A vulnerability analysis method for network routing mechanisms based on knowledge graphs

Through a knowledge graph-based method, analyzing the fragility characteristics of the satellite network routing mechanism and building a fragility analysis model is solved, which solves the problem of lack of source-level analysis and security considerations in the existing technology, and achieves a more accurate and comprehensive analysis of the fragility of the network routing mechanism, and improves the reliability and security of the network.

CN117834508BActive Publication Date: 2025-06-17NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410016525.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-05
Publication Date
2025-06-17
Estimated Expiration
2044-01-05

AI Technical Summary

Technical Problem

When analyzing the vulnerability of satellite network routing mechanisms, the prior art lacks source-level analysis and fails to fully consider the confidentiality and integrity of network security, resulting in still vulnerabilities in satellite network security.

Method used

Using a knowledge graph-based method, a target network routing mechanism fragility analysis model is constructed by analyzing the fragility characteristics and complex structures and semantics of the programs that implement the routing mechanism part in the router operating system. This model abstracts the fragility analysis problem into node classification problem, combines the message delivery mechanism and graph neural convolution network, generates control flow data flow graphs, embeds the fragility characteristics of the network routing mechanism, and builds a fragility knowledge graph of the target network routing mechanism.

Benefits of technology

A more complete and accurate analysis of the fragility of the network routing mechanism is achieved, which can effectively reduce the number of failure injections, enhance the comprehensiveness and intuitiveness of the analysis process, and improve the reliability and security of the target routing mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117834508B_ABST
    Figure CN117834508B_ABST
Patent Text Reader

Abstract

The present invention discloses a vulnerability analysis method for network routing mechanisms based on a knowledge graph. The knowledge graph is used to model and analyze the overall program implementing the routing mechanism, and the relevance between factors such as the complex structure of the program, instruction and function operations, routing protocols, packet reception, transmission, and verification, and program vulnerabilities is summarized and presented in the form of a graph. By training a graph neural network model to learn the context semantic relationships between nodes in the knowledge graph, the vulnerability analysis of the program is realized, and further the vulnerability of the overall network routing mechanism is analyzed. The present invention models the vulnerability ontology of the network routing mechanism, gives a method for constructing the vulnerability knowledge graph of the network routing mechanism, can realize the in-depth mining of the context semantic relationships in the graph, and makes the vulnerability analysis of the network routing mechanism more complete and accurate. The method of the present invention can effectively improve the vulnerability analysis ability of the network routing mechanism, effectively reduce the time overhead, and improve the security and reliability of the routing mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of trusted vulnerability analysis, and in particular, to a method for analyzing the vulnerability of a network routing mechanism based on a knowledge graph. Background Art

[0002] The damage of the space complex radiation environment to the satellite network communication system cannot be ignored. There are a large number of high-energy charged particles in the cosmic space environment where the satellite is located. In recent years, with the increasing influence of the single-event effect, the requirements for the reliability and security of the space-based network communication mechanism have become higher and higher. The transient errors caused by the single-event effect on satellite node routing can generally be divided into two categories: data stream errors and control flow errors. Data stream errors refer to the transient errors caused by the single-event effect modifying the values in the storage units (such as registers and program and data memories) in the router, resulting in errors in communication data; control flow errors are generally caused by soft errors due to the single-event effect occurring in the storage units implementing the routing algorithm, resulting in data being routed in the wrong direction. In the communication system of low-orbit satellites in the space-based network, due to the low deployment altitude of the satellite, the propagation delay of its space-ground link is correspondingly low, but at the same time, low-orbit satellites also have the characteristic of fast running speed, resulting in failures in the links between satellites and between satellites and ground communication devices. Given the importance of the satellite network, in recent years, a large amount of work at home and abroad has focused on analyzing the vulnerability of the satellite network and enhancing the reliability and security of the satellite network.

[0003] Among the numerous threats faced by the space-based network, the reliability and security of the routing mechanism are the most important. Once the satellite network routing is attacked by malicious network behaviors, the satellite network is likely to be paralyzed. Therefore, routing security is the core of the satellite network. To address issues such as network routing security, LI Zhangyuan et al. started from the establishment and vulnerability analysis of the complex network model in the space information network, introduced the concept of the space information network and the development process of the complex network, and focused on summarizing its classification methods for modeling and vulnerability measurement results. ZHENG Jing et al. aimed at the medium and low-orbit satellite network, and the medium-orbit satellite used a trust assessment mechanism to construct a trusted routing for the low-orbit satellite network, and proposed solutions for the situations of satellite node failure and inter-satellite link congestion. NISHIYAMAH et al. proposed a routing protocol based on load balancing and developed a new network structure for the LEO / MEO double-layer satellite network respectively, but this method has a large overhead. At present, the research on the vulnerability of the network routing mechanism lacks source-level analysis.

[0004] In addition, with the rapid development of machine learning, machine learning has been widely applied in fields such as image recognition and classification, natural language processing, etc. Related methods have provided new development directions for the field of routing security. The work of combining machine learning with routing technology is also continuously evolving. Based on machine learning, there are more perfect methods for studying the vulnerability of network routing mechanisms. Liu Heyu et al. addressed the QoS problem of medium and low Earth orbit satellite networks. Using relevant knowledge of machine learning, they modeled the routing process of satellite nodes as a classifier classification process and performed routing according to the results of classification tasks, enhancing the performance of the network. Bronovetsky et al. compared the advantages and disadvantages of two machine learning methods, support vector machines and neural networks, in analyzing program vulnerabilities and proposed a basic framework for modular program fault analysis. This framework is not specific to routing programs and can analyze the vulnerabilities of each code segment and generate vulnerability models. However, the methods they proposed are only limited to linear algebra applications.

[0005] The methods for analyzing the vulnerability of routing mechanisms adopted in the above research do not fully consider the confidentiality and integrity of network security, resulting in many vulnerabilities in satellite network security. Moreover, due to the unpredictable forms of routing attacks, the current methods for vulnerability analysis of routing security protocols cannot take into account all threats during the design process. Currently, knowledge graphs have been applied and developed in multiple fields: they have been successfully applied in many fields such as medical and military. There are already relevant domestic and foreign literatures introducing knowledge graphs into the field of fault diagnosis to assist in realizing system fault diagnosis. Jiang Da et al. used text mining technology to process fault repair logs, constructed a fault knowledge graph, mined the internal connections of vehicle equipment faults, and constructed a vehicle fault knowledge graph, improving the efficiency of fault diagnosis. Liu Xin et al. introduced relevant technical ideas of knowledge graphs into the field of fault diagnosis analysis, combined the fault tree diagnosis method, failure mode and effects analysis method with the ontology representation process and reasoning function realization of knowledge graphs, providing a new feasible idea for realizing knowledge-sharing general intelligent fault diagnosis technology. Currently, the main research work in the field of fault analysis and diagnosis mainly focuses on the current operating state of the system. The specific application fields of the fault diagnosis software or systems involved are relatively single, lacking general-purpose fault diagnosis software and methods. At the same time, the reuse rate of knowledge and experience resources for fault diagnosis is relatively low. Therefore, taking the data related to the vulnerability of network routing mechanisms as the research object, using knowledge graph technology for knowledge extraction, knowledge fusion, and knowledge processing to form a series of interrelated knowledge provides a feasible method for constructing a knowledge graph in the field of network routing mechanism vulnerability. In terms of knowledge graph construction, constructing intelligent fault diagnosis methods with prediction functions and generality is the main research focus and direction of domestic and foreign scholars in this field. However, there are still problems such as the research field not being wide enough, and the methods not being comprehensive and mature enough. The research and application of knowledge graphs in vulnerability analysis need to be expanded. Summary of the Invention

