Hybrid game-based edge intelligence control platform risk assessment method and system
By introducing a hybrid attack-defense game strategy and a dynamic Bayesian network into the attack graph model of the edge intelligent control platform, the problem of insufficient dynamic threat monitoring in risk assessment in existing technologies is solved, and high-precision risk assessment and real-time response for the edge intelligent control platform are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD
- Filing Date
- 2024-12-23
- Publication Date
- 2026-06-23
Smart Images

Figure CN122263103A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of edge intelligent control platform control, and specifically to a risk assessment method and system for edge intelligent control platforms based on hybrid game theory. Background Technology
[0002] With the rapid development of IoT and 5G communication technologies, edge intelligent control platforms, as an emerging computing paradigm, are widely used in industrial automation, smart cities, and telemedicine due to their low latency and high efficiency. However, the widespread adoption of this distributed architecture has also brought new security challenges. The decentralized deployment of edge devices makes them more vulnerable to physical attacks, unauthorized intrusions, and data tampering. Coupled with their resource-constrained nature, traditional security mechanisms often struggle to effectively cover these vulnerabilities. Specifically, the risks faced by edge platforms include, but are not limited to: external malicious attacks (such as DDoS attacks and man-in-the-middle attacks), exploitation of internal security vulnerabilities, data breaches, privacy violations, and supply chain security threats. Therefore, a comprehensive and accurate assessment of these risks is urgently needed to ensure the stable operation of the platform and the security of user data.
[0003] Currently, risk assessments for edge intelligent control platforms largely rely on traditional security audits, static risk assessment models, or simple quantitative analysis methods. These methods generally have several limitations: First, they often ignore the dynamically changing threat scenarios in edge computing environments and lack the ability to dynamically monitor and respond to real-time threats; second, the assessment models are overly simplified, usually based only on historical data or static rules, making it difficult to accurately reflect complex system interactions and changes in attacker behavior; third, the assessment process lacks sufficient understanding of the causal relationships of security events, ignores the strategic interactions between attackers and defenders, resulting in inaccurate assessment results, and often neglects cost-benefit analysis of security measures. Summary of the Invention
[0004] To address the shortcomings of existing technologies, such as neglecting dynamically changing threat scenarios in edge computing environments, lacking dynamic monitoring and response capabilities for real-time threats, overly simplistic assessment models that fail to accurately reflect complex system interactions and changes in attacker behavior, insufficient understanding of the causal relationships of security events during the assessment process, and neglect of the strategic interactions between attackers and defenders, leading to inaccurate assessment results and often overlooking the cost-benefit analysis of security measures, this invention proposes a risk assessment method for edge intelligent control platforms based on hybrid game theory, comprising:
[0005] A security risk hierarchy is constructed based on the information domain and physical domain of the edge intelligent control platform;
[0006] The attack graph model is used to describe potential attack paths in the edge intelligent control platform. A hybrid attack and defense game strategy is added to the nodes. The risk value of the nodes in the attack graph is determined by combining fuzzy hierarchical analysis and Critic combined weighting.
[0007] Based on dynamic Bayesian networks, the correlation between risk factors is updated according to real-time monitoring data, the risk values of nodes are optimized, and the risk value of the root node is calculated. The risk of the intelligent control platform is then assessed based on the optimized node and root node risk values.
[0008] Optionally, the construction of a security risk hierarchy based on the edge intelligent control platform's ground information domain and physical domain includes:
[0009] The target layer is the edge intelligent control platform;
[0010] The information domain and physical domain of the edge intelligent control platform are used as primary indicators;
[0011] The attack methods and techniques in the information domain and physical domain are used as secondary indicators of the primary indicator;
[0012] The specific attack behaviors or conditions derived from the secondary indicators are the tertiary indicators of the secondary indicator layer.
[0013] Optionally, the step of using an attack graph model to describe potential attack paths in the edge intelligent control platform, and incorporating a hybrid attack-defense game strategy into the nodes, combined with fuzzy hierarchical analysis and Critic combined weighting, to determine the risk value of nodes in the attack graph includes:
[0014] The edge intelligent control platform components and their network vulnerabilities are abstracted as sensor nodes, controller nodes, and actuator nodes;
[0015] The normal operation of the edge intelligent control platform is taken as the root node, the attack points related to different attack stages or components are taken as intermediate nodes, and the physical components or attack actions involved in specific attack events are taken as leaf nodes.
