High-risk network node defense method based on effect function weight calculation and game theory
By combining the effect function weight calculation and game theory method with the progressive AHP and entropy weight method, the strategy selection probability of both the attacker and the defender is dynamically updated, which solves the problem of inaccurate strategy caused by different asset importance in network security defense and achieves more accurate and dynamic defense strategy selection.
Patent Information
- Application Number
- CN202510172496.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-02-17
AI Technical Summary
Existing technologies fail to effectively consider the different importance of asset information such as services and data on different devices in network security defense, resulting in inaccurate defense strategies.
A method based on effect function weight calculation and game theory is adopted to obtain high-risk nodes through attack graph analysis. The comprehensive weight is calculated using progressive AHP and entropy weight method. The strategy selection probability of both the attacker and defender is dynamically updated by combining vulnerability characteristics and strategy costs.
It improves the accuracy and dynamic balance of defense strategies, reduces subjectivity and randomness, and enhances the effectiveness of defense measures and the accuracy of strategy selection.
Smart Images

Figure CN119945792B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security defense technology, and specifically to a high-risk network node defense method based on effect function weight calculation and game theory. Background Art
[0002] With the rapid development of network technology, modern information systems are becoming increasingly complex, and network security issues are becoming increasingly prominent. High-risk nodes are identified through network analysis, such as attack graphs and intrusion detection. Due to their importance and vulnerability within the network, they often become prime targets for attack. In recent years, game theory has been increasingly applied to network security to simulate the game behavior between attackers and defenders, providing theoretical support for security defense in complex networks.
[0003] Chinese patent CN101820413B discloses a method for selecting the optimal network security protection strategy. This method collects and analyzes host information, link information, service information, protection system information, economic costs, and asset importance information during the attack and defense process in real time. It then uses statistical and correlation analysis techniques to output the analysis results and calculate the performance of the attack and defense strategy. Chinese patent CN107566387A discloses a network defense action decision-making method based on attack and defense evolutionary game analysis. However, this solution does not consider the varying importance of asset information such as services and data on different devices. Summary of the Invention
[0004] In view of the shortcomings of the existing technology, the present invention discloses a high-risk network node defense method based on effect function weight calculation and game theory to solve the problems raised in the above background technology.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a high-risk network node defense method based on effect function weight calculation and game theory, comprising the following steps:
[0006] S11. Obtain high-risk nodes in the network through attack graph analysis and collect security information of high-risk nodes;
[0007] S12. Based on the security information of the target node, obtain the benefit indicators of the attacker and defender, and use the progressive AHP and entropy weight method to obtain the comprehensive weight information of each indicator;
[0008] S13. Based on the node security information and weight information, calculate the utility functions of the attacker and defender when the attacker and defender adopt different strategies respectively;
[0009] S14. Obtain the attack strategy and defense strategy selection probability vectors for each node through game theory;
[0010] S15. Select the maximum probability according to the strategy of each node to obtain the optimal defense strategy of the current node.
[0011] Preferably, in step S11, security information of high-risk network nodes is collected, and the security information includes the asset economic value, service economic value, data economic value, vulnerabilities, possible attack strategies and available defense strategies of the collected network nodes, and device vulnerabilities are detected through vulnerability tools, and vulnerability exploitability indicators are obtained according to the general vulnerability scoring standards.
[0012] Preferably, in step S12, the profit indicators of the attacker and defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method, which specifically includes the following steps:
[0013] 1) Based on node security information, extract the profit indicators of attackers and defenders, and the defense strategies available to defenders;
[0014] 2) Obtain the subjective weight vector W of the attacker and defender's benefit indicators through progressive AHP AHP ' and W AHP ”;
[0015] 3) Use the first formula to obtain the objective weight w of the jth indicator in the attacker and defender's benefit indicators respectively through the entropy weight method j , and finally form the attacker's profit index weight W E ' and the defender's benefit indicator weight W E ”:
[0016] The first formula is:
[0017]
[0018] in i=1,2…m;j=1,2…n,m is the total number of high-risk nodes, n is the number of indicators, calculate W E 'When n', find W E "When it is n", x i,j It is the quantitative value of the i-th target asset on the j-th indicator;
[0019] 4) Based on the subjective weight vector W of the attacker's benefit index and the defender's benefit index AHP ' and W AHP "、Objective weight vector W E ' and W E ", use the second formula to obtain the comprehensive weight vector W' of the attacker's benefit index and the comprehensive weight vector W" of the defender's benefit index:
[0020]
[0021] The second formula is:
[0022]
[0023] Among them, α is the subjective weight effectiveness factor, which is used to control the effectiveness of the subjective weight in the comprehensive weight and is obtained in the progressive AHP algorithm.
