Methods, apparatus, computer equipment, storage media, and computer program products for determining host infection losses.
By constructing infection constraints and solving for the infection equilibrium point, the host infection loss is accurately estimated, solving the problem of inaccurate host infection loss estimation in existing technologies and achieving higher-precision loss assessment.
Patent Information
- Application Number
- CN202411693003.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-25
AI Technical Summary
In existing technologies, the estimation accuracy of host infection losses in malware attack incidents is insufficient, relying on the subjective experience of technicians, which leads to inaccurate estimations.
By determining the infection status and communication relationships of each host in the target network, infection constraints are constructed, the infection equilibrium point is solved, the infection loss of the host is calculated, and the infection equilibrium point and infection state transition probability are used to accurately estimate the infection loss of the host.
It improves the accuracy of host infection loss estimation, and can predict the infection equilibrium point and loss based on the actual network conditions, providing a more accurate loss assessment.
Smart Images

Figure CN119484134B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, computer equipment, storage medium, and computer program product for determining host infection loss. Background Technology
[0002] With the rapid development of cloud computing and the Internet, cybersecurity issues have become increasingly complex and severe. Malware, as one of the main methods of cyberattacks, is constantly evolving and expanding in its propagation methods and scope of impact. Especially in cloud service and cloud network environments, due to the high degree of interconnectivity and resource sharing in cloud networks, malware can spread rapidly among a wide range of network nodes, posing a serious security threat.
[0003] To combat malware attacks, it is crucial to estimate the potential damage to the network during an attack. Related technologies often assume a fixed loss value for such events; however, this approach relies on the subjective experience of the technicians setting the loss value, resulting in insufficient accuracy in estimating the damage caused by host infection. Summary of the Invention
[0004] Therefore, it is necessary to provide a method, apparatus, computer equipment, storage medium, and computer program product for determining host infection loss in response to the above-mentioned technical problems.
[0005] Firstly, this application provides a method for determining host infection loss. The method includes:
[0006] Determine the infection status of each host in the target network, as well as the communication relationships between the hosts;
[0007] Based on the communication relationships between the hosts and the probability of each host switching between infection states, infection constraints corresponding to the target network are constructed.
[0008] Based on the infection status of each host and the infection constraints, the infection equilibrium point of the target network corresponding to the target infection status is obtained.
[0009] The infection loss of each host is determined based on the infection state transition at the infection equilibrium point corresponding to each host.
[0010] In one embodiment, the infection constraint includes at least a host number change rate constraint for each infection state, the host number change rate constraint representing the rate at which the number of hosts in the infection state changes over time.
[0011] In one embodiment, the infection state includes at least an uninfected state and an infected state, and the probability of the host transitioning from the uninfected state to the infected state is used to represent the probability that the host transitions from the uninfected state to the infected state when a host with which it has a communication relationship is in the infected state.
[0012] The step of constructing infection constraints corresponding to the target network based on the communication relationships between the hosts and the probabilities of transitions between infection states includes:
[0013] A contact probability constraint is constructed, which is used to characterize the probability that the host in an uninfected state communicates with the host in an infected state.
[0014] Based on the probability of transitioning from the uninfected state to the infected state and the contact probability constraint, a constraint on the rate of change of the number of hosts in the infected state is constructed.
[0015] In one embodiment, the step of obtaining the infection equilibrium point of the target network corresponding to the target infection state based on the initial infection state and the infection constraints includes:
[0016] Based on the constraint condition of the rate of change of the number of hosts corresponding to the target infection state, an infection equilibrium point constraint condition is constructed for the target infection state. The infection equilibrium point constraint condition is used to indicate that the rate of change of the number of hosts in the target infection state over time is 0.
[0017] Based on the infection equilibrium point constraint, the infection state corresponding to each host, and each of the infection constraints except for the host number change rate constraint corresponding to the target infection state, the infection equilibrium point of the target network corresponding to the target infection state is obtained.
[0018] In one embodiment, determining the infection loss of each host based on the infection state transition at the infection equilibrium point for each host includes:
[0019] For any of the aforementioned hosts, determine the number of infections corresponding to the infection equilibrium point for that host, where the number of infections is the number of times the host transitions from an uninfected state to an infected state when it reaches the infection equilibrium point;
[0020] The infection loss of each host is determined based on its initial value, the number of infections, and the loss per infection.
