Network attack defense method and system

By dynamically adjusting the unmanned vehicle formation using heterogeneity indicators and multi-mode voting mechanisms, the problem of cluster failure in the face of unknown vulnerabilities and internal attacks was solved, enabling efficient identification and response to internal attacks and improving the security and mission continuity of the formation.

CN121530737APending Publication Date: 2026-02-13PURPLE MOUNTAIN LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202512015442.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

When faced with unknown vulnerabilities and internal attacks, unmanned vehicle formations are prone to cluster failure due to the spread of homogeneous vulnerabilities and insufficient detection of internal threats. Existing defense methods are unable to effectively identify hijacked nodes and lack the ability to dynamically reconstruct topology.

Method used

Trusted nodes and ordinary nodes are identified by heterogeneity index. Trusted nodes are used to monitor communication traffic and movement trajectory to determine node status. A greedy algorithm is used to optimize the position of trusted nodes. Combined with a multi-mode voting mechanism and a backup node replacement mechanism, the formation topology is dynamically adjusted.

Benefits of technology

It improves the defense against cluster failures of unmanned vehicles, reduces the risk of homogeneous spread of unknown vulnerabilities, enhances the ability to identify and respond to internal attacks, and ensures the overall security and mission continuity of the formation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530737A_ABST
    Figure CN121530737A_ABST
Patent Text Reader

Abstract

The invention discloses a network attack defense method and system, and the method comprises the steps: determining credible nodes and common nodes in a credible set according to an isomerism degree index, and enabling the credible nodes to be used for receiving and transmitting signals to the common nodes during the communication between the common nodes; the isomerism degree index is a weighted isomerism degree including supplier, hardware, software and vulnerability overlap ratio; the trusted node judges the attacked state of the common node by monitoring the communication flow and the motion trail of the common node; and the trusted nodes judge the attacked state of the trusted nodes by mutually monitoring the communication flow and the motion trail. According to the scheme, the defense effect on the cluster failure problem caused by individual unmanned carrier node loss can be improved, and the homogenization diffusion risk of unknown vulnerabilities can be resisted.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a network security defense scheme, in particular to a network attack defense method and system. BACKGROUND

[0002] At present, various types of unmanned vehicles, including unmanned aerial vehicles, unmanned ships, etc., adopt various types of hardware and software resources, advanced intelligent algorithms, control algorithms and wireless communication systems, and are generally equipped with a cooperative controller specially used for formation control. Based on the open source ecological environment and complex supply chain, while bringing the improvement of the task performance capability, the system is also more complex, leaving security risks and vulnerabilities that cannot be thoroughly investigated. In addition, an attacker may reverse engineer or physically seize an unmanned vehicle, modify it into a "dumb" node and mix it into the formation. Such a controlled node can initiate attacks from within the formation, such as data tampering, malicious instruction injection, etc., use single-point vulnerabilities to trigger cascading failures, and ultimately cause the entire cluster to fail. Therefore, how to protect the entire fleet from cluster failure caused by the loss of individual unmanned vehicles in the case of untraceable backdoors is very important.

[0003] The current defense means divides the nodes in the unmanned vehicle group into trusted nodes, general nodes and untrusted nodes, and routes based on trusted nodes to achieve network security defense, but there are significant defects: 1. Homogenization vulnerability diffusion risk. Existing formations mostly use nodes of the same type / same source hardware and software, resulting in vulnerabilities that are universally applicable (Single Point of Failure). Once an attacker masters the vulnerability of a certain type, all homogenous nodes in the formation can be compromised at the same time. 2. Lack of internal threat detection mechanism. Traditional technologies based on border protection (such as firewalls) or static identity authentication cannot effectively identify hijacked legal nodes. When attacks are initiated from within the formation, existing solutions lack multi-dimensional perception capabilities for abnormal node behavior. 3. Static defense architecture is vulnerable to reverse engineering. Fixed node role allocation and communication topology allow attackers to analyze system rules over a long period of time and implement trial-and-error attacks, such as brute force attacks, or standby coordinated attacks, where the latent nodes attack simultaneously according to instructions. 4. Insufficient disturbance node isolation and self-healing capabilities. When some nodes are attacked and fail, existing formation control protocols often only perform simple removal operations, lacking dynamic topology reconstruction mechanisms, resulting in disturbance diffusion (such as malicious instruction propagation) or formation structure collapse. SUMMARY

[0004] The present application is proposed to solve the above problems, and provides a network attack defense method and system, which can improve the defense effect of cluster failure caused by the loss of individual unmanned vehicles and resist the homogenization diffusion risk of unknown vulnerabilities.

