A method for resisting cyberattacks considering robust practical stability

By constructing the Lyapunov function and event triggering mechanism, the robust stability problem of complex coupled network systems under DoS attacks is solved, and the system stability and performance improvement during the attack is achieved.

CN119109618BActive Publication Date: 2025-07-08SICHUAN ARTIFICIAL INTELLIGENCE RESEARCH INSTITUTE (YIBIN)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411071274.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-06
Publication Date
2025-07-08
Estimated Expiration
2044-08-06

AI Technical Summary

Technical Problem

The prior art fails to effectively consider the robust actual stability of complex coupled network systems under DoS attacks, and ignores factors such as uncertainty, network delay, actuator saturation and non-periodic attacks, resulting in insufficient attack resistance performance.

Method used

The Liyapunov function is constructed, and the control gain, auxiliary gain matrix and trigger matrix are obtained by deriving, the event triggering mechanism is designed, and the controller parameters are updated to resist DoS attacks, ensuring the robust stability of the system during attacks.

Benefits of technology

In the case of poor physical state of the system, robust actual stability is achieved, resource consumption is reduced, Zeno's behavior is eliminated, and system performance is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119109618B_ABST
    Figure CN119109618B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for resisting cyberattacks considering robust practical stability. This method uses Lyapunov functions to obtain sufficient conditions to ensure that complex coupled networks achieve robust event stability. Based on the idea of switching, there are two strategies to handle the active time of the controller during the nth cyberattack, that is, in one case, zero input is used. A denial-of-service attack will cause the controller to be unable to update in time, and the controller is triggered immediately after the attack on the system ends. The other is to save the latest published trigger data during non-attacks to resist the impact of attacks and use the controller to control the system state. It not only eliminates Zeno behavior, but also reduces resource consumption in the channel and improves system performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a method for resisting network attacks considering robust practical stability. Background Art

[0002] The background of robust practical stability technology is a multi-disciplinary field, including computer networks, information security, data science, systems engineering, etc. Its development and application are crucial for ensuring the secure operation of modern networks and information systems. Robust practical stability under DoS (Denial of Service) attacks is part of the field of network security.

[0003] Regarding the problem of denial of service attacks, existing researchers only model it as obeying the Bernoulli model. However, in fact, DoS attacks are carefully planned by attackers to reduce system performance. Therefore, considering the periodic model and Bernoulli distribution is inappropriate.

[0004] Due to the limitations of the structure of complex coupled networks itself, few researchers consider studying stability problems under poor physical states, and do not simultaneously consider issues such as attacks, time delays, resource consumption, actuator saturation, etc. Currently, the research on complex coupled network systems focuses on problems such as consensus and Lyapunov stability, and there are no research results on robust practical stability. However, the Lyapunov stability and consensus problems do not consider the boundedness of the system state. Therefore, in the application of actual engineering, it is necessary to ensure that the system state is within a certain range to improve system performance. Summary of the Invention

[0005] Aiming at the above deficiencies in the prior art, a method for resisting network attacks considering robust practical stability provided by the present invention solves the problem that the existing methods do not consider robust practical stability, resulting in poor attack resistance performance.

[0006] To achieve the above invention purpose, the technical solution adopted by the present invention is as follows:

[0007] Provide a method for resisting network attacks considering robust practical stability, which includes the following steps:

[0008] S1. Construct a Lyapunov function; obtain the control gain K, the auxiliary gain matrix H, and the trigger matrix W by differentiating the Lyapunov function, and construct a controller based on the control gain K and the auxiliary gain matrix H;

[0009] S2. Determine whether there is a network attack currently. If so, enter step S3; otherwise, enter step S5;

[0010] S3. Construct an event trigger mechanism based on the error between the current system state and the system state at the previous moment, the trigger matrix, and the system state that triggered the attack resistance last time;

[0011] S4. Determine whether the current time is within the attack interval. If it is within the attack interval, immediately obtain the trigger time through the event trigger mechanism at the end of the attack, and substitute the trigger time into the controller to update the controller parameters, cancel the impact of the current attack, complete the resistance to the current DoS attack, and enter step S5; otherwise, enter step S6;

[0012] S5. Determine whether to continue the network attack resistance. If so, return to step S1; otherwise, end;

[0013] S6. Determine whether the error between the current system state and the system state at the previous moment satisfies the given condition. If so, obtain the trigger time through the event trigger mechanism, and substitute the trigger time into the controller to update the controller parameters, and return to step S5; otherwise, directly enter step S5.

