Underwater wireless optical network-oriented malicious node and invalid link detection method and system under hybrid attack
Through the Hidden Markov model and Trust Cloud technology, malicious nodes and failed links in underwater wireless optical networks are detected, and the problem of failure to effectively consider node and link reliability deviations in complex underwater environments in the existing technology is solved, and efficient malicious node and failed link detection is achieved.
Patent Information
- Application Number
- CN202510473170.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art fails to effectively consider the reliability deviations of nodes and links in complex underwater environments when detecting malicious nodes and failed links in underwater wireless optical networks.
The hidden Markov model is adopted to extract the trust characteristics of nodes and links, generate a comprehensive trust cloud, deduce the hidden state of nodes or links, and use historical information to predict to eliminate the deviation between the observed state and the hidden state.
It realizes accurate detection of malicious nodes and failed links in a hybrid attack environment, ensures the normal operation of the underwater wireless optical network, and improves the basis of network security protection.
Smart Images

Figure CN120224191A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a malicious node and failed link detection technology for underwater wireless optical networks under hybrid attacks, belonging to the field of underwater wireless optical communication technology. Background Art
[0002] Underwater wireless optical communication sensor networks have received extensive attention due to the characteristics of small sensor node devices and strong mobility. They can give full play to their flexible networking characteristics and do not generate high-intensity sound waves, which is more friendly to marine life. With the development of the network and the innovation of attack means, underwater wireless sensor networks often face composite attacks that include multiple single specific attacks. The detection of malicious nodes and failed links under hybrid attacks for underwater wireless optical networks can timely screen out malicious nodes and failed links to ensure the normal operation of underwater wireless optical networks.
[0003] In the paper "A TrustCloud Model for Underwater Wireless Sensor Networks" published by Jinfang Jiang et al. in IEEE Internet of Things Journal, a trust evaluation model based on cloud theory was studied, and malicious nodes in underwater wireless sensor networks were detected through three methods: direct trust calculation, recommended trust calculation, and indirect trust calculation. In the paper "A Discrete-Time Markov Chains Cloud-Based Trust Management Approach Model for Underwater Wireless Sensor Networks" published by Zhiquan Jiang et al. in the 2024 International Conference on Artificial Intelligence of Things and Systems, the discrete-time Markov chain and cloud model were combined to effectively detect hybrid attacks and predict node and link states. These two literatures did not consider that in a complex underwater environment, the reliability of nodes and links may also be affected by other factors, and the trust metrics of nodes and links often only reflect the observed state. In some special cases, there are non-negligible deviations between the actual state of nodes and links and the state reflected by trust evidence. Summary of the Invention
[0004] Objective of the Invention: The objective of the present invention is to provide a method and system for detecting malicious nodes and failed links in an underwater wireless optical network under hybrid attacks, which derives the hidden state of nodes or links at the current moment from a hidden Markov model, and derives the predicted state of nodes or links at the next moment based on the forward and backward probabilities of the hidden Markov, being more comprehensive and targeted.
[0005] Technical Solution: To achieve the above objective of the invention, the technical solution adopted by the present invention is as follows:
[0006] In the first aspect, the present invention provides a method for detecting malicious nodes in an underwater wireless optical network under hybrid attacks, including the following steps:
[0007] Regarding the communication characteristics of the underwater optical communication network, trust features for nodes are extracted, including abnormal energy consumption for collecting node trust evidence, data consistency, and activity.
[0008] According to the reverse cloud algorithm, a corresponding comprehensive trust cloud for nodes is generated to reflect the observed state of nodes, serving as the basis for deriving the actual state of nodes using the hidden Markov model.
[0009] The true state of the node itself is defined as the hidden state. The hidden state of the node at the current moment is derived from the observed state at the current moment, and the hidden state at the next moment is predicted from the hidden state at the current moment. The hidden Markov model uses historical information for prediction to eliminate the deviation between the hidden state of the node and the observed state reflected by the trust evidence.
[0010] Malicious node detection is performed based on the detection and prediction results of the hidden Markov model.
[0011] In the second aspect, the present invention provides a method for detecting failed links in an underwater wireless optical network under hybrid attacks, including the following steps:
[0012] Regarding the communication characteristics of the underwater optical communication network, trust features for links are extracted, including link trust evidence collection delay rate, packet error rate, packet loss rate, and link usage frequency.
[0013] According to the reverse cloud algorithm, a corresponding comprehensive trust cloud for links is generated to reflect the observed state of links, serving as the basis for deriving the actual state of links using the hidden Markov model.
