Dynamic Defense Decision-making Method and System for Complex Networks Based on Attack-Defense Game
By building a differential game model for offensive and defensive forces for complex networks and combining saddle point equilibrium strategy, the problem of insufficient applicability of existing defense methods in complex networks is solved, real-time global optimal defense decisions are achieved, and defense efficiency is improved.
Patent Information
- Application Number
- CN202210991886.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-17
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-08-17
AI Technical Summary
The existing defense methods fail to effectively deal with the dynamic and high adversariality of offensive and defensive behavior in complex networks, resulting in limited targetedness and effectiveness of defense strategies, and the existing game theory-based defense strategies are insufficiently applicable in actual complex networks.
Combining the structural characteristics of complex networks and potential differential game theory, a differential game model for network offensive and defense is constructed, and the global optimal defense decision is obtained through saddle point equilibrium strategy, and the security state transfer differential equation of network nodes is used to analyze offensive and defense confrontation, quantify the benefits of both offensive and defense to solve the optimal strategy.
It realizes real-time and global optimal defense decisions in complex networks, improves defense efficiency, adapts to the structural characteristics of different types of complex networks, and improves the applicability and effectiveness of defense strategies.
Smart Images

Figure CN115314316B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to a complex network dynamic defense decision-making method and system based on attack and defense game. Background Art
[0002] With the development of information technology, the internet has become an essential part of modern society, profoundly impacting people's lifestyles. At the same time, network security issues continue to emerge. The secure operation of networks is crucial to the normal functioning of society. Effectively defending against cyberattacks and improving network security and stability have become urgent priorities. Real networks, such as the Internet, the World Wide Web, and telecommunications networks, have numerous nodes and complex structures, with significant heterogeneity between nodes. Most nodes maintain connections only with central nodes and have few connections themselves. A small number of central nodes, however, dominate the network, commanding a high position and greater influence. Defense methods must adapt to the structural characteristics of complex networks. Currently, key approaches include node immunization strategies and network structure adjustments.
[0003] In terms of node immunization strategies, some have used targeted immunization to immunize nodes with high median weights, effectively improving network stability. Others have used optimal control methods to solve immunization strategies, effectively controlling the number of infections and reducing defense costs. Others have used moderate and weakly supervised immunization to curb the spread of infection by shifting activation from specific motifs to collectively driven activation, improving the effectiveness of non-mandatory immunization strategies. Others have studied immunization defense methods in the absence of data, improving acquaintance immunization and enhancing network defense capabilities. The effectiveness of these proposed methods has been verified by comparing them with other immunization strategies. In terms of structural adjustment methods, adaptive networks have been used to rewire the network, effectively raising the infection threshold. Others have studied weighted adaptive networks, in which network structure and weights dynamically interact, and based on this, proposed a real-time link weight dynamic reconnection strategy. However, these methods all operate purely from a defensive perspective, ignoring the proactive and dynamic nature of attack behavior, making them difficult to adapt to highly adversarial network scenarios. In attack-defense adversarial scenarios, attackers dynamically adjust their attack strategies based on the attack target, defense behavior, and the adversarial process. Attack and defense interact, and their strategies become interdependent, resulting in strong correlation and tight coupling. Due to their own limitations, the above-mentioned defense methods lack the ability to conduct adversarial analysis, and the defense strategies are limited in their targeting and effectiveness.
[0004] As a theoretical method for studying decision-making problems in competitive and adversarial environments, game theory has obvious advantages in the adversarial analysis of network attack and defense behaviors. Introducing game theory to provide a theoretical basis and method guidance for network defense decision-making can effectively improve decision-making efficiency and enhance the applicability of decision-making results. Currently, a series of achievements have been made in the research on attack and defense behavior analysis and defense decision-making based on game theory. For example, a signaling game model with a deception detection mechanism is used, and on this basis, the mixed equilibrium strategy and the separating equilibrium strategy are obtained by solving, and a deception defense strategy is designed; another example is to use the Stackelberg game to discuss the placement problem of intrusion detection systems (IDS) in a moving target defense system, and the optimal placement strategy is obtained by solving the game equilibrium; another example is to establish a stochastic game model in the cloud computing environment, use the attack graph to simulate the attack and defense interaction, and propose a comprehensive defense method combining virtual machine migration and honeypots, which improves the anti-attack ability of the system. The common problem of their work is to carry out modeling research using a dynamic stage game model, and the obtained defense strategy is discrete and has hysteresis, and cannot adjust the strategy in real time according to the current attack and defense state, and is prone to being in a passive position in network attack and defense.
