Double-layer defense strategy and system under random denial of service attack facing switching system
By constructing a basic model of the switching system and a random DoS attack model, and combining optimized design of the network layer and control layer, the problem of insufficient modeling accuracy in existing technologies is solved, achieving better defense effects and improving the stability and robustness of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGDONG UNIV OF TECH
- Filing Date
- 2026-01-21
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies lack sufficient modeling accuracy under random denial-of-service attacks and fail to effectively combine the network layer and control layer in the design, resulting in compromised system stability and performance.
We construct a basic model of the switching system and a random DoS attack model, establish a two-layer defense strategy, optimize the performance parameters of H-infinity by bandwidth allocation at the network layer and controller gain at the control layer, and improve the traditional basic defense strategy by combining the network layer and the control layer for correlation constraints.
The system improved the stability and robustness of the switching system under random denial-of-service attacks, achieving better defense.
Smart Images

Figure CN121940184A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication network technology, and in particular to a two-layer defense strategy and system for random denial-of-service attacks on dynamic handover systems. Background Technology
[0002] Switched systems are important hybrid systems widely used in various fields. Typically, a switched system consists of a finite number of continuous-time or discrete-time subsystems, with transitions between these subsystems coordinated by corresponding switching signals. In real-world applications, driven by environmental changes and the demand for intelligent control, many systems, such as automotive engine control systems, flight control systems, and network control systems, are modeled as switched systems. These control systems contain multiple variables, measured by different sensors and transmitted through multiple independent channels.
[0003] Multi-channel systems, as an important type of switching system, utilize multiple independent channels to transmit status information in parallel. They have become the core architecture of modern network control systems and are widely used in various fields. For example, in smart manufacturing, critical signals from different production modules are transmitted through separate channels to ensure the reliability of the monitoring system; in the field of autonomous driving, data from multiple sensors are transmitted through different communication channels, thereby enhancing the robustness of environmental perception and the stability of the system.
[0004] With the deepening research into multi-channel systems, network channel transmission technologies have also developed rapidly. However, the introduction of networks has brought new security challenges, especially the risk of network attacks, such as denial-of-service (DoS) attacks and spoofed data injection attacks. DoS attacks send traffic exceeding the bandwidth of the communication channel, causing channel buffer congestion and resulting in the loss of data packets in transmission, severely impacting system stability and performance. Therefore, DoS attacks have become one of the hot research topics.
[0005] Currently, research on DoS attacks focuses on two main aspects. First, it concentrates on modeling attack behavior by limiting attack frequency and duration. Second, researchers are increasingly adopting stochastic process modeling methods that better reflect real-world attacks, such as modeling DoS attacks as Bernoulli processes with time-invariant attack probabilities, or describing their state transition processes using Markov chains.
[0006] DoS attacks significantly impact system stability and performance; therefore, research on network control systems under DoS attacks has been extensive. Most existing research focuses on controller design, attempting to address different types of DoS attacks through various control strategies to meet system performance targets. However, existing research suffers from two main problems: first, the modeling accuracy of random DoS attacks is insufficient, failing to fully consider the dynamic characteristics of DoS attacks; second, most studies only focus on control-level optimization, neglecting the influence of the network layer and failing to effectively co-design the network and control layers. Summary of the Invention
[0007] To overcome the insufficient modeling accuracy of the aforementioned random DoS attacks and the failure to effectively combine the network layer and control layer in design, this invention provides a two-layer defense strategy and system for random denial-of-service attacks on switching systems.
[0008] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a two-layer defense strategy against random denial-of-service attacks on switching systems, comprising: Construct a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. Based on the aforementioned switching system basic model and random DoS attack model, a multi-channel switching model under random DoS attack is constructed. A traditional basic defense strategy is established with the goal of satisfying exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks. Channel modeling is performed on the network layer of the multi-channel switching model under the random DoS attack, and correlation constraints are established in the joint control layer; Based on bandwidth allocation at the network layer and controller gain at the control layer, an optimization objective is established to minimize the performance parameter H infinity. Based on the optimization objective and related constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy; Solving the controller gain matrix of the control layer in the two-layer defense strategy yields the minimum H-infinity performance parameter, and thus the optimal defense strategy.