[0016] A hybrid attack-defense game strategy is introduced on the leaf nodes, intermediate nodes, and root nodes to simulate the interactive decision-making process between attackers and defenders, and to obtain the probability that the attacker will choose a certain attack behavior and the probability that the defender will take a certain defensive measure.
[0017] The weights of each defense method are determined by using fuzzy hierarchical analysis and Critic combined weighting, thereby determining the risk values of leaf nodes and root nodes in the attack graph.
[0018] Optionally, the introduction of a hybrid attack-defense game strategy at the leaf nodes, intermediate nodes, and root node to simulate the interactive decision-making process between the attacker and the defender, and to obtain the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure, includes:
[0019] Calculate the defender's and attacker's profits based on different attack and defense profit functions;
[0020] Based on the defender's and attacker's payoffs, the attack-defense game problem is solved to obtain the optimal strategies for each of the attacker and defender.
[0021] A payoff matrix is formed based on the payoff functions of the optimal strategies adopted by the attacker and defender, respectively.
[0022] If the payoff matrix satisfies the judgment condition under the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action, then the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action are taken as the solution of the mixed strategy Nash equilibrium, thereby obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure.
[0023] Optionally, the method of determining the weight of each defense method using a combination of fuzzy hierarchical analysis and Critic weighting, and thus determining the risk values of leaf nodes and root nodes in the attack graph, includes:
[0024] The fuzzy hierarchical analysis method is used to construct a judgment matrix based on expert judgment, and the comparative scale is used to quantify the relative importance of each evaluation factor and calculate the subjective weight of each level of indicator.
[0025] Using the Critic weighting method, the objective weights of each indicator are calculated based on the variability and interrelationships of the indicators.
[0026] The weights of the indicators are determined by a combined weighting method based on the subjective weights and the objective weights.
[0027] By applying the weights of the indicators to the nodes and combining the payoff function and probability of occurrence of each node's attack and defense strategy, the risk value of the node is calculated.
[0028] Optionally, the step of constructing a judgment matrix based on expert judgment using fuzzy hierarchical analysis, quantifying the relative importance of each evaluation factor using a comparison scale, and calculating the subjective weights of each level of indicators includes:
[0029] Based on the relationships between each level in the safety risk hierarchy, a fuzzy judgment matrix is established using the 0.1-0.9 nine-scale method;
[0030] When the elements in the fuzzy judgment matrix meet the set judgment conditions, the fuzzy judgment matrix is a fuzzy complementary matrix;
[0031] The fuzzy complementary matrix is subjected to a consistency check, converted into a fuzzy consistent matrix, and the weights of the fuzzy consistent matrix are calculated based on the weight value formula.
[0032] The subjective weight of an indicator is obtained by multiplying the weights of each level of indicator.
[0033] Optionally, the step of using the Critic weighting method to calculate the objective weight of each indicator based on the variability and interrelationship of the indicators includes:
[0034] Dimensionless processing is performed on indicators at all levels;
[0035] Calculate the standard deviation of each indicator and use correlation analysis to analyze the conflict between two indicators to obtain a quantitative index of conflict.
[0036] The objective weights of each indicator are calculated based on the standard deviation and the conflict quantification index.
[0037] Optionally, the weight of the indicator is calculated using the following formula:
[0038]
[0039] In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
[0040] Optionally, the step of optimizing the risk value of a node based on a dynamic Bayesian network and updating the correlation between risk factors according to real-time monitoring data includes:
[0041] For each node, calculate the conditional probability under different combinations of parent node states based on the collected data;
[0042] Using the constructed dynamic Bayesian network and the learned parameters, the state of nodes within future time slices is predicted;
[0043] Based on the predicted node status and combined with weighting, the dynamic changes in risk value are calculated.
[0044] The portfolio weighting is optimized based on the dynamic changes in risk value;
[0045] By using optimized combined weighting, the risk value of each node in the attack graph model is recalculated.
[0046] Optionally, the calculation of the root node risk value, and the assessment of the risk of the intelligent control platform based on the optimized node and root node risk values, includes:
[0047] The risk value of the root node is determined based on the structure and node relationships of the attack graph.
[0048] The risk level of the system is determined by the proportion of the risk value of the root node to the total risk value of the edge intelligent control platform.
