A complex network defense system robustness verification method

By constructing a defense structure and attack-defense matrix for a complex network defense system, and combining self-learning and adaptive evolution processes, the robustness of the system was verified, solving the problem of lack of theoretical verification in existing technologies and improving the security and stability of the system.

CN119561760BActive Publication Date: 2025-12-05CHINA UNIV OF PETROLEUM (EAST CHINA)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411736362.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-12-05
Estimated Expiration
2044-11-29

AI Technical Summary

Technical Problem

Existing technologies have failed to theoretically prove the robustness of complex network defense systems. They mainly focus on the analysis of the system's defense technologies and strategies, but lack methods for verifying the system's robustness.

Method used

Construct a defense structure for a complex network defense system, determine the matrix of server, defense strategy, and attack strategy, calculate the defense benefits through the interaction strategies of the attacker and defender, design a self-learning and adaptive evolutionary process, and verify the robustness of the system.

Benefits of technology

Through self-learning and adaptive evolution, complex network defense systems can periodically adjust their defense strategies, reducing the difficulty of prediction for attackers and improving the security and stability of the system, thus demonstrating their robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561760B_ABST
    Figure CN119561760B_ABST
Patent Text Reader

Abstract

The application belongs to the field of network security, and relates to a complex network defense system robustness verification method, which comprises the following steps: constructing a complex network defense system defense structure; determining a service end matrix, a defense strategy matrix and an attack strategy matrix of an attack party of the complex network defense system; determining the defense benefit of the complex network defense system when the attack and defense parties interact with each other; obtaining an evolved defense strategy matrix and a defense strategy transition probability matrix according to the characteristics of the complex network defense system; obtaining an attack strategy matrix and an attack strategy transition prediction probability matrix of the attack party according to the characteristics of the complex network defense system; calculating the benefit of the complex network defense system opening a real service in each period; calculating the expected energy consumption of the complex network defense system in each period; calculating the service quality of the complex network defense system in each period; calculating the energy consumption of the complex network defense system switching the true and false service attributes in each period; calculating the total benefit of the complex network defense system in each period; and analyzing the robustness of the system according to the total benefit of the complex network defense system. The complex network defense system is verified to have the robustness by the design theory method, the robust defense system can meet the actual security requirements of the complex network system, and the defense ability of the system against malicious network attacks is significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security and relates to a method for verifying the robustness of complex network defense systems. Background Technology

[0002] With the development and popularization of computer network technology, the Internet has increasingly integrated into various fields such as military, government, and industry, leading the global trend of informatization. At the same time, the massive increase in network device nodes has brought severe security challenges to complex network systems. Due to their highly complex network structures, complex network systems are easily affected by varied and disordered malicious network attacks, making the systems vulnerable. Therefore, proactive network defense technologies are gradually being applied to complex network defense systems to resist attack threats.

[0003] The basic idea of ​​proactive network defense technology is to increase the attacker's cost by dynamically changing and disguising the characteristics of the target network system, thereby improving the target system's security defense capabilities. Network deception technology is a typical example of proactive network defense. This technology is usually deployed across multiple collaborative hosts, periodically switching between real and fake service defense strategies deployed on these hosts to increase attacker uncertainty and mislead them into misinterpreting the situation. Therefore, when complex network systems are subjected to malicious attacks, network deception technology can help reduce the impact of vulnerabilities and improve the system's security and stability.

[0004] Robustness refers to a system's ability to maintain stable and reliable performance in the face of changes in the internal and external environment, parameter disturbances, and interference from external factors. The characteristics of a robust system are mainly reflected in fault tolerance, adaptability, redundancy, and stability. A complex network defense system based on network deception technology has multiple servers, each deploying various services with both real and fake attributes. Even if the defense measures are detected by the attacker, the complex network defense system can still provide services normally through other hosts and evolve its own defense strategy through self-learning and self-adaptation. It then periodically adjusts its real and fake service defense strategy, making it difficult for attackers to predict the system's deployed defense measures, thereby reducing the impact of system vulnerability. Therefore, a complex network defense system based on network deception technology is a robust system, capable of maintaining secure and stable operation when subjected to attack threats. However, current research on the robustness of complex network defense systems mainly focuses on the system's defense technologies, defense strategies, and types of attacks. These studies analyze the system's robustness at the technical level but do not consider how to theoretically prove the system's robustness. Therefore, based on the characteristic design theory and method of complex network defense systems, and by analyzing the benefits of complex network defense systems during the attack and defense process, we prove that complex network defense systems possess robust properties. Summary of the Invention

