A network space key terrain identification method

By constructing a hierarchical analysis model of cyberspace key terrain and a hierarchical analysis model of network attack tasks, and combining the fuzzy hierarchical analysis method and the ideal solution sorting method, the problems of node multi-attribute correlation and attack task influence in cyberspace key terrain identification are solved, achieving higher identification accuracy.

CN119135357BActive Publication Date: 2025-10-17Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310657095.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-05
Publication Date
2025-10-17
Estimated Expiration
2043-06-05

AI Technical Summary

Technical Problem

Existing methods for identifying critical terrain in cyberspace ignore the correlation between multiple node attributes and the impact of cyber attack tasks, resulting in low identification accuracy.

Method used

The fuzzy hierarchical analysis method is used to construct a hierarchical analysis model of cyberspace key terrain and a hierarchical analysis model of cyber attack tasks. By determining the weights of cyber attack tasks and the weighted value matrix, combined with the ideal solution sorting method, the key terrain of cyberspace is identified.

Benefits of technology

The accuracy of identifying key terrain in cyberspace has been improved, the impact of cyber attack tasks on nodes has been taken into account, and the accuracy of identification has been enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119135357B_ABST
    Figure CN119135357B_ABST
Patent Text Reader

Abstract

The application relates to a network space key terrain identification method and belongs to the technical field of network space surveying and mapping. The application constructs a network space key terrain analytic hierarchy model and a network attack task analytic hierarchy model based on a fuzzy analytic hierarchy process; the weight of a network attack task is determined according to the network attack task analytic hierarchy model, and a weighted value matrix is determined according to the network space key terrain analytic hierarchy model; then, the obtained weighted value matrix is calculated through an ideal solution sequencing method, the closest value of each node in the network space is obtained and sequenced, the weight of the network attack task is multiplied by the closeness of each network node, the closeness of each network node under different attack tasks is determined, and the network space key terrain is identified. The application considers the influence of network attacks, determines the key node through the network attack task weight, closely connects the network attack task and the network space key terrain, and improves the identification precision.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to a network space key terrain identification method and belongs to the technical field of network space mapping. BACKGROUND

[0002] As the fifth dimension of human activities, network space breaks the time and space boundaries of traditional space and builds a new activity field for human beings. However, the universal vulnerability of network space also brings more and more serious security risks to enterprises and countries.

[0003] As a new theory and technology field derived from the cross of mapping and network, network space mapping has great significance in ensuring national network security. Network space mapping is an effective means of detecting network space resources and mining and applying network space big data. How to describe the structure and hierarchical information of network space, identify and locate the weak links of network space, and improve the network space situation awareness and defense capability has become an important research content in the field of network space mapping.

[0004] Since Willian Gibson proposed the term of network space, it has been widely used by scholars to express various scenarios related to computer technology and network globalization. Network space is divided into broad network space and narrow network space. The narrow network space simply refers to the Internet space that human beings can enter by means of computers or mobile devices. The broad network space contains various information technology infrastructure networks, virtual environments and human influences. The concept of terrain comes from the field of geography, which refers to the total of various undulating forms on the earth's surface. Scholars introduce the concept of "terrain" into network space when studying network space to describe the hierarchical structure of network space. David Raymond defines network space terrain as systems, devices, protocols, data, software, processes, network roles and other networks of entities that constitute, supervise and control network space. He divides network space terrain into supervision layer, network role layer, logic layer, physical layer and geographic layer, and believes that network space terrain is not always directly connected with physical location. Jakobson defines network terrain as network assets and services and their internal and interdependent multi-level information structure, which contains three aspects of hardware, software and service sub-terrain. Jakobson's definition of network terrain belongs to the physical layer and logic layer of broad network space, which can also be called asset layer network space.

[0005] The classical definition of critical terrain is "to seize or hold any position or area that offers a significant advantage to either side's combatants." Similar to the geographical high ground, cyber critical terrain is used to describe the cyber connections and nodes that are vital to both friendly and enemy forces, which are usually perceived in the form of network IP. Cyber critical terrain has important strategic significance. For the attacking side, cyber critical terrain is essential intelligence information for developing network attack plans; for the defending side, cyber critical terrain is key information for improving network space situational awareness and reducing network space threat risk.

