Network attack and defense strategy selection method and system based on three-party evolutionary game
By constructing a three-party evolutionary game model that considers the interaction between the attacker, the defender, and the user, the problem of neglecting the user in existing network attack and defense confrontations is solved, and more accurate network defense strategy selection and security improvement are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Chinese People's Liberation Army Cyberspace Force Information Engineering University
- Filing Date
- 2024-03-22
- Publication Date
- 2026-05-29
AI Technical Summary
Existing methods for selecting network attack and defense strategies only consider the perspectives of the attackers and defenders, neglecting the users themselves. They cannot accurately model and describe real-world attack and defense scenarios, thus affecting the effectiveness of network defense strategy selection.
A three-party participant model based on evolutionary game theory is constructed, including attackers, defenders, and users. By imitating and learning advantageous strategies and adjusting their respective strategies under the drive of game payoffs, the dynamic equation of the three-party behavioral strategy selection is used to solve for stability and obtain the optimal selection strategy.
It provides a more accurate description of real-world network attack and defense scenarios, offers more proactive and effective defense measures, can curb network attacks, and improve network security defense capabilities.
Smart Images

Figure CN118432850B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method and system for selecting network attack and defense strategies based on three-party evolutionary game theory, to guide the selection of cyberspace defense strategies. Background Technology
[0002] Evolutionary game theory originates from Darwin's ideas on biological evolution. It views decision-makers as boundedly rational individuals and takes group behavior as its research object. By explaining the long-term development and evolutionary selection of biological species, it analyzes the evolutionary game process of biological behavior. In the process of biological evolution, different individuals, through long-term trial and error, learning and adjustment, will eventually tend towards a certain stable strategy. This stable strategy has good stability and may remain stable in the long term. This is very similar to the evolutionary stable strategy in biological evolution theory, and ultimately a game equilibrium state can be reached.
[0003] With the ever-expanding scale of cyberspace, network information technology has been widely applied to various industries, effectively promoting the development and progress of society in the information age. However, it also faces serious security threats and challenges. The main form of confrontation between parties in cyberspace is network attack and defense. To minimize damage or further reduce losses, scientific, reasonable, and feasible defense strategies are needed to improve security capabilities. Therefore, researching network security analysis methods based on game theory and strengthening the construction of defense technology systems has significant practical implications. In the process of network attack and defense games, the security knowledge and skill levels of different attacking and defending parties are not entirely consistent, leading to different decision-making mechanisms. Participants initially gain different payoffs during the game. As time changes, driven by payoff differences and learning mechanisms, both sides improve their decisions by imitating and learning each other's strategies. Under this mechanism, the attack and defense confrontation exhibits dynamic evolution, eventually reaching a stable state over time. The replicating dynamic equation is used to analyze and solve the game model, thereby obtaining the optimal defense strategy for the attack and defense game system. Currently, game theory plays an important role in network security situation assessment, network attack and defense confrontation, and network information warfare, making significant contributions to the field of network security. However, existing methods for selecting network attack and defense strategies only consider the perspectives of the attackers and defenders, neglecting the users themselves. They cannot accurately model and describe real-world attack and defense scenarios, thus affecting the effectiveness of network defense strategy selection in actual cyberspace. Summary of the Invention
[0004] To address this, the present invention provides a method and system for selecting network attack and defense strategies based on three-party evolutionary game theory. This method solves the problem that existing network attack and defense strategy selection neglects the user and causes discrepancies between the game model and the actual attack and defense scenario. By constructing a game model involving the attack, defense, and user parties, the present invention can more accurately model and describe real-world attack and defense scenarios, providing technical support for solving network information security problems.
[0005] According to the design scheme provided by this invention, on the one hand, a method for selecting network attack and defense strategies based on three-party evolutionary game theory is provided, comprising:
[0006] Based on evolutionary game theory, a three-party evolutionary game model is constructed, in which the attacker, the defender, and the user are the participants in the network attack and defense confrontation. In the evolutionary game, the participants in the three-party evolutionary game model learn advantageous strategies by imitation and adjust their respective strategy choices under the drive of game payoffs.
[0007] By using the dynamic equations of the three-party behavioral strategy selection, the stability of the three-party evolutionary game model is solved, the equilibrium point of the three-party evolutionary game model is obtained, and the optimal selection strategy of each participant is obtained based on the equilibrium point of the three-party evolutionary game model.
[0008] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory, this invention further constructs a three-party evolutionary game model based on evolutionary game theory, in which the attacker, defender, and user are the participants in the network attack and defense confrontation, including:
[0009] By using network information systems to scan the target network for vulnerabilities and combining the vulnerability database data, a set of attack behavior strategies for attackers is constructed. Based on the defense behaviors taken by defenders when the attack occurs, a set of defense strategies for defenders is constructed. Furthermore, a set of user behavior strategies is constructed by collecting user access behavior during the attack and defense process.
