A spatiotemporal network boolean tomography method and system against congestion attacks

By combining Fisher divergence detection and K-Means clustering with the Tomo algorithm to locate congestion attacks, and using F-measure to optimize the identification of congested links, the problem of high false negative rate in network Boolean tomography is solved, and effective identification and location of congestion attacks is achieved.

CN119728230BActive Publication Date: 2025-12-12BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411877585.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-12-12
Estimated Expiration
2044-12-19

AI Technical Summary

Technical Problem

Existing network Boolean tomography methods are ineffective against congestion attacks, have a high false negative rate, and can be exploited by malicious attackers to covertly attack, leading to a decline in network performance.

Method used

A congestion attack detection algorithm based on Fisher divergence is adopted, which combines K-Means clustering and Tomo algorithm to determine the attacked path and link location, and a congestion link identification algorithm that maximizes F-measure is used to identify congested links.

Benefits of technology

It effectively reduces the false negative rate, responds promptly to congestion attacks, improves the accuracy and reliability of congested link identification, and significantly reduces the false alarm rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728230B_ABST
    Figure CN119728230B_ABST
Patent Text Reader

Abstract

The application discloses a space-time network Boolean tomography method and system against congestion attack, and belongs to the field of communication, and comprises the following steps: acquiring multi-time slot path observation results on a network topology to be measured; performing congestion attack detection based on a Fisher divergence-based congestion attack detection algorithm; if an attack is detected, firstly, a K-Means clustering method is used to determine the position of an attacked path, and then a Tomo algorithm is used to further find the position of an attacked link; and a congestion link identification algorithm maximizing F-measure is used to identify the congestion link. The application solves the problems that the existing network Boolean tomography method cannot cope with congestion attack and has a high false negative rate, and can give a higher weight to a false negative rate (FNR), thereby effectively reducing the negative influence caused by the congestion attack, reducing the false negative rate, and timely and effectively coping with the congestion attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of communication, and particularly relates to a space-time network Boolean tomography method and system for resisting congestion attacks. BACKGROUND

[0002] The Internet is composed of a large number of autonomous systems. Due to security and privacy considerations, autonomous systems are usually unwilling to share link-level performance parameters, so it is impossible to directly monitor each link in the Internet. In addition, the cost of monitoring each link far exceeds its benefits.

[0003] Network tomography technology breaks through these limitations and can infer the required link-level performance parameters (such as packet loss rate and delay) according to a small number of end-to-end path measurements without accessing the internal network. It accurately captures the performance of the target link through ingenious end-to-end path detection design, such as the "back-to-back" detection method for measuring link delay and the "sandwich" detection method for identifying the hop point of the shared link. Obviously, if the packet loss rate or delay of the link is known, it is easy to diagnose whether the link is congested, but this requires a high-complexity detection scheme and has a high error rate. Therefore, the network Boolean tomography method converts accurate numerical estimates into robust Boolean qualitative estimates, and according to the Boolean state of the end-to-end path, the Boolean state of the internal link of the network is inferred under the given routing constraints between the link and the path.

[0004] Network Boolean tomography has an ill-posed problem because the number of links in the actual network topology is usually greater than the number of paths, so one path observation may correspond to multiple possible sets of congested links. In order to solve the ill-posed problem of network Boolean tomography, the most reasonable congested link identification algorithm needs to be selected according to certain optimization criteria. There are many existing congested link identification algorithms, such as the Maximum A Posteriori Algorithm (MAP), the Boolean Satisfiability Problem (SAT), and the Congested Link Identification (CLINK). Among them, the MAP algorithm finds the set of congested links with the maximum posterior probability according to the prior congestion probability of the link; the SAT algorithm regards the network Boolean tomography as a Boolean satisfiability problem to find the set of congested links with the minimum number; and the CLINK algorithm is a greedy algorithm based on the MAP algorithm, which identifies the congested link in the network by gradually selecting the optimal link.

