A method for constructing an anti-kill chain based on a service-type kill chain
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 未分类(SHANGHAI) TECHNOLOGY CO LTD
- Filing Date
- 2026-02-25
- Publication Date
- 2026-05-29
Smart Images

Figure CN121744719B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of kill chain construction technology, and in particular to a method for constructing an anti-kill chain based on a service-oriented kill chain. Background Technology
[0002] With the development of information-based and system-of-systems warfare, the kill chain is gradually evolving from a fixed process centered on a single piece of equipment to a complex link structure involving multiple platforms and nodes. In existing technologies, the construction of kill chains for target engagement missions typically relies on pre-planned operational procedures or link combinations based on static resource configuration. That is, before the mission begins, a relatively fixed kill chain execution path is determined based on the given target type and available equipment. This type of method can be effective when the target state is stable and operational resources are complete, but its adaptability is significantly limited in complex and dynamic environments.
[0003] On the one hand, existing kill chain construction methods generally rely on direct binding to specific equipment, lacking abstraction and decoupling of equipment capabilities. When some combat equipment is damaged, loses contact, or becomes temporarily unavailable, the original kill chain often cannot continue to execute, and the system struggles to generate alternative links in a timely manner, leading to a decline in overall strike capability or even mission interruption. On the other hand, existing technologies typically base kill chain construction on static spaces or fixed areas, making it difficult to effectively address situations where targets are continuously maneuvering and their trajectories frequently change. The kill chain's response to changes in target position is lagging, resulting in unstable strike effects.
[0004] To address the above issues, this application proposes a method for constructing an anti-kill chain based on a service-oriented kill chain. Summary of the Invention
[0005] The technical problem this application aims to solve is to address the shortcomings of existing technologies by providing a method for constructing an anti-kill chain based on a service-oriented kill chain. This method predicts the target's movement based on real-time status information, obtaining the predicted path within a preset time period. A probabilistic cloud model is then constructed in a three-dimensional tactical space, and the target's influence area is determined after tactical environment constraint correction. Based on this, candidate service objects are selected from a service resource library according to spatial, temporal, and capability constraints. These candidate service objects are then mapped to each link in the kill chain, combined with the target's corresponding service-oriented kill chain template. When capability gaps exist in the template, gap segment identification, local constraint derivation, index tree retrieval, and completion process search are introduced to generate a complete sequence that satisfies the link continuity, thereby constructing an executable anti-kill chain. This method enables rapid reconstruction of the kill chain under conditions of target maneuver, equipment damage, or resource replacement, improving the flexibility and sustained strike capability of the combat system.
[0006] To achieve the above objectives, this application provides the following technical solution:
[0007] A method for constructing an anti-kill chain based on a service-based kill chain is applied to a service-based kill chain anti-kill chain construction system. The anti-kill chain construction system is configured with a service resource library and a kill chain template library, wherein the kill chain template library corresponds to multiple service-based kill chain templates. The method includes:
[0008] Obtain the current state information of the target to be attacked, and predict the target's movement based on the current state information to obtain the target's predicted path;
[0009] The predicted target path is spatially expanded to obtain the affected area, and candidate service objects that are suitable for the spatiotemporal constraints and capability constraints of the affected area are selected from the service resource library;
[0010] Based on the service-oriented kill chain template corresponding to the target to be attacked, the candidate service object is mapped to each kill chain link of the corresponding service-oriented kill chain template to determine the current kill chain.
[0011] The service resource library includes multiple service objects, each of which includes at least one of the following: service type, capability parameters, timeliness parameters, spatial coverage, and mobility characteristics. The steps for constructing a service object include:
[0012] Acquire equipment data for each combat device in the combat system, and perform functional abstraction and service modeling for the combat functions of each combat device to generate service objects that represent the combat functions, including reconnaissance, tracking, command and control, fire strike, and effect evaluation.
[0013] The current state information includes at least one of the target's current position, trajectory, speed, heading, maneuvering mode, and threat level. Target motion prediction based on the current state information includes:
[0014] Based on the target's current position and trajectory, the target's position is predicted through kinematic calculations, resulting in a set of predicted trajectory points.
[0015] Based on speed, heading, and maneuvering mode, the potential movement patterns of the target are determined, and the credibility weights of each target's predicted trajectory points are assigned in combination with the preset threat level.
[0016] The target prediction trajectory point set and the corresponding confidence weights are combined to generate at least one target prediction path, wherein the target prediction path is used to characterize the target's activity area within a preset time period.
[0017] The predicted target path is spatially expanded to obtain the affected area, including:
[0018] Based on the target prediction trajectory points and corresponding confidence weights in the target prediction path, a target position probability cloud model is constructed within a preset time. The target position probability cloud model is used to characterize the probability distribution of target appearance at spatial discrete units, wherein the spatial discrete units represent grid units generated after the tactical space is gridded based on a preset resolution.
[0019] Acquire tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information;
[0020] The tactical constraint set is fused with the target position probability cloud model to reduce the probability of target occurrence in spatial discrete units located in no-fly zones and physically inaccessible areas, and to enhance the probability of target occurrence in spatial discrete units located in preset air routes and terrain-concealed passages, thus obtaining a modified model.
[0021] The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to the preset confidence threshold. The minimum set of spatial regions can be obtained by clustering spatial discrete units.
[0022] The spatial outer envelope corresponding to the set of minimum spatial regions is determined as the influence region.
[0023] The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to a preset confidence threshold, including:
[0024] The target occurrence probability of each spatial discrete unit in the modified model is accumulated and summed according to the time order to obtain the cumulative target occurrence probability value of each spatial discrete unit;
[0025] Based on the cumulative target occurrence probability value and the confidence threshold, spatial discrete units with a cumulative target occurrence probability value greater than or equal to the confidence threshold are selected as the target activity unit set;
[0026] Spatial clustering is performed on the target activity unit set to obtain candidate regions. The candidate regions are then geometrically regularized through morphological dilation to obtain the minimum spatial region set.
[0027] The service resource library is used to select candidate service objects that fit the spatiotemporal constraints and capability constraints of the affected area, including:
[0028] Based on the spatial coverage, available time window, and service type information of each service object in the service resource library, the service objects are organized hierarchically to construct a service index tree, wherein the service index tree includes: a first-level node divided by tactical spatial regions; a second-level node divided by available time windows under each first-level node; and a third-level node divided by service type information under each second-level node.
[0029] Based on the affected region, the service index tree is traversed from top to bottom, and pruning operations are performed on the first-level nodes and their subtrees that do not have spatial intersection with the affected region.
[0030] Based on the kill chain execution time window, prune the second-level nodes and their subtrees that do not meet the preset time.
[0031] Based on the capability requirements of the corresponding links in the service-oriented kill chain template, prune the third-layer nodes and their leaf nodes that do not meet the capability constraints.
[0032] The service objects corresponding to all remaining leaf nodes in the pruned service index tree are summarized and determined as the candidate service objects.
[0033] Mapping the candidate service objects to the corresponding kill chain links of the service-oriented kill chain template to determine the current kill chain includes:
[0034] Based on the mapping results, determine whether the candidate service object completely covers the corresponding service-type kill chain template;
[0035] If so, the mapping result is processed through redundancy optimization logic, the target service kill chain is selected, and the service object sequence corresponding to the target service kill chain is determined as the current kill chain;
[0036] If not, the mapping result is reorganized through link completion logic to obtain the current kill chain. The reorganization includes retrieving supplementary service objects from the service index tree for the uncovered kill chain links, adjusting the sequence of candidate service objects and the supplementary service objects to generate alternative service-type kill chains, and determining the service object sequence corresponding to the alternative service-type kill chains as the current kill chain.
[0037] The redundancy optimization logic includes:
[0038] For multiple candidate service objects mapped to the same kill chain link, a performance score is calculated for each according to a preset performance evaluation model, wherein the performance evaluation model generates the performance score based on one or more parameters among detection accuracy, response time, combat radius, reliability and resource consumption;
[0039] Based on the performance score, multiple candidate service objects are sorted, and the candidate service object with the highest performance score is taken as the service object of the corresponding kill chain link, and the remaining candidate service objects are taken as alternative objects.
[0040] A link consistency verification is performed on the service object sequence consisting of service objects. If the verification passes, the service object sequence is confirmed as the current kill chain. If the verification fails, local adjustments are made based on alternative objects until the link consistency verification passes.
[0041] The link completion logic includes:
[0042] The kill chain links not covered by candidate service objects in the mapping results are identified, and multiple consecutive uncovered kill chain links are merged into a gap segment to generate one or more gap segments, wherein the gap segment also includes a single kill chain link.
[0043] For each gap segment, the assigned service objects corresponding to the kill chain links before and after the gap segment are obtained. Based on the start and end times and spatial coverage of the assigned service objects, and combined with the affected area, the completion time constraint window and completion spatial constraint window for the gap segment are determined.
[0044] In the service index tree, the first-level nodes and their subtrees that have spatial intersection with the completion space constraint window are retrieved to obtain the supplementary service object set for the gap segment;
[0045] A completion search tree is constructed based on each link of the kill chain within the gap segment. The state of the supplementary service object set is expanded according to the order of the kill chain links. During the state expansion process, the search path is pruned according to time continuity constraints, spatial connectivity constraints, and communication link reachability constraints. Each search path in the current layer is evaluated, and only the top-ranked search paths with the highest comprehensive scores are retained as the starting point for the next layer expansion.
[0046] The service object sequence with the highest comprehensive performance score is selected from the completion search tree as the completion sequence of the gap segment, and the completion sequence is concatenated with the selected service object sequences before and after the gap segment to generate the corresponding completion link;
[0047] Combine the complete links corresponding to all missing segments with the service object sequences corresponding to the already covered kill chain links to generate alternative service-type kill chains.
