Anti-killer chain construction method based on service-oriented killer chain
By employing a service-oriented kill chain construction method, the problem of insufficient adaptability of kill chains in complex environments in existing technologies is solved, enabling rapid reconfiguration and sustained strike capabilities under conditions of target mobility and equipment damage.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-25
- Publication Date
- 2026-03-27
AI Technical Summary
Existing kill chain construction methods are not adaptable enough to complex and dynamic environments, making it difficult to cope with target mobility and equipment damage, resulting in a decrease or interruption of strike capability.
The anti-kill chain construction method based on service-oriented kill chain predicts the path by acquiring the target's real-time status information, constructs a probabilistic cloud model, selects suitable service objects, maps them to kill chain links, and completes the link under capability and space constraints to generate an executable kill chain.
It enables adaptive reconstruction of the kill chain under dynamic target and resource changes, improving the efficiency of chain construction and the flexibility and sustained strike capability of the combat system.
Smart Images

Figure CN121744719A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of kill chain construction, and particularly relates to a service-based anti-kill chain construction method. BACKGROUND
[0002] With the development of informatization and systematization of combat modes, the kill chain gradually evolves from a fixed process with a single equipment as the core to a complex link structure with multi-platform and multi-node cooperation. In the prior art, the construction of the kill chain for a target attack task usually depends on a pre-planned combat process or a link combination method based on static resource configuration, that is, before the task starts, a relatively fixed kill chain execution path is determined according to a given target type and available equipment. This kind of method can play a certain role in the case of stable target state and complete combat resources, but its adaptability is obviously limited in a complex dynamic environment.
[0003] On the one hand, the existing kill chain construction method generally depends on the direct binding of specific equipment, and lacks abstraction and decoupling of equipment capabilities. When part of the combat equipment is damaged, lost or temporarily unavailable, the original kill chain often cannot continue to execute, and the system is difficult to generate alternative links in time, resulting in a decline in overall attack capability, and even interruption of the task. On the other hand, the existing technology usually takes a static space or a fixed area as the basis in the process of constructing the kill chain, and it is difficult to effectively respond to the situation of target continuous maneuvering and frequent changes in trajectory. The kill chain lags behind in responding to changes in the target position, and the attack effect is unstable.
[0004] To solve the above problems, the present application designs a service-based anti-kill chain construction method. SUMMARY
[0005] The technical problem to be solved by the present application is to provide a service-based anti-kill chain construction method to solve the problems of the prior art. The method performs target motion prediction based on real-time state information of a target to be attacked, obtains a predicted path of the target within a preset time, and constructs a probability cloud model in a three-dimensional tactical space. After being corrected by a tactical environment constraint, a target influence area is determined. On this basis, candidate service objects are selected from a service resource library according to spatial, temporal and capability constraints, and the candidate service objects are mapped to each link of the kill chain in combination with a service-based kill chain template corresponding to the target. When there is a capability gap in the template, a complete sequence satisfying link continuity is generated through the introduction of a gap segment identification, local constraint derivation, index tree retrieval and completion process search, so as to construct an executable anti-kill chain. The method can quickly reconstruct the kill chain under the conditions of target maneuvering, equipment damage or resource replacement, and improve the flexibility and sustained attack capability of the combat system.
[0006] To achieve the above purpose, the present application provides the following technical solutions:
[0007] A method for constructing an anti-kill chain based on a service-type kill chain, applied to a service-type kill chain anti-kill chain construction system, wherein a service resource library and a kill chain template library are configured in the anti-kill chain construction system, the kill chain template library corresponds to a plurality of service-type kill chain templates, and the method comprises:
[0008] obtaining current state information of a target to be attacked, performing target motion prediction according to the current state information, and obtaining a target prediction path;
[0009] spatially expanding the target prediction path to obtain an influence area, and screening candidate service objects from the service resource library that are adapted to the time-space constraints and capability constraints of the influence area;
[0010] mapping the candidate service objects to each kill chain link of the corresponding service-type kill chain template according to the service-type kill chain template corresponding to the target to be attacked, to determine a current kill chain.
[0011] The service resource library comprises a plurality of service objects, and each service object comprises at least one of a service type, a capability parameter, a time parameter, a spatial coverage range and a maneuvering characteristic, wherein the construction step of the service object comprises:
[0012] obtaining equipment data of each combat equipment in a combat system, and performing function abstraction and service modeling for the combat function of each combat equipment, to generate a service object representing the combat function, wherein the combat function comprises reconnaissance, tracking, command control, firepower attack and effect evaluation.
[0013] The current state information comprises at least one of a target current position, a track, a speed, a heading, a maneuvering mode and a threat level, and target motion prediction is performed according to the current state information, which comprises:
[0014] based on the target current position and the track, predicting the target position by kinematics to obtain a target prediction trajectory point set;
[0015] based on the speed, the heading and the maneuvering mode, determining a target potential motion mode, and combining a preset threat level to perform credibility weight distribution on each target prediction trajectory point;
[0016] combining the target prediction trajectory point set and the corresponding credibility weight to generate at least one target prediction path, wherein the target prediction path is used to represent an activity area of the target within a preset time.
[0017] spatially expanding the target prediction path to obtain an influence area, which comprises:
[0018] construct a target position probability cloud model within a preset time based on each target prediction trajectory point in the target prediction path and the corresponding confidence weight, the target position probability cloud model being used to represent a probability distribution of the target appearing at a spatial discrete unit, wherein the spatial discrete unit represents a grid unit generated after the tactical space is grid processed based on a preset resolution;
[0019] obtain tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information;
[0020] perform constraint fusion processing on the tactical constraint set and the target position probability cloud model, attenuate the target appearance probability of the spatial discrete unit located in the no-fly zone and the physically inaccessible area, and enhance the target appearance probability of the spatial discrete unit located in the preset flight path and the terrain concealed channel to obtain a modified model;
[0021] perform cumulative probability operation on the modified model to determine a minimum spatial region set in which the cumulative target appearance probability is greater than or equal to a preset confidence threshold within the preset time, wherein the minimum spatial region set can be obtained by clustering the spatial discrete units;
[0022] determine the spatial envelope corresponding to the minimum spatial region set as the influence area.
[0023] perform cumulative probability operation on the modified model to determine a minimum spatial region set in which the cumulative target appearance probability is greater than or equal to a preset confidence threshold within the preset time, comprising:
[0024] cumulatively sum the target appearance probability of each spatial discrete unit in the modified model according to time sequence to obtain a cumulative target appearance probability value of each spatial discrete unit;
[0025] select, based on the cumulative target appearance probability value and the confidence threshold, a spatial discrete unit in which the cumulative target appearance probability value is greater than or equal to the confidence threshold as a target active unit set;
[0026] perform spatial clustering on the target active unit set to obtain a candidate region, and perform geometric regularization on the candidate region through morphological dilation to obtain the minimum spatial region set.
[0027] select, from the service resource library, a candidate service object that is adapted to the spatiotemporal constraint and the capability constraint of the influence area, comprising:
[0028] based on the spatial coverage, available time window and service type information of each service object in the service repository, the service objects are hierarchically organized to construct a service index tree, wherein the service index tree comprises: first layer nodes divided by tactical space regions; second layer nodes under each first layer node divided by available time windows; third layer nodes under each second layer nodes divided by service type information;
[0029] According to the influence area, the service index tree is traversed from top to bottom, and the first layer nodes and their sub-trees which have no spatial intersection with the influence area are pruned;
[0030] According to the kill chain execution time window, the second layer nodes and their sub-trees which do not meet the preset time are pruned;
[0031] According to the ability requirement of the corresponding link in the service type kill chain template, the third layer nodes and their leaf nodes which do not meet the ability constraint are pruned;
[0032] All the remaining leaf nodes corresponding to the service objects in the pruned service index tree are summarized to determine the candidate service objects.
[0033] Map the candidate service objects to each kill chain link of the corresponding service type kill chain template to determine the current kill chain, comprising:
[0034] According to the mapping result, judge whether the candidate service objects completely cover the corresponding service type kill chain template;
[0035] If yes, process the mapping result through redundancy optimization logic, select the target service type kill chain, and determine the service object sequence corresponding to the target service type kill chain as the current kill chain;
[0036] If not, reorganize the mapping result through link completion logic to obtain the current kill chain, wherein the reorganization includes: for the kill chain links that are not covered, retrieving supplementary service objects from the service index tree, and adjusting the sequence of candidate service objects and the supplementary service objects to generate an alternative service type kill chain, and determining the service object sequence corresponding to the alternative service type kill chain as the current kill chain.
[0037] The redundancy optimization logic comprises:
[0038] For multiple candidate service objects mapped to the same kill chain link, calculate the performance score according to the preset performance evaluation model, wherein the performance evaluation model generates performance score based on one or more parameters of detection accuracy, response time, combat radius, reliability and resource consumption;
[0039] According to the performance score, the candidate service objects are ranked, the candidate service object with the highest performance score is taken as the service object corresponding to the corresponding kill chain link, and the remaining candidate service objects are taken as alternative objects;
[0040] The service object sequence formed by the service objects is subjected to link consistency verification, if the verification is passed, the service object sequence is confirmed as the current kill chain, if the verification is not passed, local adjustment is carried out based on the alternative objects until the link consistency verification is passed.
