Effect function weight calculation and game theory-based high-risk network node defense method
By applying the method based on effect function weight calculation and game theory in the defense of high-risk network nodes, the problem of different asset importance on different devices is solved, effective defense of high-risk network nodes is achieved, and the targetedness and accuracy of defense strategies are improved.
Patent Information
- Application Number
- CN202510172496.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-02-17
AI Technical Summary
The existing technology fails to effectively consider the importance of asset information such as services and data on different devices in network security defense, resulting in a lack of targetedness and effectiveness in high-risk network node defense.
The method based on effect function weight calculation and game theory is adopted to obtain high-risk nodes through attack graph analysis, collect security information, calculate the comprehensive weight of each indicator using progressive AHP and entropy weight method, calculate the utility functions of both attack and defense sides, and obtain the probability of attack and defense strategy selection of each node through game theory to obtain the optimal defense strategy.
The targetedness and effectiveness of high-risk network node defense is improved. By comprehensively considering node availability indicators and utility functions, dynamically balance the offensive and defense strategy selection, the subjectivity and contingency are reduced and the accuracy of the results is improved.
Smart Images

Figure CN119945792A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security defense, and in particular to a high-risk network node defense method based on effect function weight calculation and game theory. Background Art
[0002] With the rapid development of network technology, modern information systems are becoming increasingly complex, and network security issues are becoming more prominent. High-risk nodes refer to nodes obtained by network systems through attack graphs, intrusion detection and other network analyses. Due to their importance and vulnerability in the network, they often become the main targets of attacks. In recent years, game theory has gradually been applied to the field of network security to simulate the game behavior between attackers and defenders, providing theoretical support for security defense in complex networks.
[0003] Chinese patent CN101820413B discloses a method for selecting the best network security protection strategy. This method collects and analyzes host information, link information, service information, protection system information, economic cost and asset importance information in real time during the attack and defense process, outputs the analysis results using statistical analysis and correlation analysis techniques, and then calculates the performance of the attack and defense strategy; Chinese patent CN107566387A discloses a network defense action decision-making method based on attack and defense evolutionary game analysis, but the above scheme does not take into account the different importance of asset information such as services and data on different devices. Summary of the invention
[0004] In view of the deficiencies in the prior art, the present invention discloses a high-risk network node defense method based on effect function weight calculation and game theory to solve the problems raised in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solution: a high-risk network node defense method based on effect function weight calculation and game theory, comprising the following steps:
[0006] S11. Obtain high-risk nodes in the network through attack graph analysis and collect security information of high-risk nodes;
[0007] S12. Based on the security information of the target node, the profit indicators of the attacker and the defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method;
[0008] S13, based on the node security information and weight information, calculate the utility functions of the attacker and defender when the attacker and defender adopt different strategies respectively;
[0009] S14. Obtain the attack strategy and defense strategy selection probability vector of each node through game theory;
[0010] S15. Select the maximum value of the probability according to the strategy of each node to obtain the optimal defense strategy of the current node.
[0011] Preferably, in step S11, security information of high-risk network nodes is collected, and the security information includes the asset economic value, service economic value, data economic value, vulnerabilities, possible attack strategies, and available defense strategies of the network nodes. Device vulnerabilities are detected through vulnerability tools, and vulnerability exploitability indicators are obtained according to general vulnerability scoring standards.