[0021] In one embodiment, the method further includes:
[0022] Based on the infection loss of each host, determine the average infection loss and the variance of infection loss of the target network;
[0023] Based on the average infection loss, the variance of infection loss, and the preset safety factor, the expected loss repair resources for hosts in the target network are determined.
[0024] Secondly, this application also provides a device for determining host infection loss. The device includes:
[0025] The first determining module is used to determine the infection status of each host in the target network, as well as the communication relationship between the hosts.
[0026] A construction module is used to construct infection constraints corresponding to the target network based on the communication relationships between the hosts and the probability of each host switching between infection states.
[0027] The second determining module is used to solve for the infection balance point of the target network corresponding to the target infection state based on the infection state of each host and the infection constraints.
[0028] The third determining module is used to determine the infection loss of each host based on the infection state transition of each host corresponding to the infection equilibrium point.
[0029] In one embodiment, the infection constraint includes at least a host number change rate constraint for each infection state, the host number change rate constraint representing the rate at which the number of hosts in the infection state changes over time.
[0030] In one embodiment, the infection state includes at least an uninfected state and an infected state, and the probability of the host transitioning from the uninfected state to the infected state is used to represent the probability that the host transitions from the uninfected state to the infected state when a host with which it has a communication relationship is in the infected state.
[0031] The building module is also used for:
[0032] A contact probability constraint is constructed, which is used to characterize the probability that the host in an uninfected state communicates with the host in an infected state.
[0033] Based on the probability of transitioning from the uninfected state to the infected state and the contact probability constraint, a constraint on the rate of change of the number of hosts in the infected state is constructed.
[0034] In one embodiment, the second determining module is further configured to:
[0035] Based on the constraint condition of the rate of change of the number of hosts corresponding to the target infection state, an infection equilibrium point constraint condition is constructed for the target infection state. The infection equilibrium point constraint condition is used to indicate that the rate of change of the number of hosts in the target infection state over time is 0.
[0036] Based on the infection equilibrium point constraint, the infection state corresponding to each host, and each of the infection constraints except for the host number change rate constraint corresponding to the target infection state, the infection equilibrium point of the target network corresponding to the target infection state is obtained.
[0037] In one embodiment, the third determining module is further configured to:
[0038] For any of the aforementioned hosts, determine the number of infections corresponding to the infection equilibrium point for that host, where the number of infections is the number of times the host transitions from an uninfected state to an infected state when it reaches the infection equilibrium point;
[0039] The infection loss of each host is determined based on its initial value, the number of infections, and the loss per infection.
[0040] In one embodiment, the device further includes:
[0041] The fourth determining module is used to determine the average infection loss and the variance of infection loss of the target network based on the infection loss of each host.
[0042] The fifth determining module is used to determine the expected loss repair resources for hosts in the target network based on the average infection loss, the variance of infection loss, and a preset security factor.
[0043] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement any of the methods described above.
[0044] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements any of the above methods.
[0045] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements any of the above methods.
[0046] The aforementioned method, apparatus, computer equipment, storage medium, and computer program product for determining host infection loss construct infection constraints corresponding to the target network based on the communication relationships between hosts and the probability of each host transitioning between different infection states. Furthermore, it calculates the infection equilibrium point based on these constraints and then calculates the infection loss of each host at the infection equilibrium point. Therefore, it can predict when the target network will reach the infection equilibrium point based on the actual situation of the target network, and further determine the infection loss based on the actual situation of each host in the target network at the infection equilibrium point, thereby improving the accuracy of host infection loss estimation. Attached Figure Description
[0047] Figure 1 This is a flowchart illustrating a method for determining host infection loss in one embodiment;
[0048] Figure 2 This is a flowchart illustrating step 104 in one embodiment;
[0049] Figure 3 This is a schematic diagram illustrating the transition between different infection states in one embodiment;
[0050] Figure 4 This is a schematic diagram of the target network in one embodiment;
[0051] Figure 5 This is a flowchart illustrating step 108 in one embodiment;
[0052] Figure 6 This is a flowchart illustrating the process of determining expected loss repair resources in one embodiment;
[0053] Figure 7 This is a structural block diagram of a host infection loss determination device in one embodiment;
[0054] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0056] In one embodiment, such as Figure 1 As shown, a method for determining host infection loss is provided. This embodiment illustrates the method by applying it to a server; however, it is understood that the method can also be applied to a terminal, or to a system including both a terminal and a server, and is implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0057] Step 102: Determine the infection status of each host in the target network and the communication relationship between each host.