[0041] The link completion logic comprises:
[0042] The kill chain links not covered by the candidate service objects in the mapping result are identified, and a plurality of continuous kill chain links not covered are merged into a gap segment, to generate one or more gap segments, wherein the gap segment further comprises a single kill chain link;
[0043] For each gap segment, the assigned service objects corresponding to the kill chain links located before and after the gap segment are obtained, based on the combat start and end time and the spatial coverage range of the assigned service objects, in combination with the influence area, the completion time constraint window and the completion spatial constraint window for the gap segment are determined;
[0044] In the service index tree, the first layer node and its subtree having a spatial intersection with the completion spatial constraint window are searched, to obtain a set of supplementary service objects facing the gap segment;
[0045] The completion search tree is constructed with the kill chain links in the gap segment as levels, and the set of supplementary service objects is state-expanded according to the kill chain link order, wherein in the state expansion process, the search path is pruned according to the time continuity constraint, the spatial connectivity constraint and the communication link reachability constraint, and each search path of the current layer is evaluated, only the search paths with the top pre-set number of comprehensive scores are reserved as the starting points for the next layer expansion;
[0046] The service object sequence with the highest comprehensive performance score is selected from the completion search tree as the completion sequence of the gap segment, and the completion sequence is spliced with the selected service object sequences before and after the gap segment, to generate the corresponding completion link;
[0047] The completion links corresponding to all gap segments are combined with the service object sequences corresponding to the kill chain links that have been covered, to generate an alternative service type kill chain.
[0048] The state expansion of the set of supplementary service objects according to the kill chain link order comprises:
[0049] In each layer of the completed search tree, the corresponding kill chain link is taken as a current expansion target link, service objects matching the kill chain link are filtered from the supplementary service object set, and each filtered service object is taken as a candidate expansion node to generate a corresponding expansion state;
[0050] For each expansion state, legality is determined according to time continuity constraints, space connectivity constraints and communication link reachability constraints between the current expansion target link and the corresponding service object of the adjacent determined kill chain link, and a pruning operation is performed on the expansion state that does not satisfy any constraint;
[0051] For the expansion state determined by the legality, a comprehensive performance score is calculated according to a comprehensive score function constructed according to the target performance weight and the resource consumption weight, and when the number of expansion states determined by the legality exceeds a preset number threshold, the expansion state is limited and filtered based on the comprehensive performance score.
[0052] Compared with the prior art, the beneficial effects of the present application are:
[0053] The present application realizes the adaptive reconstruction of the kill chain under the condition of dynamic target and resource changes by serviceizing the combat equipment capability and introducing the target influence area driven kill chain construction mechanism. The kill chain link can be screened and completed as needed, the link construction efficiency and continuity are improved, the flexibility and sustained attack capability of the system operation are enhanced, and the present application is suitable for complex and uncertain combat environments. BRIEF DESCRIPTION OF DRAWINGS
[0054] Other features, objects and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments made with reference to the accompanying drawings:
[0055] Figure 1 An exemplary application scenario provided for the embodiments of the present application;
[0056] Figure 2 A module schematic diagram of a processor provided for the embodiments of the present application;
[0057] Figure 3 A flowchart of a kill chain construction method based on a service-type kill chain provided for the embodiments of the present application;
[0058] Figure 4 A structure schematic diagram of a service index tree provided for the embodiments of the present application;
[0059] Figure 5 A service index tree pruning principle schematic diagram provided for the embodiments of the present application;
[0060] Figure 6 A structure schematic diagram of a gap segment provided for the embodiments of the present application. DETAILED DESCRIPTION
[0061] The technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application.
[0062] Reference to“an embodiment” herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The appearances of the phrase that the phrase in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive of other embodiments. It is apparent that those skilled in the art can explicitly or implicitly understand that the embodiments described herein can be combined with other embodiments.
[0063] The present application is applicable to a weapon system environment facing a multi-domain cooperative combat system and organized in a service-oriented manner. In particular, the present application is applicable to an application scenario of dynamically maintaining and reconstructing a friendly damage chain and implementing targeted destruction of a target damage chain under the condition that targets are highly mobile, combat platform types are various, links are easily disturbed and damaged. In such a scenario, multi-source equipment such as air-based, space-based, sea-based, and ground-based equipment jointly participate in the discovery, tracking, and attack of the same target. The damage chain gradually evolves from a traditional fixed platform-fixed process to a capability service-dynamic arrangement. However, in the actual operation process, it is inevitable to be affected by factors such as platform loss, communication interruption, and target penetration and mobility, and it is difficult to maintain the integrity of the damage chain for a long time.
[0064] In the example technology, a combat command and control system usually pre-plans several typical damage chains, statically groups radars, optical-electrical reconnaissance equipment, command nodes, and firepower units according to the process, and selects an appropriate damage chain from the pre-plan library according to the threat level and position of the target to call in the war. Some schemes also try to introduce the service-oriented idea, abstract part of the combat functions as capability modules, and combine these modules through centralized or rule-driven methods. However, such methods usually assume that the combat unit structure is stable, the communication link is reliable, and the target mobility mode is predictable. When facing the anti-damage chain actions of the target party and the sudden failure of part of the equipment of the friendly party, it is difficult to assess the availability of the remaining capabilities in time, and it is even more difficult to quickly and reasonably dynamically reconstruct the damage chain under complex space-time constraints.
[0065] On the one hand, the combat resources involved in the killing chain show the characteristics of various types, scattered deployment, and significant differences in capabilities. Simple reliance on manual experience or static rules for link selection makes it difficult to exhaust all feasible combinations within the limited decision-making time. On the other hand, the target is usually in a state of continuous maneuvering. The traditional link design method based on fixed combat area or static fire coverage is difficult to accurately cover the spatial path that the target may pass through in the future. When the target deviates from the predetermined area or conducts evasive maneuvers in a complex electromagnetic and spatial environment, the original killing chain is prone to break in the middle. In addition, how to identify the key links and vulnerable nodes of the target's killing chain in the service level, so as to form a targeted chain-breaking scheme, also lacks a unified modeling framework and executable algorithm approach.
[0066] In a typical application scenario, the method described in the application is used to implement continuous attack on high-speed maneuvering high-value targets in a large-scale multi-domain joint combat environment. The target party changes the route frequently, uses terrain and electromagnetic environment to hide its own traces, and at the same time suppresses the reconnaissance and communication nodes of the own side, so that the traditional killing chain based on fixed preplan is difficult to maintain integrity. In another typical application scenario, the method described in the application can be used to construct an equivalent model of the target's service-type killing chain, identify its key dependencies in target search, target indication, and fire delivery based on the service perspective, and generate an anti-killing chain scheme accordingly, which is used to guide the priority attack of the own command chain or fire chain.
[0067] It should be noted that the anti-killing chain construction method based on the service-type killing chain proposed in the application is not limited to a specific weapon system or fixed command structure, but is aimed at a generalized combat scenario with multi-source combat capability service description, target state availability, and combat environment with obvious space-time constraint characteristics.
[0068] It can be understood that the method of the application is proposed based on the abstract understanding of the essential characteristics of the killing chain:
[0069] The kill chain is not a simple equipment list, but a chain of capabilities in a certain logical order formed by a series of combat services meeting timing constraints, space constraints and capability constraints. Once the functions of various combat equipment such as reconnaissance, tracking, command and control, firepower attack and effect evaluation are abstracted into service objects that can be registered, discovered and arranged, and the process is described in a standardized manner by a service-type kill chain template, the core problem of "where, when and with what capability to attack the target" can be automatically filtered and reorganized around the target prediction path and its influence area to form a kill chain that meets the current combat requirements. When the original kill chain is interrupted due to node failure or target escape, the application identifies and partially completes the missing link, searches the service index and optimizes the search tree according to the space-time window and capability demand, and quickly generates an alternative link under the premise of limiting the computational complexity, thereby completing the countermeasures and recovery of the original kill chain in the service layer.
[0070] It should be emphasized that the anti-kill chain construction is not a global search and reorganization of any resource or any link, but is centered on the dynamic activity trend of the target to be attacked, and the influence area formed by the target prediction path and its spatial expansion is the constraint basis for the entire link reconstruction process. The influence area reflects the space-time range that the target may appear within a preset time, and is a key criterion for measuring whether the kill chain can effectively attack the target. Only when a service object can effectively attack the influence area in terms of capability parameters, space-time coverage and combat accessibility, can it be a candidate link of the kill chain.
[0071] In other words, the application determines the space window and time window of the executable combat action based on the target influence area, and then constrains, filters, constructs and completes the service resources. When the existing kill chain is interrupted due to target maneuvering beyond the original scope, key node damage or link continuity being destroyed, the adaptive deviation between the influence area and the current link can be identified first, then the service objects meeting the regional constraints are re-searched within the limited influence area, and the missing link is completed or replaced based on the service-type kill chain template, thereby generating an anti-kill chain facing the current situation of the target.
[0072] Reference Figure 1 , Figure 1 An exemplary application scenario is provided for the embodiments of the application.
[0073] In a typical multi-domain cooperative combat environment, the anti-kill chain construction system is usually deployed in a command and control node or a combat unit with edge computing capability, for generating, adjusting and reconstructing the kill chain in a highly dynamic and task-driven scenario. The system can simultaneously receive state information from multiple combat equipment, sensor platforms and external intelligence sources, and abstractly manage the combat capabilities of these equipment in a service-oriented manner.
[0074] like Figure 1 As shown, the system internally includes a service resource library and a kill chain template library. The service resource library stores various types of combat service objects after capability abstraction, while the kill chain template library stores service-oriented kill chain templates corresponding to different combat missions or target characteristics. Based on the current mission requirements, target status, and available service objects, the processor generates, filters, completes, and reconstructs the service-oriented kill chain, outputs the final execution plan of the current kill chain or counter-kill chain, and transmits it to the controller for controlled strike.
[0075] In a specific implementation not shown in the figure, the target to be attacked is in a continuous maneuvering state, and its position, trajectory, speed, and maneuvering mode are continuously updated by reconnaissance resources and input to the processor. The processor predicts the future movement trend of the target based on its state and determines the spatial activity area that the target may pass through within a preset time window as the area of influence. Subsequently, the processor filters candidate service objects that can act on the area of influence from the service resource library, and maps and arranges these candidate service objects into the current kill chain according to the process structure in the kill chain template library.
[0076] refer to Figure 2 , Figure 2 A schematic diagram of a processor module provided in an embodiment of this application.