[0006] The object of the present invention is to provide a vulnerability analysis method for network routing mechanisms based on knowledge graphs in view of the problems existing in the above-mentioned prior art. By analyzing the vulnerability characteristics of the programs implementing the routing mechanisms in router operating systems and the complex structures and semantics of the programs, a vulnerability analysis model for the target network routing mechanism is constructed. This model abstracts the vulnerability analysis problem of the target program into a node classification problem, combining a message passing mechanism and a graph neural convolutional network; methods for constructing knowledge graphs and vulnerability analysis models are given; a vulnerability analysis method for network routing mechanisms based on knowledge graphs is proposed, which can visually display the intricate relationships between program vulnerability probabilities, influencing factors, and the instructions themselves, and can thus be used in strategies for strengthening routing mechanisms. In the research on the phenomenon of soft errors occurring in routing mechanisms due to interference and space radiation, the application of the present invention can particularly improve the security and reliability of the network.

[0007] The technical solution for achieving the object of the present invention is: a vulnerability analysis method for network routing mechanisms based on knowledge graphs, the method comprising the following steps:

[0008] Step 1, design a fault injection experiment plan for typical routing programs, conduct random fault injection experiments on the target low-earth orbit interconnected network routing program set, and construct a network routing mechanism vulnerability data set;

[0009] Step 2, establish a virtual network topology according to the actual network topology of the target low-earth orbit Internet and considering various factors, that is, simulate the target network model to implement the simulation of the target low-earth orbit Internet routing mechanism;

[0010] Step 3, run the routing program on the routers simulating the target network, simulate the vulnerability of the network routing mechanism, analyze the running results, dynamically collect the vulnerability characteristic information of the target network routing mechanism, and construct a network routing mechanism vulnerability data set;

[0011] Step 4, design the schema layer of the vulnerability knowledge graph of the target network routing mechanism according to the vulnerability characteristics of the network routing mechanism, and construct the target routing mechanism vulnerability ontology model;

[0012] Step 5, generate a control flow data flow graph according to the obtained network routing mechanism vulnerability data set, embed the network routing mechanism vulnerability characteristics, and construct the target network routing mechanism vulnerability knowledge graph;

[0013] Step 6, represent the nodes in the knowledge graph in the form of low-dimensional, real-valued, and dense vectors, and use them as the input of the target network routing mechanism vulnerability analysis model for model training;

[0014] Step 7: Convert the routing mechanism vulnerability analysis task of the target network into a node classification and prediction task, and construct a vulnerability analysis model for the target network routing mechanism.

[0015] Step 8: Analyze the vulnerability of the instruction nodes in the vulnerability knowledge graph of the target network routing mechanism according to the constructed vulnerability analysis model of the target network routing mechanism, and obtain the vulnerability of the target network routing mechanism from the analysis experimental results.

[0016] Compared with the prior art, the significant advantages of the present invention are as follows:

[0017] (1) It is proposed to use the knowledge graph in the field of network routing mechanism vulnerability analysis. Through the knowledge graph technology, the overall structure of the routing program and the complex logical relationships and vulnerable links among various components in the network topology are demonstrated.

[0018] (2) The present invention models the vulnerability ontology of the network routing mechanism, and gives a method for constructing the vulnerability knowledge graph of the network routing mechanism, which can realize the in-depth mining of the context semantic relationships in the graph, making the analysis of the network routing mechanism vulnerability more complete and accurate.

[0019] (3) A method for analyzing the vulnerability of the network routing mechanism based on the knowledge graph is proposed. Compared with the previous method of exhaustive fault injection experiments, it can effectively reduce the number of fault injections, and enhance the comprehensiveness and intuitiveness of the analysis process, improving the reliability and security of the target routing mechanism.

[0020] (4) It is proposed to abstract the vulnerability analysis of the target network routing mechanism into a node classification and label prediction problem. Compared with the previous analysis using machine learning models, it effectively improves the prediction efficiency. Moreover, the previous models rely on manually crafted features and lack the reasoning ability for SDC propagation, resulting in poor SDC prediction performance. The method of the present invention can automatically learn the structural features of error propagation and can achieve more accurate prediction analysis.

[0021] (5) Starting from the source of routing security, the present invention analyzes the routing program itself, which further ensures the security and reliability of the network routing mechanism.

[0022] (6) Applying the method given by the present invention can effectively improve the vulnerability analysis ability of the network routing mechanism, effectively reduce the time overhead, and improve the security and reliability of the routing mechanism.

[0023] The present invention will be further described in detail below with reference to the accompanying drawings. Description of the Drawings

[0024] Figure 1 It is a framework diagram of the method for analyzing the vulnerability of the network routing mechanism based on the knowledge graph of the present invention.

[0025] Figure 2 It is a diagram of the vulnerability ontology model of the network routing mechanism constructed in an embodiment.

[0026] Figure 3 It is a partial instance diagram of the knowledge graph of the vulnerability of the network routing mechanism in an embodiment.

[0027] Figure 4 It is a diagram of the experimental results of the vulnerability analysis model and the comparison model of the network routing mechanism in an embodiment. Specific implementation manners

[0028] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0029] It should be noted that if there are directional indications (such as up, down, left, right, front, back,...) involved in the embodiments of the present invention, the directional indications are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the drawings). If the specific posture changes, the directional indications will also change accordingly.

[0030] In addition, if there are descriptions such as "first", "second", etc. involved in the embodiments of the present invention, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those skilled in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0031] In one embodiment, in combination with Figure 1 , a method for analyzing the vulnerability of a network routing mechanism based on a knowledge graph is provided, including the following steps:

[0032] Step 1, perform a random fault injection experiment on the target low-earth-orbit Internet routing mechanism program to construct a vulnerability dataset of the network routing mechanism. The specific implementation steps are as follows:

[0033] Step 1.1, search for the running program of the low-earth-orbit Internet router, select the source program that implements the routing mechanism, and convert the routing program into an intermediate code format through analysis methods such as disassembly.

[0034] Step 1.2. Use a fault injection tool to simulate the occurrence of faults under interference and radiation effects, conduct random fault injection experiments on the target routing program, and use the results obtained after the experiment runs as the vulnerability dataset of the network routing mechanism.