[0058] In this embodiment, the target network can be an undivided network or divided into multiple subnets. Each host is a host within the target network. The infection status of each host can be set by those skilled in the art based on the actual situation of the target network. For example, the infection status can include at least an uninfected state (the host is not infected with malware) and an infected state (the host is infected with malware). Depending on the different circumstances of the target network, it can also include a protected state (the host has security software installed, reducing the probability of infection), a monitoring state (monitoring the infected host, giving it a certain probability of being repaired), and an immune state (the infected host will not be infected with malware again after being repaired), etc. This embodiment does not specifically limit these states.
[0059] A communication relationship between two hosts means that these two hosts can communicate with each other, and they may even exchange malware through this communication. If analyzing a specific target network, the actual communication status of each host in the target network can be obtained, which serves as the communication relationship between the hosts. If analyzing an unspecified target network, the target network can be modeled as a scale-free network, meaning the connectivity distribution of network nodes follows a power-law distribution, and the communication relationships between hosts can be set based on the connectivity of network nodes in a scale-free network.
[0060] After obtaining the infection status and communication relationships between each host, the target network can be represented as a graph. Nodes in the graph represent hosts, edges between nodes represent communication relationships between hosts, and the edge value represents the probability that a host will become infected through that communication relationship. After constructing the graph, the adjacency matrix can also be obtained, facilitating subsequent calculation of the infection equilibrium point.
[0061] Step 104: Based on the communication relationships between hosts and the probability of each host switching between different infection states, construct the infection constraints corresponding to the target network.
[0062] In this embodiment, the probability of a host switching between different infection states can be set by those skilled in the art according to actual needs. For example, when the infection states include uninfected and infected states, it can be set that a host in an uninfected state, upon contact with another host in an infected state, has... The probability of being infected, that is, the probability of transitioning from an uninfected state to an infected state, is... It can also be configured to detect malware on infected hosts. The probability of being eliminated, that is, the probability of transitioning from an infected state to an uninfected state, is... When other infection states exist, those skilled in the art can also set the probability of transitioning between other infection states according to actual needs.
[0063] Infection constraints refer to the conditions that malware must meet to spread within a target network. For example, infection constraints may include a total host count constraint, which states that at any given time, the sum of the number of hosts in different infection states within the target network is equal to the original number of hosts in the target network. Infection constraints may also include a host count change rate constraint for each infection state, which represents the rate at which the number of hosts in an infected state changes over time. For instance, when infection states include uninfected and infected states, the host count change rate constraint for the infected state can be set to the product of the probability of transitioning from an uninfected state to an infected state and the number of hosts in the uninfected state.
[0064] In one embodiment, such as Figure 2 As shown, when the infection state includes at least an uninfected state and an infected state, the probability of a host transitioning from an uninfected state to an infected state is used to represent the probability of a host transitioning from an uninfected state to an infected state when a host with a communication relationship with the host is in an infected state. Based on the communication relationships between hosts and the probabilities of transitioning between infection states, infection constraints corresponding to the target network are constructed, including:
[0065] Step 202: Construct contact probability constraints. Contact probability constraints are used to characterize the probability that a host in an uninfected state will communicate with a host in an infected state.
[0066] Step 204: Based on the probability of transitioning from an uninfected state to an infected state and the contact probability constraint, construct the host number change rate constraint for the infected state.
[0067] In this embodiment of the application, since the probability of a host changing from an uninfected state to an infected state when a host with a communication relationship with the host is in an infected state is also related to the probability of the host coming into contact with the infected host, when constructing the constraint condition for the rate of change of the number of hosts in the infected state, the contact probability constraint condition can be constructed first, and then the constraint condition for the rate of change of the number of hosts in the infected state can be constructed based on the probability of changing from an uninfected state to an infected state and the contact probability constraint condition.