[0014] Furthermore, the expression of the Lyapunov function is:

[0015]

[0016] where V δ (t) represents the Lyapunov function at time t; x(t) represents the system state at time t; x(s) represents the system state at time s; δ is a value-taking function. If the current time t is a non-attack time, the value is 1. If the current time t is an attack time, the value is 2; is the sampling interval; e is the natural constant; Q δ and are both positive definite matrices; θ represents time; the superscript T represents the transpose of the matrix; represents the first derivative of the transpose of x(s); represents the first derivative of x(s); ds and dθ are both integral elements; when δ takes the value of 1, a δ is 0.16, and when δ takes the value of 2, a δ is 0.1.

[0017] Furthermore, the specific method for obtaining the control gain K, the auxiliary gain matrix H, and the trigger matrix W by taking the derivative of the Lyapunov function is as follows:

[0018] Take the derivative of the Lyapunov function:

[0019]

[0020] Solve for Ψ1 < 0 and Ψ2 < 0 through Matlab to obtain the control gain K and the triggering matrix W; where represents the derivative of the Lyapunov function without attacks; represents the derivative of the Lyapunov function with attacks; τ k,n (t) represents the time of the k-th trigger, and x T (t - τ k,n (t)) is an n-dimensional state matrix with time delay; represents the piecewise error of the k-th trigger and the n-th attack; is a state matrix including the adopted period; Ψ T (t, x(t)) is an n-dimensional nonlinear term;

[0021]

[0022]

[0023] are all positive definite matrices; The parameter θ l satisfies D l and are both prior matrices; is the coefficient matrix of the nonlinear term; U1 is the matrix that satisfies the nonlinear term; represents the Kronecker inner product; M f represents the internal coupling matrix; the * in the matrix represents the transpose of the symmetric position; c is the coupling strength; A, E, and G are all constant matrices, and G = [g ii N×N , N represents the set of positive integers; v is a constant;

[0024]

[0025]

[0026] U1 and U2 are both positive definite matrices; G1 and G2 are prior matrices.

[0027] Furthermore, the expression of the controller is:

[0028]

[0029] where represents the i-th input variable of the actuator with saturation at time t; x i (t) is the i-th state variable of the system at time t, that is, the object to be updated; F 1,n ​is the nth non - attack time period; F 2,n is the nth attack time period; f(t, x i (t)) represents the non - linear term; x j (t) represents the jth state variable of the system at time t; B f is a constant matrix.

[0030] Furthermore, the expression of the event - triggering mechanism in step S3 is:

[0031]

[0032] where is the triggering time of the kth trigger and the nth attack; represents the dth time period between the kth trigger and the (k + 1)th trigger; represents the next triggering time; represents the transpose of the error matrix between the current system state and the system state at the previous moment; represents the error matrix between the current system state and the system state at the previous moment; δ(t) is the triggering threshold; represents when the time point is the system parameter matrix at this time; F 1,n-1 represents the (n - 1)th non - attack time period; h n is the start time of the nth attack; represents in the case of the situation.

[0033] Furthermore, the matrices A, E, G, M f , matrix B f and matrix G2 are respectively:

[0034]

[0035] The value of the coupling strength c is 9; matrix G1 is a matrix with all element values being 0; The value of is 0.01; the value of v is 5.

[0036] Furthermore, the matrix F2, the auxiliary gain matrix H and the trigger matrix W are respectively:

[0037]

[0038]

[0039] The beneficial effects of the present invention are:

[0040] 1. This method takes into account factors that can affect system performance, such as uncertain nonlinearity, network delays, aperiodic network attacks, actuator saturation, and actuator faults. This method can achieve robust practical stability under poor physical conditions of the system and has a wider range of practical applications.