[0006] The current network critical terrain identification method not only ignores the correlation between the multiple attributes of each node in the network space, but also does not pay attention to the influence of the network attack task on the network critical terrain, resulting in that the identified network critical terrain is not accurate enough, and then affecting the subsequent network security processing. SUMMARY

[0007] The purpose of the present application is to provide a network critical terrain identification method to solve the problem that the current identification method ignores the correlation between the multiple attributes of each node and the network attack task leads to low identification accuracy.

[0008] The present application provides a network critical terrain identification method to solve the above technical problems, which comprises the following steps:

[0009] 1) Obtain the attribute information of each network node in the network space, wherein the attribute information includes the characteristic attributes of the physical layer network space terrain and the network information security attributes;

[0010] 2) According to the obtained physical layer network network information security attributes, a fuzzy analytic hierarchy process is used to construct a network attack task analytic hierarchy model, and the network attack task weight is determined; the constructed network attack task analytic hierarchy model includes a target layer, a criterion layer and an alternative scheme layer, the target layer is used to describe the network critical terrain, the criterion layer is the network information security attribute for describing information transmission, and the alternative scheme layer is the network attack task determined based on each item of the ATT&CK framework;

[0011] 3) According to the obtained characteristic attributes of the physical layer network space terrain, a fuzzy analytic hierarchy process is used to construct a network critical terrain analytic hierarchy model, and the corresponding weighted value matrix is determined; the constructed network critical terrain analytic hierarchy model includes a target layer, a criterion layer and an alternative scheme layer, the target layer is used to describe the network critical terrain, the criterion layer is used to describe the characteristic attributes of the asset layer network space terrain, and the alternative scheme layer is used to describe the connection nodes in the network space;

[0012] 4) The weighted value matrix is calculated by the ideal solution ordering method, the closest value of each node in the network space is obtained and sorted, the weight of the network attack task is multiplied by the closeness of each network node, the closeness of each network node under different attack tasks is determined, and the network space key terrain is identified.

[0013] The application constructs a network space key terrain analytic hierarchy model and a network attack task analytic hierarchy model based on the fuzzy analytic hierarchy method; the weight of the network attack task is determined according to the network attack task analytic hierarchy model, and the weighted value matrix is determined according to the network space key terrain analytic hierarchy model; then the weighted value matrix is calculated by the ideal solution ordering method, the closest value of each node in the network space is obtained and sorted, the weight of the network attack task is multiplied by the closeness of each network node, the closeness of each network node under different attack tasks is determined, and the network space key terrain is identified. The application considers the influence of network attack, determines the key node through the network attack task weight, closely connects the network attack task and the network space key terrain, and improves the identification accuracy.

[0014] Further, the network attack task weight determination process is as follows:

[0015] The evaluation value of each network information security attribute in the criterion layer is obtained to obtain a fuzzy matrix of the network attack task, and the obtained fuzzy matrix is adjusted for consistency to obtain a consistent fuzzy matrix of the network attack task;

[0016] Each network information security attribute in the criterion layer is compared with each other to obtain the weight of the consistent fuzzy matrix of the network attack task, and the weight is the network attack task weight.

[0017] The application uses experts familiar with the network space and having network attack experience to evaluate each network information security attribute in the criterion layer of the analytic hierarchy model, thereby establishing the fuzzy matrix of the network attack task; each network information security attribute in the criterion layer is compared with each other to obtain the weight of the consistent fuzzy matrix of the network attack task. The network attack task weight determined by the evaluation result of the experts can accurately represent the influence of the network attack task on the node.

[0018] Further, the network attack task weight determination process is as follows:

[0019] The evaluation value of each physical layer network space terrain feature attribute in the criterion layer of the network space key terrain analytic hierarchy model is obtained to obtain a fuzzy matrix of the network space key terrain, and the obtained fuzzy matrix is adjusted for consistency to obtain a consistent fuzzy matrix of the network space key terrain;

[0020] The network space key terrain consistency fuzzy matrix of the network space key terrain is obtained by comparing the network space key terrain feature attributes in the criterion layer of the analytic hierarchy model with each other.