[0049] Furthermore, this invention also provides a risk assessment system for an edge intelligent control platform based on hybrid game theory, comprising:
[0050] The structural building module is used to construct a security risk hierarchy based on the information domain and physical domain of the edge intelligent control platform.
[0051] The risk value calculation module is used to describe potential attack paths in the edge intelligent control platform using an attack graph model, and to add a hybrid attack and defense game strategy to the nodes. It combines fuzzy hierarchical analysis and Critic combined weighting to determine the risk value of the nodes in the attack graph.
[0052] The risk assessment module is used to update the correlation of risk factors based on real-time monitoring data using a dynamic Bayesian network, optimize the risk value of nodes, calculate the risk value of the root node, and assess the risk of the intelligent control platform based on the optimized node and root node risk values.
[0053] Optionally, the structure building module is specifically used for:
[0054] The target layer is the edge intelligent control platform;
[0055] The information domain and physical domain of the edge intelligent control platform are used as primary indicators;
[0056] The attack methods and techniques in the information domain and physical domain are used as secondary indicators of the primary indicator;
[0057] The specific attack behaviors or conditions derived from the secondary indicators are the tertiary indicators of the secondary indicator layer.
[0058] Optionally, the risk value calculation module includes:
[0059] The abstract processing submodule is used to take the normal operation of the edge intelligent control platform as the root node, the attack points related to different attack stages or components as intermediate nodes, and the physical components or attack actions involved in specific attack events as leaf nodes.
[0060] The simulation submodule is used to introduce a hybrid attack and defense game strategy on the leaf nodes, intermediate nodes and root nodes to simulate the interactive decision-making process between the attacker and the defender, and to obtain the probability that the attacker will choose a certain attack behavior and the probability that the defender will take a certain defensive measure.
[0061] The risk calculation submodule is used to determine the weight of each defense method by using fuzzy hierarchical analysis and Critic combined weighting, and then determine the risk value of the leaf nodes and root nodes in the attack graph.
[0062] Optionally, the simulation submodule is specifically used for:
[0063] Calculate the defender's and attacker's profits based on different attack and defense profit functions;
[0064] Based on the defender's and attacker's payoffs, the attack-defense game problem is solved to obtain the optimal strategies for each of the attacker and defender.
[0065] A payoff matrix is formed based on the payoff functions of the optimal strategies adopted by the attacker and defender, respectively.
[0066] If the payoff matrix satisfies the judgment condition under the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action, then the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action are taken as the solution of the mixed strategy Nash equilibrium, thereby obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure.
[0067] Optionally, the risk calculation submodule includes:
[0068] The supervisory weight calculation unit is used to construct a judgment matrix based on expert judgment using fuzzy hierarchical analysis, quantify the relative importance of each evaluation factor using a comparative scale, and calculate the subjective weight of each level of indicator.
[0069] The objective weight calculation unit is used to calculate the objective weight of each indicator based on the variability and interrelationship of the indicators using the Critic weighting method.
[0070] A combined weighting unit is used to determine the weight of an indicator based on the subjective weight and the objective weight using a combined weighting method.
[0071] The calculation unit is used to apply the weights of the indicators to the nodes, and calculate the risk value of the nodes by combining the payoff function of each node's attack and defense strategy with the probability of occurrence.
[0072] Optionally, the supervisor weight calculation unit is specifically used for:
[0073] Based on the relationships between each level in the safety risk hierarchy, a fuzzy judgment matrix is established using the 0.1-0.9 nine-scale method;
[0074] When the elements in the fuzzy judgment matrix meet the set judgment conditions, the fuzzy judgment matrix is a fuzzy complementary matrix;
[0075] The fuzzy complementary matrix is subjected to a consistency check, converted into a fuzzy consistent matrix, and the weights of the fuzzy consistent matrix are calculated based on the weight value formula.
[0076] The subjective weight of an indicator is obtained by multiplying the weights of each level of indicator.
[0077] Optionally, the objective weight calculation unit is specifically used for:
[0078] Dimensionless processing is performed on indicators at all levels;
[0079] Calculate the standard deviation of each indicator and use correlation analysis to analyze the conflict between two indicators to obtain a quantitative index of conflict.
[0080] The objective weights of each indicator are calculated based on the standard deviation and the conflict quantification index.
