Method and device for determining attack and defense information in heterogeneous network, medium and program product
By building a state transformation model of heterogeneous network nodes, the status information of attackers and defenders is determined in real time, which solves the problem that traditional network defense strategies are difficult to deal with dynamic attacks, and improves network security and defense resource utilization efficiency.
Patent Information
- Application Number
- CN202510526185.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-06-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional network defense strategies are difficult to analyze the status of defenders and attackers in real-time, resulting in poor defense performance and difficulty in dealing with dynamic attacks and unknown threats.
By determining the status and probability of network nodes in heterogeneous networks, a state transformation model of network nodes is constructed, and the attack rate of the attacker and the defense rate of the defender are determined in real time, thereby determining the attacker’s and the defender’s status information.
The real-time status information of attackers and defenders in heterogeneous networks is determined, which helps defenders dynamically adjust defense strategies, improve network security, and reasonably allocate defense resources to achieve optimal defense deployment.
Smart Images

Figure CN120090865A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and more particularly to a method for determining attack and defense information in a heterogeneous network, an apparatus for determining attack and defense information in a heterogeneous network, a non-transitory computer-readable storage medium, and a computer program product. Background Art
[0002] With the continuous development of the Internet and information technology, network attacks have become increasingly complex and concealed. Traditional network defense strategies mainly start from the perspective of defenders and rely on passive defense means, such as firewalls, intrusion detection systems, and intrusion prevention systems. These passive defense means gradually show limitations when facing complex and dynamic network attacks. For example, traditional network defense strategies mainly focus on known threats and rely on rule or signature matching to detect attacks. However, attackers constantly adjust their attack means dynamically, making signature-based detection methods difficult to cope with dynamic attacks and unknown threats.
[0003] In network attacks, attackers will dynamically adjust their attack means according to the defenders' defense means. However, since traditional network defense strategies are difficult to analyze the states of defenders and attackers of network nodes, it is difficult for network defense strategies to be adjusted in real time, resulting in poor defense performance. For example, the network defense strategies obtained by traditional defense models lag behind the dynamically adjusted attack means. Summary of the Invention
[0004] To solve or at least mitigate one or more of the above problems, the following technical solutions are provided.
[0005] According to a first aspect of the present application, there is provided a method for determining attack and defense information in a heterogeneous network, the method including the following steps: determining the state of network nodes in the heterogeneous network and the probability that the network nodes are in the state; constructing a state transformation model of the network nodes at least based on the rate of change of the probability that the network nodes are in the state over time; determining the attack rate of an attacker and the defense rate of a defender at the network nodes via the state transformation model; and determining the state information of the attacker at least based on the attack rate of the attacker at the network nodes and the probability that the network nodes are in the state, and determining the state information of the defender at least based on the defense rate of the defender at the network nodes and the probability that the network nodes are in the state.
[0006] A method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application, wherein determining the state of a network node in the heterogeneous network includes: determining the state of the network node as one or more of a state vulnerable to attack, a state under attack, and a state of attack repair based on real-time attack and defense interactions between an attacker and a defender at the network node in the heterogeneous network.
[0007] A method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein constructing the state transformation model of the network node based at least on the rate of change of the probability of the network node being in the state over time includes: determining the correspondence between the rate of change of the probability of the network node being in the state over time and the attack rate of the attacker and the defense rate of the defender; and constructing the state transformation model of the network node based on the correspondence.
[0008] A method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein constructing the state transformation model of the network node based at least on the rate of change of the probability of the network node being in the state over time includes: constructing a first model based on the correspondence between the rate of change of the probability of the network node being in the state vulnerable to attack over time and the attack rate of the attacker; constructing a second model based on the correspondence between the rate of change of the probability of the network node being in the state under attack over time and the attack rate of the attacker and the defense rate of the defender; constructing a third model based on the correspondence between the rate of change of the probability of the network node being in the state of attack repair over time and the defense rate of the defender; and constructing the state transformation model of the network node using the first model, the second model, and the third model.
