Malicious program propagation attack and defense game method under smart fishery

By constructing a SIRQ infectious disease model for underwater wireless sensor networks, analyzing the game-theoretic behavior of malware propagation, and formulating a hybrid Nash equilibrium strategy, the internal attack problem of malware propagation in underwater wireless sensor networks is solved, thereby improving defense capabilities and intrusion detection effectiveness.

CN115915143BActive Publication Date: 2025-12-12GUANGZHOU UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210866533.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-22
Publication Date
2025-12-12
Estimated Expiration
2042-07-22

AI Technical Summary

Technical Problem

In existing technologies, research on malware propagation in underwater wireless sensor networks mainly focuses on external attacks, failing to effectively address internal attack methods, especially host enhancement attacks in a latent state, which leads to an increased intrusion success rate.

Method used

We construct a collaborative attack and defense game model for AUVs and UWSNs based on the SIRQ infectious disease model. By defining the cell state transition diagram and payoff function, we solve the mixed Nash equilibrium strategy, analyze cell behavior strategies, and formulate intrusion detection and defense measures.

Benefits of technology

It effectively suppressed the spread of malicious programs, improved system defense capabilities, reduced the success rate of internal attacks, and optimized intrusion detection and defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115915143B_ABST
    Figure CN115915143B_ABST
Patent Text Reader

Abstract

The present application relates to underwater wireless sensor network technical field, disclose a kind of malicious program propagation attack and defense game method in wisdom fishery, including the following operating steps: S1: construct the cell state conversion graph of AUV, UWSNs collaborative system attack and defense game model based on SIRQ infectious disease model;S2: according to cell state conversion relationship definition attack and defense game strategy parameter;S3: based on incomplete information game establishment function income table and income function formula;S4: income function formula solution mixed Nash equilibrium strategy solution;S5: through mixed Nash equilibrium strategy solution analysis cell behavior strategy.The present application is in SRQ neighbor cell model three-party attack and defense game, whether susceptible cell is detected or not, its expected income is negative, so immune cell will certainly adopt to send immune repair program, immune cell will adopt to send immune repair program behavior strategy, no longer need to satisfy necessary condition that susceptible cell is in detection state.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of underwater wireless sensor networks, in particular to a malicious program propagation attack and defense game method in intelligent fisheries. BACKGROUND

[0002] The malicious program propagation of an underwater wireless sensor network is an important security problem, and the application discloses an intelligent fishery malicious program propagation attack and defense game method. The microscopic mechanism of the malicious program propagation of an AUV and a UWSNs collaborative system is analyzed from the perspective of game theory, an attack and defense game model of the AUV and the UWSNs collaborative system is established, and the mixed Nash equilibrium solution of the game model is obtained from the perspective of internal attack, and the infection probability of the malicious program is determined according to the mixed Nash equilibrium strategy of the two parties in the game, so that the measures for preventing the malicious program propagation of the system are determined. The application simulates the malicious program propagation process of the AUV and the UWSNs collaborative system, and reveals the relationship between the propagation speed of the malicious program and the game parameters, and the research results have theoretical guiding significance for inhibiting the malicious program propagation.

[0003] At present, the research on the malicious program propagation mostly only includes intrusion detection and malicious program propagation, and the external attack mode is too simple, and the intrusion detection in reality has great differences, and the intrusion mode nowadays has a latent state, which can consume the host, enhance the enemy, and greatly increase the success rate of the enemy intrusion. The application not only relates the internal connection between the research on the intrusion detection and the malicious program propagation, but also introduces the internal attack mode, which is more in line with the research on the malicious program propagation. The attack and defense game model of the AUV and the UWSNs collaborative system is established, and the mixed Nash equilibrium strategy solution is obtained, so that the deficiency of the single external simple external attack game analysis is solved. SUMMARY

[0004] The application aims to provide a malicious program propagation attack and defense game method in intelligent fisheries, so as to solve the problems in the background technology.

[0005] To achieve the above-mentioned purpose, the application provides the following technical scheme.

[0006] A malicious program propagation attack and defense game method in intelligent fisheries comprises the following operation steps.

[0007] S1: constructing a cell state transformation graph of the attack and defense game model of the AUV and the UWSNs collaborative system based on the SIRQ infectious disease model.

[0008] S2: defining the parameters of the attack and defense game strategy according to the cell state transformation relationship.

[0009] S3: Establishing a function revenue table and revenue function formula based on incomplete information game.

[0010] S4: Solving mixed Nash equilibrium strategy solution of revenue function formula.

[0011] S5: Analyzing cell behavior strategy through mixed Nash equilibrium strategy solution.

[0012] Preferably, the cell state in step S2 includes susceptible cells, malicious cells, immune cells and latent cells.

[0013] Preferably, the susceptible cells can normally communicate with surrounding cells, and the intercellular communication will produce energy loss. The susceptible cells can detect the attack of malicious cells, but the malicious cells will convert the susceptible cells into latent cells by modifying and encrypting malicious programs or viruses and then spreading them to the susceptible cells. When the susceptible cells are receiving the program patch of immune cells, the immune cells can convert the susceptible cells into immune cells through immune recovery.

