A network effect comprehensive evaluation method, system, device and medium

By establishing an indicator system for both the attacker and the attacked side, and combining game theory methods with an embedded evaluation model, the problem of the single nature of existing network attack evaluation methods is solved. This enables a comprehensive, multi-faceted evaluation of complex network attacks, improving the accuracy and comprehensiveness of the evaluation results.

CN116455656BActive Publication Date: 2026-05-12XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XI AN JIAOTONG UNIV
Filing Date
2023-04-27
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

现有的网络攻击效果评估方法较为单一,无法全面自适应地评估复杂网络攻击,忽略了指标数据之间的关联性和冲突性,影响评估结果的精确性。

Method used

Establish an attack cost indicator system for the attacking side and an attack effect indicator system for the attacked side. Use game theory to combine subjective and objective weight vectors, and conduct a comprehensive evaluation by integrating variable weight vectors and combining embedded evaluation models.

Benefits of technology

It enables a comprehensive, multi-faceted assessment of both the offensive and defensive sides, overcoming the limitations of unilateral empowerment and improving the accuracy and comprehensiveness of the assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455656B_ABST
    Figure CN116455656B_ABST
Patent Text Reader

Abstract

The application provides a network effect comprehensive evaluation method, system, device and medium, relates to the technical field of network effect comprehensive evaluation, and comprises the following steps: through complex network attacks carried out by n attackers, attack cost index system and attack effect index system on both attack and defense sides are established; the attack cost index and index data are collected and standardized, and standardized index data on both sides is obtained; subjective weight and objective weight of the index are subjected to variable weight processing, and based on a game method, a comprehensive variable weight weight vector is obtained; the standardized index data on both sides and the comprehensive variable weight weight vector are combined, based on a combined embedded comprehensive evaluation model, corresponding evaluation results are obtained, and the evaluation results on both attack and defense sides are comprehensively obtained, so that the comprehensive evaluation result of the whole network attack action is obtained. The network effect comprehensive evaluation method can be used for comprehensive evaluation of both attack and defense sides in a complex network attack environment, and can comprehensively evaluate the security situation of the whole network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of comprehensive network performance evaluation technology, and in particular to a method, system, device and medium for comprehensive network performance evaluation. Background Technology

[0002] With the development of the internet and information technology, and facing a complex network environment, various types of cyberattacks are emerging one after another. Attackers' attack methods are becoming increasingly diversified, and attacks are showing multi-source characteristics. The types and frequency of attacks on networks and facilities are increasing year by year, making the network security situation extremely serious. Moreover, the era of the Internet of Things has given hackers more opportunities to attack, and the entire network security environment is facing new challenges. Therefore, evaluating the effects of cyberattacks is of great practical significance.

[0003] Existing methods for evaluating the effectiveness of cyberattacks mostly focus on the perspective of the attacked party, resulting in relatively simplistic evaluation indicator systems. These systems, built solely from the victim's point of view, fail to reflect the dynamic changes in the impact of different attack methods and costs employed by the attacker. When evaluating the effects of one or more cyberattacks, the unilateral weighting of indicators ignores the correlations and conflicts between indicator data, ultimately affecting the accuracy of the evaluation results. Furthermore, current evaluation methods are rather simplistic and require more comprehensive evaluation models for adaptive assessment of complex cyberattacks. A holistic evaluation of cyberattacks helps to gain a more comprehensive understanding of attack behavior, quantitatively and qualitatively assess attack effects, measure the harm caused by attacks, and guide network systems to improve their defense capabilities, ensuring the security and stability of system operation. Summary of the Invention

[0004] This invention provides a comprehensive evaluation method, system, device, and medium for network effects, in order to solve the problem that existing evaluation methods are relatively singular and cannot comprehensively and adaptively evaluate network attacks.

[0005] In a first aspect, embodiments of the present invention provide a method for comprehensive evaluation of network performance, the method comprising:

[0006] For a complex network attack carried out by n attackers, establish an attack cost index system on the attacking side and an attack effect index system on the attacked side, where n is an integer greater than or equal to 1.

[0007] Based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types, a mapping relationship of "type-attribute" and "type-pattern" is formed. According to the attribute layer and the pattern layer, the corresponding attack cost index of the attack side and the attack effect index of the attacked side are matched respectively. The index data corresponding to the attack cost index and the attack effect index are collected and standardized to obtain standardized index data on both sides.

[0008] The subjective and objective weights of the indicators are transformed into subjective and objective weight vectors. The subjective and objective weight vectors are then combined using a game theory method to obtain a comprehensive weight vector.

[0009] By combining the standardized index data from both sides and the comprehensive variable weight vector, weighted normalized index data matrices for the attacking and attacked sides are obtained respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized index data matrices for the attacking and attacked sides are evaluated respectively to obtain the corresponding evaluation results. By combining the evaluation results of the attacking and attacked sides, the comprehensive evaluation result of the entire network attack operation is obtained.

[0010] Based on the first aspect, the establishment of an attack cost index system on the attacking side and an attack effect index system on the attacked side includes:

[0011] For the attacking side, an attack cost indicator system of "target-attribute-indicator" is established by combining the attacker's factors and attributes. The attacker's factors include attack attributes, attack methods, attack costs, and attacking side resources and network consumption. The attributes include availability, confidentiality, and cost.

[0012] For the attacked side, a three-tiered attack effect indicator system of "target-mode-indicator" is established, combining factors of the attacking device and the attack mode. The factors of the attacking device include changes in system resources, performance, network, and operational stability. The modes include resource consumption mode, manipulation configuration mode, privilege acquisition mode, interactive deception mode, and service exploitation mode.

[0013] Based on the first aspect, obtaining the standardized indicator data on both sides also includes:

[0014] The single attack type is determined by matching the attack pattern with the attack cost index and the attack effect index based on the attacker's attack attributes and attack purpose.

[0015] The combined attack type of the various attacks is based on the aggregation of specific indicators under each mode and the attack cost indicators on the attacker side and the attack effect indicators on the attacked side.

[0016] Based on the first aspect, the comprehensive variable weight vector is obtained through the following steps:

[0017] Based on expert experience, the importance of the relevant indicators is compared pairwise according to the bubble sort method, and then sorted according to the degree of importance to obtain the indicator importance ranking queue.

[0018] Based on the importance ranking queue of the indicators, the importance between two adjacent indicators is calculated in turn to obtain the importance ratio between adjacent indicators;

[0019] Based on the importance ratio between the adjacent indicators and subjective judgment, a subjective variable weight vector is obtained;

[0020] Based on the conflict, correlation and dispersion of the indicators, and combined with the information entropy of the indicators, an objective variable weight vector is obtained.

