A network information security optimization method based on multi-layer defense
Patent Information
- Application Number
- CN202611199171.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-09
- Publication Date
- 2026-09-25
AI Technical Summary
[0004]本发明要解决的技术问题是:现有多层防御体系中,加密流量场景下网络层安全检测能力不足,以及跨层安全策略协同响应存在延迟,具体而言,现有方案对加密隐蔽信道的检测依赖中间人解密还原报文明文,存在计算开销大、隐私合规风险高且对无法解密流量检测粗糙的缺陷;
[0012]1.本发明无需对网络流量负载进行解密还原,即可实现对加密隐蔽信道的高置信度检测,避免了中间人解密带来的计算资源消耗及数据隐私合规风险;
Smart Images

Figure CN122824489A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security technology, specifically to a network information security optimization method based on multi-layered defense. Background Technology
[0002] With the popularization of zero-trust architecture and cloud-native technology, modern enterprise networks have generally built a multi-layered defense system with perimeter firewalls, intrusion detection systems, web application firewalls and endpoint security agents as core nodes. Various security devices detect traffic based on the traffic characteristics of the network layer, transport layer and application layer respectively. With the promotion of encryption protocols such as TLS, network traffic load has been encrypted in large quantities. In the existing multi-layered defense system, it is generally believed in the field that if the detection accuracy of encrypted covert channels is to be improved, it is necessary to rely on man-in-the-middle decryption to restore the message text. However, if cross-layer policy real-time coordination is to be achieved, the integrity of policy conflict judgment must be sacrificed. It is difficult to achieve both, which has formed a long-standing technical limitation in the understanding of those skilled in the art.
[0003] This invention overcomes the limitations mentioned above by combining non-decryption feature game inference with local graph structure updates. It achieves high-confidence detection without decryption and millisecond-level response while ensuring the integrity of conflict determination. However, this is insufficient to meet the real-time requirements of network attack and defense. Furthermore, although eBPF technology, as a lightweight data acquisition technology that can run in the operating system kernel mode, has been applied to the observability of network traffic, it has not yet been systematically applied to the fields of cross-layer covert channel detection and policy coordination, resulting in a significant deficiency in network layer security detection capabilities. Summary of the Invention
[0004] The technical problem to be solved by this invention is that in the existing multi-layer defense system, the network layer security detection capability is insufficient in encrypted traffic scenarios, and there is a delay in the collaborative response of cross-layer security strategies. Specifically, the existing solutions rely on man-in-the-middle decryption to restore the message text for the detection of encrypted covert channels, which has the defects of large computational overhead, high privacy compliance risk and coarse detection of traffic that cannot be decrypted.
[0005] Meanwhile, existing solutions require a full traversal and comparison of the rule sets of all security devices when implementing cross-layer linkage response, resulting in response latency of minutes. This makes it difficult to match the speed of attacker penetration and lateral movement, rendering the cross-layer linkage defense mechanism ineffective.
[0006] To address the aforementioned technical problems, this invention provides a network information security optimization method based on multi-layered defense, comprising: deploying eBPF probes in the kernel mode of network egress gateways and terminal nodes to intercept the original metadata of the network layer, transport layer, and application layer of passing network connections in real time, wherein the original metadata does not contain the decrypted content of the message payload;
[0007] The intercepted raw metadata is parsed to extract JA3 fingerprint features, packet interval jitter frequency features, and time sequence connection graph features, and then the joint feature vector corresponding to the connection is constructed by splicing them in a preset order.
[0008] The joint feature vector is input into the multi-agent generative adversarial game inference engine deployed in the edge detection layer to obtain the confidence level of the hidden channel determination of the connection.
[0009] The confidence level is compared with a preset threshold. When the confidence level is not lower than the preset threshold, the connection is determined to be a covert channel and a corresponding interception policy is generated. When the confidence level is lower than the preset threshold, the connection is determined to be normal encrypted traffic and is allowed to pass.
[0010] The interception strategy is reported to the control plane strategy layer. The control plane strategy layer abstracts the multi-layer defense rules into a directed acyclic graph. Based on the defense level, interception action type, target and priority attributes of the interception strategy to be inserted, the set of adjacent candidate nodes is retrieved in the directed acyclic graph. A locally affected subgraph is constructed with the set of adjacent candidate nodes as the center. Policy conflict is determined within the scope of the locally affected subgraph. When a conflict is determined, the conflict weight of the affected edge is updated and the priority of the conflicting nodes is reordered to generate a set of resolved cooperative strategies. The strategies are then sent to the corresponding defense devices at the network layer, application layer and terminal layer for execution.