[0081] Optionally, the weight of the indicator is calculated using the following formula:
[0082]
[0083] In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
[0084] In another aspect, this application also provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus;
[0085] The memory is used to store one or more programs;
[0086] When the one or more programs are executed by the at least one processor, the risk assessment method for the edge intelligent control platform based on hybrid game theory as described above is implemented.
[0087] Furthermore, this application also provides a readable storage medium on which an executable program is stored, which, when executed, implements the risk assessment method for the edge intelligent control platform based on hybrid game theory as described above.
[0088] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0089] This invention provides a risk assessment method for edge intelligent control platforms based on hybrid game theory, comprising: constructing a security risk hierarchy based on the geospatial and physical domains of the edge intelligent control platform; describing potential attack paths in the edge intelligent control platform using an attack graph model, incorporating hybrid attack-defense game strategies into nodes, and determining the risk value of nodes in the attack graph by combining fuzzy hierarchical analysis and Critic combined weighting; optimizing the risk value of nodes based on a dynamic Bayesian network by updating the correlation of risk factors according to real-time monitoring data, calculating the risk value of the root node, and assessing the risk of the intelligent control platform based on the optimized node and root node risk values. This invention utilizes an attack graph model to depict in detail the attack paths that the platform may encounter, accurately reflecting complex system interactions and changes in attacker behavior, enabling dynamic monitoring and response to real-time threats; through game theory analysis, defining payoff functions for attackers and defenders, solving for Nash equilibrium, and accurately characterizing the optimal solution for both sides' strategy choices using a mathematical model, thereby determining the implementation probability of different defense strategies, improving the accuracy of the assessment results, and enhancing the real-world adaptability of the assessment. Attached Figure Description
[0090] Figure 1 This is a flowchart of the risk assessment method for the edge intelligent control platform based on hybrid game theory of the present invention.
[0091] Figure 2 This is a hierarchical structure diagram of security risk assessment elements based on the edge intelligent control platform of the present invention, which includes information domain and physical domain.
[0092] Figure 3 This is a schematic diagram of the attack graph model structure of the edge intelligent control platform of the present invention;
[0093] Figure 4 This is a step diagram illustrating the risk assessment method for the edge intelligent control platform based on hybrid game theory of the present invention.
[0094] Figure 5 This is a schematic diagram of an electronic device structure according to the present invention. Detailed Implementation
[0095] This invention proposes a risk assessment method for edge intelligent control platforms based on hybrid game theory, aiming to address the diverse security challenges faced by edge computing platforms in the era of the Internet of Things and 5G. This method constructs a two-dimensional security risk assessment framework spanning the information and physical domains, achieving comprehensive coverage of potential threats to edge platforms. It utilizes an attack graph model to depict potential attack paths within the platform, incorporating hybrid game strategies from both attackers and defenders into the nodes of the attack graph, effectively simulating real-world attack-defense interaction scenarios. Through game theory analysis, the payoff functions of attackers and defenders are established, and Nash equilibria are solved to predict strategy selection, enhancing the practical adaptability of the assessment. Combining fuzzy hierarchical analysis and the Critic weighting method, the risk of each node in the attack graph model is quantified. Based on this, a dynamic Bayesian network is introduced to update the correlations of risk factors in real time, optimize node risk calculation, predict risk propagation paths, and continuously improve the accuracy and practicality of risk assessment, providing more scientific and effective decision support for the security management of edge intelligent control platforms.
[0096] To better understand the present invention, the following description, in conjunction with the accompanying drawings and embodiments, will further illustrate the content of the present invention.
[0097] Example 1:
[0098] A risk assessment method for an edge intelligent control platform based on hybrid game theory, such as Figure 1 As shown, it includes:
[0099] Step S1: Construct a security risk hierarchy based on the edge intelligent control platform's ground information domain and physical domain;
[0100] Step S2: Use an attack graph model to describe potential attack paths in the edge intelligent control platform, and add a hybrid attack and defense game strategy to the nodes. Combine fuzzy hierarchical analysis and Critic combined weighting to determine the risk value of the nodes in the attack graph.
[0101] Step S3: Based on the dynamic Bayesian network, update the correlation of risk factors according to real-time monitoring data, optimize the risk value of nodes, calculate the risk value of the root node, and assess the risk of the intelligent control platform based on the optimized node and root node risk values.
