Industry security joint defense method based on federal game
By employing a federated game approach, early identification of cross-organizational threats and quantitative risk assessment were achieved, generating differentiated collaborative defense solutions. This addressed the difficulties in threat identification and unreasonable task allocation in industry-wide security cooperation, thereby improving defense effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING SWIFT SAFETY TECH CO LTD
- Filing Date
- 2026-05-18
- Publication Date
- 2026-06-26
AI Technical Summary
In the field of industry-wide security cooperation, difficulties in identifying cross-organizational threats, lack of quantitative assessment of risks in member cooperation, unpredictable risk propagation trends, and unreasonable allocation of collaborative tasks make it difficult to detect and deal with threats in a timely manner, resulting in insufficient utilization of resources.
By employing a federated game approach, through encrypted transmission and cross-organizational threat correlation analysis, the system quantifies the comprehensive threat pressure and cooperation risk values of its members, predicts risk propagation trends, and generates differentiated collaborative defense solutions.
It enables early identification and automated response to cross-organizational threats, quantifies the collaborative risks of members, accurately predicts risk propagation trends, and rationally allocates collaborative tasks, thereby improving the intelligence level and defense effectiveness of the industry joint defense system.
Smart Images

Figure CN122293431A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industry security joint defense technology, and in particular to an industry security joint defense method based on federated game theory. Background Technology
[0002] In the field of industry-wide security cooperation, member companies or organizations typically enhance their overall protection capabilities by sharing security information and coordinating incident response. However, because the threat perception data reported by each member involves sensitive information such as internal production operations, members are reluctant to share due to concerns about privacy leaks, making it difficult to detect cross-organizational threats in a timely manner. Even if members are willing to share, existing methods lack automated correlation analysis tools to identify the cross-organizational spread characteristics of the same threat in different member network environments. As a result, threats are often only discovered after they have already caused significant impact, leading to irreparable losses.
[0003] Meanwhile, the joint prevention and control coordination center struggles to quantify and assess the actual operational status of each member. For example, it cannot determine whether a member has sufficient resources or exhibits abnormal behavior, which directly leads to an inability to accurately assess the actual cooperation risks faced by each member when confronted with external threats. On the other hand, the lack of a quantifiable trust assessment mechanism among members makes it impossible to predict whether a member's cooperation risks will spread to other members through trust relationships when one member faces such risks, making it difficult to take early intervention measures. In this ambiguous situation, collaborative response tasks are usually distributed equally without considering the differences in risk status among members. This results in high-risk members being overburdened and further worsening their own situation, while the resources and capabilities of low-risk members are not fully utilized.
[0004] Therefore, there is an urgent need for a collaborative defense scheme generation method that can take into account privacy protection, automated threat correlation, quantitative assessment of member status, risk propagation prediction, and differentiated task allocation. Summary of the Invention
[0005] To overcome the shortcomings of existing technologies, this application provides an industry security joint defense method based on federated game theory, which aims to solve the problems of difficulty in identifying cross-organizational threats, lack of quantitative assessment of risks in member cooperation, unpredictable risk propagation trends, and unreasonable allocation of collaborative tasks in existing technologies.
[0006] To achieve the above objectives, this application adopts the following technical solution:
[0007] Firstly, this application provides an industry-wide security joint defense method based on federated game theory, comprising the following steps:
[0008] S1. Collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported by each joint defense member to the joint defense coordination center;
[0009] S2. Perform cross-organizational correlation analysis on the threat alarm log data reported by each joint defense member to identify early threat signals that are spreading among multiple organizations, thereby quantifying the comprehensive threat pressure value of each joint defense member.
[0010] S3. Based on the resource usage index data and behavior-related index data of each joint defense member, analyze the operational status of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member.
[0011] S4. Based on the cooperation risk and trust data among the members of each joint defense team, deduce the evolution process of risk spreading from individual members to the overall joint defense network, and output the evolved cooperation risk value of each member of the joint defense team.
[0012] S5. Based on the evolved cooperative risk value of each joint defense member, solve the collaborative tasks that each joint defense member should undertake and the corresponding incentive and constraint schemes, and generate a collaborative defense scheme for the overall security joint defense of the industry.
[0013] According to the above technical solution, the steps for collecting threat alert log data, resource usage index data, behavior-related index data, and trust data among members reported to the joint defense coordination center by each joint defense member include:
[0014] Step S11: Each joint defense member encrypts and uploads the threat alarm log data to the joint defense coordination center, which then decrypts the data and extracts the relevant fields of the threat alarm.
[0015] Step S12: Each joint defense member collects and encrypts the resource usage index data and uploads it. The joint defense coordination center decrypts the data and extracts the resource index of each joint defense member.
[0016] Step S13: Each joint defense member collects behavioral-related indicator data, encrypts and uploads it, and the joint defense coordination center decrypts it to extract the corresponding behavioral indicators of each member.
[0017] Step S14: The joint defense coordination center also counts the historical interaction records of each pair of members from the member interaction database it maintains, and calculates the trust data between members accordingly.
[0018] Based on the above technical solution, the steps for performing cross-organizational correlation analysis on the threat alert log data reported by each joint defense member, identifying early threat signals spreading across multiple organizations, and thus quantifying the comprehensive threat pressure value of each joint defense member include:
[0019] Step S21: Based on the threat alarm log data reported by each joint defense member, construct a bipartite graph with members and threat indicators as nodes, and filter out threat indicator nodes that are connected to at least two member nodes as candidate seed nodes for cross-organizational diffusion; for each candidate seed node, calculate the degree of association between it and other threat indicator nodes through mutual information, and determine the association threshold using the natural breakpoint method. Based on this, threat indicator nodes with mutual information exceeding the threshold are merged into the same threat. After a threat type consistency check, output cross-organizational similarity abnormal threat clusters.
[0020] Step S22: For each cross-organizational similarity anomalous threat cluster, obtain the first detection time, number of detections, and median confidence level of each member for that threat cluster. Based on this, calculate the exposure duration pressure component, activity pressure component, and confidence pressure component of each member, aggregate them into the pressure value of that threat cluster for that member, and then merge the pressure values of all threat clusters faced by each member to obtain the comprehensive threat pressure value of each member.
[0021] According to the above technical solution, the steps to analyze the operational status of each joint defense member based on their resource usage and behavior-related data, and then combine this with the comprehensive threat pressure value of each member to obtain the cooperation risk value of each member include:
[0022] Step S31: Extract member CPU utilization, member memory utilization, member network bandwidth utilization, and member storage remaining rate from the resource usage index data of each joint defense member to form a resource stress vector. Calculate the weight of each resource index using the vertical and horizontal grading method, and calculate the weighted Euclidean distance between each member's resource stress vector and the ideal state vector to obtain the resource stress value of each member.
[0023] Step S32: Extract real-time values of member network traffic rate, number of member outbound connection attempts, and member non-working time activity duration from the behavior-related indicator data of each joint defense member to form a real-time behavior feature vector. Obtain the normal behavior baseline vector of each member from S1, calculate the Mahalanobis distance between the two vectors, and convert it to obtain the behavior abnormality value of each member.