[0010] This study analyzes the impact of attack costs and gains on attackers' behavioral strategies, the impact of defense costs and gains on defenders' behavioral strategies, and the impact of the gains and losses from successful or failed user accesses on user behavioral strategies. Based on the attackers, defenders, users, their behavioral strategies, and the gains and losses from attack and defense, a three-party evolutionary game model is constructed to describe the dynamic attack and defense game process.
[0011] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory in this invention, the three-party evolutionary game model is further represented as a quadruple (N,S,P,U), where N is the space of game participants consisting of attackers, defenders, and users; S is the game strategy space consisting of the set of behavioral strategies of each participant; P is the set of game beliefs consisting of the probability of selecting behavioral strategies of each participant; and U is the set of payoff functions consisting of the payoffs of each participant under different strategy combinations.
[0012] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory, this invention further utilizes the dynamic equations for selecting three-party behavioral strategies to solve for the stability of the three-party evolutionary game model, including:
[0013] An average payoff function for the attacker is constructed based on the probability of the attacker choosing an attack strategy, the required cost, and the attack success rate.
[0014] An average revenue function for the defender is constructed based on the probability of the defender selecting a defensive action strategy, the value of its data assets, the fixed revenue brought by the data assets, the cost required to select a defensive action, and the losses suffered by the defender when user access fails.
[0015] The average revenue function for users is constructed based on the probability of users choosing access strategies, the revenue gained by users through normal access, and the loss factor passed to users when access fails.
[0016] Based on the average payoff function of each participant, we construct the three-party behavioral strategy selection replication dynamic equations respectively, and construct the three-party game evolution equation set by simulating the replication dynamic equations of each behavioral strategy selection.
[0017] The stability of the three-party evolutionary game model is solved by using the three-party game evolution equations to obtain the equilibrium point of the three-party evolutionary game model.
[0018] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory in this invention, the stability of the three-party evolutionary game model is further solved using a set of three-party game evolution equations, including:
[0019] The behavioral strategies of each agent in the three-party game evolution equation set are selected and the replication dynamic equation is assigned a value of 0 to obtain the stable equilibrium point of the three-party evolution game model.
[0020] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory in this invention, further, the optimal selection strategy for each participating entity is obtained based on the equilibrium point of the three-party evolutionary game model, including:
[0021] By replicating the dynamic equations, the corresponding partial derivative function Jacobian matrix is obtained, and the equilibrium point is substituted into the Jacobian matrix to obtain the eigenvalues of each stable equilibrium point.
[0022] Based on eigenvalues and using Lyapunov's first rule to analyze the stability of each equilibrium point, we can obtain the game evolution patterns under different scenarios and the optimal choice strategies of each participant.
[0023] As a method for selecting network attack and defense strategies based on three-party evolutionary game theory in this invention, further, the stability of each equilibrium point is analyzed based on eigenvalues and using Lyapunov's first rule, including:
[0024] An equilibrium point is a stable point when all corresponding eigenvalues are negative, and an equilibrium point is an unstable point when at least one corresponding eigenvalue is positive.
[0025] Furthermore, this invention also provides a network attack and defense strategy selection system based on three-party evolutionary game theory, comprising: an attack and defense modeling module and a model solving module, wherein,
[0026] The attack and defense modeling module is used to construct a three-party evolutionary game model based on evolutionary game theory, in which the attacker, the defender and the user are the participants in the network attack and defense confrontation. The participants in the three-party evolutionary game model learn advantageous strategies by imitation in the evolutionary game and adjust their respective strategy choices under the drive of game payoffs.
[0027] The model solving module is used to solve the stability of the three-party evolutionary game model by selecting dynamic equations based on the three-party behavioral strategies, obtain the equilibrium point of the three-party evolutionary game model, and obtain the optimal selection strategy of each participant based on the equilibrium point of the three-party evolutionary game model.
[0028] The beneficial effects of this invention are:
[0029] This invention takes actual network attack and defense confrontation as the research background, deploys a network information system, and starts from the perspective of bounded rationality. By introducing a third-party participant—the user—it constructs a three-party evolutionary game model composed of the attacker, the defender, and the user based on evolutionary game theory, finds its equilibrium solution, and conducts stability analysis on the equilibrium point of the game model. It obtains the game evolution law under different situations and the optimal strategy selection of each subject, which is more in line with actual network scenarios and facilitates the selection of more proactive and effective defense measures to curb network attacks. It has good application prospects. Attached image description:
[0030] Figure 1 This is a schematic diagram of the network attack and defense strategy selection process based on three-party evolutionary game in the embodiment;
[0031] Figure 2 This is a schematic diagram of the three-party attack and defense game tree structure in the embodiment;
[0032] Figure 3 This is a schematic diagram of the evolution phase of the attacker's behavior strategy in the embodiment.
[0033] Figure 4 This is a schematic diagram of the evolution phase of the defender's behavioral strategy in the embodiment.
[0034] Figure 5 This is a schematic diagram of the user policy evolution phase in the embodiment;
[0035] Figure 6 This is a schematic diagram of the experimental network information system topology in the embodiment;
[0036] Figure 7 This example illustrates the stable strategies of a three-way evolutionary game under different initial values.