[0009] Preferably, a basic model of the switching system is constructed, including: The basic model of the switching system includes several subsystems, and the expressions of the subsystems are as follows: ; The switching signal of the basic model of the switching system is In the interval The internal temperature remains constant; The fundamental dynamic equations of the switching system's basic model are expressed as follows:
[0010] Where x(k)∈ m Let u(k) be the system state vector. 0 To control the input vector, K(k)∈ 0 × m Let L(k) be the feedback gain matrix of the control layer. m × m Let w(k) ∈ [the state channel matrix of the network layer]. p Let z(k) be the external perturbation vector. q For the system output vector, The known constant matrix of the corresponding subsystem; The norm of the external perturbation vector is defined as: ; The norm of the system output vector is defined as: .
[0011] Preferably, the subsystem includes a stable subsystem and an unstable subsystem, and the set expression of the stable subsystem is: The set expression for the unstable subsystem is: , For stable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, For the first The pattern-dependent average residence time of each subsystem; For unstable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, The average dwell time is required for rapid mode switching.
[0012] Preferably, a random DoS attack model is constructed, including: The random DoS attack model includes state information, the network layer state channel matrix under attack conditions, and the transition probability matrix. The status information is represented as ; The state channel matrix of the network layer under the attack state is represented as follows: ; Under a fixed network layer bandwidth allocation, the characteristics of random DoS attacks are as follows:
[0013] The characteristics of the random DoS attack are modeled as Markov transition behavior of the state channel matrix:
[0014] in, For attack mode, n=2 m , where m is the dimension of the state channel matrix; The transition probability matrix is:
[0015] The transition probability matrix satisfies probability normalization. .
[0016] Preferably, a multi-channel switching model under random DoS attack is constructed based on the switching system basic model and the random DoS attack model, including: The control input vector of the basic model of the switching system is combined with the state feedback control law Construct a multi-channel switching model under random DoS attacks; in, For subsystem i in attack mode Feedback control gain matrix of the lower control layer; The multi-channel switching model under random DoS attack is represented as follows: .
[0017] Preferably, a traditional basic defense strategy is established with the goal of achieving exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks, including: The inequalities that satisfy the exponential mean square stability state are as follows:
[0018] The inequality that satisfies the performance state of H infinity is as follows: .
[0019] Preferably, the traditional basic defense strategy, which aims to achieve exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks, also includes: Constructing Lyapunov functions:
[0020] in, It is a positive definite matrix; The mathematical expectation of the analytical difference of the Lyapunov function is:
[0021] Substituting the mathematical expectation into the system dynamics of a multi-channel switching model under a random DoS attack, we obtain:
[0022] in, ; The conditions for satisfying exponential mean square stability and H-infinity performance are constructed as follows:
[0023] in, Let Lyapunov's energy change coefficient be the coefficient for... ;right ; Utilizing system characteristics Substituting the given conditions and optimizing, we obtain the optimized conditions:
[0024]
[0025] Applying Schur's complement lemma to the optimized conditions, we obtain the matrix inequality:
[0026] Design of energy mutation during subsystem switching in the multi-channel switching model under the aforementioned random DoS attack:
[0027] Among them, for , ; , ; For stable and unstable subsystems, design separately:
[0028]
[0029] in, ,and , ; Combining energy mutation design, we obtain: (1) in, , ; Simplifying inequality (1) and setting x(0) = 0, we obtain the condition that the performance index H is infinite:
[0030] make The inequality (1) is simplified to:
[0031] make , in, , Each is a matrix The maximum and minimum eigenvalues; make For all They all This ensures that the exponential mean square stability is satisfied; Establish preliminary traditional basic defense strategies:
[0032]
[0033]
[0034] in, ; The preliminary traditional basic defense strategy is optimized to obtain the traditional basic defense strategy:
[0035]
[0036]
[0037]
[0038]
[0039] in, ,and , , .