[0068] Since the more hosts a given host can communicate with, the lower the probability that a given host will come into contact with an infected host after that host has a communication relationship with it is infected, the contact probability constraint can be related to the number of hosts a given host can communicate with. As shown in Formula (I):
[0069] Formula (1)
[0070] in, This refers to the probability that at time t, a host in an uninfected state (this host) and a host in an infected state come into contact. This is the number of hosts that this host can communicate with. It is the number of infected hosts in the target network that are capable of communication (i is the number of hosts in the target network), where n is the maximum value of the number of communicable hosts i in the target network. It is the probability that a host with an i number of communicable hosts will communicate with this host.
[0071] Therefore, the constraint on the rate of change of the number of infected hosts can be: the rate of change of the number of infected hosts is equal to the product of the probability of a host transitioning from an uninfected state to an infected state, the contact probability constraint, and the number of hosts in an uninfected state. See Formula (II):
[0072] Formula (II)
[0073] in, This refers to the number of hosts in the target network that are uninfected and capable of communication, with a total number of hosts of number i.
[0074] It should be noted that, as the number of hosts in the infected state increases when hosts transition from an uninfected state to an infected state, the number of hosts in the uninfected state will decrease accordingly. Therefore, without considering the possibility of infected hosts transitioning to an uninfected state, the constraint on the rate of change of the number of hosts in the uninfected state can be: the rate of change of the number of hosts in the uninfected state is equal to the negative probability of a host transitioning from an uninfected state to an infected state.
[0075] In one embodiment, the infection status also includes a protective status, a monitoring status, and an immune status;
[0076] The probability of transitioning from an uninfected state to a protected state represents the probability that a vulnerability in an uninfected host will be patched by security software; the probability of transitioning from a protected state to an infected state represents the probability that malware will break through security software protection and exploit vulnerabilities; and the probability of transitioning from a protected state to an uninfected state represents the probability that security software will successfully combat malware.
[0077] The probability of transitioning from an uninfected state to a monitored state represents the probability that a host in an uninfected state will be monitored; the probability of transitioning from an infected state to a monitored state represents the probability that a host in an infected state will be monitored; and the probability of transitioning from a monitored state to an immune state represents the probability that a host in a monitored state will become immune to malware attacks by patching.
[0078] The probability of transitioning from an immune state to an uninfected state is used to represent the probability that a patch on a host in an immune state will fail.
[0079] In this embodiment, three new infection states are defined to represent the states of common hosts in the network when combating malware: protected state, monitored state, and immune state. The protected state indicates that an uninfected host has security software installed, which can prioritize the detection and patching of vulnerabilities that malware may exploit. In other words, a host in the protected state is a host with a certain level of protection. Correspondingly, in this embodiment, the uninfected state in the aforementioned embodiments is defined as a host that does not have security software installed and can be infected by malware exploiting vulnerabilities.
[0080] The monitoring status indicates that the monitoring software on the network has been monitoring the host, and the monitoring software has a certain probability of making the host immune through methods such as antivirus removal and patching.
[0081] An immune status indicates that a host is not infected by malware, but patches have a certain probability of failing, causing an immune host to revert to an uninfected status.
[0082] In one embodiment, the target network includes at least two subnets. When hosts in different subnets communicate with each other, the probability of a host transitioning from an uninfected state to an infected state is different from the probability of a host transitioning from an uninfected state to an infected state when hosts in the same subnet communicate with each other.
[0083] In this embodiment of the application, in order to better reflect the real-world network situation, different probabilities of transitioning from an uninfected state to an infected state can be set for communication between different subnets and communication between the same subnet. This is because communication between different subnets generally requires passing through a gateway, and some subnets also need to use different communication protocols when communicating. Therefore, the probability of malware spreading between different subnets is generally lower than the probability of malware spreading between the same subnet.