[0037] Figure 8 This example illustrates the analysis of factors influencing the selection of the attacker's strategy.
[0038] Figure 9 This is a schematic diagram illustrating the factors influencing the selection of defense strategies in this embodiment.
[0039] Figure 10 This example illustrates the analysis of factors influencing user strategy selection. Detailed implementation method:
[0040] To make the objectives, technical solutions, and advantages of this invention clearer and more understandable, the invention will be further described in detail below with reference to the accompanying drawings and technical solutions.
[0041] Existing network attack and defense strategies only consider the attacker and defender, neglecting the user. To address the issue of defense strategy selection in network attack and defense scenarios and to more accurately model and describe real-world attack and defense scenarios, this invention provides an embodiment (see [link]). Figure 1 As shown, a method for selecting network attack and defense strategies based on three-party evolutionary game theory is provided, including:
[0042] S101. Based on evolutionary game theory, a three-party evolutionary game model is constructed, in which the attacker, the defender, and the user are the participants in the network attack and defense confrontation. The participants in the three-party evolutionary game model learn advantageous strategies by imitation in the evolutionary game and adjust their respective strategy choices under the drive of game payoffs.
[0043] Specifically, network information systems can be used to scan the target network for vulnerabilities and combine this with vulnerability database data to construct a set of attack strategies for the attacker. A set of defense strategies for the defender can be constructed based on the defense actions taken by the defender when the attack occurs. A set of user behavior strategies can be constructed by collecting user access behavior during the attack and defense process. The impact of attack costs and gains on the attacker's behavior strategies, the impact of defense costs and gains on the defender's behavior strategies, and the impact of the gains and losses from successful or failed user access on user behavior strategies can be analyzed. Based on the attacker, defender, user, and their respective sets of behavior strategies and attack and defense gains, a three-party evolutionary game model can be constructed to describe the dynamic attack and defense game process.
[0044] The network attack-defense tripartite evolutionary game model (NADTEGM) in this embodiment can be represented as a 4-tuple, NADTEGM = (N, S, P, U).
[0045] 1) N = (N A N D N U ) represents the space of game participants. Where N...A Indicates the attacker, N D N represents the defending side. U Indicates the user.
[0046] 2) S=(S A ,S D ,S U S is the strategy space of the game. A ={S A1 ,S A2 ,…S An} represents the attacker's set of strategies, S D ={S D1 ,S D2 …S Dm} represents the set of strategies of the defending side, U S ={S U1 ,S U2 ,…S Ul} represents the user's set of policies.
[0047] 3) P = (x, y, z) is the set of game beliefs. Here, x represents the attacker's chosen attack strategy S. Ai The probability y represents the defender's choice of defense strategy S. Dj The probability z represents the user's choice of strategy S. Uk The probability of.
[0048] 4) U=(U A U D U U ) is a set of payoff functions, representing the game payoffs of each participant under different strategy combinations.
[0049] S102. Using the dynamic equations selected by the three parties' behavioral strategies, the stability of the three-party evolutionary game model is solved to obtain the equilibrium point of the three-party evolutionary game model. Based on the equilibrium point of the three-party evolutionary game model, the optimal selection strategy of each participant is obtained.
[0050] Specifically, the stability solution of the three-party evolutionary game model can be designed by selecting dynamic equations based on the three-party behavioral strategies, and can include the following:
[0051] An average payoff function for the attacker is constructed based on the probability of the attacker choosing an attack strategy, the required cost, and the attack success rate.
[0052] An average revenue function for the defender is constructed based on the probability of the defender selecting a defensive action strategy, the value of its data assets, the fixed revenue brought by the data assets, the cost required to select a defensive action, and the losses suffered by the defender when user access fails.
[0053] The average revenue function for users is constructed based on the probability of users choosing access strategies, the revenue gained by users through normal access, and the loss factor passed to users when access fails.
[0054] Based on the average payoff function of each participant, we construct the three-party behavioral strategy selection replication dynamic equations respectively, and construct the three-party game evolution equation set by simulating the replication dynamic equations of each behavioral strategy selection.
[0055] The stability of the three-party evolutionary game model is solved by using the three-party game evolution equations to obtain the equilibrium point of the three-party evolutionary game model.
[0056] In network attack and defense confrontations, attacker A, defender D, and user U can choose different strategies. These three parties imitate and learn advantageous strategies and adjust their respective strategy choices under the drive of self-interest, thus exhibiting a dynamic nature in the attack and defense process. The game tree formed by the three parties during the attack and defense process is as follows: Figure 2 As shown.
[0057] Assume the three parties have the following set of available strategies: {Strong Attack S} A1 Weak attack S A2}, {Strong Defense S D1 Weak defense S D2}, {Access S U1 Do not access S U2 C1 and C2 represent the costs for the attacker to choose strong attack and normal attack strategies respectively; α represents the probability of successful attack under different strategies chosen by the attacker and defender; V represents the value of the resources owned by the defender; E represents the fixed benefit brought to the defender by the resources; C3 represents the cost for the defender to choose strong defense (the cost is negligible when choosing weak defense); L represents the loss suffered by the defender when the user access fails; R represents the benefit gained by the user when the access is successful; β represents the reduction factor (the loss suffered by the defender will be reduced and passed on to the user). The symbols and meanings of the three main parameters in the game model are shown in Table 1.