[0021] Based on game theory, this paper adopts the conflict between Nash equilibrium indicators and utilizes the inherent information of indicator weights to determine the comprehensive variable weight vector by taking the common interest maximization point between different indicators as the optimal linear combination weight coefficient.

[0022] Based on the first aspect, the comprehensive evaluation results are obtained through the following steps:

[0023] Construct a weighted normalized index data matrix based on the comprehensive variable weight vector;

[0024] Load the combined embedded evaluation model to determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix;

[0025] Calculate the correlation coefficients of the indicators and construct the correlation coefficient matrix;

[0026] The correlation coefficient matrix is ​​used to calculate the correlation degree between each index data and the positive and negative ideal solution reference vectors;

[0027] Calculate the Euclidean distance between the indices of different evaluation objects and the reference vectors of positive and negative ideal solutions;

[0028] By integrating the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects, the overall closeness of different evaluation objects is calculated.

[0029] Based on the comprehensive proximity of different evaluation objects, the same order of magnitude evaluation results are calculated for both the attacking and attacked sides. Combining the evaluation results from both the attacking and defending sides, a comprehensive evaluation result of the overall attack is obtained.

[0030] In a second aspect, embodiments of the present invention provide a comprehensive network performance evaluation system, the system comprising:

[0031] The two-sided indicator system construction subsystem is used to establish an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side for complex network attacks by n attackers, where n is an integer greater than or equal to 1.

[0032] The indicator data processing subsystem is used to form a mapping relationship of "type-attribute" and "type-pattern" based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types. According to the attribute layer and the pattern layer, the corresponding attack cost indicator on the attacking side and the attack effect indicator on the attacked side are matched respectively. The indicator data corresponding to the attack cost indicator and the attack effect indicator are collected and standardized to obtain standardized indicator data on both sides.

[0033] The game theory index variable weight subsystem is used to perform variable weight processing on the subjective and objective weights of the index to obtain subjective variable weight vectors and objective variable weight vectors. The subjective and objective variable weight vectors are combined using game theory methods to obtain a comprehensive variable weight vector.

[0034] The comprehensive evaluation subsystem is used to combine the standardized indicator data from both sides and the comprehensive variable weight vector to obtain weighted normalized indicator data matrices for the attacking side and the attacked side, respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized indicator data matrices for the attacking side and the attacked side are evaluated to obtain the corresponding evaluation results. The comprehensive evaluation results of the entire network attack operation are obtained by combining the evaluation results of the attacking side and the attacked side.

[0035] Based on the second aspect, the game-theoretic index variable weight subsystem is further configured as follows:

[0036] The importance ranking module is used to compare the importance of relevant indicators pairwise according to the bubble sort algorithm based on expert experience, and sort them according to the degree of importance to obtain the indicator importance ranking queue.

[0037] The importance ratio calculation module is used to calculate the importance between two adjacent indicators in turn based on the importance ranking queue of the indicators, and obtain the importance ratio between adjacent indicators.

[0038] The subjective variable weight vector determination module is used to obtain the subjective variable weight vector based on the importance ratio between the adjacent indicators and subjective judgment.

[0039] The objective variable weight vector determination module is used to obtain the objective variable weight vector based on the conflict, correlation and dispersion of the indicators, combined with the information entropy of the indicators.

[0040] The module for determining the comprehensive variable weight vector is used to determine the comprehensive variable weight vector based on game theory, by adopting the conflict between Nash equilibrium indicators, utilizing the inherent information of indicator weights, and taking the optimal linear combination weight coefficients of the common interests of different indicators as the maximization of interests.

[0041] Based on the second aspect, the comprehensive evaluation subsystem is further configured to:

[0042] The weighted normalized index data matrix determination module is used to construct a weighted normalized index data matrix based on the comprehensive variable weight vector;

[0043] The positive and negative ideal solution reference vector determination module is used to determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix;

[0044] The correlation coefficient matrix construction module is used to calculate the correlation coefficients of indicators and construct the correlation coefficient matrix.

[0045] The correlation coefficient calculation module is used to calculate the correlation coefficient between each index data and the positive and negative ideal solution reference vectors from the correlation coefficient matrix.

[0046] The Euclidean distance calculation module is used to calculate the Euclidean distance between the index data of different evaluation objects and the reference vectors of positive and negative ideal solutions;

[0047] The comprehensive proximity calculation module is used to integrate the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects to calculate the comprehensive proximity of different evaluation objects.

[0048] The comprehensive evaluation result calculation module is used to calculate the same-order evaluation results for the attacking side and the attacked side based on the comprehensive proximity of different evaluation objects. By combining the evaluation results of the attacking and defending sides, the comprehensive evaluation result of the overall attack is obtained.

[0049] Thirdly, embodiments of the present invention provide an electronic device, comprising:

[0050] Memory, used to store one or more programs;

[0051] processor;

[0052] When the one or more programs are executed by the processor, the comprehensive network performance evaluation method as described in any one of the first aspects above is implemented.

[0053] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network performance comprehensive evaluation method as described in any one of the first aspects above.

[0054] This invention has the following advantages:

[0055] (1) The embodiments of the present invention establish evaluation index systems from both the offensive and defensive sides. The attacking side establishes a three-layer attack cost index system of "target-attribute-index" and the attacked side establishes a three-layer attack effect index system of "target-mode-index". From different perspectives, a comprehensive understanding of all parties involved in the entire attack operation is formed.

[0056] (2) The embodiments of the present invention propose a comprehensive variable weight index weight vector, which overcomes the limitations of one-sided subjective weighting and objective weighting, and also avoids the immutability of constant weights. It proposes subjective variable weighting, objective variable weighting and comprehensive variable weighting methods, so that the index weights can have a certain degree of variability according to different attack objects and attack targets, and realize the flexible adjustment of index weight assignment.