[0021] The network space key terrain consistency fuzzy matrix is multiplied by the corresponding weight, and the result is the weighted value matrix.

[0022] The application uses experts familiar with network space to evaluate the network space key terrain feature attributes in the criterion layer of the analytic hierarchy model, so as to establish the fuzzy matrix of the network space key terrain; the weight of the network space key terrain consistency fuzzy matrix is obtained by comparing the network space key terrain feature attributes in the criterion layer with each other. The weighted value matrix determined by the evaluation result of the experts can accurately represent the influence of the network space key terrain feature attributes on the node.

[0023] Further, the ideal solution sorting method in step 4) is realized by using the TOPSIS algorithm corrected by the cosine similarity.

[0024] Further, the implementation process of the ideal solution sorting method is as follows:

[0025] The corresponding positive ideal solution and negative ideal solution are obtained from the weighted value matrix;

[0026] The distance of each network asset to the positive ideal solution and the negative ideal solution is calculated according to the vector cosine distance algorithm;

[0027] The closeness between each alternative solution and the ideal solution is determined according to the distance of the network asset to the positive ideal solution and the negative ideal solution, and the smaller the closeness is, the farther the alternative solution is from the ideal solution.

[0028] The cosine angle calculation in the vector space is converted from the Euclidean distance calculation in the traditional TOPSIS algorithm, so that the correlation between the network assets can be reduced.

[0029] Further, when calculating the distance of each network asset to the positive ideal solution and the negative ideal solution, the average of each index to the positive ideal solution and the negative ideal solution is calculated first, and then the network asset is subtracted by the average.

[0030] Further, the calculation formula of the distance of each network asset to the positive ideal solution and the negative ideal solution is as follows:

[0031]

[0032]

[0033] d(A i ,C + ), d(A i ,C -respectively are the distances of the network assets to the positive ideal solution and the negative ideal solution, v i is the ith network asset, c avg is the average number, c + is the positive ideal solution, c - is the negative ideal solution.

[0034] The present application amplifies the gap between each scheme and improves the identification accuracy by calculating the average number of each index to the positive and negative ideal solutions and subtracting the average number in all dimensions when calculating the distance of each network asset to the positive ideal solution and the negative ideal solution respectively.

[0035] Further, the network attack task is a combination of one or more tactics in the three major tactics in the ATT&CK framework.

[0036] The present application classifies the tactics in the ATT&CK framework, takes each category or combination of categories as a network attack task, and considers various possible situations during the attack.

[0037] Further, the network information security attributes include confidentiality, integrity, availability, controllability and non-repudiation; and the feature attributes of the physical layer network space terrain include components, hardware devices, ports, network protocols and operating systems. BRIEF DESCRIPTION OF DRAWINGS

[0038] Figure 1 is the technical roadmap of the network space key terrain identification method of the present application;

[0039] Figure 2 is the asset layer network space key terrain analytic hierarchy model structure diagram constructed by the present application;

[0040] Figure 3 is a schematic diagram of the tactics of the ATT&CK tactic framework;

[0041] Figure 4 is a classification diagram of the tactics of the ATT&CK tactic framework according to the present application;

[0042] Figure 5 is a schematic diagram of the network attack tasks that a hacker may formulate;

[0043] Figure 6 is a schematic diagram of the fuzzy judgment degree of the evaluation index used in the present application;

[0044] Figure 7 is a schematic diagram of the feature attributes of the physical layer network space terrain of the node;

[0045] Figure 8 is the distribution of each node in the embodiment of the present application;

[0046] Figure 9 is the correlation of each attribute in the network space key terrain hierarchical analysis model;

[0047] Figure 10 is the asset layer network space key terrain identified by the present application and the TIOSIS method, the TOPSIS improved by the Mahalanobis distance and the network system vulnerability value method based on CVSS3.1 in the experimental process;

