Security event cooperative defense method, defense device, defense system, and medium
By using hash intersection and strategy game theory methods, the defense devices can identify cooperative defense devices and negotiate strategies without leaking data, thus solving the problems of data leakage and unfavorable strategies and improving the effectiveness of cooperative defense.
Patent Information
- Application Number
- CN202410396596.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-02
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-04-02
AI Technical Summary
When multiple defense devices work together to handle security incidents, there are issues such as data leakage and defense strategies that are not conducive to their own effectiveness, resulting in poor collaborative defense.
By using hash intersection and strategy game theory methods, the defense device can identify collaborative defense devices and negotiate security strategies to obtain the final defense strategy without disclosing security event data.
It has enabled the synergy of data protection and defense strategies, and enhanced the participation of defense devices and their collaborative defense capabilities.
Smart Images

Figure CN118784264B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network security, and in particular to a security event cooperative defense method, a defense device, a defense system, and a computer readable storage medium. BACKGROUND
[0002] In some cases, multiple defense devices cooperatively process security events. The security analysis control center mainly collects security events, strategies, event processing results, and logs of the cooperative defense devices, analyzes abnormal traffic data comprehensively, and formulates a new security strategy according to the original preset defense strategy, so as to play the cooperative ability of the defense devices to process security events.
[0003] Problems exist. First, when multiple defense devices cooperatively defend security events, it is necessary to understand the relevant security event situation of the cooperation party. When security event data used for cooperative defense is shared among multiple defense devices, data leakage problem of data seen is obtained. Second, the defense device does not participate in formulating a new security strategy in time, which may not be conducive to itself, resulting in low enthusiasm of the defense device in cooperative defense and suboptimal cooperative defense effect. SUMMARY
[0004] The technical problem to be solved by the present disclosure is to provide a security event cooperative defense method, a defense device, a defense system, and a computer readable storage medium to solve the problem of how to protect data and formulate a defense strategy for cooperative defense of security events.
[0005] In a first aspect, the present disclosure provides a security event cooperative defense method, which comprises:
[0006] The method comprises:
[0007] A certain defense device obtains a first hash calculation result of its own security event and a second hash calculation result of security events of the remaining defense devices,
[0008] and the first hash calculation result and the second hash calculation result are intersected to determine the cooperative defense devices for cooperative defense of a certain security event with itself;
[0009] A certain defense device obtains a first defense strategy of its own for a certain security event and a second defense strategy of the cooperative defense devices for the certain security event,
[0010] and the first defense strategy and the second defense strategy are played to obtain the final defense strategy of the certain defense device and the cooperative defense devices for a certain security event.
[0011] Further, wherein:
[0012] The specific result of the first hash calculation is: the general result of the first hash calculation. Alternatively, the first hash calculation result of symmetric encryption. Alternatively, the first hash calculation result of asymmetric encryption.
[0013] The specific result of the second hash calculation is: the general result of the second hash calculation. Alternatively, the result of the second hash calculation in symmetric encryption. Alternatively, the result of the second hash calculation in asymmetric encryption.
[0014] Where H(·) is the hash function, This is a security incident involving a certain defense device itself. i This refers to the number of security events occurring within a specific defense device i. i It is the first random key of a certain defense device i itself, a j d is the first random key of each of the other defense devices j, and d is the private key of the asymmetric key of each of the other defense devices j. These are the individual security incidents of the other defense devices, m j It represents the number of security incidents for each of the other defense devices.
[0015] Furthermore, a certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of the other defense devices, specifically including:
[0016] A certain defense device i obtains X of its own security events. i =H(Y) i ),
[0017] Send X to the defense platform i ,
[0018] And receive the security events X from the other defense devices j sent by the defense platform. j =H(Y) j The set B) -i ={X j ,j≠i}.
[0019] Furthermore, a certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of the other defense devices, specifically including:
[0020] A certain defense device i utilizes a i Encrypting its own security events to obtain the first one-sided cryptographic hash calculation result.
[0021] and send to the defense platform
[0022] And receive the second one-sided cryptographic hash calculation result sent by the defense platform. and in, The remaining defense equipment each utilizes a j Each entity encrypts the security events it receives and sends to the defense platform. The remaining defense equipment each utilizes a j Each encrypted message received from the defense platform Acquired and sent to the defense platform; and,
[0023] Using a i encryption Get
[0024] Furthermore, a certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of the other defense devices, specifically including:
[0025] A certain defense device i receives the public keys e of the other defense devices j sent by the defense platform, where (e,d) is an asymmetric key pair.
[0026] And generate its own random number {r} l ,l∈m i},
[0027] And using e and {r l ,l∈m i Encrypt its own security events to obtain the result of a random hash calculation of the first public key. as well as,
[0028] Send to the defense platform
[0029] And receive X sent by the defense platform j =H(Y) j ) d The result of random hash calculation of the first private key Among them, X j =H(Y) j ) d The other defense devices (j) each use d to encrypt their own security events and then send them to the defense platform. The other defense devices each use d to decrypt and encrypt the data they receive from the defense platform. Obtained and sent to the defense platform
[0030] And using {r l ,l∈m i Decryption to obtain X i = H(Y i ) d .
[0031] Further, the first hash calculation result and the second hash calculation result are intersected to determine a cooperative defense device that cooperates with itself to defend against a certain security event, specifically comprising:
[0032] X i ∩ X j to obtain the remaining defense devices k' ∈ j that jointly have a certain security event
[0033] and send a first cooperation invitation to the remaining defense devices k' to jointly defend q to the defense platform,
[0034] and receive a second cooperation invitation set of the remaining defense devices k' requesting to jointly defend q sent by the defense platform; and
[0035] in response to the first cooperation invitation and the second cooperation invitation matching, determine the cooperative defense device k ∈ k' that cooperates with the defense device i to defend q.
[0036] Further, wherein:
[0037] The first defense strategy includes the bid and / or utility of a certain defense device itself to defend at least part of the security phenomena of a certain security event,
[0038] The second defense strategy includes the bid and / or utility of each cooperative defense device to defend at least part of the security phenomena of a certain security event,
[0039] The final defense strategy is obtained according to at least one round of bid and / or utility to defend all security phenomena of a certain security event,
[0040] wherein the utility is equal to the bid to defend a certain security phenomenon of a certain security event minus the overhead.
[0041] Further, a certain defense device obtains the first defense strategy of itself for a certain security event and the second defense strategy of each cooperative defense device for a certain security event, specifically comprising:
[0042] A certain defense device i obtains the first bid of itself to defend a security phenomenon q(z n ) of a certain security event q = {q(z n ), n ∈ N}
[0043] and sends
[0044] and receiving the second offer of the defense q(z n ) of each of the cooperative defense devices k sent by the defense platform wherein N'+1≤N, k≠i.
[0045] Further, the first defense strategy and the second defense strategy are further gambled to obtain the final defense strategy of the self and the cooperative defense devices for the partial security phenomenon of the defense of a certain security event, and specifically comprising:
[0046] obtaining the minimum second offer v k (q(z k )) of the defense q(z n ) according to Q, n n ,
[0047] and selecting the partial minimum second offer {v k (q(z k )), k∈n} and the partial first offer {v i (q(z i )), i∈n} of the self,
[0048] and obtaining the utility u i (q(z i )) of the self for the defense of the partial security phenomenon q(z i ) u i (q(z i ))=v i (q(z i ))-b i (q(z i )), wherein b i (q(z i )) is the overhead of the self for the defense of q(z i ), and
[0049] judging whether ∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i ))≥0 are true at the same time, wherein s is a preset revenue unit,
[0050] if yes, obtaining the final defense strategy of the self for the defense of the partial security phenomenon q(z i ) and the cooperative defense devices for the defense of the partial security phenomenon q(z k ),
[0051] if no, re-obtaining and sending to the defense platform, and receiving Q, and re-obtaining the final defense strategy.
