Active attack detection method and system based on moving target defense and event triggering
By establishing a system model and a detection model based on mobile target defense and event triggering, and analyzing Zeno behavior, the detection and defense problems of false data injection attacks are solved, and active attack detection and the reduction of network data transmission burden are achieved.
Patent Information
- Application Number
- CN202511064392.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-09-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies are difficult to effectively detect and defend against false data injection attacks. For intelligent attackers, passive defense has limited effectiveness, and event-triggered control fails to effectively reduce the burden on network transmission.
An active attack detection method based on mobile target defense and event triggering is proposed. By establishing a system model, determining the defense strategy and attack detection model, and using the event triggering mechanism to analyze Zeno behavior, the detection and defense of false data injection attacks can be achieved.
It enhances the detection capability of false data injection attacks, reduces the amount of network data transmission, reduces the network transmission burden, and achieves effective active defense effects.
Smart Images

Figure CN120602219A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of detection technology, and in particular to an active attack detection method and system based on mobile target defense and event triggering. Background Art
[0002] Cyber-physical systems (CPSs) have attracted considerable research attention due to their widespread applications. However, due to the existence of communication networks, they are vulnerable to malicious attacks from competitors. Therefore, it is necessary to develop effective attack detection and defense methods, primarily passive and active. Passive defenses are limited against intelligent attackers, and active defense theory is needed to enhance their effectiveness. Furthermore, event-triggered control is often used to reduce data transmission volume and alleviate network transmission burdens. Therefore, research on active defense and event-triggered systems is essential for the protection of continuous event systems exposed to attacks. Summary of the Invention
[0003] The present invention provides an active attack detection method and system based on mobile target defense and event triggering, which are used to solve the technical problem of active attack detection for a continuous-time linear system with false data injection attacks.
[0004] An embodiment of the present invention provides an active attack detection method based on mobile target defense and event triggering, the method comprising: Establish a system model based on parameter information related to the continuous-time linear system; After the system is attacked by false data injection, determining a defense strategy of the system against mobile targets according to the system model; Establishing an attack detection model for the system based on the system model and the defense strategy; Determining an event triggering mechanism for the system using the attack detection model; the event triggering mechanism is used to analyze Zeno behavior; Based on the defense strategy, the attack detection model, and the event triggering mechanism, attack detection analysis of the mobile target defense is performed on the system.
[0005] In some embodiments, the parameter information includes state information, output information, and control input information of the system; and establishing a system model based on the parameter information related to the continuous-time linear system includes: The system model is established according to the state information, the output information and the control input information.
[0006] In some embodiments, determining the system's defense strategy against a mobile target based on the system model includes: Acquiring mechanism information of the mobile target; The defense strategy is determined according to the mechanism information and the system model.
[0007] In some embodiments, establishing an attack detection model for the system based on the system model and the defense strategy includes: Obtaining a false data signal injected into the output channel of the system by an attacker; Determine an output model of the system after being attacked by false data injection according to the false data signal and the system model; The attack detection model is established based on the output model, the system model and the defense strategy.
[0008] In some embodiments, establishing the attack detection model based on the output model, the system model, and the defense strategy includes: Determine a state observation model of the system after being attacked by false data injection according to the system model and the defense strategy; determining first estimation error information of the system based on the system model and the state observation model; determining estimated residual information of the system according to the first estimated error information; The attack detection model is established using the estimated residual information.
[0009] In some embodiments, the event triggering mechanism includes an event triggering condition that avoids Zeno behavior; and determining the event triggering mechanism of the system using the attack detection model includes: Obtaining information about the time when an event of the system is triggered; determining gain information of an observer in the system according to the time information and the attack detection model; The event triggering mechanism is determined based on the gain information.
[0010] In some embodiments, the performing attack detection analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism includes: determining second estimation error information of the system based on the defense strategy and the event triggering mechanism; determining a state observation model of the system according to the second estimation error information and the attack detection model; Attack detection and analysis of mobile target defense is performed based on the state observation model.
[0011] An embodiment of the present invention further provides an active attack detection system based on mobile target defense and event triggering, the system comprising: A first establishing unit is used to establish a system model based on parameter information related to the continuous-time linear system; a first determining unit, configured to determine, based on the system model, a defense strategy of the system against mobile targets after the system is attacked by false data injection; A second establishing unit, configured to establish an attack detection model for the system based on the system model and the defense strategy; a second determining unit, configured to determine an event triggering mechanism of the system using the attack detection model; the event triggering mechanism being used to analyze Zeno behavior; A detection unit is used to perform attack detection analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism.