[0005] This invention provides a robustness verification method for a complex network defense system, comprising: constructing the defense structure of the complex network defense system; determining the server matrix, defense strategy matrix, and attacker's attack strategy matrix of the complex network defense system; determining the defense benefits of the complex network defense system when the attacker and defender interact; obtaining an evolved defense strategy matrix and a defense strategy transition probability matrix based on the characteristics of the complex network defense system; obtaining the attacker's attack strategy matrix and attack strategy transition prediction probability matrix based on the characteristics of the complex network defense system; calculating the benefits of enabling real services in the complex network defense system each cycle; calculating the expected energy consumption of the complex network defense system each cycle; calculating the service quality of the complex network defense system each cycle; calculating the energy consumption of switching between real and fake service attributes in the complex network defense system each cycle; calculating the total benefits of the complex network defense system each cycle; and analyzing the robustness of the system based on the total benefits of the complex network defense system. This invention designs theoretical methods to verify that the complex network defense system possesses robust properties. A robust defense system can meet the actual security requirements of complex network systems and significantly improve the system's ability to defend against malicious network attacks.

[0006] The technical solution adopted by this invention to solve its technical problem is as follows:

[0007] A robustness verification method for a complex network defense system, the method comprising the following steps:

[0008] a. Constructing a complex network defense system's defense structure

[0009] The complex network defense system has the following structure: it deploys n servers, where n is a positive integer, and each server is represented as server_server. i Let i ∈ [1, n], where each server can provide m types of services, where m is a positive integer, and each service is represented as service. j ,j∈[1,m], and each service has two attributes: real and fake. By periodically switching between real and fake service attributes, attackers are deceived, thereby improving the system's security defense capabilities.

[0010] b. Determine the server matrix SP of the complex network defense system n×m Defense Strategy Matrix DS n×m and the attacker's attack strategy matrix AS n×m Among them, the server-side matrix SP n×m Each element SP ij Indicates server i The service provided j Service, Defense Strategy Matrix DS n×m Each element DS ij Indicates the server-side SP ijThe defensive strategy adopted by DS ij ∈ B, Attack strategy matrix AS n×m Each element AS ij This indicates that the attacker is targeting the server's SP. ij attack strategies, AS ij ∈ B, B = {0, 1} is a Boolean set, DS ij =1 indicates SP ij Provide real service, DS ij =0 indicates SP ij Providing fake services, AS ij =1 indicates that the attacker is attacking SP. ij AS ij =0 indicates that the attacker does not attack SP. ij ;

[0011] c. Determining the defensive benefits of complex network defense systems when considering the interactions between attackers and defenders.

[0012] The interaction between the attacker and defender is as follows: during the interaction between the attacker and defender, on the server-side SP... ij Interaction strategy on DS ij AS ij There are 4 categories, and each interaction strategy is represented by type. l According to the attacking and defending sides in SP ij SP during interaction ij The defense benefit of the complex network defense system in the current period t is calculated based on the defense benefit:

[0013]

[0014] Where l∈[1,4] represents the interaction strategy type, and the four interaction strategies are represented by type1 (DS) ij AS ij ) = (0,0), type2 represents (DS) ij AS ij ) = (1,0), type3 represents (DS) ij AS ij ) = (0,1) and type4 represents (DS) ij AS ij )=(1,1),u l This indicates that both the attackers and defenders are at each SP ij When SP executes the type l interaction strategy ij The defensive benefits, r l t This represents the SP (Special Principle) in which both the attacker and defender execute the l-th type of interaction strategy during the current period t. ij quantity;

[0015] d. Obtain the evolutionary defense strategy matrix DS based on the characteristics of complex network defense systems. t+1 and the defense strategy transition probability matrix P t

[0016] The evolutionary defense strategy matrix DS t+1 The complex network defense system adjusts the defense strategy matrix DS for the current period t based on the network environment, the obtained defense benefit information, and the strategy information of both the attacker and defender. t The process involves self-learning and adaptive evolution to obtain the evolutionary defense strategy matrix for the next cycle t+1. The adaptive strategy adjustment process is reflected in the server-side matrix SP of the system in the current period t. n×m Defense strategy transition probability matrix P t , represented as Then the defense strategy transition probability matrix P t Each element This indicates that in the current period t, each server SP ij The probability of switching defensive strategies on the surface is expressed as

[0017]

[0018] Among them, P t-1 For the previous period t-1 system in the server matrix SP n×m The defense strategy transition probability matrix, P t-1 Each element This indicates that in the previous period t-1, each server SP ij The function F is the strategy adjustment function, which takes a probability value as input. If the probability value is used as input, the output is 1; otherwise, the output is 0. The function H is the defense strategy transition probability function, and the function sgn is the sign function.