[0005] Technical Solution: The technical solution adopted in this invention is a network attack defense method, including:

[0006] Trusted nodes and ordinary nodes in the trusted set are determined based on the heterogeneity index. Trusted nodes are used to receive and send signals to ordinary nodes when communicating between them. The heterogeneity index is determined based on at least one of vendor heterogeneity, hardware heterogeneity, software heterogeneity, and vulnerability overlap heterogeneity.

[0007] By monitoring the communication traffic and movement trajectory of any node in the trusted set through trusted nodes, the attack status of any node can be determined.

[0008] Network attack defense is performed based on the attack status of any of the nodes.

[0009] The method further includes:

[0010] The supplier heterogeneity is determined based on the proportion of the largest number of nodes from the same supplier in the total number of nodes in the trusted set.

[0011] Traverse any hardware in the key hardware type as the first type of hardware, determine the heterogeneity of the first type of hardware based on the proportion of the maximum number of nodes of the same model in the first type of hardware to the total number of nodes in the trusted set, and sum the heterogeneity of the first type of hardware according to the specified hardware type to obtain the hardware heterogeneity.

[0012] The software heterogeneity is obtained by the proportion of the number of nodes of each type of software combination in the total number of nodes of the trusted set;

[0013] The degree of vulnerability overlap and heterogeneity is determined by the ratio of the sum of the number of overlapping public vulnerabilities between any two nodes in the trusted set to the square of the total number of node pairs in the trusted set.

[0014] The method of determining trusted nodes and ordinary nodes in the trusted set based on the heterogeneity index includes: taking the maximum heterogeneity index as the primary optimization condition and the minimum communication cost of trusted nodes as the secondary optimization condition, determining the position of trusted nodes in the entire unmanned vehicle group and the ordinary nodes under their jurisdiction.

[0015] The communication cost of the trusted node includes communication overhead, energy consumption overhead, and computing overhead.

[0016] A greedy algorithm is used to determine the location of the trusted nodes and the ordinary nodes under their jurisdiction. The greedy selection criteria of the greedy algorithm are designed based on the primary optimization conditions and the secondary optimization conditions. The constraints of the greedy algorithm include communication range constraints.

[0017] The attack state of the common node is determined, including: calculating the residual of the actual trajectory and the predicted trajectory of the common node according to the motion trajectory of the common node; calculating the information entropy in the period according to the communication traffic in the period of the common node; if the residual is greater than the set cumulative residual threshold and the information entropy change of the adjacent period is greater than the set information entropy monitoring threshold, the attack state is determined.

[0018] The abnormal common node determined as the attack state is replaced by the nearby backup node; the replacement of the abnormal common node includes: calling the backup node to enter the working position of the abnormal common node; the abnormal common node suspends the execution of the task and recovers the abnormal disturbance through the automatic repair program.

[0019] In the case that the disturbance of the abnormal common node cannot be recovered and the control system is normal, passive tracking flight is performed based on the relative navigation method; in the case that the disturbance of the abnormal common node cannot be recovered and the control system is abnormal, the abnormal common node is excluded from the feasible set.

[0020] The attack state of the trusted node is determined, including: determining the attack state of the trusted node by using a multi-mode voting mechanism; the multi-mode voting mechanism includes: a super-half voting algorithm; the multi-mode voting mechanism further includes: when there are paired mutually exclusive accusations, the node with higher credibility is retained and the current accusation is recorded, whether the current accusation is established is determined preferentially in the next round of voting, and the credibility is determined according to the historical attack state.

[0021] The abnormal trusted node determined as the attack state is replaced by the nearby backup trusted node, and the replacement of the abnormal common node includes: calling the backup trusted node to enter the working position of the abnormal trusted node; the abnormal trusted node suspends the execution of the task and is offline for cleaning; the offline cleaning includes: the abnormal trusted node enters the backup node group; the abnormal trusted node is initialized and reset, the system of the abnormal trusted node is switched to the backup security system, and the authentication key of the abnormal trusted node is updated; after the cleaning operation is completed, the abnormal trusted node is set to a replaceable state.

