A task-oriented method for constructing action chains in network confrontation war games
Through the task-oriented network confrontation war game action chain construction method, using the instruction pool and task decomposition steps, the problems of slow construction and difficult reconstruction of network confrontation war game action plans are solved, and a confrontation action plan that can be quickly constructed and flexibly adjusted is realized.
Patent Information
- Application Number
- CN202410461229.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-17
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-04-17
AI Technical Summary
Existing network confrontation war game modeling methods are complex, costly, and have poor plasticity, making it difficult for operators to quickly formulate and promptly change confrontation actions.
A task-oriented network confrontation war game action chain construction method is adopted, including the command pool construction and task decomposition steps. Unified rule mapping is performed through the five elements of meta-commands (phase, action, personnel, weapon, and target), and the tasks are split through the IPDRR architecture to form a command chain.
It enables the rapid construction and flexible adjustment of adversarial actions. Operators can quickly build and optimize action chains, supporting the rapid deduction of adversarial tasks and the intuitive presentation of action results.
Smart Images

Figure CN118233203B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and in particular relates to a task-oriented network confrontation war game action chain construction method. Background Art
[0002] Cyber warfare wargame modeling primarily involves process-based modeling based on the characteristics of each entity's actions. This requires modeling the rules for each adversarial action to support cyber warfare simulations. Wargames involve a vast number of rules and numerous constraints, which vary significantly depending on the simulation level. Modeling each specific rule requires clearly describing who does what, how it is done, and what the consequences are.
[0003] Cyberspace confrontations are characterized by rapid technological advancements, diverse target types, and complex actions. During wargames, players must make decisions based on constantly changing information according to the game rules. Existing cyber confrontation wargame modeling methods are complex, costly, and lack flexibility, making them difficult to meet operators' needs for rapidly developing and modifying countermeasure actions. Therefore, designing a task-oriented action chain construction method for cyber confrontation wargames has become a pressing technical challenge. Summary of the Invention
[0004] (1) Technical issues to be solved
[0005] The technical problem to be solved by the present invention is how to provide a task-oriented network confrontation war game action chain construction method to solve the problems of slow construction and difficult reconstruction of current network confrontation war game action plans.
[0006] (2) Technical solution
[0007] In order to solve the above technical problems, the present invention proposes a task-oriented network confrontation war game action chain construction method, which includes two steps: command pool construction and task disassembly;
[0008] Instruction pool construction steps: Each confrontation mission can be divided into different phases, and different confrontation actions are implemented for different phases. Different actions should call on corresponding personnel, forces, weapons and equipment to achieve the action objectives. The instruction pool construction step maps the confrontation actions according to unified rules and standards to form meta-instructions to support the system's deduction activities. Meta-instructions are the smallest and indivisible action unit, representing the basic confrontation action. Each meta-instruction contains five elements: phase, action, target, personnel, weapon and target.
[0009] Task decomposition steps: Split the adversarial task according to the IPDRR architecture, and then select meta-instructions from the instruction pool to form an instruction chain. The instruction chains of different stages are serialized together according to the stages to form a task action chain to ensure that the adversarial task is deduced in the system; among them, the instruction chain is composed of multiple meta-instructions of the same stage, and the chain supports the completion of the task of that stage; the task action chain is composed of multiple command chains serially connected together to support the completion of the adversarial task deduction.
[0010] (3) Beneficial effects
[0011] This paper proposes a task-oriented method for constructing action chains in networked adversarial wargames. This method maps adversarial actions to unified rules, establishes meta-instructions to describe the smallest action unit, and breaks down action tasks to achieve phased processing and presentation of deduced actions. Using this method, operators can quickly construct action chains for adversarial tasks. At different stages, corresponding meta-instructions can be selected based on the objectives of each stage to form instruction chains. Multiple instruction chains support the deduction of this adversarial task, allowing for intuitive visualization of the results of each stage's actions. Furthermore, this method allows for rapid modification of action plan options, allowing operators to add or delete meta-instructions from the action chain based on actual conditions or task requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 A flowchart of the task-oriented network confrontation war game action chain construction method of the present invention;
[0013] Figure 2 This is a flow chart of Example 1 of the present invention. DETAILED DESCRIPTION
[0014] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below with reference to the accompanying drawings and examples.
[0015] The technical problem to be solved by the present invention is to propose a method for quickly constructing a task-oriented network confrontation war game action chain, which mainly solves the problems of slow construction and difficult reconstruction of current network confrontation war game action plans.