[0005] In the commonly used network Boolean tomography method, the MAP algorithm has a high false negative rate (FNR) when facing congestion attacks. The inference result of the MAP algorithm is predictable, and network Boolean tomography has an ill-posed problem. Attackers can inject a large link delay on links outside the MAP algorithm prediction to conceal attacks, which makes the MAP algorithm unable to discover attacks. This concealment increases the false negative rate and continuously causes network performance degradation.

[0006] Since the network Boolean tomography method itself has an ill-posed problem, malicious attackers can use this feature to launch congestion attacks on links. Since most existing methods only rely on single-time slot information for analysis, it is difficult to effectively detect such attacks, resulting in a high false negative rate. Link congestion attacks can cause the joint distribution of path states to deviate, so by analyzing the hidden information in multi-time slot observation data, the path state deviation affected by attacks can be effectively identified, and attacks can be detected.

[0007] Based on the above analysis, there is an urgent need for a reliable network Boolean tomography method with congestion attack awareness and new congestion identification strategies. SUMMARY

[0008] To solve the problem that the existing network Boolean tomography method cannot cope with congestion attacks and has a high false negative rate, the present application provides a spatiotemporal network Boolean tomography method and system against congestion attacks.

[0009] The technical solution adopted by the present application to solve the technical problems is as follows:

[0010] The present application provides a spatiotemporal network Boolean tomography method against congestion attacks, which specifically includes the following steps:

[0011] Step S1: Obtain multi-time slot path observation results on the network topology to be measured.

[0012] Step S2: Perform congestion attack detection based on the Fisher divergence-based congestion attack detection algorithm.

[0013] Step S3: If an attack is detected, first use the K-Means clustering method to determine the location of the attacked path, and then use the Tomo algorithm to further find the location of the attacked link.

[0014] Step S4: Use the congestion link identification algorithm that maximizes the F-measure to identify congestion links.

[0015] Further, in step S1, a multi-congestion link path state model is established, and the path state is subdivided into: good, represented by 0; single-congestion link path, represented by 1; and multi-congestion link path, represented by >1; the path state y j + and the following logical relationship exists between the path state y i

[0016]

[0017] In a single time slot, the collected path observation results are represented as a vector Y, and the link state is represented as a vector X; in multiple time slots, the collected path observation results form a matrix Y, and the link state forms a matrix X.

[0018] Further, the specific implementation process of step S2 is as follows:

[0019] S2.1: A small multivariate Gaussian noise ε is applied to the multi-time slot path observation value and the current multi-time slot path observation value Y to obtain and Y';

[0020] S2.2: According to the multi-time slot path observation value , a Fisher dispersion set {F j (b) | b = 1,..., B} corresponding to each non-attack path is obtained.

[0021] S2.3: According to and Y', the Fisher dispersion F j corresponding to each path p j is solved.

[0022] S2.4: According to the Fisher dispersion set {F j (b) | b = 1,..., B}, the threshold τ j of each path p j is determined by the confidence interval method.

[0023] S2.5: The Fisher dispersion F j and the threshold τ j of each path p j are compared one by one; once F j > τ j , it is considered to be under attack; otherwise, it is considered not to be under attack.

[0024] Further, in step S2.2, the multi-time slot path observation value under the non-attack scenario is randomly divided into two parts and ​The joint distribution was obtained by fitting the model using a multivariate Gaussian model. and For each path p j The joint distribution can be approximated using formula (3) and the Monte Carlo method. and Fisher divergence F' j Repeat the above operation B times, for each path p. j Each has a Fisher divergence set {F' of length B}. j (b)|b=1,...,B};

[0025]

[0026] Among them, F j Represents Fisher divergence. Ω(Y) represents the state distribution of the path in a no-attack scenario, and Ω(Y) represents the state distribution of the current path. It represents the mathematical expectation.

[0027] Furthermore, in step S2.3, the observations of multi-slot paths in the non-attack scenario are... Y and Y' were fitted using a multivariate Gaussian model to obtain their joint distributions. and Ω; for each path p j The joint distribution can be approximated using formula (3) and the Monte Carlo method. Fisher divergence F with Ω j .