[0041] 2. Based on the idea of switching, this method has two strategies to handle the active time of the controller during the nth network attack. One case is to use zero input. A denial-of-service attack can cause the controller to fail to update in a timely manner, and the controller is triggered immediately after the attack on the system ends. The other is to save the latest published trigger data during non-attack periods to resist the impact of the attack and use the controller to control the system state. This not only eliminates Zeno behavior but also reduces resource consumption in the channel and improves system performance.

[0042] 3. This method uses Lyapunov functions to obtain sufficient conditions to ensure the robust event stability of complex coupled networks. Eventually, the system state reaches the pre-determined robust design stable domain from the given initial domain. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 Schematic diagram of the process of this method;

[0044] Figure 2 Schematic diagram of the framework of the adaptive event-triggered control scheme under denial-of-service attack in the embodiment;

[0045] Figure 3 The first component of the three nodes selected for the complex coupled network in the embodiment;

[0046] Figure 4 The second component of the three nodes selected for the complex coupled network in the embodiment;

[0047] Figure 5 The third component of the three nodes selected for the complex coupled network in the embodiment;

[0048] Figure 6 Timing diagram of the controller update for the three nodes in the embodiment;

[0049] Figure 7 Schematic diagram of the DoS attack in the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0050] The following describes the specific embodiments of the present invention to facilitate those skilled in the art to understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concept of the present invention are within the scope of protection.

[0051] As Figure 1 shown, the method for resisting cyber attacks considering robust practical stability includes the following steps:

[0052] S1. Construct a Lyapunov function; obtain the control gain K, the auxiliary gain matrix H, and the triggering matrix W by taking the derivative of the Lyapunov function, and construct a controller based on the control gain K and the auxiliary gain matrix H;

[0053] S2. Determine whether there is a cyber attack currently. If so, go to step S3; otherwise, go to step S5;

[0054] S3. Based on the error between the current system state and the system state at the previous moment, the triggering matrix, and the system state at which the previous triggering attack resistance occurred, construct an event-triggering mechanism;

[0055] S4. Determine whether the current state is in the attack interval. If it is in the attack interval, immediately obtain the triggering moment through the event-triggering mechanism at the end of the attack, and substitute the triggering moment into the controller to update the controller parameters, cancel the influence of the current attack, complete the resistance to the current DoS attack, and go to step S5; otherwise, go to step S6;

[0056] S5. Determine whether to continue the cyber attack resistance. If so, return to step S1; otherwise, end;

[0057] S6. Determine whether the error between the current system state and the system state at the previous moment satisfies the given condition. If so, obtain the triggering moment through the event-triggering mechanism, and substitute the triggering moment into the controller to update the controller parameters, and return to step S5; otherwise, directly go to step S5.

[0058] The expression of the Lyapunov function is:

[0059]

[0060] where V δ (t) represents the Lyapunov function at time t; x(t) represents the system state at time t; x(s) represents the system state at time s; δ is a value-taking function, which takes the value of 1 if the current time t is a non-attack time, and takes the value of 2 if the current time t is an attack time; h is the sampling interval; e is the natural constant; and are both positive definite matrices; θ represents time; the superscript T represents the transpose of the matrix; represents the first derivative of the transpose of x(s); represents the first derivative of x(s); ds and dθ are both integral elements; when δ takes the value of 1, a δis 0.16. When δ takes the value of 2, a δ is 0.1.

[0061] The specific method for obtaining the control gain K, the auxiliary gain matrix H, and the triggering matrix W by taking the derivative of the Lyapunov function is as follows:

[0062] Take the derivative of the Lyapunov function:

[0063]

[0064] Solve ψ1 < 0 and ψ2 < 0 through matlab to obtain the control gain K and the triggering matrix W; where represents the derivative of the Lyapunov function without attacks; represents the derivative of the Lyapunov function with attacks; τ k,n (t) represents the time of the k-th trigger, x T (t - τ k,n (t)) is an n-dimensional state matrix containing time delay; represents the segmentation error of the k-th trigger and the n-th attack; is a state matrix containing the adopted period; Ψ T (t, x(t)) is an n-dimensional non-linear term;