[0012] Preferably, in step S12, the profit indicators of the attacker and the defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method, which specifically includes the following steps:
[0013] 1) Based on the node security information, extract the profit indicators of attackers and defenders, and the available defense strategies of defenders;
[0014] 2) Obtain the subjective weight vector W of the attacker and defender's benefit indicators through progressive AHP AHP ' and W AHP ”;
[0015] 3) Use the first formula to obtain the objective weight w of the jth indicator in the attacker and defender's benefit indicators respectively through the entropy weight method j , and finally form the attacker's profit index weight W E ' and the defender's benefit indicator weight W E ”:
[0016] The first formula is:
[0017]
[0018] in i=1,2…m;j=1,2…n,m is the total number of high-risk nodes, n is the number of indicators, find W E 'When is n', find W E "When it is n", x i,j It is the quantitative value of the i-th target asset on the j-th indicator;
[0019] 4) Based on the subjective weight vector W of the attacker's benefit index and the defender's benefit index AHP ' and W AHP "、Objective weight vector W E ' and W E ", use the second formula to obtain the comprehensive weight vector W' of the attacker's benefit index and the comprehensive weight vector W" of the defender's benefit index:
[0020]
[0021] The second formula is:
[0022]
[0023] Among them, α is the subjective weight effectiveness factor, which is used to control the effectiveness of the subjective weight in the comprehensive weight and is obtained in the progressive AHP algorithm.
[0024] Preferably, the subjective weight vector W of the attacker's benefit index and the defender's benefit index is obtained through progressive AHP: AHP ' and W AHP ",include:
[0025] 1) Establish target layer, criterion layer and scheme layer for attacker benefit indicators on high-risk network nodes;
[0026] 2) T experts weight the criteria layer indicators to obtain multiple comparison matrices A1, A2, ...A T ;
[0027] 3) Based on T comparison matrices, calculate the weight w of the t-th expert in the r-th round for the i-th indicator using the third formula: t,r (i) The weighted evaluation result vector w of each expert t,r ;
[0028] The third formula is:
[0029]
[0030] 4) Evaluate the result vector w based on the weight of each expert t,r The global weight vector w is calculated by the fourth formula r ;
[0031] The fourth formula is:
[0032]
[0033] 5) Through the global weight vector w r Calculate the suggestion matrix A according to the fifth formula * r :
[0034] The fifth formula is:
[0035]
[0036] 6) The proposed matrix A * r As a reference, it is fed back to the experts for the next round of scoring until the global weight vector w r Satisfy the consistency check, the total number of iterations r is α, w ris the final attacker benefit indicator weight W AHP '; The defender's benefit indicator weight W AHP ” is calculated in the same way.
[0037] Preferably, in step S13, the utility functions of the attacker and the defender when they adopt different strategies are calculated, which specifically includes the following:
[0038] 1) Based on the obtained W' and W", calculate the attacker's benefit b' (AS) when the attacker selects the i-th attack strategy and the defender selects the j-th defense strategy according to the sixth formula i ,DS j ) and the defender's payoff b”(AS i ,DS j );
[0039]
[0040] The sixth formula is:
[0041]
[0042] Among them, n' and n" are the total number of profit indicators of the attacker and defender respectively, β is the control factor, and value k is the return corresponding to the current indicator;
[0043] 2) Calculate the cost when the attacker chooses the i-th attack strategy:
[0044] c′(AS i ) = c′ e (AS i )+c′ r (AS i );
[0045] Among them, c' e (AS i ) is the execution time cost, which is determined by the time it takes to execute an attack with this strategy; c' r (AS i ) is the resource cost, which is determined by the malware purchase cost, development cost, and cloud computing resource cost;
[0046] 3) Calculate the cost when the defender selects the jth defense strategy:
[0047] c”(DS j )=c” d (DS j )+c” m (DS j );
[0048] Among them, c"d (DS j ) is the deployment cost, c” m (DS j ) is the maintenance cost;
[0049] 4) Calculate the attacker’s utility function: U A (i,j)=b'(AS i ,DS j )-c'(AS i );
[0050] 5) Calculate the defender’s utility function: U D (i,j)=b”(AS i ,DS j )-c”(DS j ).