[0035] Step 2. Establish a simulated network topology according to the actual network topology of the target low-earth-orbit Internet, simulate the construction process of the network topology of the target low-earth-orbit Internet routing mechanism, and construct it based on multiple elements as shown in Equation (1):

[0036] F topology =(T scale ,T paramter ,T topology ,T protocol ,T safety ,T state ) (1)

[0037] Among them, F topology is the set of factors considered for constructing the simulated target network topology, T scale is the network scale, that is, the number of nodes and links that the topology needs to contain, and the size of the network scale is reflected by the number of nodes. T parameter is the network performance parameter, that is, bandwidth, delay, routing convergence time, etc. The bandwidth and delay between nodes and the routing convergence time have an important impact on network performance, and the bandwidth and delay characteristics of the real network need to be simulated. T topology is the type of network topology structure. Select a suitable network topology structure, such as star, ring, mesh, etc., to reflect the structural characteristics of the real network. T protocol is the routing protocol. Select a routing algorithm suitable for the target low-earth-orbit Internet and implement it in the simulated network topology. T safety is the security of router configuration. Consider factors such as router authentication and authorization, security log recording and auditing. T state is the network node status. Consider node status, such as faults, maintenance, etc., to reflect the operating status of the real network:

[0038] · Network performance parameter T paramter As shown in Equation (2):

[0039] T paramter =(D delay ,C convergence ,B bandwidth ,T traffic ) (2)

[0040] In the formula, D delay is the network delay, C convergence is the routing convergence time, B bandwidth is the network bandwidth, T trafficis the data traffic, i.e., the number of data packets received by the node;

[0041] · Network topology type T topology As shown in Equation (3):

[0042] T topology =(S star , N net , C circle ) (3)

[0043] In the formula, S star represents the star network topology of the space-based network. In the star topology of the space-based network, all satellites are directly connected to the ground station, and there is usually no direct connection between satellites. The ground station acts as the central node, and the communication between satellites needs to be relayed through the ground station; N net represents the mesh network topology of the space-based network. The mesh topology of the space-based network is a multi-to-multi connection method, in which each satellite can communicate directly with multiple other satellites, not just connected to the ground station; C circle represents the ring network topology of the space-based network. In the ring topology of the space-based network, satellites are arranged in a ring orbit, and each satellite is connected to its adjacent front and rear satellites to form a closed loop;

[0044] · Router configuration security T safety As shown in Equation (4):

[0045] T safety =(A authentication , L log , S safe_protocal ) (4)

[0046] In the formula, A authentication is the authentication and authorization of the router, L log is the security log record, S safe_protocal is the security protocol, including SSH, HHTPS, etc.;

[0047] · Network node status T state As shown in Equation (5):

[0048] T state =(A active , F faulty , O offline , S security ) (5)

[0049] In the formula, A active indicates whether the network node is in an active state, F faulty indicates whether the network node is in a fault state, O offline indicates whether the network node is in an offline state, S securityIndicates whether the network node is in a secure state. A status information of 0 indicates that the network node is in a secure state; otherwise, it is in a high vulnerability state.

[0050] Configure the routing protocol for the constructed network topology. The routing protocols used are: OSPF (Open Shortest Path First, OSPF) protocol, BGP (Border Gateway Protocol, BGP), RIP (Routing Information Protocol, RIP), etc.

[0051] Step 3: Based on the simulated network topology constructed in Step 2, the vulnerability characteristic information of the network routing mechanism is obtained through the analysis of the target network simulation experiment results. By running the routing program on the routers in the network topology and combining with the fault injection experiment, the vulnerability of the network routing mechanism is simulated, and then the vulnerability characteristic set of the target network is obtained through the analysis of the running results. The specific method is as follows:

[0052] Step 3.1: Construct the target network routing mechanism vulnerability characteristic data set type set F as shown in Equation (6):

[0053] F = (I type , R table , F operate , P protocol , T performance ) (6)

[0054] Where, I type is the instruction type in the routing program, R table is the routing table, F operate is the routing operation related calculation function, P protocol is the routing protocol, and T performance is the network performance;

[0055] The instruction type characteristic I type is as shown in Equation (7):

[0056] I type = (i com , i cal , i shi , i conv , i term , i float , i send , i receive , i check ) (7)

[0057] In the formula, i com is the comparison instruction, i cal is the arithmetic instruction, i shi is the shift instruction, i convis a conversion instruction, i term is a termination instruction, i float is a floating-point instruction, i send is an instruction for sending control information, i receive is an instruction for receiving control information, i check is a check instruction;

[0058] Routing table feature R table As shown in Equation (8):

[0059]

[0060] In the formula, r sorce_ip is the source IP address, r des_ip is the destination IP address, r interface is the interface information, r router_id is the router identification ID, r protocal is the next-hop information, r available_links is the available link information;

[0061] Routing operation-related function type feature F operate As shown in Equation (9):

[0062] F operate =(f routing_algorithm , f packet_handle , f system_call , f safety_check , f interface_charge )(9)

[0063] In the formula, f routing_algorithm is the function implemented by the routing algorithm, f packet_handle is the data packet processing function, f function_call is the function call function, f safety_check is the security check function, f interface_charge is the interface configuration management function;

[0064] Routing protocol feature P protocol As shown in Equation (10):

[0065] P protocol =(p rip , p ospf , p bgp )(10)

[0066] In the formula, p rip is the RIP (Routing Information Protocol, RIP) protocol, p ospf is the OSPF (Open Shortest Path First, OSPF) protocol, p bgpis the BGP (Border Gateway Protocol) protocol;

[0067] Network performance characteristic T performance As shown in Equation (11):

[0068]

[0069] In the formula, t delay is the network latency, t struc is the network topology type, t packet_loss is the packet loss rate, t convergence is the routing convergence time, t connect is the network connectivity, t safe_securc is the credibility of network nodes and links;

[0070] Step 3.2. Based on the rules and conditions for extracting the vulnerability characteristics of the target network routing mechanism, run the RMVFE (Route Mechanism Vulnerability Feature Extraction) algorithm to implement the extraction of the vulnerability characteristics of the target network routing mechanism. The algorithm steps are as follows:

[0071] Step 3.2.1. Extract the set of vulnerability characteristics of the target network routing mechanism as shown in Equation (12):

[0072]

[0073] (1) R instruction is the set of vulnerability characteristics of the target routing program instructions, constructed according to Equation (7). The extraction method is as follows:

[0074]

[0075] (2) R router_table is the set of vulnerability characteristics of the target network routing table, constructed according to Equation (8). The extraction method is as follows:

[0076]

[0077]

[0078] (3) R function is the set of vulnerability characteristics of the calculation functions related to the target network routing operations, constructed according to Equation (9). The extraction method is as follows:

[0079]

[0080] (4) R protocalis the set of vulnerability features of the target network routing protocol, constructed according to Equation (10), and the extraction method is as follows:

[0081]

[0082]

[0083] (5)R performance : is the set of network performance vulnerability features of the target network, constructed according to Equation (11), and the extraction method is as follows:

[0084]

[0085] Among them, rule3 means that for each node x, if node x is a security vulnerability node, then in the established simulated target network topology, simulate the vulnerabilities or malicious behaviors of the router on network node x, analyze the simulation results, and evaluate the security of node x; rule4 means that for the link connecting node x and node y, if the link is a security vulnerability link, then in the established simulated target network topology, analyze the simulation results by simulating active attacks on the link and evaluate the security of the link; rule5 means that for each node x, if node x is a reliability vulnerability node, then in the established simulated target network topology, monitor the response and recovery capabilities of node x by injecting faults into node x, and monitor the connection status of node x in real time, such as connectivity, latency and other indicators; rule6 means that for the link connecting node x and node y, if the link is a reliability vulnerability link, then evaluate the reliability of the link by injecting faults into the link and detecting performance parameter information such as the bandwidth utilization rate and packet loss rate of the link.