[0048] Figure 11 is the correlation of the present application and the TIOSIS method and the TOPSIS improved by the Mahalanobis distance in the experimental process;

[0049] Figure 12 is the distance between the results obtained by the present application and the TIOSIS method and the TOPSIS improved by the Mahalanobis distance and the system vulnerability value;

[0050] Figure 13 is the root mean square error between the results obtained by the present application and the TIOSIS method, the TOPSIS improved by the Mahalanobis distance and the network system vulnerability value method based on CVSS3.1 and the system vulnerability value;

[0051] Figure 14 is the closeness of each node in the six different attack tasks in the embodiment of the present application;

[0052] Figure 15 is the ranking of network nodes under different tasks in the embodiment of the present application. DETAILED DESCRIPTION

[0053] The specific embodiments of the present application will be further described below in combination with the drawings.

[0054] The present application introduces network attack tasks from the perspective of hackers, analyzes the influence of network attack tasks on the identification of network space key terrain, and proposes a network space key terrain identification method. The method constructs a network space key terrain hierarchical analysis model and a network attack task hierarchical analysis model based on a fuzzy hierarchical analysis method. According to the network attack task hierarchical analysis model, the weight of the network attack task is determined, and according to the network space key terrain hierarchical analysis model, the weighted value matrix is determined. Then the ideal solution sorting method is used to calculate the weighted value matrix, and the most close value of each node in the network space is obtained and sorted. The weight of the network attack task is multiplied by the closeness of each network node to determine the closeness of each network node under different attack tasks, so as to identify the network space key terrain. The implementation route of the method is shown in Figure 1 , which will be described in detail below.

[0055] The application uses fuzzy analytic hierarchy process to construct a network attack task analytic hierarchy model and an asset layer network space key terrain analytic hierarchy model. The asset layer network space key terrain (KCT) analytic hierarchy model constructed is shown in Figure 2 , the first layer is a target layer, i.e. network space key terrain; the second layer is a criterion layer, which is a characteristic attribute of the asset layer network space terrain, and the characteristic attribute includes components, hardware devices, ports, network protocols, and operating systems, which are represented by F l , and l represents [1, k]; the third layer is an alternative solution layer, which refers to a connected node in the network space, and the node is represented by IP, which is represented by A m , and m represents [1, n]. The network attack task analytic hierarchy model and the asset layer network space key terrain analytic hierarchy model constructed are similar, and also include three layers, and the target layer is also network space key terrain, and the difference lies in that the criterion layer is a network information security attribute for describing information transmission, and the alternative solution layer is a network attack task determined based on the ATT&CK framework.

[0056] ATT&CK (Adversarial Tactics, Techeiques And Common Knowledge Tactics Framework) is a framework for describing network attack paths proposed by MITRE, an organization established by the Massachusetts Institute of Technology Computer Laboratory, from the perspective of attackers. The framework includes tactics (14 items) and techniques (177 items, 348 sub-techniques) used in each stage of network attacks, and the tactical composition is shown in Figure 3 .

[0057] A network attack task should describe the attack effect achieved by using network attack means instead of describing the task purpose of the network system. The ATT&CK framework is a very mature network attack technology classification framework, which divides the tactics into 14 items, but hackers do not use all the 14 tactics at the same time when performing network attacks. A network attack task includes multiple tactics and combinations thereof, and therefore, the 14 tactics in the ATT&CK framework need to be reclassified.