[0084] The following describes the infection status, which includes the aforementioned five infection states (uninfected, protected, infected, monitored, and immune). The target network has two subnets: Subnet A and Subnet B (see diagram). Figure 4Taking a target network as an example, here is a sample of various infection constraints. The parameters in the infection constraints are shown in Table 1 below:
[0085] Table 1
[0086]
[0087] The degree value refers to the number of hosts in different subnets that have communication relationships with this host. A degree value of (i, j) means that this host is located in subnet A, the number of hosts in subnet A that have communication relationships with this host is i, and the number of hosts in subnet B that have communication relationships with this host is j. Similarly, a degree value of (k, l) means that this host is located in subnet B, the number of hosts in subnet A that have communication relationships with this host is k, and the number of hosts in subnet B that have communication relationships with this host is l. Based on the above parameters, the constraint condition for the rate of change of the number of hosts for each infection state can be constructed in the following formula (III). A schematic diagram of the mutual conversion between each infection state can also be found in [reference missing]. Figure 3 :
[0088] Formula (3)
[0089] The basic principle of formula (III) above is that the rate of change of the number of hosts corresponding to a certain infection state is equal to the sum of the rate of change of other infection states to the current infection state and the rate of change of the current infection state to other infection states. Wherein, (m and n are either A or B) refers to the contact probability constraint between a host in subnet m and a host in subnet n, see formula (IV):
[0090] Formula (IV)
[0091] in, (m and n are either A or B) refers to the number of hosts in subnet n that have communication relationships with this host when this host is in subnet m. It is the maximum value of degree i in subnet A, and similarly. It is the maximum value of j. It is the maximum value of k. It is the maximum value of l. This is the probability that a host with a degree value of (i, j) will communicate with this host located in subnet A. The meanings of other parameters are similar and will not be repeated in this embodiment.
[0092] Based on formula (III) above, a constraint on the total number of hosts can be added, namely, the total number of hosts in subnet A remains unchanged, the total number of hosts in subnet B remains unchanged, and the degree value of the hosts also remains unchanged. See formula (V):
[0093] Formula (5)
[0094] in, This is the total number of hosts in subnet A. This refers to the total number of hosts in subnet A with a degree value of (i, j). The meanings of other parameters follow the same logic.
[0095] Step 106: Based on the infection status and infection constraints of each host, solve for the infection equilibrium point of the target network corresponding to the target infection status.
[0096] In this embodiment, the initial infection state of each host is substituted into the infection constraints, and after solving each infection constraint, the infection equilibrium point corresponding to a certain target infection state can be obtained. The infection equilibrium point is the point in time when the number of hosts in the target infection state no longer changes, or the point in time when the number of hosts in the target infection state no longer changes and the number of hosts in the target infection state reaches a preset number. For example, when the infection equilibrium point to be solved is the "sickness equilibrium point," it is the point in time when the number of hosts in the infected state no longer changes. When the infection equilibrium point to be solved is the "no-sickness equilibrium point," it is the point in time when the number of hosts in the infected state no longer changes and the number of hosts in the infected state is 0.
[0097] In one embodiment, where the infection constraints include at least a constraint on the rate of change of the number of hosts for each infection state, the infection equilibrium point can be obtained by solving for it in the following manner:
[0098] Based on the constraint of the rate of change of the number of hosts corresponding to the target infection state, an infection equilibrium point constraint is constructed for the target infection state. The infection equilibrium point constraint is used to indicate that the rate of change of the number of hosts in the target infection state over time is 0.
[0099] Based on the infection equilibrium point constraints, the infection states corresponding to each host, and all infection constraints except for the constraint on the rate of change of the number of hosts corresponding to the target infection state, the infection equilibrium point of the target network corresponding to the target infection state is obtained.
[0100] In this embodiment of the application, when it is necessary to solve for the infection equilibrium point corresponding to the target infection state, the infection equilibrium point constraint condition for the target infection state can be constructed first based on the host number change rate constraint condition corresponding to the target infection state, that is, the host number change rate in the target infection state is 0. For example, when using the infection constraint condition shown in formula (III), if it is necessary to solve for the infection equilibrium point (sick equilibrium point) corresponding to the infected state of the target network, the value on the left side of the host number change rate constraint condition corresponding to the infected state can be set to 0 to indicate that the host number change rate in the infected state is 0, thus obtaining the infection equilibrium point constraint condition for the infected state.
[0101] Furthermore, by substituting the initial infection states of each host into the various other infection constraints and infection equilibrium point constraints, the infection constraints and infection equilibrium point constraints can be solved. If a valid solution is successfully obtained, it indicates that the target infection state has a corresponding infection equilibrium point, and the solution result is the infection equilibrium point. If a valid solution cannot be obtained, it indicates that the target infection state does not have a corresponding infection equilibrium point.
[0102] In one embodiment, the above method further includes:
[0103] Based on the probability of each host transitioning between different infection states, the transition matrix of the target network is constructed.