[0005] Actual network attack and defense is generally a real-time and continuous confrontation process, and attack and defense strategies have the characteristics of high-frequency dynamic changes. Therefore, a continuous real-time defense decision-making method can effectively adapt to the actual scenario and improve the defense efficiency. As a theoretical method for describing the continuous control process in conflict and confrontation under real-time conditions, differential game meets the real-time requirements of network attack and defense. For example, an isolation defense strategy based on differential game is proposed for distributed denial of service (DDoS) attacks, and the effectiveness of the proposed method is verified through numerical experiments; another example is a multi-person attack and defense analysis model based on differential game, which studies the relationship between attack and defense behavior interaction and infection threshold, and proposes an optimal strategy selection algorithm for multiple defenders; another example is to combine differential game with FlipIt game to study the optimal strategy problem in a moving target defense system, which improves the defense decision-making efficiency; another example is to study the contagion and diffusion of security threats in a sensor network based on differential game, and propose a method to inhibit the growth of infected nodes, which reduces the network defense cost. However, all of the above use a random network model to carry out modeling research on the target network, assuming that all nodes in the network are homogeneous, and on this basis, analyze attack and defense behaviors and solve defense strategies. Since it does not conform to the actual situation that real networks such as the Internet, the World Wide Web, and the telecommunications network are mostly large-scale complex networks, the defense strategy often does not adapt to the structural characteristics of complex networks such as small-world, scale-free, and high-clustering, and the defense effect is not satisfactory. Summary of the Invention
[0006] To this end, the present invention provides a complex network dynamic defense decision-making method and system based on attack and defense game, comprehensively considering the structural characteristics of the complex network and the confrontation characteristics of network security, combining the complex network with the potential differential game theory, and obtaining a globally optimal network defense decision for the overall network defense goal, which is more suitable for the network defense scenario and convenient for practical scenario applications.
[0007] According to the design scheme provided by the present invention, a complex network dynamic defense decision-making method based on attack and defense game is provided, including the following contents:
[0008] Draw on the classic epidemic model to describe the evolution of network nodes among the susceptible state, infected state, and repaired state;
[0009] Use the security state transition differential equation of network nodes to analyze the network node state evolution process, and construct a network attack and defense potential differential game model for analyzing network attack and defense confrontation capabilities;
[0010] For the network attack and defense potential differential game model, use the saddle point equilibrium strategy to solve the model to obtain the optimal strategy that maximizes the overall benefit of the defender.
[0011] As the complex network dynamic defense decision-making method based on attack and defense game in the present invention, further, in the process of network node state evolution, use the network node state probability to describe the node conversion process, and the sum of the susceptible state, infected state, and repaired state of the node is set to 1.
[0012] As the complex network dynamic defense decision-making method based on attack and defense game in the present invention, further, in the analysis of the network node state evolution process, take the infection rate as the attack strategy and the repair rate as the defense strategy, and use the mean field model to construct the security state transition differential equation of network nodes.
[0013] As the complex network dynamic defense decision-making method based on attack and defense game in the present invention, further, the security state transition differential equation of network nodes constructed by using the mean field model is expressed as: where, N represents the total number of network nodes, b ij represents the coefficient of whether node i and node j are directly connected, β i (t), γ i (t), α i are respectively the infection rate, repair rate, and rate of returning from the immune state to the susceptible state of node i at time t, S i (t), R i (t), I i (t) are respectively the susceptible probability, infected probability, and repaired probability of node i at time t.
[0014] As the complex network dynamic defense decision-making method based on attack and defense game of the present invention, further, the network attack and defense potential differential game model is expressed as NAPDG=(N i ,t,x i ,E,f,J), where N i represents the game participant of network node i, t represents the time variable of attack and defense game, x i represents the state variable of network node i, and x i (t)={S i (t),I i (t),R i (t)|S i (t)+I i (t)+R i (t)=1}, S i (t),I i (t),R i (t) respectively represent the probabilities of network node i being in the normal state, infected state and repaired state at time t, E represents the control strategy sets of both sides of the game, and E=(γ(t),β(t)), γ(t)=(γ1(t),γ2(t),...,γ n (t)) represents the defense strategy at time t, β(t)=(β1(t),β2(t),...,β n (t)) represents the attack strategy at time t, f represents the set of state transition functions, and J represents the set of benefit functions of both sides of the game, and J=(J D ,J A ), J D and J A respectively represent the global benefits of the attack and defense sides.
[0015] As the complex network dynamic defense decision-making method based on attack and defense game of the present invention, further, when calculating the global benefits of both the attack and defense sides, the rewards brought to both the attack and defense sides by the current state of the network nodes and the costs generated by the real-time control strategies of both the attack and defense sides are quantified respectively to obtain the global benefits of both the attack and defense sides.
[0016] As the complex network dynamic defense decision-making method based on attack and defense game of the present invention, further, the global benefit of the attacker is expressed as: The global benefit of the defender is expressed as: Where, r i represents the reward obtained by the attacker per unit time after network node i is infected, s i represents the reward obtained by the defender per unit time from the immune state, σ(β i ) represents the attacker at a rate of β iThe unit time cost of infecting network node i, δ(γ i ) represents the unit time cost for the defender to repair network node i at rate γ i .
[0017] As the complex network dynamic defense decision-making method based on attack-defense game of the present invention, further, in the solution of the attack-defense potential differential game model, the Hamilton functions of the attacker and the defender are used to couple the overall instantaneous benefits of the attacker and the defender with the network state, and the optimal strategies of the attacker and the defender are obtained by solving through the co-state function in the attack-defense potential differential game from the perspective of the global benefit.
[0018] As the complex network dynamic defense decision-making method based on attack-defense game of the present invention, further, an iterative algorithm is used to solve the model. During the iterative process, first, the network node state is calculated and updated forward using the differential equation of the security state transition of the network node; then, the control strategies of the attacker and the defender are calculated through the co-state function in the attack-defense potential differential game. When the difference between the old and new control strategy pairs of the attacker and the defender is less than the preset threshold or the number of iterations reaches the preset maximum value, the defense control strategy is obtained based on the global benefits of the attacker and the defender.