[0024] Preferably, the subjective weight vector W of the attacker's benefit index and the defender's benefit index is obtained through progressive AHP AHP ' and W AHP ",include:
[0025] 1) Establish target layer, criterion layer and solution layer for attacker benefit indicators on high-risk network nodes;
[0026] 2) T experts perform weighted scoring on the criteria layer indicators to obtain multiple comparison matrices A1, A2, ...A T ;
[0027] 3) Based on T comparison matrices, calculate the weight w of the t-th expert in the r-th round for the i-th indicator using the third formula: t,r (i) The weighted evaluation result vector w of each expert t,r ;
[0028] The third formula is:
[0029]
[0030] 4) According to the weight evaluation result vector w of each expert t,r The global weight vector w is calculated by the fourth formula r ;
[0031] The fourth formula is:
[0032]
[0033] 5) Through the global weight vector w r Calculate the suggestion matrix A according to the fifth formula * r :
[0034] The fifth formula is:
[0035]
[0036] 6) The proposed matrix A * r Feedback is given to the experts as a reference for the next round of scoring until the global weight vector w r Satisfy the consistency check, the total number of iterations r is α, w ris the final attacker benefit indicator weight W AHP '; The defender's benefit indicator weight W AHP ” is calculated in the same way.
[0037] Preferably, in step S13, the utility functions of the attacker and defender when they adopt different strategies are calculated, which specifically includes the following:
[0038] 1) Based on the obtained W' and W", calculate the attacker's profit b' (AS) when the attacker selects the i-th attack strategy and the defender selects the j-th defense strategy according to the sixth formula. i ,DS j ) and the defender's payoff b”(AS i ,DS j );
[0039]
[0040] The sixth formula is:
[0041]
[0042] Among them, n' and n" are the total number of profit indicators of attacker and defender respectively, β is the control factor, value k is the return corresponding to the current indicator;
[0043] 2) Calculate the cost when the attacker chooses the i-th attack strategy:
[0044] c′(AS i ) = c′ e (AS i )+c′ r (AS i );
[0045] Among them, c' e (AS i ) is the execution time cost, which is determined by the time it takes to execute an attack with this strategy; c' r (AS i ) is the resource cost, which is determined by the malware purchase cost, development cost, and cloud computing resource cost;
[0046] 3) Calculate the cost when the defender selects the jth defense strategy:
[0047] c”(DS j )=c” d (DS j )+c” m (DS j );
[0048] Among them, c”d (DS j ) is the deployment cost, c” m (DS j ) is the maintenance cost;
[0049] 4) Calculate the attacker's utility function: U A (i,j)=b'(AS i ,DS j )-c'(AS i );
[0050] 5) Calculate the defender's utility function: U D (i,j)=b”(AS i ,DS j )-c”(DS j ).
[0051] Preferably, in step S14, the attack strategy selection probability vector p and the defense strategy selection probability vector q of the node are obtained respectively through game theory, which specifically includes the following:
[0052] 1) Construct the attacker's profit matrix U according to the utility functions of the attacker and defender respectively A and the defender's payoff matrix U D ;
[0053]
[0054] 2) Initialize p in a uniformly distributed manner i and q j , calculate the probability p that the attacker adopts each strategy i i and the probability q that the defender chooses each strategy j j ,
[0055] 3) Use iterative optimization method to obtain p i and q j , repeat the above steps until the convergence condition is met or the number of iterations reaches the maximum value.
[0056] Preferably, in step S15, the probability p of the attacker adopting each strategy i is calculated according to the profit matrix i and the probability q that the defender chooses each strategy j j , specifically including the following:
[0057] 1) Quantify the attack success probability P of a node based on the exploitability index of the node vulnerability s (AS i );P s (AS i ) is calculated as:
[0058] Ps (AS i )=8.22*AV*AC*PR*UI
[0059] Among them, the exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, which are obtained according to CVSS.
[0060] 2) Calculate the probability p of the attacker choosing strategy i according to the seventh formula i ; The seventh formula is:
[0061]
[0062] 3) Calculate the probability q of the defender selecting strategy j according to the eighth formula j , the eighth formula is:
[0063]
[0064] Where n' and n" are the total number of attacker and defender strategies, respectively, and μ and θ are temperature coefficients used to control the randomness of strategy selection.
