Information security risk assessment method for optimizing SND based on improved PFS algorithm
By combining Pythagorean fuzzy sets and multi-criteria decision-making methods, the problem of insufficient vulnerability assessment in SDN systems is solved, achieving more efficient and accurate information security risk assessment, reducing risk assessment errors, and improving the accuracy of risk assessment.
Patent Information
- Application Number
- CN202510299949.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-11-07
AI Technical Summary
In existing software-defined networking (SDN) systems, vulnerability assessment has not been adequately studied, resulting in insufficient accuracy and efficiency in information security risk assessment, and an inability to effectively address complex cybersecurity challenges.
By combining Pythagorean Fuzzy Sets (PFS) with the Analytic Hierarchy Process (AHP) and the Decision Experimentation and Evaluation Laboratory (DEMATEL) method, a multi-criteria decision-making approach is developed for information risk assessment in SDN. This approach uses mathematical tools such as membership degree, non-membership degree, and hesitation degree to handle uncertainty.
It improves the accuracy and efficiency of information security risk assessment in SDN systems, reduces the prediction error of risk assessment results, and enhances the prediction accuracy of risk assessment results.
Smart Images

Figure CN120915477A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The concept of software-defined network is introduced into the network field to enhance the network capability to cope with the rapid growth of network resources. BACKGROUND
[0002] In the current rapidly evolving network environment, ensuring secure communication has become a basic responsibility of network administrators. To achieve this goal, managers must fully describe the properties of each network working component and its potential security vulnerabilities. Software-defined network (SDN) has significant differences in architecture and communication mode from traditional network environment, although SDN is superior to traditional network in many ways, it also brings new security vulnerabilities and related risk awareness.
[0003] Regarding the security of SDN, D. Kreutz et al. identified and discussed seven major vulnerabilities related to SDN architecture in their 2013 study (Kreutz et al., 2013), while C. Yoon et al. further studied twelve new vulnerabilities in SDN architecture in 2017, which brought greater challenges to information security (Yoon et al., 2017). However, so far, the ranking and priority assessment of these vulnerabilities have not been fully studied.
[0004] The key analysis of the identified vulnerabilities in the current state of network systems is an important standard for building stable and sustainable SDN systems. Therefore, there is an urgent real demand to develop a novel vulnerability assessment mechanism for SDN systems. This demand inspires our research motivation.
[0005] There are multiple security vulnerabilities in SDN systems, which create multiple attackable paths for information risk. Therefore, before implementing any security mechanism, network administrators must clearly identify the main vulnerabilities of the system. It can be seen that determining the priority of vulnerabilities is a multi-criteria decision problem, which becomes a further driving force for our research. In order to improve the accuracy and efficiency of information security risk assessment, it is imperative to develop a new risk assessment method to cope with the complex challenges of the current network security environment. SUMMARY
[0006] This paper aims to provide an efficient and effective multi-criteria decision making (MCDM) method for information risk assessment in software-defined networks (SDN) by introducing Pythagorean Fuzzy Sets (PFS). This is the first attempt to apply a risk assessment mechanism to the SDN environment. Analytic Hierarchy Process (AHP) and Decision Experimentation and Evaluation Laboratory (DEMATEL) are widely known MCDM methods that, when combined with PFS, significantly enhance the effectiveness of the proposed risk assessment model and provide new ideas for expressing uncertainty in SDNs.
[0007] This paper elaborates on the proposed integration model and explains the operational procedures at each stage. In addition, a computational evaluation of the integration mechanism is discussed. This patent is divided into two main parts: the first part introduces the theoretical approach of the proposed mechanism, and the second part gradually evaluates the mechanism through a reference case study, further comparing and discussing the results. This patent also proposes an alternative computational method, which is compared and analyzed with the traditional fuzzy method in the subsequent part. Finally, the article gives a summary opinion of the proposed mechanism.
[0008] Pythagorean Fuzzy Sets (PFS) is a mathematical tool for handling fuzziness and uncertainty problems. This method extends the concept of Intuitionistic Fuzzy Sets (IFS) by introducing a new dimension, allowing for more flexible and accurate expression of information uncertainty. In a finite discussion domain X, a PFS P is a set composed of tuples <x, μ p (x), v p (x)> where x ∈ X.
[0009] Here, μ p (x): X→[0, 1] represents the degree to which an element x belongs to a certain set, while v p (x): X→[0, 1] represents the degree to which an element x does not belong to a certain set. The hesitation degree π p (x) = 1 - μ p (x) 2 -v p (x) 2 is defined as π p (x) = 1 - μ(x) 2 -v p (x) 2 , indicating the degree of uncertainty when neither membership nor non-membership is completely determined. For any PFS and its element x, the condition μ p (x) 2 +v p (x) 2≤ 1. This condition means that the sum of the membership and non-membership degrees cannot exceed 1, thus limiting their range of values and introducing the concept of hesitancy.