[0019] Further, the present invention also provides a complex network dynamic defense decision-making system based on attack-defense game, including: a model construction module and a model solution module, where
[0020] The model construction module is used to describe the evolution of network nodes among the susceptible state, the infected state, and the repaired state by referring to the classical epidemic model; analyze the evolution process of the network node state using the differential equation of the security state transition of the network node, and construct an attack-defense potential differential game model for analyzing the network attack-defense confrontation ability;
[0021] The model solution module is used to solve the attack-defense potential differential game model using the saddle point equilibrium strategy to obtain the optimal strategy that maximizes the overall benefit of the defender.
[0022] The beneficial effects of the present invention:
[0023] The present invention realizes the analysis of the security state evolution of microscopic network nodes by establishing a network security threat propagation model, and obtains the overall offensive and defensive control strategy at the macro level through the quantification of the game benefits of offensive and defensive strategies; and based on the potential differential game theory, by constructing an offensive and defensive potential differential game model with real-time confrontation analysis ability, the saddle point equilibrium strategy is used to obtain the global optimal decision for the overall network defense goal; the decision-making subjects of network offense and defense are no longer individual network nodes, but defenders and attackers with the ability of global network control. The problem is transformed into a single optimal control problem for solving the overall offensive and defensive strategy, and the calculation process and complexity are greatly compressed. Further verification is carried out through experiments on typical complex networks. Compared with the random defense strategy in the comparative experiment, the defense efficiency advantage of the solution in this case is obvious and it is convenient for application in actual scenarios. Description of the Drawings
[0024] Figure 1 It is a schematic diagram of the dynamic defense decision-making process of a complex network based on offensive and defensive games in the embodiment;
[0025] Figure 2 It is a schematic diagram of the degree distribution of the small-world network and the scale-free network in the embodiment;
[0026] Figure 3 It is a schematic diagram of the comparison of the defense benefits between the solution in this case and the random strategy in the embodiment;
[0027] Figure 4 It is a schematic diagram of the offensive and defensive strategies based on the potential differential game decision-making method in the small-world network in the embodiment;
[0028] Figure 5 It is a diagram of the offensive and defensive strategies based on the potential differential game decision-making method in the scale-free network in the embodiment;
[0029] Figure 6 It is a schematic diagram of the offensive and defensive strategies based on the classical differential game decision-making method in the small-world network in the embodiment;
[0030] Figure 7 It is a schematic diagram of the offensive and defensive strategies based on the classical differential game decision-making method in the scale-free network in the embodiment;
[0031] Figure 8 It is a schematic diagram of the comparison of the defense benefits in the small-world network in the embodiment;
[0032] Figure 9 It is a schematic diagram of the comparison of the defense benefits in the scale-free network in the embodiment. Detailed Embodiment
[0033] To make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the drawings and technical solutions.
[0034] Most of the current complex network defense methods solely focus on the defense perspective, ignoring the core characteristics of the offense-defense confrontation in network security. When dealing with dynamically changing attack behaviors, the effectiveness of defense decisions is insufficient. Most of the existing defense decision methods based on offense-defense confrontation analysis use random network models to conduct modeling research on the target network, which does not conform to the actual situation that most real-world networks are large-scale complex networks. The defense decision algorithms and results do not adapt to the structural characteristics of complex networks such as small-world, scale-free, and high-clustering, and the applicability of defense decisions is limited. In the embodiments of the present invention, as shown in Figure 1 shown, a complex network dynamic defense decision method based on offense-defense game is provided, including:
[0035] S101. Draw on the classic epidemic model to describe the evolution of network nodes among the susceptible state, infected state, and repaired state;
[0036] S102. Use the security state transfer differential equation of network nodes to analyze the evolution process of network node states, and construct a network offense-defense potential differential game model for analyzing network offense-defense confrontation capabilities;
[0037] S103. For the network offense-defense potential differential game model, use the saddle-point equilibrium strategy to solve the model to obtain the optimal strategy that maximizes the overall benefit of the defender.
[0038] Since the decision-makers of traditional game methods are individuals, although the above complex network defense decision method can obtain the individual optimal strategy for network nodes, it generally cannot achieve the global optimum of network overall defense. The potential differential game combines the advantages of potential games and differential games and has advantages in solving global real-time optimal control problems. When solving the global optimal strategy, the classic differential game couples multiple optimal control problems and then calculates. Due to the large number of nodes in complex networks, the computational complexity is huge, and the algorithm is not realistically feasible. In the embodiments of this case, considering the structural characteristics of complex networks and the confrontation characteristics of network security, combining complex networks with potential differential game theory, aiming at the network overall defense goal, based on the analysis of the evolution of network security states, an offense-defense potential differential game model is constructed; for the overall offense-defense control strategy, an adversarial analysis is carried out, and based on the saddle-point equilibrium strategy of the game, a network defense decision scheme oriented to the global optimum is realized. The decision-making subjects of network offense-defense are no longer individual network nodes, but defenders and attackers with network global control capabilities. The problem is transformed into a single optimal control problem of solving the overall offense-defense strategy, and the calculation process and complexity are greatly compressed, with obvious advantages.