[0057] (3) The present invention combines existing evaluation models, integrates the advantages of different evaluation models, and adds the correlation coefficient of the index correlation to the evaluation model, so that the evaluation results can more comprehensively combine the correlation of the index data; at the same time, the evaluation is carried out from the attack side and the attacked side respectively to obtain the effect of both the attack and defense sides, and finally combines to obtain a comprehensive evaluation result, realizing a comprehensive evaluation from all aspects and multiple angles. Attached Figure Description

[0058] Figure 1 This is a flowchart of a comprehensive network performance evaluation method provided in an embodiment of the present invention;

[0059] Figure 2 A schematic diagram of an attack cost index system constructed on the attack side, provided in an embodiment of the present invention;

[0060] Figure 3 This is a schematic diagram of an attack effect index system constructed by the attacked side, provided in an embodiment of the present invention;

[0061] Figure 4 A flowchart illustrating a method for obtaining a comprehensive variable weight vector according to an embodiment of the present invention;

[0062] Figure 5 A flowchart illustrating a method for obtaining comprehensive evaluation results from an offensive and defensive two-sided model, provided in an embodiment of the present invention;

[0063] Figure 6 A flowchart illustrating a comprehensive evaluation method for network performance provided in an embodiment of the present invention;

[0064] Figure 7 An architecture diagram of a comprehensive network performance evaluation system provided in an embodiment of the present invention;

[0065] Figure 8 This is a schematic structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0066] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0067] Firstly, this invention provides a method for comprehensive evaluation of network performance, see below. Figure 1 , Figure 1 This is a flowchart of a comprehensive network performance evaluation method provided in an embodiment of the present invention. The method includes the following steps:

[0068] Step S110: For complex network attacks launched by n attackers, establish an attack cost index system on the attacking side and an attack effect index system on the attacked side, where n is an integer greater than or equal to 1.

[0069] For the attacker, a system of attack cost indicators should be established, taking into account factors such as the attacker's attack attributes, attack methods, attack costs, attack complexity, and attack time. For the attacked, a system of attack effect indicators should be established, taking into account factors such as changes in system resources, performance, network, and operational stability of the attacked device.

[0070] Furthermore, the establishment of an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side includes:

[0071] For the attacker, a "target-attribute-indicator" attack cost indicator system is established, combining attacker factors and attributes. The attacker factors include attack attributes, attack methods, attack costs, and attacker-side resource and network consumption. The attributes include availability, confidentiality, and cost. Please refer to the attack cost indicator system constructed for the attacker side. Figure 2 ,exist Figure 2 In this attack cost indicator system, three layers are defined: an indicator layer, an attribute layer, and a target layer. First, the indicator layer is established by acquiring indicators from the attacking side. For example, these indicators could include memory usage, network utilization, CPU utilization, attack stealth, attack complexity, attack time, number of attacking machines, number of attack steps, and attack failure rate. Then, the acquired indicators are categorized according to their attributes to establish an attribute layer. Attributes in this layer can include availability, confidentiality, and cost. For example, availability indicators include memory usage, network utilization, and CPU utilization; confidentiality indicators include attack stealth and attack complexity; and cost indicators include attack time, number of attacking machines, number of attack steps, and attack failure rate. Finally, the target layer, or attack cost indicator system, is established based on the indicator and attribute layers. The corresponding target for the attacking side can be obtained from the attacking side's indicators and attributes through this system.

[0072] For the attacked side, a three-tiered attack effectiveness indicator system of "target-pattern-indicator" is established, combining factors related to the attacking device and the attack pattern. The factors related to the attacking device include changes in system resources, performance, network, and operational stability. The patterns include resource consumption patterns, configuration manipulation patterns, privilege acquisition patterns, interactive deception patterns, and service exploitation patterns. Please refer to the above attack effectiveness indicator system constructed for the attacked side. Figure 3 ,exist Figure 3 In this attack effectiveness indicator system, three layers are defined: an indicator layer, a pattern layer, and a target layer. First, the indicator layer is established by acquiring indicators from the attacked side. For example, indicators from the attacked side can include memory usage, CPU usage, packet loss rate, recovery time, throughput, end-to-end latency, resource damage level, amount of modified information, amount of stolen data, file importance, port probes, IP probes, process damage level, privilege escalation, privilege maintenance, number of vulnerabilities, privilege acquisition level, type of deception, number of deceptions, successful deception rate, deception consequence level, service exploitation type, service control level, service utilization, and impact on normal services. Then, the acquired indicators are categorized according to their patterns to establish a pattern layer. Patterns in the pattern layer can include resource consumption patterns, configuration manipulation patterns, privilege acquisition patterns, interactive deception patterns, and service exploitation patterns. For example, the indicators for resource consumption mode include memory usage, CPU usage, packet loss rate, recovery time, throughput, end-to-end latency, and degree of resource damage; the indicators for configuration manipulation mode include the amount of modified information, the amount of data stolen, file importance, port probes, IP probes, and degree of process damage; the indicators for permission acquisition mode include attack time, number of attacking machines, number of attack steps, and attack failure rate; the indicators for interactive deception mode include deception type, number of deceptions, success rate of deception, and deception consequence level; the indicators for service utilization mode include service utilization type, service control level, service utilization rate, and impact on normal services; based on the indicator layer and mode layer established above, a target layer is established, namely, the attack effect indicator system. The target corresponding to the attacked side can be obtained from the indicators and modes of the attacked side through the attack effect indicator system.

[0073] Step S120: Based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types, form a mapping relationship of "type-attribute" and "type-pattern". Match the corresponding attack cost index on the attacking side and the attack effect index on the attacked side according to the attribute layer and the pattern layer respectively. Collect the index data corresponding to the attack cost index and the attack effect index and perform standardization processing to obtain standardized index data on both sides of the standardization process.

[0074] Furthermore, obtaining the standardized index data on both sides also includes:

[0075] The single attack type is determined by matching the attack pattern with the attack cost index and the attack effect index based on the attacker's attack attributes and attack purpose.

[0076] The combined attack type of the multiple attacks is based on the aggregation of attack cost indicators on the attacking side and attack effect indicators on the attacked side, according to the specific indicators matched under each mode.

[0077] In this embodiment of the invention, the data standardization process is performed using a normalization method, which can be range normalization.

[0078] Step S130: Perform variable weighting on the subjective and objective weights of the indicators to obtain subjective variable weight vectors and objective variable weight vectors. Use a game theory method to combine the subjective and objective variable weight vectors to obtain a comprehensive variable weight vector.

[0079] Furthermore, the integrated variable weight vector is obtained through the following steps:

[0080] Step S301: Based on expert experience, the importance of the relevant indicators is compared pairwise according to the principle of bubble sort, and the indicators are sorted according to their importance to obtain the indicator importance ranking queue.