[0019] e. Obtain the attacker's attack strategy matrix AS based on the characteristics of complex network defense systems. t+1 and attack strategy transition prediction probability matrix * P t

[0020] The attack strategy matrix AS t+1 In the current period t, the attacker predicts the defense strategy matrix DS for the current period t by analyzing the historical changes in the defender's defense strategies. t Therefore, the attack strategy matrix for the next cycle t+1 is formulated as follows. If the attacker obtains the attack strategy matrix for the next period t+1 through prediction, then the attack strategy transition prediction probability matrix for the current period t is: Where k∈[2,t] represents the k-th period, DSk Let DS be the defense strategy matrix for the k-th period. k-1 This is the defense strategy matrix for the (k-1)th period;

[0021] f. Calculate the benefit of enabling real services in the complex network defense system per cycle:

[0022]

[0023] Among them, u real For the system on each server SP ij Revenue from enabling real services For the server SP that starts real services in the system during the current period t ij Quantity, i.e. The server SP is responsible for executing the second type of interaction strategy between the attacking and defending sides in the current period t. ij quantity, The server SP is responsible for executing the fourth type of interaction strategy between the attacking and defending sides in the current period t. ij quantity;

[0024] g. Calculate the expected energy consumption of the complex network defense system per cycle:

[0025]

[0026] Here, the function ln is a penalty function used to reduce high... High system energy consumption due to value;

[0027] h. Calculate the service quality of the complex network defense system for each cycle:

[0028]

[0029] Among them, u reward For the system on each server SP ij The benefits of switching from fake services to real services For the previous cycle of server-side SP ij The fake service provided above becomes a real service in the current period t. ij quantity;

[0030] i. The energy consumption of a complex network defense system switching between true and false service attributes per cycle is:

[0031]

[0032] Among them, u punish For each server SP ij The penalty value for switching between real and fake service attributes, u punish >u reward , For the previous cycle of server-side SP ij The real service provided on the SP becomes a fake service in the current period t. ij quantity;

[0033] j. Calculate the total benefit of the complex network defense system per cycle:

[0034] k. Based on the robustness of the total benefit analysis of the complex network defense system, specifically, when threatened by malicious attacks, the complex network defense system periodically adjusts its defense strategy through a self-learning and adaptive evolutionary process, making it difficult for the attacker to predict the defense strategy, resulting in a decrease in attack benefits and an increase in the total benefit of the defense system, thus proving that the complex network defense system has robust properties.

[0035] This invention provides a robustness verification method for complex network defense systems, which has the following advantages compared with existing technologies:

[0036] This paper designs a robustness verification method for complex network defense systems. Based on the attack and defense process of complex network defense systems in reality, the method involves the attacker predicting the defense strategy by analyzing the changing patterns of the defender's defense strategy, and then formulating an attack strategy. The method also involves the complex network defense system periodically deploying defense strategies that better meet actual security needs through a self-learning and adaptive evolutionary process. As the attack and defense process progresses, it becomes increasingly difficult for the attacker to predict the defense strategy, leading to a decrease in attack gains and a gradual increase in the total gains of the defense system. This makes the complex network defense system robust, thereby improving its security and stability. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention, the present invention will be further described below with reference to the accompanying drawings and specific implementation schemes:

[0038] Figure 1 This is a flowchart of a robustness verification method for a complex network defense system. Detailed Implementation

[0039] To make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but this application is not limited to these embodiments.

[0040] This embodiment provides a method for robustness verification of a complex network defense system, the method comprising the following steps:

[0041] a. Constructing a complex network defense system's defense structure

[0042] In step a, a complex network defense system is constructed based on proactive network deception defense technology. Since proactive network deception defense technology refers to increasing the attacker's uncertainty by periodically switching between real and fake service defense strategies deployed on multiple collaborative hosts, the complex network defense system requires the deployment of n servers, where n is a positive integer. The specific number of servers n is determined by the system based on its own circumstances and costs. Each server is represented as 'server'. i Let i ∈ [1, n], where each server can provide m types of services, where m is a positive integer. The system determines the types m of services that the server provides based on its own situation, and each service is represented as service. j ,j∈[1,m], and each service has two attributes: real and fake. Complex network defense systems improve the security defense capabilities of the system by periodically switching between real and fake service attributes to deceive attackers.