[0048] The step of extending the state of the supplementary service object set according to the kill chain sequence includes:
[0049] In each layer of the completion search tree, the corresponding kill chain link is taken as the current expansion target link. Service objects that match the kill chain link are selected from the set of supplementary service objects, and each selected service object is used as a candidate expansion node to generate the corresponding expansion state.
[0050] For each extended state, a legality determination is made based on the temporal continuity constraint, spatial connectivity constraint, and communication link reachability constraint between the current extended target link and the service object corresponding to the adjacent determined kill chain link. An extended state that does not meet any of the constraints is pruned.
[0051] For extended states that pass the legality determination, a comprehensive performance score is calculated based on a comprehensive scoring function constructed according to the target performance weight and resource consumption weight. When the number of extended states that pass the legality determination exceeds a preset threshold, the extended states are filtered for width limitation based on the comprehensive performance score.
[0052] Compared with the prior art, the beneficial effects of this application are:
[0053] This application achieves adaptive reconfiguration of the kill chain under dynamic target and resource changes by service-oriented approach to combat equipment capabilities and the introduction of a kill chain construction mechanism driven by the target's area of influence. It can filter and complete kill chain links as needed, improving link construction efficiency and continuity, enhancing the flexibility and sustained strike capability of system-of-systems operations, and is suitable for complex and uncertain combat environments. Attached Figure Description
[0054] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0055] Figure 1 An exemplary application scenario diagram provided for an embodiment of this application;
[0056] Figure 2 A schematic diagram of a processor module provided in an embodiment of this application;
[0057] Figure 3 A flowchart illustrating a method for constructing an anti-kill chain based on a service-oriented kill chain, provided in an embodiment of this application;
[0058] Figure 4 This is a schematic diagram of the structure of the service index tree provided in the embodiments of this application;
[0059] Figure 5 This is a schematic diagram illustrating the service index tree pruning principle provided in the embodiments of this application;
[0060] Figure 6 A schematic diagram of the notch segment provided in an embodiment of this application. Detailed Implementation
[0061] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0062] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0063] This application applies to weapon system environments that are geared towards multi-domain collaborative combat systems and organize combat capabilities in a service-oriented manner. It is particularly relevant to application scenarios where targets are highly mobile, combat platforms are diverse, and communication links are susceptible to interference and damage. The application involves dynamically maintaining and reconstructing one's own kill chain and selectively disrupting the target's kill chain. In such scenarios, multiple sources of equipment, including air-based, space-based, sea-based, and ground-based systems, participate in the detection, tracking, and engagement of the same target. The kill chain evolves from a traditional fixed platform-fixed process to a capability service-dynamic orchestration approach. However, in actual operation, it is still inevitably affected by factors such as platform loss, communication interruption, and target penetration maneuvering, making it difficult to maintain the integrity of the kill chain in the long term.
[0064] In exemplary technologies, combat command and control systems typically pre-plan several typical kill chains, statically grouping radar, optoelectronic reconnaissance equipment, command nodes, and fire units according to a process. During wartime, appropriate kill chains are selected from a contingency plan library based on the target threat level and location. Some solutions attempt to introduce a service-oriented approach, abstracting some combat functions into capability modules and combining these modules through centralized or rule-driven methods. However, these methods often assume stable combat unit structures, reliable communication links, and predictable target movement patterns. When facing deliberate counter-kill chain actions by the target or sudden failures of some friendly equipment, it is difficult to promptly assess the availability of remaining capabilities, let alone quickly and rationally reconstruct kill chains under complex spatiotemporal constraints.
[0065] On the one hand, the combat resources involved in the kill chain are diverse in type, dispersed in deployment, and have significant differences in capabilities. Simply relying on human experience or static rules for link selection makes it difficult to exhaustively explore feasible combinations within a limited decision-making time. On the other hand, targets are usually in a state of continuous maneuver. Traditional link design methods based on fixed combat areas or static fire coverage are difficult to accurately cover the spatial paths that targets may take in the future. When targets deviate from the predetermined area or perform evasive maneuvers in complex electromagnetic and spatial environments, the original kill chain is prone to break midway. In addition, there is a lack of a unified modeling framework and executable algorithmic approach for identifying the key links and vulnerable nodes of the target's kill chain at the service level, thereby forming targeted chain-breaking solutions.
[0066] In one typical application scenario, the method described in this application is used to conduct sustained strikes against high-speed, high-value targets in a large-scale, multi-domain joint operations environment. The target party frequently changes its flight path, utilizes terrain and electromagnetic environment to conceal its tracks, and simultaneously suppresses friendly reconnaissance and communication nodes, making it difficult to maintain the integrity of traditional kill chains based on fixed plans. In another typical application scenario, the method described in this application can be used to construct an equivalent model of the target party's service-oriented kill chain. Based on a service perspective, it identifies the key dependencies in target search, target designation, and fire delivery, thereby generating an anti-kill chain scheme to guide friendly command and control chains or fire chains in prioritizing strikes.
[0067] It should be noted that the anti-kill chain construction method based on service-oriented kill chain proposed in this application is not limited to a specific service system or fixed command architecture, but is aimed at a generalized combat scenario with multi-source combat capability service description, target status available, and combat environment with obvious spatiotemporal constraints.
[0068] Understandably, the method proposed in this application stems from an abstract understanding of the essential characteristics of the kill chain:
[0069] A kill chain is not simply a list of equipment, but a capability link composed of a series of combat services that meet temporal, spatial, and capability constraints, arranged in a certain logical order. Once the reconnaissance, tracking, command and control, fire strike, and effect assessment functions of various combat equipment are uniformly abstracted into registerable, discoverable, and orchestratable service objects, and the process is standardized using a service-oriented kill chain template, the sequence of service objects can be automatically filtered and reorganized within the target's predicted path and its area of influence, focusing on the core question of "where, when, and with what capabilities to act on the target," forming a kill chain that meets current operational needs. When the original kill chain is interrupted due to node failure or target escape, this application identifies and partially completes the missing links, optimizes service index retrieval and search tree based on spatiotemporal windows and capability requirements, and rapidly generates alternative links while limiting computational complexity, thereby achieving countermeasures and restoration of the original kill chain at the service layer level.
[0070] It is important to emphasize that the construction of the anti-kill chain is not a global search and reorganization of arbitrary resources or links. Instead, it centers on the dynamic activity trends of the target to be attacked, using the predicted path of the target and the influence area formed by its spatial expansion as the constraint basis for the entire link reconstruction process. The influence area reflects the spatiotemporal range where the target may appear within a preset time and is a key criterion for measuring whether the kill chain can effectively affect the target. Only when a service object can effectively affect the influence area in terms of capability parameters, spatiotemporal coverage, and operational reachability can it enter the candidate stage of the kill chain.
[0071] In other words, this application determines the spatial and temporal windows for executable combat actions based on the target's influence area, and then performs constraint screening, link construction, and gap filling on service resources based on this. When the existing kill chain is disrupted due to target maneuvering beyond its original domain, damage to key nodes, or disruption of link continuity, it can first identify the adaptation deviation between the influence area and the current link, then re-search for service objects that meet the constraints of the defined influence area, and perform gap filling or replacement construction based on the service-oriented kill chain template, thereby generating an anti-kill chain oriented towards the target's current situation.
[0072] refer to Figure 1 , Figure 1 This is an exemplary application scenario diagram provided for an embodiment of this application.
[0073] In typical multi-domain collaborative combat environments, anti-kill chain construction systems are usually deployed at command and control nodes or combat units with edge computing capabilities. These systems are used to generate, adjust, and reconstruct kill chains in highly dynamic, mission-driven scenarios. The system can simultaneously receive status information from multiple combat equipment, sensor platforms, and external intelligence sources, and abstractly manage the combat capabilities of these devices in a service-oriented manner.
[0074] like Figure 1 As shown, the system internally includes a service resource library and a kill chain template library. The service resource library stores various types of combat service objects after capability abstraction, while the kill chain template library stores service-oriented kill chain templates corresponding to different combat missions or target characteristics. Based on the current mission requirements, target status, and available service objects, the processor generates, filters, completes, and reconstructs the service-oriented kill chain, outputs the final execution plan of the current kill chain or counter-kill chain, and transmits it to the controller for controlled strike.
[0075] In a specific implementation not shown in the figure, the target to be attacked is in a continuous maneuvering state, and its position, trajectory, speed, and maneuvering mode are continuously updated by reconnaissance resources and input to the processor. The processor predicts the future movement trend of the target based on its state and determines the spatial activity area that the target may pass through within a preset time window as the area of influence. Subsequently, the processor filters candidate service objects that can act on the area of influence from the service resource library, and maps and arranges these candidate service objects into the current kill chain according to the process structure in the kill chain template library.
[0076] refer to Figure 2 , Figure 2 A schematic diagram of a processor module provided in an embodiment of this application.
[0077] Figure 2 The processor shown includes:
[0078] The path prediction module receives the current state information of the target to be attacked and calculates the target's future movement trend based on the state information. The path prediction module analyzes the target's current position, speed, heading, and maneuvering mode to generate a predicted path for the target. It can further combine this with confidence weights to form multiple possible trajectories of the target within a preset time period, reflecting the target's maneuvering uncertainty in the future time domain.
[0079] The region segmentation module, based on the target prediction path output by the path prediction module, uses spatial expansion calculations to form the target's influence area. This module can spatially correct the predicted path based on probabilistic cloud models, tactical environmental constraints, and external factors such as terrain, no-fly zones, and communication obstruction zones, determining the potential spatiotemporal range of the target. This influence area serves as a core constraint in kill chain construction, limiting the service area of the target and thus preventing ineffective operational resources from participating in link reconstruction.