[0104] Based on the preset new infection matrix and transfer matrix, the regeneration matrix of the target network is determined. The basic regeneration number is determined based on the characteristic spectrum of the regeneration matrix. Based on the basic regeneration number, the stable trend of the disease-free equilibrium point of the target network is determined.
[0105] In this embodiment, the possibility of the target network reaching a disease-free equilibrium point can be determined by referring to epidemiological concepts. A transition matrix for the target network can be constructed based on the probability of each host transitioning between different infection states. The new infection matrix is constructed based on the probability that an uninfected host becomes infected without contacting an infected host. This probability can be preset.
[0106] The regeneration matrix can be determined based on the new infection matrix and the transfer matrix, see formula (VI):
[0107] Formula (VI)
[0108] in, F is the regeneration matrix, and F is the new infection matrix. It is the transition matrix.
[0109] The fundamental reproduction number can be obtained from the characteristic spectrum of the reproduction matrix, that is... .when When <1, the target network may reach a disease-free equilibrium point. When the value is greater than 1, the target network cannot stably maintain a disease-free equilibrium state.
[0110] Step 108: Determine the infection loss of each host based on the infection status transition at the corresponding infection equilibrium point of each host.
[0111] In this embodiment, the infection loss of the host can be analyzed based on the infection state transition at the infection equilibrium point. For example, when the infection state includes an uninfected state, a protected state, and an infected state, the resource overhead of the security software when the host transitions from an uninfected state to a protected state can be set to 'a', and the information loss of the host when the host transitions from an uninfected state to an infected state, or from a protected state to an infected state, can be set to 'b'. Then, based on the number of times the host transitions from an uninfected state to a protected state, from an uninfected state to an infected state, and from a protected state to an infected state when reaching the infection equilibrium point, as well as the losses caused by transitioning between different infection states, the infection loss of the host can be determined.
[0112] In one embodiment, such as Figure 5 As shown, the infection loss of each host is determined based on the infection state transition at the infection equilibrium point of each host, including:
[0113] Step 502: For any host, determine the number of infections at the infection equilibrium point corresponding to the host. The number of infections is the number of times the host changes from an uninfected state to an infected state when it reaches the infection equilibrium point.
[0114] Step 504: Determine the infection loss of each host based on its initial value, number of infections, and loss per infection.
[0115] In this embodiment, the analysis focuses on the number of times a host transitions from an uninfected state to an infected state. A simulation model can be constructed based on the infection constraints of the aforementioned embodiments. By simulating the infection state transitions of each host in the target network from the initial moment to the infection equilibrium point, the number of infections at the corresponding infection equilibrium point for each host can be calculated.
[0116] The initial value of a host can be proportional to the number of other hosts it communicates with, because a host is generally more important when it can communicate with more hosts. The loss from a single infection can be related to the direct loss of information due to infection and the time required to recover from the infected state. See Equation (VII):
[0117] Formula (VII)
[0118] in, This represents the infection loss at the infection equilibrium point corresponding to host i. It is the number of infections on host i. This refers to the loss from a single infection, among which It is the direct loss from the mth infection. It is the indirect loss from the mth infection.
[0119] The direct losses from infection can be modeled using stochastic costs. These stochastic costs can be related to the initial value of the host, as shown in Equation (8):
[0120] Formula (8)
[0121] in The direct cost of loss caused by malware. It is a function of x, where x is the information loss of host i. This is the initial value of the host. B(a,b) is the Beta function, B(a,b) = ,in , a, b>0. Formula (8) assumes that the ratio of information loss to initial value follows a Beta distribution, and that the initial value is independent of the direct loss from infection.
[0122] Initial value reference formula (IX):
[0123] Formula (IX)
[0124] in, is a coefficient, and k is the number of other hosts that have a communication relationship with this host.
[0125] Indirect losses from infection are positively correlated with the host recovery time. See Formula (10):
[0126] Formula (10)
[0127] in, It is the value that the host could have generated during the recovery period. It is the recovery time cost rate. It is a coefficient, and k is the number of other hosts that have communication relationships with this host (assuming that the value generated by the host is proportional to the number of hosts that the host can communicate with). It refers to the recovery time. This is used to correlate the indirect losses from infection with the initial value of the host. It is the initial cost rate.