[0077] Figure 2 The processor shown includes:
[0078] The path prediction module receives the current state information of the target to be attacked and calculates the target's future movement trend based on the state information. The path prediction module analyzes the target's current position, speed, heading, and maneuvering mode to generate a predicted path for the target. It can further combine this with confidence weights to form multiple possible trajectories of the target within a preset time period, reflecting the target's maneuvering uncertainty in the future time domain.
[0079] The region segmentation module, based on the target prediction path output by the path prediction module, uses spatial expansion calculations to form the target's influence area. This module can spatially correct the predicted path based on probabilistic cloud models, tactical environmental constraints, and external factors such as terrain, no-fly zones, and communication obstruction zones, determining the potential spatiotemporal range of the target. This influence area serves as a core constraint in kill chain construction, limiting the service area of the target and thus preventing ineffective operational resources from participating in link reconstruction.
[0080] A kill chain construction module is configured to filter candidate service objects that meet the spatio-temporal constraints and capability constraints from the service resource library under the influence area constraints provided by the area division module, and map, arrange and combine the candidate service objects based on the kill chain template library. The kill chain construction module can not only construct a complete service-type kill chain within the influence area, but also perform gap identification, local completion and alternative link search when there is a missing link, generate an anti-kill chain that meets the current situation through limited width search, pruning rules and performance scoring mechanism, and ensure that the effective combat link can be maintained under the target evasion maneuver or the case of damaged friendly nodes.
[0081] Next, a service-type kill chain based anti-kill chain construction method provided by the embodiment of the application is further described in combination with the drawings, Figure 3 The method shown is applied to an anti-kill chain construction system, the anti-kill chain construction system is configured with a service resource library and a kill chain template library, the kill chain template library corresponds to a plurality of service-type kill chain templates, and the method comprises the following steps:
[0082] S1: obtaining current state information of a target to be attacked, performing target motion prediction according to the current state information, and obtaining a target predicted path;
[0083] In this embodiment, the current position, speed, track, heading and maneuvering mode of the target and other operation data can be dynamically collected according to the reconnaissance capability of the combat equipment. The type and accuracy of the current state information can be selected according to the use requirement, as long as it can support the prediction of the future motion trend of the target.
[0084] By performing time series analysis on the target state characteristics and constructing a credibility distribution according to the possible evasion strategies of the target, the predicted path not only contains a single deterministic path, but also reflects the potential activity trend of the target under different maneuvering assumptions, which can significantly improve the effectiveness of subsequent spatio-temporal constraint screening and avoid the kill chain construction lag or failure caused by excessive dependence on instantaneous position in the traditional method.
[0085] S2: performing spatial expansion on the target predicted path to obtain an influence area, and filtering candidate service objects that meet the spatio-temporal constraints and capability constraints of the influence area from the service resource library;
[0086] In this embodiment, the spatial expansion process is centered on the target prediction path, and is corrected according to constraint conditions such as terrain shelter, no-fly zone, physically inaccessible area, and key reconnaissance corridor in the operational environment, so that the influence area can cover not only the actual position that the target may reach, but also the restriction of the task environment on the deployment of operational resources. The role of the influence area is to limit the screening of service objects to the range where the target has actual action possibility. Compared with the traditional global retrieval method, the participation of invalid resources can be significantly reduced, and the link construction efficiency can be improved. Subsequently, the influence area is matched with the service objects in the spatial coverage range, available time window, and function category to form a candidate service object set. The service objects can be abstracted according to the detection range, fire radius, and communication link conditions of the equipment, and the specific attributes are determined by the actual equipment capability. Those skilled in the art can understand that these attributes can be flexibly extended according to the performance of different operational units.
[0087] S3: According to the service-type kill chain template corresponding to the target to be attacked, the candidate service objects are mapped to each kill chain link of the corresponding service-type kill chain template to determine the current kill chain.
[0088] In this embodiment, when the candidate service objects are mapped to the template links one by one, they are not statically assigned according to the equipment type, but dynamically bound according to the capability attributes and spatio-temporal accessibility, to ensure that each link is covered by a service object that can actually complete the operational action. In this process, if some links fail to be successfully mapped, they will be marked as gap segments for subsequent link completion, providing a necessary prerequisite for anti-kill chain construction. The current kill chain constructed in this way can accurately map the available operational resources under the current situation of the target, so that the link appears as a capability sequence that can be self-adapted to environmental changes, rather than a fixed combination of devices in the traditional sense. This embodiment uses service-oriented arrangement, making the link more flexible, so that in the case of target maneuvering avoidance or operational equipment damage, it can provide higher feasibility and directionality for subsequent completion and reconstruction.
[0089] Before the specific technical content corresponding to the unfolding step, the embodiments of the present application need to be emphasized again:
[0090] This embodiment does not regard the generation and reconstruction of the service-type kill chain as an isolated process, but as an implementation way of dynamic capability arrangement in a constantly changing space-time constraint environment. Unlike the traditional link construction method which is centered on fixed operational processes or equipment resources, the core of this application is the activity space that the target may touch in the future period of time, and the set of service objects that can continuously form operational effects in this space. The construction and reconstruction process of the kill chain is carried out under this dynamic regional constraint.
[0091] In actual execution, the link does not have a preset unique structure, but is constantly adjusted with the update of the target motion trend, the change of the service object state and the change of the environmental constraints. For a target at a moment, the service objects that can act on its behavior show obvious regional characteristics, for example, the fire unit cannot cover all the space due to range limitation, the reconnaissance node is temporarily disabled due to terrain obstruction, the command node is unavailable due to poor communication conditions, etc. When these changes cause some links in the original link to lose continuity, the link has a functional gap. The anti-killing chain construction method used in this embodiment is carried out around the identification, constraint extraction and capability completion of this gap.
[0092] In this embodiment, in order to ensure the rationality of the link reconstruction, the reachable area in the future is determined by the spatio-temporal characterization of the target behavior. The area is not a static boundary, but a dynamic space set formed by different prediction paths with different confidence levels. Based on this space set, a type of capability demand with common characteristics can be extracted, that is, the service capability that can form an effective effect on the target in the area. Then, through the double screening of the capability model and the time window, a group of replaceable service objects can be obtained. Unlike the traditional replacement method according to the classification or platform, the replacement process of this embodiment emphasizes the functional continuity and spatio-temporal coherence within the link, so that the generated link not only can connect the missing links, but also can maintain the overall logical closure with the previous and subsequent links.
[0093] Further, when the service objects are replaced and combined, all possible configurations are not pursued, but are regarded as a search process under multiple constraints. The combination behavior of the service objects in the link shows the state continuity problem. In this embodiment, the directionality of state expansion, reachability and capability matching conditions are constrained in multiple layers, so that the expansion path can converge to the link sequence that meets the demand within an acceptable amount of calculation. Finally, in order to avoid the combination that is feasible in form but poor in tactical effect, the performance evaluation model is used to distinguish the multiple candidate links generated, so that the finally determined link can keep a relative balance between operational effectiveness and resource consumption.
[0094] Next, the technical content of the service resource library of the method of the application is further expanded.
[0095] It can be understood that the service resource library described in the application is not a resource set classified according to platforms, equipment or static nodes in the traditional sense, but an ability-based service set formed by abstracting the functional capabilities of various equipment in the operational system.
[0096] In actual deployment, each service object in the service repository corresponds to a combat action that a certain equipment can perform under specific conditions, which can be a reconnaissance service, a tracking service, a command and control service, a fire attack service, or an effect evaluation service, etc.
[0097] As can be appreciated by those skilled in the art, in order to support dynamic link construction, the service object is not limited to a specific equipment model, and specific attributes such as spatial coverage, capability parameters, response time, combat radius, etc. can be updated in real time according to the equipment operating state, as long as the basic capability description requirements are met, and the present application does not make too many limitations.
[0098] In one example, each service object includes at least one of a service type, a capability parameter, a time parameter, a spatial coverage, and a mobility characteristic, wherein:
[0099] The attributes carried by the service object are used to describe the ability form it can play in the actual combat environment and the executability under the space-time condition. The service type is usually used to represent the functional role of the service object in the kill chain, such as performing reconnaissance, tracking, command and control, fire attack, or effect evaluation, etc. combat action, which is essentially an abstraction of a task function, rather than a limitation on the equipment name or physical form. The capability parameter reflects the combat effectiveness of the service object, which can include detection accuracy, action distance, weapon load, data link bandwidth, etc. related to the strength of the value description, which is used to select between multiple candidate objects in the performance level.
[0100] The time parameter is used to depict whether the service object can complete the task within the preset time, including response delay, sustainable action time, available window start and end time, etc. These parameters are not fixed values, but can be updated as the equipment state or task load changes, as long as they can reflect their executability in the link arrangement stage. The spatial coverage is used to describe the action scope of the service object in the physical space, such as the detection sector of the sensor, the range envelope of the fire unit, or the effective link coverage area of the communication node, which is used to ensure that each link of the generated kill chain can truly form an effect on the target area of influence.
[0101] The mobility characteristic is usually used to reflect the mobile ability of the service object itself, such as unmanned aerial vehicles, ships or mobile launch platforms can participate in action by changing position, and this characteristic is particularly important in the link completion stage, because some service objects that are not originally in the influence area can enter the action area through the mobility capability, thereby becoming a replacement node.
[0102] In yet another example, the construction steps of the service object include:
[0103] Obtain equipment data of each combat equipment in a combat system, and perform function abstraction and service modeling on a combat function of each combat equipment, to generate a service object representing the combat function, wherein the combat function includes reconnaissance, tracking, command control, fire attack, and effect evaluation.
[0104] In the embodiment, the kill chain template library can be understood as a set of standardized capability chain link models formed after process abstraction of different combat task requirements. Unlike the traditional combat plan library which is pre-configured according to target types or weapon platforms, the template is not directly bound to a specific equipment combination, but takes the capability requirements of each link of the kill chain as the core, and abstracts the discovery, positioning, tracking, indication, attack, and evaluation corresponding combat links into a series of capability nodes with clear input-output relationship and space-time constraint conditions. Each template can be regarded as a general description of the combat process under certain task assumptions, target characteristics, and combat environment. For example, for high-speed air targets, low-slow-small targets, sea mobile targets, or important fixed targets, the link configuration order, capability requirements, and timing constraints included in different templates can be different, but their common point is that they organize the link structure in the form of service type and capability constraint.