[0102] The following is a further explanation of each step in the application process:
[0103] Step S1: Construct a security risk hierarchy based on the edge intelligent control platform's ground information domain and physical domain, including:
[0104] The target layer is the edge intelligent control platform;
[0105] The information domain and physical domain of the edge intelligent control platform are used as primary indicators;
[0106] The attack methods and techniques in the information domain and physical domain are used as secondary indicators of the primary indicator;
[0107] The specific attack behaviors or conditions derived from the secondary indicators are the tertiary indicators of the secondary indicator layer.
[0108] Construct a hierarchical structure of security risk assessment elements based on an edge intelligent control platform, encompassing both information and physical domains.
[0109] like Figure 2 As shown, a cross-domain hierarchical structure for security risk assessment elements based on an edge intelligent control platform is constructed. This structure comprehensively considers various security threats faced by the edge intelligent control platform from two core aspects: the information domain and the physical domain.
[0110] Security analysis was conducted on the information and physical domains of the edge intelligent control platform. The assessment elements were summarized to derive the security risk assessment elements for the edge intelligent control platform. The information domain was assessed from four aspects: terminal device security, authentication service security, access control security, and communication security. This included 15 security assessment elements such as vulnerability detection and removal, malicious code detection and removal, online updates, software fault tolerance and attack resistance; configuration management, session management, identity authentication; user access control, information access control, service access control; and communication integrity and confidentiality. The physical domain was assessed from three aspects: physical device security, physical environment security, and physical interface security. This included 10 security assessment elements such as equipment hardening measures, physical access control, environmental security (e.g., fire prevention, waterproofing, theft prevention); disaster protection (e.g., earthquakes, floods), power supply stability, humidity control, temperature control; interface protection mechanisms, physical interface security, and interface access control. These elements were then constructed into a hierarchical structure diagram of security risk assessment elements.
[0111] Step S2: Utilize an attack graph model to describe potential attack paths in the edge intelligent control platform, and incorporate a hybrid attack-defense game strategy into the nodes. Combine fuzzy hierarchical analysis and Critic weighting to determine the risk value of each node in the attack graph, including:
[0112] The edge intelligent control platform components and their network vulnerabilities are abstracted as sensor nodes, controller nodes, and actuator nodes;
[0113] The normal operation of the edge intelligent control platform is taken as the root node, the attack points related to different attack stages or components are taken as intermediate nodes, and the physical components or attack actions involved in specific attack events are taken as leaf nodes.
[0114] A hybrid attack-defense game strategy is introduced on the leaf nodes, intermediate nodes, and root nodes to simulate the interactive decision-making process between attackers and defenders, and to obtain the probability that the attacker will choose a certain attack behavior and the probability that the defender will take a certain defensive measure.
[0115] The weights of each defense method are determined by using fuzzy hierarchical analysis and Critic combined weighting, thereby determining the risk values of leaf nodes and root nodes in the attack graph.
[0116] Furthermore, the introduction of a hybrid attack-defense game strategy at the leaf nodes, intermediate nodes, and root node simulates the interactive decision-making process between the attacker and the defender, obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure, including:
[0117] Calculate the defender's and attacker's profits based on different attack and defense profit functions;
[0118] Based on the defender's and attacker's payoffs, the attack-defense game problem is solved to obtain the optimal strategies for each of the attacker and defender.
[0119] A payoff matrix is formed based on the payoff functions of the optimal strategies adopted by the attacker and defender, respectively.
[0120] If the payoff matrix satisfies the judgment condition under the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action, then the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action are taken as the solution of the mixed strategy Nash equilibrium, thereby obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure.
[0121] Furthermore, the method of using fuzzy hierarchical analysis and Critic combined weighting to determine the weight of each defense method, and thus determining the risk values of leaf nodes and root nodes in the attack graph, includes:
[0122] The fuzzy hierarchical analysis method is used to construct a judgment matrix based on expert judgment, and the comparative scale is used to quantify the relative importance of each evaluation factor and calculate the subjective weight of each level of indicator.
[0123] Using the Critic weighting method, the objective weights of each indicator are calculated based on the variability and interrelationships of the indicators.
[0124] The weights of the indicators are determined by a combined weighting method based on the subjective weights and the objective weights.
[0125] By applying the weights of the indicators to the nodes and combining the payoff function and probability of occurrence of each node's attack and defense strategy, the risk value of the node is calculated.
