Network elasticity quantitative evaluation method oriented to DDoS (Distributed Denial of Service) attack

By combining the CRITIC method, Choquet fuzzy integral and three-dimensional model methods, the problem of low accuracy and difficult to compare network elasticity assessment in the prior art is solved, and a more accurate and comprehensive elastic evaluation of the system when facing DDoS attacks is achieved.

CN120017391APending Publication Date: 2025-05-16ZHENGZHOU UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510204124.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing network elastic quantitative evaluation method considers single factors when facing DDoS attacks, resulting in poor assessment accuracy and difficult to compare.

Method used

The CRITIC method and Choquet fuzzy integration combined with three-dimensional model are used to quantify the overall security performance and network elasticity of the system. By measuring the system security performance changes over time at different DDoS attack intensity, a three-dimensional surface is built to evaluate the overall elasticity of the system when facing DDoS attacks.

Benefits of technology

It realizes objective, accurate and comparable quantitative assessment of network elasticity, which can more accurately evaluate the overall elasticity of the system when facing DDoS attacks, and helps to formulate a more comprehensive elastic strategy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017391A_ABST
    Figure CN120017391A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network elasticity evaluation research, in particular to a DDoS attack-oriented network elasticity quantitative evaluation method, which comprises the following steps of: determining DDoS attack intensities under different attack traffic based on the average traffic of a system to be evaluated in a normal working state; respectively fusing the evaluation index values at different moments under each DDoS attack intensity through a CRITIC method and a Choquet fuzzy integral method, and determining the overall system safety performance values of the to-be-evaluated system at different moments under each DDoS attack intensity; and based on a three-dimensional curved surface formed by the system overall safety performance values of the to-be-evaluated system under different DDoS attack intensities in the three-dimensional coordinate system, determining the overall elasticity of the to-be-evaluated system facing the DDoS attack. According to the method, the network elasticity quantitative evaluation facing the DDoS attack is realized, and the accuracy of the network elasticity quantitative evaluation is improved by adopting an objective quantification means.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the research field of network resilience evaluation, and in particular to a network resilience quantitative evaluation method for DDoS attacks. Background Art

[0002] In recent years, the scale and frequency of DDoS attacks have increased significantly. For example, the 2024 DDoS Trend Report shows that compared with 2022, the total number of DDoS attacks in 2023 has decreased by 74%, but the average attack size has soared by 233.33%, and the maximum attack size has reached 700Gbps, an increase of 42% over 2022. This growth trend highlights the serious threat that DDoS attacks pose to the stability of the Internet and corporate operations. In addition, DDoS attacks are easy to implement, difficult to defend, have a wide range of impact, and are highly destructive, making them a more preferred target for attackers. The increase in the scale and frequency of DDoS attacks makes it more important to assess the resilience of the system against DDoS attacks, as this is directly related to the continuity and reliability of corporate business. Effective resilience assessment can help identify the weak links of the system, develop corresponding defense measures, and improve the system's response and recovery capabilities when it is attacked by DDoS. Therefore, for any organization that relies on network services, conducting a system resilience assessment under DDoS attacks is a key step in ensuring network security and business continuity.

[0003] Existing network resilience assessments are mainly divided into two categories: qualitative assessment and quantitative assessment. Qualitative assessment methods evaluate and judge network resilience based on factors such as threats, vulnerabilities, and security measures faced by the system and rely on the knowledge and experience of experts. Although the operation process of qualitative assessment methods is relatively simple and suitable for situations where data materials are insufficient, its assessment results are too dependent on the experience and knowledge of the experts themselves and are highly subjective. In addition, they lack comparability. The evaluation results of the same system in different environments or under different experts will be different, resulting in the inability to compare the assessment results.

