Method, device, equipment, medium and product for quantifying heterogeneity of executive bodies based on Bayesian network
By constructing a Bayesian network attack graph and quantifying the heterogeneity between executors, the problem of insufficient quantification in existing technologies is solved, and the security and stability of the mimicry defense system are improved.
Patent Information
- Application Number
- CN202411375451.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-09-29
AI Technical Summary
Existing technologies make it difficult to accurately quantify the heterogeneity between executors, especially in small-scale redundant systems. The lack of measurement of the environment in which the executors are located leads to insufficient security and stability of the mimicry defense system.
By constructing an attack graph based on a Bayesian network and utilizing the test vector probability and directed edge probability of the initial node, the conditional probability of the executor under the parent node set is determined. Combined with the reachability probability of the minimum action unit, the heterogeneity between executors is quantified.
More accurately measure the characteristics and differences of executors in different environments, and improve the security and stability of the mimicry defense system.
Smart Images

Figure CN119232468B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of mimicry defense security technology, and in particular to a method, device, equipment, medium and product for quantifying the heterogeneity of an executive body based on a Bayesian network. Background Art
[0002] In today's cybersecurity field, mimetic defense is a cutting-edge research hotspot. Its core concept is the architecture of heterogeneous, redundant systems. Introducing heterogeneity and redundancy enhances the system's ability to withstand various attacks. However, quantitatively assessing heterogeneity is a critical and challenging task. Effectively quantifying the heterogeneity between executors is a pressing issue.
[0003] Existing technologies primarily quantify the diversity of actuator characteristics, performance indicators, and various behavioral patterns related to mimicry defense by quantifying actuator similarity and complexity. However, this quantitative assessment method suffers from limitations in dimensionality and low accuracy of relational attributes, leading to limitations. Furthermore, clustering algorithms, which quantify differences and similarities, are only applicable to large-scale data sets and cannot quantify the heterogeneity of redundant systems with a small number of actuators. While quantifying heterogeneity through complexity and differences is somewhat versatile and applicable to heterogeneous redundant systems, it only considers the differences between the actuators themselves and lacks a measure of the environment in which the actuators operate. Summary of the Invention
[0004] In view of this, the present invention provides a method, device, equipment, medium and product for quantifying the heterogeneity of executors based on a Bayesian network, which can measure the heterogeneity between executors through probability, more accurately reflect the characteristics and differences of executors under different test vectors, and significantly increase the security and stability of the mimicry defense system.
[0005] According to one aspect of the present invention, an embodiment of the present invention provides a method for quantifying the heterogeneity of an executable body based on a Bayesian network, the method comprising:
[0006] A Bayesian network attack graph is constructed based on the dependency relationships between at least three layers of nodes in the mimicry defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, each of the test vectors represents a type of network attack in the network environment in which the executor is located, and each of the test vectors corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executor; and each node in the third layer of nodes is represented as a minimum action unit corresponding to each of the executors;
[0007] Determining a first conditional probability of the execution body under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and a preset directed edge probability; wherein the preset directed edge probability is the occurrence probability of the test vector breaking the execution body;
[0008] Determine the number of target executables included in the minimum action unit according to a preset scheduling scenario, and group the target executables into a second parent node set corresponding to the minimum action unit;
[0009] Determine, based on the first conditional probability, a second conditional probability of the minimum action unit under the influence of the second parent node set;
[0010] Determining a reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability;
[0011] The degree of heterogeneity between the executables is determined according to the reachability probability.
[0012] According to another aspect of the present invention, an embodiment of the present invention further provides a device for quantifying the heterogeneity of an executable based on a Bayesian network, the device comprising:
[0013] A construction module is used to construct a Bayesian network attack graph based on the dependency relationship between at least three layers of nodes in the mimic defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, each test vector represents a type of network attack in the network environment where the executor is located, and each test vector corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executor; and each node in the third layer of nodes is represented as the minimum action unit corresponding to each executor;
[0014] A first probability determination module is configured to determine a first conditional probability of the executable under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and a preset directed edge probability; wherein the preset directed edge probability is the occurrence probability of the test vector breaking the executable;
[0015] a parent node set determining module, configured to determine the number of target executables contained in the minimum action unit according to a preset scheduling scenario, and group the target executables into a second parent node set corresponding to the minimum action unit;
[0016] A second probability determination module, configured to determine a second conditional probability of the minimum action unit under the influence of the second parent node set based on the first conditional probability;
[0017] a reachability probability determination module, configured to determine the reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability;
[0018] A heterogeneity determination module is used to determine the heterogeneity between the executables according to the reachability probability.
[0019] According to another aspect of the present invention, an embodiment of the present invention further provides an electronic device, comprising:
[0020] at least one processor; and
[0021] a memory communicatively connected to the at least one processor; wherein,
[0022] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the Bayesian network-based execution body heterogeneity quantification method described in any embodiment of the present invention.
[0023] According to another aspect of the present invention, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the Bayesian network-based execution body heterogeneity quantification method described in any embodiment of the present invention when executed.
[0024] According to another aspect of the present invention, an embodiment of the present invention further provides a computer program product, characterized in that the computer program product includes a computer program, and when the computer program is executed by a processor, it implements the Bayesian network-based execution body heterogeneity quantification method described in any embodiment of the present invention.
[0025] The above-mentioned technical solution of the embodiment of the present invention constructs a Bayesian network attack graph through the dependency relationship between at least three layers of nodes, determines the first conditional probability of the executor under the influence of the initial node set based on the probability of the test vector configured by the initial node in the Bayesian network attack graph, and the preset directed edge probability, determines the second conditional probability of the minimum action unit under the influence of the second parent node set through the first conditional probability, and on this basis, determines the reachable probability of the minimum action unit based on the first conditional probability and the second conditional probability, thereby determining the quantitative value of the heterogeneity between each executor according to the reachable probability, and can achieve the heterogeneity between the executors by measuring the probability of network threats in the environment in which the executors are located, more accurately reflecting the characteristics and differences of the executors in different operating environments, and in the field of mimetic scheduling of endogenous security defense, it will be more conducive to increasing the security of the mimetic defense system.
[0026] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0028] Figure 1 A flowchart of a method for quantifying the heterogeneity of an executive body based on a Bayesian network according to an embodiment of the present invention;
[0029] Figure 2 A schematic diagram of a Bayesian network attack graph provided by one embodiment of the present invention;
[0030] Figure 3 A flowchart of another method for quantifying the heterogeneity of an executive body based on a Bayesian network provided in one embodiment of the present invention;
[0031] Figure 4 A schematic diagram of another Bayesian network attack graph provided by one embodiment of the present invention;
[0032] Figure 5 A schematic diagram of another Bayesian network attack graph provided by an embodiment of the present invention;
[0033] Figure 6 A schematic diagram of another Bayesian network attack graph provided by one embodiment of the present invention;
[0034] Figure 7 This is a structural block diagram of a device for quantifying the heterogeneity of an executive body based on a Bayesian network provided by one embodiment of the present invention;
[0035] Figure 8 A schematic structural diagram of an electronic device provided for implementing an embodiment of the present invention. DETAILED DESCRIPTION
[0036] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0037] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0038] In one embodiment, Figure 1 A flowchart of a Bayesian network-based executable heterogeneity quantification method provided in accordance with one embodiment of the present invention is provided. This embodiment is applicable to situations where the heterogeneity of executables is quantified. The method can be performed by a Bayesian network-based executable heterogeneity quantification device, which can be implemented in the form of hardware and / or software.