[0012] An embodiment of the present invention provides an active attack detection device based on mobile target defense and event triggering, the device comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is used to execute the steps of any of the above methods when running the computer program.
[0013] An embodiment of the present invention provides a storage medium having a computer program stored thereon; when the computer program is executed by a processor, the steps of any one of the above methods are implemented.
[0014] An embodiment of the present invention provides an active attack detection method based on mobile target defense and event triggering. The method comprises: establishing a system model based on parameter information related to a continuous-time linear system; determining the system's defense strategy against mobile targets based on the system model after the system is attacked by false data injection; establishing an attack detection model for the system based on the system model and the defense strategy; determining the system's event triggering mechanism using the attack detection model; using the event triggering mechanism to analyze Zeno behavior; and performing attack detection analysis for mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism. Using the technical solution of the present application, after the system is attacked by false data injection, determining the system's defense strategy against mobile targets based on the system model; establishing the system's attack detection model based on the system model and the defense strategy; determining the system's event triggering mechanism for analyzing Zeno behavior using the attack detection model; and performing attack detection analysis for mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism. Specifically, an active defense strategy and event triggering mechanism are implemented for a continuous event system under attack, thereby solving both the problem of active attack detection and the problem of network data transmission burden, thereby enhancing defense effectiveness, reducing data transmission volume, and alleviating network transmission burden. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1A flow chart of an active attack detection method based on mobile target defense and event triggering provided by an embodiment of the present invention; Figure 2 A schematic diagram of the structure of an active attack detection system based on mobile target defense and event triggering provided by an embodiment of the present invention; Figure 3 The figure is a schematic diagram of the hardware structure of an active attack detection device based on mobile target defense and event triggering according to an embodiment of the present invention. DETAILED DESCRIPTION
[0016] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings and specific embodiments.
[0017] The various specific technical features in the various embodiments described in the specific implementation methods can be combined in various ways without contradiction. For example, different implementation methods can be formed by combining different specific technical features. In order to avoid unnecessary repetition, the various possible combinations of the specific technical features in the present invention will not be described separately.
[0018] It should also be noted here that, in order to avoid obscuring the present invention due to unnecessary details, only structures and / or processing steps closely related to the solutions of the present invention are shown in the drawings, while other details that are not closely related to the present invention are omitted.
[0019] In addition, it should be noted that the terms "include", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the following description, the terms "first\second\..." involved are merely used to distinguish different objects and do not indicate that there is any similarity or connection between the objects. It should be understood that the directions described by the directional nouns such as "above", "below", "inside" and "outside" are all directions in normal use.
[0020] To make the purpose, technical solutions and advantages of the embodiments of the present invention more clear, the specific technical solutions of the invention will be described in further detail below in conjunction with the accompanying drawings in the embodiments of the present invention. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0021] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0022] The present invention provides an active attack detection method based on mobile target defense and event triggering, such as Figure 1As shown, Figure 1 A flow chart of an active attack detection method based on mobile target defense and event triggering provided by an embodiment of the present invention; the method includes: Step S101: Establish a system model based on parameter information related to the continuous-time linear system.
[0023] Step S102: After the system is attacked by false data injection, a defense strategy of the system against mobile targets is determined according to the system model.
[0024] Step S103: establishing an attack detection model for the system based on the system model and the defense strategy.
[0025] Step S104: Determine an event triggering mechanism of the system using the attack detection model; the event triggering mechanism is used to analyze Zeno behavior.
[0026] Step S105: performing attack detection analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism.
[0027] It should be noted that in step S101, the parameter information can be determined according to actual conditions and is not limited here. As an example, the parameter information includes the state information, output information and control input information of the system; wherein the state information can also be called the system state, which is recorded as ; The output information can also be called system output, recorded as The control input information can also be called system control input, which is recorded as .
[0028] The specific process for establishing a system model based on parameter information related to a continuous-time linear system can be determined based on actual circumstances and is not limited herein. As an example, the parameter information includes state information, output information, and control input information of the system; and establishing the system model based on the parameter information related to the continuous-time linear system may include establishing the system model based on the state information, the output information, and the control input information.