[0004] The evaluation results of quantitative evaluation methods are objective, and the evaluation results only depend on the accuracy and completeness of the measured data, and do not rely on expert opinions or subjective judgments. At present, the most commonly used quantitative evaluation method in network resilience evaluation is to evaluate the network resilience of the system through the area under the curve (AUC) ratio. Specifically, the ratio of the area under the curve of the system's overall security performance over time to the area under the baseline curve under a given attack mode is used to evaluate the network resilience of the system. Although the resilience evaluation method based on the area under the curve (AUC) is popular due to its quantitative characteristics, it can provide objective evaluation results for the system resilience under a specific attack mode. However, the intensity of DDoS attacks is variable, and the AUC evaluation method can only evaluate the resilience of the system under a specific attack mode (or intensity). It is difficult to reflect the overall resilience of the system when facing DDoS attacks, resulting in poor accuracy in the quantitative evaluation of network resilience. Summary of the invention

[0005] In order to solve the problem that the existing network resilience quantitative evaluation method has poor accuracy and is difficult to compare because the existing network resilience quantitative evaluation method considers only a single factor when evaluating DDoS attacks, the present invention proposes a network resilience quantitative evaluation method for DDoS attacks.

[0006] The present invention provides a method for quantitatively evaluating network resilience against DDoS attacks, which proposes a method for quantifying the overall security performance of the system, namely, objective quantification through the CRITIC method and Choquet fuzzy integral. This quantification method is objective and can solve the problem of subjectivity to a certain extent. Secondly, a method for quantifying the overall network resilience of the system through a three-dimensional model is proposed, namely, the DDoS attack intensity is quantified to make it the vertical axis, and then the changes in the overall security performance of the system under different DDoS attack intensities over time are measured respectively to form three-dimensional data points, and finally the three-dimensional data points are fitted into a three-dimensional surface to evaluate the overall network resilience of the system, which solves the limitations of the area under the curve method to a certain extent. Specifically, a method for quantitatively evaluating network resilience against DDoS attacks provided by the present invention may include:

[0007] Based on the pre-obtained average traffic of the system to be evaluated under normal working conditions and the pre-set different attack traffic, determine the DDoS attack intensity under different attack traffic;

[0008] According to the evaluation index values ​​at different times obtained in advance under each DDoS attack intensity, the evaluation index values ​​at different times under each DDoS attack intensity are respectively integrated through the CRITIC method and the Choquet fuzzy integral method to determine the overall security performance value of the system to be evaluated at different times under each DDoS attack intensity;

[0009] A three-dimensional coordinate system is constructed with time as the horizontal axis, the overall security performance value of the system to be evaluated as the vertical axis, and the DDoS attack intensity as the vertical axis. Based on the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system, the overall resilience of the system to be evaluated when facing DDoS attacks is determined.

[0010] Optionally, the determining of the DDoS attack intensity under different attack flows based on the pre-acquired average flow of the system to be evaluated under normal working conditions and pre-set different attack flows includes:

[0011] The sum of the average flow of the system to be evaluated under normal working conditions and each attack flow is determined as the total flow corresponding to each attack flow;

[0012] The ratio of each attack flow to its corresponding total flow is determined as the DDoS attack intensity under each attack flow.

[0013] Optionally, the step of determining the overall security performance value of the system to be evaluated at different times under each DDoS attack intensity by respectively fusing the evaluation index values ​​at different times under each DDoS attack intensity through the CRITIC method and the Choquet fuzzy integral method according to the evaluation index values ​​at different times pre-acquired under each DDoS attack intensity, includes:

[0014] Determine any DDoS attack intensity as the marked attack intensity, and construct an original data matrix under the marked attack intensity according to all evaluation index values ​​under the marked attack intensity, wherein the evaluation index value is the measured value under the evaluation index;

[0015] Normalizing the original data matrix under the marked attack intensity to obtain a standardized matrix under the marked attack intensity;

[0016] According to the standardized matrix under the marked attack intensity, the weight of each evaluation indicator under the marked attack intensity is determined by the CRITIC method;

[0017] According to the weights of all evaluation indicators under the marked attack intensity, the Choquet fuzzy integral method is used to determine the overall security performance value of the system to be evaluated at each moment under the marked attack intensity.

[0018] Optionally, the step of determining the weight of each evaluation indicator under the marked attack intensity by the CRITIC method according to the standardized matrix under the marked attack intensity includes:

[0019] The standard deviation of all elements in the standardized matrix corresponding to each evaluation indicator under the marked attack intensity is determined as the indicator variability under each evaluation indicator under the marked attack intensity;

[0020] According to the Spearman correlation coefficient between each evaluation indicator under the marked attack intensity and other evaluation indicators, the conflict under each evaluation indicator under the marked attack intensity is determined;

[0021] The product of the indicator variability and conflict under each evaluation indicator under the marking attack intensity is determined as the information amount under each evaluation indicator under the marking attack intensity;

[0022] The proportion of the amount of information under each evaluation indicator under the marked attack intensity in the amount of information under all evaluation indicators is determined as the weight of each evaluation indicator under the marked attack intensity.