[0051] Preferably, in step S14, the attack strategy selection probability vector p and the defense strategy selection probability vector q of the node are respectively obtained through game theory, which specifically includes the following:
[0052] 1) Construct the attacker's profit matrix U according to the utility functions of the attacker and defender respectively A and the defender’s payoff matrix U D ;
[0053]
[0054] 2) Initialize p in a uniformly distributed manner i and q j , calculate the probability p of the attacker adopting each strategy i i and the probability q that the defender chooses each strategy j j ,
[0055] 3) Use iterative optimization method to obtain p i and q j , repeat the above steps until the convergence condition is met or the number of iterations reaches the maximum value.
[0056] Preferably, in step S15, the probability p of the attacker adopting each strategy i is calculated according to the profit matrix i and the probability q that the defender chooses each strategy j j , specifically including the following:
[0057] 1) Quantify the attack success probability P of a node based on the exploitability index of the node vulnerability s (AS i );P s (AS i ) is calculated as:
[0058] Ps (AS i )=8.22*AV*AC*PR*UI
[0059] Among them, the exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, which are obtained according to CVSS.
[0060] 2) According to the seventh formula, calculate the probability p that the attacker chooses strategy i i ; The seventh formula is:
[0061]
[0062] 3) Calculate the probability q of the defender selecting strategy j according to the eighth formula j , the eighth formula is:
[0063]
[0064] Where n' and n" are the total number of attacker strategies and defender strategies, respectively, and μ and θ are temperature coefficients used to control the randomness of strategy selection.
[0065] Compared with the prior art, the present invention has the following beneficial effects:
[0066] 1. The present invention uses progressive AHP to calculate the subjective weight of the utility function through multiple rounds of feedback. The suggestion matrix obtained from the results of the previous round of evaluation is used as feedback to provide a reference for the current round of evaluation. Multiple rounds of evaluation can reduce the subjectivity and contingency of ordinary AHP.
[0067] 2. The present invention takes into account the different importance of the same indicator at each node in the system, and uses the entropy weight method to calculate the objective weight of the utility function; the subjective weight and the objective weight are combined through the effective factor to obtain the comprehensive weight. The effective factor can reflect the effectiveness of the subjective weight. The larger the effective factor is, the more difficult it is to unify expert opinions, and the effectiveness of the subjective weight needs to be reduced.
[0068] 3. The present invention combines node availability index and utility function to calculate the probability of strategy selection by iterative updating method. Applying vulnerability characteristics to the calculation of utility matrix can make the result more accurate. At the same time, the probability of strategy selection of both sides of attack and defense is interdependent, so that the strategy selection of both sides can be dynamically balanced. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.
[0070] In the attached picture:
[0071] Figure 1 It is a flowchart of a high-risk network node defense method based on effect function weight calculation and game theory provided by an embodiment of the present invention;
[0072] Figure 2 is a strategy selection probability graph on the network node device 1 in an embodiment of the present invention;
[0073] Figure 3 is a strategy selection probability graph on the network node device 2 in an embodiment of the present invention;
[0074] Figure 4 It is a strategy selection probability graph on the network node device 3 in an embodiment of the present invention. DETAILED DESCRIPTION
[0075] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0076] Example: Figure 1 As shown, the present invention provides a high-risk network node defense method based on effect function weight calculation and game theory, which reflects the different importance of each indicator by introducing progressive AHP and entropy weight method to calculate the weight of each indicator, and progressive AHP can reduce the subjectivity of weight evaluation. In addition, the above scheme does not consider the impact of vulnerability characteristics on the attacker's strategy selection. Since the vulnerability characteristics are public, the attacker will be affected by their characteristics. The characteristics of the vulnerability are affected by their own strategy selection. Therefore, the present invention quantifies the vulnerability characteristics by using a universal vulnerability scoring standard, and uses it to calculate the probability of the attacker's strategy selection, and further combines it with the actual scenario to improve the accuracy of the results; specifically, the following steps are included:
[0077] S11: Obtain high-risk nodes in the network through attack graph analysis, and use tools to collect security information of high-risk nodes.
