Method, device and equipment for predicting network security state of border gateway protocol

By obtaining the relevant parameters of the boundary gateway protocol, the attack risk assessment function is constructed, and the network security state is calculated in combination with the initial transfer probability matrix, the problem of insufficient accuracy of BGP network security state prediction in the prior art is solved, and more accurate prediction is achieved.

CN120434031APending Publication Date: 2025-08-05SUZHOU IND PARK SERVICE OUTSOURCING VOCATIONAL COLLEGE (SUZHOU SERVICE OUTSOURCING TALENT TRAINING & TRAINING CENT)
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510769580.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

The existing Border Gateway Protocol (BGP) network security state prediction model relies on traditional statistical analysis and simple machine learning methods, making it difficult to accurately handle complex nonlinear relationships between features, resulting in insufficient prediction accuracy.

Method used

By obtaining the attack prefix injection rate, network defense capability and attacked prefix importance of the border gateway protocol, an attack risk assessment function is constructed, and the network security state is calculated in combination with the initial transfer probability matrix to reduce the subjectivity of manual experience.

Benefits of technology

It improves the accuracy of network security status prediction, reduces the impact of subjective judgment, and provides more accurate network security status prediction results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434031A_ABST
    Figure CN120434031A_ABST
Patent Text Reader

Abstract

The invention discloses a network security state prediction method and device of a border gateway protocol, equipment and a readable storage medium, and relates to the technical field of Internet. Comprising the following steps: acquiring relevant parameters of a border gateway protocol; the related parameters comprise the attack prefix injection rate, the network defense capability and the attacked prefix importance of the border gateway protocol; determining the attack risk of the border gateway protocol based on the related parameters of the border gateway protocol; and calculating a network security state prediction result of the border gateway protocol based on the attack risk and the initial transition probability matrix of the border gateway protocol. According to the method, the accuracy of network security state prediction is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technology, and in particular to a method, device, equipment and readable storage medium for predicting the network security status of a border gateway protocol. Background Art

[0002] The Border Gateway Protocol (BGP) is responsible for transmitting routing information between autonomous systems (ASs). BGP utilizes a distributed architecture, leveraging frequent information exchange between ASes to dynamically maintain the global network routing table, ensuring accurate traffic flow in complex environments. However, BGP's initial design lacked comprehensive security considerations and exhibited serious vulnerabilities, including a lack of effective authentication mechanisms for advertised routes, creating opportunities for attackers to launch BGP attacks.

[0003] Existing BGP network security status prediction models primarily rely on traditional statistical analysis and simple machine learning methods. The data used in model construction primarily comes from historical BGP routing information, some network traffic monitoring data, and a small amount of feature data from known attack events. Applied methods include Multiple Linear Regression (MLR), Logistic Regression (LR), Decision Tree (DT), and simple Neural Network (NN). Models based on neural networks perform relatively well in terms of accuracy. Logistic Regression (LR) uses a logistic function to probabilistically predict the presence of security threats in the BGP network and is often used to determine whether an attack has occurred. Its drawback is its difficulty handling complex nonlinear relationships between features. Decision Trees (DT) use a tree-like structure to make decisions, classifying and predicting based on the characteristics of BGP network data. For example, they can determine whether anomalous routes exist based on different route attributes. However, decision trees are prone to overfitting and lack generalization capabilities to new data.

[0004] Therefore, the above methods cannot accurately predict the network security status of the border gateway protocol, and there is an urgent need for a network security status prediction method of the border gateway protocol that can overcome the above defects. Summary of the Invention

[0005] The purpose of the present invention is to provide a network security status prediction method, device, equipment and readable storage medium for the Border Gateway Protocol. The present invention quantifies the relevant parameters of the Border Gateway Protocol, and incorporates the attack prefix injection rate, network defense capability and the importance of the attacked prefix into the attack risk assessment function. Finally, the network security status prediction result is calculated based on the attack risk and the initial probability transfer matrix, eliminating the subjectivity of relying on manual experience to judge the network security status and increasing the accuracy of the network security status prediction result.