[0040] Preferably, channel modeling is performed on the network layer of the multi-channel switching model under random DoS attack, and correlation constraints are established in the joint control layer, including: Perform channel modeling on the network layer and obtain the normal traffic of the r-th channel at time k. Attack traffic and bandwidth ; The joint control layer establishes associated constraints: .
[0041] Preferably, the traditional basic defense strategy is improved based on the optimization objective and related constraints to obtain a two-layer defense strategy:
[0042]
[0043]
[0044] .
[0045] This invention also provides a two-layer defense system against random denial-of-service attacks on switching systems, comprising: The basic model and attack model building module is used to build a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. A multi-channel switching model construction module is used to construct a multi-channel switching model under random DoS attack based on the switching system basic model and the random DoS attack model. The traditional basic defense strategy establishment module is used to establish a traditional basic defense strategy with the goal of satisfying exponential mean square stability and H-infinity performance of a multi-channel switching model under random DoS attacks. The correlation constraint establishment module is used to perform channel modeling on the network layer of the multi-channel switching model under the random DoS attack and to establish correlation constraints in conjunction with the control layer. An optimization objective establishment module is used to establish an optimization objective that minimizes the performance parameter H based on bandwidth allocation at the network layer and controller gain at the control layer. A two-layer defense strategy construction module is used to improve the traditional basic defense strategy based on optimization objectives and related constraints to obtain a two-layer defense strategy; The dual-layer defense strategy solution module is used to solve the controller gain matrix of the control layer in the dual-layer defense strategy to obtain the minimum H-infinity performance parameter, and then obtain the optimal defense strategy.
[0046] Compared with the prior art, the beneficial effects of the technical solution of the present invention are: This invention constructs a basic model and a random DoS attack model; based on the basic model and the random DoS attack model, it constructs a multi-channel switching model under random DoS attacks; based on the multi-channel switching model under random DoS attacks, it establishes a traditional basic defense strategy; it performs channel modeling on the network layer of the multi-channel switching model under random DoS attacks and establishes correlation constraints jointly with the control layer; based on the bandwidth allocation of the network layer and the controller gain of the control layer, it establishes an optimization objective of minimizing the H-infinity performance parameter; based on the optimization objective and correlation constraints, it improves the traditional basic defense strategy to obtain a two-layer defense strategy; it solves the controller gain matrix of the control layer in the two-layer defense strategy to obtain the minimum H-infinity performance parameter, and thus obtains the optimal defense strategy. This invention improves the traditional basic defense strategy by randomly modeling DoS attacks and jointly constructing correlation constraints on the network layer and control layer, with the goal of minimizing the H-infinity performance parameter, resulting in a two-layer defense strategy that achieves better defense performance and improves stability and robustness. Attached Figure Description
[0047] Figure 1 This is a flowchart illustrating a two-layer defense strategy against random denial-of-service attacks on a switching system, as shown in Example 1. Figure 2 This is a schematic diagram of a two-layer defense system against random denial-of-service attacks on a switching system, as shown in Example 3. Detailed Implementation
[0048] The accompanying drawings are for illustrative purposes only and should not be construed as limiting the scope of this patent. To better illustrate this embodiment, some parts in the accompanying drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions; It will be understood by those skilled in the art that certain well-known structures and their descriptions may be omitted in the accompanying drawings.
[0049] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.
[0050] Example 1 This embodiment provides a two-layer defense strategy against random denial-of-service attacks on switching systems, such as...Figure 1 As shown, it includes: Construct a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. Based on the aforementioned switching system basic model and random DoS attack model, a multi-channel switching model under random DoS attack is constructed. A traditional basic defense strategy is established with the goal of satisfying exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks. Channel modeling is performed on the network layer of the multi-channel switching model under the random DoS attack, and correlation constraints are established in the joint control layer; Based on bandwidth allocation at the network layer and controller gain at the control layer, an optimization objective is established to minimize the performance parameter H infinity. Based on the optimization objective and related constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy; Solving the controller gain matrix of the control layer in the two-layer defense strategy yields the minimum H-infinity performance parameter, and thus the optimal defense strategy.