[0009] A method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein the network nodes in the heterogeneous network include one or more of the following: servers, terminal devices, routers, switches, base stations, gateways.
[0010] The method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein determining the state information of the attacker based at least on the attack rate of the attacker at the network node and the probability that the network node is in the state includes: determining the attack benefit of the attacker based on the attack benefit per unit time of the attacker and the probability that the network node is in the attacked state; determining the attack cost of the attacker based on the attack rate of the attacker at the network node, the probability that the network node is in the vulnerable state, and the probability that the network node is in the attacked state; and determining the state information of the attacker based on the attack benefit and attack cost of the attacker.
[0011] The method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein determining the state information of the attacker based on the attack benefit and attack cost of the attacker includes, during the attack period: integrating the difference between the attack benefit and attack cost of the attacker over time to determine the state information of the attacker.
[0012] The method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein determining the state information of the defender based at least on the defense rate of the defender at the network node and the probability that the network node is in the state includes: determining the defense benefit of the defender based on the defense benefit per unit time of the defender and the probability that the network node is in the attack repair state; determining the defense cost of the defender based on the defense rate of the defender at the network node and the probability that the network node is in the attacked state; determining the attack benefit of the attacker based on the attack benefit per unit time of the attacker and the probability that the network node is in the attacked state; and determining the state information of the defender based on the defense benefit and defense cost of the defender and the attack benefit of the attacker.
[0013] The method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein determining the state information of the defender based on the defense benefit and defense cost of the defender and the attack benefit of the attacker includes, during the defense period: determining the difference between the defense benefit and defense cost of the defender; and integrating the difference between the difference and the attack benefit of the attacker over time to determine the state information of the defender.
[0014] The method for determining attack and defense information in a heterogeneous network according to an embodiment of the present application or any one of the above embodiments, wherein the method further includes: determining a target defense strategy of the defender based on the status information of the attacker and the status information of the defender.
[0015] According to a second aspect of the present application, there is provided an apparatus for determining attack and defense information in a heterogeneous network, the apparatus including: a memory; a processor coupled to the memory; and a computer program stored on the memory, which causes the steps of the method for determining attack and defense information in a heterogeneous network according to the first aspect of the present application to be executed when the computer program runs on the processor.
[0016] According to a third aspect of the present application, there is provided a non-transitory computer-readable storage medium, characterized in that the non-transitory computer-readable storage medium includes instructions that execute the steps of the method for determining attack and defense information in a heterogeneous network according to the first aspect of the present application when running.
[0017] According to a fourth aspect of the present application, there is provided a computer program product, the computer program product including instructions that implement the steps of the method for determining attack and defense information in a heterogeneous network according to the first aspect of the present application when executed by a processor.
[0018] The solution for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application can construct a state transformation model of network nodes through the rate of change of the probability of the state of network nodes in the heterogeneous network over time, so as to obtain the status information of the attacker and the defender at the network nodes that changes in real time through the constructed state transformation model, which is beneficial for the defender to adjust the defense strategy in real time to cope with dynamic network attacks, thereby improving the security of the heterogeneous network. At the same time, it is beneficial for the defender to reasonably allocate limited defense resources, and can help the defender achieve an optimal defense deployment with limited defense resources and improve the utilization efficiency of defense resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above and / or other aspects and advantages of the present application will become clearer and easier to understand through the following description of each aspect in conjunction with the drawings, where the same or similar units in the drawings are denoted by the same reference numerals. In the drawings: Figure 1 A flowchart of a method for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application is shown.
[0020] Figure 2 A schematic diagram of the state transformation of a network node according to an embodiment of the present application is shown.
[0021] Figure 3 A schematic block diagram of a device for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application is shown. Detailed implementation manners
[0022] Example embodiments of the present application are described in detail below, and examples of these embodiments are illustrated in the accompanying drawings. It should be noted that the following description is for explanation and illustration purposes only, and should not be construed as a limitation of the present application. Without departing from the principles of the present application, those skilled in the art can make electrical, mechanical, logical, and structural changes to these embodiments according to actual needs without departing from the scope of the present application. In addition, those skilled in the art can understand that one or more features of different embodiments described below can be combined according to any specific application scenario or actual needs.