[0023] Optionally, the formula corresponding to the conflict under the evaluation index under the marking attack intensity is:

[0024] Among them, R j is the conflict under the jth evaluation indicator under the marked attack intensity; n is the number of items of different evaluation indicators; i and j are the item numbers of different evaluation indicators; r ij is the Spearman correlation coefficient between the j-th evaluation indicator and the i-th evaluation indicator under the marked attack intensity.

[0025] Optionally, the determining the overall resilience capability of the system to be evaluated when facing DDoS attacks based on a three-dimensional surface formed in a three-dimensional coordinate system by the overall security performance values ​​of the system to be evaluated under different DDoS attack intensities includes:

[0026] The ratio of the volume under the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system to the system baseline security performance volume is determined as the overall resilience capability of the system to be evaluated when facing DDoS attacks.

[0027] The present invention has the following beneficial effects:

[0028] First, the method proposed in the present invention adopts an objective quantitative analysis method and relies on measured data for evaluation, which has the advantages of being objective, accurate and comparable.

[0029] Second, the actual situation of DDoS attacks in a real environment is taken into consideration. By measuring the changes in the overall security performance of the system under different DDoS intensities over time, the overall resilience of the system in the face of DDoS attacks is evaluated, helping to formulate a more comprehensive resilience strategy.

[0030] Thirdly, an objective quantitative method for the overall safety performance of the system is given. By constructing an objective quantitative method for the overall safety performance of the system based on the CRITIC method and fuzzy Choquet integral, the objective weights of the indicators are first quantified by the CRITIC method, and then the 2-additive fuzzy measure of the indicator set is calculated. Finally, the fuzzy Choquet integral is used to calculate the quantifiable value of the overall safety of the system, thereby solving the problem that the overall safety performance of the system is difficult to measure directly.

[0031] Fourth, a quantitative evaluation method for network resilience against DDoS attacks was constructed. A three-dimensional surface was generated with time as the horizontal axis, the overall system security performance as the vertical axis, and the DDoS attack intensity as the vertical axis. The overall network resilience of the system against DDoS attacks was evaluated by calculating the ratio of the volume under the three-dimensional surface to the system's baseline security performance volume, thereby improving the accuracy of the quantitative evaluation of network resilience. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0033] Figure 1 The present invention is a flow chart of a method for quantitatively evaluating network resilience against DDoS attacks. DETAILED DESCRIPTION

[0034] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the specific implementation methods, structures, features and effects of the technical solutions proposed by the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.

[0035] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0036] refer to Figure 1, showing the process of some embodiments of a network resilience quantitative evaluation method for DDoS attacks according to the present invention. The present invention aims to propose a network resilience quantitative evaluation method for DDoS attacks. In the present invention, a quantification method for DDoS attack intensity is first given, and the method can be applied to systems of different scales. At the same time, a result-oriented resilience index system is given, and then an objective quantification method for the overall security performance of the system is given according to the index system. The quantitative evaluation method in the present invention includes: measuring the change of the overall security performance of the system over time under different DDoS attack intensities, then taking time as the horizontal axis, the overall security performance of the system as the vertical axis, and the DDoS attack intensity as the vertical axis, a three-dimensional surface is formed according to the measured values, and the overall resilience capability of the system facing DDoS attacks is evaluated by calculating the ratio of the volume under the three-dimensional surface to the system baseline security performance volume. Through this evaluation method, the system security performance data of the system facing different DDoS attack intensities can be collected, and then the overall resilience capability of the system facing DDoS attacks can be analyzed and evaluated, so that the system can effectively resist DDoS attacks of different intensities in an actual environment. Such an evaluation method can provide the system with a more accurate and comprehensive security resilience score for DDoS attacks, and help formulate a more comprehensive resilience strategy. Specifically, the network resilience quantitative evaluation method for DDoS attacks includes the following steps:

[0037] Step S1, based on the pre-acquired average flow of the system to be evaluated under normal working conditions and the pre-set different attack flow rates, determine the DDoS attack intensity under different attack flow rates.