[0006] In order to achieve the above object, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a method for predicting the network security status of a border gateway protocol, the method comprising:

[0008] Obtaining border gateway protocol (BGP) parameters, including the BGP attack prefix injection rate, network defense capability, and importance of the attacked prefix.

[0009] Based on the relevant parameters of the Border Gateway Protocol, the attack risk of the Border Gateway Protocol is determined; the attack risk evaluation function is:

[0010] Among them, α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol;

[0011] Based on the attack risk and initial transition probability matrix of the Border Gateway Protocol, the network security status prediction results of the Border Gateway Protocol are calculated.

[0012] In some embodiments, calculating a prediction result of a network security status of the border gateway protocol based on the attack risk and transition probability matrix of the border gateway protocol includes:

[0013] Based on the attack risk of the Border Gateway Protocol, the initial transition probability matrix is modified to obtain a modified transition probability matrix;

[0014] Obtaining an initial state vector of the border gateway protocol; the initial state vector includes a security state probability, a warning state probability, and an attack state probability of the border gateway protocol at an initial moment;

[0015] Based on the modified transition probability matrix and the initial state vector, a first state vector of the border gateway protocol after a time period is obtained; the first state vector includes a safety state probability, a warning state probability, and an attack state probability of the border gateway protocol after a time period.

[0016] In some embodiments, the method further comprises:

[0017] Based on the modified transition probability matrix and the first state vector, a second state vector of the border gateway protocol after two time periods is obtained.

[0018] In some embodiments, obtaining a border gateway protocol attack prefix injection rate includes:

[0019] Get the number of attack prefixes of the Border Gateway Protocol in a period;

[0020] Calculate the attack prefix injection rate of the Border Gateway Protocol based on the number of attack prefixes and the duration of a cycle.

[0021] In some embodiments, obtaining a network defense capability of a border gateway protocol includes:

[0022] Obtaining the defense capability of each defense strategy in the border gateway protocol and the first weight coefficient corresponding to each defense strategy;

[0023] The defense capabilities of the various defense strategies are weighted and summed based on the first weight coefficient to obtain the network defense capability of the border gateway protocol.

[0024] In some embodiments, obtaining the importance of an attacked prefix of a border gateway protocol includes:

[0025] Obtaining the importance score of each service in the border gateway protocol and the second weight coefficient corresponding to each service;

[0026] The importance scores of the various services are weighted and summed based on the second weight coefficient to obtain the importance of the attacked prefix of the Border Gateway Protocol.

[0027] In a second aspect, the present invention further provides a network security status prediction device for a border gateway protocol, the device comprising:

[0028] A parameter acquisition module is used to obtain relevant parameters of the Border Gateway Protocol; the relevant parameters include the attack prefix injection rate of the Border Gateway Protocol, the network defense capability and the importance of the attacked prefix;

[0029] The risk assessment module is used to determine the attack risk of the Border Gateway Protocol based on the relevant parameters of the Border Gateway Protocol. The attack risk assessment function is:

[0030] Among them, α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol;

[0031] The result prediction module is used to calculate the network security status prediction result of the border gateway protocol based on the attack risk and initial transition probability matrix of the border gateway protocol.

[0032] In a third aspect, the present invention also provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the network security status prediction method for the border gateway protocol provided in the first aspect is implemented.

[0033] In a fourth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network security status prediction method of the border gateway protocol provided in the first aspect.

[0034] In a fifth aspect, the present invention further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the network security status prediction method of the Border Gateway Protocol provided in the first aspect.

[0035] The beneficial effects of the present invention are:

[0036] The present invention provides a method for predicting the network security status of the Border Gateway Protocol (BGP). The method first obtains relevant parameters of the BGP, including the BGP's attack prefix injection rate, network defense capability, and importance of the attacked prefix. Based on the BGP's relevant parameters, the BGP's attack risk is determined. Finally, a prediction result for the BGP's network security status is calculated based on the BGP's attack risk and an initial transition probability matrix. The BGP's relevant parameters are quantified, and the attack prefix injection rate, network defense capability, and importance of the attacked prefix are incorporated into the attack risk assessment function. Finally, a prediction result for the network security status is calculated based on the attack risk and the initial probability transition matrix. This eliminates the subjectivity inherent in relying on manual experience to determine the network security status, thereby increasing the accuracy of the network security status prediction result.