[0028] Furthermore, in step S2.4, the Fisher divergence set is sorted, and the boundary values ​​of the 95% confidence interval are used as the threshold τ. j .

[0029] Furthermore, the specific implementation process of the K-Means clustering method is as follows:

[0030] Measure each path p j The difference in empirical congestion probability between the two multi-slots Δ j :

[0031]

[0032] Where Y(j,t) represents path p j The observation results at time t, This indicates the indicator function, where #{Y(:,t)} represents the current number of multi-slot observations. Indicates the number of multi-slot observations without attack; using two features (F j Δ jK-Means clustering is performed to distinguish the attack-free path and the attacked path; the cluster with larger centroid is the attacked path because the congestion probability of the path is increased due to the attack.

[0033] Further, the specific implementation process of the congestion link identification algorithm for maximizing the F-measure is as follows:

[0034] (1) For each Y in the current multi-time-slot path observation value Y, find all feasible congestion link solutions S(Y);

[0035] (2) According to the prior probability, obtain the posterior probability of each feasible congestion link solution S(Y), and then sort each feasible congestion link solution S(Y) according to the posterior probability; take the solutions with larger posterior probability in each feasible congestion link solution S(Y), and update S(Y) with these solutions;

[0036] (3) For each solution Assume that it is the true solution, i.e., w i = 100%, w j = 0% for all j ≠ i, to calculate the F-measure value to be optimized

[0037] (4) The solution corresponding to the maximum F-measure value is the congestion link solution identified by the congestion link identification algorithm

[0038] (5) Repeat the above steps to obtain the congestion link solution S(Y) of the current multi-time-slot path observation value Y

[0039] Further, the calculation formula of the F-measure value to be optimized is as follows:

[0040]

[0041] wherein w k represents the probability of the kth solution, S(Y) represents the set of feasible congestion link solutions, represents the true solution, represents the solution of the congestion link identification algorithm, represents any possible solution of the congestion link identification algorithm, represents the conditional probability that the link state is when the observation result Y is given; represents the F1 value between the true solution and the solution of the congestion identification algorithm ​​

[0042] The application provides a spatiotemporal network Boolean tomography system against congestion attacks, and implements the spatiotemporal network Boolean tomography method against congestion attacks.

[0043] The multi-congestion link path state model establishment module is used for establishing a multi-congestion link path state model, and acquiring multi-time slot path observation results on a network topology to be measured by using the multi-congestion link path state model.

[0044] The congestion attack detection module is used for a congestion attack detection algorithm based on Fisher divergence, and uses Fisher divergence to measure the difference between the empirical distributions of multi-time slot path states.

[0045] The congestion attack positioning module is used for determining the position of an attacked path by using a K-Means clustering method in the case of detecting an attack, and further finding the position of an attacked link by using a classic Tomo algorithm.

[0046] The congestion link identification module is used for identifying a congestion link by using a congestion link identification algorithm maximizing F-measure.

[0047] The application has the beneficial effects that:

[0048] The application provides a spatiotemporal network Boolean tomography method against congestion attacks, which is mainly realized by a congestion attack detection method based on Fisher divergence and a congestion link identification method taking F-measure as an optimization target. The congestion attack detection algorithm based on Fisher divergence used in the application uses Fisher divergence to measure the joint distribution displacement of multi-time slot path states, that is, the difference between the distributions of multi-time slot path states, uses a bootstrap confidence interval threshold to detect whether congestion attacks are suffered, and positions attacked paths through clustering. In addition, the application also uses a congestion link identification algorithm taking F-measure as an optimization target to identify congestion links in an attack environment. Different from the maximum posterior probability of the traditional MAP algorithm, the congestion link identification algorithm used in the application is dedicated to maximizing F-measure. This optimization method can give a higher weight to the false negative rate (FNR), thereby effectively reducing the negative impact of congestion attacks, reducing the false negative rate, and timely and effectively responding to congestion attacks. BRIEF DESCRIPTION OF DRAWINGS

[0049] Figure 1 The application provides a spatiotemporal network Boolean tomography method against congestion attacks.