[0086] Step 4, according to the vulnerability features of the network routing mechanism obtained in Step 3, establish the vulnerability ontology model of the target network routing mechanism as shown in Equation (13):

[0087] NRMVDO=(C,E,S,L) (13)

[0088] In the formula, NRMVDO represents the target network routing mechanism vulnerability domain ontology (Network Routing Mechanism Vulnerabilities Domain Ontology, NRMVDO), C={c1,c2,...,c |C|} represents the class set involving the vulnerability elements of the network routing mechanism, including router class, routing protocol class, routing algorithm class, etc.; E={e1,e2,...,e |E|} represents the set of entities in a certain class. For example, the entities included in the routing protocol class are: OSPF protocol, RIP protocol, BGP protocol; S = {s1, s2,..., s |S|} represents the set of relationships between different classes, including data dependency relationships, inclusion relationships, call relationships, etc.; L = {l1, l2,..., l |L|} represents the set of constraints between classes and relationships, including: type constraints, attribute constraints, and constraint rules. In this paper, for the field of target network routing mechanism vulnerability, Protégé tool is selected for modeling based on expert knowledge;

[0089] The specific method for constructing the vulnerability ontology model of the target network routing mechanism is as follows:

[0090] Step 4.1, according to Equation (13), determine the scope and domain requirements of the ontology: The scope of the ontology should be clear, including network devices such as routers and switches in the network topology, the routing protocols followed, the attack types included, etc.; the domain of the ontology should be clear. The vulnerability ontology model of the target network routing mechanism established in this patent aims at the field of trusted vulnerability to analyze the vulnerability of the network routing mechanism;

[0091] Step 4.2, according to Equation (13), collect relevant information required for constructing the ontology: According to the scope and objectives of the ontology, collect concepts and attributes related to the vulnerability of the network routing mechanism. For example, routing protocols, routing tables, rules, conditions, instruction types, topological structures, etc.;

[0092] Step 4.3, construct the vulnerability ontology structure of the routing mechanism: According to the collected concepts and attributes, design the structure of the ontology, including the definition of ontology classes, the definition of ontology attributes and relationships, etc., as shown in the appendix Figure 2 as follows;

[0093] Step 4.4, define the vulnerability ontology instances of the routing mechanism: According to the ontology structure, define specific ontology instances, including various routers, switches, routing protocols, routing tables, rules, conditions, instruction types, topological structures, etc. Specific ontology instances are shown in Table 1 and Table 2;

[0094] Table 1 Object Property Table

[0095]

[0096] Table 2 Data Property Table

[0097]

[0098] Step 4.5, verify and correct the ontology: According to the usage of ontology instances, verify and correct the structure and content of the ontology to ensure the accuracy and integrity of the ontology.

[0099] Step 5. Based on the target network routing mechanism vulnerability dataset, feature information, and ontology model obtained in Steps 1, 2, and 4, generate a control-data flow graph, embed the network routing mechanism vulnerability feature information, extract entities, relationships, and attributes, and construct a target network routing mechanism vulnerability knowledge graph. The specific steps are as follows:

[0100] Step 5.1. Propose the RouteGraphGen algorithm (Routing program Control Data Flow Graph Generate algorithm, RouteGraphGen) to construct the RCDFG (Router Control Data Flow Graph, RCDFG) of the routing program. The RCDFG is constructed by writing a custom LLVM pass. First, perform static analysis on the programs in the dataset, collect information such as program variables, functions, and statements, and then use tools such as compilers and interpreters to perform code analysis, divide the program into basic blocks, and further combine the basic blocks into a control flow graph, including jumps and conditional statements between basic blocks. Next, construct a data dependence graph based on the variables and operations in the program, where nodes represent variables and operations, and edges represent data dependence relationships. Finally, merge the control flow graph and the data dependence graph into the RCDFG, where nodes represent instructions, operands, and data types, and edges represent control dependence, data dependence relationships, storage dependence relationships, etc. The steps of the RouteGraphGen algorithm are as follows:

[0101] Step 5.1.1. Run the target network routing program after fault injection to perform lexical analysis and syntax analysis, and construct a target routing program abstract syntax tree (Router Abstrat Syntax Tree, RAST).

[0102] Step 5.1.2. Construct a control flow graph (Control Flow Graph, CFG) of the target routing program:

[0103] (1) If the node is a conditional statement or a loop statement, create a new basic block and use it as a node in the control flow graph;

[0104] (2) If the node is a sequential statement, add it to the current basic block;

[0105] (3) If the node is a jump statement, create a new basic block and use it as a node in the control flow graph, and establish a jump relationship between the current basic block and the new basic block;

[0106] (4) Connect the basic blocks in the control flow graph to establish the control flow relationship between the basic blocks;

[0107] Step 5.1.3, construct the target routing program data dependency graph (DDG):

[0108] (1) Initialize an empty data dependency graph;

[0109] (2) Traverse each node of the syntax tree;

[0110] (3) If the node is an assignment statement, identify the data dependency relationship, take the relevant variables and operations as nodes of the data dependency graph, and establish data dependency edges;

[0111] (4) If the node is an expression, take the variables and operations in it as nodes of the data dependency graph, and establish data dependency edges;

[0112] (5) Connect the nodes in the data dependency graph to establish data dependency relationships;

[0113] Step 5.1.4, merge the control flow graph and the data dependency graph to form the RCDFG, where the nodes represent routing program instructions, operands of routing-related calculation functions, and data types, and the edges represent routing control dependencies, routing data dependencies, and routing storage dependencies. The method is as follows:

[0114] (1) Create RCDFG nodes

[0115] For each basic block of the CFG and each node of the DDG, create corresponding RCDFG nodes:

[0116] Rule 1: If it is a basic block node of the CFG, create an RCDFG node representing the instruction sequence of the routing program. These nodes should include information such as the routing program instruction type, operands corresponding to routing-related calculation functions, and data types;

[0117] Rule 2: If it is a node of the DDG, create an RCDFG node representing a routing-related calculation function or the operand corresponding to a routing-related calculation function. These nodes should include names and types related to the routing program domain;

[0118] (2) Establish the connection of the edges between the nodes in the RCDFG graph:

[0119] Rule 1: For each control dependency relationship in the CFG, that is, control structures such as conditional branches and loops in the routing program, create a control dependency edge pointing from the source node of the control dependency to the target node;

[0120] Rule 2: For each data dependency relationship in the DDG, that is, the dependency relationship between variables and operations in the routing program, create a data dependency edge to connect the relevant RCDFG nodes. This represents the data flow in the routing program;

[0121] Rule 3: For storage dependencies, handle the storage dependencies, that is, multiple writes and reads of the same data in the routing program. According to the rules and algorithms of the routing program, determine whether it is necessary to create storage dependency edges in the RCDFG. These edges represent the storage dependencies of the shared data in the routing program;

[0122] (3) Identify the data types of the nodes in the RCDFG graph;

[0123] (4) Merge all the edges and nodes to form the RCDFG:

[0124] Among them, the nodes represent the instructions of the routing program, the routing-related calculation functions, the operands and data types corresponding to the routing-related calculation functions, and the edges represent the routing control dependencies, routing data dependencies, and routing storage dependencies;

[0125] Step 5.2, perform attribute embedding on the generated RCDFG:

[0126] Step 5.2.1, according to the vulnerability feature types defined in Equation (7), traverse the RCDFG to identify the nodes related to the vulnerability features in the RCDFG;

[0127] Step 5.2.2, add the set of vulnerability features of the network routing mechanism obtained in Step 3 as the attributes of the corresponding instruction nodes in the graph, that is, the vulnerability labels of the nodes;

[0128] Step 5.3, construct the vulnerability knowledge graph of the target network routing mechanism. The construction method is as follows:

[0129] Step 5.3.1, according to the definitions and constraints of classes, attributes, and relationships in the vulnerability ontology model of the target network routing mechanism in Equation (13), start traversing the graph obtained in Step 5.2 from the root node. For each node in the graph, determine whether they represent entities, including instructions in the routing program, operands of routing-related calculation functions, data types, etc.; extract the attribute information by viewing the attributes or labels of the nodes; during the process of traversing the graph, detect the relationships between the nodes. The relationships are established based on the connections and interactions between the nodes, and these established relationships are the edges in the vulnerability knowledge graph of the target network routing mechanism;

[0130] Step 5.3.2, store the extracted entity, attribute, and relationship information in a CSV (Comma-Separated Values, CSV) file. Each entity and attribute corresponds to a row in the CSV, and the relationship corresponds to a column in the CSV. Store the knowledge graph in the format of a CSV file and display it in a visual form.

[0131] Step 6: Represent the nodes in the knowledge graph as low-dimensional, real-valued, and dense vector forms, and use them as the input for the target network routing mechanism vulnerability analysis model for model training.

[0132] Step 7: Convert the target network routing mechanism vulnerability analysis task into a node classification and prediction task, and construct a target network routing mechanism vulnerability analysis model;

[0133] Adopt a method that combines the GCN (Graph Convolutional Networks) model with the knowledge graph and combines the vulnerability label propagation algorithm to construct a KGCNLP (Knowledge Graph Convolutional Networks Label Propagation) model. Abstract the routing mechanism vulnerability analysis problem into a node classification and label prediction problem. Through training the model, learn the context relationship between the nodes and vulnerability labels in the constructed target routing mechanism vulnerability knowledge graph, classify the nodes, and predict the vulnerability labels of the nodes without labels. During the training process, use the cross-entropy loss function to optimize the model and minimize the difference between the predicted labels and the actual labels. The specific model implementation method is as follows:

[0134] Step 7.1: Perform data preprocessing. represents the network routing mechanism vulnerability knowledge graph graph after vectorization processing, V = {v1,..., v m} represents the set of nodes in the graph. is the adjacency matrix, F is the feature matrix of the nodes, and Y is the vulnerability label of the nodes. The adjacency matrix is calculated using Equation (14):

[0135]

[0136] In the formula, α is a vulnerability feature interpolation coefficient used to control the influence degree of the target network routing mechanism vulnerability feature shown in Equation (6) on the vulnerability label prediction result of the nodes in the graph. When α = 1, the original adjacency matrix is completely retained; when α = 0, only the degree matrix is retained. By adjusting the value of α, the connection strength between the nodes in the target network routing mechanism vulnerability knowledge graph is adjusted to better reflect the influence degree of the vulnerability feature on the network routing mechanism vulnerability. is the degree matrix of the network routing mechanism vulnerability knowledge graph. represents the degree matrix The diagonal element in represents the degree of node i, where represents the edge connection situation between nodes v i and v j in the graph, that is, the weight of the edge.

[0137] Step 7.2, input the vulnerability knowledge graph data obtained in Step 7.1 into a two-layer graph convolutional neural network for learning the representation of nodes in the graph. The constructed KGCN model is shown in Equation (15):

[0138]

[0139] In the formula, W (l) represents the trainable weight matrix of the l-th layer in the KGCN model, which is updated according to the feedback of the loss function during the model training process. F (l+1) represents the feature propagation update method of the l-th layer in the KGCN model, σ is the activation function, F (l) is the node representation of the l-th layer, k represents the number of update propagation iterations in the KGCN model, and the value of k is determined by the model training results and hyperparameter tuning; represents the representation of the n-th node after k times of update propagation iterations; F (0) represents the initial layer (the 0-th layer) of the graph convolutional neural network, and the feature representation of the node is equal to the input initial feature. F represents the initial feature matrix of the nodes in the knowledge graph;

[0140] Step 7.3, design a vulnerability label propagation algorithm (Vulnerability Label Propagation Algorithm, VLPA) to predict the vulnerability labels of nodes without vulnerability labels. The steps of VLPA are as follows:

[0141] Step 7.3.1, let (v1, y1), …, (v m , y m ) be the data samples with vulnerability labels, where Y m ={y1, …, y m} is the label set. Set the number of vulnerability label categories to 3 (SDC, Crash, Mask respectively), and all vulnerability label types exist in this set. For nodes without vulnerability labels (assuming the number of nodes without vulnerability labels is q), initialize the vulnerability label as "0";

[0142] Step 7.3.2, calculate the weights between any two nodes, and calculate according to Equation (16):

[0143]

[0144] In the formula, σ is the hyperparameter controlling the weight, w ij represents the distance weight between nodes v i and v j , d represents the dimension of the node features, represents node v iand v j The distance between and respectively represent the eigenvalues of nodes v i and v j on dimension d; Dim represents the number of dimensions in the feature space;

[0145] Step 7.3.3, the label propagation probability calculation formula between any two nodes in the graph is shown in Equation (17):

[0146]

[0147] In the formula, is the sum of the connection weights between all neighbor nodes of node v j . If node v i is an unlabeled node and node v j is a node with a vulnerability label, then according to the magnitude of the transition probability between the two nodes, it is determined whether node v i has the same sample label as node v j ;

[0148] Step 7.3.4, construct a vulnerability label matrix P with the structure of (m + q, 3), as shown in Table 3:

[0149] Table 3 Vulnerability Label Matrix

[0150]

[0151]

[0152] Each row is used to represent the probability distribution of each node sample belonging to each vulnerability category, which is uniformly represented by Pnode_c. Each Pnode_c represents the probability that sample Node i belongs to vulnerability category c. The calculation method of Pnode_c is as follows:

[0153] (1) For samples with known labels, that is, Node i, the corresponding probability is deterministic. Set the corresponding probability to 1, indicating that they belong to their corresponding vulnerability label categories; where, i = 1, 2,..., m;

[0154] (2) For samples with unknown labels, that is, Nodej, calculate the transition probability between Nodej and all nodes with vulnerability labels according to Equation (17), and sum up these transition probabilities to obtain a probability distribution, indicating the probability that Node j belongs to each vulnerability label category; where, j = m + 1, m + 2,..., m + q;

[0155] Step 7.3.5: Perform iterative update to predict the vulnerability label types of nodes without vulnerability labels:

[0156] (1) Calculate the updated vulnerability labels:

[0157] Y = PT ij (18)

[0158] Where P represents the vulnerability label matrix, and T ij is the transition probability between nodes v i and v j ;

[0159] (2) Perform row normalization on the updated vulnerability label matrix Y so that the sum of probabilities in each row equals 1:

[0160]

[0161] Where Pnode_c is the probability that the sample belongs to class c, and c represents the vulnerability class, including three vulnerability types SDC, Crash, and Mask, denoted as c = 1, 2, 3 respectively;

[0162] Replace the results at the label positions of nodes with known vulnerability labels with the initialized vulnerability labels. Repeat steps (1) and (2) until convergence to construct the KGCNLP model and obtain the vulnerability label types of nodes with unknown labels.