[0037] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention and implement it according to the contents of the specification, the following is a detailed description of the preferred embodiments of the present invention with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A schematic flow chart of a method for predicting network security status of a border gateway protocol according to an embodiment of the present invention;

[0039] Figure 2 A schematic flow chart of another method for predicting the network security status of a border gateway protocol according to an embodiment of the present invention;

[0040] Figure 3 This is a schematic structural diagram of a network security status prediction device for a Border Gateway Protocol according to an embodiment of the present invention;

[0041] Figure 4 This is a schematic structural diagram of another Border Gateway Protocol network security status prediction device according to an embodiment of the present invention;

[0042] Figure 5 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0043] The technical solution of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0044] It should be noted that references to "one embodiment," "an embodiment," "an example embodiment," etc., in this specification indicate that the described embodiment may include specific features, structures, or characteristics. However, not every embodiment must include these specific features, structures, or characteristics. In addition, such references do not necessarily refer to the same embodiment. Furthermore, when specific features, structures, or characteristics are described in conjunction with an embodiment, whether or not explicitly described, it is indicated that it is within the knowledge of those skilled in the art to incorporate such features, structures, or characteristics into other embodiments.

[0045] In addition, the technical features involved in the different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0046] In some embodiments, as Figure 1 As shown, a method for predicting the network security status of the Border Gateway Protocol is provided, and the specific method includes:

[0047] S101, obtaining relevant parameters of the Border Gateway Protocol.

[0048] Among them, the relevant parameters include the attack prefix injection rate of the Border Gateway Protocol, the network defense capability and the importance of the attacked prefix.

[0049] Specifically, many businesses require border gateway protocols, such as finance, e-commerce operations, government affairs, healthcare, education, general corporate offices, and personal online services. When it is necessary to predict the network security status of the border gateway protocols of these businesses, the attack prefix injection rate, network defense capabilities, and importance of the attacked prefixes of these border gateway protocols can be monitored and evaluated in real time.

[0050] Optionally, the method for obtaining the attack prefix injection rate, network defense capability and importance of the attacked prefix of the Border Gateway Protocol can also be: obtaining the number of attack prefixes of the Border Gateway Protocol within a cycle; calculating the attack prefix injection rate of the Border Gateway Protocol based on the number of attack prefixes and the length of a cycle; obtaining the defense capability of each defense strategy in the Border Gateway Protocol and the first weight coefficient corresponding to each defense strategy; performing weighted summation of the defense capability of each defense strategy based on the first weight coefficient to obtain the network defense capability of the Border Gateway Protocol; obtaining the importance score of each service in the Border Gateway Protocol and the second weight coefficient corresponding to each service; performing weighted summation of the importance score of each service based on the second weight coefficient to obtain the importance of the attacked prefix of the Border Gateway Protocol.

[0051] For example, the number of attack prefixes within a period can be counted according to a time window. For example, if a period is 2 hours, the time window can be set to 2 hours. If the total number of prefixes counted within the period is 20, the total prefix injection rate can be calculated as 20 / 2 hours = 10 / hour. For details, please refer to Table 1:

[0052] Table 1 Statistics of attack prefix injection rate

[0053]

[0054] In addition, the Border Gateway Protocol (BGP) includes multiple defense strategies, which are further divided into BGP security mechanisms and participant decision-making mechanisms. BGP security mechanisms include routing filtering, encryption authentication, the general time-to-live (GTTL) security protection mechanism (GTSM), and resource public key infrastructure (RPKI). Participant decision-making mechanisms include the receiver-initiated filtering strategy and the sender-initiated signing strategy. These defense strategies have different defense capability values in different situations. For details, see Table 2 below:

[0055] Table 2 BGP security defense mechanism

[0056]

[0057] After determining the defense capability and the first weight coefficient of each defense strategy, the defense capability of each defense strategy is weighted and summed based on the first weight coefficient to obtain the network defense capability of the border gateway protocol.