[0052] Further, wherein:
[0053]
[0054] wherein c i (q(z i )) is the computation overhead of the certain defense device i to defend q(z i ) by itself, i (o i (q(z i )) is the operation overhead of the certain defense device i to defend q(z i ) by itself, p(z i ) is the penalty of the certain defense device i failing to defend q(z i ) by itself, ceiling() represents the ceiling function, and a is the probability of the certain defense device i failing to defend q(z i ) by itself.
[0055] In a second aspect, the present disclosure provides a defense device for cooperative defense of security events, the defense device comprising:
[0056] a hash intersection module configured to obtain a first hash calculation result of a security event of the defense device itself and second hash calculation results of security events of the rest of the defense devices, respectively,
[0057] and perform intersection on the first hash calculation result and the second hash calculation results to determine cooperative defense devices that cooperate with the defense device itself to defend a certain security event;
[0058] a strategy game module connected with the hash intersection module, configured to obtain a first defense strategy of the defense device itself for a certain security event and second defense strategies of the cooperative defense devices for the certain security event, respectively,
[0059] and perform game according to the first defense strategy and the second defense strategies to obtain final defense strategies of the defense device itself and the cooperative defense devices for partial security phenomena of the certain security event.
[0060] Further, wherein:
[0061] the first hash calculation result is specifically a general first hash calculation result or a symmetrically encrypted first hash calculation result or an asymmetrically encrypted first hash calculation result
[0062] the second hash calculation result is specifically a general second hash calculation result or a symmetrically encrypted second hash calculation result or an asymmetrically encrypted second hash calculation result
[0063] wherein H(·) is a hash function, is a security event of the certain defense device i, m i is the number of security events of the certain defense device i, a i is a first random key of the certain defense device i, a j is a first random key of each of the remaining defense devices j, d is a private key of an asymmetric key of each of the remaining defense devices j, is a security event of each of the remaining defense devices j, m j is the number of security events of each of the remaining defense devices j.
[0064] Further, the hash intersection module specifically comprises:
[0065] a calculation unit, configured to obtain X i = H(Y i ),
[0066] a sending unit, connected with the calculation unit, configured to send X i = H(Y i ) to the defense platform,
[0067] a receiving unit, connected with the sending unit, configured to receive a set B j = {X -i , j≠i} of X j = H(Y i ) of each of the security events of the remaining defense devices j sent by the defense platform.
[0068] Further, the hash intersection module specifically comprises:
[0069] a calculation unit, configured to encrypt the security event of the certain defense device i by using a j to obtain a first one-way encrypted hash calculation result
[0070] a sending unit, connected with the calculation unit, configured to send the first one-way encrypted hash calculation result
[0071] a receiving unit, connected with the sending unit, configured to receive a second one-way encrypted hash calculation result and wherein, is obtained and sent to the defense platform by each of the remaining defense devices j by encrypting the security event of each of the remaining defense devices j by using a j is obtained and sent to the defense platform by each of the remaining defense devices j by encrypting the received from the defense platform by each of the remaining defense devices j by using a i ; and
[0072] The computing unit, also connected to the receiving unit, is also used to utilize a i encryption Get
[0073] Furthermore, the hash intersection module specifically includes:
[0074] The receiving unit is used to receive the public keys e of the other defense devices j sent by the defense platform, where (e,d) is a pair of asymmetric keys.
[0075] The generation unit, connected to the receiving unit, is used to generate its own random number {r}. l ,l∈m i},
[0076] The computational unit, connected to the generation unit, is used to utilize e and {r l ,l∈m i Encrypt its own security events to obtain the result of a random hash calculation of the first public key. as well as,
[0077] The sending unit, connected to the computing unit, is used to send data to the defense platform.
[0078] The receiving unit, also connected to the transmitting unit, is also used to receive X signals sent by the defense platform. j =H(Y) j ) d The result of random hash calculation of the first private key Among them, X j =H(Y) j ) d The other defense devices (j) each use d to encrypt their own security events and then send them to the defense platform. The other defense devices each use d to decrypt and encrypt the data they receive from the defense platform. Obtained and sent to the defense platform
[0079] The computing unit, also connected to the receiving unit, is also used to utilize {r l ,l∈m i Decryption Get X i =H(Y) i ) d .
[0080] Furthermore, the hash intersection module specifically includes:
[0081] Intersection cell, used to calculate X i ∩X j In order to obtain information about a common security incident the rest of the defense devices k' e j;
[0082] The sending unit, connected with the intersection unit, is further used for sending a first cooperation invitation for requesting the rest of the defense devices k' to jointly defend q to the defense platform;
[0083] The receiving unit, connected with the sending unit, is used for receiving a set of second cooperation invitations for requesting the rest of the defense devices k' to jointly defend q sent by the defense platform;
[0084] The matching unit, connected with the receiving unit, is used for determining the cooperative defense devices k e k' that cooperate with the defense device i to defend q in response to the matching of the first cooperation invitation and the second cooperation invitation.
[0085] Further, wherein:
[0086] The first defense strategy includes a bid and / or utility of the defense device itself to defend at least part of the security phenomena of the security event,
[0087] The second defense strategy includes a bid and / or utility of each of the cooperative defense devices to defend at least part of the security phenomena of the security event,
[0088] The final defense strategy is obtained according to at least one round of bids and / or utilities to defend all security phenomena of the security event,
[0089] Wherein, the utility is equal to the bid to defend the security phenomenon of the security event minus the overhead.
[0090] Further, the strategy game module specifically includes:
[0091] The bidding unit is used for obtaining a first bid of the security phenomenon q(z n ) of the security event q = {q(z n ), n e N} defended by itself, Wherein, N is the number of security phenomena of q,
[0092] The sending unit, connected with the bidding unit, is used for sending the first bid to the defense platform,
[0093] The receiving unit, connected with the sending unit, is used for receiving a set of second bids of the security phenomenon q(z n ) of q of each of the cooperative defense devices k sent by the defense platform, Wherein, N' + 1 < N, k ≠ i.
[0094] Further, the strategy game module specifically further includes:
[0095] The bid analysis unit is used for obtaining the second bid of the security phenomenon q(z nThe minimum second quote v n (q(z n )),
[0096] The quotation selection unit, connected to the quotation analysis unit, is used to select a subset of the smallest second quotations {v}. k (q(z k ),k∈n} and its own first quote {v i (q(z i ),i∈n},
[0097] The utility unit, connected to the quotation selection unit, is used to obtain the security phenomena q(z) of its own defense components. i The utility of u i (q(z i ))=v i (q(z i ))-b i (q(z i )),in,
[0098] b i (q(z i )) is the self-defense q(z) of a certain defense device i. i The expenses of ) and,
[0099] The judgment unit, connected to the utility unit, is used to judge ∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i Whether ))≥0 are true simultaneously, where s is the preset revenue unit.
[0100] If so, obtain the security phenomena of its own defenses q(z) i ) and collaborative defense equipment defends against some security phenomena q(z) k The ultimate defense strategy,
[0101] If not, retrieve again. It sends and receives Q to the defense platform, and retrieves the final defense strategy again.