[0014] Preferably, the malicious cells can normally communicate with surrounding cells, that is, they can interact with normal information transmission, and do not transmit malicious programs or viruses. Normal communication needs to consume a certain amount of energy cost. The malicious cells can attack the susceptible cells, and if the attack on the susceptible cells is successful, the susceptible cells will be converted into latent cells. The attack of the malicious program or virus needs to consume more energy cost, and the attack will also produce a benefit. The attack of the malicious cells on the immune cells is invalid, and the immune cells can convert the malicious cells into immune cells through immune recovery.

[0015] Preferably, the immune cells can normally communicate with surrounding cells, and can also convert the susceptible cells, malicious cells and latent cells into immune cells through immune recovery. Normal cell communication and immune recovery work need to consume a certain amount of energy cost.

[0016] Preferably, the latent cells are nominally susceptible cells, but they carry and spread malicious programs or viruses, so they are essentially malicious cells. The attack of the latent cells on the susceptible cells can be directly successful, converting the susceptible cells into malicious cells. The attack of the latent cells on the immune cells is invalid, and the immune cells can convert the latent cells into immune cells through immune recovery.

[0017] The risk fault propagation from one direction to another direction without risk fault is defined as an attack, and different attack modes are analyzed to further obtain the risk fault propagation attack and defense strategy. The existing cell attack is mostly external attack, i.e., the first type of cell directly attacks the second type of cell, and the success rate of the attack is affected by both parties. In fact, there is another way of external attack, i.e., the low type of cell converts the second type of cell into the third type, so that the internal essence is the former, but the external characteristics are the latter, and then the third type of cell attacks the second type of cell, and the success rate of the attack is greatly increased.

[0018] Table 1: a1>e S1 >0; b1>e I12 >e I11 >0; c1>e R1 >0, when the susceptible cell is in the detection state, the immune cell receives the detection state of the susceptible cell and converts the susceptible cell into an immune cell, the susceptible cell is converted into a latent cell by the malicious cell, and the susceptible cell is converted into a malicious cell by the latent cell; the malicious cell is converted into a susceptible cell by the immune cell, the susceptible cell is converted into an immune cell by the immune cell, and the latent cell is converted into an immune cell by the immune cell; the above process is an independent process, S: susceptible cell, I: malicious cell, R: immune cell, Q: latent cell.

[0019] The symbol definition table of the SIRQ model is shown in Table 1.

[0020] Firstly, a malicious program propagation model of WSN is constructed, and the participants of the model are determined, which can be divided into SIRQ four parties, SIQ three parties, SRQ three parties and IRQ three parties. According to the symbol definition in Table 1, the function relationship between the participants of the model is written, and the function income table is listed in the form of table.

[0021] According to the function income table, the income function expression of each participant under each model is constructed according to the income expectation formula, and the attack and defense game behavior between the four parties or three parties of the susceptible node, malicious node, immune node and latent node is analyzed from the perspective of game theory, and the malicious program propagation process of the AUV, UWSNs collaborative system driven by the game strategy is researched and discussed, and the mixed Nash equilibrium strategy solution of the attack and defense game of each model is obtained.

[0022] (1) SIRQ four-party attack and defense game:

[0023] E uS(SIRQ) = x * y * z * (a1-2c1-b1-e S1 -e I12 ) + (1-x) * y * z * (-b1-e I12+ (1 - x) * y * (1 - z) * (a1 - b1 - e S1 - e I12 + (1 - x) * y * (1 - z) * (-b1 - e I12 + x * (1 - y) * z * (-c1 - e S1 + x * (1 - y) * (1 - z) * (-e S1 )

[0024] E uI(SIRQ) = * y * z * (-a1 + 2b1 - c1 - e I12 + x * (1 - y) * z * (-c1 - e I11 + x * y * (1 - z) * (-a1 + 2b1 - e I12 + x * (1 - y) * (1 - z) * (-e I11 + (1 - x) * y * z * (2*b1 - c1 - e I12 + (1 - x) * (1 - y) * z * (-c1 - e I11 + (1 - x) * y * (1 - z) * (2*b1 - e I12 + (1 - x) * (1 - y) * (1 - z) * (-e I11 )

[0025] E uR(SIRQ) = x * y * z * (3c1 - e R1 + x * (1 - y) * z * (c1 - e R1 + (1 - x) * y * z * (2c1 - e R1 + (1 - x) * (1 - y) * z * (c1 - e R1 )

[0026] And the mixed Nash equilibrium strategy of SIRQ four-party attack and defense game is known as z = 1, then:

[0027] E uS(SIRQ) = (a1 * y - e S1 - b1 * y - c1 * z - e I12 * y - z * y * c1) * x + b1 * y * z - y * e I12 - y * b1 + e I12 * y * z

[0028] E uI(SIRQ) = (-a1 * y) * x + 2b1 * y - e I11 - c1 * z + e I11 * y - e I12 * y

[0029] E uR(SIRQ) = c1 * z * y + z * (c1 - eR1 )

[0030] Let there be:

[0031]

[0032]

[0033]

[0034] Let there be a system of equations:

[0035] The solution to the system of equations is

[0036] When , the expected payoff to a malicious cell launching a malware or virus attack is equal to the expected payoff to not launching an attack.

[0037] When , the expected payoff to a malicious cell launching a malware or virus attack is greater than the expected payoff to not launching an attack.