[0029] In step S102, the specific process of determining the system's defense strategy for a mobile target based on the system model can be determined based on actual circumstances and is not limited herein. As an example, determining the system's defense strategy for a mobile target based on the system model may include: obtaining mechanism information of the mobile target; and determining the defense strategy based on the mechanism information and the system model.
[0030] In step S103, the specific process of establishing the attack detection model for the system based on the system model and the defense strategy can be determined based on actual circumstances and is not limited herein. As an example, establishing the attack detection model for the system based on the system model and the defense strategy may include: obtaining a false data signal injected into the system output channel by an attacker; determining an output model of the system after being attacked by the false data injection based on the false data signal and the system model; and establishing the attack detection model based on the output model, the system model, and the defense strategy.
[0031] In step S104, the specific process for determining the system's event triggering mechanism using the attack detection model can be determined based on actual circumstances and is not limited herein. As an example, the event triggering mechanism includes an event triggering condition that avoids Zeno behavior. Determining the system's event triggering mechanism using the attack detection model may include: obtaining event triggering time information for the system; determining gain information of an observer in the system based on the time information and the attack detection model; and determining the event triggering mechanism based on the gain information.
[0032] In step S105, the specific attack detection analysis process for performing attack detection analysis on the system for mobile target defense based on the defense strategy, the attack detection model, and the event triggering mechanism can be determined based on actual circumstances and is not limited herein. As an example, the attack detection analysis on the system for mobile target defense based on the defense strategy, the attack detection model, and the event triggering mechanism may include: determining second estimation error information for the system based on the defense strategy and the event triggering mechanism; determining a state observation model for the system based on the second estimation error information and the attack detection model; and performing attack detection analysis on the mobile target defense based on the state observation model.
[0033] An embodiment of the present invention provides an active attack detection method based on mobile target defense and event triggering. After a system is attacked by false data injection, the system's defense strategy against mobile targets is determined based on a system model. An attack detection model for the system is established based on the system model and defense strategy. The attack detection model is used to determine the system's event triggering mechanism for analyzing Zeno behavior. Finally, attack detection and analysis of mobile target defense are performed on the system based on the defense strategy, attack detection model, and event triggering mechanism. This method implements an active defense strategy and event triggering mechanism for a continuous event system experiencing attacks, solving both the problem of active attack detection and the problem of network data transmission burden. This enhances defense effectiveness, reduces data transmission volume, and reduces network transmission burden.
[0034] In some embodiments, the parameter information includes state information, output information, and control input information of the system; and establishing a system model based on the parameter information related to the continuous-time linear system includes: The system model is established according to the state information, the output information and the control input information.
[0035] In this embodiment, the parameter information includes the state information, output information and control input information of the system; wherein, the state information can also be called the system state, which is recorded as ; The output information can also be called system output, recorded as The control input information can also be called system control input, which is recorded as .
[0036] The specific process of establishing the system model according to the state information, the output information and the control input information can be determined according to actual conditions and is not limited here. As an example, the system model can be ; ; in, is the system status, is the system output, is the system control input, A, B and C are known system matrices with appropriate dimensions.
[0037] In some embodiments, determining the system's defense strategy against mobile targets based on the system model includes: Acquiring mechanism information of the mobile target; The defense strategy is determined according to the mechanism information and the system model.
[0038] In this embodiment, the mechanism information of the mobile target can be determined according to actual conditions and is not limited here. As an example, the mechanism information of the mobile target can be referred to as the mobile target mechanism, which can be recorded as .
[0039] The defense strategy can be determined according to the actual situation and is not limited here. As an example, the defense strategy can be a mobile target defense strategy, which can be recorded as .
[0040] In practical applications, as an example, the moving target defense strategy: ;in, represents the system output after the moving target mechanism, stands for Moving Target Mechanism, Designed as a diagonal matrix, ;in, , , Represents the system output dimension.
[0041] In some embodiments, establishing an attack detection model for the system based on the system model and the defense strategy includes: Obtaining a false data signal injected into the output channel of the system by an attacker; Determine an output model of the system after being attacked by false data injection according to the false data signal and the system model; The attack detection model is established based on the output model, the system model and the defense strategy.
[0042] In this embodiment, the false data signal can be determined according to actual conditions and is not limited here. As an example, the false data signal can be recorded as ; It is a fake data signal injected into the output channel by the attacker.
[0043] The output model of the system after being attacked by false data injection can be determined according to the actual situation and is not limited here. As an example, the output model of the system after being attacked by false data injection can be recorded as 。
[0044] The attack detection model can be determined according to actual conditions and is not limited here. As an example, the attack detection model can be called an attack detector.