[0023] Terms such as "including" and "comprising" indicate that in addition to the units and steps directly and explicitly stated in the specification, the technical solutions of the present application do not exclude the situation of having other units and steps that are not directly or explicitly stated. Terms such as "first" and "second" do not indicate the order of the units in terms of time, space, size, etc., but are only used to distinguish the units.
[0024] In the context of the present application, the term "heterogeneous network" refers to a network system that includes different types of network technologies (e.g., wireless networks (e.g., Wi-Fi, 5G, Bluetooth, etc.), wired networks (e.g., Ethernet, satellite communication networks, etc.), communication protocols (e.g., TCP / IP, ZigBee, LoRa, etc.) or devices. In the context of the present application, the term "network node" refers to various devices included in a heterogeneous network, such as servers, terminal devices, routers, switches, base stations, gateways, etc. These network nodes perform different functions in the heterogeneous network, such as data forwarding, resource management, security detection, etc. The connections between network nodes can be through different types of network technologies or communication protocols.
[0025] Hereinafter, various exemplary embodiments of the present application will be described in detail with reference to the accompanying drawings.
[0026] Figure 1 A flowchart of a method for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application is shown.
[0027] As Figure 1 shown, in step S101, the state of a network node in a heterogeneous network and the probability that the network node is in the state are determined.
[0028] Optionally, in step S101, the state of the network node may be determined as one or more of a vulnerable state, a compromised state, and a state of attack repair based on real-time attack-defense interactions between an attacker and a defender at a network node in a heterogeneous network.
[0029] It should be noted that the vulnerable state means that the network node can perform normal functions, but there are security vulnerabilities or configuration defects in the network node, making it vulnerable to attacks by attackers. The compromised state means that the network node has been attacked by an attacker, and the state of attack repair means that the attack on the network node by the attacker has been cleared through defense measures and restored to a secure state. It should be noted that the real-time attack-defense interaction between the attacker and the defender refers to the dynamic process in which the attacker attempts to attack the network node while the defender takes measures to prevent the attack. The attacks by the attacker may include vulnerability exploitation attacks, path traversal and directory traversal attacks, distributed denial-of-service attacks, injection attacks, brute-force attacks, advanced persistent threat attacks, DNS tunneling attacks, etc. The measures taken by the defender may include intrusion detection, intrusion prevention, vulnerability repair, active scanning, etc.
[0030] Optionally, in step S101, a directed acyclic graph may be constructed based on the connection relationships between network nodes, conditional probabilities may be defined for each network node according to historical data or expert experience to describe the probability distribution of each network node given the state of its parent network node, and the probability of the network node state may be updated based on the real-time attack-defense interaction between the attacker and the defender at the network node. For example, the state and the probability of the state of the network node may be dynamically updated through the Bayesian algorithm in combination with real-time monitored attack-defense interaction data. Exemplarily, the real-time monitored attack-defense interaction data may be obtained through log analysis of an intrusion detection system.
[0031] In step S103, a state transformation model of the network node is constructed at least based on the rate of change of the probability of the state of the network node over time.
[0032] Optionally, in step S103, for each network node in the heterogeneous network, a state transformation model of the network node may be constructed at least based on the rate of change of the probability of the state of the network node over time. Optionally, in step S103, the correspondence between the rate of change of the probability of the state of the network node over time and the attack rate of the attacker and the defense rate of the defender may be determined, and a state transformation model of the network node may be constructed based on this correspondence.
[0033] In one embodiment, a first model can be constructed based on the correspondence between the rate of change of the probability that a network node is in a vulnerable state over time and the attack rate of an attacker, a second model can be constructed based on the correspondence between the rate of change of the probability that a network node is in an attacked state over time and the attack rate of the attacker and the defense rate of a defender, a third model can be constructed based on the correspondence between the rate of change of the probability that a network node is in an attack-repair state over time and the defense rate of the defender, and a state transformation model of the network node can be constructed by using the constructed first model, second model, and third model.