[0016] Attachment Figure 1 This paper describes a flowchart of the method for constructing a task-oriented cyber-adversarial wargame action chain, which includes two steps: command pool construction and task decomposition.
[0017] Instruction pool construction steps: Each confrontation mission can be divided into different stages, and different confrontation actions are implemented for different stages. Different actions should call on corresponding personnel, forces, weapons and equipment to achieve the purpose of the action. The instruction pool construction step maps the confrontation actions according to unified rules and standards, and constructs meta-instructions to support the system to carry out deduction activities. Meta-instructions are the smallest and indivisible action unit, representing the basic confrontation action. Each meta-instruction contains five elements: stage, action, target, personnel, weapon and target:
[0018] (1) Stage refers to the basic process of achieving combat missions. Different combat actions and personnel forces will be organized to take corresponding measures to achieve the missions at different stages. According to the IPDRR network security framework, the confrontation mission can be divided into five stages: identification, protection, detection, response, and recovery. The identification stage (I) conducts risk investigation on network assets and promptly discovers security risks. The protection stage (P) ensures the normal operation of the network through access control, security operation and maintenance, etc. The detection stage (D) promptly discovers network attack behaviors by monitoring network traffic and services. The response stage (Re) responds to and handles discovered network attack behaviors through emergency plans, policy changes, etc. The recovery stage (Ry) recovers the system and data, finds the root cause of the security incident, and conducts prevention and recovery.
[0019] (2) Action refers to the various actions taken to support the tasks of this stage. Different stages correspond to different action instructions. According to the five stages of the confrontation task, the action also includes five types of actions, namely I, P, D, Re, and Ry.
[0020] (3) Personnel refers to the personnel force mobilized to achieve mission objectives. Different types of personnel force support different actions. Personnel forces are organized for different stages of action to assist in achieving stage objectives. This factor is mapped based on the types and numbers of personnel available in reality. The same person may perform multiple actions.
[0021] (4) Weapons refer to the cyber weapons used to conduct adversarial actions. Different weapons have different effectiveness. Appropriate cyber weapons are used to achieve mission objectives in response to adversarial actions. This element is mapped based on the types and quantities of weapons currently available.
[0022] (5) Objective refers to the purpose to be achieved by the action. Different actions have different objectives and are used to help operators find meta-instructions.
[0023] The five elements above form a meta-instruction. This meta-instruction includes <Stage, Action, Person, Weapon, and Objective>, providing a unified description of the wargame meta-instructions during the game process using a five-tuple structure:
[0024] Meta Directive<Stage,Action,Person,Weapon,Objective>
[0025] Among them, force and weaponry determine whether the meta-command can be executed normally. The action element in a meta-command must be supported by the corresponding personnel and weapons, that is, Action = [Person, Weapon]. The meta-command can only be executed when the personnel and weaponry are fully equipped, that is, the mapping is Value(Action) = Value(Person) ∩Value(Weapon). When the value of the meta-command is 1, that is, Value(Action) = 1, it indicates that the action can be executed normally. When constructing meta-commands, it is assumed that all actions are supported by personnel and weapons, that is, Value(Action) = 1. The constructed meta-commands are stored in a command pool, which contains all meta-commands for cyber adversarial actions and is divided into five categories of command pools according to the action. During subsequent task decomposition, qualified meta-commands can be quickly found based on the objectives to support task deduction.
[0026] Task decomposition step: To ensure the effective deduction of the task, the task decomposition step will split the confrontation task according to the IPDRR architecture, and then select meta-instructions from the instruction pool to form an instruction chain. The instruction chains of different stages are serialized together according to the stage to form a task action chain to ensure that the confrontation task is deduced in the system. Among them, the instruction chain is composed of multiple meta-instructions of the same stage, which supports the completion of the task of that stage; the task action chain is composed of multiple command chains serially connected together to support the completion of the confrontation task deduction. The task decomposition step includes:
[0027] The first step is to break down the adversarial task. Network adversarial personnel break down the adversarial task into its components according to IPDRR, mapping it to the accumulation of several stages: Task = [I, P, D, Re, Ry].