[0065] Compared with the prior art, the present invention has the following beneficial effects:
[0066] 1. The present invention uses progressive AHP to calculate the subjective weight of the utility function through multiple rounds of feedback. The suggestion matrix obtained from the results of the previous round of evaluation is used as feedback to provide a reference for the evaluation of this round. Multiple rounds of evaluation can reduce the subjectivity and randomness of ordinary AHP.
[0067] 2. The present invention takes into account the different importance of the same indicator at each node in the system and uses the entropy weight method to calculate the objective weight of the utility function; the subjective weight and the objective weight are combined through the effective factor to obtain the comprehensive weight. The effective factor can reflect the effectiveness of the subjective weight. The larger the effective factor is, the more difficult it is to unify the expert opinions and the need to reduce the effectiveness of the subjective weight.
[0068] 3. This invention combines node availability metrics and utility functions to calculate strategy selection probabilities using an iterative update method. Incorporating vulnerability characteristics into the utility matrix calculations results in more accurate results. Furthermore, the interdependence of strategy selection probabilities between the attacker and defender allows for a dynamic balance between their strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.
[0070] In the attached figure:
[0071] Figure 1 This is a flowchart of a high-risk network node defense method based on effect function weight calculation and game theory provided by an embodiment of the present invention;
[0072] Figure 2 is a strategy selection probability graph on the network node device 1 in an embodiment of the present invention;
[0073] Figure 3 is a strategy selection probability graph on the network node device 2 in an embodiment of the present invention;
[0074] Figure 4 It is a strategy selection probability graph on the network node device 3 in an embodiment of the present invention. DETAILED DESCRIPTION
[0075] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0076] Example: Figure 1 As shown, the present invention provides a high-risk network node defense method based on effect function weight calculation and game theory. By introducing progressive AHP and entropy weight method to calculate the weight of each indicator to reflect its different importance, progressive AHP can reduce the subjectivity of weight evaluation. In addition, the above scheme does not consider the impact of vulnerability characteristics on the attacker's strategy selection. Since vulnerability characteristics are public, attackers will be affected by their characteristics and their own strategy selection. Therefore, the present invention quantifies vulnerability characteristics by using a universal vulnerability scoring standard and uses it to calculate the probability of the attacker's strategy selection. It further combines actual scenarios to improve the accuracy of the results. Specifically, it includes the following steps:
[0077] S11: Obtain high-risk nodes in the network through attack graph analysis, and use tools to collect security information of high-risk nodes.
[0078] S12: Based on the target node information, the attacker's benefit index and the defender's benefit index are obtained, and the comprehensive weight information of each index is obtained by using the progressive AHP and entropy weight method.
[0079] S13: Based on the node information and weight information, the utility functions of the attacker and defender are calculated when the attacker and defender respectively adopt different strategies.
[0080] S14: Obtain the attack strategy and defense strategy selection probability vectors for each node through game theory.
[0081] S15: Finally, the maximum value of the probability is selected according to the strategy of each node to obtain the optimal defense strategy of the current node.
[0082] Specifically, in step S11, tools are used to collect security information of high-risk network nodes. The economic value of assets, economic value of services, economic value of data, available attack strategies, and available defense strategies are collected through internal company data. Device vulnerabilities are detected through vulnerability tools, and vulnerability exploitability indicators are obtained based on general vulnerability scoring standards.
[0083] Asset economic value X e Determined by the market value of the assets contained in the network node; the economic value of the service is X s Determined by the service loss cost per unit time; the economic value of data is X d Determined by the market value of the data; the economic value of the system is X sys Determined by the economic value of downstream services.
[0084] Available attack strategies include SQL injection data theft, system control attacks, and DDoS attacks; available defense strategies include database permission settings, system permission isolation, and intrusion detection systems; device vulnerabilities include unauthorized access vulnerability CVE-2021-3129, buffer overflow vulnerability CVE-2021-3156, DDoS attack vulnerability CVE-2013-5211, and SQL injection vulnerability CVE-2011-4898.
[0085] Specifically, in step S12, the profit indicators of the attacker and defender are obtained, and the comprehensive weight information of each indicator is obtained by using the progressive AHP and entropy weight method, which includes the following steps:
[0086] Step 201: Based on the collected node security information, extract the attacker's profit index, the defender's profit index, and the defender's available defense strategies.