[0081] From a qualitative perspective, the m indicators are ranked according to their importance. For an m-dimensional evaluation task, the importance of each indicator is compared pairwise using the bubble sort algorithm, ultimately resulting in a ranking queue of indicator importance. The importance of sequences satisfies the following conditions:

[0082]

[0083] Step S302: Based on the importance ranking queue of the indicators, calculate the importance between two adjacent indicators in turn to obtain the importance ratio between adjacent indicators;

[0084] This involves quantitatively determining the relative importance of adjacent indicators; As the k-th indicator after ranking, where 1≤k≤m, the relative importance ratio is determined by combining expert knowledge and experience, and the specific magnitude of the importance between adjacent indicators is judged. k , 2≤k≤m; where r k The value assigned can be any intermediate value between 1 and 2. This represents the importance value of the (k-1)th indicator. This refers to the importance value of the k-th indicator.

[0085] Step S303: Based on the importance ratio between the adjacent indicators and subjective judgment, obtain the subjective variable weight vector;

[0086] Among them, the subjective weight of the m-th indicator The definition is as follows: The importance ratio r between adjacent indicators k Calculate the weights Weight of adjacent indicators The definition is as follows: Based on the calculated weights of adjacent indicators, the final subjective weight vector of n indicators is [a1, a2, ..., a...]. n ].

[0087] Step S304: Based on the conflict, correlation and dispersion of the indicators, and combined with the information entropy of the indicators, obtain the objective variable weight vector.

[0088] Taking the combined calculation of objective variable weights using the CRITIC method and entropy method as an example, the CRITIC method is a better objective weighting method than the entropy weight method and standard deviation method. It calculates the information entropy, difference coefficient, correlation coefficient, and conflict coefficient of the indicator, and combines them to change the corresponding objective weights. Let 1 represent the CRITIC method and 2 represent the entropy method. The objective weights of the j-th indicator calculated using the CRITIC method and the entropy method are respectively... and The objective variable weight of the j-th indicator is w. j , Based on the calculated objective variable weights, the final objective variable weight vector for the n indicators is [b1, b2, ..., b n ].

[0089] Step S305: Based on game theory, the conflict between Nash equilibrium indicators is adopted. The inherent information of indicator weights is used to determine the comprehensive variable weight vector by taking the common point of maximizing the interests between different indicators as the optimal linear combination weight coefficient.

[0090] To avoid directly combining subjective and objective weights, this study, based on game theory (GT), seeks a compromise and consistency among various weights, minimizing the deviation between the existing indicator weights and each basic weight. This is done to achieve arbitrary linear combination u and the basic weight vector set u0. k The objective is to minimize the deviation and optimize the combination coefficients u. k Thus, the optimal weight vector is obtained; the objective function for minimizing the deviation is: In the formula, min represents the minimization function, ε is the linear combination weight coefficient, the linear combination weight coefficient of the Kth index, T represents the matrix transpose, and || represents the calculation method for deviation minimization. The final comprehensive variable weight vector is determined as [c1, c2, ..., c...]. n ];

[0091] The comprehensive variable weight vector is calculated based on the subjective and objective variable weight vectors. For example, the linear combination weight coefficients ε are calculated using the objective function of minimizing deviation. k If the value is 0.3, then the subjective variable weight vector is multiplied by ε. k (0.3) multiplied by the objective variable weight vector by 1-ε k Add (0.7) together to obtain the comprehensive variable weight vector.

[0092] Please see Figure 4 , Figure 4 This is a flowchart illustrating a method for obtaining a comprehensive variable weight vector according to an embodiment of the present invention. Specifically, a subjective variable weight vector is obtained based on attack cost index data. Then, based on expert experience, the importance of the relevant indicators is compared pairwise according to the bubble sort principle, and they are sorted according to their importance. An importance ratio is set between adjacent indicators. The importance judgment changes based on subjective experience, resulting in a subjective variable weight vector [a1, a2, ..., a...]. n Based on attack effect indicator data, an objective variable weight vector is obtained. This vector is derived by considering the conflict, correlation, and dispersion of the indicator data, taking into account the information entropy carried by the indicator data, and balancing the conflict and correlation of the indicator data, by combining multiple objective weights. n Based on the aforementioned subjective and objective variable weight vectors, a weight vector set is constructed. Using game theory (GT) theory, deviation minimization optimization combination coefficients are obtained. These coefficients are then used to normalize the weight vector set, resulting in a game theory-based comprehensive weighting. Finally, the comprehensive variable weight vector [c1, c2, ..., c] is determined. n ].

[0093] Step S140: Combine the standardized index data from both sides and the comprehensive variable weight vector to obtain the weighted normalized index data matrices for the attacking side and the attacked side, respectively. Based on the combined embedded comprehensive evaluation model, evaluate the weighted normalized index data matrices for the attacking side and the attacked side, respectively, and obtain the corresponding evaluation results. Combine the evaluation results of the attacking side and the attacked side to obtain the comprehensive evaluation result of the entire network attack action.

[0094] Furthermore, the comprehensive evaluation results are obtained through the following steps:

[0095] Step S401: Construct a weighted normalized index data matrix based on the comprehensive variable weight vector;

[0096] Among them, after standardizing the indicator data, combined with the comprehensive variable weight vector, the weighted normalized indicator data matrix X is obtained, defined as follows: X=(x ij ) m×n In the formula, x ij Let m be the value of the j-th indicator for the i-th evaluation object in the standardized weighted normalized indicator data matrix, where m is the number of evaluation objects and n is the number of indicators.

[0097] Step S402: Load the combined embedded evaluation model and determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix;

[0098] Specifically, a combined embedded evaluation model is obtained by embedding an evaluation model into a weighted normalized index data matrix. The combined embedded evaluation model calculates the correlation degree values ​​of the positive and negative ideal solution reference vectors. In this embodiment of the invention, the combined embedded evaluation model can be a correlation TOPSIS evaluation model, a fuzzy comprehensive evaluation model, a grey theory evaluation model, etc. For n evaluation indicators of the evaluation object, the maximum value combination of each indicator data constitutes the positive ideal solution reference vector x corresponding to that indicator. j + x is defined as follows j + =max(x 1j ,x 2j ,...,x nj The minimum combination is the negative ideal solution reference vector x corresponding to this index. j - x is defined as follows j - =min(x 1j ,x 2j ,...,x nj In the formula, max(·) represents the maximum value function, min(·) represents the minimum value function, and x ij Let be the value of the j-th indicator of the i-th evaluation object in the standardized weighted normalized indicator data matrix, where 1 ≤ i ≤ n.