[0078] S12: Based on the target node information, the attacker's profit index and the defender's profit index are obtained, and the comprehensive weight information of each index is obtained by using the progressive AHP and entropy weight method.
[0079] S13: Based on the node information and weight information, the utility functions of the attacker and defender when the attacker and defender respectively adopt different strategies are calculated.
[0080] S14: Obtain the attack strategy and defense strategy selection probability vectors of each node through game theory.
[0081] S15: Finally, the maximum value of the probability is selected according to the strategy of each node to obtain the optimal defense strategy of the current node.
[0082] Specifically, in step S11, tools are used to collect security information of high-risk network nodes, which collects asset economic value, service economic value, data economic value, available attack strategies, and available defense strategies through internal company data, detects device vulnerabilities through vulnerability tools, and obtains vulnerability exploitability indicators based on general vulnerability scoring standards.
[0083] Asset economic value X e Determined by the market value of the assets contained in the network node; service economic value X s Determined by the service loss cost per unit time; data economic value X d Determined by the market value of the data; system economic value X sys Determined by the economic value of downstream services.
[0084] Available attack strategies include SQL injection data theft, system control attacks, and DDoS attacks; available defense strategies include database permission settings, system permission isolation, and intrusion detection systems; device vulnerabilities include unauthorized access vulnerability CVE-2021-3129, buffer overflow vulnerability CVE-2021-3156, DDoS attack vulnerability CVE-2013-5211, and SQL injection vulnerability CVE-2011-4898.
[0085] Specifically, in step S12, the profit indicators of the attacker and the defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method, including the following steps:
[0086] Step 201: Based on the collected node security information, extract the attacker's benefit index, the defender's benefit index, and the defender's available defense strategies.
[0087] Step 202: Obtain the subjective weight vector W of the attacker's benefit index and the defender's benefit index through progressive AHP AHP ' and W AHP ”.
[0088] Step 203: Obtain the objective weight w of the jth indicator in the attacker's benefit indicator and the defender's benefit indicator respectively by using the entropy weight method j , and finally form the attacker's profit index weight vector W E ' and the defender's profit indicator weight vector W E ”. j The calculation formula is:
[0089]
[0090] in i=1,2…m;j=1,2…n;n=n',n”, m is the total number of high-risk nodes, n is the number of indicators, and W is obtained. E'When the value is n', find W E "When the value is n", x i,j It is the quantitative value of the i-th target asset on the j-th indicator.
[0091] Step 204: Based on the subjective weight vector W of the attacker's profit index and the defender's profit index AHP ' and W AHP "、Objective weight vector W E ' and W E ”, calculate the comprehensive weight vector W’ of the attacker’s benefit index and the comprehensive weight vector W” of the defender’s benefit index.
[0092] Specifically, in step 202, the progressive AHP is used to obtain the subjective weight vector W of the attacker's benefit index and the defender's benefit index. AHP ' and W AHP ”, including the following steps:
[0093] (1) Establish target layer, criterion layer and scheme layer for attacker benefit indicators on high-risk network nodes.
[0094] (2) T experts compare the criteria layer indicators pairwise and perform weighted scoring to obtain T comparison matrices A1, A2, …A T .
[0095] (3) Based on T comparison matrices, calculate the weight w of the t-th expert in the r-th round for the i-th indicator t,r (i) The weighted evaluation result vector w of each expert t,r , w t,r The calculation formula for (i) is:
[0096]
[0097] Among them, n' is the number of indicators of the attacker, A t (i,j) is the value of row i and column j in the Tth comparison matrix.
[0098] (4) The result vector w is evaluated based on the weight of each expert t,r Calculate the global weight vector w r :
[0099]
[0100] (5) Through the global weight vector w r Calculate the suggestion matrix A * r , A * r The calculation formula for (i,j) is:
[0101]
[0102] Where n' is the number of indicators of the attacker.