[0051] In its implementation, this embodiment first constructs a basic switching system model and a random DoS attack model. The basic switching system model includes a network layer and a control layer. Then, based on these models, a multi-channel switching model under random DoS attacks is constructed. Next, a traditional basic defense strategy is established with the goal of achieving exponential mean square stability and H-infinity performance in the multi-channel switching model under random DoS attacks. Next, channel modeling is performed on the network layer of the multi-channel switching model under random DoS attacks, and correlation constraints are established jointly with the control layer. Based on the bandwidth allocation of the network layer and the controller gain of the control layer, an optimization objective is established to minimize the H-infinity performance parameter. Based on the optimization objective and correlation constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy. Finally, the controller gain matrix of the control layer in the two-layer defense strategy is solved to obtain the minimum H-infinity performance parameter, thus yielding the optimal defense strategy. This invention improves the traditional basic defense strategy by stochastically modeling DoS attacks and jointly constructing correlation constraints with the network and control layers, aiming to minimize the H-infinity performance parameter, thereby obtaining a two-layer defense strategy with better defense performance and improved stability and robustness.
[0052] Example 2 This embodiment provides a two-layer defense strategy against random denial-of-service attacks on handover systems, including: constructing a basic model of the handover system and a random DoS attack model, wherein the basic model of the handover system includes a network layer and a control layer; Based on the aforementioned switching system basic model and random DoS attack model, a multi-channel switching model under random DoS attack is constructed. A traditional basic defense strategy is established with the goal of satisfying exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks. Channel modeling is performed on the network layer of the multi-channel switching model under the random DoS attack, and correlation constraints are established in the joint control layer; Based on bandwidth allocation at the network layer and controller gain at the control layer, an optimization objective is established to minimize the performance parameter H infinity. Based on the optimization objective and related constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy; Solving the controller gain matrix of the control layer in the two-layer defense strategy yields the minimum H-infinity performance parameter, and thus the optimal defense strategy.
[0053] Construct a basic model for the switching system, including: The basic model of the switching system includes several subsystems, and the expressions of the subsystems are as follows: ; The switching signal of the basic model of the switching system is In the interval The internal temperature remains constant; The fundamental dynamic equations of the switching system's basic model are expressed as follows:
[0054] Where x(k)∈ m Let u(k) be the system state vector. 0 To control the input vector, K(k)∈ 0 × m Let L(k) be the feedback gain matrix of the control layer. m × m Let w(k) ∈ [the state channel matrix of the network layer]. p Let z(k) be the external perturbation vector. q For the system output vector, The known constant matrix of the corresponding subsystem; The norm of the external perturbation vector is defined as: ; The norm of the system output vector is defined as: .
[0055] It should be noted that, in this embodiment, the basic model of the switching system is the basic model of an autonomous vehicle system; x(k)∈ m Let u(k) be the state vector of the autonomous vehicle system. 0 To control the input vector; for External disturbances at any given time (corresponding to uncertainties such as crosswinds, road surface changes, and modeling errors); for The driving mode signal at any given time is used to characterize the vehicle's current operating mode; This is the performance output vector at time k, used to evaluate the vehicle's control performance (e.g., a combined index of tracking error and control cost).
[0056] The subsystem includes a stable subsystem and an unstable subsystem, and the set expression for the stable subsystem is: The set expression for the unstable subsystem is: , For stable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, For the first The pattern-dependent average residence time of each subsystem; For unstable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, The average dwell time is required for rapid mode switching.
[0057] It should be noted that in this embodiment, the stability subsystem corresponds to the conventional autonomous driving cruise mode (e.g., lane keeping + cruise tracking). In this mode, the vehicle is dynamically stable, the information link is highly complete, and the closed loop is easy to maintain convergence. The unstable subsystem corresponds to the emergency obstacle avoidance / emergency takeover mode. In this mode, the vehicle is highly maneuverable and more sensitive to the real-time nature of information. If communication is disturbed, the error is more easily amplified, and there is a risk of short-term divergence.