[0039] like Figure 1 As shown, the method includes:
[0040] S110. Construct a Bayesian network attack graph based on the dependency relationship between at least three layers of nodes in the mimicry defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, and each test vector corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executor; each node in the third layer of nodes is respectively represented as the minimum action unit corresponding to each executor.
[0041] Among them, the Bayesian network attack graph can also be called the attack graph of the Bayesian network. In the attack graph of the Bayesian network, the initial node is assigned a probability value, and the directed edges represent the causal relationship between the nodes. According to the probability value of the initial node and the causal relationship between the nodes, the conditional probability of all subsequent nodes can be derived.
[0042] In this embodiment, the dependency relationships include the dependency relationships between first-layer nodes and second-layer nodes, and the dependency relationships between second-layer nodes and third-layer nodes. A first-layer node can also be referred to as the initial node of a Bayesian network attack graph. This initial node is pre-configured with a test vector. The test vectors in this embodiment can be understood as relevant vectors used to test an executable. Each test vector represents the type of network attack in the network environment in which the executable resides. The test vectors can be used to test the test results for the executable. The test results can be quantified to obtain structural information, network environment information, and interaction information for n executables in the network environment described by the test vectors. The test vectors contain elements such as threat types and hardware fluctuations in the different network environments in which the executable resides. In this embodiment, the more complete the test vectors, the more accurate the description of the network environment, and the more accurate the test results for the executable. For example, threat types can include, but are not limited to, various types of Trojan viruses, vulnerabilities, and other attacks on the executable. Hardware fluctuations can include, but are not limited to, excessive or insufficient current in the hardware, which can cause the executable to fail and inaccurate execution results.
[0043] In this embodiment, the test vectors can be of various types, and the occurrence probabilities corresponding to different types of test vectors are different. It can be understood that the occurrence probabilities corresponding to test vectors for different elements are generally different. The occurrence probability in this embodiment can be configured based on the test vectors to measure the heterogeneity characteristics between the executables to configure the occurrence probability. In some embodiments, the occurrence probability can be configured based on information such as the network attacks suffered by the executables during a certain period of time, the network type of the attacks, the number of attacks, the attack frequency, etc.; in other embodiments, the occurrence probability corresponding to the test vectors can also be configured in other forms, which are not limited in this embodiment.
[0044] In this embodiment, each node in the second-layer node is represented as an executor, and each node in the third-layer node is represented as the minimum action unit corresponding to each executor. The number of minimum actions in the three-layer node is one or more, and each minimum action unit includes a certain number of target executors. The number of executors included in the minimum executor can be selected according to the scheduling scenario. When the test vector acts on n executors in the second-layer node, the minimum action unit observed and measured.
[0045] In this embodiment, the construction of the Bayesian network attack graph can be constructed through the dependency relationship between at least three layers of nodes in the mimetic defense system. Specifically, all nodes to be considered for quantification of the executor heterogeneity can be determined first, the dependency relationship between the nodes can be determined, the nodes can be connected with directed edges, and then the probability distribution of each node can be determined. When the probability distribution is the parent node of a given node, the conditional probability of the node under the parent node can be determined. Afterwards, the Bayesian network can be further improved, such as checking whether the constructed Bayesian network is reasonable. In addition, the constructed network can also be verified, etc. In one embodiment, the Bayesian network attack graph is expressed as: BAG = (S / U, E, P); wherein S / U represents the node set in the Bayesian network graph, S represents the node set corresponding to the initial node and the second-layer node, and S includes {S0, S1, S2, ..., S n}, where S0 is the node set of the initial node; {S1, S2, ..., S n} represents a set of nodes on the second layer; U includes {U1, U2, ..., U n}, represented as a node set of three-layer nodes, U n Represents the nth smallest action unit; E represents a set of directed edges, representing the causal relationship between nodes; P represents a probability set. For example, to better understand the constructed Bayesian network attack graph, Figure 2 A schematic diagram of a Bayesian network attack graph provided by an embodiment of the present invention is shown as follows: Figure 2 As shown in , the mimicry defense system has a total of several heterogeneous executives, the number of which is n. The heterogeneity between the n executives is quantitatively described. Figure 2 S0 is the initial node, S1, S2, ..., S n is the execution body in the second-layer node, U1, U2, ..., U n It is the smallest action unit in the three-layer node. The probability of occurrence of the test vector W configured by the initial node S0 is expressed as P W , E1, E2, …, E n The directed edge set of the Bayesian network attack graph represents the causal relationship between nodes. That is, the starting point of each directed edge is the precondition of its end point. When the test vector W acts on n execution bodies, there are n paths from the starting node S0 to reach different execution bodies. P(E1), P(E2), ..., P(E n ) is expressed as the probability of a directed edge, which can also be understood as the probability of the test vector elements to each execution body. P(S1), P(S2), ..., P(S n ) represents the probability that each execution body in the second-layer node is attacked by the test vector. For example, when the elements in the test vector are network threats, this probability is also the probability that the execution body is attacked by the corresponding network threat. P(U1), P(U2), ..., P(Un ) is expressed as the reachability probability of the minimum action unit. When all the parent nodes of the minimum action unit are occupied, the minimum action unit is occupied.
[0046] S120. Determine a first conditional probability of the execution body under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and the preset directed edge probability; wherein the preset directed edge probability is the occurrence probability of the test vector breaking through the execution body.
[0047] The preset directed edge probability can be understood as the probability of a pre-configured test vector breaching an executable. This directed edge probability can be derived through comprehensive evaluation of the network environment and hardware fluctuations. The first parent node set can be understood as the set of parent nodes corresponding to the executables. Since the initial node is S0, the parent node corresponding to each executable included in the second-layer node in the Bayesian network attack graph is the initial node. The first conditional probability refers to the conditional probability of the executable under the influence of the probability of the test vector configured at the initial node.
[0048] In this embodiment, the probability of occurrence of the test vector configured by the initial node and the probability of the test vector breaking through the execution body can be used to determine the first conditional probability of the execution body under the influence of the initial node. Specifically, the network attacks suffered by the execution body in a certain period of time and the network type, number of attacks, attack frequency, etc. can be counted, so as to configure the occurrence probability based on the statistical network type, number of attacks, attack frequency and other information. Then, the probability of the configured test vector breaking through the execution body and the product of the occurrence probability can be used to determine the first conditional probability of each execution body under the influence of the initial node. It should be noted that the method of determining the first conditional probability of each execution body under the influence of the initial node in this embodiment is not limited to the above method, and can also be determined by other methods in the prior art, which is not limited in this embodiment.
[0049] S130: Determine the number of target executables included in the minimum action unit according to a preset scheduling scenario, and group the target executables into a second parent node set corresponding to the minimum action unit.
[0050] Among them, the preset scheduling scenarios can include dynamic heterogeneous redundancy (DHR) scenarios with majority consensus and DHR scenarios with full consensus. In different scheduling scenarios, the number of target executors contained in the minimum action unit is different, which can be selected according to the scheduling scenario. The target executor is a certain number of executors selected from the executors of the second-layer nodes. The second parent node set can be understood as the combination of the parent nodes corresponding to the minimum action unit in the three-layer nodes, and the second parent node set is composed of the executors in the second-layer nodes.
[0051] In this embodiment, the number of target executors included in the minimum action unit is selected according to different scheduling scenarios, and the target executors are grouped into a second parent node set corresponding to the minimum action unit. Specifically, if the scheduling scenario is a DHR scenario with a majority decision, the number of target executors included in the minimum action unit is a portion of the number of executors included in the second-layer node. If the scheduling scenario is a DHR scenario with a full decision, the number of target executors included in the minimum action unit is the total number of executors included in the second-layer node. For example, the second-layer node includes a total of 5 executors. In the DHR scenario with a majority decision, the number of target executors included in the minimum action unit is 3. In the DHR scenario with a full decision, the number of target executors included in the minimum action unit is 5, that is, all executors are grouped into the minimum action unit.