[0014] The true state of the link itself is defined as the hidden state. The hidden state of the link at the current moment is derived from the observed state at the current moment, and the hidden state at the next moment is predicted from the hidden state at the current moment. The hidden Markov model uses historical information for prediction to eliminate the deviation between the hidden state of the link and the observed state reflected by the trust evidence.
[0015] Failure link detection is performed based on the detection and prediction results of the hidden Markov model.
[0016] Furthermore, in the malicious node detection method of the first aspect, the energy consumption anomaly rate of a node is defined as:
[0017]
[0018] In the formula, Q0 represents the initial energy value of the underwater wireless optical network node, and Q r represents the remaining energy of the node;
[0019] The node activity is defined as:
[0020]
[0021] In the formula, n use (n i ) is the number of times node n i is used, and Num represents the total number of nodes in the cluster;
[0022] The data consistency of the node is defined as:
[0023]
[0024] In the formula, n same is the number of times the node data is consistent, and n represents the total number of data packets sent.
[0025] Furthermore, in the failure link detection method of the second aspect, the link delay rate is defined as:
[0026]
[0027] In the formula, pk is the number of packets delivered by the sending node, st i represents the time delay required to send each packet, qt i represents the time delay required for each packet to queue, and rt i represents the time delay required to process each packet;
[0028] The packet error rate of the link is defined as:
[0029]
[0030] In the formula, b represents the packet length, erfc(x) represents the complementary error function, and SNR represents the signal-to-noise ratio during communication between adjacent nodes; the packet loss rate of the link is defined as:
[0031]
[0032] Wherein, f(x) represents the probability density function of the data packet values collected between adjacent nodes. σ represents the variance, and μ as represents the evaluated data packet value between adjacent nodes, and μ te represents the average value of the data packets collected between adjacent nodes; the link usage frequency is defined as:
[0033]
[0034] Wherein, l use (l i ) is the number of times the link l i is used, and Num represents the total number of links within the cluster.
[0035] Furthermore, in the malicious node detection method of the first aspect, the node hidden state set includes a normal state and a malicious state; in the node hidden state transition matrix, the probability that a node changes from the normal state to the malicious state is the probability that a node changes from the malicious state to the normal state is The node observation state set includes malicious behavior and normal behavior, and its element values are obtained by comparing the eigenvalue of the node comprehensive trust cloud with the threshold.
[0036] Furthermore, in the failed link detection method of the second aspect, the link hidden state set includes a normal state and a failed state; in the link hidden state transition matrix, the probability that a link changes from the normal state to the failed state is the probability that a link changes from the failed state to the normal state is The link observation state set includes failed behavior and normal behavior, and its element values are obtained by comparing the eigenvalue of the link comprehensive trust cloud with the threshold.
[0037] Furthermore, in the detection method of the first aspect or the second aspect, the hidden state is deduced through the observation state, and the concept of Bayesian inference is used to achieve it:
[0038]
[0039] Wherein, t represents the current moment, O t is the observation state, o k is a kind of observation state, S t is the hidden state, s j is a kind of hidden state, and the observation state generation probability satisfies P(S t = s j |O t = o k ) = b j (o k ), b j (o k) is the element value in the observation probability matrix, P(S t = s j ) is calculated through the state and transition probability a t-1 of S at the previous moment: ij Calculate:
[0040]
[0041] P(O t = o k ) is the total probability of the observed value. Under all hidden states, the probability of observing a specific observed value o k is calculated by weighting the observation probabilities of all hidden states.
[0042] Further, in the detection method of the first aspect or the second aspect, predicting the hidden state at the next moment by using the hidden state at the current moment is expressed as:
[0043]
[0044] In the formula, t represents the current moment, s k , s j is a kind of hidden state, α jk is the transition probability, a t (j), β t (j) respectively represent the forward probability and backward probability at the t-th moment, P(O|λ) represents the probability of the final observed sequence, λ includes the observed sequences O1, O2,... O t and the initial state parameters, and O represents the observed state.
[0045] Further, in the detection method of the first aspect or the second aspect, comprehensive decision-making is carried out according to the node / link hidden state, that is, the change rate of the node / link hidden state is compared with the threshold. If the change rate of the node hidden state is greater than the threshold, the node belongs to the malicious state or the failure state, and the data packet sent by it is discarded and a cluster-wide broadcast notice is issued; if the change rate of the link hidden state is greater than the threshold, the link belongs to the abnormal state, and the data packet sent by it is discarded and a cluster-wide broadcast notice is issued.