[0102] Furthermore, among which:
[0103]
[0104] Among them, c i (q(z i )) is the self-defense q(z) of a certain defense device i. i The computational overhead of o i(q(z i ) is the operating cost of the defense equipment i itself to defend q(z i ), is the penalty of the defense equipment i itself failing to defend q(z i ), represents rounding up, and a is the probability of the defense equipment i itself failing to defend q(z i ).
[0105] In a third aspect, the present disclosure provides a defense system, which comprises:
[0106] a defense equipment as described above;
[0107] a defense platform connected with the defense equipment, the defense platform being configured to forward data between the defense equipment and the remaining defense equipment, the data comprising the first hash calculation result, the second hash calculation result, the first defense strategy, and the second defense strategy.
[0108] In a fourth aspect, the present disclosure provides a computer readable storage medium, which stores a computer program, when the computer program is run by a processor, the computer program implements the security event cooperative defense method as described above, or the defense equipment as described above, or the defense system as described above.
[0109] The present disclosure provides a security event cooperative defense method, a defense equipment, a defense system, and a computer readable storage medium. By means of hash intersection, the present disclosure helps the defense equipment participating in cooperative defense to quickly find the defense equipment having the same security event data without leaking the security event data, so as to protect the data assets from being leaked. By means of strategy game, the present disclosure helps the defense equipment having the same security event data to negotiate the defense strategy of the security event, so as to realize trusted security strategy cooperation after negotiation, effectively improve the enthusiasm of the defense equipment participating in cooperative defense, and further improve the cooperative defense capability. BRIEF DESCRIPTION OF DRAWINGS
[0110] Figure 1 is a flowchart of a security event cooperative defense method according to an embodiment of the present disclosure;
[0111] Figure 2 is an interaction flowchart of a security event cooperative defense method according to an embodiment of the present disclosure;
[0112] Figure 3 is a structural schematic diagram of a defense equipment according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0113] In order for those skilled in the art to better understand the technical solutions of the present disclosure, the embodiments of the present disclosure will be further described in detail below with reference to the drawings.
[0114] It can be understood that the specific embodiments and drawings described herein are only used to explain the present disclosure, but not to limit the present disclosure.
[0115] It can be understood that the embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict.
[0116] It can be understood that, for the convenience of description, only parts related to the present disclosure are shown in the drawings of the present disclosure, and parts irrelevant to the present disclosure are not shown in the drawings.
[0117] It can be understood that each unit and module involved in the embodiments of the present disclosure can only correspond to one physical structure, or can be composed of multiple physical structures, or multiple units and modules can be integrated into one physical structure.
[0118] It can be understood that the functions and steps marked in the flowcharts and block diagrams of the present disclosure can occur in an order different from that marked in the drawings without conflict.
[0119] It can be understood that in the flowcharts and block diagrams of the present disclosure, the architecture, functions and operations of possible implementations of systems, devices, apparatuses and methods according to the embodiments of the present disclosure are shown. Each block in the flowchart or block diagram can represent a unit, module, program segment, code, which contains executable instructions for implementing the specified functions. Moreover, each block or combination of blocks in the block diagram and flowchart can be implemented by a hardware-based system for implementing the specified functions, or by a combination of hardware and computer instructions.
[0120] It can be understood that the units and modules involved in the embodiments of the present disclosure can be implemented in software or hardware, for example, the units and modules can be located in a processor.
[0121] Embodiment 1:
[0122] As shown in Figure 1 The present disclosure provides a security event cooperative defense method, which comprises the following steps:
[0123] The method comprises the following steps:
[0124] S1, a certain defense device obtains a first hash calculation result of a security event of itself and a second hash calculation result of a security event of each of the remaining defense devices,
[0125] and the intersection of the first hash calculation result and the second hash calculation result is calculated to determine a cooperative defense device for cooperative defense of a certain security event with itself;
[0126] S2, a defense device acquires a first defense strategy of itself for a certain security event, and a second defense strategy of each of the cooperative defense devices for the certain security event,
[0127] and performs a game according to the first defense strategy and the second defense strategy to acquire a final defense strategy of each of the defense device and the cooperative defense devices for a part of security phenomena of the certain security event.
[0128] In the embodiment, local differential privacy calculation is adopted, each defense device (which can also be referred to as a security vendor) completes the calculation in its own computing resource pool, and a clock synchronization mechanism is used to realize information synchronization occurrence and synchronization acceptance, so as to avoid the problem of asynchronization in the process of security vendor cooperation matching and cooperative strategy iteration. The security vendor cooperation matching and cooperative strategy iteration can be regarded as two stages of the method, and hash intersection and strategy game are used to realize the two stages.
[0129] Through the hash intersection, the defense devices participating in the cooperative defense can quickly find the defense devices with the same security event data without leaking the security event data, so as to protect the data assets from being leaked. Specifically, each defense device intending to join the cooperative defense performs hash calculation on the security event data of itself, and only the hash calculation results are transmitted between multiple defense devices. Since the hash calculation result cannot be used to restore the security event data through logical analysis, the data security is ensured. According to the hash calculation result, the intersection is found. When the intersection is not empty, according to the one-way nature of the hash calculation result, both of the defense devices have the corresponding security event in the intersection, and the cooperative defense can be performed on the corresponding security event in the intersection.
[0130] Through the strategy game, the defense devices with the same security event data can perform defense strategy negotiation for the security event, realize trusted security strategy cooperation after the negotiation, effectively improve the enthusiasm of the defense devices participating in the cooperative defense, and further improve the cooperative defense capability. Specifically, each cooperative defense device formulates its own defense strategy, each defense strategy is transmitted to the cooperative defense device, and each cooperative defense device negotiates according to all the defense strategies to acquire a final defense strategy that is satisfactory to each cooperative party, and the final defense strategy can defend all the security phenomena of the security event.
[0131] There are two ways for the above data and strategy transmission: one is forwarding through a defense platform (a security analysis control center / privacy calculation contract platform), and the other is directly sending the notification content between the defense devices.
[0132] In an embodiment, wherein:
[0133] The first hash calculation result is specifically: a general first hash calculation result or a symmetrically encrypted first hash calculation result Or, the first hash calculation result of asymmetric encryption
[0134] The second hash calculation result is specifically: a general second hash calculation result Or, the second hash calculation result of symmetric encryption Or, the second hash of asymmetric encryption
[0135] Calculation result
[0136] Wherein, H(·) is a hash function, is the security event of the i-th defense device itself, m i is the number of security events of the i-th defense device itself, a i is the first random key of the i-th defense device itself, a j is the first random key of each of the remaining defense devices j, and d is the private key of the asymmetric key of each of the remaining defense devices j, is the security event of each of the remaining defense devices j, m j is the number of security events of each of the remaining defense devices j.
[0137] In this embodiment, the hash intersection algorithm considers both privacy and overhead. Specifically, three hash intersection algorithms can be used, which are:
[0138] The general hash intersection algorithm obtains a value that cannot be obtained through logical analysis by holding security event data through a hash function. The general hash intersection algorithm has small calculation amount and communication amount, but in the case of small security event data value domain, it is easy to be attacked by traversal attack, resulting in data leakage. Therefore, the general hash intersection algorithm is suitable for scenarios with large factory scale, multiple security protection devices and multiple functions of the devices, and is not suitable for scenarios with small factory scale and single function of security devices.
