A network attack security monitoring and alarming system
By integrating monitoring and alarm units into the network attack security monitoring and alarm system, and employing dual unidirectional physical isolation transmission and high-precision timestamp synchronization, the problem of the separation between monitoring and alarm functions is solved, thereby improving the system's protection capabilities and operational efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- TECH COLLEGE BRANCH OF STATE GRID CORP OF CHINA
- Filing Date
- 2025-09-09
- Publication Date
- 2026-07-24
AI Technical Summary
In existing network attack security monitoring and alarm systems, the monitoring and alarm functions are separated, resulting in data transmission bottlenecks, high false alarm and false negative rates, poor device compatibility, and complex operation and maintenance, which cannot meet the protection needs in complex network environments.
The monitoring unit and alarm unit are integrated into the same hardware structure using a gateway integration module. Data transmission is achieved through a dual unidirectional physical isolation transmission module. Combined with a high-precision timestamp synchronization module, the accuracy and reliability of data transmission are ensured. The system stability and security are improved through an independent power supply module and an encryption unit.
It achieves efficient collaboration between monitoring and alarm units, reduces physical interfaces and network connection points between devices, lowers the risk of attacks, ensures the real-time and accuracy of data transmission, simplifies system deployment and maintenance, and improves the system's anti-attack capability and analysis efficiency.
Smart Images

Figure CN224555629U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of network security, and more specifically to a network attack security monitoring and alarm system. Background Technology
[0002] With the deep application of network technology in various fields, network attack methods are constantly evolving, significantly enhancing their stealth and destructiveness. This makes the real-time and integrated requirements for security protection increasingly urgent. Currently, network attack security monitoring and alarm systems generally suffer from a disconnect between monitoring and alarm functions, failing to rely on gateways to achieve synergy between the two, thus making it difficult to meet the needs of efficient protection.
[0003] Existing systems rely heavily on independent hardware for monitoring and separate alarm terminals for alarm functions, with neither integrated through a gateway, resulting in data transmission bottlenecks. Attack data collected by monitoring devices must be forwarded through multiple stages to the alarm terminal, making it prone to missed response opportunities due to data delays or transmission interruptions. Furthermore, the poor compatibility of independent devices necessitates the deployment of additional conversion modules, increasing costs and the risk of failure.
[0004] Furthermore, the existing system does not integrate multi-dimensional monitoring data through a gateway, relying solely on fixed thresholds for single devices to determine alarms, resulting in high false alarm and false negative rates. Normal business data is easily misidentified as attacks, while covert attacks are missed because they do not reach the thresholds. Moreover, maintaining independent devices is complex, requiring individual troubleshooting, leading to low operational efficiency.
[0005] In summary, the current system suffers from problems such as functional fragmentation, delayed response, low accuracy, and difficult maintenance because it does not integrate monitoring and alarm functions through a gateway. It cannot meet the protection needs in complex network environments. There is an urgent need for a system that relies on a gateway to achieve collaborative monitoring and alarm functions, in order to solve the above-mentioned technical pain points. Utility Model Content
[0006] In view of this, the present invention provides a network attack security monitoring and alarm system to solve the problems existing in the background technology.
[0007] To achieve the above objectives, the present invention adopts the following technical solution:
[0008] A network attack security monitoring and alarm system includes: a gateway integration module, a dual isolation transmission module, and a high-precision timestamp synchronization module;
[0009] The gateway integration module includes a monitoring unit and an alarm unit. The monitoring unit is used to collect network data from external network hosts and internal network hosts and identify attack characteristics. The alarm unit is used to generate alarm signals based on the attack characteristics. The monitoring unit and the alarm unit are integrated in the same gateway hardware structure and both establish communication connections with external network hosts and internal network hosts.
[0010] The dual-isolation transmission module includes a first unidirectional transmission unit and a second unidirectional transmission unit. The first unidirectional transmission unit is used to transmit the network data collected by the monitoring unit unidirectionally to the alarm unit, and the second unidirectional transmission unit is used to transmit the alarm signal generated by the alarm unit unidirectionally to the external operation and maintenance terminal. The first unidirectional transmission unit and the second unidirectional transmission unit are physically isolated by a security isolation card and an independent network cable.
[0011] The high-precision timestamp synchronization module includes a high-precision clock unit, a hardware counting unit, and a timestamp register unit. The high-precision clock unit provides a reference clock signal for the hardware counting unit. The hardware counting unit is connected to the monitoring unit to record the network data acquisition time. The timestamp register unit is used to store network data with timestamps and alarm signals.