[0099] Step S403: Calculate the correlation coefficients of the indicators and construct the correlation coefficient matrix;

[0100] After obtaining the reference vectors for the positive and negative ideal solutions, the distance between each index data point and the reference vector is calculated to obtain the absolute value reference matrix X for the positive and negative ideal solutions. + and X - Find the maximum and minimum values ​​of the absolute value reference matrix, and calculate the correlation coefficient matrix; then compare it with the correlation coefficient matrix X of the positive ideal solution.+ Each matrix element is denoted as x. ij + The definition is as follows: Correlation coefficient matrix X with the negative ideal solution - Each matrix element is denoted as x. ij - The definition is as follows: In the formula, max(·) represents the maximum value function, min(·) represents the minimum value function, and x ij X represents the value of the j-th indicator for the i-th evaluation object in the standardized weighted normalized index data matrix. β is the discrimination coefficient used to control the discrimination degree (0 < β < 1), and β is generally taken as 0.5. The positive and negative ideal solution correlation coefficient matrix X... + and X - They are defined as follows: X + =(x ij + ) m×n X - =(x ij - ) m×n In the formula, m is the number of evaluation objects and n is the number of indicators.

[0101] Step S404: Calculate the correlation degree between each index data and the positive and negative ideal solution reference vectors using the correlation coefficient matrix;

[0102] Specifically, the correlation coefficient matrix is ​​used to calculate the correlation degree ξ between the i-th evaluation object and the positive ideal solution. i + The definition is as follows: The correlation value ξ between the i-th evaluation object and the positive ideal solution i - The definition is as follows: In the formula, n is the number of indicators, x ij + The correlation coefficient matrix X of the positive ideal solution + A matrix element, x ij - The correlation coefficient matrix X for the negative ideal solution - A matrix element; ξ i + The larger ξ is, the greater the correlation between the i-th evaluation object and the positive ideal solution, meaning the better the attack will be; i - The larger the value, the greater the correlation between the i-th evaluation object and the negative ideal solution, which means the worse the effect of the attack. By calculating the correlation value, we can reflect the changing trend of the data sample and thus reflect the quality of the evaluation result.

[0103] Step S405: Calculate the Euclidean distance between the indices of different evaluation objects and the reference vectors of positive and negative ideal solutions;

[0104] Among them, the index data of each evaluation object and the positive ideal solution reference vector x are calculated. j + and negative ideal solution reference vector x j - Euclidean distance d i + and d i - Euclidean distance, also known as Euclidean metric, is the distance d. i + The definition is as follows: Euclidean distance d i - The definition is as follows: In the formula, n is the number of indicators, x ij The value of the j-th indicator for the i-th evaluation object in the standardized weighted normalized indicator data matrix; the Euclidean distance d between the evaluation object's indicator data and the positive ideal solution reference vector. i + The smaller the value, the closer it is to the optimal attack target; the smaller the distance to the optimal attack target, the better the corresponding attack effect; the Euclidean distance d between the evaluation target's index data and the negative ideal solution. i - The larger the value, the further away it is from the worst target, meaning the better the attack effect.

[0105] Step S406: Combine the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects to calculate the comprehensive closeness of different evaluation objects.

[0106] In this study, the Euclidean distance calculated in step 405 reflects the vertical trend of different evaluation objects and the positive and negative ideal solution reference vectors, while the correlation degree calculated in step 404 reflects the correlation between indicators of different evaluation objects, characterizing the changing trends between indicators from a horizontal perspective. By integrating the horizontal correlation degree values ​​of different indicators and the vertical Euclidean distance of different evaluation objects, the differences and correlations between different evaluation objects and indicators are taken into account, resulting in a more comprehensive and holistic assessment of the effectiveness of network attacks. The Euclidean distance (d...) is used to... i + d i - ) and correlation value (ξ) i + ξ i - The data is then merged, and the degree of similarity between each evaluation object and the optimal attack target is Q. i + Q is defined as follows:i + =λ1×d i - +λ2×ξ i + The degree of distance between each evaluation object and the optimal attack target (Q) i - Q is defined as follows: i - =λ1×d i + +λ2×ξ i - In the formula, λ1 and λ2 are the influence coefficients of Euclidean distance and correlation degree, respectively. λ1 and λ2 must satisfy λ1 + λ2 = 1. In order to balance the Euclidean distance and correlation degree, a value of 0.5 is generally used for the calculation of the closeness. i + A higher Q value indicates a better effect of the corresponding attack. i - A higher value indicates that the attack is further removed from the optimal target, resulting in a smaller attack challenge and threat, and a poorer attack effect; based on the degree of proximity Q between each evaluation object and the optimal target... i + And the degree of distance between each evaluation object and the optimal attack target Q i - The overall closeness E of different evaluation objects was calculated. i E i The definition is as follows: E i The higher the value, the higher the overall score, and the better the corresponding attack effect.

[0107] Step S407: Based on the comprehensive proximity of different evaluation objects, calculate the same order of magnitude evaluation results for the attacking side and the attacked side respectively, and combine the evaluation results of the attacking and defending sides to obtain the comprehensive evaluation result of the overall attack.

[0108] Based on the comprehensive proximity of different evaluation objects, evaluation results E1 and E2 of the same magnitude are calculated for the attacking side and the attacked side, respectively. Combining the evaluation results of the attacking and defending sides, the overall comprehensive evaluation result E of the attack is obtained, defined as follows: E = 1 / (1+E1 / E2); the smaller E1 is, the smaller the attack cost consumed by the attacker; the larger E2 is, the greater the harm caused to the attacked, and the better the corresponding attack effect; the larger E is, the better the overall comprehensive attack effect, thus quantifying the attacking and defending sides and the overall attack effect, and obtaining a comprehensive evaluation result.

[0109] Please see Figure 5 , Figure 5This is a flowchart illustrating a method for obtaining comprehensive evaluation results from an attack-defense side model according to an embodiment of the present invention. Specifically, a comprehensive variable weight vector [c1,c2,…,c] is obtained based on the standardized index data of the attack side and the standardized index data of the attacked side. n Based on the comprehensive variable weight vector, a weighted normalized index data matrix is ​​constructed, and a combined embedded evaluation model is loaded (in...). Figure 5 Taking the TOPSIS evaluation model's embedded index correlation coefficient matrix as an example, we obtain the positive and negative ideal solution reference vectors of the weighted normalized index data matrix. After obtaining the positive and negative ideal solution reference vectors, we calculate the distance between each index data and the reference vector, construct the correlation coefficient matrix with the positive and negative ideal solutions, and calculate the correlation degree value. We also calculate the Euclidean distance between different evaluation objects and the positive and negative ideal solution reference vectors. We integrate the correlation degree values ​​and Euclidean distances of different indicators to calculate the comprehensive closeness of different evaluation objects. Based on the comprehensive closeness of different evaluation objects, we calculate the evaluation results E1 and E2 of the attacking side and the attacked side, respectively. We then combine E = 1 / (1 + E1 / E2) to obtain the overall comprehensive evaluation result E of the attack.