[0046] Thirdly, the present invention also provides a computer system, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, the steps of the detection method of the first aspect and / or the second aspect are implemented.
[0047] Advantageous effects: The present invention focuses on the impact of hybrid attacks on underwater wireless optical networks, introduces the hidden Markov model into the field of malicious node and failed link detection, and detects the affected nodes and links by monitoring the impact on the network after the attack, laying a foundation for subsequent network security protection and the like. Compared with the prior art, the advantageous effects of the present invention are as follows:
[0048] The method of the present invention is for detecting malicious nodes and failed links under hybrid attacks on underwater wireless optical networks, considering multiple trust evidences for nodes and links, where the node trust evidences collect energy consumption anomalies, data consistency, and activity; the link trust evidences collect delay rate, packet error rate, packet loss rate, and link usage frequency. In addition, the cloud model can describe the uncertainty relationship between a qualitative concept and its corresponding quantitative value. According to the reverse cloud algorithm, the corresponding node comprehensive trust cloud and link comprehensive trust cloud are generated, and the states of the nodes and links reflected are defined as the observed states. The true states of the nodes and links themselves are defined as the hidden states. The hidden Markov model uses historical information for prediction, captures the dynamic changes of the data, and eliminates the deviation between the hidden states of the nodes and links and the observed states reflected by the trust evidences. Brief description of the drawings
[0049] Figure 1 It is a flowchart of the method for detecting malicious nodes and failed links for underwater wireless optical networks under hybrid attacks;
[0050] Figure 2 It is a network clustering model diagram;
[0051] Figure 3 It is a diagram of the detection rate and false detection rate under the same attack intensity in Scenario 1;
[0052] Figure 4 It is a diagram of the detection rate and false detection rate under different intensities in Scenario 2. Detailed implementation manners
[0053] The technology of the invention will be described in detail below in conjunction with the drawings and specific implementation manners.
[0054] As Figure 1As shown in the figure, a method for detecting malicious nodes / failed links in an underwater wireless optical network under a hybrid attack disclosed in an embodiment of the present invention. First, according to the communication characteristics of the underwater optical communication network, trust features for nodes / links are extracted, including abnormal energy consumption for node trust evidence collection, data consistency and activity, link trust evidence collection delay rate, packet error rate, packet loss rate, and link usage frequency. Then, according to the reverse cloud algorithm, corresponding comprehensive trust clouds for nodes / links are generated to reflect the observed states of nodes / links, serving as the basis for deducing the actual states of nodes / links using the hidden Markov model. Next, the true states of nodes / links themselves are defined as hidden states. The hidden state of a node / link at the current moment is deduced from the observed state at the current moment, and the hidden state at the next moment is predicted from the hidden state at the current moment. The hidden Markov model uses historical information for prediction to eliminate the deviation between the hidden state of a node / link and the observed state reflected by trust evidence. Finally, malicious nodes / failed links are detected based on the detection and prediction results of the hidden Markov model.
[0055] Specifically, this embodiment first considers a clustered network. The node clustering model is a commonly used network organization and management technology in underwater wireless sensor networks. Numerous nodes in the network are divided into several non-overlapping or partially overlapping subsets according to certain rules and algorithms, and these subsets are called clusters. Each cluster consists of one or more nodes, and there is a special node called the cluster head node, and the rest are member nodes. The node clustering model can avoid long-distance communication between nodes, and nodes only need to hand over the information they collect to the cluster head node, reducing the number of communications. The node clustering model can balance network energy and facilitate node management.
[0056] This embodiment adopts a node clustering model to divide the nodes in the network, as Figure 2 shown. The underwater part consists of clustered nodes. According to the characteristics of underwater wireless optical communication sensors, dense node clustering is adopted. The nodes in the cluster are divided into two types: member nodes and cluster head nodes. Among them, the member nodes have similar working contents, mainly responsible for collecting underwater information, transmitting trust evidence, etc. The cluster head node is also responsible for calculating the trust cloud of the nodes in the cluster and transmitting the calculation results and its own trust evidence and other information to the surface ship base station, communication buoy, etc.
[0057] Based on the above model, a method for detecting malicious nodes / failed links in an underwater wireless optical network under a hybrid attack disclosed in an embodiment of the present invention mainly includes the following steps:
[0058] Step 1: Underwater wireless optical communication networks have significant advantages such as large communication link bandwidth and small transmission delay. However, the effects of light wave scattering in water also need to be considered. Underwater sensor nodes are usually deployed in unattended and harsh environments. Malicious attacks on sensor nodes usually manifest as consuming node energy, tampering with data transmitted over the link, and so on. Three kinds of evidence that can reflect node credibility and four kinds of evidence for measuring link reliability are comprehensively considered.