[0011] Compared with the prior art, the beneficial effects of the present invention by adopting the above technical solution are as follows:
[0012] 1. This invention can achieve high-confidence detection of encrypted and concealed channels without decrypting and restoring network traffic load, thus avoiding the computational resource consumption and data privacy compliance risks caused by man-in-the-middle decryption;
[0013] 2. This invention uses a game-theoretic inference engine composed of a generated intelligent agent and multiple hierarchical discriminative intelligent agents to fuse and discriminate metadata features of the network layer, transport layer, and application layer, thereby improving the confidence in the determination of covert channels and the adaptability to new covert channel variants.
[0014] 3. This invention narrows the scope of policy conflict determination from the global rule set to the locally affected subgraph. Since the complexity of conflict determination is reduced from being related to the number of global nodes to being related only to the number of nodes in the locally affected subgraph, it can theoretically significantly reduce the response latency of cross-layer policy coordination. It achieves dynamic collaborative reconstruction of multi-layer defense strategies without sacrificing network throughput performance. Attached Figure Description
[0015] Figure 1This is a diagram illustrating the overall system architecture in an embodiment of the present invention.
[0016] Figure 2 This is a flowchart of the covert channel non-decryption detection process in an embodiment of the present invention;
[0017] Figure 3 This is a flowchart of the training and inference process of the multi-agent game model in an embodiment of the present invention;
[0018] Figure 4 This is a flowchart illustrating the cross-layer strategy conflict resolution process in an embodiment of the present invention. Detailed Implementation
[0019] The following is in conjunction with the appendix Figure 1-4 The specific embodiments of the present invention will be further described below. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.
[0020] The technical solution of the present invention will be further described in detail below with reference to specific embodiments.
[0021] I. System Overall Architecture
[0022] The network information security optimization method provided by the present invention is based on an overall system architecture consisting of four parts: a data acquisition layer, an edge detection layer, a cloud training layer, and a control plane policy layer. The data acquisition layer is deployed on the network egress gateway and each terminal node, and uses eBPF technology to extract traffic metadata in the kernel space.
[0023] The edge detection layer deploys a lightweight multi-agent generative adversarial game inference engine to make real-time judgments on metadata features;
[0024] The cloud training layer uses federated learning to centrally train the feature samples reported by each edge node and periodically distributes updated model parameters.
[0025] The control plane strategy layer maintains an incremental directed acyclic graph structure for cross-layer defense strategies. It is responsible for detecting local conflicts and adjusting the weights of newly issued strategies, and then issuing the resolved collaborative strategies to each defense node in the network layer, application layer, and terminal layer for execution.
[0026] II. Cross-layer metadata collection and feature extraction
[0027] The data acquisition process utilizes eBPF technology to mount probes in the kernel mode of the network egress gateway and terminal nodes to collect network layer, transport layer, and application layer metadata of the traffic and construct a joint feature vector. This process does not involve parsing or restoring the packet payload content, thereby obtaining feature data for discrimination without infringing on user communication privacy.
[0028] The joint feature vector used for covert channel detection is represented as follows:
[0029] ;
[0030] in, This represents the joint feature vector corresponding to a single network connection.
[0031] The JA3 fingerprint characteristic representing the connection is a hash fingerprint calculated based on the list of cipher suites and the order of extended fields in the TLS client handshake message, used to characterize the consistency of the TLS client handshake behavior;
[0032] This indicates the packet interval jitter frequency characteristic of the connection, used to characterize the statistical distribution pattern of the data packet transmission time interval;
[0033] This indicates the temporal connectivity features of the connection within a preset observation window, used to characterize the temporal topological relationship between the connection and other associated connections.
[0034] The specific implementation steps are as follows: deploy eBPF probes in the kernel mode of the network egress gateway and terminal nodes to intercept the original metadata of the network layer, transport layer and application layer of the network connection in real time. The original metadata does not include the decrypted content of the message payload.