[0024] Step S33: Analyze the relationship between the comprehensive threat pressure value, resource stress value and behavioral abnormality value of each member, and calculate the cooperation risk value of each member.
[0025] Based on the above technical solution, and using the cooperation risks and trust data among the members of the joint defense network, the steps for deduce the evolution of risk from individual members to the overall joint defense network, and output the evolved cooperation risk value of each member, include:
[0026] Step S41: Extract the directed trust matrix from the trust data among the joint defense members. For each target member, calculate the probability of risk propagating from each source member to the target member based on the trust ratio of each source member to that target member. After aggregation, obtain the risk propagation probability matrix.
[0027] Step S42: Take the cooperation risk value of each member as the initial risk value, and combine it with the risk propagation probability matrix. Use an iterative algorithm to simulate the propagation process of risk in the trust network. In each iteration, the risk value of each member is obtained by weighted summation of its own original risk value and the propagation risk value received from other members. After iterating to the maximum number of iterations, output the evolved cooperation risk value of each member.
[0028] Based on the above technical solution, and according to the evolved cooperative risk value of each joint defense member, the steps to solve for the collaborative tasks that each joint defense member should undertake and the corresponding incentive and constraint schemes, and to generate a collaborative defense scheme for the overall industry security joint defense, include:
[0029] Step S51: Based on the evolved cooperation risk value of each joint defense member, calculate the task undertaking ratio of each member;
[0030] Step S52: Based on the task assignment ratio of each member, generate the collaborative tasks that each member should undertake and the corresponding incentive and constraint schemes, and generate a collaborative defense scheme for the overall security joint defense of the industry.
[0031] Secondly, this application also provides an industry security joint defense system based on federated game theory, including:
[0032] The data acquisition module is used to collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported to the joint defense coordination center by each joint defense member;
[0033] The threat analysis module is used to perform cross-organizational correlation analysis on the threat alert log data reported by each joint defense member, identify early threat signals that are spreading across multiple organizations, and thus quantify the comprehensive threat pressure value of each joint defense member.
[0034] The risk assessment module is used to analyze the operational status of each joint defense member based on the resource usage index data and behavior-related index data of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member.
[0035] The risk simulation module is used to simulate the evolution of risk from individual members to the overall joint defense network based on the cooperation risk of each joint defense member and the trust data between members, and outputs the evolved cooperation risk value of each joint defense member.
[0036] The scheme generation module is used to solve the collaborative tasks that each member should undertake and the corresponding incentive and constraint schemes based on the evolved collaborative risk values of each member, and generate a collaborative defense scheme for the overall security joint defense of the industry.
[0037] Thirdly, this application provides an electronic device comprising a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes an industry security joint defense method based on federated game theory by calling the computer program stored in the memory.
[0038] Fourthly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform an industry security joint defense method based on federated game theory.
[0039] Compared with the prior art, this application has the following advantages and beneficial effects:
[0040] This application establishes a complete method for generating collaborative defense solutions for industry security through a series of means, including encrypted transmission, cross-organizational threat correlation analysis, quantitative assessment of member status, risk propagation prediction, and differentiated task allocation. Furthermore, the entire process is data-driven, eliminating the need for manually preset weights and thresholds. This addresses the pain point of members being unwilling to share data due to privacy concerns, while automatically identifying cross-organizational threats in the early stages of threat spread. It also achieves objective quantification of member cooperation risks, accurate prediction of risk propagation trends, and reasonable allocation of collaborative tasks, thereby comprehensively improving the intelligence level and overall defense effectiveness of the industry collaborative defense system. Attached Figure Description
[0041] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0042] Figure 1 This is an overall flowchart of the industry security joint defense method based on federated game theory provided in the embodiments of this application;
[0043] Figure 2 This is a data acquisition flowchart provided in an embodiment of this application;
[0044] Figure 3 This is a flowchart illustrating the quantification of threat and pressure levels provided in an embodiment of this application;
[0045] Figure 4 This is a flowchart of the risk level output for joint defense members provided in an embodiment of this application;
[0046] Figure 5 This is a flowchart of the evolved cooperation risk value output provided in the embodiments of this application;
[0047] Figure 6 This is a flowchart illustrating the collaborative defense scheme generation process provided in this application embodiment. Detailed Implementation
[0048] The technical solution of this application will be further described in detail below with reference to the accompanying drawings and specific embodiments, so as to enable those skilled in the art to understand and implement it; it should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0049] Please see Figure 1 , Figure 1 This is an overall flowchart of the industry security joint defense method based on federated game theory provided in this application embodiment, which specifically includes the following steps:
[0050] S1. Collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported to the joint defense coordination center by each joint defense member.
[0051] Please see Figure 2 , Figure 2 The complete technical process for data acquisition in the embodiments of this application is illustrated, and the specific steps are as follows:
[0052] Step S11: Each joint defense member encrypts and uploads the threat alert log data to the joint defense coordination center, which then decrypts the data and extracts the relevant fields of the threat alert; specifically:
[0053] Each member of the joint defense team obtains threat alert log data in real time from their respective deployed intrusion detection systems via API interfaces, encrypts and uploads it to the joint defense coordination center; the joint defense coordination center decrypts the data using the private keys corresponding to each member and extracts the following fields from each alert log: threat indicator value, threat type, first detection time, number of detections, confidence level, and member identifier;
[0054] The threat indicator value is a string directly read from the threat feature field of the threat alert log, including three types: malicious domain name, malicious IP address, and file hash value; the threat type is an enumerated value directly read from the category label field of the alert log, including four categories: ransomware, DDoS attack, phishing attack, and APT attack; the first probe time is the timestamp of the first time the member-end detection system records the threat indicator, directly read from the timestamp field of the alert log; the number of probes is the cumulative number of times the member-end detection system records the threat indicator within the current time window, calculated by the internal counter of the detection system; the confidence score is the reliability score of the alert by the member-end detection system, ranging from 0 to 1, output by the internal algorithm of the detection system; the member identifier is the unique number of the member who reported the alert, directly read from the member identifier field of the alert log;
[0055] Step S12: Each joint defense member collects and encrypts resource usage index data, then uploads it. The joint defense coordination center decrypts the data and extracts the resource indicators for each member. Specifically:
[0056] Each member of the joint defense team collects resource usage data in real time from their respective operating systems via API interfaces, encrypts and uploads it to the joint defense coordination center; the joint defense coordination center decrypts the data using the private key corresponding to each member and extracts the following indicators: member CPU usage, member memory usage, member network bandwidth utilization, member storage remaining rate, as well as the corresponding collection timestamp and member identifier.