[0059] For node trust evidence, the abnormal energy consumption rate of the node, node activity, and node data consistency are mainly considered.
[0060] The abnormal energy consumption rate of the node is defined as:
[0061]
[0062] In the formula, Q0 represents the initial energy value of the underwater wireless optical network node, and Q r represents the remaining energy of the node.
[0063] Node activity is defined as:
[0064]
[0065] In the formula, n use (n i ) is the number of times node n i is used, and Num represents the total number of nodes in the cluster.
[0066] In this embodiment, a message authentication code is used to verify the data consistency of the sensor nodes in the cluster. Considering the limited energy and resources of the underwater wireless sensor network, a simple symmetric key encryption algorithm MAC protocol is used in this embodiment. If multiple nodes collect the same message and send it to the cluster head within a certain period of time, the nodes in the cluster first generate an authentication tag tag for the data packet according to the MAC protocol. The cluster head node compares the tags sent by each received node. If they are different, then generate tag′ according to the data packet of the corresponding node to judge the data consistency of the node sending the data.
[0067] The specific process is as follows:
[0068] (1) Message authentication algorithm MAC: The nodes in the cluster use the symmetric key they save to output an authentication tag for the sent data packet, denoted as
[0069] (2) Comparison: The cluster head node processes n data packets and their corresponding tags in a certain time sequence. First, compare the tags tag i . If they are the same, the node data is consistent during this period. If they are different, go to the third step;
[0070] (3) Inspection: The cluster head node uses a verification algorithm to calculate tag′ based on the received data i That is i If it is exactly the same as tag i it means that the data consistency is 100%. If it is not exactly the same, then calculate and compare the tags i sent by each node with tag′ i same and record the serial numbers of the nodes where inconsistencies occur. The data consistency of a node is defined as:
[0071]
[0072] where n same is the number of times the node data is consistent, and n represents the total number of data packets sent.
[0073] Link trust evidence mainly considers link delay rate, link packet error rate, link packet loss rate, and link usage frequency.
[0074] The link delay rate is defined as:
[0075]
[0076] where pk is the number of packets delivered by the sending node. st i represents the time delay required to send each packet, qt i represents the time delay required for each packet to queue, and rt i represents the time delay required to process each packet.
[0077] The packet error rate of the link is defined as:
[0078]
[0079] where b represents the packet length, erfc(x) represents the complementary error function. SNR represents the signal-to-noise ratio function during communication between adjacent nodes, and its calculation formula is:
[0080]
[0081] where P t is the node transmission power, P n is the power of the noise, η t is the optical efficiency of the optical transmitter, η r is the optical efficiency of the optical receiver, A r is the aperture area of the optical receiver, θ0 is the beam divergence angle of the optical transmitter, θ is the tilt angle between the optical transmitter and the optical receiver, and c(λ) is the attenuation coefficient of seawater.
[0082] The packet loss rate of the link is defined as:
[0083]
[0084] where f(x) represents the probability density function of the packet numerical values collected between adjacent nodes, σ represents the variance, and μ as represents the evaluated packet numerical values between adjacent nodes, and μ te represents the average value of the packets collected between adjacent nodes, and the calculation formula is as follows:
[0085] where A0 represents the normalization constant, I E represents the evaluation coefficient, b represents the length of the packets transmitted between two nodes, represents the geometric path loss, d represents the Euclidean distance between two nodes, and I S represents the sensing coefficient.
[0086] The link usage frequency is defined as:
[0087]
[0088] where l use (l i ) is the number of times the link l i is used, and Num represents the total number of links within the cluster.
[0089] Step 2: Trust evidence processing based on the cloud model. The cloud theory is based on traditional fuzzy set theory and probability statistics theory, and can describe the uncertainty relationship between a qualitative concept and its corresponding quantitative value. The cloud model is a new trust evidence processing model based on the cloud theory, which inherits the good uncertainty processing ability and fuzzy expression ability of the cloud theory.