[0058] It should be noted that, in this embodiment, constructing a random DoS attack model includes: The random DoS attack model includes state information, the network layer state channel matrix under attack conditions, and the transition probability matrix. The status information is represented as ; The state channel matrix of the network layer under the attack state is represented as follows: ; Under a fixed network layer bandwidth allocation, the characteristics of random DoS attacks are as follows:
[0059] The characteristics of the random DoS attack are modeled as Markov transition behavior of the state channel matrix:
[0060] in, For attack mode, n=2 m , where m is the dimension of the state channel matrix; The transition probability matrix is:
[0061] The transition probability matrix satisfies probability normalization. It should be noted that, in this embodiment, a multi-channel handover model under a random DoS attack is constructed based on the basic handover system model and the random DoS attack model, including: The control input vector of the basic model of the switching system is combined with the state feedback control law Construct a multi-channel switching model under random DoS attacks; in, The control layer employs a state feedback controller related to the driving mode and attack mode. The multi-channel switching model under random DoS attack is represented as follows: .
[0062] It should be noted that, in this embodiment, the traditional basic defense strategy is established with the goal of achieving exponential mean square stability and H-infinity performance in the multi-channel switching model under random DoS attacks, including: The inequalities that satisfy the exponential mean square stability state are as follows:
[0063] The inequality that satisfies the performance state of H infinity is as follows: .
[0064] It should be noted that, in this embodiment, the traditional basic defense strategy, which aims to achieve exponential mean square stability and H-infinity performance in the multi-channel switching model under random DoS attacks, also includes: Constructing Lyapunov functions:
[0065] in, It is a positive definite matrix; The mathematical expectation of the analytical difference of the Lyapunov function is:
[0066] Substituting the mathematical expectation into the system dynamics of a multi-channel switching model under a random DoS attack, we obtain:
[0067] in, ; The conditions for satisfying exponential mean square stability and H-infinity performance are constructed as follows:
[0068] in, Let Lyapunov's energy change coefficient be the coefficient for... ;right ; Utilizing system characteristics Substituting the given conditions and optimizing, we obtain the optimized conditions:
[0069]
[0070] Applying Schur's complement lemma to the optimized conditions, we obtain the matrix inequality:
[0071] Design of energy mutation during subsystem switching in the multi-channel switching model under the aforementioned random DoS attack:
[0072] Among them, for , ; , ; For stable and unstable subsystems, design separately:
[0073]
[0074] in, ,and , ; Combining energy mutation design, we obtain: (1) in, , ; Simplifying inequality (1) and setting x(0) = 0, we obtain the condition that the performance index H is infinite:
[0075] make The inequality (1) is simplified to:
[0076] make , in, , Each is a matrix The maximum and minimum eigenvalues; make For all They all This ensures that the exponential mean square stability is satisfied; Establish preliminary traditional basic defense strategies:
[0077]
[0078]
[0079] in, ; The preliminary traditional basic defense strategy is optimized to obtain the traditional basic defense strategy:
[0080]
[0081]
[0082]
[0083]
[0084] in, ,and , , .
[0085] It should be noted that, in this embodiment, channel modeling is performed on the network layer of the multi-channel switching model under random DoS attack, and correlation constraints are established in the joint control layer, including: Perform channel modeling on the network layer and obtain the normal traffic of the r-th channel at time k. Attack traffic and bandwidth ; The joint control layer establishes associated constraints: .
[0086] in, For channel The information at time k can transmit an indication quantity. This indicates that the channel information can be transmitted and used for control; This indicates that information cannot be transmitted due to insufficient bandwidth (equivalent to packet loss or timeout).
[0087] It should be noted that, in this embodiment, the network layer of the autonomous vehicle system includes multiple transmission channels for transmitting information between perception / control / execution and external communication. Assume there exists... One critical channel, channel number is The actual meaning of this is illustrated in the following example: — Channel Status information channel, used to transmit key vehicle status data (necessary for forming / updating control). );- aisle : Control command channel, used to transmit control commands calculated by the control layer (to... (issued to the implementing agency); — Channel External communication channel, used to transmit / receive external collaborative information such as V2X (can be used for decision support and security alerts).
[0088] At time k, for any channel definition: For channel Normal input data volume / normal traffic; For channel The amount of attack input information / attack traffic; For channel Available bandwidth.