[0057] Member CPU utilization is obtained by reading the CPU usage percentage from the member's operating system process scheduler and dividing it by 100, with a value ranging from 0 to 1; member memory utilization is obtained by reading the physical memory usage percentage from the member's operating system memory manager and dividing it by 100, with a value ranging from 0 to 1; member network bandwidth utilization is obtained by reading the current bandwidth usage from the member server's network interface and dividing it by the maximum bandwidth of the interface, with a value ranging from 0 to 1; member storage availability is obtained by reading the remaining space from the member server's disk space and dividing it by the total space, with a value ranging from 0 to 1; the collection timestamp is read from the operating system clock, and the member identifier is read from the member configuration file;
[0058] Step S13: Each joint defense member collects relevant behavioral indicator data, encrypts and uploads it, and the joint defense coordination center decrypts it to extract the corresponding behavioral indicators for each member; specifically:
[0059] Each member of the joint defense team collects real-time and past data on behavior indicators that have not been affected by threats from their respective network gateways and host operating systems via API interfaces, and uploads the data in encryption to the joint defense coordination center. The joint defense coordination center decrypts the data using the private keys of each member and extracts the following indicators: member network traffic rate, number of outbound connection attempts, duration of member activity outside of working hours, and the corresponding collection timestamp and member identifier.
[0060] The member network traffic rate is obtained by reading the traffic statistics interface of the member network gateway, summing the inbound and outbound traffic rates at the current moment; the number of member outbound connection attempts is obtained by reading the member network connection log, counting the total number of times all hosts within the member network initiate connections to external addresses within a unit of time, where the external address is an address whose destination IP is not within the member's internal network segment; the member's non-working time activity duration is obtained by reading the operating system logs of each member host, counting the timestamps of process startup events during the non-working time period, calculating the cumulative active duration, and then summing the active durations of all hosts within each member, where the non-working time period is defined as 0:00 to 6:00 AM;
[0061] In addition, for each member, the Joint Prevention and Coordination Center organizes the behavioral-related indicator data of those who have not been threatened in the past period into a behavioral feature vector sequence in chronological order. The time span of this data is preferably the past 30 days. The mean vector and covariance matrix of this sequence in the past 30 days are calculated as statistical parameters of the member's normal behavioral baseline vector.
[0062] Step S14: The joint defense coordination center also retrieves historical interaction records for each pair of members from its maintained member interaction database, and calculates trust data between members accordingly; specifically:
[0063] The Joint Prevention and Coordination Center collects historical interaction records for each pair of members from its maintained member interaction database, calculates the trust level of each source member to each target member, and then organizes all the trust levels into a directed trust matrix by rows and columns to obtain the trust data between members.
[0064] For source member p and target member q, the Joint Defense Coordination Center calculates the following four indicators: the target member q's past performance rate in completing joint defense tasks (the ratio of the number of tasks actually completed by member q to the number of assigned tasks); the accuracy rate of threat intelligence reported by target member q (the ratio of the number of threat indicators reported by member q that have been verified as real threats by the Joint Defense Coordination Center to the total number of reported threats); the pairwise cooperation factor between source member p and target member q (the cumulative number of times both parties have jointly participated in joint defense tasks to the maximum pairwise cooperation factor among all member pairs); and the timeliness rate of target member q's response to joint defense instructions (the ratio of the number of instructions responded to by member q within the specified time to the total number of instructions received). It should be noted that trust level... This represents the degree of trust that source member p has in target member q. Therefore, apart from the pairwise cooperation factor, the other three indicators describe the performance of target member q. The joint prevention and control coordination center sums the four indicators and divides by 4 to obtain the degree of trust that source member p has in target member q. The value ranges from 0 to 1; similarly, the trust level is calculated. At that time, the fulfillment rate, accuracy rate, and timeliness rate of the four indicators should be replaced with the values corresponding to the source member q and the target member p, while the pairwise cooperation factor remains unchanged; the joint prevention and control coordination center repeats the above calculation for all members and obtains the trust level. As the element in the p-th row and q-th column of the matrix, the directed trust matrix is constructed.
[0065] The data acquisition process in this embodiment combines encrypted uploading and private key decryption to ensure the privacy and security of data reported by each joint defense member during transmission, avoiding the risk of sensitive information leakage. At the same time, by collecting threat alarm logs, resource usage indicators, behavior-related indicators, and trust data between members from multiple data sources such as intrusion detection systems, operating systems, and network gateways, a complete data foundation is provided for subsequent threat analysis, risk assessment, and risk simulation.
[0066] S2. Perform cross-organizational correlation analysis on the threat alert log data reported by each joint defense member to identify early threat signals that are spreading across multiple organizations, thereby quantifying the comprehensive threat pressure value of each joint defense member.
[0067] Please see Figure 3 , Figure 3 This is a flowchart for quantifying the degree of threat pressure provided in an embodiment of this application. The specific steps are as follows:
[0068] Step S21: Based on the threat alert log data reported by each joint defense member, construct a bipartite graph with members and threat indicators as nodes, and filter out threat indicator nodes that are connected to at least two member nodes as candidate seed nodes for cross-organizational diffusion; for each candidate seed node, calculate the degree of association between it and other threat indicator nodes through mutual information, and determine the association threshold using the natural breakpoint method. Based on this, threat indicator nodes whose mutual information exceeds the threshold are merged into the same threat. After a threat type consistency check, output the cross-organizational similarity abnormal threat cluster; the specific analysis process is as follows:
[0069] First, from the threat alert log data reported by each joint defense member, read the threat indicator value, threat type, first detection time, and member identifier of each record; treat each member as a node and each threat indicator as a node. If a member reports a threat indicator, establish an edge between the corresponding member node and the threat indicator node; at the same time, record the threat type of the threat indicator on the threat indicator node, and record the first detection time of the member reporting the threat indicator on the edge.
[0070] Secondly, traverse all threat indicator nodes and count the number of member nodes connected to each threat indicator node. Since the initial criterion for cross-organizational diffusion is that the same threat is observed by multiple members, threat indicator nodes connected to at least two member nodes are marked as candidate seed nodes for cross-organizational diffusion. Considering that mutual information is a measure of the degree of interdependence between two random variables in information theory, and a larger value indicates a stronger correlation between the two variables, calculate the mutual information value between each candidate seed node for cross-organizational diffusion and all other threat indicator nodes in the bipartite graph: ; In the formula, The mutual information value between two threat indicator nodes, in bits, represents the similarity in the member distribution of the two threat indicators. The larger the value, the higher the probability that they point to the same threat. The set of member nodes connected to the current cross-organizational diffusion candidate seed node represents which joint defense members have observed the threat indicator; The set of member nodes connected to another threat indicator node represents which members of the joint defense team observed the other threat indicator; For set The size of this is dimensionless, representing the number of members observed in the current threat indicator; For set The size of the indicator is dimensionless, representing the number of members who observed another threat indicator. for , The size of the intersection of two sets, dimensionless, is the number of members who simultaneously observe both threat indicators; The total number of all member nodes, dimensionless, that is, the total number of members in the joint defense alliance;
[0071] In industry-wide security collaboration scenarios, the same threat may manifest as multiple different threat indicators. For example, an APT group controls a malicious domain name evil.com and a C2 server 185.130.5.253, which resolves to this IP address. When this threat operates in the network environments of multiple members, member A may observe both evil.com and 185.130.5.253, member B may only observe evil.com, and member C may only observe 185.130.5.253. Although the indicators observed by different members are not exactly the same, these two indicators will exhibit a co-occurrence characteristic in the member distribution: that is, a member who observes one indicator will often also observe the other indicator, or at least the member sets corresponding to these two indicators will have significant overlap.