[0087] Step 202: Obtain the subjective weight vector W of the attacker's benefit index and the defender's benefit index through progressive AHP AHP ' and W AHP ”.
[0088] Step 203: Obtain the objective weight w of the jth indicator in the attacker's benefit index and the defender's benefit index respectively by using the entropy weight method j , and finally form the attacker's profit index weight vector W E ' and the defender's benefit indicator weight vector W E ”.w j The calculation formula is:
[0089]
[0090] in i=1,2…m;j=1,2…n;n=n',n”, m is the total number of high-risk nodes, n is the number of indicators, calculate W E'When the value is n', find W E "When the value is n", x i,j It is the quantitative value of the i-th target asset on the j-th indicator.
[0091] Step 204: Based on the subjective weight vector W of the attacker's profit index and the defender's profit index AHP ' and W AHP "、Objective weight vector W E ' and W E ”, calculate the comprehensive weight vector W’ of the attacker’s benefit index and the comprehensive weight vector W” of the defender’s benefit index.
[0092] Specifically, in step 202, the progressive AHP is used to obtain the subjective weight vector W of the attacker's benefit index and the defender's benefit index. AHP ' and W AHP ”, including the following steps:
[0093] (1) Establish target layer, criterion layer and scheme layer for attacker benefit indicators on high-risk network nodes.
[0094] (2) T experts compare the criteria layer indicators pairwise and perform weighted scoring to obtain T comparison matrices A1, A2, ...A T .
[0095] (3) Based on T comparison matrices, calculate the weight w of the t-th expert in the r-th round for the i-th indicator t,r (i) The weighted evaluation result vector w of each expert t,r , w t,r The calculation formula for (i) is:
[0096]
[0097] Among them, n' is the number of indicators of the attacker, A t (i,j) is the value of row i and column j in the Tth comparison matrix.
[0098] (4) The result vector w is evaluated based on the weight of each expert t,r Calculate the global weight vector w r :
[0099]
[0100] (5) Through the global weight vector w r Calculate the suggestion matrix A * r , A * r The calculation formula for (i,j) is:
[0101]
[0102] Where n' is the number of indicators of the attacker.
[0103] (6) The proposed matrix A * r Feedback is given to the experts as a reference for the next round of scoring until the global weight vector w r Satisfy the consistency check and record the total number of iterations r as the weight effective factor α, w r As the final attacker benefit indicator weight W AHP '.
[0104] (7) Defender's benefit indicator weight W AHP ” is calculated in the same way.
[0105] Specifically, in step 203, the objective weight w of the jth indicator in the attacker's benefit index and the defender's benefit index is obtained by the entropy weight method. j . The following steps are included:
[0106] (1) Construct the decision matrix X, x i,j Represents the quantitative value of the i-th asset on the j-th attacker indicator.
[0107] (2) According to Normalize the decision matrix X to obtain R.
[0108] (3) Calculate the entropy value of the target
[0109] (4) Calculate the weight of indicator i W E '=[w1',w2',w3',w4'] T
[0110] (5) The same method is used to obtain W E ”=[w1”,w2”,w3”,w4”] T
[0111] Specifically, in step 204, the calculation formulas for the comprehensive weight vector W′ of the attacker's benefit index and the comprehensive weight vector W″ of the defender's benefit index are:
[0112]
[0113] Among them, α is the subjective weight effectiveness factor, which can control the effectiveness of the subjective weight in the comprehensive weight and is obtained in the progressive AHP algorithm.
[0114] Specifically, the calculation of the utility functions of the attacker and defender when they adopt different strategies in S13 includes the following steps:
[0115] Step 301: Based on the obtained W′ and W″, calculate the attacker's profit b′ (AS i ,DS j ) and the defender's payoff b”(AS i ,DS j ):
[0116]
[0117] Where n′ and n” are the total number of profit indicators of the attacker and defender respectively, β is the control factor. If the current strategy can obtain the kth profit indicator, then β = 1, otherwise β = 0, value k is the profit corresponding to the current indicator.
[0118] Step 302: Calculate the cost c′ (AS i ):
[0119] c′(AS i ) = c′ e (AS i )+c′ r (AS i )
[0120] Among them, c′ e (AS i ) is the execution time cost, which is determined by the time it takes to execute an attack with this strategy; c′ r (AS i ) is the resource cost, which is determined by the malware purchase cost, development cost, and cloud computing resource cost.