[0038] Among them, the system to be evaluated can be a system for which network resilience quantitative evaluation is to be performed against DDoS attacks. The normal working state can be the system state when no DDoS attack is carried out. The method for obtaining the average flow of the system to be evaluated under normal working state can be: under the normal working state of the system to be evaluated, the total flow of the system to be evaluated at multiple times is randomly collected, and the average of the total flow at these times is determined as the average flow of the system to be evaluated under normal working state. The attack flow is the DDoS attack flow (SYNflood, UDPflood, ICMPflood, etc.) collected under the DDoS attack environment. The pre-set different attack flows can be a series of different DDoS attack flows randomly generated according to different speeds, frequencies and scales in a simulated real attack environment.

[0039] It should be noted that the more types of pre-set attack traffic there are, the more comprehensive the consideration of possible DDoS attack situations is, which can improve the accuracy of the subsequent system's overall resilience to DDoS attacks to a certain extent.

[0040] As an example, this step may include the following steps:

[0041] In the first step, the sum of the average flow of the system to be evaluated under normal working conditions and each attack flow is determined as the total flow corresponding to each attack flow.

[0042] The total traffic corresponding to a certain attack traffic indicates the total traffic of the system when the DDoS attack corresponding to the attack traffic occurs.

[0043] In the second step, the ratio of each attack flow to its corresponding total flow is determined as the DDoS attack intensity under each attack flow.

[0044] For example, any attack traffic is determined as marked attack traffic, and the formula corresponding to the DDoS attack intensity under the marked attack traffic can be:

[0045] Where y is the DDoS attack intensity under the marked attack traffic. N1 is the marked attack traffic. N2 is the average traffic of the system to be evaluated under normal working conditions. N1+N2 is the total traffic corresponding to the marked attack traffic.

[0046] It should be noted that when quantifying the intensity of DDoS attacks, the present invention aims to design a more general quantification method, taking into account the inherent differences in hardware equipment and traffic processing capabilities of systems of different scales. This method will comprehensively consider the actual attack scenarios and is suitable for evaluating the resilience of systems of various scales in the face of DDoS attacks, so that they can formulate more comprehensive resilience strategies according to their own conditions. Therefore, in an embodiment of the present invention, the ratio of different attack flows to the total flow of the system to be evaluated under normal working conditions can be determined as the DDoS attack intensity under different attack flows.

[0047] Step S2, according to the evaluation index values ​​at different times obtained in advance under each DDoS attack intensity, the evaluation index values ​​at different times under each DDoS attack intensity are respectively integrated by the CRITIC method and the Choquet fuzzy integral method to determine the overall system security performance value of the system to be evaluated at different times under each DDoS attack intensity.

[0048] It should be noted that in terms of objective quantification of the overall safety performance of the system, the overall safety performance of the system to be evaluated is objectively quantified by constructing a result-oriented index system. It is also considered that the importance of the evaluation indicators in the index system to the system to be evaluated is different and the evaluation indicators are not independent of each other, but there is a certain degree of correlation between the indicators. Therefore, the quantification method that cannot directly add or weight the index values ​​will cause serious distortion of the results. The embodiment of the present invention uses the CRITIC method and fuzzy Choquet integral to quantify it. First, the weight of the evaluation index is calculated by the CRITIC method. This method not only considers the variability of a single index value but also considers the conflict between indicators. At the same time, the CRITIC method is an objective weighting method. Next, by calculating the 2-additive fuzzy measure of the evaluation index, the importance between different indicator sets is calculated, and then the objective quantitative value of the overall safety performance of the system is calculated using the fuzzy Choquet integral.

[0049] As an example, determining the overall security performance value of the system to be evaluated at different times under each DDoS attack intensity may include the following steps:

[0050] In the first step, any DDoS attack intensity is determined as the marked attack intensity, and the original data matrix under the marked attack intensity is constructed according to all evaluation index values ​​under the marked attack intensity.

[0051] The evaluation index value is a measured value under the evaluation index. The evaluation index may be, but is not limited to, CPU utilization, upload and download rate, and correct request response rate within 10 seconds.