[0058] The application divides the 14 tactics into three categories based on the influence of network attacks, which are resource construction, environment building, and environment destruction, as shown in Figure 4The resource construction task contains three tactics of reconnaissance, resource development and collection, refers to obtaining the information and resources of the attacked party; the environment building contains six tactics of initial access, persistence, privilege escalation, defense bypass, credential acquisition and discovery, refers to figuring out the opponent network environment, obtaining system privileges and hiding identity; the destruction contains five tactics of execution, lateral movement, command control, data exfiltration and influence, refers to outputting the data in the opponent network or destroying the opponent network environment. One network attack task is a combination of one or more tactics in the three categories, and the hacker can formulate six network attack tasks as shown in the following table: Figure 5

[0059] The application of fuzzy analytic hierarchy process must construct the criterion layer, which is the criterion for experts or expert systems to evaluate the alternative scheme. In constructing the analytic hierarchy process model of network attack task, the present application adopts the network information security attributes proposed by the U.S. Cybersecurity and Infrastructure Agency (CISA) to construct the criterion layer, that is, confidentiality, integrity, availability, controllability and non-repudiation are taken as five attributes of network attack task to construct the fuzzy consistency judgment matrix. Confidentiality refers to that the information in the network is not obtained and used by unauthorized entities; integrity refers to the characteristic that the information is not modified, damaged and lost during storage or transmission; availability refers to the ability of authorized entities or users to access and use information as required; controllability refers to the ability of information to be effectively controlled by legal users; and non-repudiation refers to the authenticity of information exchange between two parties.

[0060] In constructing the analytic hierarchy process model of network space key terrain, the present application takes the components, hardware devices, ports, network protocols and operating systems of IP as the characteristic attributes of the physical layer network space terrain and constructs the criterion layer accordingly, as shown in the following table: Figure 7

[0061] The fuzzy analytic hierarchy process, like the analytic hierarchy process, allows "all important tangible and intangible, quantitative and qualitative factors" to be included and measured. The present application uses experts familiar with network space and having network attack experience to evaluate the criterion layer F l of the analytic hierarchy process model, and the fuzzy judgment scale of the evaluation index is shown in the following table: Figure 6 The fuzzy matrix for the network space terrain constituting the asset layer is as follows:​​

[0062]

[0063]

[0064] where i = (1, 2, …, n), j = (1, 2, …, m), represents the kth expert's judgment on network asset A i the evaluation value of the criterion layer, and has the following properties:

[0065] 1) r ii = 0.5

[0066] 2) r ij = 1 - r ji

[0067] 3) r ij = r it - r jt , t = (1, 2, …, n)

[0068] The fuzzy matrix is adjusted for consistency, and the row with the highest credibility is selected from the fuzzy matrix to judge r 11 , r 12 , …, r 1m . The row is subtracted from each row in the matrix , and if the n differences are all constants, no adjustment is needed, otherwise the adjusted row is adjusted so that the n differences are constants, and the adjusted fuzzy consistency matrix is R.

[0069] The construction process of the network attack task fuzzy consistency judgment matrix is similar to the network space terrain of the asset layer. The weights of the fuzzy consistency matrix R obtained by pairwise comparison of the network information security attributes related to information transmission of the network attack task are represented by W α1 , …, W αk , where W αk is the weight of the network information security attribute F l that affects information transmission. The characteristic attributes of the asset layer network space terrain are weighted by W β1 , …, W βk , which can be calculated by the fuzzy analytic hierarchy process, as shown in Figure 9 .

[0070] Based on the fuzzy consistency matrix, the fuzzy weights can be calculated using the geometric mean method, and the formula is as follows:

[0071] W αi = r i × (r1+ r2+ …+ r n ) -1

[0072]

[0073] where i,j = 1,2, …, n. The weight of the characteristic attribute of the asset layer network space terrain W βk The same method can be used to obtain.

[0074] By the adjusted fuzzy consistency matrix R and the weight of the characteristic attribute of the asset layer network space terrain W βk Multiplying, the weighted value matrix V can be obtained, as shown in the following formula:

[0075]

[0076] The positive ideal solution is the set of the highest scoring elements in the weighted value matrix V, The negative ideal solution is the set of the lowest scoring elements in the weighted value matrix V,

[0077]

[0078]

[0079] The TOPSIS algorithm based on the cosine similarity correction converts the Euclidean distance calculation in the traditional TOPSIS algorithm into the calculation of the cosine angle in the vector space, which can reduce the correlation between network assets.