[0038] When , the expected payoff to a malicious cell launching a malware or virus attack is less than the expected payoff to not launching an attack.

[0039] When , the expected payoff to a susceptible cell taking a detection is equal to the expected payoff to not taking a detection.

[0040] When , the expected payoff to a susceptible cell taking a detection is greater than the expected payoff to not taking a detection.

[0041] When , the expected payoff to a susceptible cell taking a detection is less than the expected payoff to not taking a detection.

[0042] When , the expected payoff to an immune cell choosing to take a detection is equal to the expected payoff to not taking a detection.

[0043] When , the expected payoff to an immune cell choosing to take a detection is greater than the expected payoff to not taking a detection.

[0044] When , The immune cells select the expected benefits of the detection, which is less than the expected benefits without detection.

[0045] In the SIRQ neighbor cell four-attack-defense game, S is the defense side relative to I, R, and Q; I is the attack side relative to S, the defense side relative to R, and the cooperation side relative to Q; R is the attack side relative to S, I, and Q; Q is the defense side relative to R and the attack side relative to S. Therefore, combined with the function benefit table and the function expected benefit formula of the SIRQ neighbor cell, there is a mixed Nash equilibrium strategy solution in this incomplete information game. The above formula is arranged as follows:

[0046] From the above analysis, in the SIRQ neighbor cell model four-attack-defense game, the latent cell has its own characteristics, and its energy loss belongs to the susceptible cell and the benefit belongs to the malicious cell. In the early stage of model evolution, the number of latent cells is relatively small, and the immune cells will affect their own probability of sending immune repair programs according to the detection probability of susceptible cells (receiving immune repair programs). But with the increase of the proportion of latent cells in the cell set, the immune cells will tend to send immune repair programs outside. The susceptible cells will decide whether to attack and detect according to the attack probability of malicious cells, and also decide whether to accept immune repair programs according to the immune repair probability of immune cells. In the internal attack mode, the malicious cells no longer decide whether to attack (spread malicious programs or viruses) according to the detection attack probability of susceptible cells. The success rate of the modified and encrypted malicious programs or viruses attacking the susceptible cells is 1, and the latent cells will attack all cells except the malicious cells without distinction, greatly improving the success rate of malicious cell attacks.

[0047] When the attack probability of malicious cells is greater than , the susceptible nodes will choose the detection action strategy, which will also make the detection probability gradually increase. When the detection probability of susceptible cells is greater than , but the malicious cells will still adopt the attack action strategy. The purpose of internal attack is to improve the success rate of attack with the help of latent cells. The immune cells will choose the action strategy of sending immune repair programs, which will also make the detection probability of susceptible cells gradually decrease. When the detection probability of susceptible cells is less than , the immune cells will choose not to adopt the action strategy of sending immune repair programs, which will also make the detection probability of susceptible cells gradually increase.

[0048]

[0049] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the attack and defense game of the SIRQ neighbor cell model.

[0050] (2) SIQ both attack and defense game:

[0051] E uS(SRQ) = x * y * (a1-b1-e S1 ) + (1-x) * y * (-2b1-e I12 ) + x * (1-y) * (-e I12 ) S1

[0052] E uI(SRQ) = x * y * (-a1+b1-e I12 ) + (1-x) * y * (2b1-e I12 ) + x * (1-y) * (-e I11 ) + (1-x) * (1-y) * (-e I11 )

[0053] Let there be:

[0054] So there is the equation:

[0055]

[0056] The solution of the equation group is

[0057]

[0058] When , the expected income of the malicious cell launching a malicious program or virus attack is equal to the expected income of not taking the attack.

[0059] When , the expected income of the malicious cell launching a malicious program or virus attack is greater than the expected income of not taking the attack.

[0060] When , the expected income of the malicious cell launching a malicious program or virus attack is less than the expected income of not taking the attack.

[0061] When , the expected income of the susceptible cell taking detection is equal to the expected income of not taking detection.

[0062] When , ​The expected benefit of the susceptible cell taking detection is greater than the expected benefit of not taking detection.

[0063] When , The expected benefit of the susceptible cell taking detection is less than the expected benefit of not taking detection.

[0064] In the SIQ neighbor cell double attack and defense game, S is as the defense side relative to I and Q, and I and Q are as the attack side relative to S, so according to the function benefit table and the function expected benefit formula of the SIQ neighbor cell, in order to pursue the maximum of the expected benefit of the susceptible and malicious cells, whether the susceptible cell takes detection is closely related to whether the malicious cell attacks, so there is a mixed Nash equilibrium strategy solution in the incomplete information game in this case.

[0065] According to the above analysis, in the SIQ neighbor cell model three-party attack and defense game, the susceptible cell will decide whether to take detection attack according to the attack probability of the malicious cell, that is, even if the detection attack is successful, it cannot block the attack success, and the malicious cell will decide whether to launch an attack (propagate the modified and encrypted malicious program or virus) according to the probability of the susceptible cell taking detection attack, the latent cell will continuously attack the susceptible cell, and the susceptible cell cannot detect this attack, the energy consumption of launching an attack is the energy consumption cost of the susceptible cell, and the attack success benefit is the benefit of the malicious cell, so that the attack success probability of the malicious cell increases but the energy consumption decreases.