[0058] Finally, the importance scores of each service in the Border Gateway Protocol and the second weight coefficient corresponding to each service are collected. The importance score is determined based on parameters such as the criticality of each service to network operations, the amount of loss that may be caused by service interruption, and the number of users involved in the service. The second weight coefficient is obtained by professionals in this field based on their own experience and actual conditions. The importance scores of each service are weighted and summed based on the second weight coefficient to obtain the importance of the attacked prefix of the Border Gateway Protocol.

[0059] S102: Determine the attack risk of the Border Gateway Protocol based on relevant parameters of the Border Gateway Protocol.

[0060] Among them, the attack risk evaluation function is formula (1):

[0061]

[0062] α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol.

[0063] Specifically, α1 directly reflects the impact of the attack prefix injection rate on the attack risk. The higher the attack prefix injection rate, the larger α1 is, the larger the function value is, and the higher the attack risk is. This linear relationship is clear at a glance. γ1 reflects the importance of the attacked prefix, and it is related to the defense capability β1 through the fraction The squared form of β1 in the denominator emphasizes the suppressive effect of defensive capabilities on risk. When defensive capabilities increase, the denominator increases and the fractional value decreases, thereby reducing the overall attack risk. This relationship clearly demonstrates the key role of defensive capabilities in mitigating attack risks.

[0064] S103, calculating a prediction result of the network security status of the Border Gateway Protocol based on the attack risk of the Border Gateway Protocol and the initial transition probability matrix.

[0065] For example, when a transition probability matrix When P 11 (t) = 0.9, indicating that the probability of transitioning from a safe state to a safe state is 0.9, P 12 (t) = 0.08, the probability of transitioning from the safe state to the warning state is 0.08, P 13 (t) = 0.02, the probability of transitioning from a safe state to an attack state is 0.02, and the data in the second and third rows are similar; when a transition matrix When P 11 (Δt) = 0.95, indicating that within the Δt period, the probability of the network remaining in the safe state from the safe state s1 increases by 0.95, P 12(Δt) = 0.03, indicating that within the Δt period, the probability of the network changing from the safe state s1 to the warning state s2 drops to 0.03, P 13 (Δt)=0.02, which means that within the Δt period, the probability of the network changing from the safe state s1 to the warning state s3 remains unchanged at 0.02. The same is true for the data in the second and third rows.

[0066] Specifically, the initial transition probability matrix is first corrected using the attack risk, and then the corrected transition probability matrix is multiplied by the current network status of the border gateway protocol to obtain the network security status prediction result of the border gateway protocol.

[0067] Optionally, it can also be: based on the attack risk of the border gateway protocol, the initial transfer probability matrix is corrected to obtain a corrected transfer probability matrix; the initial state vector of the border gateway protocol is obtained; the initial state vector includes the safety state probability, warning state probability and attack state probability of the border gateway protocol at the initial moment; based on the corrected transfer probability matrix and the initial state vector, the first state vector of the border gateway protocol after a time period is obtained; the first state vector includes the safety state probability, warning state probability and attack state probability of the border gateway protocol after a time period.

[0068] For example, if the attack prefix injection rate at the initial moment is 10, the network defense capability is 0.56, and the importance of the attacked prefix is 0.8, the attack risk can be calculated according to formula (1): When the initial transition probability matrix is When using the formula Then perform normalization, namely:

[0069] First row: P 11 raw =0.9*13.55=12.195,P 12 raw =0.08*13.55=

[0070] 1.084,P 13 raw =0.02*13.55=0.271; Normalization:

[0071] Second row: P 21 raw =0.15*13.55=20.0325,P 22 raw =0.7*13.55=9.485,P 23 raw=0.15*13.55=2.0325, normalized:

[0072] Third row: P 31 raw =0.05*13.55=0.6775,P 32 raw =0.1*13.55=

[0073] 1.355,P 33 raw =0.85*13.55=11.5175; Normalization:

[0074] In summary, the modified transition probability matrix is:

[0075] For example, the initial state vector It means that the probability that the Border Gateway Protocol is in a safe state at the initial moment is 80%, the probability of being in a warning state is 15%, and the probability of being in an attack state is 5%.