[0022] In the case that there is no abnormal alarm, a preset number of trusted nodes are replaced every preset time; the preset number of trusted nodes include the trusted nodes with the historical attack state being the attack state.

[0023] The application provides a computer device, including a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to realize the network attack defense method.

[0024] The application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the network attack defense method.

[0025] The application provides a computer program product, which comprises a computer program and / or instructions, and the computer program and / or instructions are executed by a processor to implement the network attack defense method.

[0026] The application provides a network attack defense system, which comprises a UAV formation and a cooperative controller for formation control, and the cooperative controller executes the network attack defense method.

[0027] Advantages: compared with the prior art, the application has the following advantages: 1. the application reduces the risk of homogeneous diffusion of unknown vulnerabilities by optimizing the selection and construction of the heterogeneous trusted set. The application determines the trusted nodes and ordinary nodes in the trusted set according to the heterogeneity index, and proposes a weighted heterogeneity that comprehensively considers the weights of suppliers, hardware, software and vulnerability overlap. 2. The application proposes that the trusted nodes monitor the communication traffic and motion trajectory of the ordinary nodes to determine the attack state of the ordinary nodes; the trusted nodes monitor the communication traffic and motion trajectory of each other to determine the attack state of the trusted nodes, which can improve the defense effect of the cluster failure problem caused by the loss of individual UAV nodes. BRIEF DESCRIPTION OF DRAWINGS

[0028] Figure 1 is a schematic diagram of the UAV formation according to the application;

[0029] Figure 2 is a schematic diagram of the communication topology structure of the fleet according to the application;

[0030] Figure 3 is a schematic diagram of the construction of the trusted set according to the application;

[0031] Figure 4 is a method for eliminating the disturbance of ordinary nodes according to the application;

[0032] Figure 5 is a schematic diagram of the dynamic rotation of trusted nodes according to the application;

[0033] Figure 6 is a flowchart of the whole-cycle protection chain according to the application. DETAILED DESCRIPTION

[0034] The technical solutions of the application will be further described below with reference to the drawings and examples. Each example will be described with the UAV scene as an example.

[0035] Example 1:

[0036] The network attack defense method comprises the following steps: determining trusted nodes and normal nodes in a trusted set according to a heterogeneity index, wherein the trusted nodes are used to receive and send signals to the normal nodes when the normal nodes communicate, and the heterogeneity index is determined according to at least one of a supplier heterogeneity, a hardware heterogeneity, a software heterogeneity and a vulnerability coincidence heterogeneity; monitoring the communication traffic and the motion trajectory of any node in the trusted set through the trusted nodes to determine the attack state of the any node; and performing network attack defense according to the attack state of the any node.

[0037] As shown in Figure 1 , the unmanned aerial vehicle formation comprises trusted nodes and normal nodes, and a plurality of normal nodes are under the jurisdiction of one trusted node, and the normal nodes are located in the monitoring area of the trusted node. As shown in Figure 2 , the communication topology structure of the formation comprises trusted nodes and normal nodes, and the normal nodes do not communicate with each other, and all communications need to pass through the trusted nodes, so that even if the normal nodes are attacked, they cannot directly affect other unmanned aerial vehicles. The heterogeneous redundant unmanned aerial vehicle basic trusted set is constructed and laid out, and the trusted nodes in the formation are selected according to the heterogeneity index. The heterogeneity index needs to comprehensively consider the differences in multiple aspects including the supplier, the hardware, the software and the vulnerability coincidence. When the trusted node monitors the abnormal behavior of the normal node under its jurisdiction, it is determined whether the normal node is attacked, and if so, the normal node is marked as an abnormal node and an alarm is triggered. The abnormal behavior of the normal node is determined according to the communication traffic and the motion trajectory of the normal node.

[0038] Embodiment 2

[0039] Based on the network attack defense method described in Embodiment 1, an effective heterogeneity index calculation method comprises: weighted summation of the supplier heterogeneity, the hardware heterogeneity, the software heterogeneity and the vulnerability coincidence heterogeneity.