[0163] In one embodiment, a vulnerability analysis system for network routing mechanisms based on a knowledge graph is provided, characterized in that the system includes:

[0164] The first module is used to implement a random fault injection experiment on the target low-earth orbit interconnection network routing program set according to a typical routing program design fault injection experiment scheme, and construct a network routing mechanism vulnerability data set;

[0165] The second module is used to implement the establishment of a virtual network topology according to the actual network topology of the target low-earth orbit Internet and considering various factors, that is, to simulate the target network model and realize the simulation of the target low-earth orbit Internet routing mechanism;

[0166] The third module is used to implement running the routing program on the routers of the simulated target network, simulate the vulnerability of the network routing mechanism, analyze the running results, dynamically collect the vulnerability characteristic information of the target network routing mechanism, and construct a network routing mechanism vulnerability data set;

[0167] The fourth module is used to implement the design of the pattern layer of the target network routing mechanism vulnerability knowledge graph according to the vulnerability characteristics of the network routing mechanism, and construct the target routing mechanism vulnerability ontology model;

[0168] The fifth module is used to generate a control flow data flow graph according to the obtained network routing mechanism vulnerability data set, embed the network routing mechanism vulnerability features, and construct a target network routing mechanism vulnerability knowledge graph;

[0169] The sixth module is used to represent the nodes in the knowledge graph in the form of low-dimensional, real-valued, and dense vectors, and use them as the input of the target network routing mechanism vulnerability analysis model for model training;

[0170] The seventh module is used to convert the target network routing mechanism vulnerability analysis task into a node classification and prediction task, and construct a target network routing mechanism vulnerability analysis model;

[0171] The eighth module is used to analyze the vulnerability of the instruction nodes in the target network routing mechanism vulnerability knowledge graph according to the constructed target network routing mechanism vulnerability analysis model, and obtain the vulnerability of the target network routing mechanism from the analysis experimental results.

[0172] After the network routing mechanism vulnerability analysis model of the present invention is trained, it can automatically predict the vulnerability types of the instructions in the routing program, and further analyze to obtain the vulnerability of the network routing mechanism, so as to be able to perform reinforcement operations on the instructions with higher vulnerability in advance, and improve the reliability and security of the routing mechanism. The network routing mechanism vulnerability analysis method of the present invention is more comprehensive, detailed, and has a visual structure compared with other methods. Figure 3 Some instances of the network routing mechanism vulnerability knowledge graph constructed in the method of the present invention are shown.

[0173] Figure 4 This is the experimental result of the method of the present invention. The performance indicators of the target network routing mechanism vulnerability analysis model are quantified using accuray (accuracy), recall, f1_score, and presicion (precision), indicating that the method of the present invention can achieve a good analysis effect.

[0174] In summary, the vulnerability analysis method of the network routing mechanism based on the knowledge graph proposed by the present invention has the main idea of accurately predicting the instructions in the routing program that may cause the vulnerability of the routing mechanism, analyzing the vulnerability of the routing program, using the knowledge graph to model and analyze the overall program implementing the routing mechanism, and summarizing and displaying the relevance between the complex structure of the program, instruction and function operations, routing protocols, packet reception, transmission and verification, etc. and the program vulnerability in the form of a graph. The vulnerability of the program is analyzed by training a graph neural network model to learn the context semantic relationship between the nodes in the knowledge graph, and further analyze the vulnerability of the overall network routing mechanism. The technology and model based on deep learning provide effective support for realizing efficient and accurate prediction of instruction vulnerability. The method of the present invention helps to enhance the reliability and security of the network.