[0050] Figure 2 The application provides a congestion attack detection algorithm based on Fisher divergence.

[0051] Figure 3 Flow chart of congestion link identification algorithm for maximizing F-measure.

[0052] Figure 4 Performance of attack detection, path localization and link localization under different attack frequencies.

[0053] Figure 5 Performance of CLIF algorithm, CLIF+ algorithm, MAP algorithm, CLINK algorithm and SAT algorithm under different congestion probabilities. DETAILED DESCRIPTION

[0054] The application will be further described in detail below with reference to the accompanying drawings.

[0055] In a first aspect, the application provides a spatio-temporal network Boolean tomography method for resisting congestion attacks.

[0056] Referring to Figure 1 The application provides a spatio-temporal network Boolean tomography method for resisting congestion attacks, and the specific implementation process is as follows:

[0057] Step S1: Obtain multi-time slot path observation results on the network topology to be measured.

[0058] In the network Boolean tomography method, the link and path states are both divided into two kinds: congestion (represented by 1) and good (represented by 0). The path state y j and all link states x i on the path have the following logical relationship:

[0059]

[0060] Wherein, l i ∠p j represents the link l i on the path p j , and the symbol V represents the Boolean OR operation.

[0061] On this basis, the application establishes a multi-congestion link path state model, and further divides the path state into three kinds: good (represented by 0), single-congestion link path (represented by 1) and multi-congestion link path (represented by >1). The path state y j + and all link states x i on the path have the following logical relationship:

[0062]

[0063] In a single time slot, the collected path observations are represented as a vector Y, and the link states are also represented as a vector X; in multiple time slots, the collected path observations form a matrix Y, and the link states also form a matrix X.

[0064] Step S2: congestion attack detection by Fisher divergence;

[0065] The Fisher divergence-based congestion attack detection algorithm of the application adopts Fisher divergence to measure the difference between the empirical distributions of the multi-time slot path states.

[0066]

[0067] Wherein, the Fisher divergence formula is as shown below: represents the state distribution of the path under the non-attack scenario, and represents the state distribution of the current path, and the symbol represents the mathematical expectation.

[0068] As Figure 2 shown, the specific implementation process of the Fisher divergence-based congestion attack detection algorithm is as follows:

[0069] S2.1: a small multivariate Gaussian noise ε is applied to the multi-time slot path observation values and the current multi-time slot path observation values Y, to obtain and Y', so that they can fit the multivariate Gaussian model.

[0070] S2.2: according to the multi-time slot path observation values of the non-attack scenario, a Fisher divergence set {F j (b)|b=1,...,B} corresponding to each non-attack path is obtained.

[0071] Specifically, the multi-time slot path observation values of the non-attack scenario are randomly divided into two parts and are fitted using the multivariate Gaussian model, to obtain the joint distributions and For each path p j , the Fisher divergence F j of the joint distributions and is approximately solved by using formula (3) and the Monte Carlo method. The above operations are repeated B times, and each path p j has a Fisher divergence set {F j (b)|b=1,...,B} with a length of B.

[0072] S2.3: According to and Y' solve each path p j The corresponding Fisher divergence F j .

[0073] Specifically, the multi-time slot path observation value under the non-attack scene and Y' are fitted using a multivariate Gaussian model, and the joint distribution and Ω are obtained. For each path p j , the Fisher divergence F of the joint distribution j and Ω is approximately solved using formula (3) and the Monte Carlo method.

[0074] S2.4: According to the Fisher divergence set {F' j (b)|b=1,...,B}, the threshold τ j of each path p j is determined by the confidence interval method.

[0075] Specifically, the Fisher divergence set {F' j (b)|b=1,...,B} is sorted, and the boundary value of the 95% confidence interval is taken as the threshold τ j .