[0058] Table 1. Parameter settings for the three parties in the game model.
[0059]
[0060]
[0061] The expected return function E of the three parties under different strategy combinations ij (i = 1, 2, 3 and j = 1, 2) and the average return function E i .
[0062] The expected payoff functions for the attacker's strong attack strategy and weak attack strategy are E. 11 and E12 The average return function is E1.
[0063]
[0064] The expected payoff functions for the defender's strong defense strategy and weak defense strategy are E. 21 and E 22 The average return function is E2.
[0065]
[0066] The expected revenue functions for user access policies and non-access policies are E 31 and E 32 The average return function is E3.
[0067]
[0068] According to the system of equations (1), the dynamic equation for the attacker's replication and its first-order partial derivatives are as follows:
[0069]
[0070] When y = C1 - C2 + V(α-1) / V(2α-1), F(x) ≡ 0. At this point, regardless of the value of x, dF(x) / dx = 0, meaning the attacker's strategy is in a stable state. When y ≠ C1 - C2 + V(α-1) / V(2α-1), let y * =C1-C2+V(α-1), and we will discuss the cases according to the value of α: 1) When 2α-1>0, y<y * If x = 0, then x = 0 is the final evolutionary stable strategy; if y > y * If x = 1 is the final evolutionary stable strategy, then the phase diagram of the attacker's behavioral strategy evolution is as follows: Figure 3 As shown in (a) of the diagram. 2) When 2α-1 < 0, if y < y * If x = 1, then x = 1 is the final evolutionary stable strategy; if y > y * If x = 0, then the final evolutionary stable strategy is as follows. The phase diagram of the attacker's behavioral strategy evolution at this point is shown below. Figure 3 As shown in (b) of the diagram.
[0071] According to equation system (2), the dynamic equation for the defensive replication and its first-order partial derivatives are as follows:
[0072]
[0073] When x = [α(V+zL)-C3] / (2α-1)(V+zL), F(y)≡0, then regardless of the value of y, dF(y) / dy = 0, meaning the defensive strategy is in a stable state; when x≠[α(V+zL)-C3] / (2α-1)(V+zL), let x * = [α(V+zL)-C3] / (V+zL), and discuss according to the value of α: 1) When 2α-1>0, if x<x * If y = 1, then y = 1 is the final evolutionarily stable strategy; if x > x * If y = 0, then the final evolutionary stable strategy is shown in the phase diagram of the defender's behavioral strategy evolution at this point. Figure 4 As shown in (a) of the diagram. 2) When 2α-1 < 0, if x < x * If y = 0, then y = 0 is the final evolutionarily stable strategy; if x > x * If y = 1, then y = 1 is the final evolutionarily stable strategy. The phase diagram of the defensive side's behavioral strategy evolution at this point is as follows: Figure 4 As shown in (b) of the diagram.
[0074] According to equation system (3), the user replication dynamic equation and its first-order partial derivative are as follows:
[0075]
[0076] when When z is constant, dF(z) / dz = 0 regardless of the value of z, indicating that the user's policy choice is in a stable state; when y ≠ y * At this point, analysis reveals that z = 0 or z = 1 are the two stable points in the dynamic equations of the user policy replication. When y > y * When z = 0, it is the final evolutionary stable strategy; when y < y * When z=1, the final evolutionary stable policy is shown in the phase diagram of the user behavior policy evolution as follows: Figure 5 As shown.
[0077] By combining the behavioral strategies of the attacker, defender, and user using the replication dynamic equation, a set of three-party game evolution equations is constructed, and the stability of the model is solved.
[0078] The behavioral strategies of each agent in the three-party game evolution equation set can be selected and the dynamic equations can be copied to be set to 0 to obtain the stable equilibrium point of the three-party evolution game model.
[0079] Among them, the optimal selection strategy for each participant, obtained based on the equilibrium point of the three-party evolutionary game model, can be designed to include:
[0080] By replicating the dynamic equations, the corresponding partial derivative function Jacobian matrix is obtained, and the equilibrium point is substituted into the Jacobian matrix to obtain the eigenvalues of each stable equilibrium point.
[0081] Based on eigenvalues and using Lyapunov's first rule to analyze the stability of each equilibrium point, we can obtain the game evolution patterns under different scenarios and the optimal choice strategies of each participant.
[0082] Setting F(x) = 0, F(y) = 0, and F(z) = 0, we obtain eight equilibrium points in the game model: E1(0,0,0), E2(1,0,0), E3(0,1,0), E4(0,0,1), E5(1,1,0), E6(1,0,1), E7(0,1,1), and E8(1,1,1). The Jacobian matrix can be obtained by replicating the dynamic equations.
[0083]
[0084] Substituting the equilibrium points E1-E8 into the Jacobian matrix respectively yields the eigenvalues of each equilibrium point, as shown in Table 2.