[0139] The hash intersection algorithm based on random key introduces a random key for each security manufacturer based on the general hash intersection algorithm. Compared with the general hash intersection algorithm, the hash intersection algorithm based on random key does not significantly increase the calculation amount and communication amount, but can effectively solve the problem of data leakage caused by traversal attack. Therefore, the hash intersection algorithm based on random key has a wide range of applications.
[0140] The hash intersection algorithm based on asymmetric encryption introduces a random number and an asymmetric key based on the general hash intersection algorithm. Compared with the hash intersection algorithm based on random key, the hash intersection algorithm based on asymmetric encryption has higher calculation complexity, and is therefore only suitable for scenarios with small factory scale and high security requirements.
[0141] In one embodiment, a defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of the other defense devices, specifically including:
[0142] A certain defense device i obtains X of its own security events. i =H(Y) i ),
[0143] Send X to the defense platform i ,
[0144] And receive the security events X from the other defense devices j sent by the defense platform. j =H(Y) j The set B) -i ={X j ,j≠i}.
[0145] In this embodiment, as Figure 2 As shown, the method involves two types of entities: one is a defense platform (also known as a privacy computing contract platform), responsible for collecting and forwarding data from security vendors to protect security event data, policy data, etc.; the other is defense equipment (i.e., security vendors), responsible for local privacy computing, security policy collaboration, etc. Its hash intersection calculation specifically includes the following steps:
[0146] Step 1: Any defense device (security vendor) i performs a hash calculation on the security event data to obtain X. i and X i Send to the defense platform (privacy computing contract platform);
[0147] Step 2: The defense platform (privacy computing contract platform) collects the hash calculation results of security event data sent by all participating defense devices (security vendors) and organizes them into a set B = {X}. j Let B, j∈n'}, where n' represents the number of defense devices (security vendors), and let B -i ={X j ,j≠i} is sent to the defense device (security vendor) i;
[0148] Step 3: The defense device (security vendor) calculates X... i ∩X j The system obtains defense equipment (security vendors) with shared security event data, which is set as k', and initiates a collaboration invitation to the defense equipment (security vendors) with shared security event data through the defense platform (privacy computing contract platform);
[0149] Let Y be the security event data held by any defense device (security vendor) i. i After a general hash calculation, we have X.i = H(Y i ), has a one-way property, i.e. it corresponds but cannot be reduced to If in the intersection calculation, there are i.e. According to the one-way property of the hash function, then It is explained that the security event I of the defense device (security vendor) i is the same as the security event P of the defense device j, and a cooperation invitation can be initiated.
[0150] In an embodiment, a certain defense device obtains a first hash calculation result of its own security event and a second hash calculation result of the security event of each of the remaining defense devices, specifically including:
[0151] A certain defense device i uses a i to encrypt its own security event to obtain a first one-sided encrypted hash calculation result
[0152] And sends it to the defense platform
[0153] And receives the second one-sided encrypted hash calculation result sent by the defense platform And Wherein, is the second one-sided encrypted hash calculation result obtained by each of the remaining defense devices j using a j to encrypt its own security event and sent to the defense platform, is the second one-sided encrypted hash calculation result obtained by each of the remaining defense devices j using a j to encrypt the received from the defense platform, and sent to the defense platform; and
[0154] Using a i to encrypt to obtain
[0155] In this embodiment, for any security vendor i, its random key is a i After the security vendor i receives the encrypted hash calculation value from the security vendor j, it encrypts it again using its own random key a i , obtaining the encrypted hash calculation value of its own security event data And send and to the security vendor j. After the security vendor j receives and , it encrypts using its own random key a j , obtaining Comparison and For any l, p, if there exists then it means that the security event data l of the security vendor i is the same as the security event data p of the security vendor j.
[0156] In an embodiment, a certain defense device obtains a first hash calculation result of its own security event and second hash calculation results of security events of the rest of the defense devices, specifically including:
[0157] A certain defense device i receives the public key e of each of the rest of the defense devices j sent by the defense platform, where (e, d) is a pair of asymmetric keys,
[0158] and generates its own random number {r l ,l∈m i},
[0159] and encrypts its own security event using e and {r l ,l∈m i} to obtain a first public key random hash calculation result and,
[0160] sends
[0161] to the defense platform and receives X j =H(Y j ) d and a first private key random hash calculation result where X j =H(Y j ) d is obtained and sent to the defense platform by each of the rest of the defense devices j using d to encrypt its own security event, is obtained and sent to the defense platform by each of the rest of the defense devices j using d to decrypt and encrypt the received from the defense platform , and
[0162] and decrypts using {r l ,l∈m i} to obtain X i =H(Y i ) d .
[0163] In this embodiment, the asymmetric key of any security vendor i of the defense device is (e, d), where e is the public key and d is the private key; the generated random number of the security vendor j is Before the algorithm is executed, the security vendor i sends the public key e to the security vendor j, and after the security vendor j receives the public key e, it calculates the hash value And send it to security vendor i; security vendor i receives it. Then, the hash value of the security event data of security vendor j is decrypted using the private key d and encrypted to obtain... Simultaneously, it encrypts the hash value of its own security event data. And and Sent to security vendor j; security vendor j receives Then, it can be used to generate random numbers. get and Compare, if exists This indicates that the security event data l of security vendor i is the same as the event data p of security vendor j.
[0164] In one embodiment, the intersection of the first hash calculation result and the second hash calculation result is used to determine the collaborative defense device that will cooperate with itself to defend against a certain security event, specifically including:
[0165] Calculate X i ∩X j In order to obtain information about a common security incident The remaining defense devices k'∈j,
[0166] It then sends a first cooperation invitation to the defense platform, requesting the other defense devices k' to jointly defend q.
[0167] And a set of second cooperation invitations sent by the defense platform to the other defense devices k' requesting joint defense q; and,
[0168] In response to the matching of the first and second cooperation invitations, determine the cooperative defense device k∈k' that cooperates with defense device i to defend q.
[0169] In this embodiment, as Figure 2 As shown, after the third step, the method further includes:
[0170] Step 4: The defense platform (privacy computing contract platform) sends the collection of collaboration invitations from the intersection defense devices (security vendors) k' to the defense device (security vendor) i;
[0171] Step 5: Defense device (security vendor) i performs matching calculations based on the invitations it has sent and the invitation sets received from other defense devices (security vendors) k', and sends the results to the relevant defense devices (security vendors) through the defense platform (privacy computing contract platform);
[0172] Step 6: After receiving the matching calculation result from the defense device (security vendor) i, the relevant defense device (security vendor) sends a confirmation cooperation message to the defense device (security vendor) i through the defense platform (privacy computing contract platform), and establishes a strategic cooperation relationship.
[0173] In an embodiment, wherein:
[0174] The first defense strategy includes the bid and / or utility of the certain defense device itself for defending at least part of the security phenomena of the certain security event,
[0175] The second defense strategy includes the bid and / or utility of each of the cooperative defense devices for defending at least part of the security phenomena of the certain security event,
[0176] The final defense strategy is obtained according to at least one round of bid and / or utility for defending all security phenomena of the certain security event,
[0177] Wherein, the utility is equal to the bid for defending a certain security phenomenon of the certain security event minus the overhead.