[0080] First, in the n-dimensional vector space, the cosine value of the angle between vectors and is calculated as shown in the following formula:

[0081]

[0082] Then, the base is 0.5, and the power is the logarithmic function of the cosine function. The composite function is a decreasing function in its domain, and its meaning is that the greater the similarity, the smaller the distance. The composite function is used to calculate the formula of each network asset A i to the positive and negative ideal solutions as follows:

[0083] A i to the positive ideal solution:

[0084]

[0085] A i to the negative ideal solution:

[0086]

[0087] Finally, the average of each index to the positive and negative ideal solution is calculated, and the average is subtracted in all dimensions to enlarge the gap between each scheme, the formula is as follows:

[0088]

[0089]

[0090] The closeness degree between each alternative and the ideal solution is represented by closeness degree f i , the smaller the closeness degree is, the farther the alternative is from the ideal solution, the formula is as follows:

[0091]

[0092] The network attack task weight is represented by W α1 ,…,W αk , the closeness degree can be represented as f1,…,f i , then the asset layer network key terrain can be represented as:

[0093]

[0094] The matrix represents the closeness degree of each node under different tasks, and the key terrain is determined by comparing the closeness degree of each node under different tasks (the number of tactics constituting the task is the same, but the tactics are different). The one with the highest closeness degree is considered as the key terrain.

[0095] The properties of the network nodes detected by the network space engine are often positively correlated with the vulnerabilities in the node, that is, the more assets, the more vulnerabilities. Therefore, when constructing the criterion layer, multiple properties are positively correlated with vulnerabilities.

[0096] The present application starts from the methodology of system science "criticality is equivalent to destructiveness", and considers that the indexes in the criterion layer are positively correlated with the vulnerability of the network system, and the network system vulnerability value is used as the experimental control group to evaluate the effectiveness of CosS-TOPSIS.

[0097] The Common Vulnerability Scoring System (CVSS) is an open standard for describing the characteristics and severity of vulnerabilities. The CVSS vulnerability scoring system focuses on the properties of the vulnerability itself, and can accurately evaluate the vulnerability value of a single asset. However, the present application focuses on the nodes (IP) in the cyberspace, which may contain multiple network devices and software and hardware, and there are t vulnerabilities. Therefore, the present application uses the cumulative method to determine the vulnerability value of the IP, that is, the vulnerability scores of multiple devices under a certain IP are added as the vulnerability value of the IP. Assuming that n devices under a certain IP detect t device vulnerabilities, the vulnerability score is M i , then the vulnerability value of the IP is:

[0098]

[0099] The vulnerability can be obtained by a network space mapping tool such as ZoomEye, and the vulnerability value is evaluated by a CVSS3.1 vulnerability scoring system. The vulnerability value is a method for evaluating the vulnerability of a network node. At present, there are few network space key terrain identification algorithms, and there is a lack of comparative experiments, and it is difficult to analyze the reliability. Therefore, the present application takes the vulnerability value as the control group (true value) to analyze the difference and superiority of the present application and other methods.

[0100] The correlation of each attribute in the network space key terrain analytic hierarchy model is as shown in Figure 9 It can be seen from the figure that the vulnerability value has a high correlation with components, hardware devices, ports and network protocols; and has a low correlation with operating systems. The hardware devices, ports, network protocols and components also have a high correlation. Therefore, the correlation between the attributes must be considered when identifying the network space key terrain.

[0101] Experimental verification

[0102] In order to better illustrate the effect of the present application, the method of the present application is applied to identify the asset layer network space key terrain of a certain power secondary information system, and the asset layer network space key terrain identified by the existing TIOSIS method, the MD-TOPSIS method and the network system vulnerability value method based on CVSS3.1 are compared, and the results are as shown in Figure 10 .

[0103] Figure 8 The nodes in this example are as shown in the table, and the network nodes ranking at the top in the network space are considered as the asset layer network space key terrain, and it can be seen from Figure 9 that the network nodes IP ranking at the top four in the network space key terrain of the power secondary information system identified by the present application (CosS-TOPSIS) are A13, A18, A10 and A8; the network nodes IP ranking at the top four in the network space key terrain identified by the TIOSIS method are A20, A8, A10 and A18; and the network nodes IP ranking at the top four in the network space key terrain identified by the MD-TOPSIS method are A13, A3, A18 and A20.