[0072] In order to automatically discover such co-occurrence relationships from the data, this embodiment designs the above mutual information formula to measure the similarity between two threat indicators in the distribution of observed members: Calculate the joint probability that two threat indicators are observed by the same member. Calculate the marginal probabilities of each of the two threat indicators being observed, logarithmic part. The result is calculated in bits with a base of 2, and is used to quantify the ratio of the actual co-occurrence probability to the expected co-occurrence probability when the two are assumed to be independent. This is because when the natural breakpoint method is used to determine the association threshold, it only depends on the relative size of the mutual information values. The choice of the base does not affect the determination of the threshold. Using a base of 2 is only for ease of calculation. In general, when two threat indicators tend to appear in the same membership set, the mutual information value is positive and large, indicating that they are more likely to point to the same threat. When the two are independent, the mutual information value approaches 0, indicating that they are less likely to point to the same threat.
[0073] Based on the above mutual information formula, calculate the mutual information value between each cross-organization diffusion candidate seed node and each other threat indicator node in the bipartite graph to obtain a set of mutual information values.
[0074] To automatically find a reasonable association threshold from the data, the natural breakpoint method is used to segment the mutual information values. Since this step only needs to distinguish between associated and unassociated states, the mutual information values are divided into two categories: high association and low association. Specifically: First, the mutual information values are sorted in ascending order. Assuming there are M mutual information values, there are M-1 possible split positions between two adjacent values. For each split position, the value to the left of the position is classified as the low association class, and the value to the right is classified as the high association class. The intra-class variances of the two classes are calculated and then summed. The split position that minimizes the sum of the intra-class variances is selected as the optimal split point. The minimum value in the high association class is taken as the association threshold. Other threat indicator nodes whose mutual information values exceed the association threshold are considered to point to the same threat as the current cross-organizational diffusion candidate seed node. Other threat indicator nodes whose mutual information values do not exceed the association threshold are considered to be unrelated to the current cross-organizational diffusion candidate seed node.
[0075] Next, for each cross-organizational diffusion candidate seed node, all other threat indicator nodes with mutual information values exceeding the association threshold are collected. These nodes are combined with the seed node to form a threat indicator set. The member nodes connected to all threat indicator nodes in this set are combined to obtain the member set involved in each threat. For each member, the earliest detection time of the member on any threat indicator of the threat is taken as the time when the member first encountered the threat.
[0076] Then, since a specific threat event cannot belong to two different attack types at the same time, check whether the threat types of all threat indicator nodes under each threat are consistent. If the types are inconsistent, the threat is discarded.
[0077] Finally, for each threat that passes the consistency check, the number of members involved is counted. If the number of members is greater than or equal to 2, the threat is marked as a cross-organizational similarity anomalous threat cluster; if the number of members is equal to 1, it means that the threat only appears in a single member and does not have the characteristics of cross-organizational diffusion, so it is excluded.
[0078] Step S22: For each cross-organizational cluster of similar anomalous threats, obtain the first detection time, number of detections, and median confidence level for each member of that threat cluster. Based on this, calculate the exposure duration pressure component, activity pressure component, and confidence pressure component for each member, aggregate them to form the pressure value of that threat cluster for that member, and then merge the pressure values of all threat clusters faced by each member to obtain the comprehensive threat pressure value for each member; the specific steps are as follows:
[0079] First, iterate through each cross-organizational cluster of similar anomalous threats. For the threat cluster currently being processed, read the set of members involved in the threat cluster and the time when each member first detected any threat indicator in the threat cluster. At the same time, obtain the number of times the member detected all threat indicators in the threat cluster from the threat alarm log data reported by each joint defense member, as well as the median confidence level of the member for these detection results.
[0080] Secondly, for each member involved in the current threat cluster, the following three pressure components are calculated sequentially:
[0081] The system time at which S2 begins execution is taken as the current analysis time. The time from the minimum of the first detection times of all members in all threat clusters to the current time is taken as the total duration of the observation window. The time when the member first detected the current threat cluster is subtracted from the current analysis time, and the difference is divided by the total duration of the observation window. The result is the exposure time pressure component of the member.
[0082] The activity stress component of the member is calculated by counting the number of times the member detected all threat indicators within the observation window, and then dividing the number of times the member detected all threat indicators in the current threat cluster by the former.
[0083] The median confidence level of the member for detecting all threat indicators in the current threat cluster is taken as the confidence pressure component of the member.
[0084] In industry-wide security collaboration scenarios, the contributions of exposure duration, activity level, and confidence level to the final stress value are interdependent. If any one of these dimensions is too low, it means that the actual stress of the threat on the member may not be that great. For example, even if a threat has been exposed for a long time and appears frequently, if the confidence level given by the member is very low, it is likely just a false alarm and should not be given a high stress score. In order to capture this weak link effect, we need to use an aggregation method that is sensitive to low values, so that a low value in any dimension can lower the final result. Geometric mean has this characteristic. Therefore, we multiply the exposure duration stress component, activity stress component, and confidence stress component of each member and then take the cube root to obtain the stress value of the current threat cluster on each member.
[0085] Once all members in a threat cluster have completed the above calculations, the process continues with the next threat cluster until all threat clusters have been processed.
[0086] Finally, for each member, the stress values of all cross-organizational similar anomalous threat clusters corresponding to that member are added together, and then divided by the total number of cross-organizational similar anomalous threat clusters to obtain the member's overall threat stress value.
[0087] The threat pressure quantification process in this embodiment can identify threat clusters that simultaneously affect multiple members in the early stages of threat spread, providing early warning time for subsequent collaborative risk assessment. At the same time, by comprehensively evaluating three dimensions—exposure duration, activity level, and confidence level—it avoids misjudgments caused by inflated values in a single dimension, making the pressure quantification results closer to the actual security situation.
[0088] S3. Based on the resource usage index data and behavior-related index data of each joint defense member, analyze the operational status of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member.
