and temporal anomalies.
[0080] No. communication flow The first in Data frames Comprehensive anomaly determination results Represented as: (5) in, , They represent the first communication flow Weighting coefficients for content anomalies and temporal anomalies. This is an indicator function.
[0081] If the combined anomaly determination results of multiple consecutive data frames are all higher than the anomaly trigger threshold, the corresponding communication flow enters an abnormal operation state and triggers network-side proactive security protection.
[0082] Through the aforementioned mathematical mapping and quantification methods, this embodiment can uniformly map the content evolution characteristics and temporal behavior characteristics of communication flows to a computable anomaly metric space. This provides a clear, feasible, and engineering-promising technical path for communication flow integrity verification, multi-dimensional anomaly fusion judgment, and proactive security protection. When the comprehensive anomaly judgment result indicates that the communication flow is in an abnormal operating state, this embodiment generates a corresponding comprehensive judgment result at the method level and marks the communication flow into a protected monitoring state to drive subsequent proactive security protection and strategy adjustment processes. It should be noted that this step only completes the comprehensive judgment of the communication flow's abnormal state and does not directly execute specific protection actions. Instead, it provides a unified and reliable judgment basis for subsequent proactive response mechanisms. Through the aforementioned multi-dimensional anomaly fusion judgment process, this embodiment achieves a transformation from single-dimensional anomaly detection to overall communication flow behavior judgment, significantly improving the network's ability to identify complex, low-feature attack behaviors.
[0083] Step S42: If the overall anomaly determination result is abnormal, trigger proactive security protection.
[0084] After completing the comprehensive anomaly determination of the communication flow, this embodiment further implements proactive network-side security protection for abnormal communication flows based on the comprehensive anomaly determination results, in order to suppress the impact of abnormal behavior on network real-time performance and system security. Specifically, when step S41 determines that the communication flow is in an abnormal operating state, the network node will trigger an active protection process for the communication flow based on the comprehensive anomaly determination results, causing the communication flow to switch from a normal operating state to a controlled operating state.
[0085] In this step, proactive security protection does not employ a single fixed strategy. Instead, it matches a protection scheme commensurate with the severity of the anomaly based on the type and evolutionary characteristics of abnormal communication flow behavior. Specifically, for communication flows exhibiting content inconsistency or timing inconsistency anomalies but not yet causing network congestion or system instability, this method applies restricted forwarding or priority adjustment to maintain controlled transmission without interfering with critical service flows, avoiding excessive suppression of system functions in misjudgment scenarios. For communication flows that continuously exhibit anomalies or possess obvious attack characteristics, this method reduces the impact of abnormal communication flows on network resources and other legitimate communication flows by limiting forwarding frequency, narrowing the available time window, or temporarily blocking forwarding paths.
[0086] Meanwhile, to ensure the real-time nature and determinism of the proactive protection process, this embodiment directly executes the aforementioned protection actions on the network side, without relying on centralized control or cross-node negotiation, thus avoiding the weakening effect of control link latency on the protection effect. This solution limits proactive protection decisions to the communication flow level and corresponds one-to-one with the aforementioned comprehensive anomaly judgment results, enabling the network to respond to abnormal behavior within milliseconds or even shorter time scales, meeting the real-time security protection requirements of scenarios such as vehicle-mounted and industrial control systems.
[0087] After completing the proactive security protection actions, this embodiment records the protection execution status of the communication flow as a reference for subsequent operational status assessment and strategy adjustment. Through the above-described proactive security protection execution process, this embodiment realizes the transformation from passive anomaly detection to proactive network-side response, enabling time-sensitive networks to quickly suppress complex and covert security threats without disrupting the existing communication architecture, significantly improving the security and reliability of integrated electronic systems in complex operating environments.
[0088] By performing the above operations, the network node completes proactive security protection of the target communication flow, thereby forming a closed-loop processing flow covering communication flow verification, anomaly detection and network-side response execution.
[0089] Step S5: After completing the active security protection of the communication flow, the consistency baseline and the active security protection strategy are adaptively updated based on the data flow's running status feedback.