[0178] In this embodiment, considering that a security event can be composed of multiple security phenomena, the defense device (security vendor) needs to solve all security phenomena when designing a security strategy to achieve security defense. It is assumed that a security event can be cooperatively defended by multiple defense devices (security vendors), but the same security phenomenon can only be defended by one defense device (security vendor). For any security vendor, the utility function for defending the security event q can be written as u(q) = v(q) - b(q), where v(q) is the revenue (derived from the bid) of the security vendor for defending the security event q, and b(q) is the overhead of the security vendor for defending the security event q, which can be composed of bandwidth overhead, computing power overhead, and punishment for not defending. After multiple rounds of bid and / or utility negotiation, the cooperative defense devices (security vendors) establish the final cooperative strategy. Since each defense device (security vendor) is profit-oriented but does not want to be punished with high probability, in the first round of bidding, it tries to make a higher revenue claim for the security phenomenon that is difficult to reduce the risk for itself; in order to achieve cooperation, in each round of bidding, the defense device (security vendor) has to reduce its own revenue based on the previous bid and increase the revenue of other defense devices (security vendors); thus, in each round of bidding, the defense device (security vendor) can maintain rational bidding and promote cooperation.
[0179] In an embodiment, a certain defense device obtains a first defense strategy of itself for a certain security event and a second defense strategy of each of the cooperative defense devices for the certain security event, specifically including:
[0180] The certain defense device i obtains a security phenomenon q(z n ) of the certain security event q = {q(zn First quote Where N is the number of safe phenomena of q.
[0181] and send to the defense platform
[0182] And receive the defense q of each of the collaborative defense devices k sent by the defense platform (q(z)). n The second offer set Where N'+1≤N, k≠i.
[0183] In this embodiment, as Figure 2 As shown, after step six, the method further includes:
[0184] Step 7: The defense device (security vendor) initiates a defense strategy to the defense platform (privacy computing contract platform);
[0185] Step 8: The defense platform (privacy computing contract platform) collects the defense strategies of participating defense devices (security vendors) k, forms a set, and feeds it back to the defense device (security vendor) i.
[0186] Step 9: Repeat steps 7 and 8 until the defense device (security vendor) i triggers the termination condition;
[0187] Step 10: The defense device (security vendor) i sends the final defense strategy to the defense platform (privacy computing contract platform).
[0188] Assume that security events are independent of each other, and that one or more security vendors can protect against the same security event, but the same security phenomenon can only be defended by one security vendor. For any security event q = {q(z)} n If N'+1 security vendors (including one security vendor i and N' security vendors k) detect its security event data, then all of these N'+1 security vendors can participate in joint game iteration to obtain a collaborative security strategy, where N'+1≤N.
[0189] In each iteration, the defense equipment (security vendor) will assess the security phenomena q(z) it is defending against. n Each security vendor makes demands regarding the security phenomena (quotes) and their benefits, based on the security phenomena q(z) defended by other security vendors received. n ) and their benefits are used to make recommendations and determine the next round of bidding. When all security phenomena q(z) n The benefits of defense (v) n (q(z n The iteration ends when the sum of the values is less than or equal to 1 benefit unit (let's assume it's 1).
[0190] In one implementation, a game is played based on a first defense strategy and a second defense strategy to obtain a final defense strategy that allows the self and the cooperative defense devices to defend against certain security phenomena of a security event. Specifically, this includes:
[0191] Based on Q, obtain the defense q(z). n The minimum second quote v n (q(z n )),
[0192] And select the minimum second quote {v k (q(z k ),k∈n} and its own first quote {v i (q(z i ),i∈n},
[0193] And obtain the security phenomena of its own defense q(z) i The utility of u i (q(z i ))=v i (q(z i ))-b i (q(z i ), where b i (q(z i )) is the self-defense q(z) of a certain defense device i. i The expenses of ) and,
[0194] Judgment∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i Whether ))≥0 are true simultaneously, where s is the preset revenue unit.
[0195] If so, obtain the security phenomena of its own defenses q(z) i ) and collaborative defense equipment defends against some security phenomena q(z) k The ultimate defense strategy,
[0196] If not, retrieve again. It sends and receives Q to the defense platform, and retrieves the final defense strategy again.
[0197] In this embodiment, for any security vendor i' among security vendor i and N' security vendors k, the specific algorithm is as follows:
[0198] Step 1: Send the first round of quotes to the defense platform (privacy computing platform).
[0199] Step 2: Receive other offer set Q from defense platform (privacy computing platform) 1 ;
[0200] Step 3: Determine whether there exists such that or
[0201] Step 4: Determine whether and are both true, if so, the algorithm ends and the cooperative strategy is obtained, otherwise, go to Step 5;
[0202] Step 5: According to the first round of offer set Q 1 , adjust the revenue and suggestion, and send the second round of offer
[0203] Step 6: Repeat Step 3 to Step 4 until the end condition is triggered;
[0204] Note: The revenue offer of the security vendor i' outside the security vendor, represents the utility of the security vendor i' outside the security vendor.
[0205] It can be understood that there are many ways to use the calculation and judgment of utility and offer, such as: the utility of each defense device to each security phenomenon can be calculated before sending the offer in each round, and the offer and utility can be sent to the defense platform together, and then the other defense devices select the final cooperative strategy according to the offer and utility; or the defense devices can send the offer first, and then select the acceptable cooperative strategy according to the offer and utility, and then negotiate with other defense devices through the defense platform.
[0206] In an embodiment, wherein:
[0207]
[0208] wherein, c i (q(z i )) is the calculation overhead of a certain defense device i to defend q(z i ), o i (q(z i )) is the operation overhead of a certain defense device i to defend q(z i ), is the punishment of a certain defense device i not to defend q(z i ), represents rounding up, and a is the punishment of a certain defense device i not to defend q(zi The probability of ).
[0209] In this embodiment, a security event q is considered to consist of multiple security phenomena. Security vendors need to address all security phenomena to achieve security defense when designing security strategies. For ease of representation, it is further assumed that a security event is a single unit quantity, then the security phenomenon q(z) n If ∑ can be expressed as the proportion of security incidents, then we have ∑ n q(z n = 1. If security vendor i defends against a partial security phenomenon q(z) of event q. n The utility function can be written as u i (q(z i ))=v i (q(z i ))-b i (q(z i )),in, c i (q(z i )) is a defensive security phenomenon q(z) i The computational overhead incurred; i (q(z i )) is a defensive security phenomenon q(z) i The operational costs incurred are different for different security vendors because each vendor has different computing resources and operational capabilities. Therefore, the computing and operational costs incurred by different security vendors defending against the same security incident will be different. The security phenomenon q(z) was not defended against. i ) punishment, To indicate rounding up, use [the appropriate method]. Representing the safety phenomenon q(z) i If not defended against, the potential losses caused by the security incident q may be incurred; α represents the security phenomenon q(z). i The probability of something not being defended against.
[0210] It is understood that the three hash intersection methods provided in this embodiment are not unique, and can be replaced by the Cuckoo hash intersection method, which can still obtain security vendors with the same security events; the method of obtaining security collaboration strategies through cooperative game is also not unique, and can be replaced by the master-slave game method.
[0211] In this embodiment 1, hash intersection is used to help security vendors participating in collaborative defense quickly find the intersection of security event data while ensuring that the data is not leaked. Based on this intersection data, through cooperative game theory and multiple rounds of security policy negotiation, security policy collaboration is achieved, which not only reduces defense costs but also improves the overall security defense capabilities of industrial enterprises.