[0034] As an example, the first model can be constructed based on the correspondence between the rate of change of the probability that a network node is in a vulnerable state over time and the attack rate of the attacker through the following formula (1): Formula (1) Wherein, represents the probability that the network node is in a vulnerable state, represents the rate of change of the probability that the network node is in a vulnerable state over time, represents the attack rate of the attacker at the network node , represents the number of network nodes, represents the network node and the network node , when the network node is directly connected to the network node = 1, otherwise = 0, represents the probability that the network node is in an attacked state, represents the rate at which the network node changes from the immune state to the vulnerable state, represents the probability that the network node is in an attack-repair state.
[0035] As an example, the second model can be constructed based on the correspondence between the rate of change of the probability that a network node is in an attacked state over time and the attack rate of the attacker and the defense rate of the defender through the following formula (2): Formula (2) Wherein, represents the probability that the network node is in an attacked state, represents the network node The rate of change of the probability of being in an attacked state over time represents the attack rate of the attacker at the network node represents the probability that the network node is in a vulnerable state represents the number of network nodes represents the network node and the network node The connectivity between them, when the network node and the network node are directly connected = 1, otherwise = 0 represents the probability that the network node is in an attacked state represents the network node The defense rate of the defender at represents the network node The probability of being in an attacked state
[0036] As an example, the third model can be constructed based on the correspondence between the rate of change of the probability of the network node being in the attack repair state over time and the defense rate of the defender through the following formula (3): Formula (3) where represents the probability that the network node is in the attack repair state represents the network node The rate of change of the probability of being in the attack repair state over time represents the network node The defense rate of the defender at represents the network node The probability of being in an attacked state represents the network node The rate from the immune state to the vulnerable state
[0037] By constructing the state transformation model of the network node, the real-time measurement of the state of each network node can be realized, which is beneficial to determining the state information of the attacker and the defender subsequently, and can help the defender dynamically adjust the defense strategy in the complex network attack and defense environment to maximize the defense benefit
[0038] In step S105, the attack rate of the attacker and the defense rate of the defender at the network node are determined via the state transformation model
[0039] Optionally, in step S105, the attack rate of the attacker and the defense rate of the defender at the network node can be determined based on the correspondence between the rate of change of the probability of the state of the network node in the state transition model over time and the attack rate of the attacker and the defense rate of the defender. Exemplarily, the attack rate of the attacker and the defense rate of the defender at the network node can be determined with reference to the above formulas (1)-(3).
[0040] In step S107, the state information of the attacker is determined based at least on the attack rate of the attacker at the network node and the probability of the state of the network node, and the state information of the defender is determined based at least on the defense rate of the defender at the network node and the probability of the state of the network node.
[0041] Optionally, in step S107, the attack benefit of the attacker can be determined based on the attack benefit per unit time of the attacker and the probability that the network node is in the attacked state, the attack cost of the attacker can be determined based on the attack rate of the attacker at the network node, the probability that the network node is in the vulnerable state, and the probability that the network node is in the attacked state, and the state information of the attacker can be determined based on the attack benefit and the attack cost of the attacker. In one embodiment, the difference between the attack benefit and the attack cost of the attacker can be integrated over time during the attack period to determine the state information of the attacker.
[0042] As an example, the following formula (4) can be used to determine the attack benefit of the attacker at the network node during the attack period based on the attack benefit per unit time of the attacker and the network node being in the attacked state : Formula (4) where represents the duration of the attack period, represents the attack benefit per unit time of the attacker after the network node is attacked, represents the network node being in the attacked state.
[0043] As an example, the following formula (5) can be used to determine the attack cost of the attacker at the network node during the attack period based on the attack rate of the attacker at the network node, the probability that the network node is in the vulnerable state, and the probability that the network node is in the attacked state : : Formula (5) Wherein, represents the duration of the attack period, represents the attacker's attack rate at the network node , represents that the attacker attacks the network node at the attack rate of the unit time cost of represents the probability that the network node is in a state vulnerable to attack, represents the number of network nodes, represents the network node and the network node the connectivity between, when the network node and the network node are directly connected = 1, otherwise = 0, represents the probability that the network node is in a state of being attacked.