[0121] Step 303: Calculate the cost c when the defender selects the jth defense strategy d (DS j ):
[0122] c”(DS j )=c” d (DS j )+c” m (DS j )
[0123] Among them, c” d (DS j ) is the deployment cost, determined by the sum of the costs of the individually deployed defense measures; c” m (AS i ,DS j ) is the maintenance cost, which is determined by the operating cost per unit time and the total operating time.
[0124] Step 304: Calculate the attacker's utility function U A (i,j), the calculation formula is:
[0125] U A (i,j)=b'(AS i ,DS j )-c'(AS i )
[0126] Step 305: Calculate the defender's utility function U D (i,j), the calculation formula is:
[0127] U D (i,j)=b”(AS i ,DS j )-c”(DS j )
[0128] Specifically, according to the game theory in S14, respectively obtaining the attack strategy selection probability vector p and the defense strategy selection probability vector q of the node includes the following steps:
[0129] Step 401: Construct the attacker's payoff matrix U based on the attacker's and defender's utility functions. A and the defender's payoff matrix U D .
[0130]
[0131] Step 402: Initialize p in a uniform distribution i and q j ,
[0132] Step 403: Update the probability p of the attacker adopting each strategy i according to the formula i and the probability q that the defender chooses each strategy j j .
[0133] Step 404: Repeat step 403 until the convergence condition is met:
[0134] max|p i t+1 -p i t |<δ,max|q i t+1 -q i t |<δ
[0135] Specifically, in step 403, the probability p of the attacker taking each strategy i is updated according to the profit matrixi and the probability q that the defender chooses each strategy j j , including the following steps:
[0136] (1) Quantify the attack success probability P of a node based on the exploitability index of the node vulnerability s (AS i ), exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, obtained according to CVSS. s (AS i ) is calculated as:
[0137]
[0138] in is the attacker's strategy AS i The value corresponding to the vulnerability being attacked
[0139] (2) The probability p that the attacker chooses strategy i i The update formula is:
[0140]
[0141] (3) The probability q that the defender chooses strategy j j The update formula is:
[0142]
[0143] Where n' and n" are the total number of attacker and defender strategies, respectively, and μ and θ are temperature coefficients used to control the randomness of strategy selection.
[0144] The application effect of the present invention is described in detail below in conjunction with simulation.
[0145] This simulation simulates three different devices as high-risk node devices obtained by other network analysis methods: Device 1 is a service provider device; Device 2 is a database device; Device 3 is an upstream device in the service chain. The experimental results obtained by applying this solution on the three devices are as follows: Figure 2-Figure 4 As shown in the figure, from left to right are the experimental results of device 1, device 2 and device 3. Table 1 shows the experimental results on each device in detail.
[0146] Table 1 Experimental results on various devices
[0147]
[0148] In the simulation, since Device 1 is a service provider and would provide significant service value if compromised, the attacker would employ Strategy 3: DDoS attack, which would result in the highest probability of a DDoS attack. In this case, the optimal strategy for the defender is to deploy an intrusion detection system. Device 2 is a database device used for data storage and provides significant economic value. Therefore, the attacker would employ Strategy 1: SQL injection attack, which would result in the highest probability of a SQL injection attack. In this case, the optimal strategy for the defender is to set database permissions. Device 3 is an upstream device in the service chain, with multiple downstream services. Therefore, the attacker would employ Strategy 2: System control attack, which would result in the highest probability of a system control attack. In this case, the optimal strategy for the defender is to isolate system permissions.