[0065]

[0066] are all positive definite matrices; The parameter θ l satisfies D l and are both prior matrices; is the coefficient matrix of the non-linear term; U1 is the matrix that satisfies the non-linear term; represents the Kronecker product; M f represents the internal coupling matrix; the * in the matrix represents the transpose of the symmetric position; c is the coupling strength; A, E, and G are all constant matrices, G = [g ij N×N , N represents the set of positive integers; v is a constant;

[0067]

[0068] U1 and U2 are both positive definite matrices; g1 and G2 are prior matrices.

[0069] The expression of the controller is:

[0070] ​

[0071] where represents the i-th input variable of the actuator containing saturation at time t; x i (t) is the i-th state variable of the system at time t, i.e., the object to be updated; F 1,n is the n-th non-attack time period; F 2,n is the n-th attack time period; f(t, x i (t)) represents the non-linear term; x j (t) represents the j-th state variable of the system at time t; B f is a constant matrix.

[0072] The expression of the event-triggering mechanism in step S3 is:

[0073]

[0074] where is the triggering time of the k-th trigger and the n-th attack; represents the d-th time period between the k-th trigger and the (k + 1)-th trigger; represents the next triggering time; represents the transpose of the error matrix between the current system state and the system state at the previous moment; represents the error matrix between the current system state and the system state at the previous moment; δ(t) is the triggering threshold; represents that the time point is when the system parameter matrix; F 1,n-1 represents the (n - 1)-th non-attack time period; h n is the start time of the n-th attack; represents in the case.

[0075] In the specific implementation process, the existing technical means for observing attacks are very mature and are not the focus of this method. The focus of this method is to resist attacks and minimize the impact of attacks on the system.

[0076] In an embodiment of the present invention, the framework of the adaptive event-triggered control scheme under a denial-of-service attack is as Figure 2 shown. Assuming that an attacker attacks the network, the actuator in the system will be correspondingly affected. This effect will spread to the complex coupled network and be detected by the sensor, and then be adaptively event-triggered by this method to obtain the corresponding triggering moment and input it into the controller to update the controller parameters, cancel the impact of the current attack, and complete the resistance to the current DoS attack.

[0077] This embodiment uses rand to generate a random aperiodic DoS attack sequence. Considering within the system, the DoS attack shown in Figure 7 is obtained. In this embodiment, matrix A, matrix E, matrix G, matrix M f , matrix B f and matrix G2 are respectively:

[0078]

[0079] The value of the coupling strength c is 9; matrix G1 is a matrix with all element values being 0; The value of is 0.01; the value of v is 5.

[0080] Based on the above parameters, by using the matlab linear matrix inequality toolbox LMI to solve the linear matrix inequalities Ψ1 < 0 and Ψ2 < 0, the matrix F2 and the triggering matrix W can be obtained. Substitute the matrix F2 into the controller, and use ode45 in matlab to solve the system state x i (t), where i represents the node, i = 1, 2, 3, corresponding respectively to Figure 3 , Figure 4 and Figure 5 .

[0081] The matrix F2, the auxiliary gain matrix H and the triggering matrix W are respectively:

[0082]

[0083] The matrix W is the corresponding triggering matrix. Substitute it into the triggering mechanism. When solving the value of the system state x i (t) at each moment, judge whether to trigger. If the triggering condition is met, then the controller is updated to obtain Figure 6 . It can be seen from Figures 3 to 5 that the controller designed by this method only controls the system at the colored time points, greatly saving channel resources. Considering the Figure 7 existence of aperiodic DoS attacks, the robust practical stability of the system can still be achieved.

[0084] In summary, the present invention considers factors that can affect the system performance, such as uncertain nonlinearity, network time delay, aperiodic network attacks, actuator saturation, and actuator errors. This method can achieve robust practical stability under the condition of poor physical state of the system and has more extensive practical applications.