[0175] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A network routing mechanism vulnerability analysis method based on knowledge graph, characterized in that: The method comprises the following steps: Step 1: Design a fault injection experiment plan for typical routing programs, conduct random fault injection experiments on the target low-orbit interconnection network routing program set, and build a network routing mechanism vulnerability dataset; Step 2: According to the actual network topology of the target low-orbit Internet and taking into account various factors, a virtual network topology is established, that is, a target network model is simulated to realize the simulation of the routing mechanism of the target low-orbit Internet; Step 3, running the routing program on the router simulating the target network, simulating the vulnerability of the network routing mechanism, analyzing the running results, dynamically collecting the vulnerability feature information of the target network routing mechanism, and constructing the vulnerability feature set of the network routing mechanism; Step 4: According to the vulnerability characteristics of the network routing mechanism, the target network routing mechanism vulnerability knowledge graph model layer is designed to construct the target routing mechanism vulnerability ontology model; Step 5: Generate a control flow data flow graph based on the obtained network routing mechanism vulnerability data set, embed the network routing mechanism vulnerability features, and construct a target network routing mechanism vulnerability knowledge graph; Step 6: Represent the nodes in the knowledge graph in the form of low-dimensional, real-valued, dense vectors, and use them as input for the target network routing mechanism vulnerability analysis model for model training; Step 7: Convert the routing mechanism vulnerability analysis task of the target network into a node classification and prediction task, and construct a routing mechanism vulnerability analysis model of the target network; Step 8, analyzing the vulnerability of the instruction nodes in the target network routing mechanism vulnerability knowledge graph according to the constructed target network routing mechanism vulnerability analysis model, and analyzing the experimental results to obtain the vulnerability of the target network routing mechanism; The simulated target network model in step 2 is constructed based on multiple factors as shown in formula (1): F topology =(T scale ,T paramter ,T topology ,T protocol ,T safety ,T state ) (1) Where, T scale is the network size, T paramter is the network performance parameter, T topology is the network topology type, T protocol is the routing protocol, T safety Configure security for your router. state is the network node status; Network performance parameters T paramter As shown in formula (2): T paramter =(D delay ,C convergence ,B bandwidth ,T traffic ) (2) Where D delay is the network delay, C convergence is the routing convergence time, B bandwidth is the network bandwidth, T traffic is the data flow, i.e., the number of data packets received by the node; Network topology type T topology As shown in formula (3): T topology =(S star ,N net ,C circle ) (3) In the formula, S star N represents the star network topology of the space-based network; net Represents the mesh network topology of the space-based network; C circle Represents the ring network topology of the space-based network; Router configuration security safety As shown in formula (4): T safety =(A authentication ,L log ,S safe_protocal ) (4) In the formula, A authentication For router authentication and authorization, L log For security logging, S safe_protocal For security protocols; Network node status T state As shown in formula (5): T state =(A active ,F faulty ,O offline ,S security ) (5) In the formula, A active Indicates whether the network node is active, F faulty Indicates whether the network node is in a fault state, O offline Indicates whether the network node is offline, S security Indicates whether the network node is in a secure state. If the status information is 0, it means the network node is in a secure state, otherwise it is in a highly vulnerable state. Configure routing protocols for the constructed network topology. The routing protocols used include: OSPF protocol, BGP protocol, and RIP protocol; Step 3 specifically includes: Step 3.1, construct the target network routing mechanism vulnerability data set type set F as shown in formula (6): F=(I type ,R table ,F operate ,P protocol ,T performance ) (6) In the formula, I type is the instruction type in the routing program, R table is the routing table, F operate is the calculation function related to routing operation, P protocol is the routing protocol, T performance For network performance; Instruction Type Characteristics I type As shown in formula (7): I type =(i com ,i cal ,i shi ,i conv ,i term ,i float ,i send ,i receive ,i check ) (7) In the formula, i com For comparison instructions, i cal is the operation instruction, i shi For shift instructions, i conv is the conversion instruction, i term To terminate the instruction, i float For floating point instructions, i send Instructions sent for control information, i receive Instructions for controlling information reception, i check To verify the instruction; Routing table characteristics R table As shown in formula (8): In the formula, r sorce_ip is the source IP address, r des_ip is the destination IP address, r interface is the interface information, r router_id is the router ID, r protocal is the next hop information, r available_links Available link information; Routing operation related function type characteristics F operate As shown in formula (9): F operate =(f routing_algorithm ,f packet_handle ,f system_call ,f safety_check ,f interface_charge ) (9) In the formula, f routing_algorithm is the relevant function implemented by the routing algorithm, f packet_handle is the data packet processing function, f function_call For function call function, f safety_check is the security verification function, f interface_charge Configure management functions for interfaces; Routing Protocol Characteristics protocol As shown in formula (10): P protocol =(p rip ,p ospf ,p bgp ) (10) In the formula, p rip is the RIP protocol, p ospf For OSPF protocol, p bgp It is the BGP protocol; Network performance characteristics performance As shown in formula (11): In the formula, t delay is the network delay, t struc is the network topology type, t packet_loss is the packet loss rate, t convergecne is the routing convergence time, t connect is the network connectivity, t safe_secure The reliability of network nodes and links; Step 3.2, based on the rules and conditions for extracting the vulnerability features of the target network routing mechanism, an RMVFE algorithm is proposed to extract the vulnerability features of the target network routing mechanism, which specifically includes: Step 3.2.1 extracts the target network routing mechanism vulnerability feature set as shown in formula (12): (1)R instruction is the target routing program instruction vulnerability feature set, which is constructed according to formula (7) and the extraction method is as follows: (2)R router_table is the target network routing table vulnerability feature set, which is constructed according to formula (8) and the extraction method is as follows: (3)R function is the vulnerability feature set of the target network routing operation related computing function, which is constructed according to formula (9) and the extraction method is as follows: (4)R protocal is the target network routing protocol vulnerability feature set, which is constructed according to formula (10) and the extraction method is as follows: (5)R performance : The network performance vulnerability feature set of the target network is constructed according to formula (11), and the extraction method is as follows: Among them, rule 3 means that for each node x, if node x is a security vulnerable node, then in the established simulated target network topology, simulate the vulnerability or malicious behavior of the router on the network node x, analyze the simulation results, and evaluate the security of node x; rule 4 means that for the link connecting node x and node y, if the link is a security vulnerable link, then in the established simulated target network topology, simulate active attacks on the link, analyze the simulation results, and evaluate the security of the link; rule 5 means that for each node x, if node x is a reliability vulnerable node, then in the established simulated target network topology, monitor the response and recovery capabilities of node x by injecting faults into node x, and monitor the connection status of node x in real time, including connectivity and delay indicators; rule 6 means that for the link connecting node x and node y, if the link is a reliability vulnerable link, evaluate the reliability of the link by injecting faults into the link and detecting the parameter information of the link; The target routing mechanism vulnerability ontology model in step 4 is shown in formula (13): NRMVDO=(C,E,S,L) (13) Where, C={c1,c2,...,c |C| } represents the class set of elements related to the vulnerability of network routing mechanism, including router class and routing protocol class; E = {e1, e2, ..., e |E| } represents the entity set in a certain class; S = {s1,s2,...,s |S| } represents the set of relationships between different classes, including data dependency, inclusion, and call relationships; L = {l1,l2,...,l |L| } represents the constraint set of classes and relationships, including: type constraints, attribute constraints and constraint rules; The method for constructing the target routing mechanism vulnerability ontology model in step 4 is as follows: Step 4.1, according to formula (13), determine the scope and domain requirements of the routing mechanism vulnerability ontology: the scope of the ontology covers the network devices included in the network topology, the routing protocols followed, and the types of attacks against network routing; Step 4.2, according to formula (13), collect the relevant information required to build the ontology: according to the scope and objectives of the ontology, collect concepts and attributes related to the vulnerability of network routing mechanisms; Step 4.3, construct the routing mechanism vulnerability ontology structure: based on the collected concepts and attributes, design the structure of the ontology, including the definition of ontology classes, ontology attributes and relationships; Step 4.4, define the routing mechanism vulnerability ontology instance: According to the ontology structure, define the specific ontology instance, including various routers, switches, routing protocols, routing tables, rules, conditions, instruction types, and topological structures; Step 4.5, verify and modify the ontology: verify and modify the structure and content of the ontology according to the usage of the ontology instance; The specific process of constructing the target network routing mechanism vulnerability knowledge graph in