[0105] Further, the kill chain template library can pre-store multiple service-type kill chain templates, which can be distinguished according to task categories, target threat levels, combat domain types, or combat styles. Each link in the template only specifies what type of combat service is needed and its minimum capability threshold, such as the requirements for detection distance, accuracy, reaction time, or anti-jamming capability, without limiting which specific equipment to undertake. In this way, in actual operation, only one or more suitable service-type kill chain templates are selected from the template library according to the characteristics of the target to be attacked and the current tactical intent, and then each link in the template is filled in by specific service objects, to form the corresponding current kill chain. For anti-kill chain construction, the template library provides a unified reference framework, so that when the link is interrupted or the node is failed, it can be clearly identified which capability links have not been effectively covered, so as to search for supplementary nodes in the service resources in a targeted manner, rather than blindly replacing equipment.
[0106] Those skilled in the art can understand that the content of the kill chain template library is not limited to a fixed number or a fixed structure, and can be gradually improved according to operational regulations, experience data or tactical simulation results. The template can also be attached with priority weight, alternative link or optional branch to support parallel evaluation and selection of multiple links. The present application only requires that the template library can provide a structured description of the kill chain link at the capability level, so that whether the target to be attacked can be completely covered in its influence area, which link has a capability gap, and whether the alternative combination meets the overall operational constraints can be clearly described and solved. The specific size and storage form of the template library are not limited.
[0107] Next, the technical content of the target motion prediction method of the present application is further expanded.
[0108] In one example, the current state information includes at least one of the target current position, track, speed, heading, maneuver mode and threat level. In this embodiment, the acquisition method of these state information is not limited to a certain specific sensing means, but is determined by the operational conditions and available resources, as long as the minimum input requirement to support prediction can be met.
[0109] The target current position is usually obtained by reconnaissance resources with real-time measurement capability, such as electro-optical sensors, radar ranging points or other remote sensing means, and the output data form can be three-dimensional coordinates or geographical position marking.
[0110] Those skilled in the art can understand that this position does not require absolute accuracy, but only needs to reflect the instantaneous spatial position of the target.
[0111] The track information can be calculated from the observation points of the target in a period of time, or can be obtained from reconnaissance equipment with track extraction function to form the historical motion curve of the target through continuous sampling.
[0112] The target speed and heading can be derived from the change of position with time, such as calculating the displacement and interval time of the continuous observation points, or directly using the original output data of some sensors (such as velocity radar).
[0113] The maneuver mode usually reflects the motion pattern of the target in a short time, such as stable cruise, evasion maneuver, acceleration, snake maneuver, etc. This kind of information can be inferred from the trajectory change characteristics of the platform, or can be identified by the behavior identification model formed after fusing multiple sensing sources. This embodiment does not require the maneuver mode to have accurate classification, but only needs to roughly express the maneuver trend of the target, so that the prediction path can cover the potential uncertain behavior.
[0114] The threat level can be automatically generated based on intelligence data, target type identification or its behavior characteristics, and is used to reflect the importance or potential attack of the target. The specific calculation method can be set by task rules, which is not limited in the present application.
[0115] In yet another example, when predicting the target motion according to the current state information, the future short-time position of the target can be first calculated based on the current position and historical track of the target. To achieve this, the observation positions of the target at all times can be discretely sampled, and a time sequence model reflecting the motion trend of the target can be constructed by calculating the velocity vector and acceleration vector of adjacent observation points. The model can use a kinematic extrapolation method with a fixed time step, that is, the current speed and heading are used as initial prediction quantities, and the reference position in the future is recursively calculated within a preset time step; or a state estimation method based on polynomial fitting, Kalman filtering or extended Kalman filtering can be used, so that the extrapolation result still has high smoothness and stability under noise disturbance. Through the above calculation, a set of prediction trajectory points continuously distributed in time sequence can be obtained, each trajectory point corresponding to a potential position of the target at a future time.
[0116] In further processing, a motion mode set can be established according to the speed, heading and maneuvering mode of the target, to reflect different maneuvering behaviors that the target can take. In actual engineering implementation, the motion mode can be divided into categories such as stable flight, linear acceleration, sharp turning evasion, and snake evasion, each category being defined by different dynamic equations or turning angle change models. For each motion mode, different offset or acceleration fields can be applied to the prediction trajectory point set based on the current state, so that the prediction trajectory can cover a wider range of maneuvering possibilities. In addition, different confidence weights can be assigned to each prediction trajectory point according to the threat level of the target, for example: a high-threat-level target is more likely to take evasive maneuvers, so the weight of the corresponding evasive mode prediction point can be correspondingly increased, so that it gets a higher spatial proportion in subsequent impact area calculation.
[0117] As understood by those skilled in the art, the setting method of the confidence weight can be adjusted according to actual tactical rules, historical experience or model training results, which is not limited in the present application.
[0118] In the comprehensive processing stage, the prediction trajectory points generated under multiple motion modes and their corresponding confidence weights can be fused to form at least one prediction path through probability superposition or weighted clustering. The prediction path can be obtained by maximum likelihood trajectory estimation, center path extraction or mean trajectory calculation based on Gaussian mixture model. The path is used to describe the spatial distribution center of the target's future activity area, and provides a basis for subsequent construction of probability cloud model and impact area.
[0119] Next, the technical content of the application method about the influence area is further expanded.
[0120] It should be noted that the influence area described in the application is not a simple two-dimensional projection area, but a target possible activity volume constructed in a three-dimensional geographic space. The three-dimensional geographic space can be defined based on the geographic coordinate system of the combat area, the terrain elevation model, and the airspace hierarchical structure, wherein each spatial discrete unit corresponds to a three-dimensional grid voxel with fixed length, width, and height, which is used to accurately depict the position range of the target possible appearance in space. In engineering implementation, a unified reference coordinate system can be established for the three-dimensional geographic space, such as using geographic coordinates, Beidou coordinates, or tactical coordinate system, so that the whole process from sensor input to predicted path and then to spatial expansion has a consistent spatial reference basis.
[0121] In one example, the target predicted path is spatially expanded to obtain the influence area, including:
[0122] S2.1: Based on each target predicted trajectory point in the target predicted path and the corresponding confidence weight, a target position probability cloud model within a preset time is constructed, wherein the target position probability cloud model is used to represent the probability distribution of the target appearing at a spatial discrete unit, and the spatial discrete unit represents a grid unit generated by grid processing of a tactical space based on a preset resolution;
[0123] Specifically, under the condition that the target is highly mobile and the reconnaissance observation has noise and incompleteness, it is difficult to truly reflect the activity range of the target within a preset time by relying only on a single or multiple deterministic predicted trajectories. The predicted path itself is often only a trend line, and the target will make various disturbances around this trend in the actual movement process, so it is necessary to introduce a distribution model that can reflect the possibility of the target appearing in space, which is used to assign different importance levels to different spatial positions in subsequent processing. By converting discrete predicted trajectory points into a probability distribution on a three-dimensional grid space, complex trajectory uncertainty can be uniformly encoded into a target position probability cloud, which facilitates the operation and superposition of tactical environment constraints, service coverage areas, and other information in a unified data structure, thereby avoiding the complexity brought by point-by-point processing of single-point trajectories in subsequent steps.
[0124] In this embodiment, the tactical space is first processed by three-dimensional gridding according to a preset spatial resolution, and the combat area is discretized into a space body composed of multiple grid cells. Each target prediction trajectory point is mapped into the corresponding grid cell according to its three-dimensional coordinates, and the target occurrence probability of the grid cell is accumulated and updated in combination with the confidence weight of the trajectory point. For example, when multiple prediction trajectory points fall into adjacent grid cells within the same time period, the respective weights can be superimposed in these grid cells, so that the target position probability cloud presents a high probability concentration trend in the area. In addition, time decay, path smoothing or local neighborhood diffusion strategies can be introduced, so that the grid cells close to the prediction path obtain a certain probability compensation, so that the probability cloud is not limited to the single grid where the trajectory point is located, but is extended to a small piece of space around the trajectory point. In this way, within the preset time, each grid cell will gradually form a complete probability distribution according to the number of trajectory point projections, weight size and time sequence, which is used to depict the activity possibility of the target in the three-dimensional space.
[0125] S2.2: Obtain tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information;
[0126] Specifically, the activity range of the target in the battlefield environment is not only determined by its movement ability, but also jointly constrained by various tactical factors such as terrain undulation, no-fly zone setting, air defense firepower coverage, communication blind area, etc. If only the kinematic characteristics of the target itself are considered for space deduction, some space regions that are not reachable or unreasonable in the actual environment will be obtained, which is not conducive to subsequent accurate screening of the actionable region.
[0127] In this embodiment, the tactical environment constraint information can be derived from various data sources, including but not limited to digital terrain elevation data, no-fly zone setting results, radar or air defense firepower coverage area, traffic corridor and air route network, important deployment areas of the own side and the target side, communication and navigation support areas, etc. For terrain data, high mountains, densely built-up areas and other areas that cannot be crossed or are highly restricted can be marked as physically unreachable areas; for no-fly zones, restricted areas, etc., corresponding space regions can be marked as forbidden entry regions according to task requirements; for air routes, canyon channels, etc., they can be marked as priority passage or high-probability passage regions. After the coordinate system and resolution conversion, the above various constraint information is mapped into the same three-dimensional grid as the target position probability cloud, and each constraint is assigned with a corresponding label or attribute value, thereby constructing a tactical constraint set containing multiple constraint categories.