[0035] The intercepted raw metadata is parsed to extract JA3 fingerprint features. Packet interval jitter frequency characteristics and temporal connectivity features The three elements are then concatenated in a preset order to construct the joint feature vector corresponding to the connection. ;
[0036] Joint feature vectors The input is fed into the multi-agent generative adversarial game inference engine deployed at the edge detection layer to obtain the confidence level of the hidden channel determination for this connection;
[0037] The confidence level is compared with a preset threshold. When the confidence level is not lower than the preset threshold, the connection is determined to be a covert channel and a corresponding interception strategy description is generated and reported to the control plane strategy layer.
[0038] When the confidence level is lower than the preset threshold, the connection is determined to be normal encrypted traffic and allowed to pass.
[0039] III. Detection Mechanism for Multi-Agent Generative Adversarial Game
[0040] The multi-agent generative adversarial game model consists of one generative agent and multiple discriminative agents. The generative agent is used to simulate the camouflage distribution of covert channels on the metadata features of the network layer, transport layer, and application layer. The multiple discriminative agents make judgments on the feature subspaces of the network layer, transport layer, and application layer, respectively. The outputs of each discriminative agent are dynamically weighted to obtain the final judgment confidence.
[0041] The game objective during the model training phase is represented as:
[0042] ;
[0043] in, This indicates the generation of an intelligent agent;
[0044] Indicates the first A discriminative intelligent agent, The value corresponds to a feature subspace in the network layer, transport layer, or application layer;
[0045] Indicates that it comes from the distribution of real samples Real traffic characteristic samples;
[0046] Indicates that it follows a distribution Random noise input;
[0047] This indicates that the intelligent agent is generated based on noise. Generated simulated covert channel feature samples;
[0048] Indicates the discriminative intelligent agent For real samples The output's discrimination confidence level;
[0049] This represents the expectation operation;
[0050] Indicates the discriminative intelligent agent With generating intelligent agents The game value function between them.
[0051] The fusion confidence score is calculated as follows during the inference phase:
[0052] ;
[0053] in, Indicates the confidence level of the final fusion decision;
[0054] Indicates the number of discriminant agents;
[0055] Indicates the first Each discriminative agent pairs the joint feature vector The output's discrimination confidence level;
[0056] Indicates the first The dynamic weights corresponding to each discriminative agent are updated by sliding based on the accuracy of each discriminative agent in historical detections.
[0057] The specific implementation steps are as follows:
[0058] The cloud training layer collects historical traffic feature samples reported by each edge node, constructs a training sample set, and starts the federated training process according to a preset cycle. Each edge node only uploads the gradient parameters and not the original feature samples after completing the gradient calculation locally.
[0059] According to the game value function in the cloud Generative intelligent agents With each discriminative intelligent agent Alternating optimization training is performed, which involves fixing the parameters of the generating agent and updating the parameters of each discriminator agent to increase... Then, fix the parameters of the discriminant agent and update the parameters of the generated agent to reduce... This process is repeated iteratively until the model converges;
[0060] The cloud sends the parameters of the discriminative agent after training convergence to each edge detection node, and the edge nodes load the parameters to complete the model deployment.
[0061] Edge detection nodes receive joint feature vectors Subsequently, the discrimination confidence is calculated by three discriminative agents at the network layer, transport layer, and application layer, respectively. ;
[0062] Edge detection nodes are based on the dynamic weights of each discriminative agent. The final decision confidence level is obtained according to the fusion confidence level calculation method. It outputs the concealed channel determination result based on the preset threshold.
[0063] IV. Incremental Directed Acyclic Graph Cross-Layer Strategy Conflict Resolution Mechanism
[0064] This invention abstracts multi-layered defense rules into a directed acyclic graph structure. Each node in the graph represents a defense strategy rule, and the node attributes include the defense level to which it belongs, the type of interception action, the target of action, and the priority.
[0065] The directed edges in the graph are used to represent at least one of the dependency relationship and priority constraint relationship between policy nodes. When a new policy node is issued, the system only performs conflict determination and weight adjustment on the local subgraph formed by the adjacent candidate nodes of that node, without traversing the global graph, thereby narrowing the detection scope of policy conflict from the global rule set to the affected local subgraph.
[0066] The incremental update method for conflict weights is represented as follows:
[0067] ;
[0068] in, Indicates the first The strategy node in the next iteration With policy nodes Conflict weights between them;
[0069] This indicates the updated conflict weights;
[0070] This represents the weight adjustment step size coefficient, used to control the magnitude of a single adjustment;
[0071] Indicates based on node With nodes The conflict intensity increment is calculated based on the priority differences and the degree of action contradictions.