[0040] The supplier heterogeneity, the hardware heterogeneity, the software heterogeneity and the vulnerability coincidence heterogeneity are comprehensively considered to calculate the heterogeneity index, and the heterogeneity index is defined as follows:

[0041] ;

[0042] Wherein, is the heterogeneity index, is a weight coefficient, and satisfies , which reflects the importance of different factors. In this embodiment, the weight coefficients are respectively preset as 0.3, 0.3, 0.2 and 0.2. is the supplier heterogeneity, is the hardware heterogeneity, is the software heterogeneity, is the vulnerability coincidence heterogeneity.

[0043] Other methods that can comprehensively reflect the heterogeneity of suppliers, hardware, software, and vulnerability overlap can be used to construct heterogeneity indicators.

[0044] Based on the aforementioned effective methods for calculating heterogeneity indices, further methods are proposed for calculating supplier heterogeneity, hardware heterogeneity, software heterogeneity, and vulnerability overlap heterogeneity, such as... Figure 3 As shown. Specifically includes:

[0045] The supplier heterogeneity is determined based on the proportion of the largest number of nodes from the same supplier in the total number of nodes in the trusted set.

[0046] Traverse any hardware in the key hardware type as the first type of hardware, determine the heterogeneity of the first type of hardware based on the proportion of the maximum number of nodes of the same model in the first type of hardware to the total number of nodes in the trusted set, and sum the heterogeneity of the first type of hardware according to the specified hardware type to obtain the hardware heterogeneity.

[0047] The software heterogeneity is obtained by the proportion of the number of nodes of each type of software combination in the total number of nodes of the trusted set;

[0048] The degree of vulnerability overlap and heterogeneity is determined by the ratio of the sum of the number of overlapping public vulnerabilities between any two nodes in the trusted set to the square of the total number of node pairs in the trusted set.

[0049] This embodiment employs a preferred method for calculating heterogeneity, including:

[0050] ;

[0051] ;

[0052] ;

[0053] ;

[0054] in, For the first The number of nodes of similar suppliers The number of trusted aggregate nodes can avoid dominance by a single vendor, such as hour . This refers to the number of key hardware types (such as flight control chips / communication modules / sensors). For the first The maximum number of nodes of the same model in similar hardware. This is the normalization coefficient. The number of software stack composite types, For the first The proportion of nodes in the software combination, the more uniform the software combination, the higher the entropy value (maximum value is 1). The number of overlapping public vulnerabilities between any two nodes is represented, and the CVE vulnerability database is used in this embodiment, The total number of node pairs, the lower the total overlap rate of the cluster, The closer to 1.

[0055] Embodiment 3:

[0056] Based on the network attack defense method described in Embodiment 1, a simple method is used to determine the trusted nodes and ordinary nodes in the UAV formation according to the heterogeneity index, and the heterogeneity index maximization is used as the optimization target to select the trusted nodes. This embodiment proposes a more optimal trusted set deployment scheme, which includes: taking the maximum heterogeneity index as the main optimization condition, and the minimum communication cost of trusted nodes as the secondary optimization condition, to determine the positions of trusted nodes in the entire UAV group and the ordinary nodes under their jurisdiction.

[0057] In this embodiment, the trusted node set is determined according to the heterogeneity index calculation method, historical experience value ≥0.7 or actual ability of the UAV group. The trusted set UAV group should include at least 4 UAVs. When deploying nodes, the communication capabilities of different nodes are fully considered to determine the positions of trusted nodes in the entire UAV group and the ordinary UAVs under their jurisdiction.

[0058] The constraint conditions include communication range constraints. In this embodiment, the constraint conditions are formation configuration constraints, communication constraints, and task load constraints.

[0059] The communication cost of the trusted node includes communication overhead, energy consumption overhead, and calculation overhead. A specific calculation method is as follows:

[0060]

[0061] Wherein, the communication overhead is , The Euclidean distance between nodes and , The available bandwidth (Mbps) between nodes , The power consumption (W) of node , The battery capacity (Wh) of node , The task load (MOPS) of node , The computing power (MOPS) of node ; The weight coefficient is taken as in this embodiment. The position coordinates of the node.

[0062] In the constraint condition, The configuration characteristic function, The angle range; The set of trusted nodes, which represents the communication constraint between two trusted nodes. The node The set of ordinary nodes under jurisdiction, The signal-to-noise ratio threshold, which represents the communication constraint of trusted nodes on ordinary nodes; The set of nodes responsible for the task , which represents the task load constraint, such as the optical resolution requirement of the imaging reconnaissance task .