[0212] Embodiment 2:
[0213] As shown in the accompanying drawings, the present disclosure provides a defense device for security event cooperative defense, which comprises: Figure 3
[0214] a hash intersection module, configured to obtain a first hash calculation result of a security event of itself and second hash calculation results of security events of the rest of defense devices respectively,
[0215] and find the intersection of the first hash calculation result and the second hash calculation results to determine the cooperative defense devices for cooperative defense of a security event with itself;
[0216] a strategy game module, connected with the hash intersection module, configured to obtain a first defense strategy of a security event of itself and second defense strategies of a security event of the cooperative defense devices respectively,
[0217] and perform game according to the first defense strategy and the second defense strategies to obtain the final defense strategy of a part of security phenomena of a security event of itself and the cooperative defense devices respectively.
[0218] In an embodiment, wherein:
[0219] the first hash calculation result is specifically: a general first hash calculation result or, a symmetrically encrypted first hash calculation result or, an asymmetrically encrypted first hash calculation result
[0220] the second hash calculation result is specifically: a general second hash calculation result or, a symmetrically encrypted second hash calculation result or, an asymmetrically encrypted second hash calculation result
[0221] wherein, H(·) is a hash function, is a security event of a defense device i itself, m i is the number of security events of a defense device i itself, a i is a first random key of a defense device i itself, a j is a first random key of the rest of defense devices j respectively, d is a private key of an asymmetric key of the rest of defense devices j respectively, is a security event of the rest of defense devices j respectively, m j is the number of security events of the rest of defense devices j respectively.
[0222] In an embodiment, the hash intersection module specifically comprises:
[0223] a computing unit configured to obtain X i = H(Y i ) of a security event of itself,
[0224] a sending unit connected with the computing unit and configured to send X i = H(Y i ) of the security event of itself to a defense platform,
[0225] a receiving unit connected with the sending unit and configured to receive a set B j = {X j , j≠i} of X -i = H(Y j ) of the security event of each of the rest of defense devices j sent by the defense platform.
[0226] In an embodiment, the hash intersection module specifically comprises:
[0227] a computing unit configured to encrypt the security event of itself by using a i to obtain a first one-sided encryption hash calculation result,
[0228] a sending unit connected with the computing unit and configured to send
[0229] a receiving unit connected with the sending unit and configured to receive a second one-sided encryption hash calculation result sent by the defense platform, and wherein, is obtained by each of the rest of defense devices j by using a j to encrypt the security event of itself and sent to the defense platform, is obtained by each of the rest of defense devices j by using a j to encrypt the security event received from the defense platform, and sent to the defense platform; and,
[0230] the computing unit is further connected with the receiving unit and further configured to encrypt by using a i to obtain
[0231] In an embodiment, the hash intersection module specifically comprises:
[0232] a receiving unit configured to receive a public key e of each of the rest of defense devices j sent by the defense platform, wherein (e, d) is a pair of asymmetric keys,
[0233] a generating unit connected with the receiving unit and configured to generate a random number {r l , l∈m i},
[0234] The computing unit, connected with the generating unit, is configured to utilize e and {r l ,l∈m i} to encrypt the own security event to obtain a first public key random hash calculation result and,
[0235] The sending unit, connected with the computing unit, is configured to send the X
[0236] The receiving unit, also connected with the sending unit, is also configured to receive the X j = H(Y j ) d and the first private key random hash calculation result wherein X j = H(Y j ) d is obtained by the rest of the defense devices j respectively utilizing d to encrypt the respective security event and sent to the defense platform, is obtained by the rest of the defense devices j respectively utilizing d to decrypt and encrypt the respective received X from the defense platform and sent to the defense platform,
[0237] The computing unit, also connected with the receiving unit, is also configured to utilize {r l ,l∈m i} to decrypt to obtain X i = H(Y i ) d .
[0238] In an embodiment, the hash intersection module specifically further comprises:
[0239] The intersection unit is configured to calculate X i ∩X j to obtain the rest of the defense devices k' ∈ j that have a certain security event in common;
[0240] The sending unit, connected with the intersection unit, is also configured to send a first collaboration invitation to the rest of the defense devices k' requesting to jointly defend q to the defense platform;
[0241] The receiving unit, connected with the sending unit, is configured to receive a second collaboration invitation set sent by the defense platform, wherein the second collaboration invitation set is sent by the rest of the defense devices k' requesting to jointly defend q;
[0242] The matching unit, connected with the receiving unit, is configured to determine the collaborative defense device k ∈ k' that collaborates with the defense device i to defend q in response to the matching of the first collaboration invitation and the second collaboration invitation.
[0243] In one embodiment, wherein:
[0244] The first defense strategy includes the price and / or utility of a defense device itself in defending against at least some of the security phenomena of a security incident.
[0245] The second defense strategy includes the quotes and / or utility of each of the collaborative defense devices for defending against at least some of the security phenomena of a security incident.
[0246] The final defense strategy is obtained based on at least one round of bids and / or utility for all security phenomena related to defending against a security incident.
[0247] In this context, utility equals the price quoted for defending against a security event or a security phenomenon minus the cost.
[0248] In one embodiment, the strategy game module specifically includes:
[0249] The quotation unit is used to obtain the self-defense information for a certain security event q = {q(z)}. n The security phenomenon q(z) of n∈N} n First quote Where N is the number of safe phenomena of q.
[0250] The sending unit, connected to the quotation unit, is used to send data to the defense platform.
[0251] The receiving unit, connected to the sending unit, is used to receive the defense q(z) of each of the collaborative defense devices k sent by the defense platform. n The set of second quotes Where N'+1≤N, k≠i.
[0252] In one embodiment, the strategy game module further includes:
[0253] The pricing analysis unit is used to obtain the defense q(z) based on Q. n The minimum second quote v n (q(z n )),
[0254] The quotation selection unit, connected to the quotation analysis unit, is used to select a subset of the smallest second quotations {v}. k (q(z k ),k∈n} and its own first quote {v i (q(z i ),i∈n),
[0255] The utility unit, connected to the quotation selection unit, is used to obtain the security phenomena q(z) of its own defense components. i The utility of ui (q(z i ))=v i (q(z i ))-b i (q(z i )),in,
[0256] b i (q(z i )) is the self-defense q(z) of a certain defense device i. i The expenses of ) and,
[0257] The judgment unit, connected to the utility unit, is used to judge ∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i Whether ))≥0 are true simultaneously, where s is the preset revenue unit.
[0258] If so, obtain the security phenomena of its own defenses q(z) i ) and collaborative defense equipment defends against some security phenomena q(z) k The ultimate defense strategy,
[0259] If not, retrieve again. It sends and receives Q to the defense platform, and retrieves the final defense strategy again.
[0260] In one embodiment, wherein:
[0261]
[0262] Among them, c i (q(z i )) is the self-defense q(z) of a certain defense device i. i The computational overhead of o i (q(z i )) is the self-defense q(z) of a certain defense device i. i Operating expenses, The defense device i itself failed to defend against q(z) i ) punishment, This indicates rounding up, where α represents the value of q(z) that a certain defense device i failed to defend against. i The probability of ).
[0263] Example 3:
[0264] like Figure 2 As shown, Embodiment 3 of this disclosure provides a defense system, the defense system comprising:
[0265] a defense device as described in Embodiment 2;
[0266] a defense platform connected with the defense device, the defense platform being configured to forward data between the defense device and the remaining defense devices, the data including the first hash calculation result, the second hash calculation result, the first defense strategy, and the second defense strategy.
[0267] Embodiment 4:
[0268] Embodiment 4 of the present disclosure provides a computer readable storage medium, the computer readable storage medium storing a computer program, when the computer program is run by a processor, the computer program implements the security event cooperative defense method as described in Embodiment 1, or the defense device as described in Embodiment 2, or the defense system as described in Embodiment 3.