[0076] The result of multiplying the initial state vector by the modified transition probability matrix is the first state vector after one time period, that is, the security state probability, warning state probability and attack state probability of the border gateway protocol after one time period.

[0077] Optionally, a second state vector of the border gateway protocol after two time periods may be obtained based on the modified transition probability matrix and the first state vector.

[0078] Specifically, when it is necessary to calculate the network security state after the second time period, it is only necessary to multiply the first state vector by the modified transition probability matrix, and so on.

[0079] It should be noted that the above-mentioned initial state vector and initial transition probability matrix are obtained after reasonable parameter estimation and model calibration based on a large amount of historical data, actual business experience and in-depth analysis of various influencing factors.

[0080] The network security status prediction method for the Border Gateway Protocol in the above-described embodiment first obtains relevant parameters of the Border Gateway Protocol; these parameters include the attack prefix injection rate, network defense capability, and importance of the attacked prefix. Based on the relevant parameters of the Border Gateway Protocol, the attack risk of the Border Gateway Protocol is determined. Finally, a network security status prediction result for the Border Gateway Protocol is calculated based on the attack risk of the Border Gateway Protocol and an initial transition probability matrix. The relevant parameters of the Border Gateway Protocol are quantified, and the attack prefix injection rate, network defense capability, and importance of the attacked prefix are incorporated into the attack risk assessment function. Finally, a network security status prediction result is calculated based on the attack risk and the initial probability transition matrix. This eliminates the subjectivity of relying on manual experience to determine the network security status, thereby increasing the accuracy of the network security status prediction result.

[0081] In another embodiment, when the network security status prediction result shows that the attack risk is high, the network defense capability of the border gateway protocol can be enhanced based on different strategies, as shown in Table 3:

[0082] Table 3 Network defense capability strategy table:

[0083]

[0084]

[0085] In another embodiment, a performance evaluation of the network security status prediction method for the Border Gateway Protocol proposed in this application was conducted. Relevant parameters of the Border Gateway Protocol were collected, and the initial state vector was set to 80% security, 15% warning, and 5% attack. The data was then randomly and evenly divided into five subsets, labeled A, B, C, D, and E. The network security status prediction method for the Border Gateway Protocol proposed in this application was tested using the five subsets. The test results showed that the method achieved an accuracy of 94.4%, a recall of 88%, a mean square error of 0.034, and a mean absolute error of 0.019, respectively. This demonstrates that the network security status prediction method for the Border Gateway Protocol proposed in this application can provide relatively reasonable and accurate prediction results.

[0086] In order to more comprehensively demonstrate this solution, this embodiment provides an optional method for predicting the network security status of the border gateway protocol, such as Figure 2 As shown:

[0087] S201, obtaining the number of attack prefixes of the Border Gateway Protocol in a cycle.

[0088] S202: Calculate the attack prefix injection rate of the Border Gateway Protocol based on the number of attack prefixes and the duration of a cycle.

[0089] S203: Obtain the defense capability of each defense strategy in the Border Gateway Protocol and the first weight coefficient corresponding to each defense strategy.

[0090] S204 , performing weighted summation of the defense capabilities of the various defense strategies based on the first weight coefficient to obtain the network defense capability of the border gateway protocol.

[0091] S205: Obtain the importance score of each service in the Border Gateway Protocol and the second weight coefficient corresponding to each service.

[0092] S206 , performing weighted summation on the importance scores of the respective services based on the second weight coefficient to obtain the importance of the attacked prefix of the Border Gateway Protocol.

[0093] S207: Determine the attack risk of the Border Gateway Protocol based on relevant parameters of the Border Gateway Protocol.

[0094] Among them, the evaluation function of attack risk is:

[0095] Among them, α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol.