[0128] Therefore, the total infection loss of all hosts in the target network can be seen in formula (XI):
[0129] Formula (XI)
[0130] Where N is the total number of hosts in the target network, and M is a parameter used to simulate the additional losses to the target network caused by host infection, in addition to the infection loss of each host.
[0131] In one embodiment, such as Figure 6 As shown, the above method also includes:
[0132] Step 602: Determine the average infection loss and variance of the target network based on the infection loss of each host;
[0133] Step 604: Determine the expected loss repair resources for hosts in the target network based on the average infection loss, the variance of infection loss, and the preset security factor.
[0134] In this embodiment, based on the infection loss of the hosts calculated in the foregoing embodiments, the estimated resource requirements for repairing each host in the target network can be determined. This allows the server to reserve these resources for host repair while simultaneously enabling the server to utilize other resources to perform other services. The estimated expected loss repair resources should have a certain margin beyond covering the host infection loss to avoid a situation where the reserved expected loss repair resources are less than the actual infection loss, thus affecting host repair.
[0135] This application embodiment uses the average infection loss as the repair resources reserved by the server for each host. The product of a preset security factor and the variance of the infection loss is used as the margin reserved by the server. Therefore, the expected loss repair resources are the sum of the products of the average infection loss and the preset security factor and the variance of the infection loss, as shown in formula (XII):
[0136] Formula (12)
[0137] in, It is the expected loss of resources to repair. This is the average value of infection loss. It is a preset safety factor. It is the variance of infection loss.
[0138] The above method, besides being applied when server resources are reserved for host repair, can also be used when insurance companies set premiums for target networks. In this case... The premium is set by the insurance company. By setting premiums for the target network using the above method, the insurance company's pricing can better reflect actual risks, while ensuring that both direct and indirect losses are reasonably covered within the insurance coverage.
[0139] The host infection loss determination method provided in this application constructs infection constraints for the target network based on the communication relationships between hosts and the probability of each host transitioning between different infection states. It then calculates the infection equilibrium point based on these constraints and further calculates the infection loss of each host at that equilibrium point. Therefore, it can predict when the target network will reach the infection equilibrium point based on the actual situation of the target network, and further determine the infection loss based on the actual situation of each host in the target network at the infection equilibrium point, thereby improving the estimation accuracy of host infection loss.
[0140] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0141] Based on the same inventive concept, this application also provides a host infection loss determination apparatus for implementing the host infection loss determination method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more embodiments of the host infection loss determination apparatus provided below can be found in the limitations of the host infection loss determination method described above, and will not be repeated here.
[0142] In one embodiment, such as Figure 7 As shown, a host infection loss determination device 700 is provided, including: a first determination module 702, a construction module 704, a second determination module 706, and a third determination module 708, wherein:
[0143] The first determining module 702 is used to determine the infection status of each host in the target network and the communication relationship between each host.
[0144] The construction module 704 is used to construct the infection constraints corresponding to the target network based on the communication relationship between the hosts and the probability of the hosts switching between infection states.
[0145] The second determining module 706 is used to solve for the infection balance point of the target network corresponding to the target infection state based on the infection state of each host and the infection constraint conditions.
[0146] The third determining module is used to determine the infection loss of each host based on the infection state transition of each host corresponding to the infection equilibrium point.
[0147] In one embodiment, the infection constraint includes at least a host number change rate constraint for each infection state, the host number change rate constraint representing the rate at which the number of hosts in the infection state changes over time.
[0148] In one embodiment, the infection state includes at least an uninfected state and an infected state, and the probability of the host transitioning from the uninfected state to the infected state is used to represent the probability that the host transitions from the uninfected state to the infected state when a host with which it has a communication relationship is in the infected state.
[0149] The building module 704 is also used for:
[0150] A contact probability constraint is constructed, which is used to characterize the probability that the host in an uninfected state communicates with the host in an infected state.
[0151] Based on the probability of transitioning from the uninfected state to the infected state and the contact probability constraint, a constraint on the rate of change of the number of hosts in the infected state is constructed.
[0152] In one embodiment, the second determining module 706 is further configured to:
[0153] Based on the constraint condition of the rate of change of the number of hosts corresponding to the target infection state, an infection equilibrium point constraint condition is constructed for the target infection state. The infection equilibrium point constraint condition is used to indicate that the rate of change of the number of hosts in the target infection state over time is 0.