[0052] S140: Determine a second conditional probability of the minimum effect unit under the influence of the second parent node set based on the first conditional probability.
[0053] The second conditional probability refers to the conditional probability of each minimum action unit in the three-layer node under the influence of the parent node set composed of the second-layer nodes.
[0054] In this embodiment, the first conditional probability affects the conditional probability of the minimum action unit in the three-layer node. Since the first conditional probability can be 1 or 0, if the first conditional probability is 0, it indicates that the i-th executable in the second-layer node cannot be compromised by the test vector, and the test vector cannot compromise the minimum action unit in the third-layer node. In this embodiment, if there are uncompromised executables in the minimum action unit, it indicates that an executable in the minimum action unit is still functioning normally and the system containing the minimum action unit can output correct results, so the minimum action unit has not been compromised. If the first conditional probability is 1, it indicates that the i-th executable in the second-layer node can be compromised by the test vector. When all executables in the minimum action unit are compromised, the test vector can compromise the minimum action unit in the third-layer node. At this time, the conditional probability corresponding to each target executable contained in the second parent node set corresponding to the minimum action unit is determined, and the product of each conditional probability is accumulated to obtain a probability result, which is used as the second conditional probability.
[0055] S150: Determine the reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability.
[0056] The reachability probability can be understood as the probability that the smallest action unit in a three-layer node is compromised, or the probability that the smallest action unit in a three-layer node is occupied. For example, if the smallest action unit includes three target executables, the probability of the smallest action unit being compromised is the probability that all three target executables are compromised. When all target executables in the smallest action unit are compromised, the smallest action unit is considered compromised.
[0057] In this embodiment, the reachability probability of the minimum action unit can be determined based on the first conditional probability of each executor in the second-layer node under the influence of the initial node, and the second conditional probability of each minimum action unit in the third-layer node under the influence of the second parent node set composed of the second-layer nodes. This can be understood as calculating the reachability probability of each minimum action unit in the third-layer node by using the probabilities of each node in the Bayesian network attack graph and the probabilities of the executor under the influence of the test vector. Thus, the heterogeneity between executors is evaluated through the reachability probability.
[0058] S160: Determine the degree of heterogeneity between the executors based on the reachability probability.
[0059] Among them, heterogeneity can be understood as the characterization of the heterogeneity between various execution entities.
[0060] In this embodiment, the reachability probability of each minimum action unit in the three-layer node can be used to determine a quantitative heterogeneity value between each executable. This quantitative heterogeneity value can represent the heterogeneity between each executable. In some embodiments, the quantitative heterogeneity value of each executable under the influence of a test vector can be determined based on the reachability probability and a preset correction coefficient. Then, the total quantitative heterogeneity value between each executable can be determined based on the quantitative heterogeneity value and the test type contained in the test vector. In other embodiments, data affecting the heterogeneity of each executable can be collected to identify key influencing factors of the heterogeneity of each executable, score the key influencing factors, and use network analysis to construct an expert scoring table based on the key influencing factors. The expert scoring table can then be used to determine the quantitative heterogeneity value between each executable. Of course, other methods can also be used to determine the quantitative heterogeneity value between each executable, which is not limited in this embodiment.
[0061] The above-mentioned technical scheme of the embodiment of the present invention constructs a Bayesian network attack graph, determines the first conditional probability of the executor under the influence of the initial node set based on the occurrence probability of the test vector configured by the initial node in the Bayesian network attack graph, and the preset directed edge probability, determines the second conditional probability of the minimum action unit under the influence of the second parent node set through the first conditional probability, and on this basis, determines the reachable probability of the minimum action unit based on the first conditional probability and the second conditional probability, thereby determining the quantitative value of the heterogeneity between each executor according to the reachable probability, and can realize the measurement of the heterogeneity between the executors by the probability of the test vector in the network environment, more accurately reflecting the characteristics and differences of the executors in different operating environments, and in the field of mimetic scheduling of endogenous security defense, it will be more conducive to increasing the security of the mimetic defense system.
[0062] In one embodiment, Figure 3 A flowchart of another method for quantifying the heterogeneity of executors based on a Bayesian network is provided for one embodiment of the present invention. Based on the above embodiments, this embodiment further refines the first conditional probability of determining the executor under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and the preset directed edge probability, determining the number of target executors included in the minimum action unit according to the preset scheduling scenario, determining the second conditional probability of the minimum action unit under the influence of the second parent node set based on the first conditional probability, determining the reachable probability of the minimum action unit based on the first conditional probability and the second conditional probability, and determining the heterogeneity quantization value between each executor based on the reachable probability.
[0063] like Figure 3 As shown, the Bayesian network-based method for quantifying the heterogeneity of executive bodies in this embodiment may specifically include the following steps:
[0064] S310. Construct a Bayesian network attack graph based on the dependency relationship between at least three layers of nodes in the mimicry defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, each test vector represents the type of network attack in the network environment where the executor is located, and each test vector corresponds to a corresponding probability of occurrence; each node in the second-layer node is represented as an executor; each node in the third-layer node is represented as the minimum action unit corresponding to each executor.
[0065] S320: Obtain the occurrence probability of the test vector configured by the initial node.
[0066] In this embodiment, since there are many types of network attacks, the types of network attacks suffered by different executable bodies may be the same or different. Therefore, for each executable body, statistics are collected on the types of network attacks suffered by each executable body within a certain period of time in history, as well as the number of network attacks.
[0067] Specifically, the probability of occurrence can be determined by statistically analyzing the types of network attacks experienced by each executable within a historical time period, as well as the number of network attacks. Based on the attack types and number of attacks, the probability of occurrence corresponding to the test vector can be determined. Alternatively, the probability of occurrence of the test vector can be determined using other methods in probability theory, which are not limited in this embodiment. For example, the frequency of network attacks experienced by the executable over the past month, the types of network attacks experienced, and the number of network attacks experienced can be statistically analyzed. The probability of occurrence of the test vector configured at the evaluation point can then be determined based on the type and number of attacks.
[0068] S330. Determine a first product of the occurrence probability and the preset directed edge probability, and use the first product as a first conditional probability of the execution body under the influence of the first parent node set; wherein the first parent node set consists of initial nodes.
[0069] In this embodiment, the first product of the occurrence probability and the predetermined directed edge probability is determined, and the first product is used as the first conditional probability of the execution body under the influence of the first parent node set; wherein the first parent node set is composed of the initial node. For example, the probability of the test vector occurring is 0.5, and the probability of the directed edge is 0.9. The first conditional probability is 0.5*0.9=0.45, which is the probability that the execution body is occupied by the test vector. In this embodiment, the first conditional probability is expressed as: P(S i =1|Par(S i ))=P(S i |S0=1)P(S0), where S i Represents the i-th execution body, Par(S i ) represents the first parent node set of the i-th execution body, P(S i |S0=1) represents the probability of the i-th executor in the second-layer node being hacked under the condition that the probability of the initial node S0 is 1, P(S0) represents the probability of the initial node S0, P(S i =1|Par(S i )) represents the first conditional probability of the i-th execution body under the influence of the first parent node set.
[0070] S340: When the preset scheduling scenario is a DHR scenario with majority decision, the minimum action unit includes a first number of target execution bodies.
[0071] The first number of target executables is k=(n+1) / 2, where n represents the total number of executables included in the second-layer nodes.