[0090] Taking the node comprehensive trust cloud as an example, in the node comprehensive trust cloud, first, according to the reverse cloud algorithm, the corresponding node energy consumption anomaly trust cloud, node activity trust cloud, and node data consistency trust cloud are generated. After obtaining the trust evidence cloud, the corresponding node direct transmission trust cloud, recommended transmission trust cloud, and indirect transmission trust cloud will be generated according to the communication characteristics between nodes. The direct communication trust cloud is obtained through the formula where j represents three kinds of trust evidence, w j represents the weight of the trust evidence, E xj , E nj , H ej are the characteristic values of the trust evidence trust cloud. The recommended communication trust cloud of a recommended path is obtained through the formula Obtained, where \(m\) represents the \(m\)-th node on a recommended transmission path, \(k\) represents that there are \(k\) nodes in the recommended transmission path, and then by synthesizing all the recommended transmission paths starting from the source node, the node recommended communication trust cloud is obtained. Let \(l\) represent the \(l\)-th transmission path, and \(n\) represent that there are \(n\) recommended transmission paths in total. The indirect communication trust cloud of an indirect communication path is obtained through the formula Obtained, where \(r\) represents the \(r\)-th node on the indirect transmission path, \(v\) represents that there are \(v\) nodes on the indirect transmission path, and then by synthesizing all the indirect communication paths starting from the source node, the node indirect communication trust cloud is obtained. Let \(u\) represent the \(u\)-th transmission path, and \(w\) represent that there are \(w\) indirect transmission paths in total. Then, by synthesizing these three trust clouds, the node comprehensive trust cloud is obtained. Let \(z\) represent the direct, recommended, and indirect three communication trust clouds. Similarly, for the link comprehensive trust cloud, the corresponding link delay trust cloud, link data packet error trust cloud, link data packet loss trust cloud, and link usage frequency trust cloud are generated. After fusing the four trust evidence clouds, the link comprehensive trust cloud is obtained. The node comprehensive trust cloud and the link comprehensive trust cloud reflect the observed states of the node and the link.
[0091] Define the state of the node / link reflected by the trust cloud as the observed state, and the true state of the node / link itself as the hidden state. The hidden state of the node / link at the current moment can be deduced from the observed state at the current moment, and the hidden state at the next moment can be predicted from the hidden state at the current moment. Since the underwater wireless sensor network works in a complex and changeable underwater environment for a long time and may encounter various unexpected interferences and influences at any time, these factors are very likely to cause a non-negligible deviation between the hidden state and the observed state of the node and the link. The hidden Markov model can use historical information for prediction, capture the dynamic changes of data, and eliminate the deviation between the hidden state of the node and the link and the observed state reflected by the trust evidence. Therefore, the hidden Markov model is very suitable for the inference and prediction of the node and link states.
[0092] Step 3: Node and link states. Nodes are divided into two states, namely normal and malicious. When the hidden state of the node is normal or malicious, it can exhibit normal behavior and malicious behavior.
[0093] Node hidden state set:
[0094] S n =\(\{NN, NA\}\) (11)
[0095] In the formula, \(NN\) represents a normal node, and \(NA\) represents a malicious node.
[0096] Hidden state transition matrix:
[0097] A n = [a n,ij (12)
[0098] In the formula, i represents the state of the node at the current moment, j represents the state of the node at the next moment, and the values of i and j are NN or NA. For example, a n,NN,NA represents that when the node changes from the normal state (NA) to the malicious state (NA), a n,NA,NN when the node changes from the malicious state (NA) to the normal state (NN),
[0099] The observed output of the node is defined as normal behavior {NNB} and malicious behavior {NAB}, and the observation probability matrix:
[0100] B n = [b n,j (o n,k )] (13)
[0101] In the formula, b n,j (o n,k ) = P(S n,t = s n,j |O n,t = o n,k ), t represents the current moment, O n,t is the observed state of the node, o n,k is one of the observed states of the node, S n,t is the hidden state of the node, and s n,j is one of the hidden states of the node.
[0102] Define the comprehensive trust cloud threshold ω cloud_node of the node, and compare the eigenvalue of the comprehensive trust cloud of the node with ω cloud_node . If E x_com_node > ω cloud_mode , the observed state of the node is malicious behavior.
[0103] The link is divided into two states. When the link is in the hidden state of normal or failed, it can exhibit normal behavior and failed behavior.
[0104] Link hidden state set:
[0105] S l = {LN, LA} (14)
[0106] In the formula, LN represents a normal link, and LA represents a failed link.
[0107] Link hidden state transition probability matrix:
[0108] Al = [a l,ij (15)
[0109] In the formula, i represents the state of the link at the current moment, j represents the state of the link at the next moment, and the values of i and j are LN or LA. For example, a l,LN,LA represents that when the link changes from the normal state (LN) to the failure state (LA), a l,LA,LN represents that when the link changes from the failure state (LA) to the normal state (LN),
[0110] The observed output of the link is defined as the normal behavior {LNB} and the failure behavior {LAB}, and the observation probability matrix:
[0111] B l = [b l,j (o l,k )] (16)
[0112] In the formula, b l,j (o l,k ) = P(S l,t = s l,j |O l,t = o l,k ), t represents the current moment, O l,t is the observed state of the link, o l,k is one of the observed states of the link, S l,t is the hidden state of the link, and s l,j is one of the hidden states of the link.