[0110] Please see Figure 6 , Figure 6 This is a flowchart illustrating a comprehensive network performance evaluation method according to an embodiment of the present invention. Specifically, it first establishes a three-layer attack cost indicator system of "target-attribute-indicator" from the attack side (see details). Figure 2 Establish a three-tiered attack effectiveness indicator system from the attacked side: "target-pattern-indicator" (see details). Figure 3In the case of a single attack type, attack cost and attack effect indicators are directly matched. In the case of combined attacks involving multiple attacks, specific indicators under each mode are matched and aggregated, collecting indicator data from both the attacking and defending sides of the corresponding attack. Based on the collected indicator data from both sides, a subjective variable weight vector is obtained based on expert experience, and an objective variable weight vector is obtained based on the attributes of the indicator data. The subjective and objective variable weight vectors are combined to obtain a comprehensive variable weight vector. A weighted normalized indicator data matrix is ​​constructed based on the comprehensive variable weight vector, and a combined embedded comprehensive evaluation model is loaded. The evaluation results of different evaluation objects on the attacking side and the attacked side are calculated separately. The evaluation results of different evaluation objects on the attacking side and the attacked side are combined to obtain a comprehensive evaluation result of the attack effect. The comprehensive evaluation result obtained by the above network effect comprehensive evaluation method is applicable to complex attack and defense game scenarios involving single network attacks and multiple combined attacks, including denial-of-service attacks, deception attacks, privilege escalation attacks, password attacks, phishing attacks, malware attacks, scanning attacks, information theft attacks, and complex attack scenarios composed of multiple attacks. Taking complex attack scenarios as an example, attackers may employ various attack phases, including reconnaissance, intrusion, vulnerability exploitation, privilege escalation, lateral movement, information theft and modification, and backdoor installation, each with varying attack intensities, resulting in different effects on the attacked party. Comprehensive assessment involves multiple aspects of the impact of a network attack, including specific numerical assessments, the overall danger level of the attack (extremely dangerous, relatively dangerous, moderately dangerous, safe), the resource costs incurred, the extent of file resource loss, the degree of damage to system software and hardware, and the overall impact on network stability.

[0111] The above implementation process establishes an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side through complex network attacks launched by n attackers, where n is an integer greater than or equal to 1. Based on the single attack type of a single attack and the combination attack type of multiple attacks, as well as the number of attack types, a mapping relationship of "type-attribute" and "type-pattern" is formed. According to the attribute layer and the pattern layer, the corresponding attack cost indicators on the attacking side and the attack effect indicators on the attacked side are matched respectively. The indicator data corresponding to the attack cost indicators and the attack effect indicators are collected and standardized to obtain standardized indicator data on both sides. The subjective and objective weights of the indicators are transformed into subjective and objective transformed weight vectors. A game theory approach is used to combine these vectors to obtain a comprehensive transformed weight vector. The standardized indicator data from both sides and the comprehensive transformed weight vector are combined to obtain weighted normalized indicator data matrices for the attacking and attacked sides, respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized indicator data matrices for both sides are evaluated to obtain corresponding evaluation results. Finally, the comprehensive evaluation results of the entire network attack operation are obtained by combining the evaluation results from both sides. This invention provides a comprehensive network performance evaluation method. First, it establishes evaluation index systems from both the attacking and defending sides. The attacking side establishes a three-layer attack cost index system ("target-attribute-index"), while the attacked side establishes a three-layer attack effect index system ("target-pattern-index"). This provides a comprehensive understanding of all parties involved in the attack from different perspectives. Then, it proposes a comprehensive variable-weight index vector, overcoming the limitations of unilateral subjective and objective weighting while avoiding the immutability of constant weights. It proposes subjective, objective, and comprehensive variable-weighting methods, allowing index weights to vary according to different attack targets and objectives, enabling flexible adjustment of index weight assignment. Finally, it combines existing evaluation models, integrating the advantages of different models and incorporating correlation coefficients for index correlation, allowing the evaluation results to more comprehensively reflect the correlation of index data. Simultaneously, evaluations are conducted from both the attacking and attacked sides to obtain the effects of both sides, ultimately combining them to obtain a comprehensive evaluation result, achieving a comprehensive and multi-faceted evaluation.

[0112] Based on the same inventive concept as the first aspect described above, embodiments of the present invention also provide a comprehensive network performance evaluation system, see below. Figure 7 , Figure 7 This invention provides an architecture diagram of a comprehensive network performance evaluation system, the system comprising:

[0113] The two-sided indicator system construction subsystem 110 is used to establish an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side for complex network attacks by n attackers, where n is an integer greater than or equal to 1.

[0114] In this embodiment of the invention, the attributes in the attack-side indicator system construction subsystem can be attributes such as availability, confidentiality, and cost, and the attack modes in the attacked-side indicator system construction subsystem can be modes such as resource consumption, configuration manipulation, permission acquisition, interactive deception, and service exploitation.

[0115] The indicator data processing subsystem 120 is used to form a mapping relationship of "type-attribute" and "type-pattern" based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types. According to the attribute layer and the pattern layer, the corresponding attack cost indicator on the attacking side and the attack effect indicator on the attacked side are matched respectively. The indicator data corresponding to the attack cost indicator and the attack effect indicator are collected and standardized to obtain standardized indicator data on both sides.

[0116] The game theory index variable weight subsystem 130 is used to perform variable weight processing on the subjective weight and objective weight of the index to obtain the subjective variable weight vector and the objective variable weight vector. The subjective variable weight vector and the objective variable weight vector are combined by game theory to obtain the comprehensive variable weight vector.

[0117] The game theory index variable weight subsystem is further configured as follows:

[0118] The importance ranking module is used to compare the importance of relevant indicators pairwise according to the bubble sort algorithm based on expert experience, and sort them according to the degree of importance to obtain the indicator importance ranking queue.

[0119] The importance ratio calculation module is used to calculate the importance between two adjacent indicators in turn based on the importance ranking queue of the indicators, and obtain the importance ratio between adjacent indicators.