[0072] In this embodiment, if the preset scheduling scenario is a DHR scenario with a consensus decision, the minimum action unit includes a first number of target executors, and the value of the first number of target executors is k = (n + 1) / 2, where n represents the total number of executors included in the second-layer node. It should be noted that when applied to the DHR scenario with a consensus decision, the relationship between the total number of executors in the second-layer node and the minimum action unit in the third-layer node satisfies Among them, n is the total number of executors; m is the number of minimum action units. At this time, the number of executors contained in the minimum action unit is k = (n + 1) / 2. When applied to a DHR system with unanimous judgment, m = 1, and the minimum action unit contains n executors, that is, the number of target executors contained in the minimum action unit is equal to the total number of executors contained in the second-layer nodes. For example, majority judgment is to select a part of all executors as the minimum execution unit. If the selected executors are compromised, it means that the system is compromised; full judgment means that there are 5 executors, and 5 are selected as the minimum execution unit, that is, all executors are regarded as the minimum execution unit. When all 5 executors are compromised, the system is compromised.
[0073] S350: When the preset scheduling scenario is a DHR scenario with all decisions being consistent, the minimum action unit includes a second number of target executables.
[0074] The second number of target executables is equal to the total number of executables included in the second-layer nodes.
[0075] In this embodiment, if the preset scheduling scenario is a DHR scenario with unanimous decision, the minimum action unit includes a second number of target executors; wherein the second number of target executors is equal to the total number of executors included in the second-layer node.
[0076] S360: Group the first number or the second number of target executables into a second parent node set corresponding to the minimum action unit.
[0077] In this embodiment, the first number or the second number of target executables is used as the number of target executables included in the minimum action unit, and the target executables are grouped into a second parent node set corresponding to the minimum action unit.
[0078] S370. When the first conditional probability is 1, determine the conditional probability corresponding to each target execution body contained in the second parent node set corresponding to the minimum action unit, add up the products of the conditional probabilities to obtain a probability result, and use the probability result as the second conditional probability.
[0079] In this embodiment, when the first conditional probability is 1, the conditional probability corresponding to each target execution body contained in the second parent node set corresponding to the minimum action unit is determined, the products of the conditional probabilities are accumulated to obtain the probability result, and the probability result is used as the second conditional probability. Among them, the first conditional probability is 1, which indicates that the i-th execution body in the second-layer node is broken by the test vector.
[0080] In this embodiment, the second conditional probability is expressed as follows: Among them, P(U j |S i =1) represents the conditional probability corresponding to the jth minimum action unit when the conditional probability of the i-th execution body of the second-layer node is 1; S i =1 means that the i-th execution body in the second-layer node is broken by the test vector, Par(U j ) represents the second parent node set corresponding to the jth minimum action unit, n represents the total number of executables contained in the second-level nodes, and (n+1) / 2 represents the number of target executables contained in the minimum action unit.
[0081] S380: When the first conditional probability is 0, determine that the second conditional probability of the minimum effect unit under the influence of the second parent node set is 0.
[0082] In this embodiment, when the first conditional probability is 0, the second conditional probability of determining that the minimum action unit is influenced by the second parent node set is 0. The first conditional probability of 0 indicates that the i-th executable in the second-layer node has not been compromised by the test vector, and the test vector cannot compromise the minimum action unit.
[0083] S390: Substitute the second conditional probability and the first conditional probability into a preset reachable probability formula to obtain the reachable probability of the minimum action unit.
[0084] In this embodiment, the second conditional probability and the first conditional probability are substituted into the preset reachable probability formula to obtain the reachable probability of the minimum action unit. The preset reachable probability formula can be expressed as: Among them, P(U j =1|Par(U j )) is expressed as the second conditional probability, that is, the probability that the jth minimum action unit in the three-layer node is under the influence of its parent node (the probability that the jth three-layer node is under the influence of its parent node), It is expressed as the conditional probability of the i+xth executor under the influence of the corresponding parent node set; x is U j The value of k is (n+1) / 2, and n is the total number of executors in the second-layer nodes.
[0085] In this embodiment, the second conditional probability and the first conditional probability are substituted into the preset reachable probability formula to obtain the reachable probability of the minimum action unit. That is, the formulas corresponding to the second conditional probability and the first conditional probability are substituted into the preset reachable probability formula. The formula for the reachable probability of the minimum action unit can be obtained by simplification, which is expressed as: Where x is a variable with a value of 0 to k-1, k = (n+1) / 2, k represents the number of target executables contained in the minimum action unit, n represents the total number of executables in the second-layer node, P(E i+x ) represents the probability of the i+xth directed edge set; P(W) represents the probability of the test vector.
[0086] S3100 , determining a heterogeneity quantization value of each execution body under a test vector condition according to the reachability probability and a preset correction coefficient.
[0087] The preset correction factor is a user-defined correction factor. Different executors have different correction factors. This correction factor can be used to remove duplicates during the calculation of the heterogeneity quantization degree. Generally, the more lower-level nodes there are, the more duplicates there are, and the larger the correction factor.
[0088] In this embodiment, the heterogeneity quantization value of each executable under the action of the test vector is determined based on the reachability probability of the minimum action unit and the preset correction coefficient. Specifically, the second product of the reachability probability corresponding to each minimum action unit and the preset weight coefficient is determined, and the difference between the second product and the preset correction coefficient is used as the heterogeneity quantization degree; wherein the heterogeneity quantization value is expressed as: Among them, r j It is expressed as the preset weight coefficient of the jth minimum action unit, m is expressed as the number of minimum action units, P(U j ) represents the reachability probability of the jth minimum action unit; X represents the preset correction coefficient, Where n represents the total number of executables in the second-layer nodes, k represents the number of target executables contained in the minimum action unit, and P(W) represents the probability of occurrence of the test vector. It is expressed as the probability that the execution body is cracked under the test vector conditions in all combinations of the i-th execution body.
[0089] S3110 : Determine the degree of heterogeneity between the execution bodies according to the heterogeneity quantization value and the test type included in the test vector.
[0090] In this embodiment, because the test types included in the test vectors are different and the corresponding probabilities of occurrence are different, the heterogeneity quantization degrees between the executables corresponding to the test vectors of different test types are also different. Therefore, the heterogeneity degree between the executables can be determined based on the heterogeneity quantization degree and the test types included in the test vectors. Specifically, when the test vectors include at least two test types, the heterogeneity quantization degrees corresponding to the at least two types of test vectors are accumulated to obtain an accumulated result, which is used as the first heterogeneity quantization value between the executables; wherein the first heterogeneity quantization value is expressed as: In the formula, w represents the test type, and t represents the total number of test vector types. When the test type contained in the test vector is of one type, the heterogeneity quantization degree corresponding to the test vector of one type is used as the second heterogeneity quantization value between the executors. The first heterogeneity quantization value, or the reciprocal of the second heterogeneity quantization value, is taken as the heterogeneity quantization value between the executors. It can be understood that after the heterogeneity degree is calculated, the heterogeneity degree is a probability, and the reciprocal of the final probability is taken as the final result, which is the final heterogeneity degree, which can better express the heterogeneity quantization. More specifically, the executor heterogeneity degree is expressed by the formula: R is represented as a heterogeneous quantization value.
[0091] In this embodiment, the test vectors will be different for different network environments. According to the heterogeneous quantization value formula, it can be seen that the heterogeneity of the executor in different network environments will be different. As the test vectors in the network environment differ, the higher the completeness of the test vectors, the more accurate the heterogeneity after quantification will be, that is, the heterogeneity between the executors will be accurately quantified.