[0090] After completing the proactive security protection of the communication flow, this embodiment further adaptively updates the consistency baseline and related protection strategies based on the operational status feedback of the communication flow, thereby improving the stability and adaptability of the method during long-term operation. Specifically, for any communication flow in the communication flow set, after completing anomaly detection and proactive protection, the content consistency, timing consistency, and anomaly identifier evolution of the communication flow in subsequent transmission processes are continuously monitored, generating status feedback information that reflects the operational trend of the communication flow.
[0091] In this step, when the communication flow gradually recovers to stable transmission behavior consistent with the consistency baseline under controlled operation, and no new anomaly markers are generated within a continuous time window, this method confirms the integrity status of the communication flow. Based on this, the original consistency baseline is progressively updated, enabling the baseline to reflect the normal evolution characteristics of the communication flow over long-term operation. This mechanism can prevent the consistency baseline from becoming permanently fixed due to changes in business load, fluctuations in the operating environment, or adjustments to system configuration, thus avoiding misjudgments or over-protection issues.
[0092] On the other hand, when the communication flow continues to generate abnormal markers under controlled operation, or when its abnormal evolution characteristics exhibit a new stable pattern, this embodiment provides operational status feedback to adjust the parameters of the proactive security protection strategy for the communication flow accordingly. This makes subsequent anomaly detection and protection execution more targeted and adaptable to new abnormal behavior characteristics. The protection strategy update process and the aforementioned consistency baseline update process are independent yet coordinated, enabling this method to maintain its responsiveness to new abnormal behaviors without weakening its fault tolerance for normal communication flows.
[0093] Through the above-described adaptive update process of consistency baseline and protection strategy based on operational status feedback, this embodiment constructs a complete closed-loop security control mechanism at the method level, enabling the integrity verification, anomaly judgment, and proactive protection of communication flows to dynamically evolve with the system's operational status, thereby significantly improving the security robustness and adaptability of time-sensitive networks under complex operating conditions and long-term operating scenarios.
[0094] In summary, the network proactive security protection method based on flow integrity verification proposed in this embodiment achieves accurate verification of data frame content consistency, timing consistency, and synchronization offset by constructing a complete verification system in the content and timing dimensions of the communication flow. Furthermore, it effectively distinguishes between occasional disturbances and systemic anomalies through a multi-dimensional anomaly fusion judgment mechanism. Based on this, a closed-loop security control mechanism covering the entire process of "verification-judgment-protection-feedback-update" is formed through hierarchical response and execution of proactive security protection on the network side, and adaptive updates of consistency baselines and protection strategies based on operational status feedback. This method does not rely on centralized control and can complete real-time responses locally at network nodes, significantly improving the perception and proactive protection capabilities of time-sensitive networks against complex attack scenarios. It provides an engineering-feasible technical path for scenarios with stringent real-time and security requirements, such as automotive and industrial control systems, effectively enhancing the security and reliability of integrated electronic systems in complex operating environments.
[0095] Specific embodiment 2 of the present invention discloses a network proactive security protection device based on flow integrity verification, the structural schematic diagram of which is shown below. Figure 2 As shown, the device includes: The baseline building module is used to build a set of all communication flows in a time-sensitive network, as well as a consistent baseline for each communication flow under normal operating conditions. The flow integrity information generation module is used to control the network nodes on the sending side to generate flow integrity information of the data frames to be sent in the data stream, and inject the flow integrity information along with the data frames into the time-sensitive network for transmission; The anomaly detection module is used to control the network nodes on the receiving side to perform multi-dimensional anomaly detection on the communication stream based on the received data frames, and if an anomaly is found, the multi-dimensional anomaly result of the corresponding data stream is output. The security protection trigger module is used to control the network node at the receiving end to make a comprehensive anomaly judgment on the communication flow based on the multi-dimensional anomaly results of the data flow. If the comprehensive anomaly judgment result is an anomaly, it triggers active security protection.
[0096] The specific implementation process of this invention can be found in the above method embodiments, and will not be repeated here.
[0097] Since this embodiment is based on the same principle as the above-described method embodiments, this system also has the corresponding technical effects of the above-described method embodiments.
[0098] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.