[0012] Optionally, it also includes an independent power supply module, which includes a gateway power supply unit and a transmission power supply unit. The gateway power supply unit provides independent power to the gateway integrated module, and the transmission power supply unit provides independent power to the dual-isolation transmission module and the high-precision timestamp synchronization module.
[0013] Optionally, the gateway integration module further includes an encryption unit and a log recording unit. The encryption unit is used to encrypt the network data collected by the monitoring unit and the alarm signals generated by the alarm unit. The log recording unit is used to store the encrypted network data, alarm signals and timestamp information. Both the encryption unit and the log recording unit are integrated into the gateway hardware structure.
[0014] Optionally, the alarm unit includes an audible and visual alarm subunit and a remote communication subunit. The audible and visual alarm subunit is integrated on the surface of the gateway hardware structure and is used to issue local audible and visual alarms. The remote communication subunit establishes a wireless communication connection with an external operation and maintenance terminal and is used to send remote alarm information.
[0015] Optionally, the dual-isolation transmission module further includes a first network switching unit and a second network switching unit. The first network switching unit is connected to the first unidirectional transmission unit and the monitoring unit, and is used to switch network data output by the monitoring unit. The second network switching unit is connected to the second unidirectional transmission unit and the alarm unit, and is used to switch alarm signals output by the alarm unit.
[0016] Optionally, both the first network switching unit and the second network switching unit adopt switch hardware with signal isolation function, and are respectively connected to the corresponding unidirectional transmission unit through independent network cables.
[0017] Optionally, the high-precision timestamp synchronization module further includes a PTP synchronization unit, which is connected to the hardware counting unit and is used to receive external network synchronization signals to calibrate the timing reference of the hardware counting unit.
[0018] Optionally, the high-precision clock unit uses the SIT8920AM series clock chip, the hardware counting unit uses the 74LS590 series counter chip, and the timestamp register unit uses the SN74HC574DWR series register chip.
[0019] Optionally, the independent power supply module further includes a redundant fault-tolerant unit, which includes an undervoltage comparator and an overvoltage comparator. The undervoltage comparator is used to detect whether the power supply voltage is lower than a preset undervoltage threshold, and the overvoltage comparator is used to detect whether the power supply voltage is higher than a preset overvoltage threshold. When the power supply voltage exceeds the threshold range, the redundant fault-tolerant unit cuts off the corresponding power supply circuit.
[0020] As can be seen from the above technical solution, compared with the prior art, the present invention discloses a network attack security monitoring and alarm system, which has the following beneficial effects:
[0021] 1. At the core security protection level, a dual unidirectional physical isolation design is adopted. Relying on security isolation cards and independent network cables, the network data collected by the monitoring unit is transmitted unidirectionally to the alarm unit, and the alarm signals generated by the alarm unit are transmitted unidirectionally to the external operation and maintenance terminal. The reverse data flow path is completely blocked at the hardware level, which effectively prevents attackers from intruding into the monitoring unit, tampering with alarm information or penetrating the internal network through the transmission link. At the same time, the monitoring unit and the alarm unit are integrated in the same gateway hardware structure, and directly establish communication connections with the external network host and the internal network host. This reduces the physical interfaces and network connection points between devices, reduces the risk of the system being attacked by side-channel attacks, and greatly improves the overall anti-attack capability.
[0022] 2. Regarding the reliability of monitoring and alarming, the monitoring unit integrated into the gateway hardware can directly collect data from the communication link between the external network host and the internal network host, avoiding the data loss problems caused by system resource occupation and network congestion in traditional software packet capture methods. This ensures accurate identification of attack characteristics. The unidirectional transmission design eliminates reverse interaction during data transmission, effectively avoiding data conflicts and link congestion that may occur in bidirectional transmission. This ensures that monitoring data is efficiently transmitted to the alarm unit and that alarm signals are quickly delivered to external maintenance terminals, reducing alarm delays and buying valuable time for emergency response.
[0023] 3. In terms of data traceability and analysis support, the high-precision timestamp synchronization module provides a reference clock signal to the hardware counting unit through a high-precision clock unit. The hardware counting unit is connected to the monitoring unit to accurately record the network data acquisition time. Then, the timestamp register unit stores the network data and alarm signals with timestamps, achieving nanosecond-level time synchronization. This ensures that every piece of network data and alarm signal has an accurate and tamper-proof timestamp, providing accurate time evidence for subsequent attack event review. It helps technicians clearly trace the attack initiation time, attack path, and scope of impact. At the same time, accurate timestamps also provide key data support for attack responsibility identification, improving the accuracy and efficiency of attack analysis.