[0128] S2.3: constraint fusion processing is performed on the set of tactical constraints and the target position probability cloud model, target appearance probabilities of spatial discrete units located in no-fly zones and physically inaccessible areas are attenuated, target appearance probabilities of spatial discrete units located in preset flight paths and terrain concealed channels are enhanced, and a modified model is obtained;
[0129] Specifically, the target position probability cloud model reflects the position distribution that the target can reach in ideal space by relying on its own maneuvering capability, but does not consider the influence of tactical constraints. If the probability cloud is not modified, the model may consider that the target has a high probability of appearing in the airspace above the target side ground defense intensive area or crossing obvious inaccessible obstacle areas, which is not consistent with the actual tactical behavior. Therefore, it is necessary to fuse the set of tactical constraints with the target position probability cloud, so that the appearance probability of the target in certain areas is suppressed or increased, so that the modified spatial distribution is more consistent with the action path that the target can take in the real battlefield environment. This fusion process is essentially a spatial redistribution of the probability cloud, which weakens the probability of unreasonable areas and encourages the target to gather in reasonable and accessible areas.
[0130] In this embodiment, the constraint fusion processing can be realized by traversing each grid cell one by one and querying its corresponding constraint type in the set of tactical constraints. For grid cells identified as no-fly zones or physically inaccessible areas, such as inside high mountain terrain, permanent no-fly airspaces, inside ground building entities, etc., the appearance probability of the target in the target position probability cloud can be greatly attenuated or directly set to zero; for preset flight paths, canyon channels, terrain concealed channels, etc., the original probability can be enlarged or kept unchanged, so that the target position probability is concentrated towards these reasonable passage paths. For grid cells affected by multiple constraints, a comprehensive adjustment factor can be obtained by comprehensively processing each type of constraint according to a pre-set weight, to modify the original probability.
[0131] S2.4: cumulative probability operation is performed on the modified model to determine a set of minimum spatial regions in which the cumulative target appearance probability is greater than or equal to a preset confidence threshold within the preset time, wherein the set of minimum spatial regions can be obtained by clustering the spatial discrete units;
[0132] Specifically, after the tactical constraint fusion is completed, each grid cell in the modified model corresponds to a probability value of the target appearing at that position. If the entire probability cloud is directly used as the influence area, it will result in an excessively large influence area range, including a large number of areas with very low probability, which is not conducive to subsequent targeted screening of service objects.
[0133] In the embodiment, all grid cells can be sorted or ranked according to the probability values of the grid cells in the modified model, and the probability values of the grid cells with higher probabilities can be accumulated first. When the accumulated probability value reaches or exceeds the preset confidence threshold, all grid cells participating in the accumulation are marked as the core region set, and the remaining grid cells with lower probabilities can be regarded as edge regions or low attention regions. In order to organize these discrete high-probability grid cells into regions with spatial continuity, a clustering method based on spatial adjacency relationship can be used to merge grid cells that are adjacent to each other and have high probability values into one or more connected regions. In the clustering process, parameters such as the minimum number of connected cells and the spatial distance threshold can be set to avoid the formation of fragmented regions that do not have practical significance due to isolated high-probability cells.
[0134] In one example, the modified model is subjected to cumulative probability operation to determine a minimum spatial region set in which the cumulative target appearance probability within the preset time is greater than or equal to a preset confidence threshold, including:
[0135] The target appearance probability of each spatial discrete cell in the modified model is accumulated and summed according to time sequence to obtain the cumulative target appearance probability value of each spatial discrete cell;
[0136] Based on the cumulative target appearance probability value and the confidence threshold, spatial discrete cells with a cumulative target appearance probability value greater than or equal to the confidence threshold are selected as a target active cell set;
[0137] The target active cell set is subjected to spatial clustering to obtain a candidate region, and the candidate region is subjected to geometric regularization by morphological dilation to obtain a minimum spatial region set.
[0138] Specifically, the tactical space has been discretized into three-dimensional spatial discrete cells. The candidate region formed by clustering the target active cell set often has jagged boundaries, local narrow channels or small fractures at the voxel level, which increases the complexity in subsequent calculation of spatial envelopes and judgment of service coverage relationships. Therefore, it is necessary to perform moderate geometric expansion and filling on the candidate region while keeping the overall outline and spatial distribution characteristics of the region unchanged, so as to reduce the internal holes, thicken the local slender structure, and connect the narrow gaps of one or several voxels, thereby facilitating the approximation of the envelope with regular geometric bodies.
[0139] In the embodiment, the spatial discrete unit corresponding to each candidate region can be constructed as a three-dimensional binary grid mask, wherein the spatial discrete unit belonging to the candidate region is marked as a valid unit, and the remaining units are marked as invalid units. Based on the binary grid, a structure element suitable for three-dimensional space is selected as a dilation template. The structure element can be a cubic neighborhood centered on a grid unit, or a neighborhood set approximated as a sphere centered on the center unit. The radius or edge length of the structure element can be set according to the spatial resolution and the expected region smoothing degree. When performing morphological dilation, the structure element is slid point by point in the three-dimensional grid. For each position of the current valid unit, all units within the coverage range of the structure element are marked as candidate valid units, thereby expanding the original candidate region boundary by one or more grid units outward. By repeatedly performing one to several dilation operations, small holes inside the candidate region can be filled in space, and narrow connecting channels can be expanded, so that the thin bridge region connected by only a single grid unit becomes a continuous strip-shaped region composed of multiple grid units.
[0140] Further, to prevent the region from expanding uncontrollably outward during the dilation process, a restriction condition can be introduced during implementation, such as allowing the dilation result to fall within the spatial range where the probability value is not zero in the previous correction model, or limiting the number of dilations to not exceed a preset upper limit of iterations, thereby ensuring that geometric regularization only works near the candidate region boundary and does not invade the distant space that does not belong to the target active region. For multiple candidate regions that are close to each other but not completely connected, a dilation threshold can also be set to naturally merge regions with a center-to-center distance of less than several grid units during the dilation process, thereby regularizing multiple fragmented small regions into a larger region with more engineering significance. After morphological dilation processing, the obtained minimum spatial region set appears as a voxel set with smooth boundaries, good internal connectivity, and fewer holes in the three-dimensional grid, which facilitates subsequent calculation of the spatial envelope and geometric operations such as intersection and inclusion with the spatial coverage range of the service object.
[0141] Those skilled in the art can understand that the specific shape of the structure element, the number of dilations, and the restriction condition can be adjusted according to the task scenario and the spatial resolution, as long as the region expression is true and the geometric regularization degree is improved. The present application does not make more limitations.
[0142] S2.5: determining the spatial envelope corresponding to the minimum spatial region set as the influence area;
[0143] Specifically, the minimum spatial region set is a set of discrete connected regions obtained by screening and clustering high-probability grid cells, which can have complex boundaries and irregular shapes in three-dimensional space. If these discrete regions are directly used as spatial restrictions for subsequent service matching and link construction, the computational geometry complexity will increase in engineering implementation, especially when it is necessary to frequently judge whether the service coverage area and the impact area intersect. Therefore, the set needs to be geometrically regularized, abstracting its boundary to a more computationally friendly spatial envelope, so that the impact area is easy to judge, store and transfer in subsequent algorithms, while still maintaining a reasonable approximation to the target activity space.
[0144] In the present embodiment, a suitable envelope construction method can be selected according to the spatial distribution characteristics of the minimum spatial region set. For a single connected region with a relatively concentrated distribution, a three-dimensional convex hull or an approximate convex hull can be used to construct the envelope, which contains all the internal grid cells within a polyhedral region; for a region set presenting multiple branches or island structures, a local envelope can be constructed for each connected component, and if necessary, several adjacent envelopes can be merged into a larger envelope body through spatial set operation. The envelope does not have to completely coincide with the original region boundary, but only needs to completely cover the minimum spatial region set in space, which can be used as a geometric approximation expression of the impact area.
[0145] Next, the technical content of the method of the present application with respect to candidate service objects is further developed.
[0146] Reference Figure 4 , Figure 4 The structure diagram of the service index tree provided by the embodiment of the present application is shown.
[0147] As Figure 4 shown, the service index tree is a four-layer structure including a root node, a first layer node, a second layer node and a third layer node, wherein the root node is used as the convergence entrance of the index tree and does not carry specific service retrieval conditions itself, but only organizes the topological relationship of the nodes at the lower layer.
[0148] The first layer node includes first layer node one, first layer node two and first layer node three, which respectively correspond to different spatial regions obtained by dividing the tactical space, such as different airspace sectors, different geographical partitions or different height layers. Through this division method, when performing spatial screening, only the first layer node with spatial intersection with the target impact area is accessed, thereby avoiding indiscriminate traversal of the entire service resource set.
[0149] The second layer nodes include second layer node one to second layer node five, each of which belongs to a different first layer node and is configured to further subdivide the available time window of the service object in the corresponding spatial region. For example, the first layer node one can be configured with second layer node one and second layer node two, which represent sets of service objects available for engagement in different time periods in the spatial region; the first layer node three can be configured with second layer node three, second layer node four, and second layer node five, which are used to represent another group of time divisions in the spatial region. In this way, when searching for a service object, the time window of the kill chain can be combined to search only in the second layer nodes and their sub-trees that overlap with the time window, thereby effectively reducing the service resources in the time dimension.
[0150] The third layer nodes include third layer node one to third layer node four, which represent different service types or capability categories under the corresponding spatial region and time window, such as reconnaissance services, tracking services, command and control services, and fire attack services. For each third layer node, one or more specific service objects can be associated thereunder, which constitute the leaf nodes of the service index tree and are used to be selected as candidate service objects when the spatial, temporal, and capability constraints are met.