[0103] (6) The proposed matrix A * r As a reference, it is fed back to the experts for the next round of scoring until the global weight vector w r Satisfy the consistency check and record the total number of iterations r as the weight effective factor α, w r As the final attacker benefit indicator weight W AHP '.
[0104] (7) Defender benefit indicator weight W AHP ” is calculated in the same way.
[0105] Specifically, in step 203, the objective weight w of the jth indicator in the attacker's benefit index and the defender's benefit index is obtained by the entropy weight method. j . The following steps are included:
[0106] (1) Construct the decision matrix X, x i,j Represents the quantitative value of the i-th asset on the j-th attacker indicator.
[0107] (2) Based on Normalize the decision matrix X to obtain R.
[0108] (3) Calculate the entropy value of the target
[0109] (4) Calculate the weight of index i W E '=[w1',w2',w3',w4'] T
[0110] (5) The same method is used to obtain W E ”=[w1”,w2”,w3”,w4”] T
[0111] Specifically, in step 204, the calculation formula of the comprehensive weight vector W′ of the attacker's benefit index and the comprehensive weight vector W″ of the defender's benefit index is:
[0112]
[0113] Among them, α is the effective factor of subjective weight, which can control the effectiveness of subjective weight in comprehensive weight and is obtained in the progressive AHP algorithm.
[0114] Specifically, the calculation of the utility functions of the attacker and the defender when they adopt different strategies respectively in S13 includes the following steps:
[0115] Step 301: Based on the obtained W′ and W″, calculate the attacker's profit b′ (AS i ,DS j ) and the defender's payoff b”(AS i ,DS j ):
[0116]
[0117] Where n′ and n” are the total number of profit indicators of the attacker and defender respectively, β is the control factor. If the current strategy can obtain the kth profit indicator, then β = 1, otherwise β = 0, and value k is the return corresponding to the current indicator.
[0118] Step 302: Calculate the cost c′ (AS i ):
[0119] c′(AS i ) = c′ e (AS i )+c′ r (AS i )
[0120] Among them, c′ e (AS i ) is the execution time cost, which is determined by the time it takes to execute an attack with this strategy; c′ r (AS i ) is the resource cost, which is determined by the malware purchase cost, development cost, and cloud computing resource cost.
[0121] Step 303: Calculate the cost c when the defender selects the jth defense strategy d (DS j ):
[0122] c”(DS j )=c” d (DS j )+c” m (DS j )
[0123] Among them, c" d (DS j ) is the deployment cost, which is determined by the sum of the costs of the individually deployed defense measures; c” m (AS i ,DS j ) is the maintenance cost, which is determined by the operating cost per unit time and the total operating time.
[0124] Step 304: Calculate the attacker's utility function U A (i,j), the calculation formula is:
[0125] U A (i,j)=b'(AS i ,DS j )-c'(AS i )
[0126] Step 305: Calculate the defender's utility function U D (i,j), the calculation formula is:
[0127] U D (i,j)=b”(AS i ,DS j )-c”(DS j )
[0128] Specifically, according to the game theory in S14, respectively obtaining the attack strategy selection probability vector p and the defense strategy selection probability vector q of the node includes the following steps:
[0129] Step 401: Construct the attacker's profit matrix U according to the attacker's and defender's utility functions respectively. A and the defender’s payoff matrix U D .
[0130]
[0131] Step 402: Initialize p in a uniform distribution i and q j ,
[0132] Step 403: Update the probability p of the attacker adopting each strategy i according to the formula i and the probability q that the defender chooses each strategy j j .