[0076] S2.5: The Fisher divergence F j of each path p j and the threshold τ j are compared one by one; once F j >τ j , it is considered to be attacked; otherwise, it is considered not to be attacked.

[0077] Step S3: Use clustering to locate the congestion attack;

[0078] Specifically, if an attack is detected in step S2, first, the K-Means clustering method is used to determine the location of the attacked path, and then the classic Tomo algorithm is used to further find the location of the attacked link.

[0079] The specific implementation process of determining the location of the attacked path using the K-Means clustering method is as follows:

[0080] The present application measures the difference Δ j of the empirical congestion probability of each path p j in two multi-time slots:

[0081]

[0082] Where Y(j,t) represents the path pj Y(:,t) represents the observation at time t, represents an indicator function, #{Y(:,t)} represents the current multi-slot observation number, represents the multi-slot observation number under no attack.

[0083] The present application uses two features (F j , Delta j ) to perform K-Means clustering, thereby distinguishing between attack-free paths and attacked paths. Since attacks cause the congestion probability of paths to increase, clusters with larger centroids are attacked paths.

[0084] The specific implementation process of further finding the location of the attacked link using the classic Tomo algorithm is as follows:

[0085] Given the attacked path and the network topology, the attacked link can be solved by using the network Boolean tomography method. The present application uses the classic Tomo algorithm to locate the attacked link, and the Tomo algorithm usually sets the shared link as the attacked link.

[0086] Step S4: congestion link identification by optimizing F-measure;

[0087] The present application defines that when the path observation result Y of a given single slot is given, the F-measure value to be optimized is:

[0088]

[0089] Where w k represents the probability of the kth solution, S(Y) represents the feasible congestion link solution set, represents the true solution, represents the solution of the congestion link identification algorithm, represents any possible solution of the congestion link identification algorithm, represents the conditional probability of the link state being when the observation result Y is given, represents the F1 value between the true solution and the solution of the congestion identification algorithm . Since each time slot is independent of each other, the F-measure can be optimized on each time slot to identify the congestion link.

[0090] The application provides a congested link identification algorithm (CLIF) for maximizing F-measure.

[0091] As shown in the figure, Figure 3 The specific implementation process of the CLIF algorithm is as follows:

[0092] (1) for each Y in the current multi-time-slot path observation value Y, find all feasible congested link solutions S(Y);

[0093] (2) according to the prior probability, obtain the posterior probability of each feasible congested link solution S(Y), and then sort each feasible congested link solution S(Y) according to the posterior probability; take the solutions with large posterior probability in each feasible congested link solution S(Y), and update S(Y) with the solutions;

[0094] (3) for each solution Assume that it is the true solution, that is, w i = 100%, w j = 0% for all j≠i, and obtain the F-measure value to be optimized according to formula (5)

[0095] (4) the solution corresponding to the maximum F-measure value is the congested link solution identified by the congested link identification algorithm

[0096] (5) repeat the above steps to obtain the congested link solution of the current multi-time-slot path observation value Y

[0097] In the second aspect, the application provides a spatiotemporal network Boolean tomography system against congestion attacks, which is mainly used for implementing the spatiotemporal network Boolean tomography method against congestion attacks provided in the first aspect.

[0098] The spatiotemporal network Boolean tomography system against congestion attacks provided by the application mainly comprises the following modules: a multi-congested link path state model establishing module, a congestion attack detection module, a congestion attack positioning module and a congested link identification module. The specific functions and roles of the modules are as follows:

[0099] ​The multi-congestion link path state model establishment module is configured to establish a multi-congestion link path state model and obtain multi-time slot path observation results on a network topology to be measured by using the multi-congestion link path state model.

[0100] The congestion attack detection module is mainly configured to implement a Fisher dispersion-based congestion attack detection algorithm, and use Fisher dispersion to measure the difference between the empirical distributions of multi-time slot path states.