[0066] When the attack probability of the malicious cell is greater than , the susceptible node will select the detection action strategy, which will also make the detection probability gradually increase, when the detection probability of the susceptible cell is greater than , the malicious cell will select the non-attack action strategy, which will also make the attack probability of the malicious cell gradually decrease, when the attack probability of the malicious cell is lower than , the susceptible cell will select the non-detection action strategy, which will also make the detection probability gradually decrease, when the detection probability of the susceptible cell is less than , the malicious cell will select the attack action strategy, which will also make the attack probability of the malicious cell gradually increase.

[0067]

[0068] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the SIQ neighbor cell model attack and defense game.

[0069] (3) SRQ double attack and defense game:

[0070] E us(SRQ)= x * z * (-c1 - e S1 ) + x * (1 - z) * (-e S1 )

[0071] E uR(SRQ) = x * z * (c1 - e R1 ) + (1 - x) * z * (-e R1 )

[0072] In the SRQ neighbor cell game, S and Q are the defense side relative to R, and R is the attack side relative to S and Q. Therefore, according to the function profit table and the function expected profit formula of the SRQ neighbor cell, the expected profit of S should always be a positive profit. In order to make E uS(SRQ) reach the maximum value, that is, when z = 0 and x = 1, E uS(SRQ) reaches the maximum value. Therefore, the incomplete information game in this case has a mixed Nash equilibrium strategy solution.

[0073] In the SRQ neighbor cell model three-party attack and defense game, the expected profit of the susceptible cell is negative whether it is detected or not. Therefore, the immune cell will definitely adopt the behavior strategy of sending the immune repair program. For the immune cell, whether the susceptible cell adopts the behavior measure of detection (receiving the immune repair program) or not, the latent cell will attack the susceptible cell and convert it into a latent cell. Therefore, the immune cell will adopt the behavior strategy of sending the immune repair program and no longer need to satisfy the necessary condition that the susceptible cell is in the detection (receiving the immune repair program) state.

[0074]

[0075] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the SIQ neighbor cell model attack and defense game.

[0076] (4) IRQ two-party attack and defense game:

[0077] E uI(IRQ) = y * z * (-c1 + 2 * b1 - e I12 ) + (1 - y) * z * (-c1 - e I11 ) + y * (1 - z) * (2 * b1 - e I12 ) + (1 - y) * (1 - z) * (-e I12 )

[0078] E uR(IRQ) = y * z * (2 * c1 - e I12 ) + (1 - y) * z * (c1 - e R1 )

[0079] In the three-party attack and defense game of the IRQ neighbor cell, I and Q are the defense party relative to R, and R is the attack party relative to I and Q, so according to the function income table and the function expected income formula of the SIR neighbor cell, the expected income of I should never be positive, E uI(IRQ) In order to obtain the maximum value, that is, when z = 0 and y = 0, E uI(IRQ) reach the maximum, and for the expected income of R, the value of y (0 ≤ y ≤ 1) does not affect the expected income of R, which is always positive, so there is a mixed Nash equilibrium strategy solution in this case.

[0080] According to the above analysis, in the two-party attack and defense game of the IRQ neighbor cell model, the malicious cell cannot attack the susceptible cell regardless of whether it attacks, so it cannot provide income for the malicious cell, and its expected income is negative, while the immune cell will definitely send an immune repair program to maximize its own income. For the immune cell, because the immune repair probability of the immune cell The action strategy income of the immune repair of the malicious cell will be greater than the loss consumed, and the malicious cell will adopt the behavior strategy of not attacking in order to reduce its own loss in the case of being immune repaired.

[0081]

[0082] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the attack and defense game of the IRQ neighbor cell model.

[0083] Compared with the prior art, the malicious program propagation attack and defense game method under the intelligent fishery provided by the present application has the following beneficial effects:

[0084] 1. The malicious program propagation attack and defense game method under the intelligent fishery, in the two-party attack and defense game of the IRQ neighbor cell model, the malicious cell cannot attack the susceptible cell regardless of whether it attacks, so it cannot provide income for the malicious cell, and its expected income is negative, while the immune cell will definitely send an immune repair program to maximize its own income.

[0085] 2. The malicious program propagation attack and defense game method under the intelligent fishery, in the three-party attack and defense game of the SRQ neighbor cell model, the expected income of the susceptible cell is negative regardless of whether it detects, so the immune cell will definitely send an immune repair program. For the immune cell, regardless of whether the susceptible cell adopts the behavior measure of detection (receiving the immune repair program), the latent cell will attack the susceptible cell and convert it into a latent cell, so the immune cell will adopt the behavior strategy of sending the immune repair program, and there is no need to satisfy the necessary condition that the susceptible cell is in the detection (receiving the immune repair program) state. Attached Figure Description

[0086] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort:

[0087] Fig. 1 This is a schematic diagram of the overall process structure of an embodiment of the present invention;

[0088] Fig. 2 This is a schematic diagram of the structural cell state transition in an embodiment of the present invention;

[0089] Fig. 3 This is a schematic diagram of the cell attack method in an embodiment of the present invention. Detailed Implementation

[0090] Example

[0091] Please see Figs. 1-3 The malicious program propagation attack and defense game method provided in this embodiment of the invention includes the following steps:

[0092] S1: Construct a cell state transition diagram based on the SIRQ infectious disease model and the attack-defense game model of the AUV and UWSNs collaborative system.