[0080] The kill chain construction module, under the constraints of the influence area provided by the region division module, selects candidate service objects from the service resource library that meet spatiotemporal and capability constraints, and maps, arranges, and combines these candidate service objects based on the kill chain template library. This module not only constructs complete service-oriented kill chains within the influence area, but also performs gap identification, local completion, and alternative link search when missing links exist. Through width-limited search, pruning rules, and effectiveness scoring mechanisms, it generates anti-kill chains that meet the current situation, ensuring that effective operational links are maintained even when targets evade maneuver or friendly nodes are damaged.
[0081] Next, with reference to the accompanying drawings, a method for constructing an anti-kill chain based on a service-oriented kill chain, as provided in an embodiment of this application, will be further described. Figure 3 The method shown is applied to an anti-kill chain construction system, which is configured with a service resource library and a kill chain template library. The kill chain template library corresponds to multiple service-type kill chain templates. The method includes:
[0082] S1: Obtain the current state information of the target to be attacked, and predict the target movement based on the current state information to obtain the target prediction path;
[0083] In this embodiment, the target's current position, speed, trajectory, heading, and maneuvering mode, among other operational data, can be dynamically collected based on the reconnaissance capabilities of the combat equipment. The type and accuracy of the current status information can be selected according to usage requirements, as long as it can support the prediction of the target's future movement trend.
[0084] By performing time-series analysis on the target's state characteristics and constructing a credibility distribution based on the target's possible evasion strategies, the predicted path not only includes a single deterministic path but also reflects the target's potential activity trends under different maneuvering assumptions. This significantly improves the effectiveness of subsequent spatiotemporal constraint screening and avoids the lag or failure of kill chain construction caused by the over-reliance on instantaneous position in traditional methods.
[0085] S2: Spatially expand the target prediction path to obtain the influence area, and select candidate service objects from the service resource library that are adapted to the spatiotemporal constraints and capability constraints of the influence area;
[0086] In this embodiment, the spatial expansion process centers on the target prediction path and is corrected based on constraints in the operational environment, such as terrain obscuring, no-fly zones, physically inaccessible areas, and key reconnaissance corridors. This ensures that the affected area covers both the actual locations the target might reach and reflects the limitations imposed by the mission environment on the deployment of operational resources. The role of the affected area is to limit the selection of service objects to those with a practical possibility of impacting the target. Compared to traditional full-domain retrieval methods, this significantly reduces the participation of ineffective resources and improves link construction efficiency. Subsequently, by matching the affected area with service objects in terms of spatial coverage, available time windows, and functional categories, a set of candidate service objects is formed. Service objects can be abstracted based on factors such as the equipment's detection range, fire radius, and communication link conditions. Their specific attributes are determined by the actual equipment capabilities. As those skilled in the art will understand, these attributes can be flexibly expanded according to the performance of different combat units.
[0087] S3: Based on the service-oriented kill chain template corresponding to the target to be attacked, map the candidate service object to each kill chain link of the corresponding service-oriented kill chain template to determine the current kill chain;
[0088] In this embodiment, when mapping candidate service objects to the template stage, the allocation is not static based on equipment type, but dynamically bound based on capability attributes and spatiotemporal accessibility. This ensures that each stage is covered by service objects capable of actually performing combat actions. During this process, if some stages fail to be mapped successfully, they are marked as gaps in subsequent link completion, providing the necessary prerequisites for constructing the anti-kill chain. The current kill chain constructed in this way can accurately map the available combat resources under the target's current situation, making the chain a capability sequence that can adaptively adjust with environmental changes, rather than a fixed combination of equipment in the traditional sense. This embodiment adopts a service-oriented orchestration approach, making the chain more flexible, thus providing greater feasibility and directionality for subsequent completion and reconstruction in the event of target maneuvering or equipment damage.
[0089] Before detailing the specific technical aspects of the steps, this application's embodiments need to reiterate:
[0090] This embodiment does not treat the generation and reconstruction of service-oriented kill chains as isolated processes, but rather as a means of dynamic capability orchestration in an environment with constantly changing spatiotemporal constraints. Unlike traditional link construction methods centered on fixed combat procedures or equipment resources, this application focuses on the activity space that the target may reach in the future, and the set of service objects that can continuously generate combat effects within that space. The construction and deconstruction process of the kill chain unfolds under these dynamic regional constraints.
[0091] In actual execution, the link does not have a predetermined, unique structural direction. Instead, it continuously adjusts as the target's movement trend updates, the status of service objects changes, and environmental constraints evolve. For a target at any given moment, the service objects that can influence its behavior exhibit distinct regional characteristics. For example, fire units may not be able to cover the entire space due to range limitations, reconnaissance nodes may be temporarily disabled due to terrain obstructions, and command and control nodes may be unavailable due to poor communication conditions. When these changes cause certain links in the original link to lose continuity, a functional gap appears in the link. The anti-kill chain construction method adopted in this embodiment revolves around the identification, constraint extraction, and capability completion of this gap.
[0092] In this embodiment, to ensure the rationality of link reconstruction, the future reachable area must first be determined by spatiotemporally characterizing the target behavior. This area is not a static boundary, but a dynamic spatial set formed by predicted paths with different levels of confidence. Based on this spatial set, a class of capability requirements with common characteristics can be extracted, namely, service capabilities that can effectively affect the target within this area. Subsequently, through dual screening using capability models and time windows, a set of service objects that can be used for replacement can be obtained. Unlike the traditional replacement method based on category or platform, the replacement process in this embodiment emphasizes the functional continuity and spatiotemporal coherence within the link, ensuring that the generated link not only connects missing links but also maintains overall logical closure with the preceding and following links.
[0093] Furthermore, when performing alternative combinations of service objects, the aim is not to exhaustively enumerate all possible configurations, but rather to treat it as a search process under multiple constraints. The combination behavior of each service object in the link manifests as a state continuity problem. This embodiment imposes multi-layered constraints on the directionality, reachability, and capability matching conditions of state expansion, enabling the expansion path to converge to a link sequence that meets the requirements within an acceptable computational load. Finally, to avoid combinations that are formally feasible but tactically ineffective, the embodiment uses an effectiveness evaluation model to discriminate among the generated candidate links, ensuring that the final determined links maintain a relative balance between operational effectiveness and resource consumption.
[0094] Next, we will further elaborate on the technical content of the service resource library in this application.
[0095] It is understood that the service resource library described in this application is not a resource collection classified by platform, equipment or static node in the traditional sense, but a capability-based service collection formed by abstracting the functional capabilities of various equipment in the combat system.
[0096] In actual deployment, each service object in the service resource library corresponds to a certain combat action that a certain equipment can perform under specific conditions. Its form can be reconnaissance service, tracking service, command and control service, fire strike service, or effect assessment service, etc.
[0097] Those skilled in the art will understand that, in order to support dynamic link construction, the service object is not limited to a specific equipment model. Specific attributes such as spatial coverage, capability parameters, response time, and combat radius can be updated in real time according to the equipment's operating status. As long as the basic capability description requirements are met, this application does not impose too many restrictions on this.
[0098] In one example, each service object includes at least one of the following: service type, capability parameter, timeliness parameter, spatial coverage, and mobility characteristic, wherein:
[0099] These attributes of a service object describe its capabilities in a real combat environment and its feasibility under spatiotemporal conditions. Service type typically characterizes the functional role of the service object in the kill chain, such as performing reconnaissance, tracking, command and control, fire strikes, or effects assessment. It is essentially an abstraction of mission function, rather than a limitation on equipment name or physical form. Capability parameters reflect the operational effectiveness of the service object and may include numerical descriptions related to capability strength, such as detection accuracy, range, weapon payload, and data link bandwidth, used for effectiveness-level selection among multiple candidate objects.
[0100] The timeliness parameter describes whether the service object can complete the task within a preset time, including response latency, sustained action time, and the start and end times of the available window. These parameters are not fixed values but can be updated as equipment status or task load changes, as long as they reflect executability during the link orchestration phase. The spatial coverage range describes the scope of the service object's action in physical space, such as the detection sector of a sensor, the range envelope of a fire unit, or the effective link coverage area of a communication node. Its role is to ensure that each link in the generated kill chain can truly affect the target's area of influence.
[0101] Mobility characteristics are typically used to reflect the mobility of service objects themselves. For example, drones, ships, or mobile launch platforms can participate in the action by changing their position. These characteristics are particularly important in the link completion phase because some service objects that were not originally in the area of influence may enter the area of influence through their mobility, thus becoming alternative nodes.
[0102] In yet another example, the steps for constructing a service object include:
[0103] Acquire equipment data for each combat device in the combat system, and perform functional abstraction and service modeling for the combat functions of each combat device to generate service objects that represent the combat functions, including reconnaissance, tracking, command and control, fire strike, and effect evaluation.
[0104] In this embodiment, the kill chain template library described in this application can be understood as a set of standardized capability link models formed after abstracting the process requirements of different combat missions. Unlike traditional combat plan libraries that are pre-configured only according to target type or weapon platform, the templates here are not directly bound to a specific equipment combination. Instead, they are based on the capability requirements of each link in the kill chain, abstracting the corresponding combat links of detection, location, tracking, designation, strike, and assessment into a series of capability nodes with clear input-output relationships and spatiotemporal constraints. Each template can be regarded as a general description of the combat process under specific mission assumptions, target characteristics, and combat environment. For example, for high-speed air targets, low-speed small targets, sea-mobile targets, or important fixed targets, the configuration order of links, capability requirements, and timing constraints included in different templates may vary, but their common point is that they all organize the link structure in a way that uses service type and capability constraints.