[0120] The subjective variable weight vector determination module is used to obtain the subjective variable weight vector based on the importance ratio between the adjacent indicators and subjective judgment.

[0121] The objective variable weight vector determination module is used to obtain the objective variable weight vector based on the conflict, correlation and dispersion of the indicators, combined with the information entropy of the indicators.

[0122] The module for determining the comprehensive variable weight vector is used to determine the comprehensive variable weight vector based on game theory, by adopting the conflict between Nash equilibrium indicators, utilizing the inherent information of indicator weights, and taking the optimal linear combination weight coefficients of the common interests of different indicators as the maximization of interests.

[0123] The comprehensive evaluation subsystem 140 is used to combine the standardized index data from both sides and the comprehensive variable weight vector to obtain the weighted normalized index data matrices of the attacking side and the attacked side, respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized index data matrices of the attacking side and the attacked side are evaluated to obtain the corresponding evaluation results. The comprehensive evaluation results of the entire network attack action are obtained by combining the evaluation results of the attacking side and the attacked side.

[0124] The comprehensive evaluation subsystem is further configured as follows:

[0125] The weighted normalized index data matrix determination module is used to construct a weighted normalized index data matrix based on the comprehensive variable weight vector;

[0126] The positive and negative ideal solution reference vector determination module is used to determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix;

[0127] The correlation coefficient matrix construction module is used to calculate the correlation coefficients of indicators and construct the correlation coefficient matrix.

[0128] The correlation coefficient calculation module is used to calculate the correlation coefficient between each index data and the positive and negative ideal solution reference vectors from the correlation coefficient matrix.

[0129] The Euclidean distance calculation module is used to calculate the Euclidean distance between the index data of different evaluation objects and the reference vectors of positive and negative ideal solutions;

[0130] The comprehensive proximity calculation module is used to integrate the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects to calculate the comprehensive proximity of different evaluation objects.

[0131] The comprehensive evaluation result calculation module is used to calculate the same-order evaluation results for the attacking side and the attacked side based on the comprehensive proximity of different evaluation objects. By combining the evaluation results of the attacking and defending sides, the comprehensive evaluation result of the overall attack is obtained.

[0132] In the above implementation process, the subsystem 110, which constructs a two-sided indicator system, establishes an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side for complex network attacks by n attackers, where n is an integer greater than or equal to 1. The indicator data processing subsystem 120 forms a mapping relationship of "type-attribute" and "type-pattern" based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types. According to the attribute layer and the pattern layer, it matches the corresponding attack cost indicator on the attacking side and the attack effect indicator on the attacked side, collects the indicator data corresponding to the attack cost indicator and the attack effect indicator, and performs standardization processing to obtain the standardized indicators on both sides. The data; the game theory index variable weight subsystem 130 performs variable weight processing on the subjective and objective weights of the indicators to obtain subjective variable weight vectors and objective variable weight vectors. The subjective and objective variable weight vectors are combined using a game theory method to obtain a comprehensive variable weight vector. The comprehensive evaluation subsystem 140 combines the standardized index data from both sides and the comprehensive variable weight vector to obtain weighted normalized index data matrices for the attacking and attacked sides, respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized index data matrices for the attacking and attacked sides are evaluated to obtain corresponding evaluation results. The comprehensive evaluation results of the entire network attack action are obtained by combining the evaluation results of the attacking and attacked sides. This invention provides a comprehensive network performance evaluation system. First, it establishes evaluation index systems from both the attacking and defending sides. The attacking side establishes a three-layer attack cost index system ("target-attribute-index"), while the attacked side establishes a three-layer attack effect index system ("target-pattern-index"). This provides a comprehensive understanding of all parties involved in the attack from different perspectives. Then, it proposes a comprehensive variable-weight index vector, overcoming the limitations of unilateral subjective and objective weighting while avoiding the immutability of constant weights. It proposes subjective, objective, and comprehensive variable-weighting methods, allowing index weights to vary according to different attack targets and objectives, enabling flexible adjustment of index weight assignment. Finally, it combines existing evaluation models, integrating the advantages of different models and incorporating correlation coefficients for index correlation, allowing the evaluation results to more comprehensively reflect the correlation of index data. Simultaneously, it evaluates from both the attacking and attacked sides to obtain the effects of both sides, ultimately combining them to obtain a comprehensive evaluation result, achieving a comprehensive and multi-faceted evaluation.

[0133] Please see Figure 8 , Figure 8This is a schematic structural block diagram of an electronic device provided in an embodiment of the present invention. The electronic device includes a memory 101, a processor 102, and a communication interface 103. The memory 101, processor 102, and communication interface 103 are electrically connected to each other directly or indirectly to realize data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The memory 101 can be used to store software programs and modules, such as the program instructions / modules corresponding to a brain-inspired global-local dual-channel image classification system provided in an embodiment of the present invention. The processor 102 executes various functional applications and data processing by executing the software programs and modules stored in the memory 101. The communication interface 103 can be used for signaling or data communication with other node devices.

[0134] The memory 101 may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.

[0135] The processor 102 can be an integrated circuit chip with signal processing capabilities. The processor 102 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0136] Understandable. Figure 8 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 8 The more or fewer components shown, or having the same Figure 8 The different configurations shown. Figure 8 The components shown can be implemented using hardware, software, or a combination thereof.

[0137] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0138] In addition, the functional modules in the various embodiments of the present invention can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0139] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0140] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

[0141] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A comprehensive evaluation method for network performance, characterized in that, The method includes: For a complex network attack carried out by n attackers, establish an attack cost index system on the attacking side and an attack effect index system on the attacked side, where n is an integer greater than or equal to 1. Based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types, a mapping relationship of "type-attribute" and "type-pattern" is formed. According to the attribute layer and the pattern layer, the corresponding attack cost index of the attack side and the attack effect index of the attacked side are matched respectively. The index data corresponding to the attack cost index and the attack effect index are collected and standardized to obtain standardized index data on both sides. The subjective and objective weights of the indicators are transformed into subjective and objective weight vectors. The subjective and objective weight vectors are then combined using a game theory method to obtain a comprehensive weight vector. By combining the standardized index data from both sides and the comprehensive variable weight vector, weighted normalized index data matrices for the attacking side and the attacked side are obtained respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized index data matrices for the attacking side and the attacked side are evaluated respectively to obtain the corresponding evaluation results. By combining the evaluation results of the attacking side and the attacked side, the comprehensive evaluation result of the entire network attack action is obtained. The comprehensive variable weight vector is obtained through the following steps: Based on expert experience, the importance of the relevant indicators is compared pairwise according to the bubble sort method, and then sorted according to the degree of importance to obtain the indicator importance ranking queue. Based on the importance ranking queue of the indicators, the importance between two adjacent indicators is calculated in turn to obtain the importance ratio between adjacent indicators; Based on the importance ratio between the adjacent indicators and subjective judgment, a subjective variable weight vector is obtained; Based on the conflict, correlation and dispersion of the indicators, and combined with the information entropy of the indicators, an objective variable weight vector is obtained. Based on game theory, this paper adopts the conflict between Nash equilibrium indicators and utilizes the inherent information of indicator weights to determine the comprehensive variable weight vector by taking the common interest of maximizing different indicators as the optimal linear combination weight coefficient.