[0028] The second step is to construct a stage command chain. After completing the first step of decomposition, the task is divided into different stages. The adversary constructs the stage command chain in parallel based on the stage tasks. For each stage task, the corresponding instruction pool is searched and meta-instructions are selected from it according to timing and logic to form the command chain that completes the stage task. To ensure the normal execution of the command chain, the meta-instructions in the command chain must be checked to ensure that each meta-instruction has personnel and weapon support. In other words, the value of all meta-instructions in the command chain must be 1. If a meta-instruction with a value of 0 exists in the command chain, it means that the command chain cannot be executed properly. The adversary must redesign the command chain until all meta-instructions in the chain have a value of 1. This completes the stage command chain construction. Taking the recognition stage as an example, four recognition stage meta-instructions are selected from the instruction pool to form the command chain, represented as Link_I = [I1, I2, I3, I5].
[0029] The third step is to form a task action chain. After completing the construction of the stage command chain, the command chains are serialized according to the mission phase to form a task action chain for mission simulation. Assuming that the mission includes five stages: identification, protection, detection, response, and recovery, the constructed task action chain contains five command chains, namely Link_Task = [Link_I, Link_P, Link_D, Link_Re, Link_Ry]. At the same time, operators can timely optimize and adjust the command chains in the task action chain according to the status of the simulation action and changes in the mission objectives to achieve the mission requirements.
[0030] Example 1:
[0031] The following is a detailed example with reference to the attached Figure 2 The present invention is described in further detail.
[0032] In this specific embodiment, the confrontation task is to discover and block cross-network infiltration actions, discover the weak links (power units) of network confrontation through system solution deduction, evaluation and analysis, and support and strengthen network confrontation forces.
[0033] In the first step, the adversary divided the anti-cross-network penetration task into three stages: detection, response, and recovery.
[0034] The second step is to build command chains for the detection, response, and recovery phases. The detection phase primarily focuses on detecting abnormal network behavior. This involves building a command chain through meta-commands like abnormal traffic monitoring, virus monitoring, Trojan horse monitoring, vulnerability and backdoor monitoring, illegal user monitoring, and network traffic monitoring to support detection. The response phase primarily focuses on handling network anomalies. This involves building a command chain through meta-commands like patch generation and virus removal to handle incidents. The recovery phase primarily focuses on upgrading the network. This involves building a command chain through meta-commands like virus library upgrades and vulnerability patching to address network vulnerabilities.
[0035] The third step is to check whether the chain of command is feasible. Check the three chains of command to ensure that the meta-commands in each chain are supported by personnel and weapons.
[0036] The fourth step is to form a task action chain. Connect the three command chains in sequence to form an anti-cross-network penetration task action chain.
[0037] The proposed method for constructing action chains for cyber-based adversarial wargames employs unified rules for mapping adversarial actions, establishes meta-instructions to describe the smallest action unit, and breaks down action tasks into phased processing and presentation. This method allows operators to quickly construct action chains for adversarial tasks. At each stage, meta-instructions corresponding to the objectives of that stage are selected to form a command chain. Multiple command chains support the deduction of this adversarial task, allowing for intuitive visualization of the results of each stage's actions. Furthermore, this method enables the rapid modification of action plan options, allowing operators to add or remove meta-instructions from the action chain based on actual conditions or task requirements.
[0038] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A task-oriented network confrontation war game action chain construction method, characterized by: The method includes two steps: instruction pool construction and task decomposition; Instruction pool construction steps: Each confrontation mission can be divided into different phases, and different confrontation actions are implemented for different phases. Different actions should call on corresponding personnel, forces, weapons and equipment to achieve the action objectives. The instruction pool construction step maps the confrontation actions according to unified rules and standards to form meta-instructions to support the system's deduction activities. Meta-instructions are the smallest and indivisible action unit, representing the basic confrontation action. Each meta-instruction contains five elements: phase, action, personnel, weapons and target. Task decomposition steps: The adversarial task is split according to the IPDRR architecture, and then meta-instructions are selected from the instruction pool to form an instruction chain. The instruction chains of different stages are serialized together according to the stage to form a task action chain to ensure that the adversarial task can be deduced in the system. Among them, the instruction chain is composed of multiple meta-instructions of the same stage, which supports the completion of the stage task. The task action chain is composed of multiple instruction chains serially connected together to support the completion of the adversarial task deduction. in, The stage refers to the process of achieving combat missions. Different combat actions and personnel forces will be organized to take corresponding measures to achieve the missions at different stages. According to the IPDRR network security framework, the confrontation mission is divided into five stages: identification I, protection P, detection D, response Re and recovery Ry. In the identification stage I, risk investigation of network assets is carried out to timely discover security risks. In the protection stage P, access control and security operation and maintenance are used to ensure the normal operation of the network. In the detection stage D, network attack behaviors are detected in a timely manner by monitoring network traffic and business methods. In the response stage Re, emergency plans and policy jumps are used to respond to and handle discovered network attacks. In the recovery stage Ry, systems and data are restored, and the root causes of security incidents are found for prevention and recovery.