[0072] The specific implementation steps are as follows: After receiving the newly issued security policy, the control plane policy layer parses the defense level, interception action type, target and priority attributes corresponding to the policy, and generates the policy node to be inserted.
[0073] Based on a pre-established tree index structure based on defense level and target, retrieve the set of adjacent candidate nodes that are associated with the node to be inserted in at least one of the target and priority intervals.
[0074] Centered on the candidate node set, expand the graph by a preset number of hops along the inbound and outbound edges of the directed acyclic graph to construct the affected local subgraph.
[0075] Within the local subgraph, compare the node to be inserted with each candidate node one by one to see if there is a contradiction in the type of interception action. For example, if one party is to allow passage and the other is to block, if there is a contradiction, it is determined that a conflict has occurred.
[0076] For node pairs that are determined to have a conflict, the conflict intensity increment is calculated based on their priority differences and the degree of contradiction in their actions. The updated conflict weights are calculated using an incremental update method. ;
[0077] Based on the updated conflict weights, the conflict nodes within the local subgraph are prioritized and reordered to determine the final strategy action to be executed, generating a set of reconciled collaborative strategies.
[0078] The node to be inserted and its resolution result are written into the directed acyclic graph to complete the local update. The coordinated policy set is then distributed to the corresponding defense devices at the network layer, application layer and terminal layer for execution. Since the retrieval of candidate nodes depends on the index structure built according to hierarchy and priority, the affected subgraph can be located without traversing all nodes, which reduces the response latency of cross-layer policy synchronization and conflict resolution from minutes to milliseconds.
[0079] V. Alternative Implementation Methods
[0080] In another implementation of the covert channel detection process, a supervised classification model based on a temporal heterogeneous graph neural network can be used to replace the multi-agent generative adversarial game model. That is, the metadata features of the network layer, transport layer, and application layer are constructed into a heterogeneous temporal graph structure, and the temporal evolution patterns of nodes and edges are supervised and classified by the graph neural network. Covert channel identification can also be achieved without decrypting the traffic load.
[0081] In another implementation of the policy conflict resolution process, a rule version tree structure based on hash partitioning can be used instead of the incremental directed acyclic graph structure. That is, each level of policy rule is hash partitioned according to the target and priority and a version fingerprint is generated. When a new policy is issued, the set of partitions that have changed is located by comparing the version fingerprints, and then conflict determination is performed within the partition range, which can also achieve a millisecond-level response effect.
[0082] Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the present invention. Therefore, any modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall fall within the protection scope defined by the claims of the present invention.
Claims
1. A network information security optimization method based on multi-layered defense, characterized in that, include: Deploy eBPF probes in the kernel mode of network egress gateways and terminal nodes to intercept the original metadata of the network layer, transport layer and application layer of passing network connections in real time. The original metadata does not contain the decrypted content of the message payload. The intercepted raw metadata is parsed to extract JA3 fingerprint features, packet interval jitter frequency features, and temporal connection graph features. The joint feature vector corresponding to the connection is constructed by sequentially arranging and splicing the JA3 fingerprint features, packet interval jitter frequency features, and temporal connection graph features. The joint feature vector is input into the multi-agent generative adversarial game inference engine deployed in the edge detection layer to obtain the confidence level of the hidden channel determination of the connection. The confidence level is compared with a preset threshold. When the confidence level is not lower than the preset threshold, the connection is determined to be a covert channel and a corresponding interception policy is generated. When the confidence level is lower than the preset threshold, the connection is determined to be normal encrypted traffic and is allowed to pass. The interception strategy is reported to the control plane strategy layer, which abstracts the multi-layer defense rules into a directed acyclic graph. Each node in the graph represents a defense strategy rule. The node attributes include the defense level, interception action type, target, and priority. The directed edges in the graph are used to represent at least one of the dependency relationship and priority constraint relationship between strategy nodes. Based on the defense level, interception action type, target and priority attributes of the interception strategy to be inserted, a set of adjacent candidate nodes that are associated with the node to be inserted is retrieved in the directed acyclic graph. A locally affected subgraph is constructed with the set of adjacent candidate nodes as the center. Policy conflict is determined within the scope of the locally affected subgraph. When a conflict is determined, the conflict weight of the affected edge is updated and the conflicting nodes are reordered by priority to generate a set of cooperative strategies after resolution. The set of collaborative strategies is distributed to the corresponding defense devices at the network layer, application layer, and terminal layer for execution.