[0089] Please see Figure 4 , Figure 4 This is a flowchart of the risk level output for joint defense members provided in an embodiment of this application. The specific steps are as follows:
[0090] Step S31: Extract member CPU utilization, member memory utilization, member network bandwidth utilization, and member storage remaining rate from the resource usage index data of each joint defense member to form a resource stress vector. Calculate the weight of each resource index using a tiered approach, and calculate the weighted Euclidean distance between each member's resource stress vector and the ideal state vector to obtain the resource stress value for each member. Specific steps are as follows:
[0091] First, from the resource usage data reported by each joint defense member, four resource indicators were extracted for each member: member CPU utilization, member memory utilization, member network bandwidth utilization, and member storage remaining rate. Since member CPU utilization, member memory utilization, and member network bandwidth utilization represent the degree of resource consumption, the higher the value, the more strained the resources are. However, member storage remaining rate represents the degree of resource surplus, and the higher the value, the more abundant the resources are. The four indicators have different directions. In order to unify the evaluation direction and make all indicators indicate that the higher the value, the more strained the resources are, the member storage remaining rate was converted into member storage utilization rate by subtracting the original value from 1. The higher the value of the converted value, the more strained the storage is. The member storage utilization rate and the original three indicators together constitute a four-dimensional resource stress vector for each member, with each dimension ranging from 0 to 1.
[0092] Secondly, in industry-wide security joint defense scenarios, different resource indicators have varying degrees of impact on members' joint defense participation capabilities, and this impact varies with the type and duration of the joint defense task. The tiered approach, however, determines weights by utilizing the degree of data variation across time and member dimensions for each indicator. Driven entirely by the distribution characteristics of the data itself, it is suitable for the dynamic changes in resource status among different members at different times in joint defense scenarios. Therefore, this method is used to automatically calculate the weights of each resource indicator from the data; specifically…
[0093] The current calculation window is defined as a 30-day time interval prior to the system time starting from S2. Within this window, each member has resource usage data from multiple sampling points. Assuming there are N members in the current calculation window, and each member has sampling data from T time points, with each sampling point containing four resource metrics: member CPU utilization, member memory utilization, member network bandwidth utilization, and member storage utilization, the data is organized into a three-dimensional structure. ,in Indicates the member sequence number. Indicates the index number. Representing the time sequence number, construct a 4x4 total covariance matrix. ,in For the first A matrix of indicator values for all members at each time point, with dimension 1. Solve for the total covariance matrix. Maximum eigenvalue and its corresponding eigenvectors The specific solution method is as follows: use the power iteration method to randomly initialize a non-zero vector. Iterative calculation Considering that the power iteration of a 4×4 matrix usually converges within tens of steps, the maximum number of iterations is set to 100. Iteration stops when the maximum number of iterations is reached, and the convergence time is... That is, the eigenvector corresponding to the largest eigenvalue. Corresponding The eigenvectors obtained by solving Its four components correspond to the weight coefficients of member CPU utilization, member memory utilization, member network bandwidth utilization and member storage utilization, respectively, and the sum of these four weight coefficients is 1;
[0094] Then, after obtaining the weight coefficients, they are substituted into the weighted Euclidean distance formula to calculate the distance between each member's resource stress vector and the ideal state vector; where a vector with all four dimensions equal to 0 is used as the ideal state vector, representing the ideal state where all resources are completely idle; the calculation formula is: ; In the formula, The weighted Euclidean distance between the member's resource status and the ideal state is dimensionless and ranges from 0 to positive infinity. The smaller the distance, the less strained the resources are. For the first The weighting coefficients of each resource indicator are dimensionless. For members in the The stress value for each resource indicator is dimensionless.
[0095] Finally, since the range of the weighted Euclidean distance depends on the resource status distribution of each member and the upper limit cannot be determined in advance, a proportional function is used to compress the weighted Euclidean distance to the interval between 0 and 1. That is, the weighted Euclidean distance is divided by one and then added to obtain the resource stress value of each member. When the resource status is exactly the same as the ideal state, the weighted distance is 0 and the resource stress value is 0. When the difference between the resource status and the ideal state is greater, the weighted distance is larger and the resource stress value is closer to 1.
[0096] For example, if a member's current CPU utilization is 0.8, memory utilization is 0.6, network bandwidth utilization is 0.5, and storage utilization is 0.2, then the member's resource stress vector is (0.8, 0.6, 0.5, 0.2). Using a tiered approach, the weights of the four resource indicators are calculated to be 0.4, 0.3, 0.2, and 0.1, respectively. The distance between this member and the ideal state vector (0, 0, 0, 0) is calculated using the weighted Euclidean distance formula: the contribution from the CPU utilization dimension is 0.4 × (0.8 - 0)² = 0.4 × 0.64 = 0.256, and the contribution from the memory utilization dimension is 0.3 × (0.6 - 0)² = 0.3 × 0.36 = 0.10. 8. The contribution of the member network bandwidth utilization dimension is 0.2×(0.5-0)²=0.2×0.25=0.05, and the contribution of the member storage utilization dimension is 0.1×(0.2-0)²=0.1×0.04=0.004. The sum of the four terms is 0.418. After taking the square root, the weighted Euclidean distance is approximately 0.646. Substituting this distance into the proportional function, the resource stress value of this member is approximately 0.646 / (1+0.646)≈0.392.
[0097] Step S32: Extract real-time values of member network traffic rate, number of outbound connection attempts, and duration of non-working activity from the behavior-related indicator data of each joint defense member to form a real-time behavior feature vector. Obtain the normal behavior baseline vector for each member from S1, calculate the Mahalanobis distance between the two vectors, and convert them to obtain the behavior anomaly value for each member. The specific steps are as follows:
[0098] First, calculate the Mahalanobis distance between the current real-time behavior feature vector and the normal behavior baseline vector: ; In the formula, The Mahalanobis distance is dimensionless and ranges from 0 to positive infinity. The larger the distance, the greater the deviation of the current behavior from the normal pattern. This represents the real-time behavioral feature vector at the current moment. This is the baseline vector for normal behavior; This is the transpose operator for vectors, used to convert column vectors into row vectors for matrix multiplication. The covariance matrix of the baseline vector of normal behavior is calculated in step S13; This is the inverse of the covariance matrix;
[0099] In industry-wide security collaboration scenarios, different behavioral indicators may be correlated. For example, an increase in the number of outbound connection attempts by a member is often accompanied by an increase in the member's network traffic rate. Mahalanobis distance can decorrelate and normalize the scale of each dimension through the inverse of the covariance matrix, which not only eliminates the influence of correlation between indicators but also makes the distance calculation more accurate. When a member's real-time behavior is completely consistent with the normal behavior baseline, the Mahalanobis distance approaches 0. As a member's real-time behavior gradually deviates from the normal behavior baseline, the Mahalanobis distance increases accordingly. This monotonically increasing relationship meets the assessment requirement of "the greater the deviation, the higher the abnormality" in behavior anomaly assessment.
[0100] Finally, since Mahalanobis distance is positively correlated with the degree of behavioral abnormality, and the abnormality increases rapidly when the deviation is small, while the rate at which the abnormality approaches 1 gradually slows down when the deviation is large, the complement of the exponential decay function is used for mapping. That is, the behavioral abnormality value of each member is equal to the negative Mahalanobis distance raised to the power of one minus the natural constant. When the real-time behavior of the joint defense members is completely consistent with the normal behavior baseline, the Mahalanobis distance is 0, and the behavioral abnormality value is 0. When the real-time behavior deviates from the normal behavior baseline, the Mahalanobis distance increases, and the behavioral abnormality value increases exponentially and approaches 1. The larger the behavioral abnormality value, the more abnormal the member's behavior, and the higher the risk of cooperation.