[0045] The specific establishment process of establishing the attack detection model based on the output model, the system model and the defense strategy can be determined according to actual conditions and is not limited here. As an example, the establishment of the attack detection model based on the output model, the system model and the defense strategy may include determining the state observation model of the system after being attacked by false data injection based on the system model and the defense strategy; determining the first estimated error information of the system based on the system model and the state observation model; determining the estimated residual information of the system based on the first estimated error information; and establishing the attack detection model using the estimated residual information. Among them, the state observation model, the first estimated error information, and the estimated residual information can all be determined according to actual conditions and are not limited here. As an example, the state observation model can also be called a state observer, which can be recorded as The first estimation error information can also be called estimation error, which can be recorded as The estimated residual information can also be called estimated residual, which can be recorded as .
[0046] In practical applications, as an example, define , then ,in Represents the switching signal, is the number of subsystems. Therefore, the system output model after the false data injection attack becomes: ; in, This invention assumes that the attacker can obtain relevant information such as the system matrix, but cannot obtain After being attacked, the corresponding state observer is designed as follows: ;in, is the observer state, ,matrix and Satisfy the equality conditions , is a given matrix; is the observer gain matrix; assuming that each pair is observable. The estimation error is defined as , so we can get ; Therefore, the estimated residual is The residual-based attack detector is designed as follows: ;in, is the attack detector threshold.
[0047] In some embodiments, establishing the attack detection model based on the output model, the system model, and the defense strategy includes: Determine a state observation model of the system after being attacked by false data injection according to the system model and the defense strategy; determining first estimation error information of the system based on the system model and the state observation model; determining estimated residual information of the system according to the first estimated error information; The attack detection model is established using the estimated residual information.
[0048] In this embodiment, the attack detection model can be determined according to actual conditions and is not limited here. As an example, the attack detection model can be called an attack detector.
[0049] The state observation model, the first estimation error information, and the estimation residual information can all be determined according to actual conditions and are not limited here. As an example, the state observation model can also be called a state observer, which can be recorded as The first estimation error information can also be called estimation error, which can be recorded as The estimated residual information can also be called estimated residual, which can be recorded as .
[0050] In practical applications, as an example, after being attacked, the corresponding state observer is designed as follows: ;in, is the observer state, ,matrix and Satisfy the equality conditions , is a given matrix; is the observer gain matrix; assuming that each pair is observable. The estimation error is defined as , so we can get ; Therefore, the estimated residual is The residual-based attack detector is designed as follows: ;in, is the attack detector threshold.
[0051] In some embodiments, the event triggering mechanism includes an event triggering condition that avoids Zeno behavior; and determining the event triggering mechanism of the system using the attack detection model includes: Obtaining information about the time when an event of the system is triggered; determining gain information of an observer in the system according to the time information and the attack detection model; The event triggering mechanism is determined based on the gain information.
[0052] In this embodiment, the event triggering mechanism includes an event triggering condition for avoiding Zeno behavior; the event triggering condition can be determined according to actual conditions and is not limited here. As an example, the event triggering condition can be .
[0053] The time information of the event triggering of the system can be determined according to the actual situation and is not limited here. As an example, the time information of the event triggering of the system can be referred to as the event triggering time, which can be recorded as .
[0054] The gain information of the observer in the system can be determined according to the actual situation and is not limited here. As an example, the gain information may include the observer gain matrix, which can be expressed as .
[0055] In practical applications, as an example, the event triggering mechanism of the present invention is designed as follows: ;in, , is the event triggering time, is a pre-given event triggering threshold. For the convenience of description, and Respectively referred to as and Therefore, the state observer and error equation can be written as follows: ; ;definition , then ,in , .
[0056] Next, calculate the observer gain matrix , the matrix should make the estimation error approach 0. For the given parameters , , , by solving the following matrix inequality, we can get the matrix and a positive definite symmetric matrix , , ;in, , If the switching signal If the average dwell time condition is met , then the estimated error system is stable, and the observer gain matrix can be expressed as Calculated. For any , .definition , then ;in, .because will converge to ,so is a constant. Integrating the above formula, we can get ; Solving the integral inequality, we can deduce From the above formula we can get ; Therefore, the event triggering conditions designed by the present invention can effectively avoid Zeno behavior.