[0151] In one example, filtering candidate service objects from the service resource library that adapt to the spatiotemporal constraints and capability constraints of the affected area includes:
[0152] Based on the spatial coverage, available time window, and service type information of each service object in the service resource library, the service objects are hierarchically organized to construct a service index tree, wherein the service index tree includes: first layer nodes divided by tactical spatial regions; second layer nodes under each first layer node divided by available time windows; and third layer nodes under each second layer node divided by service type information;
[0153] According to the affected area, the service index tree is traversed from top to bottom, and the first layer nodes and their sub-trees that have no spatial intersection with the affected area are pruned;
[0154] According to the kill chain execution time window, the second layer nodes and their sub-trees that do not meet the preset time are pruned;
[0155] According to the capability requirements of the corresponding link in the service-type kill chain template, the third layer nodes and their leaf nodes that do not meet the capability constraints are pruned;
[0156] The service objects corresponding to all the remaining leaf nodes in the pruned service index tree are summarized to determine the candidate service objects.
[0157] ReferenceFigure 5 , Figure 5 The service index tree pruning principle schematic diagram provided by the embodiment of the application.
[0158] Figure 5 Taking the service index tree of Figure 4 , it is shown that when actually performing candidate service object screening, full traversal of the entire service index tree is not required, but according to the influence area, the preset time window and the ability requirement of the kill chain template, each layer node is pruned in turn, so as to exclude the whole subtree that does not meet the constraint condition. The dashed box in the figure represents the pruned subtree, and the arc-shaped arrow is used to show the constraint transmission direction from top to bottom in the pruning process.
[0159] As shown in Figure 5 , the first layer node one and the first layer node two have no spatial intersection with the influence area, so the subtree with the first layer node one and the first layer node two as the root cannot provide service objects that can act on the target influence area. The reason is that the first layer node and the first layer node two correspond to the tactical space division, once the spatial range of the node is completely overlapped with the influence area, all service objects in the subtree of the node cannot cover the target in space, so Figure 5 the whole subtree is directly pruned in the dashed line in the figure.
[0160] After the rest of the layers are operated in the same way, the final obtained subtree is: the first layer node three, the second layer node three and the third layer node two, so the service objects in the leaf node corresponding to the third layer node two can be used as the candidate service objects.
[0161] It can be understood that Figure 5 the pruning process shown in the figure is only used to show an exemplary node screening result, which is used to explain the basic behavior of the service index tree after being shrunk layer by layer by the space constraint, the time constraint and the ability constraint. In specific practice, when the tactical space is more finely divided according to the elevation, the sector or the geographical grid, the number of first layer nodes may significantly increase; when the task involves a longer time scale or requires ability matching in a smaller time slice, the number of second layer nodes will also expand; the classification method of service types can also be refined according to different architectures, so that the third layer node presents different number scales.
[0162] Next, the technical content of the method of the application about determining the current kill chain is further expanded.
[0163] It can be understood that in the precondition of the present application, each target to be attacked corresponds to one or more service-type kill chain templates, and how to search in the kill chain template library according to the target to be attacked can be realized by a matching rule based on target attribute information, a template indexing method based on a task type, or a template selection strategy based on a threat level, for example, a template set most matched with the target can be located in the template library according to target classification, platform type, maneuvering capability, target threat level, or task scene to which the target belongs. Those skilled in the art can select a suitable search mechanism according to the system configuration and task flow, and therefore the present application is not limited herein.
[0164] In one example, the candidate service object is mapped to each kill chain link of the corresponding service-type kill chain template to determine the current kill chain, including:
[0165] S3.1: judging whether the candidate service object completely covers the corresponding service-type kill chain template according to the mapping result;
[0166] In one example, after the preliminary mapping of the candidate service object and the service-type kill chain template, it is necessary to first judge whether each kill chain link has at least one available service object matching. This judgment is essentially a check on the coverage relationship between the template link list and the service mapping result. Specifically, the pre-defined link sequence in the template can be taken as a set of ordered capability slots, and a covered / uncovered flag field is maintained for each slot. When the capability matching of the candidate service object is completed, the service object that meets the corresponding capability constraint and meets the influence area and time window constraint is hung on the related slot, and the slot is marked as covered, and if a slot cannot find any service object meeting the condition, the slot is marked as uncovered. The template coverage can be obtained by traversing the entire template link sequence.
[0167] The embodiment takes a service-type kill chain template F2T2EA as an example, where F2T2EA specifically refers to Find, Fix, Track, Target, Engage, and Assess, i.e., reconnaissance, positioning, tracking, command, attack, and assessment. In the preliminary mapping process, the above six links can be sequentially established corresponding capability slots. For example, the Find link corresponds to the detection and search capability slot, the Fix link corresponds to the positioning accuracy and duration capability slot, the Track link corresponds to the continuous tracking and trajectory updating capability slot, the Target link corresponds to the command control and task allocation capability slot, the Engage link corresponds to the firepower delivery capability slot, and the Assess link corresponds to the battlefield effect assessment capability slot. The candidate service object can be hung in the corresponding slot on the premise that it meets its capability constraint, spatial coverage range, and time window.
[0168] In some optional embodiments, when making the coverage judgment, not only it is necessary to confirm that there is at least one service object in each slot that can satisfy the capability matching, but it is also necessary to further consider whether the execution connection between the cross links is feasible. For example, assuming that a certain unmanned reconnaissance platform can be used for the Find link, and a certain ground fire unit can be used for the Engage link, but if there is a significant time offset between the two in the target activity window, or the detectable area of the reconnaissance platform and the field of fire of the fire unit cannot form an effective space-time link inside the impact area, then these two service objects, although each can cover the link, cannot form a continuous executable kill chain. At this time, the coverage status of the Find link is already covered, but it still needs to be recorded that there is a potential breakpoint in the link level of this link, so as to be considered when judging whether it is necessary to enter the completion process later.
[0169] Further, in some cases, there may be multiple tactically equivalent capability configurations for a template link. For example, in some rapid suppression tasks, the Fix link and the Track link can be completed in a continuous manner by the same equipment, at which time the system can combine the processing of these two capability slots, as long as a service object has the ability to cover both capability slots, it is considered that both links are covered. For example, in the Assess link, there may be different evaluation methods such as image evaluation, signal evaluation, and damage inference, as long as one of the evaluation methods is feasible, it can be considered that the link meets the coverage requirement. Through this flexible coverage judgment mode, the differentiated needs of the kill chain execution logic in different types of targets and different combat stages can be adapted to, so as to ensure that the judgment result has practical significance.
[0170] S3.2: If yes, processing the mapping result through a redundancy optimization logic, selecting a target service-type kill chain, and determining the service object sequence corresponding to the target service-type kill chain as the current kill chain;
[0171] In one example, the redundancy optimization logic includes:
[0172] For a plurality of candidate service objects mapped to the same kill chain link, an efficiency score is calculated for each candidate service object according to a preset efficiency evaluation model, wherein the efficiency evaluation model generates the efficiency score based on one or more parameters of detection accuracy, response time, combat radius, reliability, and resource consumption;
[0173] The plurality of candidate service objects are sorted according to the efficiency scores, the candidate service object with the highest efficiency score is selected as the service object of the corresponding kill chain link, and the remaining candidate service objects are selected as alternative objects;
[0174] The service object sequence formed by the service objects is subjected to link consistency verification, and if the verification passes, the service object sequence is confirmed as the current kill chain; if the verification fails, local adjustment is made based on the alternative objects until the link consistency verification passes.
[0175] It can be understood that when the coverage judgment indicates that all links of the service-type kill chain template have at least one candidate service object satisfying the corresponding capability requirement, it means that the condition for building a complete kill chain has been met at the capability level. However, there are often multiple replaceable relationships among candidate service objects.
[0176] For example, there may be multiple air-based platforms with reconnaissance capabilities in the Find link; there may be sensor combinations with different update frequencies in the Track link; and there may be multiple fire resources with action capabilities in the Engage link.
[0177] If such capability redundancy is not handled, although it can provide greater flexibility, it will cause the number of combinations to grow exponentially when building a link, and may form a large number of links that are not optimal in terms of time continuity, spatial connectivity or resource consumption. Therefore, it is necessary to introduce redundancy optimization logic after mapping is completed to evaluate and screen multiple candidate service objects for the same link, so that the final kill chain formed meets the task requirements and has higher execution efficiency and overall coordination.
[0178] In this embodiment, redundancy optimization can be established around each link of the kill chain. The performance model can be composed of multiple factors, such as detection accuracy, response time, platform reliability, execution cost, task duration, communication link stability, etc. The relevant parameters of each candidate service object can be mapped into the performance model to form a quantifiable score for measuring the comprehensive performance of the service object in executing the task of the link. Subsequently, the candidate service objects for the same link can be sorted according to the score, and the service object with the highest score is selected as the preferred node for the link, and the remaining objects are marked as alternative nodes.
[0179] Further, after local redundancy optimization is performed on all links, the preferred service objects of each link can be combined in the template order to form an initial service object sequence. Although this sequence is complete in terms of capability, it does not guarantee complete feasibility in terms of time and space dimensions. For example, the reconnaissance platform in the Find link may end the task at t1, while the positioning device in the Fix link cannot be put into use after t1, or the spatial coverage areas of the two have no intersection in the impact area, which may all cause the link to have a breakpoint, or the device in a link cannot fully cover all functions of the link.
[0180] To avoid this situation, link consistency verification is required for the initial sequence at this stage, including:
[0181] whether the adjacent links have connectable time windows, whether the service objects of the two links have actionable paths in the influence area, whether the communication and data links meet the real-time requirements, and whether the functions of the current link service objects completely cover the corresponding kill chain links.
[0182] In some optional embodiments, if it is found that a link cannot be effectively connected with the previous and subsequent links, a service object with a higher score or a more matched service object can be selected from the corresponding alternative nodes of the link to replace it, a local sequence is regenerated, and consistency verification is performed again.
[0183] S3.3: If not, the mapping result is reorganized by link completion logic to obtain the current kill chain, wherein the reorganization includes retrieving a supplementary service object from the service index tree for a kill chain link that is not covered, and performing sequence adjustment on the candidate service object and the supplementary service object to generate an alternative service-type kill chain, and determining the service object sequence corresponding to the alternative service-type kill chain as the current kill chain.