[0133] Step 404: Repeat step 403 until the convergence condition is met:
[0134] max|p i t+1 -p i t |<δ,max|q i t+1 -q i t |<δ
[0135] Specifically, in step 403, the probability p of the attacker taking each strategy i is updated according to the profit matrixi and the probability q that the defender chooses each strategy j j , including the following steps:
[0136] (1) Quantify the attack success probability P of a node based on the exploitability index of the node vulnerability s (AS i ), exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, which are obtained according to CVSS. s (AS i ) is calculated as:
[0137]
[0138] in is the attacker's strategy AS i The value corresponding to the vulnerability being attacked
[0139] (2) The probability p that the attacker chooses strategy i i The update formula is:
[0140]
[0141] (3) The probability q that the defender chooses strategy j j The update formula is:
[0142]
[0143] Where n' and n" are the total number of attacker strategies and defender strategies, respectively, and μ and θ are temperature coefficients used to control the randomness of strategy selection.
[0144] The application effect of the present invention is described in detail below in conjunction with simulation.
[0145] This simulation simulates three different devices as high-risk node devices obtained by other network analysis methods: Device 1 is a service provider device; Device 2 is a database device; Device 3 is a service chain upstream device. The experimental results obtained by applying this solution on the three devices are as follows: Figure 2-Figure 4 As shown, from left to right are the experimental results of device 1, device 2 and device 3. Table 1 shows the experimental results on each device in detail.
[0146] Table 1 Experimental results on various devices
[0147]
[0148] In the simulation, since device 1 is a service provider, it will provide greater service value after being compromised. Therefore, the attacker adopts strategy 3: the probability of DDoS attack is the highest. At this time, the optimal strategy for the defender is to deploy an intrusion detection system. Device 2 is a database device that is used to store data and provides greater economic value. Therefore, the attacker adopts strategy 1: the probability of SQL injection attack is the highest. At this time, the optimal strategy for the defender is database permission setting. Device 3 is an upstream device in the service chain, and there are multiple services downstream. Therefore, the attacker adopts strategy 2: the probability of system control attack is the highest. At this time, the optimal strategy for the defender is system permission isolation.
[0149] Finally, it should be noted that the above description is only a preferred example of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein by equivalents. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A high-risk network node defense method based on effect function weight calculation and game theory, characterized in that: The following steps are involved: S11. Obtain high-risk nodes in the network through attack graph analysis and collect security information of high-risk nodes; S12. Based on the security information of the target node, the profit indicators of the attacker and the defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method; S13, based on the node security information and weight information, calculate the utility functions of the attacker and defender when the attacker and defender adopt different strategies respectively; S14. Obtain the attack strategy and defense strategy selection probability vector of each node through game theory; S15. Select the maximum value of the probability according to the strategy of each node to obtain the optimal defense strategy of the current node.
2. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 1 is characterized by: In step S11, security information of high-risk network nodes is collected, and the security information includes the asset economic value, service economic value, data economic value, vulnerabilities, possible attack strategies, and available defense strategies of the collected network nodes.
3. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 1 is characterized by: In step S12, the profit indicators of the attacker and the defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method, which specifically includes the following steps: 1) Based on the node security information, extract the profit indicators of attackers and defenders, and the available defense strategies of defenders; 2) Obtain the subjective weight vectors of the attacker and defender's benefit indicators respectively through progressive AHP; 3) Use the first formula to obtain the objective weight w of the jth indicator in the attacker and defender's benefit indicators respectively through the entropy weight method j , and finally form the attacker's profit index weight W E ' and the defender's benefit indicator weight W E ”: The first formula is: in i=1,2…m;j=1,2…n,m is the total number of high-risk nodes, n is the number of indicators, find W E 'When is n', find W E "When it is n", x i,j It is the quantitative value of the i-th target asset on the j-th indicator; 4) Based on the subjective weight vector W of the attacker's benefit index and the defender's benefit index AHP ' and W AHP "、Objective weight vector W E ' and W E ", use the second formula to obtain the comprehensive weight vector W' of the attacker's benefit index and the comprehensive weight vector W" of the defender's benefit index; The second formula is: Among them, α is the subjective weight effectiveness factor, which is used to control the effectiveness of the subjective weight in the comprehensive weight and is obtained in the progressive AHP algorithm.
4. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 3 is characterized by: Obtain the subjective weight vector W of the attacker's benefit index and the defender's benefit index through progressive AHP AHP ' and W AHP ",include: 1) Establish target layer, criterion layer and scheme layer for attacker benefit indicators on high-risk network nodes; 2) T experts weight the criteria layer indicators to obtain multiple comparison matrices A1, A2, ...A T ; 3) Based on T comparison matrices, calculate the weight w of the t-th expert in the r-th round for the i-th indicator using the third formula: t,r (r), which constitutes the weighted evaluation result vector w of each expert t,r ; The third formula is: 4) Evaluate the result vector w based on the weight of each expert t,r The global weight vector w is calculated by the fourth formula r ; The fourth formula is: 5) Through the global weight vector w r Calculate the suggestion matrix A according to the fifth formula * r : The fifth formula is: 6) The proposed matrix A * r As a reference, it is fed back to the experts for the next round of scoring until the global weight vector w r Satisfy the consistency check, the total number of iterations r is α, w r is the final attacker benefit indicator weight W AHP ', where the defender's benefit indicator weight W AHP ” is calculated in the same way.
5. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 4 is characterized by: In step S13, the utility functions of the attacker and defender when they adopt different strategies are calculated, which specifically include the following: 1) Based on the obtained W' and W", calculate the attacker's benefit b' (AS) when the attacker selects the i-th attack strategy and the defender selects the j-th defense strategy according to the sixth formula i ,DS j ) and the defender's payoff b”(AS i ,DS j ); The sixth formula is: Among them, β is the control factor, value k is the return corresponding to the current indicator; 2) Calculate the cost when the attacker chooses the i-th attack strategy: turn i )=c′ e (AS i )+c′ r (AS i ): Among them, c' e (AS i ) is the execution time cost, c' r (AS i ) is the resource cost; 3) Calculate the cost when the defender selects the jth defense strategy: c″(DS j )=c″ d (DS j )+c″ m (DS j ); Among them, c″ d (DS j ) is the deployment cost, c″ m (DS j ) is the maintenance cost; 4) Calculate the attacker’s utility function: U A (i,j)=b'(AS i ,DS j )-c'(AS i ); 5) Calculate the defender’s utility function: U D (i,j)=b”(AS i ,DS j )-c”(DS j ).
6. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 5 is characterized by: In step S14, the attack strategy and defense strategy selection probability vectors of the node are obtained respectively through game theory, which specifically include the following: 1) Construct the profit matrices of the attacker and defender respectively according to their utility functions; 2) Calculate the probability p of the attacker adopting each strategy i i and the probability q that the defender chooses each strategy j j , 3) Use iterative optimization method to obtain p i and q j .
7. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 6 is characterized by: In step S15, the probability p of the attacker taking each strategy i is calculated based on the payoff matrix. i and the probability q that the defender chooses each strategy j j , specifically including the following: 1) Quantify the attack success probability P of a node based on the exploitability index of the node vulnerability s (AS i ), the calculation formula is: P s (AS i )=8.22*AV*AC*PR*UI Among them, the exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, which are obtained according to CVSS; 2) According to the seventh formula, calculate the probability p that the attacker chooses strategy i i ; The seventh formula is: 3) Calculate the probability q of the defender selecting strategy j according to the eighth formula j , the eighth formula is: Where n' and n" are the total number of attacker strategies and defender strategies, respectively, and μ and θ are temperature coefficients used to control the randomness of strategy selection.
Citation Information
Patent Citations
Method for selecting optimized protection strategy for network security
CN101820413B
Attack and defense evolutionary game analysis based network defense action decision method
CN107566387A
Global security game decision-making method of industrial information physical system in cloud environment
CN115174173A
Over-the-horizon air combat simulation target threat assessment method based on dynamic game variable weight
CN115759754A
Target value analysis method based on attack and defense game
CN117952434A