[0039] As a preferred embodiment, further, during the evolution process of network node states, the network node state probability is used to describe the node conversion process, and the sum of the susceptible state, infected state, and repaired state of the node is set to 1.
[0040] For a network with N nodes, due to the impact of attack and defense actions, the states of the nodes in the network will change in real time. We use the classic infectious disease SIRS model to describe the evolution of the states of network nodes. There are three states for the nodes in the network: susceptible (S), infected (I), and recovered (R). Respectively, use S i 、I i 、R i to represent the probabilities that node i is in the susceptible, infected, and recovered states. There is S i +I i +R i = 1.
[0041] As a preferred embodiment, further, during the analysis of the evolution process of the network node states, the infection rate is used as the attack strategy, and the repair rate is used as the defense strategy. The mean-field model is used to construct the differential equation for the secure state transition of network nodes.
[0042] According to the characteristics of the network, for the three states of network nodes: S (susceptible state): Susceptible nodes can provide services normally; due to the lack of effective protection, they are easily invaded by attackers. After being attacked, they transfer from the susceptible state to the infected state; I (infected state): Attackers can use infected nodes to attack susceptible nodes, thereby further spreading the infection range; Defenders can repair the infected nodes to make them enter the recovered state; R (recovered state): Recovered nodes have immune efficacy and will not be infected again in a short time, but as time goes by, the immune efficacy will gradually disappear, causing the nodes to return to the susceptible state. Under the mean-field model, the differential equation for the secure state transition of network nodes can be established as follows:
[0043]
[0044] In the above formula, b ij represents whether node i and node j are connected. If the two nodes are directly connected, there is b ij = 1, otherwise b ij = 0, β i 、γ i 、α i are respectively the infection rate, repair rate of node i, and the rate at which the node returns from the immune state to the susceptible state. Based on the above secure state transition equation, according to the probabilities S i 、I i 、R i of all the network nodes being in the susceptible, infected, and recovered states, the microscopic analysis of the secure state evolution of network nodes can be realized. From the perspective of the macroscopic network security attack and defense goals, attackers spread the infected state by infecting susceptible nodes, thereby disrupting the normal operation of the network. Therefore, the infection rate β i can be used as the attack strategy; defenders, on the other hand, make the functions of the infected nodes return to normal by repairing them, and use the repair rate γi As a defense strategy.
[0045] As a preferred embodiment, further, when calculating the global benefits of both the attacker and the defender, the rewards brought by the current state of the network node to both the attacker and the defender and the costs generated by the real-time control strategies of both the attacker and the defender are quantified respectively to obtain the global benefits of both the attacker and the defender.
[0046] Combined with the characteristics of network attack and defense confrontation, the attack and defense benefits are divided into two parts: one part is the rewards brought by the current state of the network node to both the attacker and the defender, and the other part is the costs generated by the defender and the attacker implementing control strategies.
[0047] Let r i represent the reward obtained by the attacker per unit time after node i is infected. This reward may be user data, network configuration, etc. Therefore, the reward obtained by the attacker from node i can be expressed as Similarly, when node i is in the immune state, the attacker can no longer infect it, reducing the infection risk for the defender and bringing indirect benefits to the defender. Let s i represent the reward obtained by the defender per unit time from the immune state. Then the reward brought to the defender in node i is
[0048] Both the attacker and the defender have to pay corresponding costs for implementing the corresponding strategies. σ(β i ) represents the cost per unit time for the attacker to infect node i at a rate of β i . Then the cost for the attacker to implement the attack strategy at node i is δ(γ i ) represents the cost per unit time for the defender to repair node i at a rate of γ i . Then the cost for the defender to implement the defense strategy at node i is
[0049] In summary, the global benefit of the attacker can be obtained as:
[0050]
[0051] The global benefit of the defender is:
[0052]
[0053] Further, the network attack and defense potential differential game model NAPDG (Network Attack-Defense Potential Differential Game) can be represented as a six-tuple NAPDG = (N i , t, x i , E, f, J), where Ni Denotes the game participants. t represents the time variable of the attack - defense game, where \(t\in[t_0,T]\), and \(t_0\) and \(T\) represent the initial and end times of the game process respectively. \(x\) i (t)=\(\{S\) i (t),I i (t),R i (t)|S i (t)+I i (t)+R i (t)=1\} is the state variable of the nodes in the network. \(S\) i (t),I i (t),R i (t) are the probabilities that node \(i\) is in the normal state, infected state, and repaired state at time \(t\) respectively. \(E = (\gamma(t),\beta(t))\) represents the control strategy set of both sides of the game. \(\gamma(t)=(\gamma_1(t),\gamma_2(t),...,\gamma\) n (t)) represents the defense strategy at time \(t\), and \(\beta(t)=(\beta_1(t),\beta_2(t),...,\beta\) n (t)) represents the attack strategy at time \(t\). is the set of state - transition function, where,[[]] J=(J D ,J A ) is the set of pay - off functions of the defender and the attacker. \(J\) D and \(J\) A represent the global pay - offs of the defender and the attacker respectively.