[0269] The computer readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information such as computer readable instructions, data structures, computer program modules or other data. The computer readable storage medium includes but is not limited to RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disc (DVD) or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device, or any other medium that can be used to store desired information and can be accessed by a computer.
[0270] In addition, the present disclosure can also provide a computer device including a memory and a processor, the memory storing a computer program, when the processor runs the computer program stored in the memory, the processor executes the security event cooperative defense method as described in Embodiment 1, the computer device can be the defense device as described in Embodiment 2, or the defense system as described in Embodiment 3.
[0271] The memory is connected with the processor, the memory can adopt flash memory or read-only memory or other storage, and the processor can adopt central processing unit or single-chip microcomputer.
[0272] Embodiments 1-4 of the present disclosure provide a security event cooperative defense method, a defense device, a defense system and a computer readable storage medium. By hash intersection, the defense device participating in cooperative defense is helped to quickly find the defense device with the same security event data without leaking the security event data, so as to protect the data assets from being leaked. By cooperative game, the defense device with the same security event data is helped to negotiate the defense strategy of the security event, and the trusted security strategy cooperation is realized after negotiation, so as to effectively improve the enthusiasm of the defense device participating in cooperative defense, and further improve the cooperative defense capability.
[0273] It can be understood that the above implementation is only an exemplary implementation adopted for illustrating the principles of the present disclosure, however the present disclosure is not limited thereto. Various modifications and improvements can be made by those of ordinary skill in the art without departing from the spirit and essence of the present disclosure, and these modifications and improvements are also considered as the protection scope of the present disclosure.
Claims
1. A collaborative defense method for security incidents, characterized in that, The method includes: A certain defense device obtains the first hash calculation result of its own security event, and the second hash calculation results of the security events of the other defense devices. Furthermore, the intersection of the first hash calculation result and the second hash calculation result is used to determine the collaborative defense device that collaborates with itself to defend against a certain security event; A certain defense device acquires its own primary defense strategy against a certain security event, as well as the secondary defense strategies of each of the cooperating defense devices against the same security event. Furthermore, it engages in a game based on the first and second defense strategies to obtain the final defense strategy that allows it and its collaborative defense devices to defend against certain security phenomena related to a security event.
2. The method according to claim 1, characterized in that, in: The specific result of the first hash calculation is: the general result of the first hash calculation. Alternatively, the first hash calculation result of symmetric encryption. Alternatively, the first hash calculation result of asymmetric encryption. The specific result of the second hash calculation is: the general result of the second hash calculation. Alternatively, the result of the second hash calculation in symmetric encryption. Alternatively, the result of the second hash calculation in asymmetric encryption. Where H(·) is the hash function, This is a security incident involving a certain defense device itself. i This refers to the number of security events occurring within a specific defense device i. i It is the first random key of a certain defense device i itself, a j d is the first random key of each of the other defense devices j, and d is the private key of the asymmetric key of each of the other defense devices j. These are the individual security incidents of the other defense devices, m j It represents the number of security incidents for each of the other defense devices.
3. The method according to claim 2, characterized in that, A certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of other defense devices, specifically including: A certain defense device i obtains X of its own security events. i =H(Y) i ), Send X to the defense platform i , And receive the security events X from the other defense devices j sent by the defense platform. j =H(Y) j The set B) -i ={X j ,j≠i}.
4. The method according to claim 2, characterized in that, A certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of other defense devices, specifically including: A certain defense device i utilizes a i Encrypting its own security events to obtain the first one-sided cryptographic hash calculation result. and send to the defense platform And receive the second one-sided cryptographic hash calculation result sent by the defense platform. and in, The remaining defense equipment each utilizes a j Each entity encrypts the security events it receives and sends to the defense platform. The remaining defense equipment each utilizes a j Each encrypted message received from the defense platform Acquired and sent to the defense platform; and, Using a i encryption Get 5. The method according to claim 2, characterized in that, A certain defense device obtains the first hash calculation result of its own security event and the second hash calculation results of the security events of other defense devices, specifically including: A certain defense device i receives the public keys e of the other defense devices j sent by the defense platform, where (e,d) is an asymmetric key pair. And generate its own random number. , And using e and Encrypt its own security events to obtain the result of a random hash calculation of the first public key. as well as, Send to the defense platform And receive X sent by the defense platform j =H(Y) j ) d The result of random hash calculation of the first private key Among them, X j =H(Y) j ) d The other defense devices (j) each use d to encrypt their own security events and then send them to the defense platform. The other defense devices each use d to decrypt and encrypt the data they receive from the defense platform. Obtained and sent to the defense platform, And utilize Decryption Get X i =H(Y) i ) d .
6. The method according to claim 2, characterized in that, The intersection of the first hash calculation result and the second hash calculation result is used to determine the collaborative defense devices that will cooperate with it in defending against a certain security event. Specifically, these include: Calculate X i ∩X j In order to obtain information about a common security incident The remaining defense devices k'∈j, It then sends a first cooperation invitation to the defense platform, requesting the other defense devices k' to jointly defend q. And a set of second cooperation invitations sent by the defense platform to the other defense devices k' requesting joint defense q; and, In response to the matching of the first and second cooperation invitations, determine the cooperative defense device k∈k' that cooperates with defense device i to defend q.
7. The method according to any one of claims 1-6, characterized in that, in: The first defense strategy includes the price and / or utility of a defense device itself in defending against at least some of the security phenomena of a security incident. The second defense strategy includes the quotes and / or utility of each of the collaborative defense devices for defending against at least some of the security phenomena of a security incident. The final defense strategy is obtained based on at least one round of bids and / or utility for all security phenomena related to defending against a security incident. In this context, utility equals the price quoted for defending against a security event or a security phenomenon minus the cost.
8. The method according to claim 7, characterized in that, A certain defense device acquires its own primary defense strategy against a certain security event, as well as the secondary defense strategies of each of the cooperating defense devices against the same security event, specifically including: A certain defense device i obtains information about a certain security event q = {q(z)}. n The security phenomenon q(z) of n∈N} n First quote Where N is the number of safe phenomena of q. and send to the defense platform And receive the defense q of each of the collaborative defense devices k sent by the defense platform (q(z)). n The second offer set Where N'+1≤N, k≠i.
9. The method according to claim 8, characterized in that, The game involves a first and second defense strategy to determine the final defense strategy, which involves both the individual and collaborative defense devices each defending against a specific security event. This strategy includes: Based on Q, obtain the defense q(z). n The minimum second quote v n (q(z n )), And select the minimum second quote {v k (q(z k ),k∈n} and its own first quote {v i (q(z i ),i∈n}, And obtain the security phenomena of its own defense q(z) i The utility of u i (q(z i ))=v i (q(z i ))-b i (q(z i ), where b i (q(z i )) is the self-defense q(z) of a certain defense device i. i The expenses of ) and, Judgment∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i Whether ))≥0 are true simultaneously, where s is the preset revenue unit. If so, obtain the security phenomena of its own defenses q(z) i ) and collaborative defense equipment defends against some security phenomena q(z) k The ultimate defense strategy, If not, retrieve again. It sends and receives Q to the defense platform, and retrieves the final defense strategy again.
10. The method according to claim 9, characterized in that, in: Among them, c i (q(z i )) is the self-defense q(z) of a certain defense device i. i The computational overhead of o i (q(z i )) is the self-defense q(z) of a certain defense device i. i Operating expenses, The defense device i itself failed to defend against q(z) i ) punishment, This indicates rounding up, where α represents the value of q(z) that a certain defense device i failed to defend against. i The probability of ).