[0052] For example, suppose there are m time measurement points and n evaluation indicators, and the original data matrix is ​​established as A=(a kj ) m×n Among them, a kj Represents the measured value of the jth evaluation indicator at the kth time measurement point. The time measurement point is also called a time point or moment.

[0053] In the second step, the original data matrix under the marked attack intensity is normalized to obtain the standardized matrix under the marked attack intensity.

[0054] It should be noted that in order to eliminate the influence of factors such as different dimensions and magnitudes of various indicators on data analysis, each factor is normalized according to the number of each option to form a standardized matrix X, which can be expressed as:

[0055]

[0056] The positive indicator can be expressed as:

[0057]

[0058] Negative indicators can be expressed as:

[0059]

[0060] Among them, a kj is the original data value of the indicator; a jmax is the maximum value of the jth evaluation index; a jmin is the minimum value of the j-th evaluation indicator.

[0061] It should be noted that the calculation of positive and negative indicators is to obtain a standardized matrix. For example, the accuracy is a positive indicator, and the larger the value, the better; the error rate is a negative indicator, and the smaller the value, the better; this distinction is to better normalize indicators of different natures.

[0062] The third step is to determine the weight of each evaluation indicator under the marked attack intensity by the CRITIC method according to the standardized matrix under the marked attack intensity, which can include the following sub-steps:

[0063] In the first sub-step, the standard deviation of all elements in the standardized matrix corresponding to each evaluation indicator under the marked attack intensity is determined as the indicator variability under each evaluation indicator under the marked attack intensity.

[0064] In the second sub-step, the conflict under each evaluation indicator under the marked attack intensity is determined according to the Spearman correlation coefficient between each evaluation indicator under the marked attack intensity and other evaluation indicators.

[0065] For example, the formula corresponding to the conflict under the evaluation index under the marking attack intensity can be:

[0066] Among them, R j is the conflict under the jth evaluation indicator under the marking attack intensity. n is the number of items of different evaluation indicators. i and j are the item numbers of different evaluation indicators. ij is the Spearman correlation coefficient between the jth evaluation indicator and the ith evaluation indicator under the marking attack intensity. If a certain indicator has a high correlation with other indicators, it means that there is a certain overlap in the evaluation content with other indicators, so the weight of such indicators should be reduced.

[0067] In the third sub-step, the product of the indicator variability and the conflict under each evaluation indicator under the marked attack intensity is determined as the information amount under each evaluation indicator under the marked attack intensity.

[0068] For example, the formula for determining the amount of information under the evaluation index under the marking attack intensity can be:

[0069] Cj =S j ×R j Among them, C j is the amount of information under the jth evaluation indicator under the marking attack intensity. S j is the indicator variability under the j-th evaluation indicator under the marked attack intensity. R j is the conflict under the j-th evaluation indicator under the marking attack intensity.

[0070] In the fourth sub-step, the proportion of the amount of information under each evaluation indicator under the marked attack intensity in the amount of information under all evaluation indicators is determined as the weight of each evaluation indicator under the marked attack intensity.

[0071] It should be noted that in the CRITIC method, the standard deviation is used to quantify the degree of variation of the internal values ​​of each indicator. The larger the standard deviation, the wider the range of the value variation of the indicator. Therefore, this indicator has a stronger amount of information and should be given a higher weight.

[0072] For example, the formula for determining the weight of the evaluation index under the marked attack intensity can be:

[0073] Among them, W j is the weight of the jth evaluation indicator under the marked attack intensity. j is the amount of information under the jth evaluation indicator under the label attack intensity. n is the number of items of different evaluation indicators. i and j are the item numbers of different evaluation indicators. C i is the amount of information under the i-th evaluation indicator under the marking attack intensity.

[0074] The fourth step is to determine the overall security performance value of the system to be evaluated at each moment under the marked attack intensity according to the weights of all evaluation indicators under the marked attack intensity through the Choquet fuzzy integral method, which can include the following sub-steps:

[0075] In the first sub-step, the 2-additive fuzzy measure of the indicator set is calculated.