[0089] It should be noted that, in this embodiment, the traditional basic defense strategy is improved based on the optimization objective and correlation constraints to obtain a two-layer defense strategy:
[0090]
[0091]
[0092] .
[0093] Example 3 This embodiment provides a two-layer defense system against random denial-of-service attacks on handover systems, used to implement the two-layer defense strategy against random denial-of-service attacks on handover systems described in Embodiment 1 or 2, such as... Figure 2 As shown, it includes: The basic model and attack model building module is used to build a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. A multi-channel switching model construction module is used to construct a multi-channel switching model under random DoS attack based on the switching system basic model and the random DoS attack model. The traditional basic defense strategy establishment module is used to establish a traditional basic defense strategy with the goal of satisfying exponential mean square stability and H-infinity performance of a multi-channel switching model under random DoS attacks. The correlation constraint establishment module is used to perform channel modeling on the network layer of the multi-channel switching model under the random DoS attack and to establish correlation constraints in conjunction with the control layer. An optimization objective establishment module is used to establish an optimization objective that minimizes the performance parameter H based on bandwidth allocation at the network layer and controller gain at the control layer. A two-layer defense strategy construction module is used to improve the traditional basic defense strategy based on optimization objectives and related constraints to obtain a two-layer defense strategy; The dual-layer defense strategy solution module is used to solve the controller gain matrix of the control layer in the dual-layer defense strategy to obtain the minimum H-infinity performance parameter, and then obtain the optimal defense strategy.
[0094] The same or similar labels correspond to the same or similar parts; The terms used to describe positional relationships in the accompanying drawings are for illustrative purposes only and should not be construed as limiting this patent. Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the implementation of the present invention. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively describe all embodiments here. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the claims of the present invention.
Claims
1. A two-layer defense strategy against random denial-of-service attacks on switching systems, characterized in that, include: Construct a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. Based on the aforementioned switching system basic model and random DoS attack model, a multi-channel switching model under random DoS attack is constructed. A traditional basic defense strategy is established with the goal of satisfying exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks. Channel modeling is performed on the network layer of the multi-channel switching model under the random DoS attack, and correlation constraints are established in the joint control layer; Based on bandwidth allocation at the network layer and controller gain at the control layer, an optimization objective is established to minimize the performance parameter H infinity. Based on the optimization objective and related constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy; Solving the controller gain matrix of the control layer in the two-layer defense strategy yields the minimum H-infinity performance parameter, and thus the optimal defense strategy is obtained.
2. The two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 1, characterized in that, Construct a basic model for the switching system, including: The basic model of the switching system includes several subsystems, and the expressions of the subsystems are as follows: ; The switching signal of the basic model of the switching system is In the interval The internal temperature remains constant; The fundamental dynamic equations of the switching system's basic model are expressed as follows: Where x(k)∈ m Let u(k) be the system state vector. 0 To control the input vector, K(k)∈ 0 × m Let L(k) be the feedback gain matrix of the control layer. m × m Let w(k) ∈ [the state channel matrix of the network layer]. p Let z(k) be the external perturbation vector. q For the system output vector, The known constant matrix of the corresponding subsystem; The norm of the external perturbation vector is defined as: ; The norm of the system output vector is defined as: .
3. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 2, characterized in that, The subsystem includes a stable subsystem and an unstable subsystem, and the set expression for the stable subsystem is: The set expression for the unstable subsystem is: , For stable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, For the first The pattern-dependent average residence time of each subsystem; For unstable subsystems ,exist , making any satisfy ,in, For subsystem In time Number of switching between them For the chatter boundary, For subsystem In time Duration of stay within, The average dwell time is required for rapid mode switching.
4. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 3, characterized in that, Constructing a random DoS attack model includes: The random DoS attack model includes state information, the network layer state channel matrix under attack conditions, and the transition probability matrix. The status information is represented as ; The state channel matrix of the network layer under the attack state is represented as follows: ; Under a fixed network layer bandwidth allocation, the characteristics of random DoS attacks are as follows: The characteristics of the random DoS attack are modeled as Markov transition behavior of the state channel matrix: in, For attack mode, n=2 m , where m is the dimension of the state channel matrix; The transition probability matrix is: The transition probability matrix satisfies probability normalization. .
5. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 4, characterized in that, Based on the aforementioned switching system basic model and random DoS attack model, a multi-channel switching model under random DoS attack is constructed, including: The control input vector of the basic model of the switching system is combined with the state feedback control law Construct a multi-channel switching model under random DoS attacks; in, For subsystem i in attack mode Feedback control gain matrix of the lower control layer; The multi-channel switching model under random DoS attack is represented as follows: 。 6. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 5, characterized in that, To achieve exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks, a traditional basic defense strategy is established, including: The inequalities that satisfy the exponential mean square steady state are as follows: The inequalities that satisfy the H-infinity performance state are as follows: 。 7. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 6, characterized in that, A traditional basic defense strategy is established with the goal of achieving exponential mean square stability and H-infinity performance in a multi-channel switching model under random DoS attacks. This strategy also includes: Constructing Lyapunov functions: in, It is a positive definite matrix; The mathematical expectation of the analytical difference of the Lyapunov function is: Substituting the mathematical expectation into the system dynamics of a multi-channel switching model under a random DoS attack, we obtain: in, ; The conditions for satisfying exponential mean square stability and H-infinity performance are constructed as follows: in, Let Lyapunov's energy change coefficient be the coefficient for... ;right ; Utilizing system characteristics Substituting the given conditions and optimizing, we obtain the optimized conditions: Applying Schur's complement lemma to the optimized conditions, we obtain the matrix inequality: Design of energy mutation during subsystem switching in the multi-channel switching model under the aforementioned random DoS attack: Among them, for , ; , ; For stable and unstable subsystems, design separately: in, ,and , ; Combining energy mutation design, we obtain: (1) in, , ; Simplifying inequality (1) and setting x(0) = 0, we obtain the condition that the performance index H is infinite: make The inequality (1) is simplified to: make , in, , Each is a matrix The maximum and minimum eigenvalues; make For all They all This ensures that the exponential mean square stability is satisfied; Establish preliminary traditional basic defense strategies: in, ; The preliminary traditional basic defense strategy is optimized to obtain the traditional basic defense strategy: in, ,and , , .
8. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 7, characterized in that, Channel modeling is performed on the network layer of the multi-channel switching model under the random DoS attack, and correlation constraints are established in the joint control layer, including: Perform channel modeling on the network layer and obtain the normal traffic of the r-th channel at time k. Attack traffic and bandwidth ; The joint control layer establishes associated constraints: 。 9. A two-layer defense strategy against random denial-of-service attacks on a handover system according to claim 8, characterized in that, Based on the optimization objective and correlation constraints, the traditional basic defense strategy is improved to obtain a two-layer defense strategy: 。 10. A two-layer defense system against random denial-of-service attacks on handover systems, used to implement the two-layer defense strategy against random denial-of-service attacks on handover systems as described in claims 1-9, characterized in that, include: The basic model and attack model building module is used to build a basic model of the switching system and a random DoS attack model. The basic model of the switching system includes a network layer and a control layer. A multi-channel switching model construction module is used to construct a multi-channel switching model under random DoS attack based on the switching system basic model and the random DoS attack model. The traditional basic defense strategy establishment module is used to establish a traditional basic defense strategy with the goal of satisfying exponential mean square stability and H-infinity performance of a multi-channel switching model under random DoS attacks. The correlation constraint establishment module is used to perform channel modeling on the network layer of the multi-channel switching model under the random DoS attack and to establish correlation constraints in conjunction with the control layer. An optimization objective establishment module is used to establish an optimization objective that minimizes the performance parameter H based on bandwidth allocation at the network layer and controller gain at the control layer. A two-layer defense strategy construction module is used to improve the traditional basic defense strategy based on optimization objectives and related constraints to obtain a two-layer defense strategy; The dual-layer defense strategy solution module is used to solve the controller gain matrix of the control layer in the dual-layer defense strategy to obtain the minimum H-infinity performance parameter, and then obtain the optimal defense strategy.