[0054] As a pre - selected embodiment, further, in the solution of the network attack - defense potential differential game model, the Hamilton functions of both the attacker and the defender are used to couple the overall instantaneous pay - offs of both sides with the network state, and the optimal strategies of both sides are obtained by solving through the co - state function in the attack - defense potential differential game from the perspective of the global pay - off.
[0055] According to the basic game theory, both sides of the attack - defense game are committed to maximizing their respective pay - offs, and the game equilibrium strategy is the optimal strategy of the defender and the attacker.
[0056] If the optimal strategy pair is the saddle - point equilibrium strategy of the attack - defense potential differential game model, then it satisfies:
[0057]
[0058] The saddle - point strategy is the optimal strategy of both the attacker and the defender, and neither side can obtain a greater pay - off by changing the strategy.
[0059] The attack - defense strategy pair The necessary and sufficient condition for the saddle-point equilibrium solution of the offensive and defensive potential differential game model is that there exists a co-state function (λ i (t), K i (t)) such that the following conditions are satisfied:
[0060]
[0061]
[0062]
[0063] In the above formula, and are the global instantaneous payoffs of the defender and the attacker respectively. See formulas (2) and (3). The co-state functions of the defender and the attacker are expressed as and and are continuously differentiable, where x ∈ {S, I, R}.
[0064] The system state transition function of the network offensive and defensive potential differential game model and the instantaneous payoffs of both sides of the offense and defense (p D , p A ) are bounded and continuous, and (p D , p A ) is a convex function. The network offensive and defensive potential differential game NAPDG has a saddle-point equilibrium.
[0065] In the general process of solving the global optimal saddle-point strategy, the Hamiltonian function of the defender can be constructed first as follows:
[0066]
[0067] Different from the classical differential game, the Hamiltonian function (formula 8) couples the overall instantaneous payoff of the defense with the network state, while the classical differential game only couples the instantaneous payoff of a single individual with the network state. Therefore, from the perspective of the global payoff, the optimal strategy obtained by solving can maximize the overall payoff of the defender.
[0068] On this basis, the co-state function in the offensive and defensive potential differential game can be obtained
[0069]
[0070]
[0071]
[0072] Calculate using the backward calculation method.
[0073] Let It can be calculated that
[0074]
[0075] Similarly, the Hamilton potential function H of the attacker can be obtained A , the co-state function and the optimal attack strategy
[0076] As a preferred embodiment, further, an iterative algorithm is used to solve the model. During the iterative process, first, the network node state is calculated and updated forward using the safety state transition differential equation of the network node; then, the control strategies of both the attacker and the defender are calculated through the co-state function in the attack-defense potential differential game. When the difference between the old and new control strategy pairs of both the attacker and the defender is less than a preset threshold or the number of iterations reaches a preset maximum value, the defense control strategy is obtained based on the global benefits of both the attacker and the defender.
[0077] In the embodiment of this case, the forward-backward scanning algorithm can be used to calculate the optimal defense strategy. This algorithm is an iterative process. First, the network state is calculated and updated forward using formula (1); then, the co-state function is calculated backward; based on this, the control strategies γ i (t) and β i (t) are calculated. When the difference between the old and new control strategy pairs is small enough or the number of iterations is large enough, the algorithm ends. The specific algorithm content can be designed as shown in Algorithm 1.
[0078]
[0079] Further, based on the above method, the embodiment of the present invention also provides a complex network dynamic defense decision-making system based on attack-defense game, including: a model construction module and a model solution module, where
[0080] The model construction module is used to describe the evolution of network nodes among the susceptible state, infected state, and repaired state by referring to the classic epidemic model; use the safety state transition differential equation of network nodes to analyze the network node state evolution process, and construct a network attack-defense potential differential game model for analyzing network attack-defense confrontation capabilities;
[0081] The model solution module is used to solve the network attack-defense potential differential game model using the saddle point equilibrium strategy to obtain the optimal strategy that maximizes the overall benefit of the defender.
[0082] To verify the effectiveness of the solution of this case, the following further explanation is made in combination with simulation data:
[0083] Table 1 Comparison of models and methods
[0084]
[0085]
[0086] Compare the security defense decision-making scheme based on potential differential game proposed in this case with existing related research, as shown in Table 1. The attack and defense confrontation analysis method refers to the perspective from which attack and defense behaviors are analyzed and defense decisions are made. In the fixed attack and defense strategy analysis, the strategy changes of both the attacker and the defender during the confrontation process are not considered, and the attack and defense behaviors are fixed; in the single-party optimal control analysis, it is assumed that the attack behavior remains unchanged, and the defender formulates a defense strategy accordingly. However, attack and defense confrontation is the core of network security. In the actual confrontation process, attack and defense behaviors are interdependent. Therefore, when studying the defense decision-making method, attack and defense behaviors cannot be separated; dynamic attack and defense game analysis, node real-time attack and defense game analysis, and the whole-network real-time attack and defense game analysis in this case analyze network attack and defense behaviors, fully analyze the impact of attack and defense interaction, and then formulate defense decisions, which conforms to the reality of network attack and defense.