[0093] S2: Define the parameters of the attack and defense game strategy based on the cell state transformation relationship.

[0094] S3: Establish a function payoff table and payoff function based on incomplete information game theory.

[0095] S4: Solve for the mixed Nash equilibrium strategy using the payoff function.

[0096] S5: Analyze cell behavior strategies using a hybrid Nash equilibrium strategy.

[0097] The cell states in step S2 include susceptible cells, malicious cells, immune cells, and latent cells.

[0098] Susceptible cells can communicate normally with surrounding cells. This communication between cells results in energy loss. Susceptible cells can detect attacks from malicious cells, but malicious cells can modify and encrypt malicious programs or viruses before spreading them to susceptible cells, turning them into latent cells. When susceptible cells are receiving program patches from immune cells, the immune cells can transform them into immune cells through immune recovery.

[0099] The malicious cell can normally communicate with the surrounding cells, that is, it can interact to propagate normal information, and it does not propagate malicious programs or viruses. Normal communication requires a certain energy cost. The malicious cell can attack the susceptible cell. If the attack on the susceptible cell is successful, the susceptible cell will be transformed into a latent cell. The attack of the malicious program or virus requires more energy cost. The attack is successful and a benefit is generated. The attack of the malicious cell on the immune cell is invalid, and the immune cell can transform the malicious cell into an immune cell through immune recovery.

[0100] The immune cell can perform normal cell communication, and can transform the susceptible cell, the malicious cell and the latent cell into an immune cell through immune recovery. Normal cell communication and the initiation of immune recovery work require a certain energy cost.

[0101] The latent cell nominally belongs to the susceptible cell, but it carries and propagates malicious programs or viruses, so it is essentially a malicious cell. Its attack on the susceptible cell can be directly successful, transforming the susceptible cell into a malicious cell. The attack on the immune cell is invalid, and the immune cell can transform the latent cell into an immune cell through immune recovery.

[0102] Research on intrusion detection and malicious program propagation, risk failure propagation from one direction to another risk-free failure is defined as an attack. Different attack methods are analyzed to further obtain risk failure propagation attack and defense strategy. Existing cell attacks are mostly external attacks, that is, the first type of cell directly attacks the second type of cell. The success rate of its attack is affected by both parties. In fact, there is another way of external attack, that is, the second type of cell is transformed into the third type by the first type of cell, so that its internal essence is the former, but its external characteristics are the latter. Then the third type of cell attacks the second type of cell, and the success rate of the attack is greatly increased.

[0103] The symbol definition table of the SIRQ model is Table 1. In Table 1: a1>e S1 > 0; b1>e I12 > e I11 > 0; c1>e R1 > 0; When the susceptible cell is in a detection state, the immune cell receives the detection state of the susceptible cell and transforms the susceptible cell into an immune cell. The susceptible cell is transformed into a latent cell by the malicious cell, and the susceptible cell is transformed into a malicious cell by the latent cell. The malicious cell is transformed into a susceptible cell by the immune cell, the susceptible cell is transformed into an immune cell by the immune cell, and the latent cell is transformed into an immune cell by the immune cell. The above process is an independent process. S: susceptible cell, I: malicious cell, R: immune cell, Q: latent cell.

[0104] Table 1 Symbol definition of SIRQ model

[0105]

[0106] First, the malicious program propagation model of WSN is constructed, and the participants of the model are established, which can be divided into SIRQ four parties, SIQ three parties, SRQ three parties and IRQ three parties. According to the symbol definition in Table 1, the function relationship between the participants of the model is written, and the function income table is listed in the form of table.

[0107] Table 2(a) SIRQ neighbor cell-function income table

[0108]

[0109] Table 2(b) SIRQ neighbor cell-function income table

[0110]

[0111] Table 2(c) SIRQ neighbor cell-function income table

[0112]

[0113] According to the function income table 2, the income function expression of each participant under each model is constructed according to the income expectation formula, and the attack and defense game behavior between the four parties or three parties of the susceptible node, malicious node, immune node and latent node is analyzed from the perspective of game theory, and the malicious program propagation process of AUV, UWSNs collaborative system driven by game strategy is further researched and discussed, and the mixed Nash equilibrium strategy solution of the attack and defense game of each model is obtained.

[0114] SIQ, SRQ, IRQ three parties as neighbors at the same time income table:

[0115] Table 3 SIQ neighbor cell-function income table

[0116]

[0117] Table 4 SRQ neighbor cell-function income table

[0118]

[0119] Table 5 IRQ neighbor cell-function income table

[0120]

[0121] The income function formula is shown in Tables 3-5.