2. The method according to claim 1, characterized in that, The establishment of an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side includes: For the attacking side, an attack cost indicator system of "target-attribute-indicator" is established by combining the attacker's factors and attributes. The attacker's factors include attack attributes, attack methods, attack costs, and attacking side resources and network consumption. The attributes include availability, confidentiality, and cost. For the attacked side, a three-tiered attack effect indicator system of "target-mode-indicator" is established, combining factors of the attacking device and the attack mode. The factors of the attacking device include changes in system resources, performance, network, and operational stability. The modes include resource consumption mode, manipulation configuration mode, privilege acquisition mode, interactive deception mode, and service exploitation mode.

3. The method according to claim 1, characterized in that, The acquisition of the standardized index data on both sides also includes: The single attack type is determined by matching the attack pattern with the attack cost index and the attack effect index based on the attacker's attack attributes and attack purpose. The combined attack type of the various attacks is based on the aggregation of specific indicators under each mode and the attack cost indicators on the attacker side and the attack effect indicators on the attacked side.

4. The method according to claim 1, characterized in that, The comprehensive evaluation results were obtained through the following steps: Construct a weighted normalized index data matrix based on the comprehensive variable weight vector; Load the combined embedded evaluation model to determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix; Calculate the correlation coefficients of the indicators and construct the correlation coefficient matrix; The correlation coefficient matrix is ​​used to calculate the correlation degree between each index data and the positive and negative ideal solution reference vectors; Calculate the Euclidean distance between the indices of different evaluation objects and the reference vectors of positive and negative ideal solutions; By integrating the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects, the overall closeness of different evaluation objects is calculated. Based on the comprehensive proximity of different evaluation objects, the same order of magnitude evaluation results are calculated for both the attacking and attacked sides. Combining the evaluation results from both the attacking and defending sides, a comprehensive evaluation result of the overall attack is obtained.

5. A comprehensive evaluation system for network performance, characterized in that, The system includes: The two-sided indicator system construction subsystem is used to establish an attack cost indicator system on the attacking side and an attack effect indicator system on the attacked side for complex network attacks by n attackers, where n is an integer greater than or equal to 1. The indicator data processing subsystem is used to form a mapping relationship of "type-attribute" and "type-pattern" based on the single attack type of a single attack and the combined attack type of multiple attacks, as well as the number of attack types. According to the attribute layer and the pattern layer, the corresponding attack cost indicator on the attacking side and the attack effect indicator on the attacked side are matched respectively. The indicator data corresponding to the attack cost indicator and the attack effect indicator are collected and standardized to obtain standardized indicator data on both sides. The game theory index variable weight subsystem is used to perform variable weight processing on the subjective and objective weights of the index to obtain subjective variable weight vectors and objective variable weight vectors. The subjective and objective variable weight vectors are combined using game theory methods to obtain a comprehensive variable weight vector. The comprehensive evaluation subsystem is used to combine the standardized index data from both sides and the comprehensive variable weight vector to obtain the weighted normalized index data matrices of the attacking side and the attacked side, respectively. Based on the combined embedded comprehensive evaluation model, the weighted normalized index data matrices of the attacking side and the attacked side are evaluated to obtain the corresponding evaluation results. The comprehensive evaluation results of the entire network attack action are obtained by combining the evaluation results of the attacking side and the attacked side. The game theory index variable weight subsystem is further configured as follows: The importance ranking module is used to compare the importance of relevant indicators pairwise according to the bubble sort algorithm based on expert experience, and sort them according to the degree of importance to obtain the indicator importance ranking queue. The importance ratio calculation module is used to calculate the importance between two adjacent indicators in turn based on the importance ranking queue of the indicators, and obtain the importance ratio between adjacent indicators. The subjective variable weight vector determination module is used to obtain the subjective variable weight vector based on the importance ratio between the adjacent indicators and subjective judgment. The objective variable weight vector determination module is used to obtain the objective variable weight vector based on the conflict, correlation and dispersion of the indicators, combined with the information entropy of the indicators. The module for determining the comprehensive variable weight vector is used to determine the comprehensive variable weight vector based on game theory, by adopting the conflict between Nash equilibrium indicators, utilizing the inherent information of indicator weights, and taking the optimal linear combination weight coefficients of the common interests of different indicators as the maximization of interests.

6. The system according to claim 5, characterized in that, The comprehensive evaluation subsystem is further configured to: The weighted normalized index data matrix determination module is used to construct a weighted normalized index data matrix based on the comprehensive variable weight vector; The positive and negative ideal solution reference vector determination module is used to determine the positive and negative ideal solution reference vectors of the weighted normalized index data matrix; The correlation coefficient matrix construction module is used to calculate the correlation coefficients of indicators and construct the correlation coefficient matrix. The correlation coefficient calculation module is used to calculate the correlation coefficient between each index data and the positive and negative ideal solution reference vectors from the correlation coefficient matrix. The Euclidean distance calculation module is used to calculate the Euclidean distance between the index data of different evaluation objects and the reference vectors of positive and negative ideal solutions; The comprehensive proximity calculation module is used to integrate the horizontal correlation values ​​of different indicators and the vertical Euclidean distance of different evaluation objects to calculate the comprehensive proximity of different evaluation objects. The comprehensive evaluation result calculation module is used to calculate the same-order evaluation results for the attacking side and the attacked side based on the comprehensive proximity of different evaluation objects. By combining the evaluation results of the attacking and defending sides, the comprehensive evaluation result of the overall attack is obtained.

7. An electronic device, characterized in that, include: Memory, used to store one or more programs; processor; When the processor executes the one or more programs, it implements the comprehensive network performance evaluation method as described in any one of claims 1-4.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the comprehensive evaluation method for network performance as described in any one of claims 1-4.