[0149] Finally, it should be noted that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A high-risk network node defense method based on effect function weight calculation and game theory, characterized by: The following steps are involved: S11. Obtain high-risk network nodes in the network through attack graph analysis and collect security information of high-risk network nodes; S12. Based on the security information of high-risk network nodes, obtain the benefit indicators of attackers and defenders, and use the progressive AHP and entropy weight method to obtain the comprehensive weight information of each indicator; specifically, the following steps are included: 1) Based on the security information of high-risk network nodes, extract the profit indicators of attackers and defenders, and the defense strategies available to defenders; 2) Obtain the subjective weight vectors of the attacker and defender's benefit indicators respectively through progressive AHP; 3) Use the first formula to obtain the first two indicators of the attacker and defender's benefits through the entropy weight method. Objective weight of indicators , and finally form the attacker's profit index weight and defender benefit indicator weights : The first formula is: ; in , is the total number of high-risk network nodes, is the index number, find When n is ,beg When n is , n′ and n” are the profit indicators of attacker and defender respectively, It means the The target asset is Quantitative value of each indicator; 4) Subjective weight vector based on attacker benefit index and defender benefit index and , objective weight vector and , use the second formula to obtain the comprehensive weight vector of the attacker's profit index and the comprehensive weight vector of the defender's benefit index ; The second formula is: ; in, The subjective weight effectiveness factor is used to control the effectiveness of the subjective weight in the comprehensive weight and is obtained through the progressive AHP algorithm; S13. Based on the security information and weight information of high-risk network nodes, calculate the effect functions of the attacker and defender when the attacker and defender adopt different strategies respectively; S14. Obtain an attack strategy selection probability vector and a defense strategy selection probability vector for each high-risk network node through game theory; S15. According to the strategy of each high-risk network node, the maximum value of the probability is selected to obtain the optimal defense strategy of the current node.
2. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 1 is characterized by: In step S11, security information of high-risk network nodes is collected, where the security information includes the asset economic value, service economic value, data economic value, vulnerabilities, attack strategies, and available defense strategies of the high-risk network nodes.
3. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 1 is characterized by: Obtain the subjective weight vector of attacker benefit index and defender benefit index through progressive AHP and ,include: 1) Establish target layer, criterion layer and solution layer for attacker benefit indicators on high-risk network nodes; 2) By Experts weight and score the criteria-level indicators to obtain multiple comparison matrices ; 3) Based on T comparison matrices, calculate the Wheel Experts on The weight of the indicator , which constitutes the weighted evaluation result vector of each expert ; The third formula is: , where A t (i j) is the value of row i and column j in the t-th comparison matrix; 4) Evaluate the result vector based on each expert's weight The global weight vector is calculated by the fourth formula ; The fourth formula is: ; 5) Through the global weight vector Calculate the suggestion matrix according to the fifth formula : The fifth formula is: ; 6) The suggestion matrix Feedback to experts as a reference for the next round of scoring until the global weight vector Satisfy the consistency check, the total number of iterations for , The final attacker benefit indicator weight , where the defender's benefit indicator weight Calculation is performed in the same way.
4. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 3 is characterized by: In step S13, the utility functions of the attacker and defender when they adopt different strategies are calculated, which specifically includes the following: 1) Based on the obtained and , according to the sixth formula, the attacker selects Attack strategy and defender selection The attacker's profit when using a defensive strategy and defender benefits ; The sixth formula is: ; in, is the control factor, is the return corresponding to the current indicator, and are the total number of attacker strategies and defender strategies, respectively; 2) Calculate the attacker's selection of The cost of this attack strategy is: ; in, is the execution time cost, is the resource cost; 3) Calculate the defender's selection The cost of a defensive strategy: ; in, is the deployment cost, is the maintenance cost; 4) Calculate the attacker's utility function: ( ); 5) Calculate the defender's utility function: .
5. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 4 is characterized by: In step S14, the attack strategy and defense strategy selection probability vectors of high-risk network nodes are obtained respectively through game theory, which specifically include the following: 1) Construct the attacker's and defender's payoff matrices based on their utility functions respectively; 2) Calculate the attacker's strategy for each Probability and the defender chooses each strategy Probability , 3) Use iterative optimization method to obtain and .
6. The high-risk network node defense method based on effect function weight calculation and game theory according to claim 5 is characterized by: In step S15, the attacker takes each strategy according to the profit matrix. Probability and the defender chooses each strategy Probability , specifically including the following: 1) Quantify the probability of successful attack on nodes based on the exploitability index of high-risk network node vulnerabilities , the calculation formula is: ; Among them, exploitability indicators include attack vector AV, attack complexity AC, permission requirement PR and user interaction UI, which are obtained according to CVSS; 2) Calculate the attacker's selection strategy based on the seventh formula Probability ; The seventh formula is: ; 3) Calculate the defender selection strategy based on the eighth formula Probability , the eighth formula is: ; in, and is the temperature coefficient, which is used to control the randomness of the strategy selection.
Citation Information
Patent Citations
Method for selecting optimized protection strategy for network security
CN101820413B
Attack and defense evolutionary game analysis based network defense action decision method
CN107566387A
Global security game decision-making method of industrial information physical system in cloud environment
CN115174173A
Unmanned aerial vehicle multi-mode command and control link network selection method under fusion operation
CN119031434A