[0122] According to the 4-function revenue table, the revenue function expression of each participant under each model is constructed according to the revenue expectation formula, and the attack and defense game behaviors among the four parties or three parties of the susceptible node, malicious node, immune node and latent node are analyzed from the perspective of game theory, and the malicious program propagation process of the AUV and UWSNs collaborative system driven by the game strategy is further researched and discussed, and the mixed Nash equilibrium strategy solution of the attack and defense game of each model is obtained:

[0123] (1) SIRQ four-party attack and defense game:

[0124] E uS(SIRQ) = x * y * z * (a1-2c1-b1-e S1 -e I12 ) + (1-x) * y * z * (-b1-e I12 ) + (1-x) * y * (1-z) * (a1-b1-e S1 -e I12 ) + (1-x) * y * (1-z) * (-b1-e I12 ) + x * (1-y) * z * (-c1-e S1 ) + x * (1-y) * (1-z) * (-e S1 )

[0125] E uI(SIRQ) = * y * z * (-a1+2b1-c1-e I12 ) + x * (1-y) * z * (-c1-e I11 ) + x * y * (1-z) * (-a1+2b1-e I12 ) + x * (1-y) * (1-z) * (-e I11 ) + (1-x) * y * z * (2*b1-c1-e I12 ) + (1-x) * (1-y) * z * (-c1-e I11 ) + (1-x) * y * (1-z) * (2*b1-e I12 ) + (1-x) * (1-y) * (1-z) * (-e I11 )

[0126] E uR(SIRQ) = x * y * z * (3c1-e R1 ) + x * (1-y) * z * (c1-e R1 ) + (1-x) * y * z * (2c1-e R1 ) + (1-x) * (1-y) * z * (c1-e R1 )

[0127] And the mixed Nash equilibrium strategy of SIRQ four-party attack-defense game can be known that z = 1, then:

[0128] E uS(SIRQ) = (a1*y-e S1 -b1*y-c1*z-e I12 *y-z*y*c1)*x+b1*y*z-y *e I12 -y*b1+e I12 *y*z

[0129] E uI(SIRQ) = (-a1*y)*x+2b1*y-e I11 -c1*z+e I11 *y-e I12 *y

[0130] E uR(SIRQ) =c1*z*y+z*(c1-e R1 )

[0131] Let There are:

[0132]

[0133]

[0134]

[0135] There are equations:

[0136] The solution of the equation group is

[0137] When , The expected income of the malicious cell launching a malicious program or virus attack is equal to the expected income of not taking the attack.

[0138] When , The expected income of the malicious cell launching a malicious program or virus attack is greater than the expected income of not taking the attack.

[0139] When , The expected income of the malicious cell launching a malicious program or virus attack is less than the expected income of not taking the attack.

[0140] When , The expected income of the susceptible cell taking detection is equal to the expected income of not taking detection.

[0141] When When The susceptible cell chooses to detect with an expected payoff that is greater than the expected payoff without detecting.

[0142] When The susceptible cell chooses to detect with an expected payoff that is less than the expected payoff without detecting. The susceptible cell chooses to detect with an expected payoff that is less than the expected payoff without detecting.

[0143] When The immune cell chooses to detect with an expected payoff that is equal to the expected payoff without detecting. The immune cell chooses to detect with an expected payoff that is greater than the expected payoff without detecting.

[0144] When The immune cell chooses to detect with an expected payoff that is less than the expected payoff without detecting. The immune cell chooses to detect with an expected payoff that is less than the expected payoff without detecting.

[0145] When The immune cell chooses to detect with an expected payoff that is less than the expected payoff without detecting. The immune cell chooses to detect with an expected payoff that is less than the expected payoff without detecting.

[0146] In the SIRQ neighbor cell four-attack-defense game, S is the defense side relative to I, R, and Q; I is the attack side relative to S and the defense side relative to R and the cooperation side relative to Q; R is the attack side relative to S, I, and Q; and Q is the defense side relative to R and the attack side relative to S. Therefore, according to the function payoff table and the function expected payoff formula of the SIRQ neighbor cell, there is a mixed Nash equilibrium strategy solution in the incomplete information game in this case. The above formula is arranged as follows:

[0147] According to the above analysis, in the SIRQ neighbor cell model four-attack-defense game, the latent cell has special existence, and its energy loss belongs to the susceptible cell and the payoff belongs to the malicious cell. In the early stage of model evolution, the number of latent cells is relatively small, and the immune cell will affect its own sending immune repair program probability according to the detection probability of the susceptible cell (receiving immune repair program). However, with the increase of the proportion of latent cells in the cell set, the immune cell will tend to send the immune repair program outside. The susceptible cell will decide whether to detect attack according to the attack probability of the malicious cell, and also decide whether to accept the immune repair program according to the immune repair probability of the immune cell. In the internal attack mode, the malicious cell no longer decides whether to launch an attack (spread malicious programs or viruses) according to the detection attack probability of the susceptible cell. The success rate of the modified and encrypted malicious program or virus attacking the susceptible cell is 1, and the latent cell will attack all cells except the malicious cell without distinction, greatly improving the success probability of the malicious cell attack.

[0148] When the attack probability of malicious cells is greater than , the susceptible node will choose to adopt the detection action strategy, which will also make the detection probability gradually increase, when the detection probability of susceptible cells is greater than , but the malicious cells will still adopt the attack action strategy, the internal attack aims to improve the success rate of attack by means of latent cells, the immune cells will choose to adopt the action strategy of sending immune repair program, which will also make the detection probability of susceptible cells gradually decrease, when the detection probability of susceptible cells is less than , the immune cells will choose not to adopt the action strategy of sending immune repair program, which will also make the detection probability of susceptible cells gradually increase.

