A partitioning and positioning risk assessment method for mimetic networks
Through the partitioning and positioning risk assessment method, the problem of lack of quantitative evaluation indicators in mimetic networks is solved, the refined risk assessment of complex networks is realized, and the accuracy and adaptability of the assessment are improved.
Patent Information
- Application Number
- CN202310661831.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-05
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2043-06-05
AI Technical Summary
Existing technologies lack universal indicators to directly measure the effectiveness of mimic network defense strategies, which makes it difficult to accurately understand the security gain areas and makes evaluation difficult.
A partitioned positioning risk assessment method is adopted to obtain network topology, scan vulnerability information, divide community structure, conduct node risk assessment and comprehensive risk assessment. Combined with the vulnerability common mode index and probability transfer, a quadratic assessment model is constructed to achieve quantitative risk assessment of mimetic networks.
It realizes refined risk assessment of large-scale complex networks, improves the accuracy and adaptability of the assessment, can effectively capture network defense performance, and is suitable for complex dynamic network scenarios.
Smart Images

Figure CN116743450B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a partition positioning risk assessment method for a mimetic network, and belongs to the technical field of information security. Background Art
[0002] With the increasing application of the internet across various socioeconomic sectors, cyberspace faces an increasing number of challenging challenges, with security threats becoming more diverse, complex, frequent, and intensive. Traditional defense technologies, such as firewalls and intrusion detection, typically identify target behavior based on known attack signatures, making them unable to proactively attack or gain an advantage in cyberattacks and defenses.
[0003] Cyber Mimic Defense (CMD), a new type of active defense, is designed based on a dynamic, heterogeneous, redundant architecture. Its effectiveness stems from its structural characteristics, independent of the characteristics of the target attack. It effectively defends against various attacks and unknown threats, while also addressing issues like "single points of failure." Currently, research on intrinsic security is frequently discussed, demonstrating strong defensive capabilities in areas such as software-defined networking, cloud computing, and distributed systems.
[0004] One of the current challenges in the development of network mimicry defense technology is the lack of universal metrics to directly measure the effectiveness of different defense strategies. If we cannot measure the security of a defense strategy, it will be difficult to improve it. This is also true for network mimicry defense technology. The massive scale and complexity of real-world networks, as well as the significant asymmetry between network attack and defense, make it difficult to precisely determine the security gain areas, making the evaluation of mimicry networks challenging. Therefore, there is an urgent need to develop universal quantitative evaluation metrics for network mimicry defense systems. Summary of the Invention
[0005] Technical problem: This invention is dedicated to solving the problem of quantitative risk assessment in complex mimetic networks.
[0006] Technical Solution: To solve the above problems, the present invention discloses a new method for mimicry defense assessment and proposes a partitioning and positioning risk assessment method for mimicry networks, which includes the following steps:
[0007] S1, network topology acquisition: Scan the network using scanning tools (such as Nmap) to discover hosts and services in the network and infer the network topology;
[0008] S2, vulnerability information scanning: Use vulnerability scanning tools (such as Nessus, OpenVAS, etc.) to detect vulnerabilities in the network and obtain detailed information about the vulnerabilities;
[0009] S3, community structure division: using the community division method based on the Louvain algorithm to segment large-scale complex networks into regions to achieve more accurate positioning measurement and risk assessment;
[0010] S4, Node Risk Assessment: Considering the dynamic heterogeneous redundant structure in the mimicry defense theory, node vulnerabilities are dynamically measured and real-time risk assessment is performed;
[0011] S5, correlation measurement: Considering the common mode of vulnerability and probability transfer, quantitative measurement is performed in combination with the actual application scenarios of the mimetic network;
[0012] S6, comprehensive risk assessment: Integrate measured conditions such as dynamic vulnerability, common mode index, and transition probability to conduct a comprehensive risk assessment.
[0013] As an improvement of the present invention, step S3 further includes:
[0014] S31, based on the scale-free network characteristics, uses the community division method based on the Louvain algorithm to perform regional segmentation of the complex network according to modularity Q and modularity gain ΔQ;
[0015] S32, maps the divided area to the target space for indicator definition and risk assessment, simplifies the complexity of the problem and improves the interpretability of the indicators.