[0105] Furthermore, the kill chain template library can pre-store various service-oriented kill chain templates, which can be differentiated based on mission type, target threat level, engagement domain type, or combat style. Each link in the template only specifies the type of combat service required and its minimum capability threshold, such as requirements for detection range, accuracy, reaction time, or anti-jamming capabilities, without specifying which particular equipment should provide the service. Thus, in actual operation, based on the characteristics of the target and the current tactical intent, one or more suitable service-oriented kill chain templates can be selected from the template library, and then specific service objects can fill in the various links in the template to form the corresponding current kill chain. For anti-kill chain construction, the template library provides a unified reference framework, enabling the identification of which capability links are not effectively covered when the link is interrupted or a node fails, allowing for targeted searching for supplementary nodes in service resources, rather than blindly replacing equipment.
[0106] Those skilled in the art will understand that the content of the kill chain template library is not limited to a fixed number or structure. It can be gradually improved based on operational doctrine, empirical data, or tactical simulation results. The templates can also include priority weights, alternative links, or optional branches to support parallel evaluation and selection of multiple chains. This application only requires that the template library provide a structured description of the kill chain links at the capability level, clearly characterizing and solving questions such as whether the target can be completely covered within its area of influence, which links have capability gaps, and whether alternative combinations meet overall operational constraints. No further limitations are placed on the specific size and storage format of the template library.
[0107] Next, we will further elaborate on the technical content of the method for predicting target motion in this application.
[0108] In one example, the current status information includes at least one of the target's current position, track, speed, heading, maneuvering method, and threat level. In this embodiment, the acquisition of this status information is not limited to a specific sensing method, but is determined by operational conditions and available resources, as long as the minimum input requirements to support prediction are met.
[0109] The target's current location is usually obtained by reconnaissance resources with real-time measurement capabilities, such as electro-optic sensors, radar ranging points, or other remote sensing methods. The output data can be in the form of three-dimensional coordinates or geographic location calibration.
[0110] Those skilled in the art will understand that the location does not need to be absolutely precise; it only needs to reflect the instantaneous spatial location of the target.
[0111] Track information can be derived from observation points over a period of time or from reconnaissance equipment with track extraction capabilities, forming the target's historical motion curve through continuous sampling.
[0112] Target speed and heading can generally be derived from changes in position over time, for example, by calculating based on the displacement and time intervals of continuous observation points, or by directly using the raw output data of some sensors (such as speed radar).
[0113] Maneuvering patterns typically reflect a target's movement patterns over a short period, such as stable cruising, evasive maneuvers, acceleration, and serpentine maneuvers. This information can be inferred from the platform's trajectory change characteristics or identified by a behavior discrimination model formed by fusing multiple sensor sources. This embodiment does not require precise classification of maneuvering patterns; it only needs to roughly express the target's maneuvering trends so that the predicted path can cover potential uncertainties.
[0114] Threat levels can be automatically generated based on intelligence data, target type identification, or their behavioral characteristics. They are used to reflect the importance or potential for attack of a target. The specific calculation method can be set by the mission rules, and this application does not impose any restrictions on it.
[0115] In another example, when predicting target motion based on current state information, the target's short-term future position can be estimated first based on its current position and historical trajectory. To achieve this, the target's previous observation positions can be discretely sampled, and a time-series model reflecting the target's motion trend can be constructed by calculating the velocity and acceleration vectors of adjacent observation points. This model can employ a kinematic extrapolation method with a fixed time step, using the current velocity and heading as initial predictions and recursively calculating the future reference position within a preset time step; alternatively, a state estimation method based on polynomial fitting, Kalman filtering, or extended Kalman filtering can be used to ensure that the extrapolation results maintain high smoothness and stability even under noise disturbances. Through the above calculations, a set of predicted trajectory points continuously distributed over time can be obtained, with each trajectory point corresponding to the target's potential position at a future time.
[0116] In further processing, a set of motion patterns can be established based on the target's speed, heading, and maneuvering method to reflect the different maneuvering behaviors the target may take. In practical engineering implementation, motion patterns can be categorized into stable flight, linear acceleration, sharp turn evasion, and serpentine evasion, with each category defined by different dynamic equations or steering angle variation models. For each motion pattern, different offsets or acceleration fields can be applied to the predicted trajectory point set based on the current state, allowing the predicted trajectory to cover a wider range of maneuvering possibilities. Furthermore, different confidence weights can be assigned to each predicted trajectory point according to the target's threat level. For example, high-threat targets are more likely to take evasive maneuvers, so the weight of their corresponding evasive mode predicted points can be increased accordingly, thus obtaining a higher spatial proportion in subsequent impact area calculations.
[0117] Those skilled in the art will understand that the method of setting the credibility weight can be adjusted according to actual tactical rules, historical experience or model training results, and this application does not limit it.
[0118] In the comprehensive processing stage, predicted trajectory points generated under multiple motion modes can be fused with their corresponding confidence weights to form at least one predicted path through probability superposition or weighted clustering. The predicted path can be obtained through maximum likelihood trajectory estimation, center path extraction, or mean trajectory calculation based on a Gaussian mixture model. This path describes the spatial distribution center of the target's future activity area, providing fundamental support for subsequent construction of probabilistic cloud models and influence regions.
[0119] Next, we will further elaborate on the technical content of the method of this application regarding the affected area.
[0120] It should be noted that the area of influence described in this application is not a simple two-dimensional projection area, but rather a volume of potential target activity constructed in three-dimensional geographic space. The three-dimensional geographic space can be defined based on the geographic coordinate system of the operational area, terrain elevation models, and airspace hierarchical structure. Each discrete spatial unit corresponds to a three-dimensional grid voxel with fixed length, width, and height, used to accurately characterize the possible location range of the target in space. In engineering implementation, a unified reference coordinate system can be established for the three-dimensional geographic space, such as geographic coordinates, BeiDou coordinates, or tactical coordinate systems, ensuring a consistent spatial reference basis throughout the entire process from sensor input to predicted path and spatial expansion.
[0121] In one example, the spatial expansion of the predicted target path yields the affected area, including:
[0122] S2.1: Based on the target prediction trajectory points and corresponding confidence weights in the target prediction path, construct a target position probability cloud model within a preset time. The target position probability cloud model is used to characterize the probability distribution of target appearance at spatial discrete units, wherein the spatial discrete units represent grid units generated after the tactical space is gridded based on a preset resolution.
[0123] Specifically, under conditions of high target mobility and noise and incompleteness in reconnaissance observation, relying solely on one or more deterministic predicted trajectories is insufficient to accurately reflect the target's activity range within a predetermined timeframe. The predicted path itself is often merely a trend line, while the target undergoes various perturbations around this trend during actual movement. Therefore, it is necessary to introduce a spatial distribution model that reflects the probability of target occurrence, allowing for the assignment of different importance levels to different spatial locations in subsequent processing. By transforming discrete predicted trajectory points into probability distributions in a three-dimensional grid space, complex trajectory uncertainties can be uniformly encoded into a target location probability cloud. This facilitates computation and overlay with information such as tactical environment constraints and service coverage areas within a unified data structure, thereby avoiding the complexity of point-by-point processing of individual trajectories in subsequent steps.
[0124] In this embodiment, the tactical space is first processed into a three-dimensional mesh according to a preset spatial resolution, discretizing the combat area into a spatial volume composed of multiple mesh cells. Each predicted target trajectory point is mapped to a corresponding mesh cell based on its three-dimensional coordinates, and the probability of target occurrence in that mesh cell is cumulatively updated by combining the confidence weight of the trajectory point. For example, when multiple predicted trajectory points fall into adjacent mesh cells within the same time period, corresponding weights can be superimposed on these mesh cells respectively, so that the target position probability cloud shows a high probability concentration trend in that area. In addition, strategies such as time decay, path smoothing, or local neighborhood diffusion can be introduced to give mesh cells closer to the predicted path a certain probability compensation, so that the probability cloud is not limited to the single mesh where the trajectory point is located, but expands into a small space distributed around the trajectory point. In this way, within a preset time period, each mesh cell will gradually form a complete probability distribution based on the number of trajectory point projections, weight magnitude, and temporal relationship, which is used to characterize the probability of target activity in three-dimensional space.
[0125] S2.2: Obtain tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information;
[0126] Specifically, a target's operational range in the battlefield environment is not solely determined by its mobility, but is also constrained by a variety of tactical factors, including terrain undulations, no-fly zones, air defense coverage, and communication blind spots. Spatial extrapolation based solely on the target's kinematic characteristics often yields spatially unreachable or unreasonable areas in the actual environment, hindering the subsequent precise selection of usable zones.
[0127] In this embodiment, tactical environmental constraint information can originate from various data sources, including but not limited to digital terrain elevation data, no-fly zone designation results, radar or air defense fire coverage areas, transportation corridors and airway networks, important deployment areas of both friendly and target forces, and communication and navigation support areas. For terrain data, areas that are inaccessible or have height restrictions, such as mountains and densely built-up areas, can be marked as physically inaccessible areas. For no-fly zones and restricted areas, the corresponding spatial areas can be marked as restricted areas according to mission requirements. For airways and canyon passages, they can be marked as priority passage or high-probability passage areas. After coordinate system one and resolution transformation, all of the above constraint information is mapped onto a three-dimensional grid identical to the target location probability cloud, assigning corresponding labels or attribute values to each type of constraint, thereby forming a tactical constraint set containing multiple constraint categories.
[0128] S2.3: Perform constraint fusion processing on the tactical constraint set and the target position probability cloud model to attenuate the target occurrence probability of spatial discrete units located in no-fly zones and physically inaccessible areas, and enhance the target occurrence probability of spatial discrete units located in preset air routes and terrain concealment channels to obtain a modified model;
[0129] Specifically, the target location probability cloud model reflects the possible location distribution of a target in an ideal space based on its own maneuverability, but it does not consider the influence of tactical constraints. Without correcting the probability cloud, the model might assume a high probability of the target appearing above densely defended ground areas or traversing obviously inaccessible obstacle zones, which does not align with actual tactical behavior. Therefore, it is necessary to fuse the set of tactical constraints with the target location probability cloud to suppress or increase the probability of the target appearing in certain areas, thus making the corrected spatial distribution more consistent with the action paths the target might take in a real battlefield environment. This fusion process essentially involves a spatial redistribution of the probability cloud, weakening the probability in unreasonable areas and encouraging targets to cluster in reasonable and accessible areas.