[0044] As an example, the difference between the attacker's attack benefit and attack cost during the attack period can be integrated over time by the following formula (6) to determine the attacker's state information : Formula (6) Wherein, represents the number of network nodes, represents the duration of the attack period, represents the network node the attacker's unit time attack benefit after being attacked, represents the network node the probability of being in a state of being attacked, represents that the attacker attacks the network node at the attack rate of the unit time cost of represents the network node the probability of being in a state vulnerable to attack, represents the network node and the network node the connectivity between, when the network node and the network node are directly connected = 1, otherwise = 0, represents the network node the probability of being in a state of being attacked.
[0045] Optionally, in step S107, the defender's defense benefit can be determined based on the defender's defense benefit per unit time and the probability that the network node is in the attack repair state, the defender's defense cost can be determined based on the defender's defense rate at the network node and the probability that the network node is in the attacked state, the attacker's attack benefit can be determined based on the attacker's attack benefit per unit time and the probability that the network node is in the attacked state, and the defender's status information can be determined based on the defender's defense benefit and defense cost and the attacker's attack benefit. In one embodiment, the difference between the defender's defense benefit and defense cost can be determined during the defense period, and the difference between this difference and the attacker's attack benefit can be integrated over time to determine the defender's status information.
[0046] As an example, the defense benefit of the defender at the network node during the defense period can be determined based on the defender's defense benefit per unit time and the probability that the network node is in the attack repair state through the following formula (7) of the defender at the network node : Formula (7) Wherein, represents the duration of the defense period, represents the defender's defense benefit per unit time at the network node , and represents the probability that the network node is in the attack repair state.
[0047] As an example, the defense cost of the defender at the network node during the defense period can be determined based on the defender's defense rate at the network node and the probability that the network node is in the attacked state through the following formula (8) of the defender at the network node : Formula (8) Wherein, represents the duration of the defense period, represents the defender's defense rate at the network node , represents the unit time cost for the defender to repair the network node at the defense rate of , and represents the probability that the network node is in the attacked state.
[0048] As an example, the difference between the defender's defense benefit and defense cost during the defense period can be determined through the following formula (9), and the difference between this difference and the attacker's attack benefit can be integrated over time to determine the defender's status information : Equation (9) Wherein, represents the number of network nodes, represents the duration of the defense period, represents the per-unit-time defense benefit of the defender at network node represents the probability that network node represents the per-unit-time attack benefit of the attacker after the network node is attacked, represents the probability that network node represents the defense rate of the defender at network node represents that the defender repairs network node at a defense rate of per-unit-time cost.
[0049] In one embodiment, the target defense strategy of the defender can be determined based on the state information of the attacker and the state information of the defender. In one embodiment, the global maximum attack and defense benefit can be determined based on the state information of the attacker and the state information of the defender, and the target defense strategy of the defender can be determined based on the global maximum attack and defense benefit. Exemplarily, the Nash equilibrium strategy can be solved by mathematical methods (such as linear programming, non-linear programming) to determine the target defense strategy of the defender.
[0050] The method for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application can construct a state transformation model of network nodes through the rate of change of the probability of the state of network nodes in the heterogeneous network over time, so as to obtain the state information of the attacker and the state information of the defender at the network nodes that changes in real time through the constructed state transformation model, which is beneficial for the defender to adjust the defense strategy in real time to cope with dynamic network attacks, thereby improving the security of the heterogeneous network. At the same time, it is beneficial for the defender to reasonably allocate limited defense resources, and can help the defender achieve an optimal defense deployment with limited defense resources and improve the utilization efficiency of defense resources.
[0051] Figure 2 shows a schematic diagram of the state transformation of network nodes according to one embodiment of the present application.
