The invention discloses a network
threat evidence fixation technology for solving
source tracing evidence chain deficiency, and belongs to the field of
network security. Aiming at the problems of distributed log
time sequence chaos, easy tampering of virtual environment
metadata, difficult association of cross-platform
attack traces and the like existing in the traditional evidence obtaining technology, the invention constructs a technical
system of
dynamic data capture and space-time fusion modeling, evidence chain reconstruction and distributed
verification, anti-
quantum storage and security solidification. A self-adaptive sensor network is constructed through an improved BFGS
algorithm, a space-time fusion evidence model is provided, and an improved MPT structure and a lattice-based cryptographic
algorithm are designed in combination with a
time sequence Petr i network and a Byzantine fault-tolerant protocol. Tests show that the
attack feature capture rate reaches 91%, the cross-platform
attack association accuracy rate reaches 93%, the
quantum signature resistance speed is 1200 times per second, and the problem of
source tracing evidence chain deficiency is effectively solved.