[0096] S208 , based on the attack risk of the Border Gateway Protocol, the initial transition probability matrix is modified to obtain a modified transition probability matrix.

[0097] S209: Obtain an initial state vector of the Border Gateway Protocol.

[0098] The initial state vector includes the security state probability, warning state probability and attack state probability of the border gateway protocol at the initial moment.

[0099] S210 , obtaining a first state vector of the border gateway protocol after a time period based on the modified transition probability matrix and the initial state vector.

[0100] The first state vector includes the security state probability, warning state probability and attack state probability of the border gateway protocol after a time period.

[0101] The specific process of the above S201-S210 can be found in the description of the above method embodiment. The implementation principle and technical effects are similar and will not be repeated here.

[0102] Based on the same inventive concept, embodiments of the present application also provide a Border Gateway Protocol (BGP) network security status prediction device for implementing the aforementioned BGP network security status prediction method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more BGP network security status prediction device embodiments provided below can be found in the aforementioned BGP network security status prediction method, and will not be further elaborated here.

[0103] In one embodiment, Figure 3 As shown, a network security status prediction device for a border gateway protocol is provided, the device comprising:

[0104] Parameter acquisition module 30, used to obtain relevant parameters of the Border Gateway Protocol; the relevant parameters include the attack prefix injection rate of the Border Gateway Protocol, network defense capability and importance of the attacked prefix;

[0105] The risk assessment module 31 is used to determine the attack risk of the Border Gateway Protocol based on the relevant parameters of the Border Gateway Protocol. The attack risk assessment function is:

[0106] Among them, α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol;

[0107] The result prediction module 32 is used to calculate the network security status prediction result of the border gateway protocol based on the attack risk of the border gateway protocol and the initial transition probability matrix.

[0108] In another embodiment, Figure 4 As shown above Figure 3 The result prediction module 32 includes:

[0109] The vector acquisition unit 320 is used to acquire the initial state vector of the border gateway protocol; the initial state vector includes the security state probability, warning state probability and attack state probability of the border gateway protocol at the initial moment;

[0110] The result determination unit 321 is used to obtain a first state vector of the border gateway protocol after a time period based on the modified transition probability matrix and the initial state vector; the first state vector includes the security state probability, warning state probability and attack state probability of the border gateway protocol after a time period.

[0111] In another embodiment, the above Figure 3The network security state prediction device of the border gateway protocol is further specifically used to: obtain a second state vector of the border gateway protocol after two time periods based on the modified transition probability matrix and the first state vector.

[0112] In another embodiment, the above Figure 3 The parameter acquisition module 30 is specifically configured to: obtain the number of attack prefixes in a Border Gateway Protocol (BGP) cycle; calculate the attack prefix injection rate of the BGP based on the number of attack prefixes and the duration of the cycle; obtain the defense capability of each defense strategy in the BGP and the first weight coefficient corresponding to each defense strategy; perform a weighted sum of the defense capabilities of each defense strategy based on the first weight coefficient to obtain the network defense capability of the BGP; obtain the importance score of each service in the BGP and the second weight coefficient corresponding to each service; perform a weighted sum of the importance scores of each service based on the second weight coefficient to obtain the importance of the attacked prefix of the BGP.

[0113] The present application also provides an electronic device, in some embodiments, referring to Figure 5 As shown, electronic device 700 includes an input unit 710, a memory 720, a processor 730, and an output unit 740. Memory 720 stores program instructions that can be executed by processor 730. Processor 730 invokes the program instructions to execute the network security status prediction method and / or technical solution based on the Border Gateway Protocol in the aforementioned embodiments. The electronic device 700 can be a mobile terminal device such as a mobile phone or a computer.

[0114] In addition, embodiments of the present application further provide a computer-readable storage medium for storing a computer program that implements a method for predicting network security status using a Border Gateway Protocol. For example, computer program instructions, when executed by a computer, can invoke or provide the method and / or technical solution according to the present application through the operation of the computer. The program instructions for invoking the method of the present application may be stored in a fixed or removable storage medium, and / or transmitted via a data stream in a broadcast or other signal-carrying medium, and / or stored in a storage medium that executes according to the program instructions.