[0024] 4. In addition, the overall hardware integration and physical isolation design not only simplifies the system deployment architecture and reduces the complexity of inter-device collaboration, but also reduces the risk of failure caused by software compatibility issues between multiple devices, improves system stability, facilitates subsequent maintenance and management, and comprehensively ensures the continuous and reliable operation of the system in complex network environments, providing strong technical support for network security monitoring and alarm work. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of this utility model or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this utility model. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0026] Figure 1 The main structural schematic diagram provided for this utility model;
[0027] Figure 2 A schematic diagram of the power supply structure provided by this utility model. Detailed Implementation
[0028] The technical solutions of the present utility model will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present utility model, and not all embodiments. Based on the embodiments of the present utility model, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present utility model.
[0029] Example 1
[0030] This embodiment discloses a network attack security monitoring and alarm system, such as Figure 1 and Figure 2 As shown, it includes: a gateway integration module, a dual-isolation transmission module, and a high-precision timestamp synchronization module;
[0031] The gateway integration module includes a monitoring unit and an alarm unit. The monitoring unit is used to collect network data from external network hosts and internal network hosts and identify attack characteristics. The alarm unit is used to generate alarm signals based on the attack characteristics. The monitoring unit and the alarm unit are integrated in the same gateway hardware structure and both establish communication connections with external network hosts and internal network hosts.
[0032] The dual-isolation transmission module includes a first unidirectional transmission unit and a second unidirectional transmission unit. The first unidirectional transmission unit is used to transmit the network data collected by the monitoring unit unidirectionally to the alarm unit, and the second unidirectional transmission unit is used to transmit the alarm signal generated by the alarm unit unidirectionally to the external operation and maintenance terminal. The first unidirectional transmission unit and the second unidirectional transmission unit are physically isolated by a security isolation card and an independent network cable.
[0033] The high-precision timestamp synchronization module includes a high-precision clock unit, a hardware counting unit, and a timestamp register unit. The high-precision clock unit provides a reference clock signal for the hardware counting unit. The hardware counting unit is connected to the monitoring unit to record the network data acquisition time. The timestamp register unit is used to store network data with timestamps and alarm signals.
[0034] Furthermore, it also includes an independent power supply module, which includes a gateway power supply unit and a transmission power supply unit. The gateway power supply unit provides independent power to the gateway integrated module, and the transmission power supply unit provides independent power to the dual-isolation transmission module and the high-precision timestamp synchronization module.
[0035] Furthermore, the gateway integration module also includes an encryption unit and a log recording unit. The encryption unit is used to encrypt the network data collected by the monitoring unit and the alarm signals generated by the alarm unit. The log recording unit is used to store the encrypted network data, alarm signals and timestamp information. Both the encryption unit and the log recording unit are integrated into the gateway hardware structure.
[0036] Furthermore, the alarm unit includes an audible and visual alarm subunit and a remote communication subunit. The audible and visual alarm subunit is integrated on the surface of the gateway hardware structure and is used to issue local audible and visual alarms. The remote communication subunit establishes a wireless communication connection with an external operation and maintenance terminal and is used to send remote alarm information.
[0037] Furthermore, the dual-isolation transmission module also includes a first network switching unit and a second network switching unit. The first network switching unit is connected to the first unidirectional transmission unit and the monitoring unit, and is used to switch the network data output by the monitoring unit. The second network switching unit is connected to the second unidirectional transmission unit and the alarm unit, and is used to switch the alarm signal output by the alarm unit.
[0038] Furthermore, both the first network switching unit and the second network switching unit adopt switch hardware with signal isolation function, and are respectively connected to the corresponding unidirectional transmission unit through independent network cables.
[0039] Furthermore, the high-precision timestamp synchronization module also includes a PTP synchronization unit, which is connected to the hardware counting unit and is used to receive external network synchronization signals to calibrate the timing reference of the hardware counting unit.
[0040] Furthermore, the high-precision clock unit uses the SIT8920AM series clock chip, the hardware counting unit uses the 74LS590 series counter chip, and the timestamp register unit uses the SN74HC574DWR series register chip.