[0085] Table 2. Eigenvalues of equilibrium points E1-E8
[0086]
[0087] According to Lyapunov's first rule, an equilibrium point is stable when all corresponding eigenvalues are negative; it is unstable when at least one corresponding eigenvalue is positive. The analysis of different cases for the corresponding eigenvalues at each equilibrium point is as follows:
[0088] In Case 1, when the conditions C1-C2>αV, R<βL, C2-C1<V(α-1), and C3>α(L+V) are met, the three-way evolutionary stable strategy is E1(0,0,0), which is (weak attack, weak defense, no access). The stability determination is shown in Table 3.
[0089] In scenario 1, the attacker chooses a weak attack strategy. Over time, the probability of the defender choosing a weak defense strategy approaches 1, while the probability of the user choosing an access strategy approaches 0. All three parties reach a stable state, and the optimal defense strategy at this point is weak defense S. D2 .
[0090] Table 3 Stability analysis of E1(0,0,0)
[0091]
[0092] In scenario 2, when the conditions C2+αV>C1, C3<V(1+α), and C1-C2<V(1-α) are met, the stable evolutionary strategy of the three parties is E2(1,0,0), which is (strong attack, weak defense, no access). The stability determination is shown in Table 4.
[0093] Table 4 Stability analysis of E2(1,0,0)
[0094]
[0095] In scenario 2, the attacker employs a strong attack strategy, but the defender, finding the strong defense strategy too costly, switches to a weak defense strategy to counter the network attack. This results in users being unable to access the system normally, and the probability of users choosing an access strategy gradually approaches 0. All three parties reach a stable state, at which point the optimal defense strategy is weak defense S. D2 .
[0096] In scenario 3, when the conditions R > βL, C1 - C2 > αV, C3 > α(L + V), and C2 - C1 < V(α - 1) are met, the stable evolutionary strategy of the three parties is E4(0,0,1), i.e., (weak attack, weak defense, access). The stability determination is shown in Table 5.
[0097] In scenario 3, due to the imbalance between benefits and costs, the probability of the attacker and defender choosing strong attack and strong defense strategies respectively tends to 0. However, the defender can provide basic service guarantees for the user, and the user can obtain higher benefits when accessing the system. Therefore, the probability of the user choosing the access strategy tends to 1, and all three parties reach a stable state. At this time, the optimal defense strategy is weak defense S. D2 .
[0098] Table 5 Stability analysis of E4(0,0,1)
[0099]
[0100]
[0101] In scenario 4, when the conditions C1-C2<αV, C3<V(1-α), and C2-C1<V(α-1) are met, the stable evolutionary strategy of the three parties is E5(1,1,0), which is (strong attack, strong defense, no access). The stability determination is shown in Table 6.
[0102] Table 6 Stability analysis of E5(1,1,0)
[0103]
[0104] In scenario 4, both the attacker and defender are in an unfavorable state of alternating offense and defense. The attacker, seeking high gains, tends towards a strategy of strong attack (probability 1), while the defender, aiming to minimize their losses, tends towards a strategy of strong defense (probability 1). Simultaneously, the user's probability of choosing an access strategy due to access failures and potential losses gradually approaches 0. All three parties reach a stable state, and the optimal defense strategy at this point is strong defense (S). D1 .
[0105] In scenario 5, when the conditions C1-C2<αV, C3<α(L+V), and C1-C2<V(1-α) are met, the stable evolutionary strategy for the three parties is E7(0,1,1), i.e. (weak attack, strong defense, access). The stability determination is shown in Table 7.
[0106] In scenario 5, the attacker chooses a weak attack strategy, and the probability of the defender choosing a strong defense strategy to ensure its own benefit tends to 1 over time. After improving security defense capabilities, the user's access strategy tends to 1, and all three parties reach a stable state. At this point, the optimal defense strategy is strong defense S. D1 .
[0107] Table 7 Stability analysis of E7(0,1,1)
[0108]
[0109] In scenario 6, when the conditions C1-C2<αV, C3<(1-α)(L+V), and C3<V(1-α) are met, the stable evolutionary strategy of the three parties is E8(1,1,1), which is (strong attack, strong defense, access). The stability determination is shown in Table 8.
[0110] Table 8 Stability analysis of E8(1,1,1)
[0111]
[0112] In scenario 6, proactive defense technology is relatively mature, offering high overall benefits at a low cost. To avoid hacking and other issues, the probability of the defender choosing a strong defense strategy tends to 1. Data privacy is effectively protected when users access the system normally, so the probability of choosing an access strategy tends to 1. All three parties reach a stable state, and the optimal defense strategy at this point is strong defense S. D1 .
[0113] Furthermore, based on the above method, this embodiment of the invention also provides a network attack and defense strategy selection system based on three-party evolutionary game theory, comprising: an attack and defense modeling module and a model solving module, wherein,
[0114] The attack and defense modeling module is used to construct a three-party evolutionary game model based on evolutionary game theory, in which the attacker, the defender and the user are the participants in the network attack and defense confrontation. The participants in the three-party evolutionary game model learn advantageous strategies by imitation in the evolutionary game and adjust their respective strategy choices under the drive of game payoffs.