[0104] Spearman's rank correlation coefficient is a commonly used method for measuring the correlation between ranked and ordered variables. The ideal solution sorting and the improved ideal solution sorting both need to calculate the closest value, and therefore it is appropriate to calculate the correlation between each method and the network system vulnerability value by using Spearman's rank correlation coefficient. The higher the correlation coefficient between each method and the network system vulnerability value calculated based on CVSS3.1 is, the better the effect of the method is.

[0105] Although the ideal solution ranking method improved by Mahalanobis distance can also reduce the similarity between multiple attributes, the Mahalanobis distance will amplify the impact of irrelevant attributes on the results. Figure 11 As shown, the present invention has a high correlation with the Mahalanobis distance improved ideal solution sorting method, but the present invention has the highest similarity with the network system vulnerability value method, which shows that the accuracy of the present invention in identifying network key terrain is higher than the other two methods.

[0106] Root mean square error (RMSE) and mean absolute error (MAE) are metrics that measure the deviation between observed values ​​and true values. They are widely used in surveying, mapping, and remote sensing. Using the results of ideal solution ranking and improved ideal solution ranking as the observed values ​​and the system vulnerability value as the true value, it is appropriate to use RMSE to assess the accuracy of each method. The lower the RMSE value of each method compared to the system vulnerability value, the higher the accuracy of the method. Figure 12 It is the distance between the results of each method and the system vulnerability value.

[0107] like Figure 13 As shown in the figure, the root mean square error between the present invention and the system vulnerability value is 16% smaller than that of TOPSIS and 22% smaller than that of MD-TOPSIS; the mean absolute error is 20% smaller than that of TOPSIS and 24% smaller than that of MD-TOPSIS, which shows that the correlation between the key terrain of cyberspace identified by the present invention and the system vulnerability value is the strongest, indicating that the method of the present invention is superior to the other two methods.

[0108] The dynamics of cyberspace refers to the continuous addition and exit of network nodes, and the rapid update and disappearance of information, which causes slight or drastic changes in the cyberspace terrain. The present invention expands the dynamics of cyberspace terrain, believing that the dynamics of cyberspace terrain is not only reflected in the addition and disappearance of network nodes, but is also closely related to network attack tasks. The present invention divides the 14 tactics in the ATT&CK framework into three categories. When hackers formulate network attack tasks, they will not use 14 tactics at the same time on the same target, but a combination of tactics in the three categories. Figure 14 As shown in the figure, M1 to M6 are randomly selected as possible tasks to discuss the relationship between network attack tasks and key terrain in cyberspace.

[0109] like Figure 15 As shown, when node A8 executes the network attack task code-named M4, its closeness value is smaller than the closeness value when node A10 executes the network attack task code-named M3. Figure 14 This shows the ranking of network nodes under different tasks. This shows that the network attack task has a decisive influence on the identification of key terrain in cyberspace, and the key terrain in cyberspace will change with the network attack task, that is, the ranking of network nodes under different network attack tasks is different.

Claims

1. A method for identifying key terrain in cyberspace, characterized in that: The identification method includes the following steps: 1) Obtaining attribute information of each network node in the cyberspace, wherein the attribute information includes characteristic attributes of the physical layer cyberspace terrain and network information security attributes; 2) Based on the obtained network information security attributes, a network attack task hierarchical analysis model is constructed using the fuzzy analytic hierarchy process to determine the network attack task weights. The constructed network attack task hierarchical analysis model includes a target layer, a criterion layer, and an alternative solution layer. The target layer is used to describe the key terrain of cyberspace, the criterion layer is used to describe the network information security attributes of information transmission, and the alternative solution layer is the network attack task determined based on the various tactics in the ATT&CK framework. 3) Based on the acquired characteristic attributes of the physical layer cyberspace terrain, a hierarchical analysis model of cyberspace key terrain is constructed using the fuzzy analytic hierarchy process to determine the corresponding weighted value matrix; the constructed hierarchical analysis model of cyberspace key terrain includes a target layer, a criterion layer, and an alternative solution layer. The target layer is used to describe the cyberspace key terrain, the criterion layer is used to describe the characteristic attributes of the asset layer cyberspace terrain, and the alternative solution layer is used to describe the connection nodes in the cyberspace; 4) The obtained weighted value matrix is ​​calculated using the ideal solution sorting method to obtain the closest value of each node in the cyberspace and sort them. The weight of the network attack task is multiplied by the proximity of each network node to determine the proximity of each network node under different attack tasks, thereby identifying the key terrain of the cyberspace.