[0057] In some embodiments, the performing attack detection analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism includes: determining second estimation error information of the system based on the defense strategy and the event triggering mechanism; determining a state observation model of the system according to the second estimation error information and the attack detection model; Attack detection and analysis of mobile target defense is performed based on the state observation model.
[0058] In this embodiment, the second estimation error information and the state observation model can be determined according to actual conditions and are not limited here. As an example, the second estimation error information can be recorded as ; The state observation model can also be called a state observer, which can be recorded as .
[0059] In practical applications, when there is a false data injection attack, considering the designed event-triggered control mechanism and moving target defense strategy, the corresponding state estimator and estimation error equation become the following form: ; ;in, , .definition ; If the false data injection attack meets the stealth attack conditions, then , This means that , that is, if the attacker intends to launch a stealth attack, the estimated error norm caused by the attack does not exceed The present invention assumes that the attacker cannot obtain information related to the moving target, so the following state observer needs to be designed: ;in, is the attacker's estimated state, It is the system status when an attack occurs. Definition , then ;in, ,satisfy The present invention assumes that the injected false data attack is , then ;in, So the corresponding estimated residuals satisfy ,in , This means ; It can be inferred that , then the condition of injecting false data to attack confidentiality is satisfied On the other hand, the state estimation error satisfies the following equation: It can be deduced ;in, Since the designed switching signal can ensure the stability of the system, The upper bound of is a finite value, that is .
[0060] In practical applications, as an example, the active attack detection method based on mobile target defense and event triggering can be specifically a design method for active attack detection based on mobile target defense and event triggering control, which can be implemented by the following steps.
[0061] (1) Design mobile target defense strategies and attack detectors.
[0062] Consider the following continuous-time linear system, (1); (2); in, is the system status, is the system output, is the system control input, A 、 B and C is a known system matrix of suitable dimension.
[0063] The present invention considers the following mobile target defense strategies: (3); in, represents the system output after the moving target mechanism, stands for Moving Target Mechanism, Designed as a diagonal matrix, ; in, , , Represents the system output dimension.
[0064] definition , then ,in Represents the switching signal, is the number of subsystems. Therefore, the system output model after being attacked by false data injection becomes: (4); in, This invention assumes that the attacker can obtain relevant information such as the system matrix, but cannot obtain .
[0065] After being attacked, the corresponding state observer is designed as follows: (5); in, is the observer state, ,matrix and Satisfy the equality conditions , is a given matrix; is the observer gain matrix; assuming that each pair is observable.
[0066] The estimation error is defined as , so we can get (6); Therefore, the estimated residual is The residual-based attack detector is designed as follows: (7); in, is the attack detector threshold.
[0067] (2) Design event triggering mechanism and analyze Zeno behavior The event triggering mechanism of the present invention is designed as follows: (8); in, , is the event triggering time, is a pre-given event triggering threshold. For the convenience of description, and Respectively referred to as and Therefore, the state observer and error equation can be written as follows: (9); (10); definition , then ,in , .
[0068] Next, calculate the observer gain matrix , the matrix should make the estimation error approach 0. For the given parameters , , , by solving the following matrix inequality, we can get the matrix and a positive definite symmetric matrix , , (11); in, , .
[0069] If the switching signal If the average dwell time condition is met , then the estimated error system is stable, and the observer gain matrix can be expressed as Calculated.
[0070] For any , .definition , then in, .because will converge to ,so is a constant. Integrating the above formula, we can get Solving the integral inequality, we can deduce From the above formula, we can get Therefore, the event triggering conditions designed by the present invention can effectively avoid Zeno behavior.
[0071] (3) Attack Detection Analysis Based on Mobile Target Defense When there is a false data injection attack, considering the designed event-triggered control mechanism and moving target defense strategy, the corresponding state estimator and estimation error equation become the following form: (12); (13); in, , .
[0072] definition ; If the false data injection attack meets the stealth attack conditions, then , This means that , that is, if the attacker intends to launch a stealth attack, the estimated error norm caused by the attack does not exceed .
[0073] The present invention assumes that the attacker cannot obtain information related to the moving target, so it is necessary to design the following state observer: (14); in, is the attacker's estimated state, It is the system status when an attack occurs. Definition , then in, ,satisfy .
[0074] The present invention assumes that the injected false data attack is , then (15); in, So the corresponding estimated residuals satisfy ,in , This means (16); It can be inferred that , then the condition of injecting false data to attack confidentiality is satisfied .