[0052] Such as Figure 2As shown in the figure, the states of the network node in the schematic process 200 of state transformation of the network node may include a vulnerable state 210, a compromised state 220, and an attack-repaired state 230. The vulnerable state 210 means that the network node can perform normal functions, but there are security vulnerabilities or configuration defects in the network node, which are easily exploited by attackers and attacked. The compromised state 220 means that the network node has been attacked by an attacker. The attack-repaired state 230 means that the attack on the network node by the attacker has been cleared through defense measures and restored to a secure state.
[0053] In the case where an attacker attacks the network node, the vulnerable state 210 can be converted into the compromised state 220; in the case where a defender takes measures to repair the attacker's attack, the compromised state 220 can be converted into the attack-repaired state 230; in the case where an attacker exploits the security vulnerabilities or configuration defects existing in the network node, the attack-repaired state 230 can be converted into the vulnerable state 210. It should be noted that with the real-time attack-defense interaction between the attacker and the defender, the states of the network nodes in the heterogeneous network can be dynamically converted between the vulnerable state 210, the compromised state 220, and the attack-repaired state 230.
[0054] Figure 3 The figure shows a schematic block diagram of a device for determining attack and defense information in a heterogeneous network according to one or more embodiments of the present application.
[0055] As Figure 3 shown in the figure, the device 300 for determining attack and defense information in a heterogeneous network includes a memory 310, a processor 320, and a computer program 330 stored on the memory 310 and executable on the processor 320. The processor 320 runs the computer program 330 to implement a method for determining attack and defense information in a heterogeneous network according to one aspect of the present application.
[0056] In addition, the present application can also be implemented as a non-transitory computer-readable storage medium in which a program for causing a computer to execute a method for determining attack and defense information in a heterogeneous network according to one aspect of the present application is stored.
[0057] Here, as the non-transitory computer-readable storage medium, various non-transitory computer-readable storage media such as disk types (e.g., magnetic disks, optical disks, etc.), card types (e.g., memory cards, optical cards, etc.), semiconductor memory types (e.g., ROM, non-volatile memories, etc.), tape types (e.g., magnetic tapes, cassette tapes, etc.) can be adopted.
[0058] In applicable cases, various embodiments provided by this application can be implemented using hardware, software, or a combination of hardware and software. Moreover, in applicable cases, without departing from the scope of this application, the various hardware components and / or software components described herein can be combined into composite components including software, hardware, and / or both. In applicable cases, without departing from the scope of this application, the various hardware components and / or software components described herein can be divided into sub-components including software, hardware, or both. Additionally, in applicable cases, it is contemplated that software components can be implemented as hardware components, and vice versa.
[0059] The software according to this application (such as program code and / or data) can be stored on one or more non-transitory computer-readable storage media. It is also contemplated that one or more general-purpose or special-purpose computers and / or computer systems, whether networked and / or otherwise, can be used to implement the software identified herein. In applicable cases, the order of the various steps described herein can be changed, combined into composite steps, and / or divided into sub-steps to provide the features described herein.
[0060] The embodiments and examples presented herein are provided to best illustrate the embodiments in accordance with this application and its specific applications, and thereby enable those skilled in the art to implement and use this application. However, those skilled in the art will know that the above description and examples are provided for the sake of illustration and exemplification only. The presented description is not intended to cover all aspects of this application or to limit this application to the precise form disclosed.
Claims
1. A method for determining attack and defense information in a heterogeneous network, characterized in that: The method comprises the following steps: Determining a state of a network node in a heterogeneous network and a probability that the network node is in the state; constructing a state transition model of the network node based at least on a rate of change of a probability of the network node being in the state over time; determining an attack rate of an attacker and a defense rate of a defender at the network node via the state transition model; as well as The state information of the attacker is determined based at least on the attack rate of the attacker at the network node and the probability that the network node is in the state, and the state information of the defender is determined based at least on the defense rate of the defender at the network node and the probability that the network node is in the state.
2. The method of claim 1, wherein determining the status of a network node in a heterogeneous network comprises: Based on the real-time attack-defense interaction between the attacker and the defender at the network node in the heterogeneous network, the state of the network node is determined as one or more of a vulnerable state, an attacked state, and an attack-repaired state.