[0115] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be implemented using a general-purpose computing device. They can be concentrated on a single computing device or distributed across a network consisting of multiple computing devices. Alternatively, they can be implemented using program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.

[0116] The technical features of the above embodiments can be arbitrarily integrated. To make the description concise, not all possible integrations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the integration of these technical features, they should be considered to be within the scope of this specification.

[0117] The above embodiments merely illustrate several implementations of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.

Claims

1. A method for predicting network security status of a border gateway protocol, characterized in that: The method comprises: Obtaining relevant parameters of the Border Gateway Protocol; the relevant parameters include the attack prefix injection rate, network defense capability and importance of the attacked prefix of the Border Gateway Protocol; Based on the relevant parameters of the border gateway protocol, the attack risk of the border gateway protocol is determined; the evaluation function of the attack risk is: Where α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol; Based on the attack risk and initial transition probability matrix of the border gateway protocol, a network security status prediction result of the border gateway protocol is calculated.

2. The method for predicting the network security status of the Border Gateway Protocol according to claim 1, wherein: Calculating a prediction result of a network security status of the border gateway protocol based on the attack risk and transition probability matrix of the border gateway protocol includes: Based on the attack risk of the border gateway protocol, the initial transition probability matrix is modified to obtain a modified transition probability matrix; Obtaining an initial state vector of the border gateway protocol; the initial state vector includes a security state probability, a warning state probability, and an attack state probability of the border gateway protocol at an initial moment; Based on the modified transition probability matrix and the initial state vector, a first state vector of the border gateway protocol after a time period is obtained; the first state vector includes the security state probability, warning state probability and attack state probability of the border gateway protocol after a time period.

3. The network security status prediction method of the Border Gateway Protocol according to claim 2, characterized in that: The method further comprises: A second state vector of the border gateway protocol after two time periods is obtained based on the modified transition probability matrix and the first state vector.

4. The method for predicting the network security status of the Border Gateway Protocol according to claim 1, wherein: Get the attack prefix injection rate of the Border Gateway Protocol, including: Obtaining the number of attack prefixes of the Border Gateway Protocol within a period; An attack prefix injection rate of the border gateway protocol is calculated based on the number of attack prefixes and a period length.

5. The method for predicting the network security status of the Border Gateway Protocol according to claim 1, wherein: Gain network defense capabilities for Border Gateway Protocol, including: Obtaining a defense capability of each defense strategy in the border gateway protocol and a first weight coefficient corresponding to each defense strategy; The defense capabilities of the various defense strategies are weighted and summed based on the first weight coefficient to obtain the network defense capability of the border gateway protocol.

6. The method for predicting the network security status of the Border Gateway Protocol according to claim 1, wherein: Get the importance of the attacked prefixes for Border Gateway Protocol, including: Obtaining an importance score of each service in the border gateway protocol and a second weight coefficient corresponding to each service; The importance scores of the respective services are weighted and summed based on the second weight coefficient to obtain the importance of the attacked prefix of the border gateway protocol.

7. A network security status prediction device for a border gateway protocol, characterized in that: The device comprises: A parameter acquisition module, configured to acquire relevant parameters of the Border Gateway Protocol; the relevant parameters include the attack prefix injection rate, network defense capability, and importance of the attacked prefix of the Border Gateway Protocol; A risk assessment module is configured to determine the attack risk of the Border Gateway Protocol based on relevant parameters of the Border Gateway Protocol; the attack risk assessment function is: Where α1 is the injection rate of attack prefixes, β1 is the network defense capability, γ1 is the importance of the attacked prefix, and f(α1,β1,γ1) is the attack risk of the border gateway protocol; The result prediction module is used to calculate the network security status prediction result of the border gateway protocol based on the attack risk and initial transition probability matrix of the border gateway protocol.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the network security status prediction method of the Border Gateway Protocol according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the network security status prediction method of the border gateway protocol according to any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the network security status prediction method of the border gateway protocol according to any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Gateway port on-off control method, equipment and medium

    CN121664549A