[0101] For example, the baseline mean of a member's behavior characteristics under normal conditions is: member network traffic rate 0.2, member outbound connection attempts 0.1, and member non-working time activity duration 0.15. The real-time behavior characteristic vector collected at the current moment is: member network traffic rate 0.7, member outbound connection attempts 0.5, and member non-working time activity duration 0.4. Substituting the difference vector between the real-time vector and the baseline mean into the Mahalanobis distance formula, and combining it with the inverse of the covariance matrix, the Mahalanobis distance is approximately 2.3. Substituting this Mahalanobis distance into the complement of the exponential decay function, the abnormality value of this member's behavior is approximately 1- ≈0.9;
[0102] Step S33: Analyze the relationship between the comprehensive threat pressure value, resource stress value, and behavioral abnormality value of each member, and calculate the cooperation risk value of each member: ; In the formula, This is the cooperation risk value for members, which is dimensionless and ranges from 0 to 1. The larger the value, the higher the cooperation risk for that member in industry security joint defense. This represents the resource scarcity level of a member, a dimensionless value ranging from 0 to 1. A higher value indicates a more severe resource scarcity for the member. This is the abnormality score of a member's behavior. It is dimensionless and ranges from 0 to 1. The larger the value, the more abnormal the member's behavior. This represents the overall threat pressure value of a member, which is dimensionless and ranges from 0 to 1. The larger the value, the greater the external threat pressure the member experiences.
[0103] In industry-wide security collaboration scenarios, the risks of cooperation among members are jointly determined by the internal basic status and external threat pressure. Therefore, it is necessary to couple three dimensions: resource stress, abnormal behavior, and overall threat pressure. Among these, resource stress... and behavioral abnormality This reflects the individual's vulnerability level; multiplying the two yields the basic risk factor. This is because deterioration in any dimension will lead to a decline in the member's baseline state, and the two have a synergistic effect of amplification; in order to convert the baseline state into a level of health, the baseline risk factor is subtracted from 1 to obtain the base. The higher this value, the better the basic condition of the members; at the same time, the overall threat pressure value This reflects the impact of external attacks on members; adding 1 to it serves as the exponent. Thus, as the threat pressure increases, the exponent also increases, and the aggravating effect intensifies. Furthermore, by combining the base and exponent through exponentiation, when the base is less than 1 and the exponent is greater than 1, the result of the exponentiation decreases as the exponent increases. Therefore, subtracting this result from 1 yields the cooperation risk value. It increases with increasing threat pressure, thus accurately depicting the exacerbating effect of external threats on internal vulnerability; while when the member's resource stress value... And the abnormality score At that time, the member's base state reaches perfection, and the base number is... Regardless of the index Regardless of the value chosen, the result of the exponentiation is always 1, therefore the cooperation risk value is... This is because members in a perfect basic state possess complete self-healing and defense capabilities, and their own operational status and joint defense participation capabilities are not affected by external threats.
[0104] The risk level output process for joint defense members in this embodiment evaluates the external threat pressure in conjunction with the member's own resource status and behavioral characteristics. This objectively reflects the true level of cooperation risk for each member in the joint defense system. Furthermore, it considers both the intensity of external shocks and the degree of internal vulnerability, thus avoiding misjudging a member's willingness to cooperate due to their own resource constraints or abnormal behavior, or underestimating their risk exposure by ignoring external threats.
[0105] S4. Based on the cooperation risk and trust data among the members of each joint defense team, deduce the evolution process of risk spreading from individual members to the overall joint defense network, and output the evolved cooperation risk value of each member of the joint defense team.
[0106] Please see Figure 5 , Figure 5 This is a flowchart of the evolved cooperation risk value output provided in an embodiment of this application. The specific steps are as follows:
[0107] Step S41: Extract a directed trust matrix from the trust data among the joint defense members. For each target member, calculate the probability of risk propagating from each source member to the target member based on the trust ratio of each source member to that target member. The resulting matrix is the risk propagation probability matrix. The specific steps are as follows:
[0108] First, obtain the directed trust matrix among the members from the trust data among the joint defense members. ,in Indicates source member For target members The level of trust is measured in terms of values ranging from 0 to 1. and All are member serial numbers. , The total number of members of the joint defense team;
[0109] Secondly, each member is considered as a node in the graph, and the pair of members with a trust degree greater than 0 is considered as a directed edge in the graph, with the direction of the edge starting from the source member. Point to target member , indicating source member The risk can propagate along that side to the target member. The weight of that edge is the trust level. ;
[0110] Then, for each target member Calculate all source members against the target member The sum of trust levels will be the source members To target members Dividing the trust level by the total trust level yields the risk from the source member. Spread to target members probability And for each fixed target member All source members The sum of the corresponding propagation probabilities is 1;
[0111] Finally, iterate through all source members. and target members Calculate each ,get Risk propagation probability matrix The first of the matrix The column indicates the risk propagation to the target members. The probability distribution;
[0112] Step S42: Using the cooperation risk value of each member as the initial risk value, and combining it with the risk propagation probability matrix, an iterative algorithm is used to simulate the risk propagation process in the trust network. In each iteration, the risk value of each member is obtained by weighted summation of its own original risk value and the propagated risk values received from other members. After iterating to the maximum number of iterations, the evolved cooperation risk value of each member is output. The specific steps are as follows:
[0113] Considering that in industry security collaboration scenarios, the trust relationships between members constitute a complex directed network, the collaborative risks of a single member will gradually spread to other members along the direction of the trust relationship, and this spread is a multi-hop, gradual process; for example, the risk of member A may first spread to member B, whom it trusts, and then through member B to member C; therefore, in order to simulate the cumulative effect of this multi-hop propagation, an iterative algorithm is needed, in which each iteration corresponds to the risk propagating forward one hop in the network, and after multiple iterations, the risk can propagate to the entire network, thereby obtaining the final risk value of each member after the risk propagation converges;
[0114] First, obtain each member from the output of S3. Cooperation risk value As the initial risk value, where , The total number of members of the joint defense team;
[0115] Secondly, considering that the number of members in a joint defense effort typically does not exceed 100, the maximum path length required for a risk to propagate from any member to the entire network will not exceed the total number of members. Therefore, the maximum number of iterations is set to 100. Simultaneously, based on industry experience in joint security defense, the impact of externally propagated risks on members is usually greater than their original risk; therefore, a risk retention factor is set for each member. The value is set to 0.3 to emphasize the diffusion effect of risk in the trust network, giving externally propagated risk a 70% weight.