[0154] Based on the infection equilibrium point constraint, the infection state corresponding to each host, and each of the infection constraints except for the host number change rate constraint corresponding to the target infection state, the infection equilibrium point of the target network corresponding to the target infection state is obtained.
[0155] In one embodiment, the third determining module 708 is further configured to:
[0156] For any of the aforementioned hosts, determine the number of infections corresponding to the infection equilibrium point for that host, where the number of infections is the number of times the host transitions from an uninfected state to an infected state when it reaches the infection equilibrium point;
[0157] The infection loss of each host is determined based on its initial value, the number of infections, and the loss per infection.
[0158] In one embodiment, the device further includes:
[0159] The fourth determining module is used to determine the average infection loss and the variance of infection loss of the target network based on the infection loss of each host.
[0160] The fifth determining module is used to determine the expected loss repair resources for hosts in the target network based on the average infection loss, the variance of infection loss, and a preset security factor.
[0161] Each module in the above-mentioned device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0162] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a method for determining host infection loss.
[0163] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0164] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0165] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0166] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0167] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0168] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0169] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0170] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for determining host infection loss, characterized in that, The method includes: Determine the infection status of each host in the target network, as well as the communication relationships between the hosts; Based on the communication relationships between the hosts and the probability of each host switching between infection states, infection constraints corresponding to the target network are constructed. Based on the infection status of each host and the infection constraints, the infection equilibrium point of the target network corresponding to the target infection status is obtained. The infection loss of each host is determined based on the infection state transition at the infection equilibrium point corresponding to each host.
2. The method according to claim 1, characterized in that, The infection constraints include at least a host number change rate constraint for each infection state, the host number change rate constraint representing the rate at which the number of hosts in the infection state changes over time.
3. The method according to claim 2, characterized in that, The infection state includes at least an uninfected state and an infected state. The probability of the host transitioning from the uninfected state to the infected state is used to represent the probability that the host transitions from the uninfected state to the infected state when a host with which it has a communication relationship is in the infected state. The step of constructing infection constraints corresponding to the target network based on the communication relationships between the hosts and the probability of each host transitioning between infection states includes: A contact probability constraint is constructed, which is used to characterize the probability that the host in an uninfected state communicates with the host in an infected state. Based on the probability of transitioning from the uninfected state to the infected state and the contact probability constraint, a constraint on the rate of change of the number of hosts in the infected state is constructed.
4. The method according to claim 2, characterized in that, The step of solving for the infection equilibrium point of the target network corresponding to the target infection state based on the infection state of each host and the infection constraints includes: Based on the constraint condition of the rate of change of the number of hosts corresponding to the target infection state, an infection equilibrium point constraint condition is constructed for the target infection state. The infection equilibrium point constraint condition is used to indicate that the rate of change of the number of hosts in the target infection state over time is 0. Based on the infection equilibrium point constraint, the infection state corresponding to each host, and each of the infection constraints except for the host number change rate constraint corresponding to the target infection state, the infection equilibrium point of the target network corresponding to the target infection state is obtained.
5. The method according to claim 1, characterized in that, The step of determining the infection loss of each host based on the infection state transition at the infection equilibrium point of each host includes: For any of the aforementioned hosts, determine the number of infections corresponding to the infection equilibrium point for that host, where the number of infections is the number of times the host transitions from an uninfected state to an infected state when it reaches the infection equilibrium point; The infection loss of each host is determined based on its initial value, the number of infections, and the loss per infection.
6. The method according to claim 1, characterized in that, The method further includes: Based on the infection loss of each host, determine the average infection loss and the variance of infection loss of the target network; Based on the average infection loss, the variance of infection loss, and the preset safety factor, the expected loss repair resources for hosts in the target network are determined.
7. A device for determining host infection loss, characterized in that, The device includes: The first determining module is used to determine the infection status of each host in the target network, as well as the communication relationship between the hosts. A construction module is used to construct infection constraints corresponding to the target network based on the communication relationships between the hosts and the probability of each host switching between infection states. The second determining module is used to solve for the infection balance point of the target network corresponding to the target infection state based on the infection state of each host and the infection constraints. The third determining module is used to determine the infection loss of each host based on the infection state transition of each host corresponding to the infection equilibrium point.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Network risk control method based on microstate prediction
CN106411904A
Method and device for executing network security policy, and electronic equipment
CN115460608A