[0043] b. Determine the server matrix SP of the complex network defense system n×m Defense Strategy Matrix DS n×m and the attacker's attack strategy matrix AS n×m

[0044] In step b, since the n servers deployed in the complex network defense system constructed in step a can each provide m types of services, the server matrix SP can be determined. n×m Defense Strategy Matrix DS n×m and the attacker's attack strategy matrix AS n×m Both are n x m matrices, where the server matrix SP n×m The element SP in the i-th row and j-th column ij That is, server-side SP ij Represents the i-th server. i The j-th type of service provided j Defense Strategy Matrix DS n×m Each element DS ij This indicates that the system has each server SP ij The defensive strategy adopted above, and the attack strategy matrix AS n×m Each element AS ij This indicates that the attacker targets each server SP. ij The attack strategy adopted, DS ij and AS ij The values ​​of DS are all Boolean sets B = {0, 1}. ij =1 indicates the server-side SP ij Provide real service, DS ij =0 indicates that the server-side SP ij Providing fake services, ASij =1 indicates that the attacker is attacking the server SP. ij Services provided, AS ij =0 indicates that the attacker does not attack the server-side SP. ij The services provided.

[0045] c. Determining the defensive benefits of complex network defense systems when considering the interactions between attackers and defenders.

[0046] In step c, in a real-world complex network defense system, the attacker and defender interact to compete for system resources. During this interaction, the server-side SP... ij Interaction strategy on DS ij AS ij There are 4 categories, and each interaction strategy is represented by type. l Among them, the first type of interaction strategy, type 1, is (DS) ij AS ij ) = (0,0), indicating that the attacker does not attack the server-side SP. ij The provided fake service, type 2 interaction strategy is (DS) ij AS ij ) = (1,0), indicating that the attacker does not attack the server SP. ij The real service provided, the third type of interaction strategy is (DS) ij AS ij ) = (0,1), indicating that the attacker is attacking the server SP. ij The provided fake services, the fourth type of interaction strategy is (DS) ij AS ij ) = (1,1), indicating that the attacker is attacking the server SP. ij The actual service provided depends on the SP provided by both the attacker and defender on the server side. ij During interaction, the server SP ij The defense benefits of a complex network defense system in the current period t are used to calculate the defense benefits. for:

[0047]

[0048] Where l∈[1,4] represents the interaction strategy type, u l This indicates that both the attacker and defender are on each server-side SP. ij When executing the type l interaction strategy, the server SP ij The defensive benefits, r l t This indicates that the server SP, representing the attacking and defending parties executing the l-th type of interaction strategy in the current period t. ij quantity.

[0049] d. Obtain the evolutionary defense strategy matrix DS based on the characteristics of complex network defense systems. t+1 and the defense strategy transition probability matrix P t

[0050] In step d, the complex network defense system possesses adaptive and self-learning characteristics. When the system is affected by disturbances such as attacks, it can adaptively adjust its own state. Specifically, the complex network defense system adjusts the defense strategy matrix DS for the current period t based on the network environment, the obtained defense benefit information, and the strategy information of both the attacker and defender. t Through a self-learning and adaptive evolutionary process, a more secure and reasonable evolutionary defense strategy matrix is ​​obtained for the next cycle t+1. Complex network defense systems can periodically and adaptively adjust their defense strategies to reduce the severe impact of malicious attacks on the system and ensure its safe and stable operation. The adaptive adjustment process of a complex network defense system is reflected in the server-side matrix SP of the system during the current period t. n×m Defense strategy transition probability matrix P t , represented as Then the defense strategy transition probability matrix P t Each element This indicates that in the current period t, each server SP ij The probability of switching defensive strategies is expressed as:

[0051]

[0052]

[0053] Among them, P t-1 For the previous period t-1 system in the server matrix SP n×m The defense strategy transition probability matrix, P t-1 Each element This indicates that in the previous period t-1, each server SP ij The function F is the strategy adjustment function, which takes a probability value as input. If the probability value is used as input, the output is 1; otherwise, the output is 0. The function H is the defense strategy transition probability function, and the function sgn is the sign function.