[0010] A Pythagorean Fuzzy Number (PFN) is defined by a pair of membership and non-membership degrees in a PFS, and can be represented as β = (μ B , v β ), where μ B , v β ∈ [0, 1] and satisfy
[0011] Comparisons between PFNs can be defined through their membership and non-membership degrees. Specifically, a PFN B1 is greater than B if and only if μ B1 > μ B2 , and v B1 ≤ v B2 . The size of two PFNs can be compared through the accuracy function a(p) and the score function s(p), which help determine the relative relationship between two PFNs, such as equal, greater than, or less than.
[0012] PFS provides a more nuanced and flexible approach to handling uncertainty, especially when there is a clear hesitation between membership and non-membership degrees. By introducing hesitancy and through the condition that the sum of membership and non-membership degrees is less than or equal to 1, PFS can more accurately describe and handle complex uncertainty problems.
[0013] P = { <x, μ p (x), v p (x)> | x ∈ X} (1)
[0014] Pythagorean Fuzzy Set (PFS): Within a finite discussion domain, a PFS is a set composed of tuples <x, μ p (x), v p (x)> where x belongs to the domain X.
[0015] Membership degree (μ): represents the degree to which an element belongs to a certain set, and the function μ p : X→ [0, 1] defines the membership degree of element x to P.
[0016] Non-membership degree (v): represents the degree to which an element does not belong to a certain set, and the function v p : X→ [0, 1] defines the non-membership degree of element x to P.
[0017] Hesitancy degree (π p (x)): represents the degree of hesitation in determining the membership or non-membership of an element, and the function π p(x) represents the degree of uncertainty of element x belonging to and not belonging to set P, and the calculation formula is π p (x) = 1 - μ p (x) 2 -v p (x) 2 .
[0018] (μ p (x)) 2 +(v p (v)) 2 ≤1 (2)
[0019] For any element x in PFS, the sum of the membership degree and the non-membership degree must satisfy the condition (μ p (x)) 2 +(v p (v)) 2 ≤1. This condition limits the value range of the membership degree and the non-membership degree, making the hesitation degree possible.
[0020]
[0021] Pythagorean fuzzy number (PFN) is defined on the basis of Pythagorean fuzzy set (PFS), which is composed of membership degree μ and non-membership degree v, and can be represented as β = P(μ β ,v β ), where μ β , V β ∈ [0, 1]. The definition of PFN needs to satisfy (μ β ) 2 +(v β ) 2 ≤1, ensuring that the sum of the membership degree and the non-membership degree does not exceed 1, so that the degree of membership and non-membership cannot reach the limit value.
[0022] In addition, the operation of PFN defines specific operation rules, including addition and multiplication:
[0023] 1. Addition: For two PFNs β = P(μ β , v β ) and γ = P(μ γ , v γ ), their addition is defined as β + γ = P(μ β + μ γ , v β + v γ ).
[0024] 2. Multiplication: For two PFNs β and γ, the multiplication is defined as β x γ = P(μ β μ γ , v β v γ ). BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0026] Figure 1 The flowchart of the information security risk assessment method of the present application based on the improved PFS algorithm optimized SND.
[0027] Figure 2 The PFS structure diagram of the information security risk assessment method of the present application based on the improved PFS algorithm optimized SND
[0028] Figure 3 The fuzzy theory of the information security risk assessment method of the present application based on the improved PFS algorithm optimized SND DETAILED DESCRIPTION
[0029] In order to make the person skilled in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0030] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] Example 1
[0032] The application provides an information security risk assessment method for optimizing SND based on an improved PFS algorithm.
[0033] 1) Initialization: T particles are randomly generated, each representing a potential solution and containing the penalty parameter C and the kernel parameter σ of the SND model. An initial speed Vi and a position Xi are set for each particle; in addition, the maximum number of iterations N and the convergence precision δ of the algorithm are also set.
[0034] 2) The position (the values of C and σ) of each particle is decoded and used as the training parameter of the SND model. The decoded parameters are used to train the SND model, and the training sample set is used for learning. The smaller the error, the greater the fitness value, indicating that the parameter setting of the particle is more optimal. Update the particle state: individual and group experience: update the speed and position of the particle according to the historical optimal position (P best ) of each particle and the optimal position (G best ) of the entire particle group. In the updating process, the crossover and mutation operations of the genetic algorithm are introduced. The crossover operation helps the particle inherit the advantageous characteristics and enhances the regional search ability; the mutation operation improves the particle diversity, avoids premature convergence, and helps to find the global optimal solution.