[0041] Furthermore, the independent power supply module also includes a redundant fault-tolerant unit, which includes an undervoltage comparator and an overvoltage comparator. The undervoltage comparator is used to detect whether the power supply voltage is lower than a preset undervoltage threshold, and the overvoltage comparator is used to detect whether the power supply voltage is higher than a preset overvoltage threshold. When the power supply voltage exceeds the threshold range, the redundant fault-tolerant unit cuts off the corresponding power supply circuit.
[0042] Example 2
[0043] The only difference between this embodiment and Embodiment 1 is the following:
[0044] Gateway integration module: It adopts an integrated gateway hardware shell and integrates a monitoring unit, alarm unit, data filtering unit, data detection unit, encryption unit and log recording unit. The monitoring unit uses an embedded chip with network data acquisition capabilities (such as the STM32F4 series chip based on ARM architecture), which connects to the network ports of the external and internal network hosts via RJ45 ports to collect network traffic, data packet characteristics, and other data from both hosts in real time. The data filtering unit and data detection unit adopt a hardware logic circuit design and are connected in series between the monitoring unit and the alarm unit via PCB traces. The data filtering unit is used to filter out interference data such as broadcast storms and invalid test data packets, while the data detection unit verifies data integrity through preset hardware verification logic (such as CRC32 verification circuit). The alarm unit includes an audible and visual alarm subunit integrated on the surface of the gateway shell (using red LED indicator and buzzer) and a built-in remote communication subunit (using a 4G module or WiFi module, such as SIM868 module). The encryption unit uses a hardware encryption chip (such as AES256 encryption chip), and the log recording unit uses an SD card storage module. Both are connected to the monitoring unit and alarm unit via SPI bus.
[0045] The dual-isolation transmission module includes a first unidirectional transmission unit, a second unidirectional transmission unit, a first network adapter unit, and a second network adapter unit. Both the first and second unidirectional transmission units utilize security isolation cards and are physically isolated using Cat 5e shielded network cables. The first and second network adapter units employ industrial-grade switches with signal isolation capabilities (such as Advantech EKI-2525 series switches). The input of the first network adapter unit is connected to the signal output of the monitoring unit via an independent network cable, and its output is connected to the input of the first unidirectional transmission unit via an independent network cable. The output of the first unidirectional transmission unit is connected to the signal input of the alarm unit via an independent network cable. Similarly, the input of the second network adapter unit is connected to the signal output of the alarm unit via an independent network cable, and its output is connected to the input of the second unidirectional transmission unit via an independent network cable. The output of the second unidirectional transmission unit is connected to the network port of an external maintenance terminal (such as a maintenance computer) via an independent network cable.
[0046] The high-precision timestamp synchronization module includes a high-precision clock unit, a hardware counting unit, a timestamp register unit, and a PTP synchronization unit. The high-precision clock unit uses the SIT8920AM-81-33E-29 series clock chip, whose clock output is connected to the counting clock signal terminal of the hardware counting unit via PCB traces. The hardware counting unit uses the 74LS590 series counter chip, whose data input is connected to the time signal output terminal of the monitoring unit via a signal line to record the time when the monitoring unit collects network data. The timestamp register unit uses the SN74HC574DWR series register chip, whose parallel bit input is connected to the parallel bit output terminal of the hardware counting unit via a ribbon cable to store timestamped network data and alarm signals. The PTP synchronization unit uses the DP83640 series chip, whose synchronization signal output is connected to the calibration signal input terminal of the hardware counting unit via a signal line. The Ethernet interface of the PTP synchronization unit is connected to an external network via a network cable to receive PTP synchronization signals from the external network to calibrate the timing reference of the hardware counting unit.
[0047] Independent power supply module: Includes gateway power supply unit, transmission power supply unit, and redundancy fault-tolerant unit. Both the gateway power supply unit and the transmission power supply unit use independent 220V to 12V switching power supply modules (such as the Mean Well RS-50-12 series power supply). The output of the gateway power supply unit is connected to the power input of the gateway integrated module via an independent power line, supplying power to all units within the gateway integrated module. The output of the transmission power supply unit is connected to the power input of each unit in the dual-isolation transmission module (first unidirectional transmission unit, second unidirectional transmission unit, first network adapter unit, second network adapter unit) and each unit in the high-precision timestamp synchronization module via independent power lines, supplying power to these units; redundancy... The fault-tolerant unit uses the LTC4365ITS8#PBF series protection chip. Its voltage input terminal is connected to the output terminal of the gateway power supply unit and the transmission power supply unit, respectively. Its voltage output terminal is connected to the power input terminal of the corresponding power receiving module. The undervoltage comparator and overvoltage comparator built into the redundant fault-tolerant unit are preset with undervoltage threshold (e.g., 9V) and overvoltage threshold (e.g., 15V). At the same time, the gate drive output terminal of its external n-channel MOSFET is connected to the gate of an external n-channel MOSFET (e.g., IRF3205 model). This MOSFET is connected in series in the power supply circuit to cut off the power supply when the voltage is abnormal.