[0113] Define the comprehensive trust cloud threshold ω cloud_link of the link. Compare the eigenvalue of the comprehensive trust cloud of the link with ω cloud_link . If E x_com_link > ω cloud_link , the observed state of the link is the failure behavior.
[0114] Step 4: Define the true states of the node and the link itself as the hidden states. Based on the hidden Markov model, the hidden state of the node and the link at the current moment can be deduced from the observed state at the current moment, and the hidden state at the next moment can be predicted from the hidden state at the current moment. The algorithms for the node and the link are the same, and the subscripts n and l used to distinguish the node and the link are omitted below.
[0115] Deduce the hidden state from the observed state and implement it using the concept of Bayesian inference:
[0116]
[0117] In the formula, t represents the current moment, o k is the observed state, sj is the hidden state. The observation state generation probability satisfies P(S t = s j |O t =
[0118] o k ) = b j (o k ). P(S t = s j ) is calculated through the state of S t-1 at the previous moment and the transition probability a ij :
[0119]
[0120] In the formula, P(O t = o k ) is the total probability of the observed value. Under all hidden states, the probability of observing a specific observed value o k is calculated by weighting the observation probabilities of all hidden states:
[0121]
[0122] That is:
[0123]
[0124] The forward probability represents the probability of being in the hidden state s j at time t and observing the sequence of observations O1, O2,... O t . It is the probability of inferring the current state from the past observation sequence;
[0125] The backward probability represents the probability of being in the hidden state s j at time t and observing the observation sequence O t+1 , O t+2 ,... O T from time t to T. It is the probability of inferring the future observation sequence from the current state;
[0126] Calculate the initial probability:
[0127] α1(j) = π j ·b j (O1) (21)
[0128] In the formula, α1(j) represents the forward state probability at t = 1, and π j is the initial state probability vector
[0129] The forward algorithm is used to calculate the hidden state probability under a given observation sequence. The forward probability is calculated through the recursive formula:
[0130]
[0131] In the formula, t represents the current moment, and a t (j) represents the forward state probability at moment t.
[0132] Probability of the final observation sequence:
[0133]
[0134] In the formula, λ includes the observation sequences O1, O2,... O t and the initial state parameters.
[0135] Initial backward probability:
[0136] β T (j) = 1 (24)
[0137] In the formula, β T (j) represents the initial backward probability.
[0138] Recursive calculation:
[0139]
[0140] In the formula, k represents the hidden state number.
[0141] Calculate the hidden state:
[0142]
[0143] Finally, use the current state to predict the next state:
[0144]
[0145] Step 5: Based on the comprehensive decision of the node and link states, calculate the change rate Δ of the node's hidden state node =(P(S t = s NN ) - P(S t-1 = s NN ) + P(S t+1 = s NN ) - P(S t = s NN )) / 2, and compare it with the threshold ω hid_node When the node is in a malicious state, discard the data packet it sends and broadcast an announcement within the cluster. If the node is in a normal state, detect the direct communication link of the node and calculate the change rate Δ of the link's hidden state link =(p(S t = s LN ) - p(S t-1 = s LN ) + P(St+1 = s LN ) - P(S t = s LN )) / 2, and compare it with the threshold ω hi_link for comparison. If the link is in a failure state, discard the data packets sent by it and broadcast an announcement within the cluster.
[0146] The beneficial effects brought by the method of the present invention can be further illustrated by the following simulations.
[0147] I. Simulation Conditions
[0148] The considered hybrid attacks include DoS attacks and FDI attacks.
[0149] Considering DoS attacks, when the nodes in the underwater wireless optical communication sensor network are under DoS attacks, there will be malicious nodes launching DoS attacks and malicious nodes suffering from DoS attacks. The malicious nodes are manifested in quickly consuming their own energy, sending a large number of data packets outward, or having their own energy quickly consumed. DoS attack modeling:
[0150] The duration of each attack can be expressed as:
[0151]
[0152] In the formula, T d (t b , t e ) represents the total attack duration of the DoS attack in the time period [t b , t e , κ represents the basic duration of the DoS attack, is the upper limit parameter of the DoS attack duration per unit time.