[0075] On the other hand, the state estimation error satisfies the following equation: (17); It can be deduced that: in, Since the designed switching signal can ensure the stability of the system, The upper bound of is a finite value, that is .
[0076] This paper proposes an active defense strategy based on mobile target defense for continuous-time linear systems subject to false data injection attacks, solving the problem of active attack detection. In addition, an event-triggered controller is designed to solve the problem of network data transmission burden.
[0077] Based on the same inventive concept as above, Figure 2 A structural diagram of an active attack detection system based on mobile target defense and event triggering provided by an embodiment of the present invention is shown in FIG. Figure 2 As shown, the system 200 includes: A first establishing unit 201 is configured to establish a system model based on parameter information related to the continuous-time linear system; A first determining unit 202 is configured to determine a defense strategy of the system against mobile targets according to the system model after the system is attacked by false data injection; A second establishing unit 203 is configured to establish an attack detection model for the system based on the system model and the defense strategy; A second determining unit 204 is configured to determine an event triggering mechanism of the system using the attack detection model; the event triggering mechanism is used to analyze Zeno behavior; The detection unit 205 is configured to perform attack detection and analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism.
[0078] In some embodiments, the parameter information includes state information, output information and control input information of the system; the first establishing unit 201 is further used to establish the system model according to the state information, the output information and the control input information.
[0079] In some embodiments, the first determining unit 202 is further configured to obtain mechanism information of the mobile target; and determine the defense strategy according to the mechanism information and the system model.
[0080] In some embodiments, the second establishing unit 203 is further used to obtain a false data signal injected into the system output channel by an attacker; determine the output model of the system after being attacked by false data injection based on the false data signal and the system model; and establish the attack detection model based on the output model, the system model and the defense strategy.
[0081] In some embodiments, the second establishing unit 203 is further used to determine the state observation model of the system after being attacked by false data injection based on the system model and the defense strategy; determine the first estimation error information of the system based on the system model and the state observation model; determine the estimated residual information of the system based on the first estimation error information; and establish the attack detection model using the estimated residual information.
[0082] In some embodiments, the event triggering mechanism includes an event triggering condition that avoids Zeno behavior; the second determination unit 204 is also used to obtain the moment information of the event triggering of the system; determine the gain information of the observer in the system based on the moment information and the attack detection model; and determine the event triggering mechanism based on the gain information.
[0083] In some embodiments, the detection unit 205 is also used to determine the second estimation error information of the system based on the defense strategy and the event trigger mechanism; determine the state observation model of the system based on the second estimation error information and the attack detection model; and perform attack detection analysis of mobile target defense based on the state observation model.
[0084] It should be noted that the active attack detection system based on mobile target defense and event triggering provided by the embodiment of the present invention and the configuration method provided by the aforementioned embodiment of the present invention belong to the same inventive concept. The meaning of the terms appearing here has been explained in detail above and will not be repeated here.
[0085] An embodiment of the present invention further provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the above-mentioned method embodiment are implemented. The aforementioned storage medium includes: a mobile storage device, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program code.
[0086] An embodiment of the present invention also provides an active attack detection device based on mobile target defense and event triggering, wherein the active attack detection device based on mobile target defense and event triggering includes: a processor and a memory for storing a computer program that can be run on the processor, wherein when the processor is used to run the computer program, it executes the steps of the above-mentioned method embodiment stored in the memory.
[0087] Figure 3 This is a hardware structure diagram of an active attack detection device based on mobile target defense and event triggering according to an embodiment of the present invention. The active attack detection device based on mobile target defense and event triggering 300 includes: at least one processor 301, a memory 302. Optionally, the active attack detection device based on mobile target defense and event triggering 300 may further include at least one communication interface 303. The various components in the active attack detection device based on mobile target defense and event triggering 300 are coupled together through a bus system 304. It can be understood that the bus system 304 is used to realize connection and communication between these components. In addition to the data bus, the bus system 304 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 3 Various buses are labeled as bus system 304 .
[0088] It is understood that memory 302 can be volatile memory or non-volatile memory, or can include both volatile and non-volatile memory. Non-volatile memory can include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disk, or compact disc read-only memory (CD-ROM); magnetic surface memory can include magnetic disk storage or magnetic tape storage. Volatile memory can include random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 302 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0089] The memory 302 in the embodiment of the present invention is used to store various types of data to support the operation of the active attack detection device 300 based on mobile target defense and event triggering. Examples of such data include any computer program for operating on the active attack detection device 300 based on mobile target defense and event triggering. The program implementing the method of the embodiment of the present invention may be included in the memory 302.