[0184] It can be understood that when the coverage judgment result or the link consistency verification indicates that there is still one or more capability gaps in the service-type kill chain template that cannot be filled by the candidate service object, link completion logic needs to be started to avoid the entire link being unable to be executed due to the absence of a key link. The core idea of the link completion logic is that:
[0185] Without repeatedly constructing links that have already met the requirements, a local completion process is constructed for the missing links, so that the link can restore integrity and executability by inserting a new service object sequence while keeping the overall structure unchanged. This logic not only provides fault tolerance for link construction, but also enables the anti-kill chain to continuously generate new effective links when equipment is damaged, resources are suddenly lost, or target behavior mutates.
[0186] In one example, the link completion logic includes:
[0187] S3.3.1: Identify the kill chain links in the mapping result that are not covered by the candidate service objects, and merge a plurality of kill chain links that are not covered into a gap segment to generate one or more gap segments, wherein the gap segment also includes a single kill chain link.
[0188] Specifically, after the candidate service object and the service-type kill chain template complete the preliminary matching, some links may fail to find a service object that meets the space-time constraints and capability constraints. If these uncovered links are processed one by one without distinction, it will lead to high complexity of the subsequent completion process, and it is difficult to reflect the continuity between the links in time and function. Therefore, it is necessary to first identify which links are in a vacancy state as a whole, and to structure and organize these links, merge multiple uncovered links adjacent to each other in the template sequence into a continuous gap segment, so as to subsequently complete the gap segment in a centralized manner, rather than scattered local repair of a single link.
[0189] In the embodiment, the flag bit of each link in the template is checked in sequence. If the flag bit is not covered, the link is added to the gap segment being currently constructed. If the flag bit is covered and the previous link is in an uncovered state, the previous continuous uncovered link is marked as a complete gap segment, and a new paragraph is started to be recorded. Through such sequential traversal, one or more gap segment lists can be automatically generated, each gap segment internally containing a continuous uncovered link, and the length of the gap segment can be one link or several links. The generated gap segment not only records the contained link index, but also records the capability requirement type of each link and the relationship information between adjacent covered links, for subsequent completion process calling.
[0190] Reference Figure 6 , Figure 6 A structural schematic diagram of the gap segment provided by the embodiment of the present application.
[0191] Figure 6 Taking F2T2EA as an example, in some dynamic combat scenarios, part of the links in the chain may have capability gaps due to resource failure, service unavailability or target state mutation. Figure 6 The case shown is that several links after the reconnaissance link and before the strike link fail to find available service objects that meet the constraint conditions, thereby forming a continuous gap segment one. In addition, the evaluation is also an independent gap segment two.
[0192] It can be understood that the example is only used to illustrate the logical structure of the gap segment, and does not limit the number or length of the gap segment. In actual application, the start and end positions of the gap segment depend on the coverage of the candidate service object:
[0193] If a link is not covered alone, a gap segment with a length of one is formed. If multiple adjacent links are not covered, they are automatically merged into a continuous combined gap segment. If capability blanks appear at different positions in the chain, multiple independent gap segments may be formed at the same time.
[0194] S3.3.2: For each gap segment, obtain the assigned service objects corresponding to the chain links before and after the gap segment, determine the completion time constraint window and the completion space constraint window for the gap segment based on the combat start and end times and the spatial coverage of the assigned service objects, and combine the influence area to determine the completion time constraint window and the completion space constraint window for the gap segment;
[0195] Specifically, the gap segment is essentially a segment of capability blank embedded in a complete chain structure, and there are usually links before and after the gap segment that have been covered by candidate service objects. If the time and space information of the two or one anchor links is not considered during the completion process, and only the global service resources are searched for a supplementary node, a local sequence that is disconnected from the original link is easily constructed, which is difficult to connect with the links before and after in time, and may deviate from the target activity area in space. Therefore, the service object information corresponding to the links before and after the gap segment is needed to derive a local constraint window for the gap segment, so that the completion process is reasonably limited in time and space, and the search is concentrated in the range where a continuous link is really possible, thereby reducing the search range and improving the effectiveness of the completion process.
[0196] In the embodiment, for each gap segment, the positions of the previous link and the next link in the template can be determined first, and the currently assigned service objects of the two links can be read. For the pre-service object, the combat end time and the actual range of action within the influence area can be extracted; for the post-service object, the combat start time and the range of action within the influence area can be extracted, and a reasonable buffer interval can be left between the two time points according to the task timing. For example, the completion time constraint window can be set to a time point after the end time of the previous link to a time point before the start time of the next link, and if necessary, the window can be appropriately widened according to the target motion prediction result. In terms of space, the coverage areas of the pre-service object and the post-service object within the influence area can be superimposed or summed, and combined with the spatial position that the target can pass through within the time period, the completion space constraint window of the gap segment in three-dimensional space can be derived, so as to ensure that the completion process is only performed in the spatial area where the target can appear and can be connected by the links before and after.
[0197] S3.3.3: In the service index tree, search the first layer nodes and their sub-trees that have a spatial intersection with the completion space constraint window to obtain a set of supplementary service objects for the gap segment;
[0198] Specifically, the service index tree has already organized the service resources in a hierarchical manner according to the tactical space area-time window-service type. If the full database scanning method is still used to find the supplementary service objects in the completion process, not only a large amount of calculation will be brought, but also a large number of service objects irrelevant to the gap segment in space will be introduced, which will significantly increase the burden of the subsequent combination and screening stage. Based on the completion space constraint window, the search range can be limited to the tactical area that has a spatial intersection with the window, and spatial filtering is started from the first layer of the tree structure. Once the tactical space corresponding to a first layer node is completely overlapped with the completion space constraint window, all service objects in the subtree of the node cannot participate in the completion of the gap segment. This spatial-based pruning operation can exclude a large number of irrelevant nodes as early as possible in the upper layer of the index tree, so that the completion process is only carried out in the subtree with potential feasibility.
[0199] In the present embodiment, all first layer nodes of the service index tree can be checked one by one, and according to the intersection of the tactical space area associated with each node and the completion space constraint window, it is judged whether the node should be retained. For the first layer node with intersection, it is marked as a completion process participating node, and its subtree is included in the subsequent search range; for the first layer node with no intersection at all, its subtree is excluded as a whole, and it will not enter the scanning of the second layer and the third layer. On this basis, the retained subtree can be further filtered in combination with the completion time constraint window and the capacity demand of the gap segment, for example, only the nodes with available time window falling within the completion process period are retained in the second layer nodes, and only the nodes with the required capacity type of the gap segment are retained in the third layer nodes. Through this consecutive filtering process, the final extracted from the service index tree will be a set of supplementary service objects that meet the space, time and capacity constraints at the same time. These service objects are the only ones that can act as candidate filling nodes for the gap segment in the subsequent completion process.
[0200] S3.3.4: constructing a completion search tree with each kill chain link in the gap segment as a level, and extending the state of the set of supplementary service objects according to the order of the kill chain links, wherein the search path is pruned according to the time continuity constraint, the space connectivity constraint and the communication link reachability constraint in the state extension process, and each search path in the current layer is evaluated, and only the search paths with the top pre-set number of comprehensive scores are retained as the starting point for the next layer extension;
[0201] Specifically, the gap segment often contains one or more continuous kill chain links inside, and the completion process needs to match each service object with appropriate service objects at these links, and ensure that these service objects can form a continuous and executable link after combination. If the set of supplementary service objects is simply matched by full permutation combination, the number of combinations will quickly expand to an unacceptable level as the length of the gap segment and the number of candidate service objects increase. Therefore, the gap segment can be regarded as a hierarchical decision path, and a completion search tree is constructed from top to bottom according to the order of the links inside the gap segment:
[0202] Each layer corresponds to a link in the gap segment, and each node state corresponds to the local link state formed after a service object at the link is selected and combined with the previous link. A complete candidate path from the start to the end of the gap segment is formed through layer-by-layer expansion.
[0203] In this embodiment, the construction of the completion search tree can start from the first link of the gap segment, and all supplementary service objects that meet the capacity requirements of the link and are within the completion constraint window are selected as candidate nodes at the next layer of the root, and the time window, spatial coverage and relationship with the target influence area of the selected service object are recorded in each node state. Subsequently, for the second link in the gap segment, all supplementary service objects that meet the capacity requirements of the link can be tried to be connected based on each valid node state at the previous layer, and whether they meet the constraint conditions in terms of time continuity, spatial connectivity and communication link reachability is checked:
[0204] If the available time windows of the two service objects have no intersection within the completion process time interval, the coverage areas cannot form a connected path within the influence area, or there is no feasible data transmission path between the two, the expanded path is considered to not meet the link continuity requirement and is pruned from the search tree. Only when all the above conditions are met, the path will be retained as a new state node in the current layer. By repeating this expansion and pruning process in each layer, all potential completion paths can be gradually constructed in the structure of the tree.
[0205] In one example, the state expansion of the set of supplementary service objects according to the order of the kill chain links includes:
[0206] In each layer of the completion search tree, the corresponding kill chain link is taken as the current expansion target link, the service objects matching the kill chain link are selected from the set of supplementary service objects, and the corresponding expansion state is generated by taking each selected service object as a candidate expansion node;
[0207] For each extended state, legality judgment is performed according to time continuity constraints, space connectivity constraints and communication link reachability constraints between the current extended target link and the corresponding service objects of adjacent determined kill chain links, and pruning operation is performed on the extended state that does not satisfy any constraint;
[0208] For the extended state that passes the legality judgment, a comprehensive performance score is calculated according to a comprehensive score function constructed according to a target performance weight and a resource consumption weight, and when the number of extended states that pass the legality judgment exceeds a preset number threshold, the extended states are limited and screened based on the comprehensive performance score.