[0126] Furthermore, the method employs fuzzy hierarchical analysis to construct a judgment matrix based on expert judgment, uses a comparative scale to quantify the relative importance of each evaluation factor, and calculates the subjective weights of each level of indicator, including:
[0127] Based on the relationships between each level in the safety risk hierarchy, a fuzzy judgment matrix is established using the 0.1-0.9 nine-scale method;
[0128] When the elements in the fuzzy judgment matrix meet the set judgment conditions, the fuzzy judgment matrix is a fuzzy complementary matrix;
[0129] The fuzzy complementary matrix is subjected to a consistency check, converted into a fuzzy consistent matrix, and the weights of the fuzzy consistent matrix are calculated based on the weight value formula.
[0130] The subjective weight of an indicator is obtained by multiplying the weights of each level of indicator.
[0131] Furthermore, the objective weights are obtained using an objective weighting method based on the comparative strength and conflict between evaluation indicators, including:
[0132] Dimensionless processing is performed on indicators at all levels;
[0133] Calculate the standard deviation of each indicator and use correlation analysis to analyze the conflict between two indicators to obtain a quantitative index of conflict.
[0134] The objective weights of each indicator are calculated based on the standard deviation and the conflict quantification index.
[0135] Furthermore, the weights of the indicators are calculated using the following formula:
[0136]
[0137] In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
[0138] Furthermore, the optimization of node risk values based on dynamic Bayesian networks, updating risk factor relationships according to real-time monitoring data, includes:
[0139] For each node, calculate the conditional probability under different combinations of parent node states based on the collected data;
[0140] Using the constructed dynamic Bayesian network and the learned parameters, the state of nodes within future time slices is predicted;
[0141] Based on the predicted node status and combined with weighting, the dynamic changes in risk value are calculated.
[0142] The portfolio weighting is optimized based on the dynamic changes in risk value;
[0143] By using optimized combined weighting, the risk value of each node in the attack graph model is recalculated.
[0144] Furthermore, the calculation of the root node risk value, and the assessment of the risk of the intelligent control platform based on the optimized node and root node risk values, includes:
[0145] The risk value of the root node is determined based on the structure and node relationships of the attack graph.
[0146] The risk level of the system is determined by the proportion of the risk value of the root node to the total risk value of the edge intelligent control platform.
[0147] Step S2 specifically includes:
[0148] Step 1: Use an attack graph model to describe potential attack paths in the edge intelligent control platform, and add a hybrid attack and defense game strategy to the nodes;
[0149] Step 2: Determine the payoff functions of the attacker and defender using game theory, and solve for the Nash equilibrium to determine the probability of different defense strategies occurring;
[0150] Step 3: Combine fuzzy hierarchical analysis and Critic weighting to determine the risk value of nodes in the attack graph.
[0151] In step 1, the attack graph model represents potential attacks on the platform in graph form. Nodes represent the attacker's attack steps or states, and edges represent the relationships between attack steps. In the edge control platform, the root node of the attack graph represents the normal operation of the entire system. Intermediate nodes of the attack graph are established based on the physical components in the edge intelligent control platform, such as sensors, controllers, and actuators. Directed edges are used to represent the attack logic relationships between components, and the direction of the edges represents the direction of the attack. A hybrid attack-defense game strategy is incorporated into the nodes of the attack graph to realize the game between the attacker and the defender.
[0152] In step 2, payoff functions for the attacker and defender are defined. The attacker's payoff function considers the probability of a successful attack, the cost of the attack, and the indirect rewards after a failed attack. The defender's payoff function considers the probability of a successful defense, the cost of defense, and potential losses. The Nash equilibrium is solved using game theory to determine the probability distribution of actions taken by the attacker and defender under different defense strategies.
[0153] In step 3, within the edge intelligent control platform, a judgment matrix is first constructed based on expert judgment using fuzzy hierarchical analysis. A comparative scale is then used to quantify the relative importance of each evaluation factor, calculating the subjective weights of each level of indicator. Next, the Critic weighting method is used to objectively calculate the weights of each indicator based on their variability and interrelationships. Subsequently, the subjective and objective weights are comprehensively considered through an optimized combination strategy to reduce the bias of a single method, resulting in a more reasonable and balanced comprehensive weight. Finally, these comprehensive weights are applied to the nodes of the attack graph model, and the risk value of each node is calculated by combining the payoff function and probability of occurrence of each node's attack and defense strategy.