[0153] The attack frequency can be expressed as:
[0154]
[0155] In the formula, N d (t b , t e ) represents the total attack frequency of the DOS attack in the time period [t b , t e , η represents the basic frequency of the DoS attack, is the upper limit parameter of the average frequency of the DoS attack.
[0156] Considering the FDI attack, attackers may tamper with the data packets being transmitted in the link, causing malicious modification of the key information therein. At the same time, they will also send additional data packets in a very concealed manner. The mixing of these redundant data packets will interfere with the normal data transmission order, and then lead to deviations and misunderstandings in the information transmitted by the entire link, posing a serious threat to communication security. FDI attack modeling:
[0157] x f = x + f(30) In the formula, x f represents the injected data, x represents the device measurement value, and f is the deviation from the normal state.
[0158] The specific parameter settings for the simulation are shown in Table 1.
[0159] Table 1 Simulation-related parameter table
[0160] Parameter Name Parameter Value <![CDATA[Initial energy value Q0]]> 20J Data Packet Length b 10 kB Longest Communication Distance d 20m <![CDATA[Node transmission power P t > 1W <![CDATA[Optical receiver efficiency η r > 0.9 <![CDATA[Divergence angle θ0 of the optical transmitter beam]]> 10° Seawater Attenuation Coefficient c(λ) 0.1514 Basic Duration κ of DoS Attack 5s Basic Frequency of DoS Attack 3
[0161] II. Simulation content and simulation results
[0162] According to some given parameters, simulations are carried out on the Matlab R2022a platform for evaluation. Five clusters are set in a space of 100*100*100m, and each cluster contains 20 nodes. The cluster head node is the node with the most neighbor nodes within the cluster. During each round of communication, the communication frequency of the node is positively correlated with the number of its neighbor nodes.
[0163] To simulate the impact of hybrid attacks on the underwater wireless optical communication network, based on the above attack model, DoS attacks and FDI attacks are set during ten rounds of communication from 0 to 1000s, and hybrid attacks are carried out on the in-cluster nodes, in-cluster links, cluster head nodes, and cluster head links.
[0164] Scenario 1: Medium-strength attacks are adopted for nodes and links, that is, within the simulation time from 0 to 1000s, 3 malicious nodes or 4 failed links appear in each cluster every 100s.
[0165] As Figure 3 shown, under a fixed attack intensity, the hybrid attack on the underwater wireless optical sensor network. A detection method for malicious nodes and failed links facing the underwater wireless optical network under a hybrid attack is very stable, and its detection rate exceeds 95% at 1000s, while the false detection rate is also as low as 8%.
[0166] Scenario 2: Change the attack intensity so that the number of malicious nodes appearing in each cluster every 100s ranges from 2 to 6, and the number of failed links ranges from 3 to 7, that is, the attack intensity increases from 16.5% to 45.2%.
[0167] AsFigure 4 As shown, with the increase of the attack intensity, the performance of a malicious node and failed link detection method for an underwater wireless optical network under a hybrid attack is always excellent. The correct detection rate reaches about 97% when the attack intensity is 30.1%, and the detection rate throughout the process remains above 90%.
[0168] In summary, using the hidden Markov model for detecting malicious nodes and failed links in an underwater wireless optical network has a relatively high detection accuracy, can detect malicious nodes and failed links, and ensure the normal operation of the underwater wireless optical network.
[0169] Based on the same inventive concept, a computer system disclosed by the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, the steps of the detection method are implemented.
Claims
1. A method for detecting malicious nodes in an underwater wireless optical network under hybrid attacks, characterized in that: The steps include: According to the communication characteristics of underwater optical communication network, the trust characteristics of nodes are extracted, and the node trust evidence is collected including energy consumption anomaly, data consistency and activity; According to the reverse cloud algorithm, the corresponding node comprehensive trust cloud is generated to reflect the observed state of the node, which serves as the basis for deducing the actual state of the node using the hidden Markov model; The true state of the node itself is defined as the hidden state. The hidden state of the node at the current moment is derived from the observed state at the current moment, and the hidden state at the next moment is predicted by the hidden state at the current moment. Hidden Markov models use historical information to make predictions and eliminate the deviation between the hidden state of a node and the observed state reflected by trust evidence; Malicious nodes are detected based on the detection and prediction results of the hidden Markov model.