[0099] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. A proactive network security protection method based on flow integrity verification, characterized in that, The method includes: Construct a flow set consisting of all communication flows in the time-sensitive network, and a consistency baseline for each communication flow under normal operating conditions; The network node on the sending side generates the flow integrity information of the data frame to be sent in the data stream, and injects the flow integrity information along with the data frame into the time-sensitive network for transmission; The receiving network node performs multi-dimensional anomaly judgment on the communication stream based on the received data frame and the consistency baseline and flow integrity information. If an anomaly is found, the corresponding multi-dimensional anomaly result of the data stream is output. The receiving network node makes a comprehensive anomaly judgment on the communication flow based on the multi-dimensional anomaly results of the data flow. If the comprehensive anomaly judgment result is anomaly, it triggers proactive security protection.
2. The network proactive security protection method based on flow integrity verification according to claim 1, characterized in that, The stream integrity information includes content integrity information and temporal correlation information.
3. The network proactive security protection method based on flow integrity verification according to claim 2, characterized in that, The sending network node generates content integrity information for the data frames to be sent in the data stream by performing the following operations: Extract content association information that characterizes the features of the frame content from the payload content of the data frame to be sent; The content association information is associated with the content integrity information of the communication stream in the previous data frame to form the content integrity information of the current data frame.
4. The network proactive security protection method based on flow integrity verification according to claim 3, characterized in that, The network node on the sending side generates timing association information for the data frames to be sent in the data stream by performing the following operations: Based on the transmission time of the data frame to be sent and the periodic parameters of the communication stream, corresponding timing association information is generated.
5. The network proactive security protection method based on flow integrity verification according to claim 4, characterized in that, The multidimensional anomaly detection includes content consistency verification, communication stream timing consistency verification, and synchronization offset verification. The multidimensional anomaly results include consistency verification failure results and / or timing verification failure results.
6. The network proactive security protection method based on flow integrity verification according to claim 5, characterized in that, The content consistency check is performed as follows: The receiving network node performs a consistency check on the content association between consecutive data frames of the communication flow based on the consistency baseline of the communication flow and the flow integrity information carried by the data frame. If the consistency check fails, there is an anomaly, and the consistency check failure result is output.
7. The network proactive security protection method based on flow integrity verification according to claim 6, characterized in that, The communication stream timing consistency and synchronization offset verification is performed as follows: The receiving network node sequentially performs timing consistency verification and synchronization offset verification based on flow integrity information on the communication flow. If the timing consistency verification or synchronization offset verification fails, an anomaly is found, and the timing verification failure result is output.
8. The network proactive security protection method based on flow integrity verification according to claim 7, characterized in that, The network node at the receiving end performs a comprehensive anomaly determination of the communication flow based on the multi-dimensional anomaly results, and executes the following: Based on the content anomaly flag in the content consistency verification failure result and the timing anomaly flag in the timing verification failure result, calculate the comprehensive anomaly judgment result of the corresponding data frame; If the combined anomaly determination results of multiple consecutive data frames are all higher than the anomaly trigger threshold, the corresponding communication flow enters an abnormal operation state and triggers network-side proactive security protection.
9. The network proactive security protection method based on flow integrity verification according to any one of claims 1-8, characterized in that, The method further includes: After completing the proactive security protection of the communication flow, the consistency baseline and the proactive security protection strategy are adaptively updated based on the feedback of the data flow's operating status.
10. A network proactive security protection device based on flow integrity verification, characterized in that, The device includes: The baseline building module is used to build a set of all communication flows in a time-sensitive network, as well as a consistent baseline for each communication flow under normal operating conditions. The flow integrity information generation module is used to control the network nodes on the sending side to generate flow integrity information of the data frames to be sent in the data stream, and inject the flow integrity information along with the data frames into the time-sensitive network for transmission; The anomaly detection module is used to control the network nodes on the receiving side to perform multi-dimensional anomaly detection on the communication stream based on the received data frames, and if an anomaly is found, the multi-dimensional anomaly result of the corresponding data stream is output. The security protection trigger module is used to control the network node at the receiving end to make a comprehensive anomaly judgment on the communication flow based on the multi-dimensional anomaly results of the data flow. If the comprehensive anomaly judgment result is an anomaly, it triggers active security protection.