[0087] The decision-making basis refers to the method by which the defense strategy is obtained. In the fixed attack and defense strategy analysis, the node connectivity is used as a benchmark to immunize the nodes in the network that meet certain characteristics. The strategy formulation is simple, but when these characteristics in the network are no longer obvious or the network structure changes greatly, the effectiveness of the defense strategy may drop significantly; in the single-party optimal control analysis, the node connection weight is used as the defense strategy, and the optimal control method is used to calculate the optimal weight, and the network topology relationship is changed by adjusting the weight; dynamic attack and defense game analysis, node real-time attack and defense game analysis, and the whole-network real-time attack and defense game analysis in this case obtain the defense strategy by solving the game equilibrium on the basis of formulating a suitable payoff function.
[0088] The decision-making timeliness refers to the effective time of the decisions of both the attacker and the defender, and also refers to whether the attack and defense strategies are timely. The fixed attack and defense strategy analysis uses the immunization strategy, which belongs to the fixed defense strategy and is difficult to adjust and optimize according to the actual situation of attack and defense; the dynamic attack and defense game analysis uses the stage game model, and the defender makes decisions following the game stage and cannot respond in time when the network state changes, so the timeliness is poor; single-party optimal control analysis, node real-time attack and defense game analysis, and the whole-network real-time attack and defense game analysis in this case can achieve real-time defense decision-making and have better timeliness.
[0089] The decision result refers to whether the method can achieve individual optimality or global optimality from the perspective of the final result. The fixed attack and defense strategy analysis adopts acquaintance immunization, which immunizes from the individual perspective and cannot achieve global optimality. The dynamic attack and defense game analysis takes the defender as the decision-making subject, but does not divide the inside of the defender. Therefore, the defender is also a defensive individual, and its result is both individual optimality and global optimality. In the node real-time attack and defense game analysis, the defensive individual calculates the defense strategy based on its own benefits when making decisions, without considering the global benefits, and can only achieve individual optimality. In the unilateral optimal control analysis and the real-time attack and defense game analysis of the whole network in this case, the defender formulates individual defense strategies from the perspective of global benefits when making decisions, so as to maximize the overall defense benefits.
[0090] In the simulation experiment, two types of typical complex networks were used to carry out verification experiments: small-world network and scale-free network. According to the classic small-world network generation method, Matlab was used to generate a small-world network with 1000 nodes. Following the growth and preferential attachment method of the scale-free network, a scale-free network with 1000 nodes was generated. In the above two simulation networks, the network nodes were sorted in ascending order of node connectivity, that is, the first node had the smallest connectivity and the 1000th node had the largest connectivity. The node degree distributions of the two networks are as Figure 2 shown, the abscissa represents the node connectivity, and the ordinate represents the node proportion. Assuming that in the initial security state, the infection probability of network nodes is 10%, that is, S i (0)=0.9, I i (0)=0.1, R i (0)=0. The cost of the attack and defense strategy is proportional to the infection rate and the repair rate per unit time, that is, δ(γ i (t))=aγ i (t), σ(β i (t))=bβ i (t). The specific parameters are shown in Table 2.
[0091] Table 2 Experimental parameter settings
[0092]
[0093] To verify the effectiveness of the solution in this case, Algorithm 1 in the embodiments of this case was used to calculate the defense benefits in the scale-free network and the small-world network respectively, and then 100 pairs of attack and defense strategy pairs (γ(t), β(t)) were randomly generated and their benefits were calculated, and compared with the benefits of the solution in this case. The experimental results are as Figure 3As shown in the figure. The horizontal axis of the coordinate represents the serial number of the random strategy, and the vertical axis represents the defense benefit. The dots in the figure are the defense benefits of the solution in this case, which are 428.4 and 464.6 respectively; the three horizontal lines represent the maximum, average, and minimum defense benefits under the random strategy, which are 212.3, 198.0, and 184.6 respectively in the small-world network and 233.5, 215.2, and 198.4 respectively in the scale-free network. It can be found that the defense benefit of the solution in this case is significantly higher than that of the random strategy.
[0094] For the small-world network and the scale-free network, a comparative analysis is carried out between the solution in this case and the defense decision-making method based on the classical differential game. The results are as Figures 4 - 7 shown. The horizontal axis in the figure represents the game time, and the vertical axis is the strategy value. The subscript in the legend of each subfigure represents the node serial number, and the degree corresponding to the node is marked at the bottom of each column of subfigures. For example, Figure 4 in the upper subfigure of the first column of , the legend γ1 represents the repair rate of the first node in the network; the legend β1 in the lower subfigure of the first column represents the infection rate of the first node in the network; k = 32 at the bottom of the first column of subfigures represents that the connection degree of the first node is 32.
[0095] Figures 4 - 7 shows the situation of the attack and defense strategies changing with time. The optimal attack and defense strategies are obtained by using the potential differential game model and decision algorithm in the solution in this case. The experimental results in the small-world network and the scale-free network are respectively as Figure 4 and Figure 5 shown, and the experimental results of using the classical differential game method are respectively as Figure 6 and Figure 7 shown.