[0209] S3.3.5: Select the service object sequence with the highest comprehensive performance score from the completion search tree as the completion sequence of the gap segment, and splice the completion sequence with the selected service object sequences before and after the gap segment to generate a corresponding completion link;
[0210] Specifically, after the completion of the completion search tree expansion, each path from the root to the leaf corresponds to a candidate completion sequence that has selected specific service objects on the internal links of the gap segment. These sequences have been filtered by time, space and link reachability constraints during construction, and thus have executability in structure. There are still differences between these candidate paths, and if any one path is simply taken as the completion result, it may result in lower operational performance and more resource waste. Therefore, it is necessary to compare all candidate paths based on the accumulated evaluation information during the expansion process, and select the one with the highest evaluation score as the final completion sequence of the gap segment, so that the gap segment can complete the capacity completion while having more reasonable performance in time utilization, space adaptation and resource allocation.
[0211] In this embodiment, the comprehensive performance score can be accumulated gradually during the path construction process of the completion search tree. Each time a service object is added at a certain layer, its own performance score and the current accumulated score of the path can be combined according to a preset weight, for example, by using weighted superposition, normalized average or minimum value protection, to integrate the performance of each service object in the completion sequence into a whole index. After the search tree is fully expanded, the comprehensive scores of all paths reserved to the leaf nodes can be compared, and the path with the highest score is selected as the completion sequence of the gap segment. Subsequently, the completion sequence is spliced with the original selected service object sequences before and after the gap segment in the time axis and the space axis, and a small amount of boundary adjustment is made if necessary, for example, fine-tuning the start and end times of the front and rear links to avoid excessive boundary overlap or leave unexplained time gaps, and merging and labeling the coverage ranges with high overlap in the same space region, so as to form a completion link that is logically continuous and reasonably in time and space.
[0212] S3.3.6: combine all the corresponding complete links of the gap segments with the corresponding service object sequence of the covered kill chain links to generate the alternative service-type kill chain.
[0213] Although the embodiments of the present application have been shown and described above, it should be understood by those ordinary skilled in the art that the above embodiments are exemplary and cannot be construed as limiting the present application, and those ordinary skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.
Claims
1. A method for constructing an anti-kill chain based on a service-oriented kill chain, applied to an anti-kill chain construction system, characterized in that, The anti-kill chain construction system is configured with a service resource library and a kill chain template library. The kill chain template library corresponds to multiple service-type kill chain templates. The method includes: Obtain the current state information of the target to be attacked, and predict the target's movement based on the current state information to obtain the target's predicted path; The predicted target path is spatially expanded to obtain the affected area, and candidate service objects that are suitable for the spatiotemporal constraints and capability constraints of the affected area are selected from the service resource library; Based on the service-oriented kill chain template corresponding to the target to be attacked, the candidate service object is mapped to each kill chain link of the corresponding service-oriented kill chain template to determine the current kill chain.
2. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The service resource library includes multiple service objects, each of which includes at least one of the following: service type, capability parameters, timeliness parameters, spatial coverage, and mobility characteristics. The steps for constructing a service object include: Acquire equipment data for each combat device in the combat system, and perform functional abstraction and service modeling for the combat functions of each combat device to generate service objects that represent the combat functions, including reconnaissance, tracking, command and control, fire strike, and effect evaluation.
3. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The current state information includes at least one of the target's current position, trajectory, speed, heading, maneuvering mode, and threat level. Target motion prediction based on the current state information includes: Based on the target's current position and trajectory, the target's position is predicted through kinematic calculations, resulting in a set of predicted trajectory points. Based on speed, heading, and maneuvering mode, the potential movement patterns of the target are determined, and the credibility weights of each target's predicted trajectory points are assigned in combination with the preset threat level. The target prediction trajectory point set and the corresponding confidence weights are combined to generate at least one target prediction path, wherein the target prediction path is used to characterize the target's activity area within a preset time period.
4. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 3, characterized in that, The predicted target path is spatially expanded to obtain the affected area, including: Based on the target prediction trajectory points and corresponding confidence weights in the target prediction path, a target position probability cloud model is constructed within a preset time. The target position probability cloud model is used to characterize the probability distribution of target appearance at spatial discrete units, wherein the spatial discrete units represent grid units generated after the tactical space is gridded based on a preset resolution. Acquire tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information; The tactical constraint set is fused with the target position probability cloud model to reduce the probability of target occurrence in spatial discrete units located in no-fly zones and physically inaccessible areas, and to enhance the probability of target occurrence in spatial discrete units located in preset air routes and terrain-concealed passages, thus obtaining a modified model. The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to the preset confidence threshold. The minimum set of spatial regions can be obtained by clustering spatial discrete units. The spatial outer envelope corresponding to the set of minimum spatial regions is determined as the influence region.
5. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 4, characterized in that, The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to a preset confidence threshold, including: The target occurrence probability of each spatial discrete unit in the modified model is summed in chronological order to obtain the cumulative target occurrence probability value of each spatial discrete unit; Based on the cumulative target occurrence probability value and the confidence threshold, spatial discrete units with a cumulative target occurrence probability value greater than or equal to the confidence threshold are selected as the target activity unit set; Spatial clustering is performed on the target activity unit set to obtain candidate regions. The candidate regions are then geometrically regularized through morphological dilation to obtain the minimum spatial region set.
6. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The service resource library is used to select candidate service objects that fit the spatiotemporal constraints and capability constraints of the affected area, including: Based on the spatial coverage, available time window, and service type information of each service object in the service resource library, the service objects are organized hierarchically to construct a service index tree, wherein the service index tree includes: a first-level node divided by tactical spatial regions; a second-level node divided by available time windows under each first-level node; and a third-level node divided by service type information under each second-level node. Based on the affected region, the service index tree is traversed from top to bottom, and pruning operations are performed on the first-level nodes and their subtrees that do not have spatial intersection with the affected region. Based on the kill chain execution time window, prune the second-level nodes and their subtrees that do not meet the preset time. Based on the capability requirements of the corresponding links in the service-oriented kill chain template, prune the third-layer nodes and their leaf nodes that do not meet the capability constraints. The service objects corresponding to all remaining leaf nodes in the pruned service index tree are summarized and determined as the candidate service objects.
7. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 6, characterized in that, Mapping the candidate service objects to the corresponding kill chain links of the service-oriented kill chain template to determine the current kill chain includes: Based on the mapping results, determine whether the candidate service object completely covers the corresponding service-type kill chain template; If so, the mapping result is processed through redundancy optimization logic, the target service kill chain is selected, and the service object sequence corresponding to the target service kill chain is determined as the current kill chain; If not, the mapping result is reorganized through link completion logic to obtain the current kill chain. The reorganization includes retrieving supplementary service objects from the service index tree for the uncovered kill chain links, adjusting the sequence of candidate service objects and the supplementary service objects to generate alternative service-type kill chains, and determining the service object sequence corresponding to the alternative service-type kill chains as the current kill chain.
8. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 7, characterized in that, The redundancy optimization logic includes: For multiple candidate service objects mapped to the same kill chain link, a performance score is calculated for each according to a preset performance evaluation model, wherein the performance evaluation model generates the performance score based on one or more parameters among detection accuracy, response time, combat radius, reliability and resource consumption; Based on the performance score, multiple candidate service objects are sorted, and the candidate service object with the highest performance score is taken as the service object of the corresponding kill chain link, and the remaining candidate service objects are taken as alternative objects. A link consistency verification is performed on the service object sequence consisting of service objects. If the verification passes, the service object sequence is confirmed as the current kill chain. If the verification fails, local adjustments are made based on alternative objects until the link consistency verification passes.
9. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 7, characterized in that, The link completion logic includes: The kill chain links not covered by candidate service objects in the mapping results are identified, and multiple consecutive uncovered kill chain links are merged into a gap segment to generate one or more gap segments, wherein the gap segment also includes a single kill chain link. For each gap segment, the assigned service objects corresponding to the kill chain links before and after the gap segment are obtained. Based on the start and end times and spatial coverage of the assigned service objects, and combined with the affected area, the completion time constraint window and completion spatial constraint window for the gap segment are determined. In the service index tree, the first-level nodes and their subtrees that have spatial intersection with the completion space constraint window are retrieved to obtain the supplementary service object set for the gap segment; A completion search tree is constructed based on each link of the kill chain within the gap segment. The state of the supplementary service object set is expanded according to the order of the kill chain links. During the state expansion process, the search path is pruned according to time continuity constraints, spatial connectivity constraints, and communication link reachability constraints. Each search path in the current layer is evaluated, and only the top-ranked search paths with the highest comprehensive scores are retained as the starting point for the next layer expansion. The service object sequence with the highest comprehensive performance score is selected from the completion search tree as the completion sequence of the gap segment, and the completion sequence is concatenated with the selected service object sequences before and after the gap segment to generate the corresponding completion link; Combine the complete links corresponding to all missing segments with the service object sequences corresponding to the already covered kill chain links to generate alternative service-type kill chains.
10. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 9, characterized in that, The step of extending the state of the supplementary service object set according to the kill chain sequence includes: In each layer of the completion search tree, the corresponding kill chain link is taken as the current expansion target link. Service objects that match the kill chain link are selected from the set of supplementary service objects, and each selected service object is used as a candidate expansion node to generate the corresponding expansion state. For each extended state, a legality determination is made based on the temporal continuity constraint, spatial connectivity constraint, and communication link reachability constraint between the current extended target link and the service object corresponding to the adjacent determined kill chain link. An extended state that does not meet any of the constraints is pruned. For extended states that pass the legality determination, a comprehensive performance score is calculated based on a comprehensive scoring function constructed according to the target performance weight and resource consumption weight. When the number of extended states that pass the legality determination exceeds a preset threshold, the extended states are filtered for width limitation based on the comprehensive performance score.
Citation Information
Patent Citations
Multi-target killing chain optimization method and device based on combinatorial optimization
CN119443858A
APT killing chain reconstruction and prediction method and system based on causal reasoning
CN119598455A
Method and device for constructing and recommending equipment system adversarial network of dynamic time sequence event
CN121052001A
Service-based killer chain analysis construction method
CN121543455A