[0149]

[0150] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the attack and defense game of SIRQ neighbor cell model.

[0151] (2) SIQ both attack and defense game:

[0152] E uS(SRQ) = x * y * (a1-b1-e S1 -e I12 ) + (1-x) * y * (-2b1-e I12 ) + x * (1-y) * (-e S1 )

[0153] E ul(SRQ) = x * y * (-a1+b1-e I12 ) + (1-x) * y * (2b1-e I12 ) + x * (1-y) * (-e I11 ) + (1-x) * (1-y) * (-e I11 )

[0154] Let there is:

[0155] So there is the equation group:

[0156]

[0157] The solution of the equation group is

[0158]

[0159] When , the expected income of malicious cells launching a malicious program or virus attack is equal to the expected income of not taking attack.

[0160] When When The expected payoff of a malicious cell initiating a spread of a malicious program or virus attack is greater than the expected payoff of not taking the attack.

[0161] When The expected payoff of a malicious cell initiating a spread of a malicious program or virus attack is less than the expected payoff of not taking the attack. When

[0162] The expected payoff of a susceptible cell taking a detection is equal to the expected payoff of not taking the detection. When The expected payoff of a susceptible cell taking a detection is greater than the expected payoff of not taking the detection.

[0163] When The expected payoff of a susceptible cell taking a detection is less than the expected payoff of not taking the detection.

[0164] When The expected payoff of a susceptible cell taking a detection is less than the expected payoff of not taking the detection. In the SIQ neighbor cell double attack and defense game, S is as a defense side relative to I and Q, and I and Q are as attack sides relative to S, so according to the function payoff table and the function expected payoff formula of the SIQ neighbor cell, in order to pursue the maximum of the expected payoffs of the susceptible and malicious cells, whether the susceptible cell takes a detection is closely related to whether the malicious cell attacks, so there is a mixed Nash equilibrium strategy solution in the incomplete information game in this case.

[0165] According to the above analysis, in the SIQ neighbor cell model three-party attack and defense game, the susceptible cell will decide whether to take a detection attack according to the attack probability of the malicious cell, that is, even if the detection attack succeeds, the attack cannot be blocked, the latent cell will continuously attack the susceptible cell, and the susceptible cell cannot detect the attack, the energy consumption of the attack is the energy consumption cost of the susceptible cell, and the attack success payoff is the payoff of the malicious cell, so that the attack success probability of the malicious cell increases but the energy consumption decreases.

[0166] When the attack probability of the malicious cell is greater than

[0167] , the susceptible node will select the detection action strategy, which will also make the detection probability gradually increase, when the detection probability of the susceptible cell is greater than , the malicious cell will select the non-attack action strategy, which will also make the attack probability of the malicious cell gradually decrease, when the attack probability of the malicious cell is lower than , the susceptible cell will select the non-detection action strategy.​ When the probability of detection is less than When the probability of detection is less than

[0168]

[0169] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the SIQ neighbor cell model for attack and defense game.

[0170] (3) SRQ both sides attack and defense game:

[0171] E uS(SRQ) = x * z * (-c1-e S1 ) + x * (1-z) * (-e S1 )

[0172] E uR(SRQ) = x * z * (c1-e R1 ) + (1-x) * z * (-e R1 )

[0173] In the SRQ neighbor cell both sides attack and defense game, S and Q are as the defense side relative to R, and R is as the attack side relative to S and Q, so according to the function income table of SRQ neighbor cell and the function expected income formula, the expected income of S should always be not positive, in order to make E uS(SRQ) reach the maximum value, that is, when z = 0 and uS(SRQ) reach the maximum, so the incomplete information game in this case exists a mixed Nash equilibrium strategy solution.

[0174] In the SRQ neighbor cell model three sides attack and defense game, the expected income of susceptible cell is negative whether it detects or not, so the immune cell will adopt the behavior strategy of sending immune repair program, and for the immune cell, the latent cell will attack the susceptible cell and convert it into latent cell whether the susceptible cell adopts the behavior measure of detection (receiving immune repair program) or not, so the immune cell will adopt the behavior strategy of sending immune repair program, and no longer need to satisfy the necessary condition that the susceptible cell is in the detection (receiving immune repair program) state.

[0175]

[0176] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the SIQ neighbor cell model for attack and defense game.

[0177] (4) IRQ both sides attack and defense game:

[0178] EuI(SRQ) = y * z * (-c1 + 2 * b1 - e I12 ) + (1 - y) * z * (-c1 - e I11 ) + y * (1 - z) * (2 * b1 - e I12 ) + (1 - y) * (1 - z) * (-e I12 )

[0179] E uR(IRQ) = y * z * (2 * c1 - e I12 ) + (1 - y) * z * (c1 - e R1 )

[0180] In the IRQ neighbor cell three-party attack and defense game, I and Q are as the defense party relative to R, and R is as the attack party relative to I and Q, so according to the function income table and the function expected income formula of the SIR neighbor cell, the expected income of I should never be positive income, E uI(IRQ) for the maximum value, that is, when z = 0 and y = 0, E uI(IRQ) reaches the maximum, and for the expected income of R, the value of y (0 ≤ y ≤ 1) does not affect the expected income of R, and the expected income of R is always positive income, so there is a mixed Nash equilibrium strategy solution in this case of incomplete information game.