2. The method for identifying key terrain in cyberspace according to claim 1, characterized in that: The process of determining the network attack task weight is as follows: Obtaining the evaluation value of each network information security attribute in the criterion layer to obtain the fuzzy matrix of the network attack task, and performing consistency adjustment on the obtained fuzzy matrix to obtain the consistent fuzzy matrix of the network attack task; The network information security attributes in the criterion layer are compared pairwise to obtain the weight of the network attack task consistency fuzzy matrix, which is the network attack task weight.

3. The method for identifying key terrain in cyberspace according to claim 1, characterized in that: The process of determining the weighted value matrix is ​​as follows: Obtaining evaluation values ​​of cyberspace terrain characteristic attributes of each physical layer in the criterion layer of the cyberspace key terrain hierarchical analysis model to obtain a fuzzy matrix of the cyberspace key terrain, and performing consistency adjustment on the obtained fuzzy matrix to obtain a consistent fuzzy matrix of the cyberspace key terrain; The cyberspace terrain feature attributes of each physical layer in the criterion layer are compared pairwise to obtain the weights of the cyberspace key terrain consistency fuzzy matrix; The obtained consistency fuzzy matrix of the key terrain in cyberspace is multiplied by the corresponding weights, and the result is the weighted value matrix.

4. The method for identifying key cyberspace terrain according to claim 3, characterized in that: The ideal solution ranking method in step 4) is implemented by using the TOPSIS algorithm corrected by cosine similarity.

5. The method for identifying key terrain in cyberspace according to claim 4, characterized in that: The implementation process of the ideal solution sorting method is as follows: the corresponding positive and negative ideal solutions obtained from the weighted value matrix; Calculate the distance of each network asset to the positive ideal solution and the negative ideal solution respectively using the vector cosine distance algorithm; The closeness between each alternative solution and the ideal solution is determined based on the distance from the network assets to the positive ideal solution and the negative ideal solution. The smaller the closeness, the farther the alternative solution is from the ideal solution.

6. The method for identifying key terrain in cyberspace according to claim 5, characterized in that: When calculating the distances of each network asset to the positive ideal solution and the negative ideal solution, the average of each indicator to the positive and negative ideal solutions is first calculated, and then the average is subtracted from the network asset.

7. The method for identifying key terrain in cyberspace according to claim 6, characterized in that: The calculation formula used for the distance between each network asset and the positive ideal solution and the negative ideal solution is: Where d(A i ,C + )、d(A i ,C - ) are the distances from network assets to positive ideal solutions and negative ideal solutions, respectively, v i is the i-th network asset, c avg is the average, c + is a positive ideal solution, c - is a negative ideal solution.

8. The method for identifying key terrain in cyberspace according to claim 1, characterized in that: The network attack task is a combination of one or more tactics from the three major categories of tactics in the ATT&CK framework.

9. The method for identifying key terrain in cyberspace according to any one of claims 1 to 8, characterized in that: The network information security attributes include confidentiality, integrity, availability, controllability and non-repudiation; the characteristic attributes of the physical layer cyberspace terrain include components, hardware devices, ports, network protocols and operating systems.

Citation Information

Patent Citations

  • Multi-channel Internet of Things routing method based on fuzzy analytic hierarchy process

    CN114567917A

  • Spatially aware wireless network

    US20160191120A1