[0115] The model solving module is used to solve the stability of the three-party evolutionary game model by selecting dynamic equations based on the three-party behavioral strategies, obtain the equilibrium point of the three-party evolutionary game model, and obtain the optimal selection strategy of each participant based on the equilibrium point of the three-party evolutionary game model.
[0116] To verify the effectiveness of this solution, the following explanation is based on simulation test data:
[0117] A network information system was deployed for simulation experiments. Using Matlab 2018b, the evolutionary patterns and behavioral tendencies of the three main actors in a network attack and defense confrontation were analyzed. The impact of attack costs and gains on the attacker's behavioral strategies, the impact of defense costs and gains on the defender's behavioral strategies, and the impact of the gains and losses from successful or failed access on the user's behavioral strategies were explored.
[0118] This network information system mainly involves firewalls, routers, MySQL servers, web servers, and PTP servers, etc., and the system topology is as follows: Figure 6 As shown in the diagram. The attacker and user are located on the external network, where external hosts can only access the web server and PTP server via the network. The three servers are located on the internal network (access between servers is possible via user privileges). The firewall is used to isolate the external and internal networks.
[0119] Using Nessus to scan the system server for vulnerabilities, and combining this with data from the National Information Security Vulnerability Database, an attacker's behavioral strategy was designed to launch a brute-force attack on the system. A1 and weak attack S A2 As shown in Table 9.
[0120] Table 9 Atomic Attack Strategies
[0121]
[0122] When a cyberattack occurs, the defender's behavioral strategy is proactive defense. D1 and passive defense S D2 As shown in Table 10.
[0123] Table 10 Atomic Defense Strategy Information
[0124]
[0125] Based on the replicated dynamic equations and corresponding constraints, and taking into account the actual situation and relevant expert opinions, the initial assignment parameters of the model were determined. The settings of arrays 1-6 are shown in Table 11.
[0126] Table 11 Initial values of simulation parameters under different conditions
[0127]
[0128] The simulation results of assigning parameters to the above array and evolving it 50 times over time are as follows: Figure 7 As shown. By Figure 7 Analysis (a) shows that when the conditions R<βL, C3>α(L+V), C1-C2>αV and C2-C1<V(α-1) are satisfied, the system's stable evolution point is E1(0,0,0); Figure 7 Analysis (b) shows that when the conditions C3>(1-α)(L+V), C2+αV>C1, and C1-C2<V(1-α) are satisfied, the system's stable evolution point is E2(1,0,0); Figure 7 Analysis (c) shows that when the conditions R>βL, C3>α(L+V), C2-C1<V(α-1) and C1-C2>αV are satisfied, the system's stable evolution point is E4(0,0,1); Figure 7 Analysis (d) shows that when the conditions R < βL, C3 < V(1-α), C1-C2 > αV, and C2-C1 < V(α-1) are met, the system's stable evolution point is E5(1,1,0); Figure 7 Analysis (e) shows that when C1-C2>αV, C1-C2<V(1-α), and C3<α(L+V), the system's stable evolution point is E7(0,1,1); Figure 7 Analysis (f) shows that when the conditions R > βL, C1 - C2 < αV, C3 < (1 - α)(L + V) and C3 < α(L + V) are met, the system's evolutionary stability point is E8(1,1,1). Therefore, the evolution of the three-party game system is influenced by multiple variables, including the attacker's cost and gains from the attack, the defender's cost and gains from the defense, and the user's gains from access and losses from failed access. When the initial values of these variables change, the system's evolutionary stability strategy will also change. Therefore, simulation results with initial parameter values under different conditions demonstrate the effectiveness of the stability analysis of the three-party game system, and the numerical relationships between variables will affect the final evolutionary stability strategy of the network attack-defense game system.