[0092] The above-mentioned technical solution of this embodiment determines the first product of the occurrence probability and the preset directed edge probability, and uses the first product as the first conditional probability of the executor under the influence of the first parent node set. According to different scheduling scenarios, the minimum action unit is selected to include the target executor. When the first conditional probability is 1, the conditional probability corresponding to each target executor is determined, and the products of the conditional probabilities are added to obtain the second conditional probability. The second conditional probability and the first conditional probability are substituted into the preset reachable probability formula to obtain the reachable probability, thereby determining the heterogeneity quantification degree of each executor under the action of the test vector based on the reachable probability and the preset correction coefficient, and determining the heterogeneity quantification value between each executor based on the heterogeneity quantification degree and the test type contained in the test vector. This can further achieve the use of probability to measure the quantification degree between executors, more accurately reflect the characteristics and differences of executors in different operating environments, and will be more conducive to increasing the security of the mimetic defense system in the field of mimetic scheduling of endogenous security defense.
[0093] In one embodiment, in order to better understand the process of the execution body heterogeneity quantification method based on Bayesian network, Figure 4 A schematic diagram of another Bayesian network attack graph provided by an embodiment of the present invention. Figure 4 As shown, in this embodiment, the initial node is S0, and there are 3 executors, including: S1, S2 and S3; there are 3 minimum action units, that is, m=3. When used in a system with majority consensus, the minimum action unit contains 2 target executors. When used in a system with full consensus, the minimum action unit contains 3 target executors. In this embodiment, the example of the minimum action unit containing 2 target executors is used for explanation. The Bayesian network can be expressed as BAG=(S / U,E,P), which is specifically defined as follows:
[0094] (1) S / U is a set of conditional nodes, and the test vector W is a vulnerability threat. S0 is the initial node, i.e., the node where the vulnerability threat initiates the attack on the executable. There are three second-level child nodes, each representing a different executable. There are three third-level grandchild nodes, each representing the smallest action unit of the executable. When used in a system with majority consensus, the smallest action unit contains two executables. When used in a system with unanimous consensus, the smallest action unit contains three executables.
[0095] (2) E is the set of directed edges in the Bayesian network attack graph, which represents the causal relationship between nodes. The directed edge from the ancestor node to the parent node represents the interaction between the test vector W and the execution body. When the test vector is a vulnerability threat, it represents the threat attack on the execution body. The directed edge from the parent node to the grandchild node represents the attack on the security performance of the minimum action unit after the execution body is attacked by the vulnerability threat. According to the mimicry defense theory, when all m execution bodies in the minimum action unit are breached, the mimicry defense system composed of n execution bodies is breached. If the execution body belongs to the minimum action unit, then the attack can reach the minimum action unit, that is, there is a directed edge between the two nodes, and its probability P(E) = 1. Otherwise, it cannot be reached, that is, there is no directed edge.
[0096] (3) P is the set of reachable probabilities of conditional nodes in the Bayesian network attack graph. P(W) is the probability of the test vector, i.e., the vulnerability threat, and is also the probability of the initial node S0. P(E) is the probability of the test vulnerability breaking the executable. The probability of the executable being broken is related to factors such as the vulnerabilities contained in the executable and the exploitability of the vulnerabilities. The probability of the second-level parent node P(S) represents the probability of the test threat reaching the node executable (P(S) = P(W) × P(E)). The probability of the third-level child node represents the probability of the minimum action unit being broken, i.e., the probability of the combination of three executables being broken. When all the executables in the minimum action unit are broken, it is the probability of the minimum action unit being broken.
[0097] In this embodiment, after constructing the Bayesian network attack graph, the three-layer node reachability probability calculation formula is: Where x is a variable with a value from 0 to k-1, where k=(n +1) / 2 , represents the number of target execution bodies contained in the minimum action unit, n represents, n represents the total number of execution bodies in the second-layer node, P(E i+x ) represents the probability of the i+xth directed edge set; P(W) represents the probability of the test vector. Therefore, according to the three-layer node reachability probability calculation formula, we can get:
[0098] P(U1)=P(W)P(U1|S1,S2)=P(W) 2 P(E1)P(E2);
[0099] P(U2)=P(W)P(U2|S2,S3)=P(W) 2 P(E2)P(E3);
[0100] P(U3)=P(W)P(U3|S1,S3)=P(W) 2 P(E1)P(E3);
[0101] Because the three executables have no difference when forming the minimum action unit, the weight influence coefficient rj = 1. There is only one vulnerability threat W in the test vector. The heterogeneous quantitative value between the three executables under the vulnerability threat W is: R = P(U1) + P(U2) + P(U3) - 2P(W) 3 P(E1)P(E2)P(E3); at this time, assuming that the probability of occurrence of test vector W, that is, P(W), is 0.5, and the probability of each executable being compromised when test vector W occurs, that is, P(E), is 0.9, then the heterogeneity quantification value of the three executables under the vulnerability threat W is 0.42525, and the heterogeneity is 2.351.
[0102] In one embodiment, Figure 5 A schematic diagram of another Bayesian network attack graph provided by an embodiment of the present invention. Figure 5 As shown, in this embodiment, the initial node is S0, and there are five executors, including: S1, S2, S3, S4, and S5, that is, n = 5; there are 10 minimum action units, that is, m = 10. When used in a system with majority consensus, the minimum action unit contains three target executors. When used in a system with unanimous consensus, the minimum action unit contains five target executors. In this embodiment, the minimum action unit contains two target executors for illustration.
[0103] The Bayesian network can be expressed as BAG = (S / U, E, P), which is defined as follows:
[0104] (1) S / U is a set of conditional nodes, and the test vector W is a vulnerability threat. S0 is the initial node, i.e., the node where the vulnerability threat initiates the attack on the executable. There are five second-level child nodes, each representing a different executable. There are ten third-level grandchild nodes, representing the smallest action unit of the executable. However, when used in a system with majority consensus, the smallest action unit contains three target executables. When used in a system with unanimous consensus, the smallest action unit contains five target executables.
[0105] (2) E is the set of directed edges in the Bayesian network attack graph, which represents the causal relationship between nodes. The directed edge from the ancestor node to the parent node represents the interaction between the test vector W and the execution body. When the test vector is a vulnerability threat, it represents an attack on the execution body by the threat. The directed edge from the parent node to the grandchild node represents the attack on the security performance of the minimum action unit after the execution body is attacked. If the execution body node belongs to the minimum action unit, then the attack can reach the minimum action unit, that is, there is a directed edge between the two nodes, and its probability P(E) = 1. Otherwise, it cannot be reached, that is, there is no directed edge.
[0106] (3) P is the set of reachable probabilities of conditional nodes in the Bayesian network attack graph. P(W) is the probability of the test vector, i.e., the vulnerability threat, and is also the probability of the initial node S0. P(E) is the probability of the test vulnerability breaking the executable. The probability of the executable being broken is related to factors such as the vulnerability contained in the executable and the exploitability of the vulnerability. The probability P(S) of the second-level parent node represents the probability that the test threat reaches the node executable, and the probability of the third-level child node represents the probability that the minimum action unit is broken. When all the executables in the minimum action unit are broken, it is the probability that the minimum action unit is broken.