[0130] In this embodiment, constraint fusion processing can be achieved by traversing each grid cell one by one and querying its corresponding constraint type in the tactical constraint set. For grid cells marked as no-fly zones or physically inaccessible areas, such as inside high mountain terrain, permanent no-fly airspace, or inside ground building entities, their probability of appearance in the target location probability cloud can be significantly reduced or directly set to zero. For areas such as preset flight paths, canyon passages, and terrain-concealed passages, the original probability can be amplified or kept unchanged, so that the target location probability concentrates towards these reasonable passage paths. For grid cells affected by multiple constraints simultaneously, various constraints can be comprehensively processed according to pre-set weights to obtain a comprehensive adjustment factor to correct the original probability.
[0131] S2.4: Perform cumulative probability calculation on the modified model to determine the minimum set of spatial regions where the cumulative probability of the target occurrence is greater than or equal to a preset confidence threshold within the preset time period, wherein the minimum set of spatial regions can be obtained by clustering spatial discrete units;
[0132] Specifically, after completing the tactical constraint fusion, each grid cell in the corrected model corresponds to a probability value of a target appearing at that location. If the entire probability cloud is used directly as the area of influence, the area of influence will be too large, containing a large number of areas with extremely low probabilities, which is not conducive to the subsequent targeted screening of service targets.
[0133] In this embodiment, all grid cells can be sorted or classified according to their probability values in the modified model, and their probability values can be accumulated starting from the grid cells with higher probabilities. When the accumulated probability value reaches or exceeds a preset confidence threshold, all grid cells participating in the accumulation are marked as the core region set, while the remaining grid cells with lower probabilities can be regarded as edge regions or low-interest regions. In order to organize these discrete high-probability grid cells into regions with spatial continuity, a clustering method based on spatial adjacency can be used to group grid cells that are adjacent to each other and have high probability values into one or more connected regions. During the clustering process, parameters such as the minimum number of connected units and spatial distance thresholds can be set to avoid the formation of fragmented regions with no practical significance due to isolated high-probability units.
[0134] In one example, cumulative probability calculation is performed on the modified model to determine the smallest set of spatial regions where the cumulative probability of the target occurrence is greater than or equal to a preset confidence threshold within the preset time period, including:
[0135] The target occurrence probability of each spatial discrete unit in the modified model is accumulated and summed according to the time order to obtain the cumulative target occurrence probability value of each spatial discrete unit;
[0136] Based on the cumulative target occurrence probability value and the confidence threshold, spatial discrete units with a cumulative target occurrence probability value greater than or equal to the confidence threshold are selected as the target activity unit set;
[0137] Spatial clustering is performed on the target activity unit set to obtain candidate regions. The candidate regions are then geometrically regularized through morphological dilation to obtain the minimum spatial region set.
[0138] Specifically, the tactical space has been discretized into three-dimensional discrete units. Candidate regions formed after clustering target activity units often exhibit jagged boundaries, narrow local channels, or minor fractures at the voxel level. This increases complexity in subsequent calculations of the spatial envelope and determination of service coverage relationships. Therefore, it is necessary to perform appropriate geometric expansion and filling on the candidate regions while maintaining the overall outline and spatial distribution characteristics. This reduces internal holes, thickens local elongated structures, and widens narrow gaps between one or several voxels, thus facilitating the approximation of the envelope using regular geometry.
[0139] In this embodiment, the spatial discrete units corresponding to each candidate region can be constructed as a three-dimensional binary raster mask. Spatial discrete units belonging to the candidate region are marked as valid units, and the remaining units are marked as invalid units. Based on this binary raster, a type of structural element suitable for three-dimensional space is selected as the dilation template. This structural element can be a cubic neighborhood centered on a single raster unit, or a set of neighborhoods approximating a sphere around the central unit. The radius or side length of the structural element can be set according to the spatial resolution and the expected smoothness of the region. During morphological dilation, the structural element is slid point-by-point in the three-dimensional raster. For each currently valid unit position, all units within the coverage area of its structural element are marked as candidate valid units, thereby expanding one or more raster units outward from the boundary of the original candidate region. By repeating the dilation operation one to several times, small holes inside the candidate region can be filled in space, and narrow, elongated connecting channels can be expanded, transforming a thin bridge region originally connected by a single raster unit into a continuous strip-shaped region composed of multiple raster units.
[0140] Furthermore, to prevent the expansion process from causing uncontrolled outward diffusion of the region, constraints can be introduced during implementation. For example, the expansion result can only be allowed to fall within the spatial range where the probability value is not zero in the previously modified model, or the number of expansions can be limited to a preset iteration limit. This ensures that geometric regularization only works near the candidate region boundary and does not intrude into the distant space that should not belong to the target activity area. For multiple candidate regions that are close to each other but not fully connected, an expansion threshold can be set to naturally merge regions with a center-to-center distance of less than a certain number of grid cells during the expansion process, thereby regularizing multiple fragmented small regions into a larger region with greater engineering significance. After morphological expansion, the resulting set of minimum spatial regions is represented on the 3D grid as a set of voxels with smooth boundaries, good internal connectivity, and few holes. This facilitates subsequent calculation of its spatial envelope and geometric operations such as intersection and inclusion with the spatial coverage of the service object.
[0141] Those skilled in the art will understand that the specific shape of the structural elements, the number of expansions, and the constraints can be adjusted according to the task scenario and spatial resolution, as long as the geometric regularity can be improved while ensuring the realism of the region representation. This application does not impose any further limitations in this regard.
[0142] S2.5: The spatial outer envelope corresponding to the set of minimum spatial regions is determined as the influence region;
[0143] Specifically, the minimum spatial region set is a set of discrete connected regions obtained by filtering and clustering high-probability grid cells. These regions may have complex boundaries and irregular shapes in three-dimensional space. Directly using these discrete regions as spatial constraints for subsequent service matching and link construction would increase computational and geometric complexity in engineering implementation, especially when frequent determinations are needed regarding the intersection of service coverage areas and affected areas. Therefore, this set needs to be geometrically regularized, abstracting its boundaries into a more computationally friendly spatial envelope. This makes it easier to determine, store, and transmit affected areas in subsequent algorithms, while still maintaining a reasonable approximation of the target activity space.
[0144] In this embodiment, an appropriate outer envelope construction method can be selected based on the spatial distribution characteristics of the minimum spatial region set. For a single connected region with a relatively concentrated distribution, a three-dimensional convex hull or approximate convex hull method can be used to construct the outer envelope, encompassing all internal mesh units within a polyhedral region. For a region set exhibiting multiple branches or island-like structures, a local outer envelope can be constructed for each connected component, and if necessary, several adjacent outer envelopes can be merged into a larger envelope through spatial union operations. The outer envelope does not need to completely coincide with the original region boundary; it only needs to completely cover the minimum spatial region set in space to serve as a geometric approximation of the affected region.
[0145] Next, we will further elaborate on the technical content of the method of this application regarding the candidate service objects.
[0146] refer to Figure 4 , Figure 4 This is a schematic diagram of the service index tree structure provided in an embodiment of this application.
[0147] like Figure 4 As shown, the service index tree is a four-layer structure including a root node, first-layer nodes, second-layer nodes, and third-layer nodes. The root node serves as the aggregation entry point of the index tree and does not carry specific service retrieval conditions; it is only used to organize the topological relationships of the lower-layer nodes.
[0148] The first-level nodes include three nodes: First-Level Node 1, First-Level Node 2, and First-Level Node 3. These three nodes correspond to different spatial regions obtained after dividing the tactical space, such as different airspace sectors, different geographical zones, or different altitude layers. This division method allows for the access of only the first-level nodes that spatially intersect with the target's influence area during spatial filtering, thus avoiding indiscriminate traversal of the entire service resource set.
[0149] The second-level nodes include nodes one through five, each belonging to a different first-level node. These nodes are used to further subdivide the available time windows of service objects within the corresponding spatial region. For example, a first-level node can be configured with second-level nodes one and two, representing the sets of service objects that can participate in combat at different times within the spatial region; a first-level node can be configured with second-level nodes three, four, and five, representing another set of time divisions within the spatial region. In this way, when retrieving service objects, the kill chain execution time window can be combined, and the search can be performed only within the second-level nodes and their subtrees that overlap with that time window, thus effectively reducing service resources in the time dimension.
[0150] The third-level nodes include third-level nodes one through four, representing different service types or capability categories within the corresponding spatial region and time window, such as reconnaissance services, tracking services, command and control services, and firepower services. Each third-level node can be associated with one or more specific service objects, which constitute the leaf nodes of the service index tree and are selected as candidate service objects when spatial, temporal, and capability constraints are met.
[0151] In one example, candidate service objects adapted to the spatiotemporal constraints and capability constraints of the affected area are filtered from the service resource library, including:
[0152] Based on the spatial coverage, available time window, and service type information of each service object in the service resource library, the service objects are organized hierarchically to construct a service index tree, wherein the service index tree includes: a first-level node divided by tactical spatial regions; a second-level node divided by available time windows under each first-level node; and a third-level node divided by service type information under each second-level node.
[0153] Based on the affected region, the service index tree is traversed from top to bottom, and pruning operations are performed on the first-level nodes and their subtrees that do not have spatial intersection with the affected region.