step 5 includes: Step 5.1, a RouteGraphGen algorithm is proposed to construct a router control data flow graph RCDFG for generating a routing program; wherein the steps of the RouteGraphGen algorithm are as follows: Step 5.1.1, construct the target routing program abstract syntax tree RAST; Step 5.1.2, construct the target routing program control flow graph CFG; Step 5.1.3, construct the target routing program data dependency graph DDG; Step 5.1.4, merge the control flow graph and the data dependency graph to form an RCDFG, where nodes represent routing program instructions, routing operation-related calculation function operands and data types, and edges represent routing control dependencies, routing data dependencies, and routing storage dependencies; the specific process is as follows: (1) Create RCDFG node For each CFG basic block and DDG node, create a corresponding RCDFG node: Rule 1: If it is a basic block node of CFG, create a RCDFG node to represent the instruction sequence of the routing program; these nodes should include the routing program instruction type, the corresponding operands and data type information of the calculation function related to the routing operation; Rule 2: If it is a DDG node, create a RCDFG node to represent the calculation function related to the routing operation or the operand corresponding to the calculation function related to the routing operation. These nodes should include the name and type related to the routing program field; (2) Establish edge connections between nodes in the RCDFG graph: Rule 1: For each control dependency in the CFG, i.e., the conditional branches and loop control structures in the routing program, create a control dependency edge from the source node of the control dependency to the target node; Rule 2: For each data dependency in the DDG, i.e., the dependency between variables and operations in the routing program, create a data dependency edge connecting the relevant RCDFG nodes, which represents the data flow in the routing program; Rule 3: For storage dependencies, handle storage dependencies, i.e., multiple writes and reads of the same data in the routing program. According to the rules and algorithms of the routing program, determine whether it is necessary to create storage dependency edges in RCDFG. These edges represent the storage dependencies on shared data in the routing program. (3) Identify the data type of the node in the RCDFG graph; (4) Merge all edges and points to form RCDFG: The nodes represent the instructions of the routing program, the calculation functions related to the routing operations, the operands and data types corresponding to the calculation functions related to the routing operations, and the edges represent the routing control dependency, the routing data dependency, and the routing storage dependency; Step 5.2, embed attributes into the generated RCDFG; Step 5.3, construct the target network routing mechanism vulnerability knowledge graph; Step 5.2 embeds attributes into the generated RCDFG, including: Step 5.2.1, according to the vulnerability feature type defined in formula (7), traverse the RCDFG and identify the nodes related to the vulnerability feature in the RCDFG; Step 5.2.2, add the network routing mechanism vulnerability feature set obtained in step 3 as the attribute of the corresponding instruction node in the graph, that is, the vulnerability label of the node; Step 5.3 constructs the target network routing mechanism vulnerability knowledge graph, and the construction process includes: Step 5.3.1, according to the definitions and constraints of classes, attributes, and relationships in the target network routing mechanism vulnerability ontology model (13), traverse the graph obtained in step 5.2 from the root node, and for each node in the graph, determine whether it represents an entity. If so, extract the entity information, which includes instructions in the routing program, operands of the calculation function related to the routing operation, and data types; at the same time, extract attribute information by checking the attributes or labels of the nodes; in the process of traversing the graph, detect the relationship between the nodes, which is established based on the connection and interaction between the nodes. These established relationships are the edges in the target network routing mechanism vulnerability knowledge graph; Step 5.3.2, store the extracted entity, attribute and relationship information in a CSV file, where each entity and attribute corresponds to a row of the CSV, and each relationship corresponds to a column of the CSV. The knowledge graph is stored in the format of a CSV file and displayed in a visual form; The construction process of the target network routing mechanism vulnerability analysis model, i.e., the KGCNLP model, in step 7 includes: Step 7.1, perform data preprocessing, represents the network routing mechanism vulnerability knowledge graph after vectorization processing; where V = {v1, ..., v m } represents the set of nodes in the graph, is the adjacency matrix, F is the feature matrix of the node, and Y is the vulnerability label of the node; the adjacency matrix is ​​calculated using formula (14): Where α is a vulnerability feature interpolation coefficient, which is used to control the influence of the vulnerability feature of the target network routing mechanism shown in formula (6) on the prediction results of the vulnerability labels of the nodes in the graph. When α = 1, the original adjacency matrix is ​​completely retained; when α = 0, only the degree matrix is ​​retained. By adjusting the value of α, the connection strength between the nodes in the target network routing mechanism vulnerability knowledge graph is adjusted to better reflect the influence of the vulnerability feature on the vulnerability of the network routing mechanism. is the degree matrix of the network routing mechanism vulnerability knowledge graph, Degree matrix The diagonal elements in represent the degree of node i, where Represents the node v in the graph i and v j The edge connectivity, that is, the edge weight; Step 7.2: Input the relevant data in the network routing mechanism vulnerability knowledge graph obtained in step 7.1 into a two-layer graph convolutional neural network. The constructed KGCN model is shown in formula (15): Where W (l) F represents the trainable weight matrix of the lth layer in the KGCN model, which is updated according to the feedback of the loss function during model training; (l+1) represents the feature propagation update method of the lth layer in the KGCN model, σ is the activation function, and F (l) is the node representation of the lth layer, k represents the number of update propagation iterations in the KGCN model, and the value of k is determined by the model training results and hyperparameter tuning; represents the representation of the nth node after k iterations of cross-propagation; F (0) represents the initial layer of the graph convolutional neural network, i.e., layer 0. The feature representation of the node is equal to the initial feature of the input. F represents the initial feature matrix of the node in the knowledge graph. Step 7.3, design the vulnerability label propagation algorithm VLPA to predict the vulnerability labels of nodes without vulnerability labels. The steps of the VLPA algorithm are as follows: Step 7.3.1, let (v1,y1),…,(v m ,y m ) is a data sample with vulnerability labels, where Y m ={y 1, …,y m, } is a label set, m is the number of nodes, and the vulnerability label category c includes three types: SDC, Crash, and Mask, and all vulnerability label types exist in this set; for nodes without vulnerability labels, the vulnerability label is initialized to "0"; the number of nodes without vulnerability labels is q; Step 7.3.2, calculate the weight between any two nodes, as shown in formula (16): In the formula, σ is the hyperparameter that controls the weight, w ij Represents node v i and v j The distance weight between them, d represents the dimension of the node feature, Represents node v i and v j The distance between and Respectively represent the node v i and v j The eigenvalue in dimension d, Dim represents the number of dimensions in the feature space; Step 7.3.3, the calculation formula for the transition probability between any two nodes in the graph is shown in formula (17): In the formula, For node v j The sum of the connection weights between all neighboring nodes. If node v i is an unlabeled node, node v j is a node with a vulnerability label, then the node v is determined based on the size of the transition probability between the two nodes. i Is it related to node v j Have the same sample labels; Step 7.3.4, construct a vulnerability label matrix P with a structure of (m+q,3), as shown in Table 1: Table 1 Vulnerability label matrix Each row is used to represent the probability distribution of each node sample belonging to each vulnerability category, which is uniformly represented by Pnode_c. Each Pnode_c represents the probability that sample Node i belongs to vulnerability category c. The calculation method of Pnode_c is as follows: (1) For samples with known labels, i.e., Node i, the corresponding probabilities are deterministic and are set to 1, indicating that they belong to their corresponding vulnerability label categories; where i = 1, 2, …, m; (2) For the sample with unknown label, i.e., Nodej, the transition probability between Nodej and all nodes with vulnerability labels is calculated according to formula (17). These transition probabilities are summarized to obtain a probability distribution, which represents the probability that Nodej belongs to each vulnerability label category; where j = m+1, m+2, …, m+q; Step 7.3.5, perform iterative updates to predict the vulnerability label type of nodes without vulnerability labels: (1) Calculate the updated vulnerability label: Y=PT ij (18) Where P represents the vulnerability label matrix, T ij For node v i and v j The transition probability between (2) Perform row normalization on the updated vulnerability label matrix Y so that the sum of the probabilities of each row is equal to 1: Where Pnode_c is the probability that the sample belongs to category c, c represents the vulnerability category, including three vulnerability types SDC, Crash, and Mask, which are denoted as c=1, 2, and 3 respectively; Replace the result at the label position of the known vulnerable label node with the initialized vulnerable label, repeat steps (1) and (2) until convergence, and build the KGCNLP model to obtain the vulnerable label type of the unknown label node.

2. According to the knowledge graph-based network routing mechanism vulnerability analysis method of claim 1, it is characterized in that: According to the number of nodes in the network, the network scale is divided into three levels: simple, medium and complex, and the thresholds for the divisions are custom set.

Citation Information

Patent Citations

  • Method and device for generating attack graph based on knowledge graph

    CN108933793A

  • Instruction SDC vulnerability prediction method based on long-term and short-term memory network

    CN109063775A