[0107] In this embodiment, after constructing the Bayesian network attack graph, according to the three-layer node reachability probability calculation formula, we can obtain:
[0108] P(U1)=P(W)P(U1|S1,S2,S3)=P(W) 3 P(E1)P(E2)P(E3);
[0109] P(U2)=P(W)P(U2|S1,S2,S4)=P(W) 3 P(E1)P(E2)P(E4);
[0110] P(U3)=P(W)P(U3|S1,S2,S5)=P(W) 3 P(E1)P(E2)P(E5);
[0111] P(U4)=P(W)P(U4|S1,S3,S4)=P(W) 3 P(E1)P(E3)P(E4);
[0112] P(U5)=P(W)P(U5|S1,S3,S5)=P(W) 3 P(E1)P(E3)P(E5);
[0113] P(U6)=P(W)P(U6|S1,S4,S5)=P(W) 3 P(E1)P(E4)P(E5);
[0114] P(U7)=P(W)P(U7|S2,S3,S4)=P(W) 3 P(E2)P(E3)P(E4);
[0115] P(U8)=P(W)P(U8|S2,S3,S5)=P(W) 3 P(E2)P(E3)P(E5);
[0116] P(U9)=P(W)P(U9|S2,S4,S5)=P(W) 3 P(E2)P(E4)P(E5);
[0117] P(U 10 )=P(W)P(U 10 |S3,S4,S5)=P(W) 3 P(E3)P(E4)P(E5);
[0118] Because there is no difference between the five actuators when they form the minimum action unit, the weight influence coefficient r j = 1. There is only one vulnerability threat W in the test vector. The heterogeneity quantification value between the five execution bodies under vulnerability threat W is:
[0119] R=P(U1)+P(U2)+P(U3)+P(U4)+P(U5)+P(U6)+P(U7)+P(U8)+P(U9)+P(U 10 )
[0120] -4P(W) 5 P(E1)P(E2)P(E3)P(E4)P(E5)-3P(W) 4 (P(E1)P(E2)P(E3)P(E4)
[0121] +P(E1)P(E2)P(E3)P(E5)+P(E1)P(E2)P(E4)P(E5)+P(E1)P(E3)P(E4)P(E5)
[0122] +P(E2)P(E3)P(E4)P(E5))
[0123] Therefore, assuming that the probability of occurrence of test vector W, i.e. P(W), is 0.5, and the probability of each executable being compromised when test vector W occurs, i.e. P(E), is 0.9, then the heterogeneity of the three executables under vulnerability threat W is 0.222345, and the heterogeneity is 4.4975.
[0124] In one embodiment, Figure 6 A schematic diagram of another Bayesian network attack graph provided by an embodiment of the present invention. Figure 6 As shown, in this embodiment, the initial node is S0, and there are five executors: S1, S2, S3, S4, and S5, i.e., n = 5. The minimum action unit is one, i.e., m = 1. When used in a system with a fully consistent decision, the minimum action unit contains five executors. In this embodiment, the minimum action unit contains five target executors as an example.
[0125] The Bayesian network can be expressed as BAG = (S, E, P), which is defined as follows:
[0126] (1) S is a set of conditional nodes, and the test vector W is a vulnerability threat. S0 is the initial node, i.e., the node where the vulnerability threat initiates the attack on the executable. There are five second-level child nodes, each representing a different executable. There is one third-level grandchild node, representing the smallest action unit of the executable. When used in a system with unanimous judgment, the smallest action unit contains five executables.
[0127] (2) E is the set of directed edges in the Bayesian network attack graph, which represents the causal relationship between nodes. The directed edge from the ancestor node to the parent node represents the interaction between the test vector W and the execution body. When the test vector is a vulnerability threat, it represents an attack on the execution body by the threat. The directed edge from the parent node to the grandchild node represents the security performance attack of the minimum action unit after the execution body is attacked. If the execution body node belongs to the minimum action unit, then the attack can reach the minimum action unit, that is, there is a directed edge between the two nodes, and its probability P(E) = 1. Otherwise, it cannot be reached, that is, there is no directed edge.
[0128] (3) P is the set of reachable probabilities of conditional nodes in the Bayesian network attack graph. P(W) is the probability of the test vector, i.e., the vulnerability threat, and is also the probability of the initial node S0. P(E) is the probability of the test vulnerability breaking the executable. The probability of the executable being broken is related to factors such as the vulnerability contained in the executable and the exploitability of the vulnerability. The probability P(S) of the second-level parent node represents the probability that the test threat reaches the node executable, and the probability of the third-level child node represents the probability that the minimum action unit is broken. When all the executables in the minimum action unit are broken, it is the probability that the minimum action unit is broken.
[0129] In this embodiment, after constructing the Bayesian network attack graph, according to the three-layer node reachability probability calculation formula, we can obtain: P(U1) = P(W) P(U1|S1,S2,S3,S4,S5) = P(W) 5 P(E1)P(E2)P(E3)P(E4)P(E5); there is only one vulnerability threat W in the test vector, and the quantized value between the five execution bodies under the vulnerability threat W is R=P(U1).
[0130] Therefore, assuming that the probability of occurrence of test vector W, that is, P(W), is 0.5, and the probability of each executable being compromised when test vector W occurs, that is, P(E), is 0.9, then the heterogeneity of the three executables under the vulnerability threat W is 0.0184528125, and the heterogeneity is 54.192.
[0131] In one embodiment, Figure 7 This is a block diagram of a Bayesian network-based quantification device for heterogeneity of execution provided by an embodiment of the present invention. The device is suitable for performing joint detection decoding on a received transmission vector. The device can be implemented by hardware / software. Figure 7 As shown, the apparatus includes: a construction module 710 , a first probability determination module 720 , a parent node set determination module 730 , a second probability determination module 740 , a reachability probability determination module 750 and a heterogeneity determination module 760 .
[0132] Among them, the construction module 710 is used to construct a Bayesian network attack graph based on the dependency relationship between at least three layers of nodes in the mimic defense system; wherein the Bayesian network attack graph includes an initial node, and the initial node is pre-configured with a test vector, each of which represents a type of network attack in the network environment where the executable is located, and each of the test vectors corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executable; and each node in the third layer of nodes is represented as the minimum action unit corresponding to each of the executables;
[0133] A first probability determination module 720 is configured to determine a first conditional probability of the executable under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and a preset directed edge probability; wherein the preset directed edge probability is the probability that the test vector can break the executable;
[0134] A parent node set determining module 730 is configured to determine the number of target executables included in the minimum action unit according to a preset scheduling scenario, and to group the target executables into a second parent node set corresponding to the minimum action unit;
[0135] A second probability determination module 740 is configured to determine a second conditional probability of the minimum action unit under the influence of the second parent node set based on the first conditional probability;
[0136] A reachability probability determination module 750, configured to determine the reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability;
[0137] The heterogeneity determination module 760 is configured to determine the heterogeneity between the executables according to the reachability probability.
[0138] In this embodiment, the first probability determination module constructs a Bayesian network attack graph based on the dependencies between at least three layers of nodes. Based on the occurrence probability of the test vector configured for the initial node in the Bayesian network attack graph and the pre-set directed edge probabilities, it determines the first conditional probability of the executor under the influence of the initial node set. The second probability determination module uses the first conditional probability to determine the second conditional probability of the minimum action unit under the influence of the second parent node set. Based on this, the reachability probability determination module determines the reachability probability of the minimum action unit based on the first and second conditional probabilities. The quantization degree determination module then determines the quantized value of the heterogeneity between executors based on the reachability probabilities. This allows the quantization degree between executors to be measured using probability, more accurately reflecting the characteristics and differences of executors in different operating environments. This will further enhance the security of mimetic defense systems in the field of mimetic scheduling for endogenous security defense.
[0139] In one embodiment, the Bayesian network attack graph is represented as: BAG = (S / U, E, P); wherein S / U represents a node set in the Bayesian network graph, S represents a node set corresponding to the initial node and the second-layer nodes, and S includes {S0, S1, S2, ..., S n}, where S0 is the node set of the initial node; {S1, S2, ..., S n} represents the node set of the second-layer nodes; U includes {U1, U2, ..., U n}, represented as a node set of three-layer nodes, U nrepresents the nth minimum action unit; E represents a set of directed edges, representing the causal relationship between nodes; P represents a probability set.