2. The task-oriented network confrontation war game action chain construction method according to claim 1, characterized in that: Action refers to the various actions taken to support the tasks of this stage. Different stages correspond to different action instructions. According to the five major stages of the confrontation task, the action also includes five categories of actions, namely I, P, D, Re, and Ry.
3. The task-oriented network confrontation war game action chain construction method according to claim 2, characterized in that: Personnel refers to the human resources mobilized to achieve mission objectives. Different types of personnel support different actions. Corresponding personnel are organized for actions at different stages to assist in achieving stage goals. This element is mapped according to the types and numbers of personnel available in reality, and the same person may perform multiple actions.
4. The task-oriented network confrontation war game action chain construction method according to claim 3, characterized in that: Weapons refer to the cyber weapons used in conducting confrontational actions. Different weapons have different effectiveness. Appropriate cyber weapons are used in confrontational actions to achieve mission objectives. This element is mapped according to the types and quantities of weapons available in reality.
5. The task-oriented network confrontation war game action chain construction method according to claim 4, characterized in that: The goal refers to the purpose of the action. Different actions have different goals, which are used to help operators find meta-instructions.
6. The task-oriented network confrontation war game action chain construction method according to claim 5, characterized in that: Meta-instructions include <phase, action, personnel, weapons, and target>, which are uniformly described in the form of a five-tuple structure for the wargame meta-instructions during the game process: Meta Directive<Stage,Action,Person,Weapon,Objective> Among them, strength and weapons will determine whether the meta-command can be executed normally; the action element in the meta-command must have corresponding personnel support and weapon guarantee, that is, Action = [Person, Weapon]; The constructed meta-instructions will be stored in the instruction pool, which contains all the meta-instructions of network adversarial actions. The instructions are stored in five types of instruction pools according to the actions. When the subsequent tasks are disassembled, the qualified meta-instructions are quickly found according to the goals to support task deduction.
7. The task-oriented network confrontation war game action chain construction method according to claim 6, characterized in that: The meta-instruction can only be executed when personnel and weapons and equipment are fully equipped, that is, the mapping is Value(Action)=Value(person)∩Value(weapon); when the value of the meta-instruction is 1, that is, Value(Action)=1, it means that the action can be executed normally; when constructing the meta-instruction, it is assumed that all actions are supported by personnel and weapons, that is, Value(Action)=1.
8. The method for constructing a task-oriented network confrontation war game action chain according to any one of claims 1 to 7, characterized in that: The task decomposition step includes: The first step is to decompose the adversarial task: the network adversary personnel will split the adversarial task into detailed parts according to IPDRR and map it into the accumulation of several stages, that is, Task = [I, P, D, Re, Ry]; The second step is to build a stage command chain: After completing the first step of decomposition, the task is divided into different stage tasks. The adversary builds the stage command chain in parallel according to the stage tasks. For each stage task, the adversary searches the corresponding instruction pool and selects meta-instructions from it according to the timing and logic to form the command chain that completes the stage task. The third step is to form a task action chain: After completing the construction of the stage command chain, the command chains are serialized together according to the task stages to form a task action chain to carry out task deduction; assuming that the task includes five stages: identification, protection, detection, response and recovery, the constructed task action chain contains five command chains, namely Link_Task = [Link_I, Link_P, Link_D, Link_Re, Link_Ry]; at the same time, the operator will timely optimize and adjust a certain command chain in the task action chain according to the status of the deduction action and the changes in the task objectives to meet the task requirements.
9. The task-oriented network confrontation war game action chain construction method according to claim 8, characterized in that: In the second step, the meta-instructions in the command chain are checked to ensure that each meta-instruction has personnel and weapon support, that is, to ensure that the values of all meta-instructions in the command chain are 1; if there is a meta-instruction with a value of 0 in the command chain, it means that the command chain cannot be executed normally, and the confrontation personnel need to redesign the command chain until the meta-instruction values in the chain are all 1, and then the stage command chain construction is completed.
Citation Information
Patent Citations
APT attack behavior analysis and detection method and device based on cascade attack chain model
CN110602042A
Wargame deduction system
CN115239023A