[0154] Based on the kill chain execution time window, prune the second-level nodes and their subtrees that do not meet the preset time.
[0155] Based on the capability requirements of the corresponding links in the service-oriented kill chain template, prune the third-layer nodes and their leaf nodes that do not meet the capability constraints.
[0156] The service objects corresponding to all remaining leaf nodes in the pruned service index tree are summarized and determined as the candidate service objects.
[0157] refer to Figure 5 , Figure 5 This is a schematic diagram illustrating the service index tree pruning principle provided in the embodiments of this application.
[0158] Figure 5 by Figure 4 Taking the service index tree as an example, this illustrates that when actually filtering candidate service objects, it is not necessary to perform a complete traversal of the entire service index tree. Instead, based on the affected area, the preset time window, and the capability requirements of the kill chain template, each level of nodes is pruned sequentially to exclude subtrees that do not meet the constraints. In the figure, the dashed boxes represent the pruned subtrees, and the curved arrows indicate the constraint propagation direction from top to bottom during the pruning process.
[0159] like Figure 5 As shown, first-layer nodes one and two have no spatial intersection with the affected area. Therefore, the subtrees rooted at first-layer nodes one and two cannot provide service objects that can act on the target's affected area. This is because first-layer nodes one and two correspond to tactical space partitioning. Once the spatial range of this node does not overlap with the affected area at all, none of the service objects in its subtrees can spatially cover the target. Figure 5 The text uses a dotted line to indicate that the entire subtree was cut off.
[0160] After performing the same operation on the remaining layers, the final subtrees are: first layer node 3, second layer node 3, and third layer node 2. Therefore, the service objects in the leaf nodes corresponding to third layer node 2 can be used as candidate service objects.
[0161] Understandable, Figure 5 The pruning process shown is only intended to demonstrate an exemplary node removal result, illustrating the basic behavior of the service index tree after being progressively shrunk by spatial, temporal, and capability constraints. In practice, when the tactical space is more finely divided based on elevation, sector, or geographic grid, the number of nodes in the first layer may increase significantly; when the task involves spanning a longer time scale or requires capability matching in smaller time slices, the number of nodes in the second layer will also expand accordingly; the classification of service types can also be refined according to different architectures, resulting in different numbers of nodes in the third layer.
[0162] Next, we will further elaborate on the technical aspects of the method in this application regarding the determination of the current kill chain.
[0163] It is understood that, in the premises of this application, each target to be attacked corresponds to one or more service-oriented kill chain templates. The specific method for searching the kill chain template library based on the target can be achieved through matching rules based on target attribute information, template indexing methods based on task type, or template selection strategies based on threat level. For example, the set of templates most closely matching the target can be located in the template library based on factors such as target classification, platform type, mobility, target threat level, or the mission scenario. Those skilled in the art can select appropriate retrieval mechanisms based on system configuration and task flow; therefore, this application does not impose any limitations on this method.
[0164] In one example, the candidate service object is mapped to each link of the corresponding service-based kill chain template to determine the current kill chain, including:
[0165] S3.1: Determine whether the candidate service object completely covers the corresponding service-type kill chain template based on the mapping result;
[0166] In one example, after initially mapping candidate service objects to the service-based kill chain template, it's necessary to first determine whether each kill chain link has at least one matching available service object. This determination essentially verifies the coverage relationship between the template link list and the service mapping results. Specifically, the predefined link sequence in the template can be treated as a set of ordered capability slots, maintaining a covered / covered flag field for each slot. After matching the capabilities of candidate service objects, service objects that meet the corresponding capability constraints and the constraints of the influence area and time window are attached to the relevant slots, and the slot is marked as covered. If no matching service object is found in a slot, it is marked as uncovered. The template coverage can be obtained by traversing the entire template link sequence.
[0167] This embodiment will now use a service-oriented kill chain template, F2T2EA, as an example. F2T2EA specifically consists of Find, Fix, Track, Target, Engage, and Assessment, representing reconnaissance, location, tracking, command, strike, and evaluation. During the initial mapping process, corresponding capability slots can be established for each of the six stages. For example, the Find stage corresponds to the detection and search capability slot, the Fix stage to the location accuracy and duration capability slot, the Track stage to the continuous tracking and trajectory update capability slot, the Target stage to the command and control and task allocation capability slot, the Engage stage to the firepower delivery capability slot, and the Assessment stage to the battlefield effect evaluation capability slot. Candidate service objects, provided they meet their capability constraints, spatial coverage, and time window requirements, can be attached to the corresponding slots.
[0168] In some optional implementations, when determining coverage, it is necessary not only to confirm that each slot has at least one service object that meets the capability matching requirements, but also to further consider the feasibility of execution connections between different stages. For example, suppose an unmanned reconnaissance platform can be used in the Find stage, and a ground fire unit can be used in the Engage stage. However, if there is a significant temporal misalignment between the two within the target activity window, or if the detectable area of the reconnaissance platform and the firing range of the fire unit cannot form an effective spatiotemporal link within the affected area, then although these two service objects can each cover their respective stages, they cannot form a continuously executable kill chain. In this case, although the Find stage is in a covered state, it is still necessary to record potential breakpoints at the link level so that they can be considered when determining whether to enter the completion process in subsequent steps.
[0169] Furthermore, in certain situations, the template stage may have multiple tactically equivalent capability configurations. For example, in some rapid suppression missions, the Fix and Track stages can be completed consecutively using the same equipment. In this case, the system can merge these two capability slots. As long as a service object has the capability to cover both capability slots simultaneously, both stages are considered covered. Similarly, in the Assessment stage, different assessment methods such as image assessment, signal assessment, and damage inference may exist simultaneously. As long as one of these assessment methods is feasible, the stage can be considered to meet the coverage requirements. This flexible coverage determination method can adapt to the differentiated needs of kill chain execution logic under different target types and different operational phases, thereby ensuring that the judgment results have practical significance.
[0170] S3.2: If so, the mapping result is processed through redundancy optimization logic, the target service kill chain is selected, and the service object sequence corresponding to the target service kill chain is determined as the current kill chain;
[0171] In one example, the redundancy optimization logic includes:
[0172] For multiple candidate service objects mapped to the same kill chain link, a performance score is calculated for each according to a preset performance evaluation model, wherein the performance evaluation model generates the performance score based on one or more parameters among detection accuracy, response time, combat radius, reliability and resource consumption;
[0173] Based on the performance score, multiple candidate service objects are sorted, and the candidate service object with the highest performance score is taken as the service object of the corresponding kill chain link, and the remaining candidate service objects are taken as alternative objects.
[0174] A link consistency verification is performed on the service object sequence consisting of service objects. If the verification passes, the service object sequence is confirmed as the current kill chain. If the verification fails, local adjustments are made based on alternative objects until the link consistency verification passes.
[0175] Understandably, when the coverage judgment indicates that at least one candidate service object in each link of the service-oriented kill chain template meets the corresponding capability requirements, it means that the conditions for constructing a complete kill chain are met at the capability level. However, multiple substitutable relationships often exist between candidate service objects.
[0176] For example, in the Find phase, there may be multiple airborne platforms with reconnaissance capabilities; in the Track phase, there may be sensor combinations with different update frequencies; and in the Engage phase, there may be multiple firepower resources capable of operating in the same area.
[0177] While such capability redundancy can provide significant flexibility if left unaddressed, it can lead to an exponential increase in the number of combinations during link construction, potentially resulting in numerous links that are suboptimal in terms of temporal continuity, spatial connectivity, or resource consumption. Therefore, it is necessary to introduce redundancy optimization logic after mapping to evaluate and filter multiple candidate service objects in the same stage, ensuring that the final kill chain meets task requirements while also possessing higher execution efficiency and overall coordination.
[0178] In this embodiment, redundancy optimization can establish a local performance evaluation model around each link in the kill chain. The performance model can be composed of multiple factors, such as detection accuracy, response time, platform reliability, execution cost, task duration, and communication link stability. The relevant parameters of each candidate service object can be mapped to this performance model to form a quantifiable score, which is used to measure the overall performance of the service object when performing the task in that link. Subsequently, the candidate service objects in the same link can be ranked according to the score, and the service object with the highest score can be selected as the preferred node in that link, while the remaining objects are marked as candidate nodes.
[0179] Furthermore, after optimizing for local redundancy in all stages, the preferred service objects of each stage can be combined in template order to form an initial service object sequence. Although this sequence is fully capable, it does not guarantee complete feasibility in both time and space dimensions. For example, the reconnaissance platform in the Find stage may finish its mission at time t1, while the positioning equipment in the Fix stage may become unusable after time t1, or the spatial coverage areas of the two stages may not overlap within the affected area, all of which could lead to a break in the link. Alternatively, the equipment in a certain stage may not be able to fully cover all the functions of that stage.
[0180] To avoid this situation, link consistency verification of the initial sequence is required at this stage, including:
[0181] Whether adjacent links have a connectable time window, whether the service objects of the two links have a path of action within the affected area, whether the communication and data links meet the real-time requirements, and whether the functions of the service objects of the current link fully cover the corresponding kill chain links.
[0182] In some optional implementations, if it is found that a certain link cannot be effectively connected with the preceding and following links, the service object with the second highest score or a better match can be selected from the candidate nodes corresponding to that link for replacement, the local sequence can be regenerated, and consistency verification can be performed again.
[0183] S3.3: If not, the mapping result is reorganized through the link completion logic to obtain the current kill chain. The reorganization includes retrieving supplementary service objects from the service index tree for the uncovered kill chain links, and adjusting the sequence of the candidate service objects and the supplementary service objects to generate alternative service-type kill chains. The service object sequence corresponding to the alternative service-type kill chain is determined as the current kill chain.