[0140] In one embodiment, the first probability determination module 720 includes:
[0141] a determination unit, configured to obtain an occurrence probability of a test vector configured by the initial node;
[0142] a conditional probability determination unit, configured to determine a first product of the occurrence probability and the preset directed edge probability, and use the first product as a first conditional probability of the executor under the influence of the first parent node set; wherein the first parent node set consists of the initial node;
[0143] The first conditional probability is expressed as follows: P(S i =1|Par(S i ))=P(S i |S0=1)P(S0), where S i Represents the i-th execution body, Par(S i ) represents the first parent node set of the i-th execution body, P(S i |S0=1) represents the probability of the i-th execution body in the second-layer node being hacked under the condition that the probability of the occurrence of the initial node S0 is 1, P(S0) represents the probability of the occurrence of the initial node S0, P(S i =1|Par(S i )) represents the first conditional probability of the i-th execution body under the influence of the first parent node set.
[0144] In one embodiment, the parent node set determination module 730 includes:
[0145] A first executor number determination unit is configured to, when the preset scheduling scenario is a dynamic heterogeneous redundancy (DHR) scenario with majority decision, include a first number of target executors in the minimum action unit, where the first number of target executors is k=(n+1) / 2, where n represents the total number of executors included in the layer-2 node;
[0146] A second executor quantity determination unit is configured to, when the preset scheduling scenario is a dynamic heterogeneous redundancy (DHR) scenario with a fully agreed decision, include a second number of target executors in the minimum action unit; wherein the second number of target executors is equal to the total number of executors included in the second-layer node;
[0147] The third execution body quantity determination unit is configured to group the first quantity or the second quantity of target execution bodies into a second parent node set corresponding to the minimum action unit.
[0148] In one embodiment, the second probability determination module 740 includes:
[0149] The first probability determination unit is configured to, when the first conditional probability is 1, determine the conditional probability corresponding to each target executable contained in the second parent node set corresponding to the minimum action unit, accumulate the products of the conditional probabilities to obtain a probability result, and use the probability result as the second conditional probability; wherein, the first conditional probability of 1 indicates that the i-th executable in the second-layer node is compromised by the test vector; and the second conditional probability is expressed as follows: Among them, P(U j |S i =1) represents the conditional probability corresponding to the jth minimum action unit when the conditional probability of the i-th execution body of the second-layer node is 1; S i =1 indicates that the i-th execution body in the second-layer node is broken by the test vector, Par(U j ) represents the second parent node set corresponding to the jth smallest action unit, n represents the total number of executables contained in the second-layer nodes, and (n+1) / 2 represents the number of target executables contained in the smallest action unit;
[0150] The third probability determination unit is used to determine that the second conditional probability of the minimum action unit under the influence of the second parent node set is 0 when the first conditional probability is 0; wherein, the first conditional probability of 0 indicates that the i-th execution body in the second-layer node has not been broken by the test vector, and the test vector cannot break the minimum action unit.
[0151] In one embodiment, the reachability probability determination module 750 includes:
[0152] a reachability probability determining unit, configured to substitute the second conditional probability and the first conditional probability into a preset reachability probability formula to obtain the reachability probability of the minimum action unit;
[0153] The preset reachability probability formula can be expressed as: Among them, P(U j =1|Par(U j )) is expressed as the second conditional probability, P(S i+x |S0) is expressed as the first conditional probability of the i+xth executor under the influence of the first parent node set; x is the number of parent nodes of the jth minimum action unit, k is (n+1) / 2, and n is the total number of executors in the second-level nodes.
[0154] The formula for the reachability probability is expressed as: Where x is a variable with a value of 0 to k-1, where k = (n+1) / 2, which represents the number of target executables contained in the minimum action unit, n represents the total number of executables in the second-layer node, and P(E i+x ) represents the probability of the i+xth directed edge set; P(W) represents the probability of the test vector.
[0155] In one embodiment, the heterogeneity determination module 760 includes:
[0156] a quantization degree determination unit, configured to determine a heterogeneity quantization value of each of the execution bodies under the test vector condition according to the reachability probability and a preset correction coefficient;
[0157] A quantization value determining unit is used to determine the degree of heterogeneity between the execution bodies according to the heterogeneity quantization value and the test type included in the test vector.
[0158] In one embodiment, the quantization degree determination unit includes:
[0159] a product determination subunit, configured to determine a second product of the reachability probability corresponding to each of the minimum action units and a preset weight coefficient;
[0160] The quantization degree determination subunit is configured to use the difference between the second product and the preset correction coefficient as the heterogeneity quantization degree; wherein the heterogeneity quantization degree is expressed as: Among them, r j It is expressed as the preset weight coefficient of the jth minimum action unit, m is expressed as the number of minimum action units, P(U j ) represents the reachability probability of the jth minimum action unit; X represents the preset correction coefficient, Where n represents the total number of executables in the second-layer nodes, x is a variable with a value from 0 to k-1, k represents the number of target executables contained in the minimum action unit, and P(W) represents the probability of occurrence of the test vector. It is expressed as the probability that the execution body is cracked under the test vector conditions in all combinations of the i-th execution body.
[0161] In one embodiment, the quantization value determination unit includes:
[0162] The first quantization value determination subunit is configured to, when the test vector includes at least two test types, accumulate heterogeneous quantization degrees corresponding to the at least two types of test vectors to obtain an accumulation result, and use the accumulation result as a first heterogeneous quantization value between execution entities; wherein the heterogeneous quantization value is expressed as: Where w represents the test type and t represents the total number of test vector types;
[0163] A second quantization value determining subunit is configured to, when the test type included in the test vector is one type, use the heterogeneous quantization value corresponding to the one type of test vector as the second heterogeneous quantization value between the execution bodies;
[0164] The heterogeneity determination subunit is configured to take the first heterogeneous quantization value or the reciprocal of the second heterogeneous quantization value as the heterogeneity between the execution entities.
[0165] The Bayesian network-based executable heterogeneity quantification device provided in an embodiment of the present invention can execute the Bayesian network-based executable heterogeneity quantification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0166] In one embodiment, Figure 8 A schematic diagram of the structure of an electronic device provided for implementing an embodiment of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0167] like Figure 8 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0168] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0169] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the Bayesian network-based method for quantifying the heterogeneity of the execution volume.
[0170] In some embodiments, the Bayesian network-based execution body heterogeneity quantification method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the Bayesian network-based execution body heterogeneity quantification method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the Bayesian network-based execution body heterogeneity quantification method by any other appropriate means (e.g., by means of firmware).
[0171] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0172] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0173] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0174] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0175] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0176] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0177] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0178] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A Bayesian network-based method for quantifying the heterogeneity of executive bodies, characterized by: include: A Bayesian network attack graph is constructed based on the dependency relationships between at least three layers of nodes in the mimicry defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, each of the test vectors represents a type of network attack in the network environment in which the executor is located, and each of the test vectors corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executor; and each node in the third layer of nodes is represented as a minimum action unit corresponding to each of the executors; Determining a first conditional probability of the execution body under the influence of the first parent node set based on the occurrence probability of the test vector configured by the initial node and a preset directed edge probability; wherein the preset directed edge probability is the occurrence probability of the test vector breaking the execution body; Determine the number of target executables included in the minimum action unit according to a preset scheduling scenario, and group the target executables into a second parent node set corresponding to the minimum action unit; Determine, based on the first conditional probability, a second conditional probability of the minimum action unit under the influence of the second parent node set; Determining a reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability; The degree of heterogeneity between the executables is determined according to the reachability probability.