[0063] The optimization method determines the position of the trusted node in the entire UAV group and the ordinary nodes under their jurisdiction. Classic optimization methods such as greedy algorithm, genetic algorithm, or particle swarm can be selected. The optimization objective is designed according to the primary and secondary optimization conditions; the constraint condition of optimization calculation is the formation configuration constraint, communication constraint, and task load constraint.

[0064] The following is a specific implementation scheme of the greedy algorithm:

[0065] The greedy selection criterion of the greedy algorithm is designed according to the primary and secondary optimization conditions; the constraint condition of the greedy algorithm includes the communication range constraint.

[0066] S1: Algorithm initialization.

[0067] Let the set of all nodes in the UAV formation be , where is the total number of nodes. Initialize the set of trusted nodes , the candidate node set , and the unassigned ordinary node set .

[0068] S2: Greedy selection of trusted nodes.

[0069] For each node in the candidate node set , calculate the heterogeneity gain and the communication cost increment after joining the set as a trusted node:

[0070] ;

[0071] ;

[0072] where is the heterogeneity index, For communication cost, the calculation method has been given above.

[0073] The greedy selection criterion is constructed to maximize the heterogeneity index as the primary optimization condition and minimize the communication cost as the secondary optimization condition:

[0074] ;

[0075] wherein, is the newly added trusted node that meets the conditions, is the trade-off coefficient, which is taken as in the embodiment, and indicates that the node with lower communication cost is preferred when the heterogeneity index is the same.

[0076] The node is added to the trusted node set , and is removed from the candidate node set :

[0077] , ;

[0078] S3: Iterative selection and termination condition.

[0079] Step S2 is repeated until a sufficient number of trusted nodes have been selected.

[0080] S4: Normal node allocation.

[0081] After the trusted node set is determined, the unallocated normal nodes are allocated to each trusted node jurisdiction. For each normal node , the trusted node closest to it and meeting the communication constraint is selected:

[0082] ;

[0083] wherein and are the position coordinates of the normal node and the trusted node , and are the minimum and maximum communication distances, is the signal-to-noise ratio threshold.

[0084] The set of normal nodes under the jurisdiction of each trusted node is defined as:

[0085] ;

[0086] S5: Algorithm output.

[0087] The final output is the trusted node set , a set of normal nodes under jurisdiction of each trusted node .

[0088] Embodiment 4

[0089] Based on the network attack defense method described in Embodiment 1, the method for optimizing the judgment of the attack state of the normal node by the trusted node includes: calculating the residual error of the actual trajectory and the predicted trajectory of the normal node according to the motion trajectory of the normal node; calculating the information entropy in the period according to the communication traffic in the period of the normal node; if the residual error is greater than the set cumulative residual error threshold and the information entropy change of the adjacent period is greater than the set information entropy monitoring threshold, it is judged as an attack state.

[0090] The trusted node judges the attack state of the normal unmanned aerial vehicle by monitoring the communication traffic and motion trajectory of the normal unmanned aerial vehicle. In the motion trajectory layer, based on the historical behavior baseline of the normal node, the residual error of the actual trajectory and the predicted trajectory is calculated , if , it is judged as abnormal, the cumulative residual error threshold is set to 10 . In the communication traffic layer, the information entropy change is monitored, if the information entropy of the adjacent period suddenly changes , it is judged as abnormal, the information entropy monitoring threshold is set. When the communication traffic and motion trajectory are both abnormal, it is judged as an attack state.

[0091] Embodiment 5

[0092] Based on the network attack defense method described in Embodiment 1, a response mode for dealing with the attack state of the normal node is further proposed. For the abnormal normal node judged as an attack state, a nearby standby node is called to replace the abnormal normal node; replacing the abnormal normal node includes: calling the standby node to enter the working position of the abnormal normal node; the abnormal normal node suspends the execution of the task and recovers the abnormal disturbance through the automatic repair program; in the case that the disturbance of the abnormal normal node is not recoverable and the control system is normal, passive tracking flight is performed based on the relative navigation method; in the case that the disturbance of the abnormal normal node is not recoverable and the control system is abnormal, the abnormal normal node is excluded from the feasible set.