[0054] e. Obtain the attacker's attack strategy matrix AS based on the characteristics of complex network defense systems. t+1 and attack strategy transition prediction probability matrix * P t

[0055] In step e, based on the characteristics of attackers in real-world complex network defense systems, attackers can obtain system defense information through methods such as eavesdropping and scanning. Then, by analyzing the historical changes in the defender's defense strategies, the defense strategy matrix DS for the current period t is predicted. t Therefore, the attack strategy matrix for the next cycle t+1 is formulated as follows. If the attacker obtains the attack strategy matrix for the next period t+1 through prediction, then the attack strategy transition prediction probability matrix for the current period t is... * P t Represented as:

[0056]

[0057] Where k∈[2,t] represents the k-th period, and k=2 indicates that the attacker starts analyzing the defender's defense information from the 2nd period. DS k Let DS be the defense strategy matrix for the k-th period. k-1 This is the defense strategy matrix for the (k-1)th period.

[0058] f. Calculate the benefits of enabling real services in each cycle of the complex network defense system.

[0059] In step f, the provision of real services by the complex network defense system indicates that the system is functioning normally, meaning it can provide the necessary service resources to normal users. Therefore, the benefit of normal system operation is measured by calculating the benefit of enabling real services by the complex network defense system in the current period t. Represented as:

[0060]

[0061] Among them, u real For the system on each server SP ij Revenue from enabling real services For the server SP that starts real services in the system during the current period t ij Quantity, i.e. The server SP is responsible for executing the second type of interaction strategy between the attacking and defending sides in the current period t. ij quantity, The server SP is responsible for executing the fourth type of interaction strategy between the attacking and defending sides in the current period t. ij quantity.

[0062] g. Calculate the expected energy consumption of the complex network defense system per cycle.

[0063] In step g, the probability value of defense strategy transition in the complex network defense system. The larger the value, the more frequently the real and fake service attributes switch, which easily leads to excessive system power consumption and a higher probability of defense strategy shifting. This will cause the system's server SP ij The system is in a state of constantly switching between true and false service attributes, thereby reducing its evolutionary characteristics. By utilizing a penalty function, it is possible to suppress excessive system energy consumption while maintaining the system's evolutionary features. Therefore, the expected energy consumption of the complex network defense system in the current period t is... Represented as:

[0064]

[0065] Here, the function ln is a penalty function used to reduce high... The high system energy consumption is caused by the value.

[0066] h. Calculate the service quality of the complex network defense system for each cycle.

[0067] In step h, when the complex network defense system provides real services, the system can provide service resources to normal users and maintain normal operation. The server-side SP... ij If switching from fake services to real services can improve the service quality of the system, then in the current period t, the benefit of switching from fake services to real services can be used to calculate the service quality of the complex network defense system. t , represented as:

[0068]

[0069] Among them, u reward For the system on each server SP ij The benefits of switching from fake services to real services For the previous cycle of server-side SP ij The server SP that provides the fake service "0" transforms into the real service "1" in the current period t. ij quantity.

[0070] i. Calculate the energy consumption of a complex network defense system switching between real and fake service attributes per cycle.

[0071] In step i, based on the characteristics of complex network defense systems, the system periodically updates each server SP through an adaptive and self-learning evolutionary process. ij Switching between real and fake services, or vice versa, consumes system energy. Therefore, calculate the energy consumption E of the complex network defense system switching between real and fake service attributes during the current period t. a t Represented as:

[0072]

[0073] Among them, u punish For each server SP ij The penalty value for switching between real and fake service attributes, u punish >u reward , For the previous cycle of server-side SP ij The server SP that provides the real service "1" will change to the spurious service "0" in the current period t. ij quantity.

[0074] j. Calculate the total benefit of the complex network defense system per cycle:

[0075] k. Robustness of the system based on the total benefit analysis of complex network defense systems.

[0076] In step k, when threatened by malicious attacks, the complex network defense system periodically adjusts its defense strategy through a self-learning and adaptive evolutionary process, making it difficult for attackers to predict the defense strategy, resulting in a decrease in attack benefits and an increase in the total benefits of the defense system, thus proving that the complex network defense system has robust properties.