2. The method according to claim 1, characterized in that The Bayesian network attack graph is represented as: BAG=(S / U, E, P); wherein S / U represents the node set in the Bayesian network graph, S represents the node set corresponding to the initial node and the second-layer node, and S includes { , , ,…, },in, is the node set of the initial node; , ,…, } represents the node set of the second-layer nodes; U includes { , ,…, }, represented as a node set of three-layer nodes, represents the nth minimum action unit; E represents a set of directed edges, representing the causal relationship between nodes; P represents a probability set.
3. The method according to claim 1, characterized in that The determining, based on the occurrence probability of the test vector configured by the initial node and the preset directed edge probability, of the first conditional probability of the execution body under the influence of the first parent node set includes: Obtaining the occurrence probability of the test vector configured by the initial node; Determine a first product of the occurrence probability and the preset directed edge probability, and use the first product as a first conditional probability of the executor under the influence of the first parent node set; wherein the first parent node set consists of the initial node; The first conditional probability is expressed as follows: , where represents the i-th executable, Represents the first parent node set of the i-th execution body, It represents the probability that the i-th execution body in the second-layer node is compromised under the condition that the occurrence probability of the initial node S0 is 1, It is expressed as the occurrence probability of the initial node S0, represents the first conditional probability of the i-th executable under the influence of the first parent node set.
4. The method according to claim 1, wherein The determining the number of target executables included in the minimum action unit according to a preset scheduling scenario, and forming the number of target executables into a second parent node set corresponding to the minimum action unit, includes: When the preset scheduling scenario is a dynamic heterogeneous redundant DHR scenario with majority decision, the minimum action unit includes a first number of target execution bodies; wherein the first number of target execution bodies is set to , where n represents the total number of executive bodies contained in the second-layer node; When the preset scheduling scenario is a DHR scenario with a full consensus decision, the minimum action unit includes a second number of target executors; wherein the second number of target executors is equal to the total number of executors included in the second-layer node; The first number or the second number of target executables are formed into a second parent node set corresponding to the minimum action unit.
5. The method according to claim 1, wherein The determining, based on the first conditional probability, a second conditional probability of the minimum action unit under the influence of the second parent node set includes: When the first conditional probability is 1, determine the conditional probability corresponding to each target executable contained in the second parent node set corresponding to the minimum action unit, add the products of the conditional probabilities to obtain a probability result, and use the probability result as the second conditional probability; wherein, the first conditional probability of 1 indicates that the i-th executable in the second-layer node is broken by the test vector; the second conditional probability is expressed by the formula: ;in, It represents the conditional probability corresponding to the jth minimum action unit when the conditional probability of the i-th executor of the second-layer node is 1; It means that the i-th execution body in the second-layer node is attacked by the test vector. It represents the second parent node set corresponding to the jth minimum action unit, and n represents the total number of executables contained in the second-layer nodes. It is expressed as the number of target executables contained in the minimum action unit; When the first conditional probability is 0, the second conditional probability of the minimum action unit under the influence of the second parent node set is determined to be 0; wherein, the first conditional probability of 0 indicates that the i-th execution body in the second-layer node has not been broken by the test vector, and the test vector cannot break the minimum action unit.
6. The method according to claim 1, wherein The determining the reachable probability of the minimum action unit based on the first conditional probability and the second conditional probability includes: Substituting the second conditional probability and the first conditional probability into a preset reachable probability formula to obtain the reachable probability of the minimum action unit; The preset reachability probability formula is expressed as: ,in, Expressed as the second conditional probability, It is expressed as the first conditional probability of the i+xth executor under the influence of the first parent node set; x is a variable with a value from 0 to k-1, k is (n+1) / 2, and n is the total number of executors in the second-level nodes; The formula for the reachability probability is expressed as: , where x is a variable with a value from 0 to k-1, , represents the number of target executives contained in the minimum action unit, n represents the total number of executives in the second-layer node, Expressed as the probability of the i+xth directed edge set; Expressed as the probability of occurrence of the test vector.
7. The method according to claim 1, wherein Determining the degree of heterogeneity between the executors according to the reachability probability includes: Determine a heterogeneity quantization value of each of the execution bodies under the test vector condition according to the reachability probability and a preset correction coefficient; The degree of heterogeneity between the executables is determined according to the heterogeneity quantization value and the test type included in the test vector.
8. The method according to claim 7, characterized in that The determining, according to the reachability probability and a preset correction coefficient, a heterogeneity quantization value of each of the executables under the test vector condition includes: Determine a second product of the reachability probability corresponding to each of the minimum action units and a preset weight coefficient; The difference between the second product and the preset correction coefficient is used as a heterogeneity quantization value; wherein the heterogeneity quantization value is expressed as: ,in, It is represented as the preset weight coefficient of the jth minimum action unit, m is represented as the number of minimum action units, Expressed as the reachability probability of the jth minimum action unit; Expressed as a preset correction factor, Where n is the total number of executors in the second-layer nodes, k is the number of target executors contained in the minimum action unit, and x is a variable with a value from 0 to k-1. Expressed as the probability of occurrence of the test vector, It is expressed as the probability that each executable in the i-th executable combination is compromised under the test vector condition.
9. The method according to claim 8, characterized in that The determining the degree of heterogeneity between the executables according to the heterogeneity quantization value and the test type included in the test vector includes: When the test vector includes at least two test types, the heterogeneous quantization values corresponding to the at least two types of test vectors are accumulated to obtain an accumulated result, and the accumulated result is used as a first heterogeneous quantization value between the execution bodies; wherein the first heterogeneous quantization value is expressed as: ; Wherein, w represents the test type contained in the test vector, and t represents the total number of test vector types; In a case where the test type included in the test vector is one type, using the heterogeneous quantization value corresponding to the one type of test vector as the second heterogeneous quantization value between the execution bodies; The first heterogeneous quantization value or the reciprocal of the second heterogeneous quantization value is taken as the heterogeneity degree between the execution bodies.
10. A device for quantifying the heterogeneity of an executive body based on a Bayesian network, characterized in that: include: A construction module is used to construct a Bayesian network attack graph based on the dependency relationship between at least three layers of nodes in the mimic defense system; wherein the Bayesian network attack graph includes an initial node, the initial node is pre-configured with a test vector, each test vector represents a type of network attack in the network environment where the executor is located, and each test vector corresponds to a corresponding probability of occurrence; each node in the second layer of nodes is represented as an executor; and each node in the third layer of nodes is represented as the minimum action unit corresponding to each executor; A first probability determination module is configured to determine a first conditional probability of the executable under the influence of the first parent node set based on the probability of the test vector configured by the initial node and a preset directed edge probability; wherein the preset directed edge probability is the probability of the test vector breaking the executable; a parent node set determining module, configured to determine the number of target executables contained in the minimum action unit according to a preset scheduling scenario, and group the target executables into a second parent node set corresponding to the minimum action unit; A second probability determination module, configured to determine a second conditional probability of the minimum action unit under the influence of the second parent node set based on the first conditional probability; a reachability probability determination module, configured to determine the reachability probability of the minimum action unit based on the first conditional probability and the second conditional probability; A heterogeneity determination module is used to determine the heterogeneity between the executables according to the reachability probability.
11. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so as to enable the at least one processor to execute the Bayesian network-based executive body heterogeneity quantification method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the Bayesian network-based execution body heterogeneity quantification method according to any one of claims 1 to 9 when executed.
13. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the Bayesian network-based execution volume heterogeneity quantification method according to any one of claims 1 to 9.