[0093] The above disturbance elimination method is inspired by the protection of injured, weak individuals in natural clusters and the idea that diseased and necrotic cells are phagocytosed and discarded by the immune system, and designs a biological heuristic-based unmanned aerial vehicle formation topology reconstruction method.

[0094] As Figure 4 shown, if the disturbance is recoverable, a nearby node is found to replace the disturbed node, the replaced node suspends the execution of the task, and the disturbance is self-relaxed through the system automatic repair program.

[0095] If the disturbance cannot be recovered, but the flight control system is normal, passive tracking flight based on relative navigation technology is carried out with the help of the cluster UAV to block the disturbance propagation.

[0096] If the disturbance cannot be recovered and the autonomous control ability is lost, the malicious node is set as a black list, access permission is refused, the cluster formation is gradually discharged and discarded, the elimination of uncertain disturbance is realized, and the overall safety of the UAV formation is ensured.

[0097] Embodiment 6:

[0098] Based on the network attack defense method described in Embodiment 1, a monitoring mechanism for trusted nodes is further proposed: the trusted nodes supervise each other's communication traffic and motion trajectories, and a multi-mode voting mechanism is used to judge the attack state of the trusted nodes, the multi-mode voting mechanism includes: super-half voting algorithm; the multi-mode voting mechanism also includes: when there are pair-wise mutually exclusive accusations, the node with higher credibility is retained and the current accusation is recorded, and in the next round of voting, it is judged whether the current accusation is established or not, and the credibility is determined according to the historical attack state.

[0099] The trusted nodes exchange the link data monitored by each other within a fixed period, and the state synchronization is realized through timestamp alignment. Based on the aligned data, double-layer consistency analysis at the behavior level and the traffic level is performed, and the specific calculation method is consistent with the method for judging the attack state in Embodiment 5. The multi-mode voting mechanism is used for abnormality judgment, each trusted node broadcasts an abnormality mark to other nodes, such as "A reports B abnormality". If a trusted node is determined to be abnormal by more than half of the trusted nodes (≥ Q / 2 + 1, Q is the total number of nodes), it is determined to be in an attack state. When there are pair-wise mutually exclusive accusations (such as A and B accusing each other of abnormality), the node with higher historical credibility is retained, but if the node is still accused of abnormality in the next round of detection, it is determined to be in an attack state.

[0100] Embodiment 7:

[0101] Based on the network attack defense method described in Embodiment 6, a response mode for dealing with the attack state of the trusted node is further proposed. For the abnormal trusted node determined to be in an attack state, a nearby backup trusted node is called to replace the abnormal trusted node, and the replacement of the abnormal trusted node includes: calling the backup trusted node to enter the working position of the abnormal trusted node; the abnormal trusted node suspends the execution of the task and goes offline for cleaning; the offline cleaning includes: the abnormal trusted node enters the backup node group; the abnormal trusted node is initialized and reset, the system of the abnormal trusted node is switched to the backup security system, and the authentication key of the abnormal trusted node is updated; after the cleaning operation is completed, the abnormal trusted node is set to a replaceable state.

[0102] As Figure 5As shown, after finding the abnormal trusted node, the standby trusted node is replaced to replace, and the abnormal trusted node is offline cleaning: calling the standby trusted node to enter the abnormal node working position to replace the original abnormal node working; the abnormal node enters the standby node group, initializes and resets, switches the standby security system, and updates the authentication new key to block the risk of historical key leakage; after completing the cleaning operation, the node is set to a replaceable state.

[0103] The standby trusted node is a standby machine reserved when the unmanned aerial vehicle group is initially constructed. When the unmanned aerial vehicle group is constructed, ordinary unmanned aerial vehicle nodes and trusted unmanned aerial vehicle nodes are divided, the trusted unmanned aerial vehicle nodes do not all go online at once, but include a running set a and a standby set b, and the unmanned aerial vehicle group is m, m=a+b.

[0104] In the standby set of unmanned aerial vehicles, since they do not participate in specific task execution, the attack surface is not exposed, and after the trusted node a1 in the running set a is attacked, the trusted node will be selected from the standby set b to replace, and a1 enters the standby set to be offline cleaned to attempt to recover to a normal state for next time calling.