[0184] Understandably, when the coverage judgment result or link consistency verification indicates that there are still one or more capability gaps in the service-oriented kill chain template that cannot be filled by candidate service objects, it is necessary to activate the link completion logic to avoid the entire link failing to execute due to the absence of a critical link. The core idea of the link completion logic is:
[0185] The system avoids reconstructing already fulfilled steps and constructs local completion processes for missing steps. This allows the link to restore integrity and executability by inserting new service object sequences while maintaining the overall structure. This logic not only provides fault tolerance for link construction but also enables the anti-kill chain to continuously generate new effective links when equipment is damaged, resources are lost, or target behavior changes abruptly.
[0186] In one example, the link completion logic includes:
[0187] S3.3.1: Identify the kill chain links in the mapping results that are not covered by the candidate service objects, and merge multiple consecutive kill chain links that are not covered into a gap segment to generate one or more gap segments, wherein the gap segment also includes a single kill chain link;
[0188] Specifically, after the initial matching of candidate service objects with the service-oriented kill chain template, some links may fail to find service objects that meet the spatiotemporal and capability constraints. If these uncovered links are not processed individually without differentiation, the subsequent completion process will become excessively complex and will fail to reflect the temporal and functional continuity between links. Therefore, it is necessary to first identify which links are missing as a whole and then organize these links in a structured manner. Multiple adjacent uncovered links in the template sequence will be grouped into a continuous gap segment, so that the gap segment can be completed centrally later, rather than making scattered local repairs to individual links.
[0189] In this embodiment, each stage in the template is checked sequentially for its marker. If a stage is marked as uncovered, it is added to the current gap segment being built. If a stage is marked as covered, and the previous stage is uncovered, the previous continuous uncovered stage is marked as a complete gap segment, and a new segment is started. By traversing in this order, one or more gap segment lists can be automatically generated. Each gap segment contains a continuous uncovered stage, which can be one stage or several stages long. The generated gap segment not only records the index of the included stages but also records the capability requirement type of each stage and the relationship information with adjacent covered stages, for use in subsequent completion processes.
[0190] refer to Figure 6 , Figure 6 This is a schematic diagram of the structure of the notch segment provided in an embodiment of this application.
[0191] Figure 6 Taking F2T2EA as an example, in certain dynamic combat scenarios, some links in the link may experience capability gaps due to resource failure, service unavailability, or sudden changes in target status. Figure 6 The scenario shown is that in several stages after the investigation stage and before the strike stage, no available service targets that meet the constraints were found, thus forming a continuous gap segment one. In addition, the assessment is also a separate gap segment two.
[0192] It is understood that this example is only used to illustrate the logical structure of gap segments and does not limit the number or length of gap segments. In practical applications, the start and end positions of gap segments depend on the coverage of candidate service objects.
[0193] If a single link is not covered, a gap segment of length one is formed; if multiple adjacent links are not covered, they are automatically merged into a continuous combined gap segment; if there are capacity gaps at different locations in the link, multiple independent gap segments may be formed simultaneously.
[0194] S3.3.2: For each gap segment, obtain the assigned service objects corresponding to the kill chain links before and after the gap segment. Based on the start and end times and spatial coverage of the assigned service objects, and in combination with the affected area, determine the completion time constraint window and completion spatial constraint window for the gap segment.
[0195] Specifically, a gap segment is essentially a capability void embedded in a complete kill chain structure, typically preceded and followed by links already covered by candidate service objects. If the spatiotemporal information of these two or one anchor link is not considered during the completion process, and only supplementary nodes are searched from the service resources across the entire domain, it is easy to construct a local sequence that is disconnected from the original link. This not only makes it difficult to connect with the preceding and following links in time, but may also deviate from the target activity area in space. Therefore, it is necessary to use the service object information corresponding to the links before and after the gap segment to derive a local constraint window for that gap segment. This ensures that the completion process is reasonably restricted in both time and space, focusing the search on the range where a continuous link can truly be formed, thereby narrowing the search scope and improving the effectiveness of the completion process.
[0196] In this embodiment, for each gap segment, the positions of its preceding and following stages in the template are first determined, and the currently assigned service objects for these two stages are read. For the preceding service object, its operation end time and actual effective range within the affected area can be extracted; for the following service object, its operation start time and effective range within the affected area can be extracted, and a reasonable buffer zone is reserved between these two time points according to the task sequence. For example, the completion time constraint window can be set as a period starting after the end time of the preceding stage and ending before the start time of the following stage. If necessary, the window can be appropriately widened based on the target motion prediction results. Spatially, the coverage areas of the preceding and following service objects within the affected area can be superimposed or merged, and combined with the spatial location that the target may pass through during this time period, the completion spatial constraint window of the gap segment in three-dimensional space can be derived, thereby ensuring that the completion process is only carried out within the spatial area where the target may appear and can be connected by the preceding and following stages.
[0197] S3.3.3: In the service index tree, the first-level nodes and their subtrees that have spatial intersection with the completion space constraint window are retrieved to obtain the supplementary service object set for the gap segment;
[0198] Specifically, the service index tree has already organized service resources hierarchically according to tactical space region - time window - service type. If a full-database scan is still used to find supplementary service objects during the completion process, it will not only bring a large amount of computation, but also introduce a large number of service objects that are spatially irrelevant to the gap segment, significantly increasing the burden on the subsequent combination and filtering stages. Based on the completion space constraint window, the search range can be limited to the tactical region that has spatial intersection with the window. Spatial filtering starts from the first level of the tree structure. Once the tactical space corresponding to a certain first-level node does not overlap with the completion space constraint window at all, all service objects in its subtree cannot participate in the completion of the gap segment. This spatial pruning operation can eliminate a large number of irrelevant nodes in the upper levels of the index tree as early as possible, so that the completion process only takes place on the subtrees with potential feasibility.
[0199] In this embodiment, all first-level nodes of the service index tree are checked one by one. Based on the intersection of the tactical space region associated with each node and the completion space constraint window, it is determined whether the node should be retained. For first-level nodes with intersection, they are marked as nodes participating in the completion process, and their subtrees are included in the subsequent search scope. For first-level nodes with no intersection, their subtrees are excluded entirely and do not proceed to the second and third levels of scanning. Furthermore, the retained subtrees can be further filtered by combining the completion time constraint window and the capability requirements of the gap segment. For example, in the second-level nodes, only nodes whose available time window falls within the completion process period are retained, and in the third-level nodes, only nodes possessing the capability type required for the gap segment are retained. Through this continuous filtering process, what is ultimately extracted from the service index tree is a set of supplementary service objects that simultaneously satisfy the spatial, temporal, and capability constraints. Only these service objects are likely to serve as candidate filling nodes for the gap segment in the subsequent completion process.
[0200] S3.3.4: Construct a completion search tree based on each link of the kill chain within the gap segment as a level, and perform state expansion on the supplementary service object set according to the order of the kill chain links. During the state expansion process, the search path is pruned according to time continuity constraints, spatial connectivity constraints, and communication link reachability constraints. Each search path in the current layer is evaluated, and only the top-ranked search paths with the highest comprehensive scores are retained as the starting point for the next layer expansion.
[0201] Specifically, gap segments often contain one or more consecutive kill chain links. The completion process requires assigning appropriate service objects to each of these links, ensuring that these service objects, when combined, form a continuous and executable chain. If we simply exhaustively match the set of supplementary service objects using all permutations, the number of combinations will rapidly expand to an unacceptable level as the length of the gap segment and the number of candidate service objects increase. Therefore, the gap segment can be viewed as a hierarchical decision path, with the order of the links within the gap segment as the hierarchy, constructing a completion search tree that unfolds from top to bottom:
[0202] Each layer corresponds to a link in the gap segment, and the state of each node corresponds to the local link state formed by selecting a certain service object in that link and combining it with the preceding link. Through layer-by-layer expansion, a complete candidate path is formed from the start point to the end point of the gap segment.
[0203] In this embodiment, the construction of the completion search tree can begin from the first stage of the gap segment. All supplementary service objects that meet the capability requirements of that stage and are within the completion constraint window are selected as candidate nodes in the next layer below the root. The state of each node records the time window, spatial coverage, and relationship with the target influence area of the selected service object. Subsequently, for the second stage of the gap segment, based on the state of each valid node in the previous layer, all supplementary service objects that meet the capability requirements of that stage can be attached, and the constraints regarding temporal continuity, spatial connectivity, and communication link reachability between them are checked.
[0204] If the available time windows of two service objects do not overlap within the completion process time interval, the coverage area cannot form a connected path within the affected area, or there is no feasible data transmission path between them, then the extended path is considered to fail to meet the link continuity requirement and is pruned from the search tree. Only when all of the above conditions are met will the path be retained as a new state node in the current layer. By repeating this expansion and pruning process in the intermediate layers, all potential completion paths can be gradually constructed in the tree structure.
[0205] In one example, the state expansion of the supplementary service object set according to the kill chain sequence includes:
[0206] In each layer of the completion search tree, the corresponding kill chain link is taken as the current expansion target link. Service objects that match the kill chain link are selected from the set of supplementary service objects, and each selected service object is used as a candidate expansion node to generate the corresponding expansion state.
[0207] For each extended state, a legality determination is made based on the temporal continuity constraint, spatial connectivity constraint, and communication link reachability constraint between the current extended target link and the service object corresponding to the adjacent determined kill chain link. An extended state that does not meet any of the constraints is pruned.
[0208] For extended states that pass the legality determination, a comprehensive performance score is calculated based on a comprehensive scoring function constructed according to the target performance weight and resource consumption weight. When the number of extended states that pass the legality determination exceeds a preset threshold, the extended states are filtered for width limitation based on the comprehensive performance score.