2. A method for detecting failed links in underwater wireless optical networks under hybrid attacks, characterized in that: The steps include: According to the communication characteristics of underwater optical communication network, the trust features of the link are extracted, and the link trust evidence is collected including delay rate, packet error rate, packet loss rate and link usage frequency; According to the reverse cloud algorithm, the corresponding link comprehensive trust cloud is generated to reflect the observed state of the link, which serves as the basis for deducing the actual state of the link using the hidden Markov model; The real state of the link itself is defined as the hidden state. The hidden state of the link at the current moment is derived from the observed state at the current moment, and the hidden state at the next moment is predicted by the hidden state at the current moment. Hidden Markov models use historical information to make predictions and eliminate the deviation between the hidden state of the link and the observed state reflected by the trust evidence; Failed link detection is performed based on the detection and prediction results of the hidden Markov model.
3. According to the method for detecting malicious nodes in an underwater wireless optical network under a hybrid attack as described in claim 1, it is characterized in that: The abnormal energy consumption rate of a node is defined as: Where Q0 represents the initial energy value of the underwater wireless optical network node, Q r Represents the remaining energy of the node; Node activity is defined as: Where n use (n i ) is node n i The number of times it is used, Num represents the total number of nodes in the cluster; The data consistency of a node is defined as: Where n same is the number of times the node data is consistent, and n represents the total number of data packets sent.
4. The method for detecting failed links in underwater wireless optical networks under hybrid attacks according to claim 2 is characterized in that: The link delay rate is defined as: Where pk is the number of packets delivered by the sending node, st i Indicates the time delay required to send each packet, qt i represents the time delay required for each packet to queue, rt i Represents the time delay required to process each packet; The packet error rate of a link is defined as: Where b represents the packet length, erfc(x) represents the complementary error function, and SNR represents the signal-to-noise ratio when adjacent nodes communicate. The packet loss rate of the link is defined as: Where f(x) represents the probability density function of the data packet values collected between adjacent nodes. σ represents variance, μ as represents the value of the evaluation data packet between adjacent nodes, μ te Represents the average value of data packets collected between adjacent nodes; the link usage frequency is defined as: In the formula, l use (l i ) is link l i Num represents the number of times the links are used, and Num represents the total number of links in the cluster.
5. The method for detecting malicious nodes in an underwater wireless optical network under a hybrid attack according to claim 1, characterized in that: The node hidden state set includes normal state and malicious state; in the node hidden state transition matrix, the probability of a node changing from a normal state to a malicious state is The probability that a node changes from a malicious state to a normal state is The node observation state set includes malicious behaviors and normal behaviors, and its element values are obtained by comparing the characteristic values of the node comprehensive trust cloud with the set threshold.
6. The method for detecting failed links in underwater wireless optical networks under hybrid attacks according to claim 2, characterized in that: The link hidden state set includes normal state and failure state. In the link hidden state transition matrix, the probability of a link changing from normal state to failure state is The probability that a link changes from a failed state to a normal state is The link observation state set includes failure behaviors and normal behaviors, and its element values are obtained by comparing the characteristic values of the link comprehensive trust cloud with the set threshold.
7. The detection method according to claim 5 or 6, characterized in that: The hidden state is derived from the observed state, using the concept of Bayesian inference: In the formula, t represents the current time, O t is the observation state, o k is one of the observed states, S t is the hidden state, s j is a hidden state, and the probability of generating the observed state satisfies P(S t =s j |O t =o k )=b j (o k ), b j (o k ) is the element value in the observation probability matrix, P(S t =s j ) through the previous moment S t-1 The state and transition probability a ij calculate: P(O t =o k ) is the total probability of observing a particular observation o in all hidden states. k The probability of is calculated by weighting the observation probabilities of all hidden states.
8. The detection method according to claim 5 or 6, characterized in that: Using the current hidden state to predict the next hidden state is expressed as: In the formula, t represents the current time, s k 、s j is a hidden state, α jk is the transition probability, a t (j), β t (j) represents the forward probability and backward probability at time t, P(O|λ) represents the probability of the final observation sequence, λ contains the observation sequence O1, O2, ...O t and initial state parameters, O represents the observed state.
9. The detection method according to claim 1 or 2, characterized in that: A comprehensive decision is made based on the hidden state of the node / link, that is, the node / link hidden state change rate is compared with the threshold. If the node hidden state change rate is greater than the threshold, the node is in a malicious state, and the data packets it sends are discarded and a notification is broadcast within the cluster; if the link hidden state change rate is greater than the threshold, the link is in a failed state, and the data packets it sends are discarded and a notification is broadcast within the cluster.
10. A computer system comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the computer program is loaded into a processor, the steps of the detection method according to any one of claims 1 to 9 are implemented.