[0035]
[0036] wherein F is the fitness function; K and D are constants; H is the number of samples; y i represents the predicted risk value of SND; t i represents the actual risk assessment value.
[0037] 3) After each update of the population, the average fitness value F avg of the particle group is calculated, and the average fitness value of the particles with a fitness value greater than or equal to F avg is calculated to obtain F′ avg . The average fitness value of the particles with a fitness value less than F avg is calculated to obtain F″ avg . The population U is divided into three parts. The particles with a fitness value greater than or equal to F′ avg are the sub-population L1, the particles with a fitness value less than F′ avg and greater than or equal to F″ avg are the sub-population L2, and the particles with a fitness value less than F″ avg are the sub-population L3.
[0038]
[0039] 4) Introducing the operation of genetic algorithm. Since the sub-population L1 has better fitness, the velocity and position of the particle are updated using formula (12) and formula (13). By applying the genetic algorithm, the sub-population L2 is subjected to a crossover operation, and a random two-by-two crossover pairing is performed, while the crossover probability p c is used for the crossover operation.
[0040] 5) The formula for the crossover operation of the velocity of particle i and particle j is as follows:
[0041]
[0042] The formula for the crossover operation of the position of particle i and particle j is as follows:
[0043]
[0044] Where θ1 and θ2 are random values between 0 and 1. After the crossover operation, the fitness of the offspring and the parent particles is compared, and the particle with higher fitness is selected for subsequent iteration. For the sub-population U3 with lower fitness, a mutation probability p m is used for the mutation operation.
[0045] 6) Updating individual extreme value and global extreme value of population. After the operation of step 4), the fitness value of the calculated new particle is compared with P best , G best . When the new particle has better fitness than P best , the original P best is updated, and P best is given priority position value.
[0046] 7) Repeat iteration. Repeat the above steps 1) to 5) until the following conditions are met (i.e. the objective function reaches the convergence precision δ or the number of iterations reaches the preset maximum number N), and the iteration is ended. Through the above multiple training, the optimal parameters of SND can be obtained.
[0047] The patent constructs and simulates the SND model based on MATLAB (R2007b) as a software platform. In order to obtain better comparative evaluation effect, the information security risk assessment is carried out by BPNN, SVM, PFS, SND and improved PFS, SND evaluation model respectively. The evaluation index of the model is the average relative error. The average relative error is defined as follows: The basic principle of SND is to use a nonlinear mapping (i.e. input space to output space) to map the input data x to a high-dimensional feature space E, and then perform linear regression. The formula of the linear regression function is as follows:
[0048] L(x) = w * Φ(x) + b (13)
[0049] w, b respectively represent bias, weight vector of hyperplane. Generally, the loss function of SND is linear insensitive loss function, and the function is represented as follows:
[0050]
[0051] Wherein, y, l(x) respectively represent predicted value, true value of regression function. In the regression function, b, w is estimated by minimizing the objective function, and the formula is as follows
[0052]
[0053] s.t.=w*Phi(x)+b-y i (16)
[0054] Wherein, C is penalty factor. The greater the value is, the greater the penalty of data greater than L E is. i And ξ represents relaxed variable, and epsilon defines the error requirement of regression function.
[0055] The patent experiment collects 60 information system evaluation cases. Select unauthorized access (X1), data leakage (X2), information tampering (X3), information loss (X4), denial of service (X5), system function collapse (X6) as the risk factors of information system. The risk value of each factor is obtained by the above fuzzy theory processing. The risk evaluation value of the system is obtained by comprehensive evaluation of the information system.
[0056] The following experimental data (wherein the factor value is rounded to one decimal place and displayed in the table; the evaluation value is taken to four decimal places) is obtained by using fuzzy theory for pretreatment, and the specific steps are as follows: Step 1: Construct the influence factor set of information system as U={X1, X2, X3, X4, X5, X6}: {low (0.0~0.2), low (0.2~0.4), medium (0.4~0.6), high (0.6~0.8), higher (0.8~1.0)}, abbreviated as {IL, L, M, H, IH}. Among them, the numerical value (such as 0.2~0.4) represents the risk degree of the factor, and the greater the value is, the greater the risk is.
[0057] Table 1 expert evaluation statistics
[0058]
[0059] The evaluation index membership matrix D is obtained from Table 1. It includes six influencing factors (X1 to X6), each of which is divided into five levels: very low (IL), low (L), medium (M), high (H), and very high (IH). These levels reflect the potential impact of different risk factors on information security.
