Protocol State Security Analysis via Node Traversal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for analyzing protocol security rely on data unit analysis, which is ineffective against false data units with high imitation, leading to a need for a method to judge protocol security based on protocol state.

Innovation Solution

A security analysis method and system that builds a protocol analysis directory, determines protocol analysis nodes, constructs a protocol trigger sequence rule, and analyzes node traversal tables to determine security evaluation factors and protocol security states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data unit analysis method is used to judge protocol security, then the analysis can be performed on individual data units, but it is ineffective against false data units with high imitation capability

Engineering Contradiction:
Improvesecurity judgment accuracyVSAvoidattack effect on false data units
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the protocol analysis into multiple protocol analysis nodes organized in a directory structure. Each node represents a specific protocol layer or function, and data units are analyzed at multiple segmentation points rather than as single units. This segmentation allows the system to track protocol state across multiple analysis points, making it effective against highly imitative false data units that might pass single-point analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent builds protocol analysis nodes and establishes analysis rules in advance before actual security analysis occurs. The system pre-configures the protocol directory structure, defines analysis criteria for each node, and prepares the framework for detecting protocol state anomalies. This preliminary setup enables the system to effectively identify false data units when they attempt to traverse the pre-established analysis path.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If protocol analysis nodes and traversal tables are built to track data through multiple protocol layers, then security evaluation accuracy is improved, but the complexity of the analysis system increases

Engineering Contradiction:
Improveprotocol security evaluation accuracyVSAvoidanalysis system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal protocol analysis directory structure that can accommodate multiple protocols and analysis scenarios. The protocol analysis nodes are designed with multi-functionality, capable of handling different protocol types and security analysis requirements through a unified framework. This universality reduces system complexity by providing a standardized approach rather than requiring separate analysis mechanisms for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a protocol analysis directory as an intermediary layer between the raw data units and the security evaluation system. This directory structure acts as a mediator that organizes and manages the complex relationships between protocol layers, analysis nodes, and security criteria. By inserting this intermediary organizational layer, the system manages complexity while maintaining high evaluation accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security evaluation factors are determined through protocol state analysis, then the trustworthiness assessment becomes more comprehensive, but the analysis time and processing overhead increase

Engineering Contradiction:
Improvetrustworthiness assessment comprehensivenessVSAvoidsecurity analysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent determines multiple security evaluation factors at different protocol analysis nodes, but not all factors are evaluated with equal depth for every data unit. The system applies partial evaluation based on the protocol state and the specific analysis context, focusing computational resources on the most critical security factors for each situation. This approach provides comprehensive trustworthiness assessment while managing processing time through selective evaluation depth.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12235972B1Security analysis method and system based on protocol state
Publication Date: 2025.02.25 HUANENG INFORMATION TECH CO LTD
  • US12235972B1 patent drawing

AI summary

The disclosure provides a security analysis method and system based on protocol state, which relates to the technical field of protocol security protection. The method includes the following: a node traversal table is built, the node traversal table is scanned and analyzed according to the protocol trigger sequence rule, a first security evaluation factor of a protocol stack is determined, and a second security evaluation factor of each protocol is determined based on protocol normal application rule, and the trustworthiness degree of the second security factor is determined based on the first security factor, and the second security factor is revised based on the trustworthiness degree, and the security state of the protocol is determined according to the revised second security factor, thus the analysis of the protocol state is realized, and the security of the protocol can be accurately determined.