3. The method according to claim 1, wherein constructing the state transition model of the network node based at least on the rate of change of the probability of the network node being in the state over time comprises: Determine a correspondence between a rate of change over time of a probability of the network node being in the state and an attack rate of an attacker and a defense rate of a defender; as well as A state change model of the network node is constructed based on the corresponding relationship.
4. The method according to claim 2, wherein constructing the state transition model of the network node based at least on the rate of change of the probability of the network node being in the state over time comprises: Constructing a first model based on the corresponding relationship between the rate of change of the probability of the network node being in the vulnerable state over time and the attack rate of the attacker; constructing a second model based on the corresponding relationship between the rate of change of the probability of the network node being in the attacked state over time and the attack rate of the attacker and the defense rate of the defender; constructing a third model based on the corresponding relationship between the rate of change of the probability of the network node being in the state of attack repair over time and the defense rate of the defender; as well as The state transition model of the network node is constructed using the first model, the second model and the third model.
5. The method according to claim 1, wherein the network nodes in the heterogeneous network include one or more of the following: a server, a terminal device, a router, a switch, a base station, and a gateway.
6. The method according to claim 2, wherein determining the state information of the attacker based at least on an attack rate of the attacker at the network node and a probability that the network node is in the state comprises: Determine the attack benefit of the attacker based on the attack benefit per unit time of the attacker and the probability that the network node is in the attacked state; determining an attack cost of the attacker based on an attack rate of the attacker at the network node, a probability that the network node is in the vulnerable state, and a probability that the network node is in the attacked state; and The state information of the attacker is determined based on the attack benefit and attack cost of the attacker.
7. The method according to claim 6, wherein determining the state information of the attacker based on the attack benefit and attack cost of the attacker comprises: The difference between the attack benefit and the attack cost of the attacker is integrated over time to determine the state information of the attacker.
8. The method of claim 2, wherein determining the defender's state information based on at least a defense rate of the defender at the network node and a probability that the network node is in the state comprises: Determine the defense benefit of the defender based on the defense benefit per unit time of the defender and the probability that the network node is in the state of attack repair; determining a defense cost of the defender based on a defense rate of the defender at the network node and a probability that the network node is in the attacked state; Determine the attack benefit of the attacker based on the attack benefit per unit time of the attacker and the probability that the network node is in the attacked state; as well as The state information of the defender is determined based on the defense benefit and defense cost of the defender and the attack benefit of the attacker.
9. The method according to claim 8, wherein determining the state information of the defender based on the defense benefit and defense cost of the defender and the attack benefit of the attacker comprises: determining the difference between the defender's defense benefit and defense cost; and The difference between the difference and the attack benefit of the attacker is integrated over time to determine the state information of the defender.
10. The method according to claim 1, wherein the method further comprises: A target defense strategy of the defender is determined based on the state information of the attacker and the state information of the defender.
11. A device for determining attack and defense information in a heterogeneous network, characterized in that: The device comprises: Memory; a processor coupled to the memory; and A computer program stored on the memory and running on the processor, the execution of the computer program results in the execution of the method for determining attack and defense information in a heterogeneous network according to any one of claims 1 to 10.
12. A non-transitory computer-readable storage medium, characterized in that The non-transitory computer-readable storage medium includes instructions that, when executed, execute the method for determining attack and defense information in a heterogeneous network according to any one of claims 1-10.
13. A computer program product, characterized in that The computer program product comprises instructions, which, when executed by a processor, implement the method for determining attack and defense information in a heterogeneous network according to any one of claims 1 to 10.
Citation Information
Patent Citations
Attack and defense differential game-based network security defense decision determination method and device
CN106936855A
Complex network dynamic defense decision-making method and system based on attack and defense game
CN115314316A
Network attack time prediction method and system based on time game
CN117118674A
Predicting attacks based on probabilistic game-theory
US20130318616A1
Network security based on critical node game (CNG)
WO2024161372A1