[0016] As an improvement of the present invention, step S4 further includes:
[0017] S41, build a vulnerability set based on the information obtained from vulnerability scanning and local prior knowledge:
[0018] VUL=VUL1∪VUL2∪…∪VUL n
[0019] VUL i ={vul j ∣vul j It is V i A vulnerability on
[0020] S42, construct the node-vulnerability matrix NV, importance vector IM and vulnerability score vector CVSS, and quantitatively evaluate the node security risk factor in the mimic network environment:
[0021] RI=IM T ×NV×CVSS.
[0022] As an improvement of the present invention, step S5 further includes:
[0023] S51, based on the network security characteristics of the mimicry, calculates the common mode index of vulnerabilities between nodes:
[0024]
[0025]
[0026] S52, considering the horizontal spread, calculate the attack probability transfer:
[0027] TP=ε0Adj+(P)+(P) 2 +(P) 3 +…
[0028] =ε0Adj+(IP) -1 -I
[0029] As an improvement of the present invention, step S6 further includes:
[0030] S61: Collect the values calculated in S4 and S5, and construct the following quadratic form based on the robustness mechanism of mimicry defense technology to quantitatively evaluate the comprehensive security risk factor of the mimicry network:
[0031] RC=RI T ×(CM⊙TP)×RI.
[0032] Beneficial Effects: Compared to existing technologies, this invention proposes a partitioned and localized risk assessment method for mimetic networks that effectively captures and measures the defense performance of specific regions in large-scale networks, filling a gap in existing security risk assessment methods for deploying mimetic defense technology in complex networks. The overall design abandons a global perspective and, through a regional perception system, employs a community partitioning method to segment complex networks, thereby providing a refined measure of network security status. It also considers common vulnerability patterns and probability transfers, and measures risk factors from multiple angles, resulting in a high degree of consistency with the actual state of mimetic networks and promising applications in complex dynamic network scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is a framework diagram of the method of the present invention. DETAILED DESCRIPTION
[0034] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.
[0035] Example 1: Figure 1 As shown, a partition positioning risk assessment method for a mimetic network includes the following steps:
[0036] S1, network topology acquisition: Scan the network using scanning tools (such as Nmap, etc.) to discover hosts and services in the network and infer the network topology;
[0037] S2, vulnerability information scanning: Use vulnerability scanning tools (such as Nessus, OpenVAS, etc.) to detect vulnerabilities in the network and obtain detailed information about the vulnerabilities;
[0038] S3, community structure division: Based on the scale-free network characteristics, the community division method based on the Louvain algorithm is used to segment large-scale complex networks into regions to achieve more accurate positioning measurement and risk assessment. The specific steps are as follows:
[0039] S31, based on the network topology information obtained in S1, calculate the modularity Q and modularity gain ΔQ:
[0040]
[0041] Where m represents the total number of edges in the graph, ∑ in represents the sum of the weights of the interconnected edges within community c, ∑ tot It represents the sum of the weights of the edges connected to the nodes of the community, including the edges within the community and the edges outside the community.
[0042]
[0043] Among them, k i represents the sum of the weights of the edges connected to node i, and k i,in represents the sum of the weights of the edges connecting node i with the nodes in community C.
[0044] S32, based on the Louvain algorithm, maximizes the local modularity of smaller communities and adds nodes to communities only when this aggregation leads to an increase in modularity, completing the regional segmentation of the complex network;
[0045] S33, standardize the relevant data information in the segmented community and map it to the target space, and then perform indicator definition and risk assessment in the target space.
[0046] S4, Node Risk Assessment: Considering the dynamic heterogeneous redundant structure in the mimicry defense theory, node vulnerabilities are dynamically measured and real-time risk assessment is performed. The specific steps are as follows:
[0047] S41, build a vulnerability set based on the information obtained from vulnerability scanning and local prior knowledge:
[0048] VUL=VUL1∪VUL2∪…∪VUL n
[0049] VUL i ={vul j ∣vul j It is V i A vulnerability on
[0050] S42, based on the vulnerability set and vulnerability score information, construct the vulnerability score vector CVSS and node vulnerability matrix NV:
[0051] CVSS=(cvss1,cvss2,…,cvss m ) T
[0052] Among them, cvss i (i=1, 2, ..., m) represents one tenth (for normalization) of the CVSS (Common Vulnerability Scoring System) score of the corresponding vulnerability.
[0053] NV n*m =(V1,V2,…,V n ) T
[0054] V i =(v1,v2,…,v m ) T , m=|VUL|,
[0055]
[0056] S43, combining the node centrality and the value of the resources it possesses, constructs the importance vector IM:
[0057] IM=(im1,im2,…,im n ) T ,
[0058] im k =w1×centrality+w2×value, k=1,2,…,n.