[0060] Specifically, the levels of each influencing factor are divided by numerical ranges: very low (IL): indicating that the factor has minimal impact on the security risk of the information system, with a numerical range of 0.1 to 0.3.
[0061] Low (L): indicating a small risk impact, with a numerical range of 0.3 to 0.5. Medium (M): meaning that the risk impact of the factor is moderate, with a numerical range of 0.5 to 0.7. High (H): referring to a larger risk impact, with a numerical range of 0.7 to 0.9. Very high (IH): indicating that the factor has a very large impact on the security risk of the information system, with a numerical range of 0.9 to 1.1.
[0062] This evaluation method can effectively help security experts and decision-makers understand the specific impact of various risk factors on information system security. Through this quantitative method, it can more accurately determine which factors need to be prioritized and addressed.
[0063]
[0064] Table 2 Partial training sample set
[0065] Number X1 X2 X3 X4 X5 X6 Evaluation value 1 0.4 0.3 0.3 0.4 0.6 0.5 0.5293 2 0.2 0.4 0.4 0.3 0.5 0.3 0.2613 3 0.5 0.6 0.4 0.6 0.3 0.5 0.4728 4 0.7 0.2 0.2 0.4 0.3 0.4 0.3886 5 0.9 0.7 0.8 0.7 0.6 0.7 0.7425
[0066] Table 2 shows 5 groups of sample data from the training sample data.
[0067] All raw data from this experiment is processed as described above, resulting in the experimental data in this paper.
[0068] The risk values of the 6 risk factors are used as input variables, and the risk assessment value of the system is used as the output variable. The collected 60 groups of sample data are divided into training sample set and test sample set.
[0069] Table 3 Test sample set
[0070] Number X1 X2 X3 X4 X5 X6 Evaluation value 1 0.5 0.6 0.4 0.6 0.7 0.25 0.5125 2 0.5 0.4 0.6 0.4 0.4 0.2 0.3264 3 0.6 0.5 0.4 0.6 0.5 0.7 0.5487 4 0.4 0.6 0.7 0.4 0.7 0.8 0.6529 5 0.2 0.1 0.5 0.4 0.6 0.4 0.5654
[0071] The input training sample set is input into SND, and the PFS algorithm and the improved PFS algorithm are used to train the samples to obtain the best optimization parameters (as shown in Table 3). Finally, the BP, NN, SVM, PFS, SND and improved PFS, SND evaluation models are used to test the data of the five groups of test sample sets. The simulation results and the relative errors of each model are compared. The simulation result comparison can draw the following conclusions: compared with the BP, NN, SVM, PFS and SND evaluation models, the average relative error of the improved evaluation model used in this paper is reduced by 54.21%, 45.66% and 30.22% respectively. This shows that the improved PFS and SND evaluation models not only reduce the prediction error of the risk evaluation result, but also improve the prediction accuracy and accuracy of the risk evaluation result.
[0072] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A software-defined network (SDN) information security risk assessment method based on improved Pythagorean Fuzzy Set (PFS) theory and particle swarm algorithm, characterized in that, The method quantitatively preprocesses information security risk factors by fuzzy theory, and optimizes parameters of a regression support vector machine (SVM) by an improved particle swarm algorithm, thereby forming an optimized risk assessment model.
2. The information security risk assessment method of claim 1, wherein, The method first preprocesses information security risk factors by PFS theory to cope with uncertainty and fuzziness in information security assessment.
3. The information security risk assessment method of claim 1 or 2, wherein, The method optimizes parameters of the SVM by the improved particle swarm algorithm to improve prediction accuracy and stability of the model, and enhance adaptability of the model to new security threats.
4. The information security risk assessment method of claim 3, wherein, The improved particle swarm algorithm optimizes the iteration process of the particle swarm by introducing dynamic inertia weight and adaptive learning factor, thereby accelerating convergence and avoiding falling into local optimum.
5. The method of information security risk assessment of claim 1, wherein, The method further combines analytic hierarchy process (AHP), decision experiment and evaluation laboratory (DEMATEL) and PFS theory to construct a novel multi-criteria decision model for quantifying and ranking security vulnerabilities in SDN systems.
6. The method of information security risk assessment of claim 5, wherein, PFS theory introduces the concept of hesitancy degree, making expressions of membership degree and non-membership degree more flexible and accurate, thereby improving effectiveness of the model in dealing with uncertainty problems.
7. The information security risk assessment method of claims 1 to 6, wherein, The method can provide a tool for network administrators to identify and cope with major security threats in the SDN environment, thereby ensuring safe and stable operation of the network.