[0105] Embodiment 8:

[0106] Based on the network attack defense method described in Embodiment 6, without abnormal alarm, a preset number of trusted nodes are replaced every preset time; the preset number of trusted nodes include trusted nodes with a historical attack state of an attacked state.

[0107] If no abnormal trusted node is found within a certain time, part of the trusted nodes are still replaced and cleaned to maintain the dynamics of the system and form the uncertainty effect on the attacker, so that the unmanned aerial vehicle group presents overall dynamics. In this embodiment, the specific periodic active rotation method is: even if there is no abnormal alarm, 25% of the trusted nodes are replaced every 10 minutes, and the nodes that have been accused of being abnormal are preferentially replaced, so that the attacker cannot predict the position and action period of the key nodes, and cannot continuously penetrate the key nodes. According to the rules, the trusted nodes are dynamically rotated, and the trusted nodes are replaced in real time, so that the attacker cannot predict the position and action period of the key nodes, and cannot continuously penetrate the key nodes. This innovation makes the entire system have the characteristics of continuous change, so that external and internal attacks cannot cause real damage, and the threat is removed in the disturbance phase.

[0108] The present application organically integrates the three security defense elements of dynamics, heterogeneity and redundancy, as shown in Figure 6 As shown, the basic trusted nodes and abnormal nodes are constructed in the unmanned aerial vehicle formation, the whole system has the characteristics of continuous change through the dynamic scheduling of the trusted nodes. Based on the multi-dimensional threat perception of the consensus mechanism, the regional trigger network security alarm is triggered. Based on the biological inspiration, the unmanned aerial vehicle formation disturbance elimination makes the threat be removed only in the disturbance phase.

[0109] By organically integrating the three security defense elements of dynamic, heterogeneous, and redundancy, under the condition that unknown vulnerabilities cannot be thoroughly checked, the full-cycle protection chain of integrated inhibition of dynamic defense deception + internal and external attacks is first realized, the risk of cascading failure caused by the loss of internal nodes of the UAV formation is fundamentally reduced, and the control efficiency and task continuity of the formation are maintained.

[0110] Embodiment 9:

[0111] In one embodiment, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned when executing the computer program.

[0112] In one embodiment, a computer readable storage medium is provided, having stored thereon a computer program, wherein the computer program is executed by a processor to implement the above-mentioned.

[0113] In one embodiment, a computer program product is provided, comprising computer programs / instructions, which are executed by a processor to implement the above-mentioned.

[0114] Those skilled in the art will understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.

[0115] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The function specified in one flow or multiple flows and / or blocks Figure 1 The device that implements the function specified in one block or multiple blocks.

[0116] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the flow Figure 1 The functions of a flow or multiple flows and / or a block or multiple blocks in accordance with the present disclosure can be implemented with hardware, software, or combinations of hardware and software. Any Figure 1 The functions of a flow or multiple flows and / or a block or multiple blocks in accordance with the present disclosure can be implemented with hardware, software, or combinations of hardware and software. Any

[0117] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow Figure 1 The functions of a flow or multiple flows and / or a block or multiple blocks in accordance with the present disclosure can be implemented with hardware, software, or combinations of hardware and software. Any Figure 1 The functions of a flow or multiple flows and / or a block or multiple blocks in accordance with the present disclosure can be implemented with hardware, software, or combinations of hardware and software. Any

[0118] Embodiment 10:

[0119] The network attack defense system described in the present application comprises a UAV formation and a cooperative controller for formation control, and the cooperative controller executes the network attack defense method described in any one of the above embodiments.

Claims

1. A method for defending against network attacks, characterized in that, include: Trusted nodes and ordinary nodes in the trusted set are determined based on the heterogeneity index. Trusted nodes are used to receive and send signals to ordinary nodes when communicating between them. The heterogeneity index is determined based on at least one of vendor heterogeneity, hardware heterogeneity, software heterogeneity, and vulnerability overlap heterogeneity. By monitoring the communication traffic and movement trajectory of any node in the trusted set through trusted nodes, the attack status of any node can be determined. Network attack defense is performed based on the attack status of any of the nodes.