[0101] The congestion attack positioning module is mainly configured to determine the position of an attacked path by using a K-Means clustering method in the case of detecting an attack, and further find the position of an attacked link by using a classic Tomo algorithm.

[0102] The congestion link identification module is mainly configured to implement a congestion link identification algorithm maximizing F-measure to identify congestion links.

[0103] To verify the effect of the space-time network Boolean tomographic imaging method and system for resisting congestion attacks, the attack detection, path positioning and link positioning of the present application under different attack frequencies are verified by experiments. Figure 4 As shown in Table 2, under different attack frequencies (25%, 50%, 75% and 100%), the accuracy and F1 score of attack detection always remain above 90%, and the accuracy and F1 score of attacked path positioning also maintain above 80%. With the increase of attack frequency, the accuracy and F1 score of attacked link positioning also increase. This is because a higher attack frequency leads to an increase in the congestion probability of each link, so that the Tomo algorithm can more effectively detect these links.

[0104] The performances of the CLIF algorithm, the CLIF+ algorithm and existing algorithms (the MAP algorithm, the CLINK algorithm and the SAT algorithm) under different congestion probabilities are verified by experiments. Figure 5 As shown in Table 3, CLIF and CLIF+ outperform other algorithms in all performance indicators, and the false negative rate (FNR) is significantly lower than that of other algorithms, which fully proves the effectiveness of the optimization strategy of the present application. Since the CLIF+ algorithm uses a multi-congestion link path state model, it can provide more abundant information, and therefore outperforms the CLIF algorithm.

[0105] The space-time network Boolean tomography method and system against congestion attack can not only effectively detect congestion attacks that cannot be coped with by a traditional Boolean fault scan method (MAP), but also accurately locate the attacked path and link. Compared with existing MAP, CLINK, SAT and other algorithms, the congestion link identification algorithm CLIF and CLIF+ significantly reduces false negatives FNR and greatly improves the identification performance of congestion links.

[0106] The above only describes the preferred embodiments of the present application, and it should be noted that those skilled in the art can make several improvements and refinements without departing from the principles of the present application, and these improvements and refinements should also be considered as the protection scope of the present application.

Claims

1. A spatiotemporal network Boolean tomography method for combating congestion attacks, characterized in that, Includes the following steps: Step S1: On the network topology to be measured, acquire multi-time-slot path observation results; Step S2: Congestion attack detection is performed using a congestion attack detection algorithm based on Fisher divergence; Step S3: If an attack is detected, first use the K-Means clustering method to determine the location of the attacked path, and then use the Tomo algorithm to further find the location of the attacked link; Step S4: Use the congestion link identification algorithm that maximizes F-measure to identify congestion links.

2. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 1, characterized in that, In step S1, a multi-congested link path state model is established, and the path state is subdivided into: good (represented by 0); single-congested link path (represented by 1); multi-congested link path (represented by >1); path state y j + and the status of all links on the path x i The following logical relationships exist between them: Within a single time slot, the collected path observations are represented as a vector Y, and the link status is represented as a vector X; across multiple time slots, the collected path observations form a matrix Y, and the link status forms a matrix X.

3. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 1, characterized in that, The specific implementation process of step S2 is as follows: S2.1: Observations of multi-slot paths in attack-free scenarios By applying a small multivariate Gaussian noise ε to the current multi-slot path observations Y, we obtain and Y'; S2.2: Based on multi-slot path observations in a no-attack scenario Obtain the Fisher divergence set {F'} for each non-attack path. j (b)|b=1,...,B}; S2.3: According to Solving for each path p with Y' j The corresponding Fisher divergence F j ; S2.4: Based on the Fisher divergence set {F' j (b) |b=1,...,B}, determine each path p using the confidence interval method. j Threshold τ j ; S2.5: For each path p j Fisher divergence F j and threshold τ j Compare them one by one; once F appears j >τ j If the condition is met, it is considered an attack; otherwise, it is considered not to have been attacked.

4. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 3, characterized in that, In step S2.2, the multi-slot path observations under the no-attack scenario are... Randomly divided into two parts and The joint distribution was obtained by fitting the model using a multivariate Gaussian model. and For each path p j The joint distribution can be approximated using formula (3) and the Monte Carlo method. and Fisher divergence F' j Repeat the above operation B times, for each path p. j Each has a Fisher divergence set {F' of length B}. j (b)|b=1,...,B}; Among them, F j Represents Fisher divergence. Let Ω(Y) represent the state distribution of the path in a no-attack scenario, and let E represent the mathematical expectation.

5. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 4, characterized in that, In step S2.3, the observations of multi-slot paths in the non-attack scenario are... Y and Y' were fitted using a multivariate Gaussian model to obtain their joint distributions. and Ω; for each path p j The joint distribution can be approximated using formula (3) and the Monte Carlo method. Fisher divergence F with Ω j .

6. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 3, characterized in that, In step S2.4, the Fisher divergence set {F' j (b) Sort the values ​​of |b=1,...,B} and use the boundary values ​​of the 95% confidence interval as the threshold τ. j .

7. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 1, characterized in that, The specific implementation process of the K-Means clustering method is as follows: Measure each path p j The difference in empirical congestion probability between the two multi-slots Δ j : Where Y(j,t) represents path p j The observation results at time t, This indicates the indicator function, where #{Y(:,t)} represents the current number of multi-slot observations. Indicates the number of multi-slot observations without attack; using two features (F j Δ j K-Means clustering is performed to distinguish between non-attacked paths and attacked paths; since the attack increases the probability of path congestion, the cluster with the larger centroid is the attacked path.

8. The spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 1, characterized in that, The specific implementation process of the congested link identification algorithm that maximizes the F-measure is as follows: (1) For each Y in the current multi-slot path observation Y, find all feasible congested link solutions S(Y); (2) Calculate the posterior probability of each feasible congested link solution S(Y) based on the prior probability, and then sort each feasible congested link solution S(Y) according to the posterior probability; select the first few solutions with large posterior probabilities from each feasible congested link solution S(Y) and use these solutions to update S(Y). (3) For each solution Assume that it is the true solution, i.e., w i =100%, for all j≠i, w j =0%, and the F-measure value to be optimized is calculated based on this. (4) The largest F-measure value The corresponding solution This is the congestion link solution identified by the congestion link identification algorithm. (5) Repeat the above steps to obtain the congested link solution of the current multi-slot path observation Y.

9. A spatiotemporal network Boolean tomography method for combating congestion attacks according to claim 8, characterized in that, The F-measure value to be optimized The calculation formula is: Among them, w k Let Y represent the probability of the k-th solution, and S(Y) represent the set of feasible congested link solutions. This represents the true solution. This represents the solution to the congested link identification algorithm. Let represent any possible solution to the congested link identification algorithm. This indicates that the link state is given the observation result Y. The conditional probability; Represents the true solution Solution of congestion identification algorithm The F1 value between.

10. A spatiotemporal network Boolean tomography system for resisting congestion attacks, characterized in that, This system is used to implement a spatiotemporal network Boolean tomography method for combating congestion attacks as described in any one of claims 1 to 9, comprising: The multi-congested link path state model building module is used to build a multi-congested link path state model and use the multi-congested link path state model to obtain multi-time slot path observation results on the network topology to be measured. The congestion attack detection module is used for congestion attack detection algorithms based on Fisher divergence, which uses Fisher divergence to measure the difference between empirical distributions of multi-slot path states. The congestion attack localization module is used to determine the location of the attacked path using the K-Means clustering method when an attack is detected, and then use the classic Tomo algorithm to further find the location of the attacked link. The congested link identification module is used to identify congested links using a congested link identification algorithm that maximizes the F-measure.

Citation Information

Patent Citations

  • Link flooding attack detection and defense system and method

    CN113364810A

  • Link flooding attack processing method and device, equipment and storage medium

    CN116961951A