Claims

1. A robustness verification method for a complex network defense system, characterized in that, Includes the following steps: a. Construct a complex network defense system architecture. Specifically, the complex network defense system deploys n servers, where n is a positive integer, and each server is represented as server. i Let i ∈ [1, n], where each server can provide m types of services, where m is a positive integer, and each service is represented as service. j ,j∈[1,m], and each service has two attributes: real and fake; b. Determine the server matrix SP of the complex network defense system n×m Defense Strategy Matrix DS n×m and the attacker's attack strategy matrix AS n×m Among them, SP n×m Each element SP ij Indicates server i The service provided j Service, DS n×m Each element DS ij Indicates the server-side SP ij The defensive strategy adopted by DS ij ∈B, AS n×m Each element AS ij This indicates that the attacker is targeting the server's SP. ij attack strategies, AS ij ∈ B, B = {0, 1} is a Boolean set, DS ij =1 indicates SP ij Provide real service, DS ij =0 indicates SP ij Providing fake services, AS ij =1 indicates that the attacker is attacking SP. ij AS ij =0 indicates that the attacker does not attack SP. ij ; c. Determine the defensive benefits of a complex network defense system when the attacker and defender interact, specifically, the differences in defense performance between the attacker and defender at the server-side SP. ij There are a total of 4 types of interaction strategies (DS) ij AS ij Each type of interaction strategy is represented as type. l According to the attacking and defending sides in SP ij SP during interaction ij The defense benefit of the complex network defense system in the current period t is calculated based on the defense benefit: Where l∈[1,4] represents the interaction strategy type, and the four interaction strategies are represented by type1 (DS) ij AS ij ) = (0,0), type2 represents (DS) ij AS ij ) = (1,0), type3 represents (DS) ij AS ij ) = (0,1) and type4 represents (DS) ij AS ij )=(1,1),u l This indicates that both the attackers and defenders are at each SP ij When SP executes the type l interaction strategy ij The defensive benefits, This represents the SP (Special Principle) in which both the attacker and defender execute the l-th type of interaction strategy during the current period t. ij quantity; d. Obtain the evolutionary defense strategy matrix DS based on the characteristics of complex network defense systems. t+1 and the defense strategy transition probability matrix P t Specifically, complex network defense systems adjust the defense strategy matrix DS for the current period t through a self-learning and adaptive evolutionary process. t Thus, an evolutionary defense strategy matrix is ​​obtained. The adaptive strategy adjustment process is reflected in the server-side matrix SP of the system in the current period t. n×m Defense strategy transition probability matrix Then each SP in the current period t ij Defense strategy shift probability for: Among them, P t-1 For the previous period t-1 system in the server matrix SP n×m The defense strategy transition probability matrix on For each SP in the previous period t-1 ij The function F is the strategy adjustment function, which takes a probability value as input. If the probability value is used as input, the output is 1; otherwise, the output is 0. The function H is the defense strategy transition probability function, and the function sgn is the sign function. e. Obtain the attacker's attack strategy matrix AS based on the characteristics of complex network defense systems. t+1 and attack strategy transition prediction probability matrix * P t Specifically, in the current period t, the attacker predicts the defense strategy matrix DS for the current period t by analyzing the defender's historical defense strategies. t Therefore, the attack strategy matrix for the next cycle t+1 is formulated as follows. The attack strategy transition prediction probability matrix for the current period t is: Where k∈[2,t] represents the k-th period, and k=2 indicates that the attacker starts analyzing the defender's defense information from the 2nd period. DS k Let DS be the defense strategy matrix for the k-th period. k-1 This is the defense strategy matrix for the (k-1)th period; f. Calculate the benefit of enabling real services in the complex network defense system per cycle: Among them, u real For the system in each SP ij Revenue from enabling real services SP that enables real services for the current period t system ij quantity; g. Calculate the expected energy consumption of the complex network defense system per cycle: Wherein, the function ln is the penalty function; h. Calculate the service quality of the complex network defense system for each cycle: Among them, u reward For the system in each SP ij The benefits of switching from fake services to real services For the previous cycle of server-side SP ij The fake service provided above becomes a real service in the current period t. ij quantity; i. The energy consumption of a complex network defense system switching between true and false service attributes per cycle is: Among them, u punish For each SP ij The penalty value for switching between real and fake service attributes. For the previous cycle of server-side SP ij The real service provided on the SP becomes a fake service in the current period t. ij quantity; j. Calculate the total benefit of the complex network defense system per cycle: k. Based on the robustness of the total benefit analysis of the complex network defense system, specifically, when threatened by malicious attacks, the complex network defense system periodically adjusts its defense strategy through a self-learning and adaptive evolutionary process, making it difficult for the attacker to predict the defense strategy, resulting in a decrease in attack benefits and an increase in the total benefit of the defense system, thus proving that the complex network defense system has robust properties.

Citation Information

Patent Citations

  • Network robustness determination method and device, equipment and storage medium

    CN113132131A

  • Complex network dynamic defense decision-making method and system based on attack and defense game

    CN115314316A