[0129] For the attacker, their strategy selection and the evolutionary stability of the game system are related to the attack cost and attack payoff, i.e., influenced by variables C1, C2, α, and V. Analyzing the correlation between changes in the values of variables C1 and C2 and the evolutionary game process and outcome, parameters C1 = 60, 75, 95, C2 = 5, 10, 15 were assigned, and the remaining variables α = 0.5, V = 100, C3 = 60, L = 10, R = 20, β = 0.8 were set. The simulation results after 50 evolutions over time t are shown in Figure (a). Analyzing the correlation between changes in parameter α and the evolutionary game process and outcome, parameters α = 0.5, 0.6, 0.7 were assigned, and the remaining variables α = 0.5, V = 100, C3 = 60, L = 10, R = 20, β = 0.8 were set. The remaining variables are C1=25, C2=5, V=60, C3=30, L=20, R=5, β=0.9. The simulation results after 50 evolutions over time t are shown in Figure (b). Analyzing the correlation between the change of parameter V and the evolutionary game process and outcome, parameters V are assigned values of 60, 75, and 90. The remaining variables are C1=25, C2=5, α=0.5, C3=30, L=20, R=5, β=0.9. The simulation results after 50 evolutions over time t are shown in Figure (b). Figure 8 As shown. By Figure 8 As shown in (a), when the conditions C1-C2>V(1-α) and C1-C2>αV are satisfied, the stable evolution strategy of the system is E4(0,0,1), that is, the attacker chooses a weak attack strategy, the defender adopts weak defense measures, and the user chooses normal access to the system. This indicates that as the cost of attack increases, the evolution speed will be further accelerated, causing the attacker to abandon the strong attack strategy and choose the weak attack strategy. Figure 8 As shown in (b) and (c), when the conditions V > (C1-C2) / α and V > C3 / (1-α) are met, the stable evolutionary strategy of the system is E5(1,1,0), meaning the attacker chooses a strong attack strategy, the defender adopts strong defense measures, and the user chooses not to access the system. Analysis shows that changes in attack gains (variables α and V) have a significant impact on the attacker's strategy selection. When variables α and V increase, the attacker's strategy will shift from a weak attack to a strong attack strategy to obtain greater gains. Simultaneously, the defender will increase investment to improve its defense capabilities to reduce its own losses, while the user, considering access security and its own gains, will ultimately choose not to access the system. Furthermore, when the values of variables α and V further increase, the impact on the final strategy selection of the attacker and the user is not significant. If the defender wants to reduce the attack level, it needs to increase investment to improve its defense measures.
[0130] The defensive player's strategic choices are related to their defensive costs and benefits, specifically influenced by variables C3 and L. Analyzing the correlation between changes in variable C3 and the evolutionary game process and outcome, and assigning active defense costs C3 = 35, 45, and 55 to array 2 while keeping other variables constant, the simulation results for 50 iterations over time t are shown below. Figure 9(a) ; Analyze the correlation between the change in the value of variable L and the evolutionary game process and outcome. Variables L = 10, 20, 30 are assigned values, and the remaining variables are C1 = 30, C2 = 5, a = 0.4, V = 50, C3 = 15, R = 15, β = 0.8. Simulation results after 50 evolutions over time t are shown in (a). Figure 9 (b) in the middle. Figure 9 From (a) in the diagram, we can see that when the condition C3>V(1-α) is satisfied, the stable evolutionary strategy of the system is E2(1,0,0), that is, the attacker chooses a strong attack strategy, the defender adopts a weak defense measure, and the user chooses not to access the system. This indicates that the defender will abandon the strong defense strategy due to the high defense cost. Figure 9 As shown in (b), when the condition L > (C3 - αV) / α is met, the stable evolutionary strategy of the system is E7(0,1,1), which means that the attacker chooses a weak attack strategy, the defender adopts strong defense measures, and the user chooses normal access. This indicates that after adopting a strong defense strategy, the defender can further reduce its own losses and effectively ensure the user's normal access. Analysis shows that the defender's gains are positively correlated with the user access situation; decreasing the value of variable L will increase the defender's gains and cause the evolution rate to change faster.
[0131] The user's behavioral strategy selection is related to variables R and β. The correlation between changes in the values of variables R and β and the evolutionary game process and outcome was analyzed. Variables R were assigned values of 20, 30, and 40, and β of 0.9, 0.8, and 0.7, respectively. The remaining variables were C1 = 35, C2 = 5, α = 0.6, V = 60, C3 = 20, and L = 20. The simulation results after 50 iterations over time are shown below. Figure 10 When the condition R > βL is met, the final evolutionary stable strategy is E8(1,1,1), meaning the attacker chooses a strong attack strategy, the defender adopts strong defense measures, and the user chooses the normal access system. This indicates that as the probability of the attacker launching a strong attack increases, the defender adopts strong defense measures to ensure access for legitimate users and provide them with normal services. Furthermore, increased access benefits will encourage users to choose the normal access system, so the defender should take more proactive and effective defense measures to curb the attacker's network attack behavior.
[0132] By using the above experimental simulation data to explore the impact of different variables on the selection of behavioral strategies by the three parties, it can be further shown that the model in this case can reach an evolutionary stable state and obtain the optimal defense strategy under different situations. It can provide support for solving network information security problems, and can provide a theoretical basis and predictable implementation effect for the selection of protection measures in actual network security protection, and has good application prospects.
[0133] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of the invention.
[0134] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.
[0135] The units and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations are not considered to be beyond the scope of this invention.
[0136] Those skilled in the art will understand that all or part of the steps in the above methods can be implemented by a program instructing related hardware, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk. Optionally, all or part of the steps in the above embodiments can also be implemented using one or more integrated circuits. Accordingly, each module / unit in the above embodiments can be implemented in hardware or as a software functional module. This invention is not limited to any particular combination of hardware and software.