[0059] Among them, w i (i=1, 2) represents the weight of the corresponding factor, ∑w i = 1. The weights and influencing factors can be adjusted appropriately according to actual conditions.
[0060] S44, combined with the above measured values, quantitatively evaluate the node safety risk factor according to the following formula:
[0061] RI=IM T ×NV×CVSS
[0062] S5, correlation measurement: Considering the common mode of vulnerability and probability transfer, quantitative measurement is performed in combination with the actual application scenarios of the mimetic network;
[0063] S51, Vulnerability Common Mode Measurement: Based on the mimic security feature, calculate the vulnerability common mode index between nodes;
[0064] S511, node N s and node N t (N s , N t ∈N) is defined as:
[0065]
[0066] in, Indicates vulnerability vul k CVSS score, used to describe the severity of the vulnerability; VUL s and VUL t Represent the vulnerability sets of node s and node t respectively.
[0067] S512, due to the structural characteristics of the mimicry system, the vulnerability set is in a dynamic state of change, and the node N of the mimicry defense technology will be deployed. cmd With ordinary node N x The common mode index between is defined as:
[0068]
[0069] in Represents the period t i N nodes deployed in the mimicry cmd (The vulnerability set is in a dynamic update state) and the normal node N x The common mode index between them; and T is expected to be a period as long as possible to show the possible states of the actuator set.
[0070] S513, integrate the common mode indicators between nodes into a matrix form:
[0071] CM=(c ij ) n×n ,
[0072]
[0073] S52, Probability Transfer Measurement: Considering the horizontal diffusion situation, the attack probability transfer situation is measured;
[0074] S521, the vulnerability transfer matrix T is defined as:
[0075] T=(t ij ) n*n ,
[0076]
[0077] S522, the probability of the attacker transferring from node i to node j in a single step is:
[0078]
[0079] Among them, d i represents the degree of the i-th node, a ij is an element in the adjacency matrix A (if a ij =1, it means there is an edge between nodes i and j, a ij = 0 means there is no edge between nodes i and j).
[0080] S523, construct the attack probability transfer matrix P:
[0081]
[0082] Where n is the number of nodes in the community, and p ij represents the probability that the attacker moves from node i to node j in one step.
[0083] S524, considering the basic transfer factor ε0 and the multi-step transfer situation, the probability transfer probability is calculated and expressed as the matrix TP:
[0084] TP=ε0Adj+(P)+(P) 2 +(P) 3 +…
[0085] =ε0Adj+(IP) -1 -I
[0086] Among them, Adj represents the adjacency matrix, P represents the probability transfer matrix, and I represents the identity matrix.
[0087] S6, Comprehensive Risk Assessment: Integrate the measured conditions such as dynamic vulnerability, common mode index, and transition probability, and construct a quadratic model for comprehensive risk assessment based on the following formula:
[0088] RC=RI T ×(CM⊙TP)×RI
[0089] Where RI represents the node security risk coefficient vector, CM represents the common mode index matrix, and TP represents the probability transfer matrix. ⊙ represents the Hadamard product, which is the multiplication operation of the corresponding elements of the matrix.
[0090] The technical means disclosed in the scheme of the present invention are not limited to the technical means disclosed in the above-mentioned implementation scheme, but also include technical solutions composed of any combination of the above technical features.