2. The method according to claim 1, characterized in that, In the joint feature vector, the JA3 fingerprint feature is used to characterize the consistency of the TLS client handshake behavior, the packet interval jitter frequency feature is used to characterize the statistical distribution law of the data packet sending time interval, and the temporal connection graph feature is used to characterize the temporal topology relationship between the connection and other associated connections.
3. The method according to claim 1, characterized in that, The multi-agent generative adversarial game inference engine includes one generative agent and multiple discriminative agents. The generative agent is used to simulate the camouflage distribution of covert channels on metadata features of network layer, transport layer and application layer. The multiple discriminative agents perform discrimination on the feature subspaces of the network layer, transport layer, and application layer, respectively, and obtain multiple discrimination confidence levels; The multiple discrimination confidence scores are weighted and fused according to the dynamic weights corresponding to each discrimination agent to obtain the covert channel determination confidence score. The dynamic weights are updated by sliding based on the accuracy of each discrimination agent in historical detection.
4. The method according to claim 3, characterized in that, The parameters of the multi-agent generative adversarial game inference engine are trained through a cloud training layer: the cloud training layer collects historical traffic feature samples reported by each edge node to construct a training sample set, each edge node completes gradient calculation locally and then uploads gradient parameters, the cloud performs alternating optimization training on the generative agent and each discriminative agent, and sends the discriminative agent parameters after training convergence to each edge detection node to complete model deployment.
5. The method according to claim 1, characterized in that, The step of retrieving the set of adjacent candidate nodes includes: retrieving candidate nodes that are associated with the node to be inserted in at least one of the target and priority range, based on a pre-established index structure built according to defense level and target.
6. The method according to claim 1, characterized in that, The method for determining the strategy conflict is as follows: within the local affected subgraph, compare the node to be inserted with each candidate node one by one to see if there is a contradiction in the interception action type. If there is a contradiction, it is determined that a conflict has occurred. For node pairs that are determined to have a conflict, the conflict intensity increment is calculated based on their priority difference and the degree of contradiction in their actions, and the new conflict weight is updated according to the sum of the current conflict weight and the conflict intensity increment.
7. The method according to claim 1, characterized in that, After generating the set of collaborative strategies, the strategy nodes to be inserted and their resolution results are written into the directed acyclic graph, thus completing the local update of the directed acyclic graph.
8. A network information security optimization system based on multi-layered defense, characterized in that, It includes a data acquisition layer, an edge detection layer, a cloud training layer, and a control plane policy layer; The data acquisition layer is deployed at the network egress gateway and terminal nodes. It is used to intercept the original metadata of the network layer, transport layer and application layer of network connection in kernel mode using eBPF technology, and extract JA3 fingerprint features, packet interval jitter frequency features and time sequence connection graph features to construct a joint feature vector. The edge detection layer is used to deploy a multi-agent generative adversarial game inference engine, obtain the confidence level of the covert channel determination based on the joint feature vector, and generate an interception strategy when the confidence level is not lower than a preset threshold. The cloud training layer is used to collect feature samples reported by each edge node, train the model parameters of the multi-agent generative adversarial game inference engine, and periodically send the updated model parameters to the edge detection layer. The control plane policy layer is used to maintain the directed acyclic graph structure of cross-layer defense policies. After receiving the interception policy, it performs local conflict determination and weight adjustment on it, generates a set of resolving cooperative policies, and sends the set of cooperative policies to the corresponding defense devices of the network layer, application layer and terminal layer for execution.
9. The system according to claim 8, characterized in that, The multi-agent generative adversarial game inference engine includes one generative agent and multiple discriminative agents. The generative agent is used to simulate the camouflage distribution of covert channels on metadata features of network layer, transport layer and application layer. The multiple discriminative agents respectively discriminate against the feature subspaces of the network layer, transport layer, and application layer, and output the discriminative confidence scores. The edge detection layer is also used to perform weighted fusion of the discrimination confidence based on the dynamic weights corresponding to each discrimination agent to obtain the concealed channel determination confidence.
10. The system according to claim 8, characterized in that, The control plane strategy layer is also used to retrieve a set of adjacent candidate nodes that are associated with the strategy node to be inserted, based on a pre-established index structure built according to defense level and target, construct a locally affected subgraph centered on the set of adjacent candidate nodes, and perform conflict determination and priority reordering within the scope of the locally affected subgraph.