[0096] Figure 4 and Figure 5 In and , the execution probability of the defense strategy of the 1000th node is the highest. The reason is that the 1000th node is the central node with the highest connection degree in the whole network. Once it is infected, it will cause huge losses. Therefore, the defense probability is the highest. Figure 5 In , the attack frequency reaches the maximum at the 970th node. The reason is that the defense probability and intensity are the highest at the 1000th node. In order to avoid the huge cost of high-intensity confrontation, the attacker chooses the node with a slightly lower connection degree as the priority target as a second choice. Comparing Figure 4 and Figure 5 It can be found that the strategy execution probabilities of both the attacker and the defender are relatively close in different networks, and the difference is not significant. This shows that the method of this patent has good adaptability to different types of complex networks.
[0097] Figure 6 and Figure 7 In and , with the increase of the node degree, the execution probability and stability of the defense strategy are enhanced. Comparing Figure 6 andFigure 7 It can be found that there are significant differences in the strategies of the attacker and the defender in different networks.
[0098] Comprehensive comparison Figures 4 - 5 and Figures 6 - 7 It can be found that when the potential differential game model and decision algorithm in the solution of this case are adopted, the difference in the attack and defense strategies between the small-world network and the scale-free network is relatively small, the frequency of the attack and defense strategies is relatively fast, and at the same time, neither the attacker nor the defender will not execute the strategy for a long time or stick to the original strategy unchanged. This is because in the potential differential game, the defense strategy is uniformly formulated by the defender who grasps the global information of the network. As long as there is an attack and defense behavior in the network, the global benefit will change, and the defender will dynamically adjust the control strategy in a timely manner to adapt to the current network defense needs. Therefore, when the potential differential game is adopted, all nodes in the network are highly correlated, and there will be a higher change frequency and correlation in the strategy performance. When the classical differential game is used for defense decision-making, each node formulates the defense strategy based on its own characteristics and security environment, lacking consideration of other nodes in the network, resulting in the defense strategy being more affected by the node degree, and the strategy correlation between different nodes being relatively small. In addition, the difference in the attack and defense strategies at different nodes in the scale-free network between the two methods is greater than that in the small-world network, because the degree distribution of nodes in the small-world network is relatively uniform, while the heterogeneity between nodes in the scale-free network is stronger, and the differences shown in the attack and defense strategies are more obvious.
[0099] Compare the defense benefits of the solution of this case with the classical differential game method, the node immunity strategy, and the structure adjustment method. Randomly select 20 attack strategies to conduct experiments, and the experimental results are as Figures 8 - 9 shown. The horizontal axis of the coordinate represents the serial number of the attack strategy, and the vertical axis represents the defense benefit. The horizontal line in the figure represents the average benefit of each strategy.
[0100] Figure 8 The defense benefits obtained by using the above four methods in the small-world network are shown. The average benefits are 428.94, 322.60, 282.85, and 394.68 respectively. The defense benefits from high to low are the potential differential game method of the solution of this case, the structure adjustment method, the differential game method, and the immunity strategy method. Figure 9 The benefit comparison of the four defense methods in the scale-free network is shown. The average benefits are 464.27, 299.87, 290.66, and 440.13 respectively. The defense benefit of the solution of this case is the highest.
[0101] Based on the comprehensive analysis of the experimental data of small-world networks and scale-free networks, it can be seen that the defense benefits of the solution and structure adjustment method in this case are significantly higher than other methods. The reason is that both of these methods formulate the optimal defense strategy from the perspective of global benefits, so they have better defense effectiveness. In terms of the stability of defense benefits, the immune strategy has the highest benefit stability. When the immune strategy is adopted, since the defender always implements the immune strategy for a part of specific nodes, the attacker can only infect the remaining part of the nodes, narrowing the attacker's infection range, so it has the best stability. The structure adjustment method has the lowest benefit stability. This method is based on the idea of unilateral optimal control, and the defense strategy lacks the analysis and response to attack behaviors. When the attacker changes the strategy dynamically, it is difficult for the defender to make timely adjustments, resulting in the largest benefit fluctuations. The solution and the classical differential game method in this case have similar stabilities.
[0102] By further comparing and analyzing the experimental data of small-world networks and scale-free networks, both the solution and the structure adjustment method in this case have higher benefits in scale-free networks, the differential game method has higher benefits in small-world networks, and the differences in the benefits of the immune strategy in the two networks are relatively small. Due to the large node heterogeneity in scale-free networks and the significant differences between different individual optimal strategies and the global optimal strategy, when adopting the solution in this case, the defender can formulate an overall defense strategy from a global perspective, with better effects and significantly higher benefits than in small-world networks. On the other hand, due to the more uniform node degree distribution in small-world networks, when adopting the classical differential game method, the environments faced by defense individuals are more similar, so the results of individual decisions are closer to the global optimal strategy, and the cost of individual strategies is lower than that of the global optimal strategy, so the benefits are higher than in scale-free networks. Similarly, for the structure adjustment method, when optimizing and adjusting the node connection weights, the number of nodes involved in small-world networks is more than that in scale-free networks, and more costs need to be paid, so the benefits are lower in small-world networks.