[0116] Subsequently, iterative propagation is carried out according to the following steps:
[0117] B1, in the At the start of the next iteration, the current risk value of each member is... For each target member Calculate the sum of risks propagating from all source members to this member, i.e. ,in Risk from the source members Spread to target members The probability of;
[0118] B2. For each member The original risks of retaining itself Combined with the total transmission risk calculated in the previous step Add them together to get the first one. Risk value after the next iteration ;
[0119] B3. Determine if the maximum number of iterations has been reached: If the current iteration count is... If the value has reached 100, then stop iterating and let... Otherwise, return to B1 to continue the next iteration;
[0120] Taking a trust network with 3 members as an example, the initial cooperation risk value obtained from step S3 is =0.8, =0.3, =0.1; From the propagation probability matrix Q obtained in step S41, the probability distribution of propagation to member 1 is: =0.2, =0.5, =0.3, the probability distribution of propagation to member 2 is: =0.4, =0.4, =0.2, the probability distribution of propagation to member 3 is: =0.1, =0.2, =0.7; Set your own risk retention coefficient =0.3, maximum number of iterations =100; The first iteration calculation is as follows: The new risk value for member 1 is 100. =0.443; the new risk value for member 2 is... =0.468; the new risk value for member 3 is... =0.289; After the first iteration, the risk value changed from (0.8, 0.3, 0.1) to (0.443, 0.468, 0.289);
[0121] Finally, repeat the above iterative process until the maximum number of iterations of 100 is reached, and obtain the evolutionary cooperation risk value of each member after convergence.
[0122] The evolved cooperative risk value output process in this embodiment constructs a trust network among joint defense members, quantifies the trust relationships among members into a directed graph, and uses an iterative propagation algorithm to simulate the diffusion process of risk in the network. It can accurately predict the trend and final impact of the high cooperative risk of individual members spreading to the overall joint defense network. It can provide quantitative basis for the joint defense coordination center to identify high-risk propagation sources in advance and formulate targeted risk isolation or trust adjustment strategies.
[0123] S5. Based on the evolved cooperative risk value of each joint defense member, solve the collaborative tasks that each joint defense member should undertake and the corresponding incentive and constraint schemes, and generate a collaborative defense scheme for the overall security joint defense of the industry.
[0124] Please see Figure 6 , Figure 6 This is a flowchart of the collaborative defense scheme generation process provided in this application embodiment. The specific steps are as follows:
[0125] Step S51: Based on the evolved cooperation risk value of each joint defense member, calculate the task-bearing ratio of each member; the specific steps are as follows:
[0126] Subtract the evolved cooperation risk value of each joint defense member from 1 to obtain the cooperation reliability of each member. Add the cooperation reliability of all members to get the total reliability. Divide the cooperation reliability of each member by the total reliability to get the task undertaking ratio of each member.
[0127] Step S52: Based on the task assignment ratio of each member, generate the collaborative tasks that each member should undertake and the corresponding incentive and constraint schemes, and generate a collaborative defense scheme for the overall industry security joint defense; the specific steps are as follows:
[0128] First, obtain the incentive points for each task unit in the joint prevention and control coordination center, and at the same time obtain the credit deduction value for each uncompleted task unit.
[0129] Secondly, obtain the total workload of this collaborative defense mission from the joint defense coordination center. The workload is measured in task units. Multiply the total workload by the task share of each member to obtain the task share that each member should bear.
[0130] Then, incentive points are awarded to each member based on the actual amount of tasks they complete. For members who refuse to take on their assigned tasks, credit points are deducted according to the amount of tasks they refuse. At the same time, their access level to threat intelligence is restricted according to the proportion of refused tasks to their assigned tasks. The higher the proportion of refused tasks, the stricter the access restrictions.
[0131] Finally, the workload of each member and the corresponding incentive and constraint scheme are packaged together to generate a collaborative defense scheme for the overall security joint defense of the industry. This scheme includes a task allocation table for each member, incentive point distribution rules, credit point deduction rules, and access restriction rules.
[0132] The collaborative defense scheme generation process in this embodiment calculates the task-sharing ratio based on the evolved cooperative risk value, thereby realizing the quantitative allocation and automated generation of collaborative defense tasks. This avoids the subjectivity of manually classifying capability levels, ensures the objectivity and interpretability of the generated scheme, and can provide the joint defense coordination center with a directly executable task allocation scheme.
[0133] This application provides an industry security joint defense system based on federated game theory, including:
[0134] The data acquisition module is used to collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported to the joint defense coordination center by each joint defense member;
[0135] The threat analysis module is used to perform cross-organizational correlation analysis on the threat alert log data reported by each joint defense member, identify early threat signals that are spreading across multiple organizations, and thus quantify the comprehensive threat pressure value of each joint defense member.
[0136] The risk assessment module is used to analyze the operational status of each joint defense member based on the resource usage index data and behavior-related index data of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member.
[0137] The risk simulation module is used to simulate the evolution of risk from individual members to the overall joint defense network based on the cooperation risk of each joint defense member and the trust data between members, and outputs the evolved cooperation risk value of each joint defense member.
[0138] The scheme generation module is used to solve the collaborative tasks that each member should undertake and the corresponding incentive and constraint schemes based on the evolved collaborative risk values of each member, and generate a collaborative defense scheme for the overall security joint defense of the industry.
[0139] This application provides an electronic device, including a memory, a processor, and a communication bus; the memory and the processor are connected via the communication bus; the memory stores an industry security joint defense method based on federated game theory, which can be loaded and executed by the processor as provided in the above embodiments.
[0140] The memory can be used to store instructions, programs, code, code sets, or instruction sets; the memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function, and instructions for implementing the industry security joint defense method based on federated game theory provided in the above embodiments, etc.; the data storage area may store data involved in the industry security joint defense method based on federated game theory provided in the above embodiments, etc.
[0141] The processor may include one or more processing cores; the processor executes or runs instructions, programs, code sets or instruction sets stored in memory, calls data stored in memory, and performs various functions and processes data in this application; the processor may be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), controller, microcontroller and microprocessor; it is understood that for different devices, the electronic device used to implement the above processor functions may also be other, and the embodiments of this application do not specifically limit it.
[0142] A communication bus may include a path for transmitting information between the aforementioned components; the communication bus may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc.; the communication bus may be divided into address bus, data bus, control bus, etc.
[0143] This application provides a computer-readable storage medium storing a computer program that can be loaded by a processor and executed as described in the above embodiments, which is an industry security joint defense method based on federated game theory.
[0144] In this embodiment, a computer-readable storage medium can be a tangible device that holds and stores instructions used by an instruction execution device; a computer-readable storage medium can be, but is not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any combination thereof; specifically, a computer-readable storage medium can be a portable computer disk, a hard disk, a USB flash drive, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital multifunction disc (DVD), a memory stick, a floppy disk, an optical disk, a magnetic disk, a mechanical encoding device, or any combination thereof.
[0145] The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0146] The above description is merely a preferred embodiment of this application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of this application is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the foregoing application concept; for example, technical solutions formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions applied in this application.