[0181] From the above analysis, in the IRQ neighbor cell model two-party attack and defense game, whether the malicious cell attacks or not, the latent cell cannot attack the susceptible cell and thus cannot provide income for the malicious cell, and the expected income of the malicious cell is negative, while the immune cell will definitely send an immune repair program to maximize its own income. For the immune cell, because the immune repair probability of the immune cell The action strategy income of the immune cell to the malicious cell will be greater than the loss consumed, and the malicious cell will adopt the behavior strategy of not attacking in order to reduce its own loss in the case of being immune repaired.

[0182]

[0183] Therefore, the above formula is the mixed Nash equilibrium strategy solution of the IRQ neighbor cell model attack and defense game.

[0184] The malicious program propagation attack and defense game method provided by the above-mentioned embodiments of the present application, in the SRQ neighbor cell model three-party attack and defense game, the expected income of the susceptible cell is negative whether the susceptible cell is detected or not, so the immune cell will definitely adopt the immune repair program sending behavior strategy, and for the immune cell, whether the susceptible cell adopts the detection (immune repair program receiving) behavior measure or not, the latent cell will attack the susceptible cell and convert the susceptible cell into the latent cell, so the immune cell will definitely adopt the immune repair program sending behavior strategy, and no longer needs to meet the necessary condition that the susceptible cell is in the detection (immune repair program receiving) state.

[0185] It should be noted that, in this document, the terms such as first and second are used merely to distinguish one entity or action from another entity or action, and do not necessarily require or imply that these entities or actions are in any way mutually exclusive or in any way arranged or ordered in succession. Moreover, the terms "comprise", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or devices including a series of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of additional identical elements in the process, method, article or device including the element.

[0186] Although the embodiments of the present application have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A method for malicious program propagation attack-defense game in smart fishery, characterized in that, The method comprises the following steps: S1: constructing a cell state transformation graph of an AUV and UWSNs cooperative system attack-defense game model based on a SIRQ infectious disease model; the cell states include susceptible cells S, malicious cells I, immune cells R, and latent cells Q; The malicious cells are modified and encrypted and then spread to the susceptible cells, converting the susceptible cells into latent cells; when the susceptible cells receive a program patch from the immune cells, the immune cells can convert the susceptible cells into immune cells through immune recovery; The latent cells carry and spread malicious programs or viruses, which can directly convert the susceptible cells into malicious cells through attacks, and the attacks on the immune cells are invalid; the immune cells can convert the latent cells into immune cells through immune recovery; S2: defining attack-defense game strategy parameters according to the cell state transformation relationship; S3: establishing a function income table and an income function formula based on an incomplete information game; S4: solving a mixed Nash equilibrium strategy solution based on the income function formula, wherein the mixed Nash equilibrium strategy is: Wherein, a1 represents the benefit of the susceptible cell detecting the malicious program or virus, and the loss of the malicious cell attacking the identification; b1 represents the benefit of the malicious cell attacking the susceptible cell successfully, the loss of the susceptible cell being infected by the malicious program, the benefit of the immune cell converting the malicious cell into the susceptible cell, and the loss of the malicious cell being converted into the susceptible cell by the immune cell; c1 represents the benefit of the immune cell converting the susceptible cell, the latent cell into the immune cell, and the loss of the susceptible cell, the latent cell being converted into the immune cell by the immune cell; es1 represents the energy cost of the susceptible cell detecting the malicious program; e I11 represents the energy cost of the malicious cell sending the non-encrypted information; e I12 represents the energy cost of the malicious cell or the latent cell sending the encrypted malicious program or virus; e R1 represents the energy cost of the immune cell sending the normal information or the immune recovery program; The mixed Nash equilibrium strategy solution of the SIQ neighbor cell model for attack-defense game is as follows: The mixed Nash equilibrium strategy solution of the SRQ neighbor cell model for attack-defense game is as follows: The mixed Nash equilibrium strategy solution of the IRQ neighbor cell model for attack-defense game is as follows: S5: analyzing cell behavior strategies through the mixed Nash equilibrium strategy solution.

2. The method of claim 1, wherein the method further comprises: The susceptible cells can normally communicate with surrounding cells, and the communication between cells causes energy loss, and the susceptible cells can detect attacks from malicious cells. 3.The method of claim 1, wherein the method further comprises: The malicious cells can normally communicate with surrounding cells, which is manifested as normal information interaction and no spread of malicious programs or viruses; normal communication needs to consume a certain amount of energy cost; the malicious cells can attack the susceptible cells, and if the attack on the susceptible cells is successful, the susceptible cells will be converted into latent cells; launching a modified and encrypted malicious program or virus attack needs to consume more energy cost, and an income is generated if the attack is successful; the attacks of the malicious cells on the immune cells are invalid, and the immune cells can convert the malicious cells into immune cells through immune recovery.

4. The method of claim 1, wherein the method further comprises: The immune cells can normally communicate with cells, and can also convert the susceptible cells, malicious cells, and latent cells into immune cells through immune recovery; normal cell communication and immune recovery need to consume a certain amount of energy cost.

Citation Information

Patent Citations

  • WSN attack and defense game method based on non-cooperative game

    CN112822682A