[0209] S3.3.5: Select the service object sequence with the highest comprehensive performance score from the completion search tree as the completion sequence of the gap segment, and concatenate the completion sequence with the selected service object sequences before and after the gap segment to generate the corresponding completion link;
[0210] Specifically, after the search tree for completion is expanded, each path from the root to the leaf corresponds to a candidate completion sequence that has already selected a specific service target within the gap segment. These sequences have been filtered through time, space, and link reachability constraints during construction, thus possessing structural executability. However, differences in quality still exist among these candidate paths. Simply using any path as the completion result may lead to low operational effectiveness and significant resource waste. Therefore, it is necessary to conduct a unified comparison of all candidate paths based on the evaluation information accumulated during the expansion process, selecting the one with the highest evaluation score as the final completion sequence for the gap segment. This ensures that the gap segment achieves capability completion while exhibiting more reasonable performance in terms of time utilization, spatial adaptation, and resource allocation.
[0211] In this embodiment, the comprehensive performance score can be gradually accumulated during the path construction process of the completion search tree. Whenever a new service object is added at a certain layer, its own performance score can be combined with the current accumulated score of the path according to a preset weight, such as by weighted superposition, normalized average, or minimum value protection, to integrate the performance of each service object in a completion sequence into a whole index. After the search tree is fully expanded, the comprehensive scores of all paths reserved to the leaf nodes can be compared, and the path with the highest score can be selected as the completion sequence for the gap segment. Subsequently, the completion sequence is spliced with the original selected service object sequences before and after the gap segment on the time axis and spatial axis, and minor boundary adjustments are made when necessary, such as fine-tuning the start and end times of the preceding and following links to avoid excessive boundary overlap or unexplained time gaps, and merging and labeling highly overlapping coverage areas in the same spatial region, thereby forming a logically continuous and spatiotemporally reasonable completion link.
[0212] S3.3.6: Combine the complete links corresponding to all missing segments with the service object sequences corresponding to the already covered kill chain links to generate alternative service-type kill chains.
[0213] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A method for constructing an anti-kill chain based on a service-oriented kill chain, applied to an anti-kill chain construction system, characterized in that, The anti-kill chain construction system is configured with a service resource library and a kill chain template library. The kill chain template library corresponds to multiple service-type kill chain templates. The method includes: Obtain the current state information of the target to be attacked, and predict the target's movement based on the current state information to obtain the target's predicted path; The predicted target path is spatially expanded to obtain the affected area, and candidate service objects that are suitable for the spatiotemporal constraints and capability constraints of the affected area are selected from the service resource library; Based on the service-oriented kill chain template corresponding to the target to be attacked, the candidate service object is mapped to each kill chain link of the corresponding service-oriented kill chain template to determine the current kill chain; Mapping the candidate service objects to the corresponding kill chain links of the service-oriented kill chain template to determine the current kill chain includes: Based on the mapping results, determine whether the candidate service object completely covers the corresponding service-type kill chain template; If so, the mapping result is processed through redundancy optimization logic, the target service kill chain is selected, and the service object sequence corresponding to the target service kill chain is determined as the current kill chain; If not, the mapping result is reorganized through link completion logic to obtain the current kill chain. The reorganization includes retrieving supplementary service objects from the service index tree for the uncovered kill chain links, and adjusting the sequence of candidate service objects and the supplementary service objects to generate alternative service-type kill chains. The service object sequence corresponding to the alternative service-type kill chain is determined as the current kill chain. The link completion logic includes: The kill chain links not covered by candidate service objects in the mapping results are identified, and multiple consecutive uncovered kill chain links are merged into a gap segment to generate one or more gap segments, wherein the gap segment also includes a single kill chain link. For each gap segment, the assigned service objects corresponding to the kill chain links before and after the gap segment are obtained. Based on the start and end times and spatial coverage of the assigned service objects, and combined with the affected area, the completion time constraint window and completion spatial constraint window for the gap segment are determined. In the service index tree, the first-level nodes and their subtrees that have spatial intersection with the completion space constraint window are retrieved to obtain the supplementary service object set for the gap segment; A completion search tree is constructed based on each link of the kill chain within the gap segment. The state of the supplementary service object set is expanded according to the order of the kill chain links. During the state expansion process, the search path is pruned according to time continuity constraints, spatial connectivity constraints, and communication link reachability constraints. Each search path in the current layer is evaluated, and only the top-ranked search paths with the highest comprehensive scores are retained as the starting point for the next layer expansion. The service object sequence with the highest comprehensive performance score is selected from the completion search tree as the completion sequence of the gap segment, and the completion sequence is concatenated with the selected service object sequences before and after the gap segment to generate the corresponding completion link; Combine the complete links corresponding to all missing segments with the service object sequences corresponding to the already covered kill chain links to generate alternative service-type kill chains.
2. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The service resource library includes multiple service objects, each of which includes at least one of the following: service type, capability parameters, timeliness parameters, spatial coverage, and mobility characteristics. The steps for constructing a service object include: Acquire equipment data for each combat device in the combat system, and perform functional abstraction and service modeling for the combat functions of each combat device to generate service objects that represent the combat functions, including reconnaissance, tracking, command and control, fire strike, and effect evaluation.
3. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The current state information includes at least one of the target's current position, trajectory, speed, heading, maneuvering mode, and threat level. Target motion prediction based on the current state information includes: Based on the target's current position and trajectory, the target's position is predicted through kinematic calculations, resulting in a set of predicted trajectory points. Based on speed, heading, and maneuvering mode, the potential movement patterns of the target are determined, and the credibility weights of each target's predicted trajectory points are assigned in combination with the preset threat level. The target prediction trajectory point set and the corresponding confidence weights are combined to generate at least one target prediction path, wherein the target prediction path is used to characterize the target's activity area within a preset time period.
4. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 3, characterized in that, The predicted target path is spatially expanded to obtain the affected area, including: Based on the target prediction trajectory points and corresponding confidence weights in the target prediction path, a target position probability cloud model is constructed within a preset time. The target position probability cloud model is used to characterize the probability distribution of target appearance at spatial discrete units, wherein the spatial discrete units represent grid units generated after the tactical space is gridded based on a preset resolution. Acquire tactical environment constraint information, and construct a tactical constraint set based on the tactical environment constraint information; The tactical constraint set is fused with the target position probability cloud model to reduce the probability of target occurrence in spatial discrete units located in no-fly zones and physically inaccessible areas, and to enhance the probability of target occurrence in spatial discrete units located in preset air routes and terrain-concealed passages, thus obtaining a modified model. The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to the preset confidence threshold. The minimum set of spatial regions can be obtained by clustering spatial discrete units. The spatial outer envelope corresponding to the set of minimum spatial regions is determined as the influence region.
5. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 4, characterized in that, The modified model is subjected to cumulative probability calculation to determine the minimum set of spatial regions in which the cumulative probability of the target occurrence within the preset time period is greater than or equal to a preset confidence threshold, including: The target occurrence probability of each spatial discrete unit in the modified model is summed in chronological order to obtain the cumulative target occurrence probability value of each spatial discrete unit; Based on the cumulative target occurrence probability value and the confidence threshold, spatial discrete units with a cumulative target occurrence probability value greater than or equal to the confidence threshold are selected as the target activity unit set; Spatial clustering is performed on the target activity unit set to obtain candidate regions. The candidate regions are then geometrically regularized through morphological dilation to obtain the minimum spatial region set.
6. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 1, characterized in that, The service resource library is used to select candidate service objects that fit the spatiotemporal constraints and capability constraints of the affected area, including: Based on the spatial coverage, available time window, and service type information of each service object in the service resource library, the service objects are organized hierarchically to construct a service index tree, wherein the service index tree includes: a first-level node divided by tactical spatial regions; a second-level node divided by available time windows under each first-level node; and a third-level node divided by service type information under each second-level node. Based on the affected region, the service index tree is traversed from top to bottom, and pruning operations are performed on the first-level nodes and their subtrees that do not have spatial intersection with the affected region. Based on the kill chain execution time window, prune the second-level nodes and their subtrees that do not meet the preset time. Based on the capability requirements of the corresponding links in the service-oriented kill chain template, prune the third-layer nodes and their leaf nodes that do not meet the capability constraints. The service objects corresponding to all remaining leaf nodes in the pruned service index tree are summarized and determined as the candidate service objects.
7. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 6, characterized in that, The redundancy optimization logic includes: For multiple candidate service objects mapped to the same kill chain link, a performance score is calculated for each according to a preset performance evaluation model, wherein the performance evaluation model generates the performance score based on one or more parameters among detection accuracy, response time, combat radius, reliability and resource consumption; Based on the performance score, multiple candidate service objects are sorted, and the candidate service object with the highest performance score is taken as the service object of the corresponding kill chain link, and the remaining candidate service objects are taken as alternative objects. A link consistency verification is performed on the service object sequence consisting of service objects. If the verification passes, the service object sequence is confirmed as the current kill chain. If the verification fails, local adjustments are made based on alternative objects until the link consistency verification passes.
8. The method for constructing an anti-kill chain based on a service-oriented kill chain according to claim 6, characterized in that, The step of extending the state of the supplementary service object set according to the kill chain sequence includes: In each layer of the completion search tree, the corresponding kill chain link is taken as the current expansion target link. Service objects that match the kill chain link are selected from the set of supplementary service objects, and each selected service object is used as a candidate expansion node to generate the corresponding expansion state. For each extended state, a legality determination is made based on the temporal continuity constraint, spatial connectivity constraint, and communication link reachability constraint between the current extended target link and the service object corresponding to the adjacent determined kill chain link. An extended state that does not meet any of the constraints is pruned. For extended states that pass the legality determination, a comprehensive performance score is calculated based on a comprehensive scoring function constructed according to the target performance weight and resource consumption weight. When the number of extended states that pass the legality determination exceeds a preset threshold, the extended states are filtered for width limitation based on the comprehensive performance score.