[0090] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 301. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware components, etc. The processor can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium located in a memory. The processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0091] In an exemplary embodiment, the active attack detection device 300 based on mobile target defense and event triggering can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the above method.
[0092] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is merely a logical functional division. In actual implementation, other divisions may be employed, such as combining multiple units or components, integrating them into another system, or omitting or disabling certain features. Furthermore, the coupling, direct coupling, or communication connection between the components shown or discussed may be through interfaces. The indirect coupling or communication connection between devices or units may be electrical, mechanical, or other. The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of these units may be selected to achieve the objectives of the present embodiments based on actual needs. Furthermore, the functional units in the various embodiments of the present invention may all be integrated into a single processing module, each unit may be a separate unit, or two or more units may be integrated into a single unit. These integrated units may be implemented in hardware or as hardware plus software functional units.
[0093] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. An active attack detection method based on mobile target defense and event triggering, characterized in that: The method comprises: Establish a system model based on parameter information related to the continuous-time linear system; After the system is attacked by false data injection, determining a defense strategy of the system against mobile targets according to the system model; Establishing an attack detection model for the system based on the system model and the defense strategy; Determining an event triggering mechanism for the system using the attack detection model; the event triggering mechanism is used to analyze Zeno behavior; Based on the defense strategy, the attack detection model, and the event triggering mechanism, attack detection analysis of the mobile target defense is performed on the system.
2. The method according to claim 1, characterized in that The parameter information includes state information, output information and control input information of the system; the system model is established based on the parameter information related to the continuous-time linear system, including: The system model is established according to the state information, the output information and the control input information.
3. The method according to claim 1, characterized in that Determining the system's defense strategy against mobile targets based on the system model includes: Acquiring mechanism information of the mobile target; The defense strategy is determined according to the mechanism information and the system model.
4. The method according to claim 1, wherein The establishing of the attack detection model of the system based on the system model and the defense strategy includes: Obtaining a false data signal injected into the output channel of the system by an attacker; Determine an output model of the system after being attacked by false data injection according to the false data signal and the system model; The attack detection model is established based on the output model, the system model and the defense strategy.
5. The method according to claim 4, characterized in that The establishing of the attack detection model based on the output model, the system model and the defense strategy includes: Determine a state observation model of the system after being attacked by false data injection according to the system model and the defense strategy; determining first estimation error information of the system based on the system model and the state observation model; determining estimated residual information of the system according to the first estimated error information; The attack detection model is established using the estimated residual information.
6. The method according to claim 1, wherein The event triggering mechanism includes an event triggering condition for avoiding Zeno behavior; and the event triggering mechanism of the system determined by using the attack detection model includes: Obtaining information about the time when an event of the system is triggered; determining gain information of an observer in the system according to the time information and the attack detection model; The event triggering mechanism is determined based on the gain information.
7. The method according to any one of claims 1 to 6, characterized in that The attack detection analysis of the mobile target defense system based on the defense strategy, the attack detection model, and the event triggering mechanism includes: determining second estimation error information of the system based on the defense strategy and the event triggering mechanism; determining a state observation model of the system according to the second estimation error information and the attack detection model; Attack detection and analysis of mobile target defense is performed based on the state observation model.
8. An active attack detection system based on mobile target defense and event triggering, characterized in that: The system comprises: A first establishing unit is used to establish a system model based on parameter information related to the continuous-time linear system; a first determining unit, configured to determine, based on the system model, a defense strategy of the system against mobile targets after the system is attacked by false data injection; A second establishing unit, configured to establish an attack detection model for the system based on the system model and the defense strategy; a second determining unit, configured to determine an event triggering mechanism of the system using the attack detection model; the event triggering mechanism being used to analyze Zeno behavior; A detection unit is used to perform attack detection analysis of mobile target defense on the system based on the defense strategy, the attack detection model, and the event triggering mechanism.
9. An active attack detection device based on mobile target defense and event triggering, characterized in that: The device comprises: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor executes the steps of the method according to any one of claims 1 to 7 when running the computer program.
10. A storage medium, characterized in that: The storage medium stores a computer program; when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Active network defense method and system based on watermark and moving target fusion
CN120166406A
Defense method and device against attack, and computer readable storage medium
WO2018103364A1