[0048] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.
[0049] The above description of the disclosed embodiments enables those skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A network attack security monitoring and alarm system, characterized in that, include: Gateway integration module, dual-isolation transmission module, and high-precision timestamp synchronization module; The gateway integration module includes a monitoring unit and an alarm unit. The monitoring unit is used to collect network data from external network hosts and internal network hosts and identify attack characteristics. The alarm unit is used to generate alarm signals based on the attack characteristics. The monitoring unit and the alarm unit are integrated in the same gateway hardware structure and both establish communication connections with external network hosts and internal network hosts. The dual-isolation transmission module includes a first unidirectional transmission unit and a second unidirectional transmission unit. The first unidirectional transmission unit is used to transmit the network data collected by the monitoring unit unidirectionally to the alarm unit, and the second unidirectional transmission unit is used to transmit the alarm signal generated by the alarm unit unidirectionally to the external operation and maintenance terminal. The first unidirectional transmission unit and the second unidirectional transmission unit are physically isolated by a security isolation card and an independent network cable. The high-precision timestamp synchronization module includes a high-precision clock unit, a hardware counting unit, and a timestamp register unit. The high-precision clock unit provides a reference clock signal for the hardware counting unit. The hardware counting unit is connected to the monitoring unit to record the network data acquisition time. The timestamp register unit is used to store network data with timestamps and alarm signals.
2. The network attack security monitoring and alarm system according to claim 1, characterized in that, It also includes an independent power supply module, which includes a gateway power supply unit and a transmission power supply unit. The gateway power supply unit provides independent power to the gateway integrated module, and the transmission power supply unit provides independent power to the dual-isolation transmission module and the high-precision timestamp synchronization module.
3. The network attack security monitoring and alarm system according to claim 1, characterized in that, The gateway integration module also includes an encryption unit and a log recording unit. The encryption unit is used to encrypt the network data collected by the monitoring unit and the alarm signals generated by the alarm unit. The log recording unit is used to store the encrypted network data, alarm signals and timestamp information. Both the encryption unit and the log recording unit are integrated into the gateway hardware structure.
4. The network attack security monitoring and alarm system according to claim 1, characterized in that, The alarm unit includes an audible and visual alarm subunit and a remote communication subunit. The audible and visual alarm subunit is integrated on the surface of the gateway hardware structure and is used to issue local audible and visual alarms. The remote communication subunit establishes a wireless communication connection with an external operation and maintenance terminal and is used to send remote alarm information.
5. A network attack security monitoring and alarm system according to claim 1, characterized in that, The dual-isolation transmission module further includes a first network switching unit and a second network switching unit. The first network switching unit is connected to the first unidirectional transmission unit and the monitoring unit, and is used to switch the network data output by the monitoring unit. The second network switching unit is connected to the second unidirectional transmission unit and the alarm unit, and is used to switch the alarm signals output by the alarm unit.
6. A network attack security monitoring and alarm system according to claim 5, characterized in that, Both the first network switching unit and the second network switching unit use switch hardware with signal isolation function, and are connected to the corresponding unidirectional transmission unit through independent network cables.
7. A network attack security monitoring and alarm system according to claim 1, characterized in that, The high-precision timestamp synchronization module also includes a PTP synchronization unit, which is connected to the hardware counting unit and is used to receive external network synchronization signals to calibrate the timing reference of the hardware counting unit.
8. A network attack security monitoring and alarm system according to claim 7, characterized in that, The high-precision clock unit uses the SIT8920AM series clock chip, the hardware counting unit uses the 74LS590 series counter chip, and the timestamp register unit uses the SN74HC574DWR series register chip.
9. A network attack security monitoring and alarm system according to claim 2, characterized in that, The independent power supply module also includes a redundant fault-tolerant unit, which includes an undervoltage comparator and an overvoltage comparator. The undervoltage comparator is used to detect whether the power supply voltage is lower than a preset undervoltage threshold, and the overvoltage comparator is used to detect whether the power supply voltage is higher than a preset overvoltage threshold. When the power supply voltage exceeds the threshold range, the redundant fault-tolerant unit cuts off the corresponding power supply circuit.