Claims
1. An industry security joint defense method based on federated game theory, characterized in that, Includes the following steps: S1. Collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported by each joint defense member to the joint defense coordination center; S2. Perform cross-organizational correlation analysis on the threat alarm log data reported by each joint defense member to identify early threat signals that are spreading among multiple organizations, thereby quantifying the comprehensive threat pressure value of each joint defense member. S3. Based on the resource usage index data and behavior-related index data of each joint defense member, analyze the operational status of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member. S4. Based on the cooperation risk and trust data among the members of each joint defense team, deduce the evolution process of risk spreading from individual members to the overall joint defense network, and output the evolved cooperation risk value of each member of the joint defense team. S5. Based on the evolved cooperative risk value of each joint defense member, solve the collaborative tasks that each joint defense member should undertake and the corresponding incentive and constraint schemes, and generate a collaborative defense scheme for the overall security joint defense of the industry.
2. The industry security joint defense method based on federated game theory according to claim 1, characterized in that, The collection of threat alert logs, resource usage metrics, behavior-related metrics, and trust data among members reported to the joint defense coordination center by each joint defense member includes the following specific content: Each member of the joint defense team will encrypt and upload the threat alert log data to the joint defense coordination center, which will then decrypt the data and extract the relevant fields of the threat alert. Each joint defense member collects and encrypts the data on resource usage indicators and uploads it. The joint defense coordination center then decrypts the data and extracts the resource indicators of each joint defense member. Each member of the joint defense team collects behavioral-related indicator data, encrypts and uploads it, and the joint defense coordination center decrypts it to extract the corresponding behavioral indicators for each member. The Joint Prevention and Control Coordination Center also compiles historical interaction records for each pair of members from its maintained member interaction database, and calculates trust data between members accordingly.
3. The industry security joint defense method based on federated game theory according to claim 2, characterized in that, The method involves cross-organizational correlation analysis of threat alert log data reported by each joint defense member to identify early threat signals spreading across multiple organizations, thereby quantifying the comprehensive threat pressure value of each joint defense member. This includes the following specific details: Based on the threat alert log data reported by each joint defense member, a bipartite graph is constructed with members and threat indicators as nodes. Threat indicator nodes that are connected to at least two member nodes are selected as candidate seed nodes for cross-organizational diffusion. For each candidate seed node, the degree of association between it and other threat indicator nodes is calculated through mutual information, and the association threshold is determined by the natural breakpoint method. Based on this, threat indicator nodes with mutual information exceeding the threshold are merged into the same threat. After a threat type consistency check, a cross-organizational similarity abnormal threat cluster is output. For each cross-organizational cluster of similar anomalous threats, the first detection time, number of detections, and median confidence level of each member for that threat cluster are obtained. Based on this, the exposure duration stress component, activity stress component, and confidence stress component of each member are calculated and aggregated to form the stress value of that threat cluster for that member. Then, the stress values of all threat clusters faced by each member are merged to obtain the comprehensive threat stress value of each member.
4. The industry security joint defense method based on federated game theory according to claim 3, characterized in that, Based on the resource usage and behavior-related data of each joint defense member, the operational status of each member is analyzed. Combined with the comprehensive threat pressure value of each member, a cooperation risk value for each member is obtained, including the following specific details: Extract member CPU utilization, member memory utilization, member network bandwidth utilization, and member storage remaining rate from the resource usage index data of each joint defense member to form a resource stress vector. Calculate the weight of each resource index using the vertical and horizontal grading method, and calculate the weighted Euclidean distance between each member's resource stress vector and the ideal state vector to obtain the resource stress value of each member. Real-time values of member network traffic rate, number of member outbound connection attempts, and member non-working time activity duration are extracted from the behavior-related indicator data of each joint defense member to form a real-time behavior feature vector. The normal behavior baseline vector of each member is obtained from S1, the Mahalanobis distance between the two vectors is calculated, and the behavior abnormality value of each member is obtained. By analyzing the relationship between the comprehensive threat pressure value, resource stress value, and behavioral abnormality value of each member, the cooperation risk value of each member can be calculated.
5. The industry security joint defense method based on federated game theory according to claim 4, characterized in that, Based on the cooperation risk and trust data among each joint defense member, the evolution process of risk spreading from individual members to the overall joint defense network is deduced, and the evolved cooperation risk value of each joint defense member is output, including the following specific contents: A directed trust matrix is extracted from the trust data among the joint defense members. For each target member, the probability of risk propagating from each source member to the target member is calculated based on the trust ratio of each source member to that target member. The resulting matrix is then used to obtain the risk propagation probability matrix. Using the cooperation risk value of each member as the initial risk value, combined with the risk propagation probability matrix, an iterative algorithm is used to simulate the propagation process of risk in the trust network. In each iteration, the risk value of each member is obtained by weighted summation of its own original risk value and the propagation risk value received from other members. After iterating to the maximum number of iterations, the evolved cooperation risk value of each member is output.
6. The industry security joint defense method based on federated game theory according to claim 5, characterized in that, Based on the evolved cooperative risk values of each joint defense member, the collaborative tasks and corresponding incentive and constraint schemes that each member should undertake are solved to generate a collaborative defense scheme for the overall security joint defense of the industry, including the following specific contents: Based on the evolved cooperation risk value of each joint defense member, the task undertaking ratio of each member is calculated; Based on the task responsibilities of each member, the collaborative tasks to be undertaken by each member and the corresponding incentive and constraint schemes are generated, thus generating a collaborative defense scheme for the overall security joint defense of the industry.
7. An industry security joint defense system based on federated game theory, implemented based on the industry security joint defense method based on federated game theory as described in any one of claims 1-6, characterized in that, The system includes: The data acquisition module is used to collect threat alarm log data, resource usage index data, behavior-related index data, and trust data between members reported to the joint defense coordination center by each joint defense member; The threat analysis module is used to perform cross-organizational correlation analysis on the threat alert log data reported by each joint defense member, identify early threat signals that are spreading across multiple organizations, and thus quantify the comprehensive threat pressure value of each joint defense member. The risk assessment module is used to analyze the operational status of each joint defense member based on the resource usage index data and behavior-related index data of each joint defense member, and then combine the comprehensive threat pressure value of each joint defense member to obtain the cooperation risk value of each joint defense member. The risk simulation module is used to simulate the evolution of risk from individual members to the overall joint defense network based on the cooperation risk and trust data between members, and outputs the evolved cooperation risk value of each joint defense member. The scheme generation module is used to solve the collaborative tasks that each member should undertake and the corresponding incentive and constraint schemes based on the evolved collaborative risk values of each member, and generate a collaborative defense scheme for the overall security joint defense of the industry.
8. An electronic device comprising a processor and a memory, characterized in that, The memory stores a computer program that can be called by the processor; the processor executes the industry security joint defense method based on federated game as described in any one of claims 1-6 by calling the computer program stored in the memory.
9. A computer-readable storage medium storing instructions, characterized in that, When the instructions are executed on a computer, the computer performs the industry security joint defense method based on federated game theory as described in any one of claims 1-6.