11. A defensive device, characterized in that, For collaborative defense against security incidents, the defense device includes: The hash intersection module is used to obtain the first hash calculation result of its own security event and the second hash calculation results of the security events of the other defense devices. Furthermore, the intersection of the first hash calculation result and the second hash calculation result is used to determine the collaborative defense device that collaborates with itself to defend against a certain security event; The strategy game module, connected to the hash intersection module, is used to obtain its own first defense strategy against a certain security event, and the second defense strategies of each of the collaborative defense devices against the same security event. Furthermore, it engages in a game based on the first and second defense strategies to obtain the final defense strategy that allows it and its collaborative defense devices to defend against certain security phenomena related to a security event.
12. The defensive device according to claim 11, characterized in that, in: The specific result of the first hash calculation is: the general result of the first hash calculation. Alternatively, the first hash calculation result of symmetric encryption. Alternatively, the first hash calculation result of asymmetric encryption. The specific result of the second hash calculation is: the general result of the second hash calculation. Alternatively, the result of the second hash calculation in symmetric encryption. Alternatively, the result of the second hash calculation in asymmetric encryption. Where H(·) is the hash function, This is a security incident involving a certain defense device itself. i This refers to the number of security events occurring within a specific defense device i. i It is the first random key of a certain defense device i itself, a j d is the first random key of each of the other defense devices j, and d is the private key of the asymmetric key of each of the other defense devices j. These are the individual security incidents of the other defense devices, m j It represents the number of security incidents for each of the other defense devices.
13. The defensive device according to claim 12, characterized in that, The hash intersection module specifically includes: The computing unit is used to obtain X of its own security events. i =H(Y) i ), The sending unit, connected to the computing unit, is used to send X to the defense platform. i =H(Y) i ), The receiving unit, connected to the sending unit, is used to receive security events X from the other defense devices sent by the defense platform. j =H(Y) j The set B) -i ={X j ,j≠i}.
14. The defensive device according to claim 12, characterized in that, The hash intersection module specifically includes: Computational unit, used to utilize a i Encrypting its own security events to obtain the first one-sided cryptographic hash calculation result. The sending unit, connected to the computing unit, is used to send data to the defense platform. The receiving unit, connected to the sending unit, is used to receive the second one-sided cryptographic hash calculation result sent by the defense platform. and in, The remaining defense equipment each utilizes a j Each entity encrypts the security events it receives and sends to the defense platform. The remaining defense equipment each utilizes a j Each encrypted message received from the defense platform Acquired and sent to the defense platform; and, The computing unit, also connected to the receiving unit, is also used to utilize a i encryption Get 15. The defensive device according to claim 12, characterized in that, The hash intersection module specifically includes: The receiving unit is used to receive the public keys e of the other defense devices j sent by the defense platform, where (e,d) is a pair of asymmetric keys. The generation unit, connected to the receiving unit, is used to generate its own random numbers. , The computational unit, connected to the generation unit, is used to utilize e and Encrypt its own security events to obtain the result of a random hash calculation of the first public key. as well as, The sending unit, connected to the computing unit, is used to send data to the defense platform. The receiving unit, also connected to the transmitting unit, is also used to receive X signals sent by the defense platform. j =H(Y) j ) d The result of random hash calculation of the first private key Among them, X j =H(Y) j ) d The other defense devices (j) each use d to encrypt their own security events and then send them to the defense platform. The other defense devices each use d to decrypt and encrypt the data they receive from the defense platform. Obtained and sent to the defense platform, The computing unit is also connected to the receiving unit and is also used to utilize... Decryption Get X i =H(Y) i ) d .
16. The defensive device according to claim 12, characterized in that, The hash intersection module further includes: Intersection cell, used to calculate X i ∩X j In order to obtain information about a common security incident The remaining defense equipment k'∈j; The sending unit, connected to the intersection unit, is also used to send a first cooperation invitation to the defense platform requesting the other defense devices k' to jointly defend q; The receiving unit, connected to the sending unit, is used to receive a set of second cooperation invitations sent by the defense platform from the other defense devices k' requesting joint defense q; A matching unit, connected to a receiving unit, is used to determine, in response to a first cooperation invitation and a second cooperation invitation, a cooperative defense device k∈k' that cooperates with defense device i to defend q.
17. The defensive device according to any one of claims 11-16, characterized in that, in: The first defense strategy includes the price and / or utility of a defense device itself in defending against at least some of the security phenomena of a security incident. The second defense strategy includes the quotes and / or utility of each of the collaborative defense devices for defending against at least some of the security phenomena of a security incident. The final defense strategy is obtained based on at least one round of bids and / or utility for all security phenomena related to defending against a security incident. In this context, utility equals the price quoted for defending against a security event or a security phenomenon minus the cost.
18. The defensive device according to claim 17, characterized in that, The strategy game module specifically includes: The quotation unit is used to obtain the self-defense information for a certain security event q = {q(z)}. n The security phenomenon q(z) of n∈N} n First quote Where N is the number of security phenomena of q, and the sending unit, connected to the quotation unit, is used to send to the defense platform. The receiving unit, connected to the sending unit, is used to receive the defense q(z) of each of the collaborative defense devices k sent by the defense platform. n The set of second quotes Where N'+1≤N, k≠i.
19. The defensive device according to claim 17, characterized in that, The strategy game module further includes: The pricing analysis unit is used to obtain the defense q(z) based on Q. n The minimum second quote v n (q(z n )), The quotation selection unit, connected to the quotation analysis unit, is used to select a subset of the smallest second quotations {v}. k (q(z k ),k∈n} and its own first quote {v i (q(z i ),i∈n}, The utility unit, connected to the quotation selection unit, is used to obtain the security phenomena q(z) of its own defense components. i The utility of u i (q(z i ))=v i (q(z i ))-b i (q(z i ), where b i (q(z i )) is the self-defense q(z) of a certain defense device i. i The expenses of ) and, The judgment unit, connected to the utility unit, is used to judge ∑ N ({v k (q(z k ))}+{v i (q(z i ))})≤s and u i (q(z i Whether ))≥0 are true simultaneously, where s is the preset revenue unit. If so, obtain the security phenomena of its own defenses q(z) i ) and collaborative defense equipment defends against some security phenomena q(z) k The ultimate defense strategy, If not, retrieve again. It sends and receives Q to the defense platform, and retrieves the final defense strategy again.
20. The defensive device according to claim 19, characterized in that, in: Among them, c i (q(z i )) is the self-defense q(z) of a certain defense device i. i The computational overhead of o i (q(z i )) is the self-defense q(z) of a certain defense device i. i Operating expenses, The defense device i itself failed to defend against q(z) i ) punishment, This indicates rounding up, where α represents the value of q(z) that a certain defense device i failed to defend against. i The probability of ).
21. A defense system, characterized in that, The defense system includes: The defensive device as described in any one of claims 11-20; A defense platform connected to the defense device, the defense platform being used to forward data between the defense device and other defense devices, the data including a first hash calculation result, a second hash calculation result, a first defense strategy, and a second defense strategy.
22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the collaborative defense method for security events as described in any one of claims 1-10, the defense device as described in any one of claims 11-20, or the defense system as described in claim 21.
Citation Information
Patent Citations
Coordinated defense method of full process and full network safety coordinated defense system
CN101938460A
Network defense strategy selection method for optimal reaction dynamic evolution game model
CN106953879A