[0076] Let P be the indicator set under the marked attack intensity, P = {P1, P2, .., Pn}. Let W be the weight set of the indicator set P, W = {w1, w2, .., wn}. K-additive fuzzy measure can well solve the contradiction between complexity and accuracy between indicators. Among them, 2-additive fuzzy measure is more practical. Its calculation formula can be expressed as follows:

[0077]

[0078] Among them, K is a set, m i is a single evaluation index P iThe Möbius transformation coefficient, m i,j For the two evaluation indicators {P i , P j} is the Möbius transformation coefficient between .

[0079] The second sub-step is the calculation of the Mobius transform coefficients, which are used in calculating the 2-additive fuzzy measure.

[0080] Let P be the indicator set, P = {P1, P2, .., Pn}. Let W be the weight set of the indicator set P, W = {w1, w2, .., wn}. Then, the single evaluation indicator P i And two evaluation indicators {P i , P j The calculation formula of the Mobius transformation coefficient of} can be expressed as follows:

[0081]

[0082] Where G represents all single evaluation indicators P i and pairwise evaluation index {P i , P j The sum of the importance of}; ij P i With P j The degree of interaction, where λ ij The Spearman correlation coefficient is also used, λ ij ∈[-1, 1].

[0083] The third sub-step is to calculate the fuzzy Choquet integral.

[0084] The fuzzy Choquet integral can be expressed as follows:

[0085]

[0086] Among them, h(P i ) is the evaluation index value, g(A i ) is a 2-additive fuzzy measure between evaluation indicators under the label attack intensity. In addition, in order to maintain generality, it is required that 0≤h(P1)≤h(P2)……≤h(P n ), otherwise it can be rearranged to satisfy the relationship, h(P0) = 0. g(A i ) is to consider the index P at the same time i , P i+1 , P i+2 ,…,P n The importance of 2-additive fuzzy measure, A i = {P i , P i+1 , P i+2,…,P n}.

[0087] Step S3, constructing a three-dimensional coordinate system with time as the horizontal axis, the overall system security performance value of the system to be evaluated as the vertical axis, and the DDoS attack intensity as the vertical axis, and determining the overall resilience of the system to be evaluated against DDoS attacks based on a three-dimensional surface formed by the overall system security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system.

[0088] As an example, the ratio of the volume under the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system to the system baseline security performance volume can be determined as the overall resilience of the system to be evaluated when facing DDoS attacks. The system baseline security performance volume is the volume under the baseline surface, and the baseline surface refers to the surface when it is not attacked.

[0089] It should be noted that by measuring the changes in the overall security performance of the system under different DDoS attack intensities (such as 10%, 20%, ..., 95%) over time, and then taking time as the horizontal axis, the overall security performance of the system as the vertical axis, and the DDoS attack intensity as the vertical axis, a three-dimensional surface is constructed according to the measured values, and the overall resilience of the system to DDoS attacks is evaluated by calculating the ratio of the volume under the three-dimensional surface to the system's baseline security performance volume.

[0090] In summary, the method proposed in the present invention adopts an objective quantitative analysis method, relies on measured data for evaluation, and has the advantages of being objective, accurate and comparable. The result-oriented elasticity index system provides a more concise and effective way. This index system takes the completion of tasks or functions delivered by the system as the core, reflects the details of the system operation through evaluation results, and does not need to spend a lot of energy to consider the intermediate behavior of the system. Taking into account the actual situation of DDoS attacks in a real environment, by measuring the changes in the overall security performance of the system under different DDoS intensities over time, the overall elasticity of the system facing DDoS attacks is evaluated to help formulate a more comprehensive elasticity strategy. An objective quantitative method for the overall security performance of the system is given. By constructing an objective quantitative method for the overall security performance of the system based on the CRITIC method and fuzzy Choquet integral, the objective weights of the indicators are first quantified by the CRITIC method, and then the 2-additive fuzzy measure of the indicator set is calculated. Finally, the fuzzy Choquet integral is used to calculate the quantifiable value of the overall security of the system, thereby solving the problem that the overall security performance of the system is difficult to measure directly. A quantitative evaluation method for network resilience against DDoS attacks was constructed. A three-dimensional surface was generated with time as the horizontal axis, the overall system security performance as the vertical axis, and the DDoS attack intensity as the vertical axis. The overall network resilience of the system against DDoS attacks was evaluated by calculating the ratio of the volume under the three-dimensional surface to the system's baseline security performance volume, thereby improving the accuracy of the quantitative evaluation of network resilience.