Claims
1. A partition positioning risk assessment method for a mimetic network, characterized in that: The method comprises the following steps: S1, network topology acquisition: Scan the network using scanning tools to discover hosts and services in the network and then infer the network topology; S2, vulnerability information scanning: Use vulnerability scanning tools to detect vulnerabilities in the network and obtain detailed information about the vulnerabilities; S3, community structure division: using the community division method based on the Louvain algorithm to segment large-scale complex networks into regions to achieve more accurate positioning measurement and risk assessment; S4, Node Risk Assessment: Considering the dynamic heterogeneous redundant structure in the mimicry defense theory, node vulnerabilities are dynamically measured and real-time risk assessment is performed; S5, correlation measurement: Considering the common mode of vulnerability and probability transfer, quantitative measurement is performed in combination with the actual application scenarios of the mimetic network; S6, comprehensive risk assessment: integrating dynamic vulnerability, common mode index, transition probability and measured conditions to conduct comprehensive risk assessment; Wherein, step S5 includes the following steps: S51, Vulnerability Common Mode Measurement: Based on the mimic security feature, calculate the vulnerability common mode index between nodes, as follows: S511, node N s and node N t , N s , N t The common mode index between ∈N is defined as: in, Indicates vulnerability vul k Vulnerability scoring vector CVSS score, used to describe the severity of the vulnerability; VUL s and VUL t represent the vulnerability sets of node s and node t respectively; S512, due to the structural characteristics of the mimicry system, the vulnerability set is in a dynamic state of change, and the node N of the mimicry defense technology will be deployed. cmd With ordinary node N x The common mode index between is defined as: The vulnerability set is in a dynamic update state. Represents the period t i Node N in which mimicry defense technology is deployed cmd With ordinary node N x The common mode index between them; and T is expected to be a period as long as possible to show the possible states of the actuator set; S513, integrate the common mode indicators between nodes into a matrix form: CM=(c ij ) n×n , 2. A partition positioning risk assessment method for a mimetic network according to claim 1, characterized in that: The step S3 is specifically as follows: S3, community structure division: Based on the scale-free network characteristics, the community division method based on the Louvain algorithm is used to segment large-scale complex networks into regions to achieve more accurate positioning measurement and risk assessment. The specific steps are as follows: S31, based on the network topology information obtained in S1, calculate the modularity Q and modularity gain ΔQ: Where m represents the total number of edges in the graph, ∑ in represents the sum of the weights of the interconnected edges within community c, Σ tot represents the sum of the weights of the edges connected to the nodes of community C, including the edges within the community and outside the community; Among them, k i represents the sum of the weights of the edges connected to node i, and k i,in represents the sum of the weights of the edges connecting node i with the nodes in community C; S32, based on the Louvain algorithm, maximizes the local modularity of smaller communities and adds nodes to communities only when this aggregation leads to an increase in modularity, completing the regional segmentation of the complex network; S33, standardize the relevant data information in the segmented community and map it to the target space, and then perform indicator definition and risk assessment in the target space.
3. The method for risk assessment of partitioned positioning of a mimetic network according to claim 1, wherein: The step S4 is specifically as follows: S41, build a vulnerability set based on the information obtained from vulnerability scanning and local prior knowledge: FILL=FILL1∪FILL2∪…∪FILL n VUL i ={vul j ∣vul j It is V i A vulnerability on S42, construct the node-vulnerability matrix NV, the importance vector IM and the vulnerability score vector CVSS, and quantitatively evaluate the node security risk coefficient according to the following formula: RI=IM T ×NV×CVSS。 4. The method for risk assessment of partitioned positioning of a mimetic network according to claim 1, wherein: The step S5 is specifically as follows: S51, based on the network security characteristics of the mimicry, calculates the common mode index of vulnerabilities between nodes: S52, taking into account the horizontal spread, calculate the attack probability transfer situation.
5. A partition positioning risk assessment method for a mimetic network according to claim 4, characterized in that: Step S52, probability transfer measurement: taking into account the horizontal diffusion situation, the attack probability transfer situation is measured, specifically as follows: S521, the vulnerability transfer matrix T is defined as: T=(t ij ) n*n , S522, the probability of the attacker transferring from node i to node j in a single step is: Among them, d i represents the degree of the i-th node, a ij is an element in the adjacency matrix Adj. If a ij =1, it means there is an edge between nodes i and j, a ij =0 means there is no edge between nodes i and j; S523, construct the attack probability transfer matrix P: Where n is the number of nodes in the community, and p ij represents the probability that the attacker moves from node i to node j in one step, S524, considering the basic transfer factor ε0 and the multi-step transfer situation, the probability transfer probability is calculated and expressed as the matrix TP: TP=ε0Adj+(P)+(P) 2 +(P) 3 +…=ε0Adj+(I-P) -1 -I, Among them, Adj represents the adjacency matrix, P represents the probability transfer matrix, and I represents the identity matrix.
6. A partition positioning risk assessment method for a mimetic network according to claim 1, characterized in that: The step S6 is specifically as follows: S61: Collect the values calculated in S4 and S5, and construct a quadratic model based on the following formula to quantitatively evaluate the comprehensive security risk factor of the mimic network: RC=RI T ×(CM⊙TP)×RI, Among them, RI represents the node security risk coefficient vector, represents the common mode index matrix, TP represents the probability transfer matrix; represents the Hadamard product, that is, the multiplication operation of the corresponding matrix elements.
Citation Information
Patent Citations
Systems and methods for cybersecurity risk assessment
US20180146004A1
Systems and methods for risk rating of vulnerabilities
US20200012796A1