2. The network attack defense method according to claim 1, characterized in that, The method further includes: The supplier heterogeneity is determined based on the proportion of the largest number of nodes from the same supplier in the total number of nodes in the trusted set. Traverse any hardware in the key hardware type as the first type of hardware, determine the heterogeneity of the first type of hardware based on the proportion of the maximum number of nodes of the same model in the first type of hardware to the total number of nodes in the trusted set, and sum the heterogeneity of the first type of hardware according to the specified hardware type to obtain the hardware heterogeneity. The software heterogeneity is obtained by the proportion of the number of nodes of each type of software combination in the total number of nodes of the trusted set; The degree of vulnerability overlap and heterogeneity is determined by the ratio of the sum of the number of overlapping public vulnerabilities between any two nodes in the trusted set to the square of the total number of node pairs in the trusted set.

3. The network attack defense method according to claim 1, characterized in that: The method of determining trusted nodes and ordinary nodes in the trusted set based on the heterogeneity index includes: taking the maximum heterogeneity index as the primary optimization condition and the minimum communication cost of trusted nodes as the secondary optimization condition, determining the position of trusted nodes in the entire unmanned vehicle group and the ordinary nodes under their jurisdiction.

4. The network attack defense method according to claim 3, characterized in that: The communication cost of the trusted node includes communication overhead, energy consumption overhead, and computing overhead.

5. The network attack defense method according to claim 3, characterized in that: A greedy algorithm is used to determine the location of the trusted nodes and the ordinary nodes under their jurisdiction. The greedy selection criteria of the greedy algorithm are designed based on the primary optimization conditions and the secondary optimization conditions. The constraints of the greedy algorithm include communication range constraints.

6. The network attack defense method according to claim 1, characterized in that: Determining the attacked state of a normal node includes: calculating the residual between the actual trajectory and the predicted trajectory of the normal node based on its movement trajectory; calculating the information entropy within a period based on the communication traffic of the normal node within a period; and determining the attacked state if the residual is greater than a set cumulative residual threshold and the change in information entropy in adjacent periods is greater than a set information entropy monitoring threshold.

7. The network attack defense method according to claim 1, characterized in that: For abnormal ordinary nodes that are determined to be under attack, call nearby backup nodes to replace the abnormal ordinary nodes; Replacing an abnormal normal node includes: calling a backup node to enter the working position of the abnormal normal node; the abnormal normal node suspends task execution and recovers from abnormal disturbances through an automatic repair program.

8. The network attack defense method according to claim 7, characterized in that: When the disturbance of the abnormal ordinary node is irreversible and the control system is normal, passive tracking flight is performed based on the relative navigation method; when the disturbance of the abnormal ordinary node is irreversible and the control system is malfunctioning, the abnormal ordinary node is excluded from the feasible set.

9. The network attack defense method according to claim 1, characterized in that: Determining the attack status of a trusted node includes: using a multi-mode voting mechanism to determine the attack status of a trusted node; the multi-mode voting mechanism includes: a majority voting algorithm; the multi-mode voting mechanism also includes: when there are paired mutually exclusive accusations, retaining the node with higher credibility and recording the current accusation, and prioritizing the determination of whether the current accusation is valid in the next round of voting, wherein the credibility is determined based on the historical attack status.

10. The network attack defense method according to claim 9, characterized in that: For abnormal trusted nodes identified as being under attack, nearby backup trusted nodes are invoked to replace the abnormal trusted nodes. Replacing an abnormal trusted node includes: invoking a backup trusted node to enter the working location of the abnormal trusted node; the abnormal trusted node suspends task execution and goes offline for cleaning; the offline cleaning includes: the abnormal trusted node enters the backup node group; initializes and resets the abnormal trusted node, switches the abnormal trusted node system to the backup security system, and updates the authentication key of the abnormal trusted node; after the cleaning operation is completed, the abnormal trusted node is set to a substitute state.

11. The network attack defense method according to claim 9, characterized in that: In the absence of any abnormal alarms, a preset number of trusted nodes are replaced at preset time intervals; the preset number of trusted nodes includes trusted nodes whose historical attack status was "attacked".

12. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the network attack defense method according to any one of claims 1 to 11.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the network attack defense method according to any one of claims 1 to 11.

14. A computer program product comprising a computer program and / or instructions, characterized in that, When the computer program and / or instructions are executed by the processor, they implement the network attack defense method according to any one of claims 1 to 11.

15. A network attack defense system, comprising a drone formation and a cooperative controller for formation control, characterized in that: The collaborative controller executes the network attack defense method as described in any one of claims 1 to 11.