[0091] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features can be replaced by equivalents. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A quantitative evaluation method for network resilience against DDoS attacks, characterized in that: The following steps are involved: Based on the pre-obtained average traffic of the system to be evaluated under normal working conditions and the pre-set different attack traffic, determine the DDoS attack intensity under different attack traffic; According to the evaluation index values ​​at different times obtained in advance under each DDoS attack intensity, the evaluation index values ​​at different times under each DDoS attack intensity are respectively integrated through the CRITIC method and the Choquet fuzzy integral method to determine the overall security performance value of the system to be evaluated at different times under each DDoS attack intensity; A three-dimensional coordinate system is constructed with time as the horizontal axis, the overall security performance value of the system to be evaluated as the vertical axis, and the DDoS attack intensity as the vertical axis. Based on the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system, the overall resilience of the system to be evaluated when facing DDoS attacks is determined.

2. According to claim 1, a network resilience quantitative evaluation method for DDoS attacks is characterized in that: The method of determining the DDoS attack intensity under different attack flows based on the pre-acquired average flow of the system to be evaluated under normal working conditions and the pre-set different attack flows comprises: The sum of the average flow of the system to be evaluated under normal working conditions and each attack flow is determined as the total flow corresponding to each attack flow; The ratio of each attack flow to its corresponding total flow is determined as the DDoS attack intensity under each attack flow.

3. According to claim 1, a method for quantitatively evaluating network resilience against DDoS attacks is characterized in that: According to the evaluation index values ​​at different times obtained in advance under each DDoS attack intensity, the evaluation index values ​​at different times under each DDoS attack intensity are respectively integrated by the CRITIC method and the Choquet fuzzy integral method to determine the overall security performance value of the system to be evaluated at different times under each DDoS attack intensity, including: Determine any DDoS attack intensity as the marked attack intensity, and construct an original data matrix under the marked attack intensity according to all evaluation index values ​​under the marked attack intensity, wherein the evaluation index value is the measured value under the evaluation index; Normalizing the original data matrix under the marked attack intensity to obtain a standardized matrix under the marked attack intensity; According to the standardized matrix under the marked attack intensity, the weight of each evaluation indicator under the marked attack intensity is determined by the CRITIC method; According to the weights of all evaluation indicators under the marked attack intensity, the Choquet fuzzy integral method is used to determine the overall security performance value of the system to be evaluated at each moment under the marked attack intensity.

4. A method for quantitatively evaluating network resilience against DDoS attacks according to claim 3, characterized in that: According to the standardized matrix under the marked attack intensity, the weight of each evaluation indicator under the marked attack intensity is determined by the CRITIC method, including: The standard deviation of all elements in the standardized matrix corresponding to each evaluation indicator under the marked attack intensity is determined as the indicator variability under each evaluation indicator under the marked attack intensity; According to the Spearman correlation coefficient between each evaluation indicator under the marked attack intensity and other evaluation indicators, the conflict under each evaluation indicator under the marked attack intensity is determined; The product of the indicator variability and conflict under each evaluation indicator under the marking attack intensity is determined as the information amount under each evaluation indicator under the marking attack intensity; The proportion of the amount of information under each evaluation indicator under the marked attack intensity in the amount of information under all evaluation indicators is determined as the weight of each evaluation indicator under the marked attack intensity.

5. A method for quantitatively evaluating network resilience against DDoS attacks according to claim 4, characterized in that: The formula corresponding to the conflict under the evaluation index under the marking attack intensity is: Among them, R j is the conflict under the jth evaluation indicator under the marked attack intensity; n is the number of items of different evaluation indicators; i and j are the item numbers of different evaluation indicators; r ij is the Spearman correlation coefficient between the j-th evaluation indicator and the i-th evaluation indicator under the marked attack intensity.

6. A method for quantitatively evaluating network resilience against DDoS attacks according to claim 1, characterized in that: The determining of the overall resilience capability of the system to be evaluated when facing DDoS attacks based on the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system includes: The ratio of the volume under the three-dimensional surface formed by the overall security performance value of the system to be evaluated under different DDoS attack intensities in the three-dimensional coordinate system to the system baseline security performance volume is determined as the overall resilience capability of the system to be evaluated when facing DDoS attacks.