Claims

1. A method for resisting cyberattacks considering robust practical stability, characterized in that, It includes the following steps: S1. Construct a Lyapunov function; obtain the control gain by taking the derivative of the Lyapunov function K , the auxiliary gain matrix H and the triggering matrix W , and construct a controller based on the control gain K and the auxiliary gain matrix H; S2. Determine whether there is a current network attack. If so, go to step S3; Otherwise, go to step S5; S3. Construct an event-triggering mechanism based on the error between the current system state and the system state at the previous moment, the triggering matrix, and the system state that triggered the attack resistance last time; S4. Determine whether it is in the attack interval. If it is in the attack interval, immediately obtain the triggering moment through the event-triggering mechanism at the end of the attack, and substitute the triggering moment into the controller to update the controller parameters, offset the impact of the current attack, complete the resistance to the current DoS attack, and go to step S5; Otherwise, go to step S6; S5. Determine whether to continue the network attack resistance. If so, return to step S1; Otherwise, end; S6. Determine whether the error between the current system state and the system state at the previous moment satisfies the given condition. If so, obtain the triggering moment through the event-triggering mechanism, and substitute the triggering moment into the controller to update the controller parameters, and return to step S5; Otherwise, directly go to step S5; The expression of the Lyapunov function is: where represents the Lyapunov function at time t ; represents t the system state at time ; s represents the system state at time t ; t is a value - taking function. If the current time is a non - attack time, its value is 1. If the current time e is an attack time, its value is 2; , and are all positive definite matrices; represents time; the superscript T represents the transpose of a matrix; represents taking the first - order derivative of the transpose of ; represents taking the first - order derivative of ; and are both integral elements; when takes the value of 1, is 0.16, and when takes the value of 2, is 0.1; The specific method for obtaining the control gain K, the auxiliary gain matrix H, and the triggering matrix W by taking the derivative of the Lyapunov function is: Take the derivative of the Lyapunov function: Solve by Matlab , obtain the control gain and the trigger matrix W ; where represents the derivative of the Lyapunov function without attacks; represents the derivative of the Lyapunov function with attacks; , , represents the time of the k -th trigger, is n a state matrix of dimension representing the k -th trigger and the n -th attack's piecewise error; is a state matrix including the adopted period; is n a non - linear term of dimension 2. The network attack resistance method considering robust practical stability according to claim 1, characterized in that ; , , are all positive definite matrices; , the parameter satisfies ; and are both prior matrices; is the coefficient matrix of the non - linear term; is the matrix that satisfies the non - linear term; represents the Kronecker inner product; represents the internal coupling matrix; * in the matrix represents the transpose of the symmetric position; is the coupling strength; A, E, and G are all constant matrices, , N represents the set of positive integers; v is a constant; , , , are all positive definite matrices; and are prior matrices.

3. The network attack resistance method considering robust practical stability according to claim 2, characterized in that The expression of the controller is: Among them denotes t the i -th input variable of the actuator containing saturation at time is t the i -th state variable of the system at time , i.e., the object to be updated; is the n -th non - attack time period; is the n -th attack time period; denotes the non - linear term; denotes t the j -th state variable of the system at time ; is a constant matrix.

4. The network attack resistance method considering robust practical stability according to claim 2, characterized in that The expression of the event-triggering mechanism in step S3 is: Among them is the k th trigger, the n th attack trigger time; Indicates the k th trigger and the k +1th trigger between the d th time period; Indicates the next trigger time; Indicates the transpose of the error matrix between the current system state and the previous system state; Indicates the error matrix between the current system state and the previous system state; Is the trigger threshold; Indicates that the time point is when the system parameter matrix; Indicates the n -1 non-attack time period; Is the n th attack start time; Indicates In the case.

5. The network attack resistance method considering robust practical stability according to claim 3, characterized in that Matrix A, matrix E, matrix G, matrix , matrix and matrix are respectively: Coupling strength c has a value of 9; the matrix is a matrix with all element values being 0; has a value of 0.01; v has a value of 5.

6. The method for resisting cyberattacks considering robust practical stability according to claim 5, characterized in that, Matrix , auxiliary gain matrix H and trigger matrix W are respectively: 。