[0137] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for selecting network attack and defense strategies based on three-party evolutionary game theory, characterized in that, Include: This study utilizes network information systems to scan the target network for vulnerabilities and combines this with vulnerability database data to construct an attacker's attack strategy set. It also constructs a defender's defense strategy set based on the defender's actions during the attack, and builds a user behavior strategy set by collecting user access behavior data during the attack and defense process. The study analyzes the impact of attack costs and benefits on attacker's and defender's attack strategies, the impact of defense costs and benefits on defender's attack strategies, and the impact of the gains and losses from successful or failed user access on user behavior strategies. Finally, it employs evolutionary game theory and, based on the attacker, defender, and user's attack strategy sets and attack and defense benefits, constructs a system to describe the attack strategy. This is a three-party evolutionary game model in which attackers, defenders, and users participate in a dynamic attack-defense game process. In this three-party evolutionary game model, the participants learn advantageous strategies through imitation and adjust their respective strategy choices under the drive of game payoffs. The three-party evolutionary game model is represented as a quadruple (N,S,P,U), where N is the game participant space composed of attackers, defenders, and users; S is the game strategy space composed of the set of behavioral strategies of each participant; P is the game belief set composed of the probability of each participant choosing a behavioral strategy; and U is the payoff function set composed of the game payoffs of each participant under different strategy combinations. An average payoff function for the attacker is constructed based on the probability of the attacker choosing an attack strategy, the required cost, and the attack success rate. An average payoff function for the defender is constructed based on the probability of the defender choosing a defense strategy, the value of their data assets, the fixed revenue generated by the data assets, the cost of choosing a defense strategy, and the loss suffered by the defender when user access fails. An average payoff function for the user is constructed based on the probability of the user choosing an access strategy, the revenue gained from a normal user access, and the loss suffered by the defender when user access fails, passed on to the user by a depreciation factor. Based on the average payoff functions of each participant, three-way dynamic equations for strategy selection are constructed, and a set of three-way game evolution equations is constructed by simultaneously solving these equations. The stability of the three-way game evolution model is solved using the set of three-way game evolution equations to obtain the equilibrium point of the three-way game model. The optimal selection strategy for each participant is obtained based on the equilibrium point of the three-way game model. The three-way dynamic equations for strategy selection and their first-order partial derivatives are expressed as follows: , , Let x be the probability of the attacker choosing a strong attack strategy, C1 be the cost of the attacker choosing a strong attack strategy, C2 be the cost of the attacker choosing a weak attack strategy, α be the attack success rate when the attacker and defender choose strong attack and strong defense or weak attack and weak defense strategies respectively, y be the probability of the defender choosing a strong defense strategy, V be the value of the data assets owned by the defender, E be the fixed revenue brought by the defender's own data assets, C3 be the cost of the defender choosing an active defense strategy, L be the loss suffered by the defender when user access fails, z be the probability of the user choosing an access strategy, R be the revenue obtained by the user through normal access, β be the reduction factor passed to the user after the loss suffered by the defender when user access fails, and E be the probability of the user choosing an access strategy. ij Let E be the expected return function of the three parties under different strategy combinations, i=1,2,3 and j=1,2. i This is the average return function.
2. The method for selecting network attack and defense strategies based on three-party evolutionary game theory according to claim 1, characterized in that, The stability of a three-party evolutionary game model is solved using a set of evolutionary equations, including: The behavioral strategies of each agent in the three-party game evolution equation set are selected and the replication dynamic equation is assigned a value of 0 to obtain the stable equilibrium point of the three-party evolution game model.
3. The method for selecting network attack and defense strategies based on three-party evolutionary game theory according to claim 1, characterized in that, Based on the equilibrium point of the three-party evolutionary game model, the optimal selection strategy for each participant is obtained, including: By replicating the dynamic equations, the corresponding partial derivative function Jacobian matrix is obtained, and the equilibrium point is substituted into the Jacobian matrix to obtain the eigenvalues of each stable equilibrium point. Based on eigenvalues and using Lyapunov's first rule to analyze the stability of each equilibrium point, we can obtain the game evolution patterns under different scenarios and the optimal choice strategies of each participant.
4. The method for selecting network attack and defense strategies based on three-party evolutionary game theory according to claim 3, characterized in that, The stability of each equilibrium point is analyzed based on eigenvalues and using Lyapunov's first rule, including: An equilibrium point is a stable point when all corresponding eigenvalues are negative, and an equilibrium point is an unstable point when at least one corresponding eigenvalue is positive.
5. A network attack and defense strategy selection system based on three-party evolutionary game theory, characterized in that, The method described in claim 1 includes: an attack and defense modeling module and a model solving module, wherein... The attack and defense modeling module is used to construct a three-party evolutionary game model based on evolutionary game theory, in which the attacker, the defender and the user are the participants in the network attack and defense confrontation. The participants in the three-party evolutionary game model learn advantageous strategies by imitation in the evolutionary game and adjust their respective strategy choices under the drive of game payoffs. The model solving module is used to solve the stability of the three-party evolutionary game model by selecting dynamic equations based on the three-party behavioral strategies, obtain the equilibrium point of the three-party evolutionary game model, and obtain the optimal selection strategy of each participant based on the equilibrium point of the three-party evolutionary game model.
6. An electronic device, characterized in that, include: At least one processor, and a memory coupled to said at least one processor; The memory stores a computer program that can be executed by the at least one processor to implement the method as described in any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, enables the implementation of the method as described in any one of claims 1 to 4.