[0103] The existing defense methods for complex networks focus on analyzing the impact of defense behaviors on the network state, ignoring the impact of attack behaviors and the interaction relationship between attack and defense; most of the current defense methods based on attack-defense confrontation analysis take the random mixed network as the research background, which does not conform to the basic characteristics of the actual large-scale network. Therefore, to address the above problems, the solution in this case combines complex networks with potential differential games, starting from the perspective of the overall network, analyzes the behavioral interaction in the attack-defense process, formulates defense decisions, and improves the effectiveness and applicability of defense decisions; starting from the micro level, constructs a network propagation model, establishes a differential equation of state evolution, proposes a macro-level attack-defense potential differential game model, and obtains an overall optimal defense strategy selection algorithm by calculating the saddle point equilibrium, improving the defense benefits; and through experiments in classical complex network models, compares and analyzes the attack-defense strategies and defense benefits under different methods, further verifying the effectiveness and good defense effectiveness of the solution in this case.
[0104] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0105] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0106] The units and method steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation is not considered to exceed the scope of the present invention.
[0107] Those of ordinary skill in the art can understand that all or part of the steps in the above methods can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk, or an optical disc, etc. Optionally, all or part of the steps of the above embodiments can also be implemented using one or more integrated circuits. Correspondingly, each module / unit in the above embodiments can be implemented in the form of hardware or in the form of a software function module. The present invention is not limited to any specific form of the combination of hardware and software.
[0108] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present invention, used to illustrate the technical solutions of the present invention, and not to limit them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or make equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A complex network dynamic defense decision-making method based on attack and defense game, characterized in that It includes the following content: Drawing on classical epidemic models to describe the evolution of network nodes among susceptible, infected, and repaired states; In the process of analyzing the evolution of network node states, the infection rate is used as the attack strategy and the repair rate is used as the defense strategy. The mean field model is used to construct the differential equation for the security state transition of network nodes. The differential equation for the security state transition of network nodes is used to analyze the evolution of network node states, and a network attack and defense potential differential game model is constructed to analyze the network attack and defense capabilities. The differential equation for the security state transition of network nodes is expressed as: The network attack and defense potential differential game model is expressed as NAPDG = (N i ,t,x i ,E,f,J), where N represents the total number of network nodes, b ij The coefficient indicating whether node i is directly connected to node j, β i (t), γ i (t), α i are the infection rate, repair rate and rate of returning from immune state to susceptible state of node i at time t, respectively. i (t), I i (t), R i (t) are the susceptible probability, infection probability and repair probability of node i at time t, respectively, N i represents the game participant of network node i, t represents the time variable of the attack and defense game, x i represents the state variable of network node i, and x i (t) = {S i (t),I i (t),R i (t)|S i (t)+I i (t)+R i (t)=1}, E represents the control strategy set of both parties in the game, and E=(γ(t),β(t)),γ(t)=(γ1(t),γ2(t),...,γ n (t)) represents the defense strategy at time t, β(t)=(β1(t),β2(t),...,β n (t)) represents the attack strategy at time t, f represents the set of state transition functions, and J represents the set of profit functions of both parties in the game, and J=(J D ,J A ), J D and J A They represent the global benefits of the attacker and defender respectively; the attacker's global benefit is expressed as: The defender's global benefit is expressed as: r i It represents the reward obtained by the attacker per unit time after the network node i is infected, s i Denote the return that the defender obtains from the immune state per unit time, and σ(β i ) denote the cost per unit time for the attacker to infect the network node i at the rate β i , and δ(γ i ) denote the cost per unit time for the defender to repair the network node i at the rate γ i , and T is the end time of the game process; For the network attack and defense potential differential game model, the Hamilton functions of the attacker and defender are used to couple the overall instantaneous benefits of both sides with the network state. From the perspective of the global benefit, the co-state function in the attack and defense potential differential game is used to iteratively solve for the optimal strategies of both sides. To use the saddle-point equilibrium strategy for model solution to obtain the optimal strategy that maximizes the overall benefit of the defender. Among them, in the iterative process, first, the network node state is calculated and updated forward using the differential equation of the security state transition of network nodes; then, the control strategies of both sides are calculated through the co-state function in the attack and defense potential differential game. When the difference between the old and new control strategy pairs of both sides is less than the preset threshold or the number of iterations reaches the preset maximum value, the defense control strategy is obtained based on the global benefits of both sides.
2. The dynamic defense decision-making method for complex networks based on attack-defense game according to claim 1, wherein During the evolution of the network node state, the network node state probability is used to describe the node transition process, and the sum of the susceptible, infected, and repaired states of the node is set to 1.
3. The dynamic defense decision-making method for complex networks based on attack-defense game according to claim 1, characterized in that When calculating the global benefits of both sides, the rewards brought by the current state of the network nodes to both sides and the costs generated by the real-time control strategies of both sides are quantified respectively to obtain the global benefits of both sides.
4. A complex network dynamic defense decision-making system based on attack and defense game, characterized in that, Implemented based on the method described in claim 1, including: a model construction module and a model solution module, where The model construction module is used to draw on classical epidemic models to describe the evolution of network nodes among susceptible, infected, and repaired states; use the differential equation of the security state transition of network nodes to analyze the evolution process of network node states, and construct a network attack and defense potential differential game model for analyzing network attack and defense capabilities; The model solution module is used to, for the network attack and defense potential differential game model, use the saddle-point equilibrium strategy for model solution to obtain the optimal strategy that maximizes the overall benefit of the defender.
Citation Information
Patent Citations
Attack and defense differential game-based network security defense decision determination method and device
CN106936855A