[0154] Step S3: Based on the dynamic Bayesian network, update the correlation between risk factors according to real-time monitoring data, optimize the risk values of nodes, calculate the risk value of the root node, and assess the risk of the intelligent control platform based on the optimized node and root node risk values. Specifically, this includes:
[0155] By leveraging dynamic Bayesian networks, real-time operational data from the edge intelligent control platform is collected, including system logs, network traffic monitoring data, and device status information. This data is used to update the conditional probability distributions among risk factors, reflecting the dynamic changes in their relationships. Simultaneously, based on the inference capabilities of dynamic Bayesian networks, and combining the initial risk values of nodes with real-time data and the relationships between risk factors, the calculation of node risk values is optimized, resulting in a more accurate assessment of the risk status of each node at the current moment. Furthermore, dynamic Bayesian networks are used to predict the propagation path and impact range of risks within the platform, enabling the early identification of potentially high-risk nodes and areas.
[0156] Based on the optimized attack graph model and node risk values using a dynamic Bayesian network, the risk value of the root node is calculated according to the structure and node relationships of the attack graph. The system's risk level is determined by the proportion of the root node's risk value to the total risk value of the edge intelligent control platform. Based on the ratio of the root node's risk value to the overall platform risk value, the risk level is categorized into different levels, such as low risk, medium risk, and high risk, providing security managers with intuitive risk assessment results to help them formulate corresponding security strategies and resource optimization configuration schemes.
[0157] To achieve the above objectives, the present invention provides the following technical solution:
[0158] A risk assessment method for an edge intelligent control platform based on hybrid game theory, such as Figure 4 As shown, it includes the following steps:
[0159] Step 1, as follows Figure 2As shown, a cross-domain hierarchical structure for security risk assessment elements based on an edge intelligent control platform is constructed. This structure comprehensively considers various security threats faced by the edge intelligent control platform from two core aspects: the information domain and the physical domain.
[0160] Step 2, as follows Figure 3 As shown, an attack tree model is used to describe potential attack paths in an edge intelligent control platform, and a hybrid attack-defense game strategy is incorporated into the leaf nodes. First, the key assets and potential security targets of the edge intelligent control platform are identified, becoming the root nodes of the attack graph. Next, possible attack methods and techniques are analyzed and added as intermediate nodes to the attack graph, with directed edges representing the order and relationships of the attacks. Further, each intermediate node is refined, expanding on specific attack behaviors or conditions to form leaf nodes. In these nodes, a hybrid attack-defense game strategy is introduced, simulating the decision-making process between attackers and defenders. Attackers consider potential defensive measures when choosing an attack path, while defenders optimize their defense strategies based on the attacker's potential behaviors.
[0161] Step 3: Determine the payoff functions of the attacker and defender using game theory and solve for the Nash equilibrium to determine the probability of different defense strategies occurring. First, based on the specific operating environment of the edge intelligent control platform, payoff functions are designed for both the attacker and defender. The attacker's payoff function reflects the benefits gained from a successful attack, including the value of directly damaging or stealing information, and the indirect benefits that may be gained in the event of failure. The defender's payoff function focuses on the losses recovered from a successful defense against an attack, as well as the negative effects caused by the cost of defense. Considering that the attacker and defender may adopt more than one strategy, and that the choice of each strategy is not fixed, a mixed strategy analysis is adopted, meaning that each party may choose different attack or defense actions with a certain probability. This requires that the payoff functions be calculated under a probability distribution to form a payoff matrix.
[0162] This paper abstracts the possible attack paths and defense measures in an edge intelligent control platform into an attack-defense game model. The attack graph model is used to map attack paths, while defense strategies are quantitatively analyzed using relevant methods. Mathematical tools (such as linear programming and iterative algorithms) are used to solve for the Nash equilibrium under this model, finding the optimal combination of strategies for both sides within a given set of strategies. The mathematical model accurately characterizes the optimal solution for both sides' strategy choices, thereby determining the probability of implementing different defense strategies.
[0163] Step 4: Combining fuzzy hierarchical analysis (AHP) and Critic weighting, determine the risk value of the leaf nodes in the attack tree. First, using AHP, a judgment matrix is constructed based on expert opinions, and a comparative scale is used to quantify the relative importance of each evaluation factor, calculating the subjective weights of each level of indicators. Next, using the Critic weighting method, the weights of each indicator are objectively calculated based on the variability and interrelationships of the indicators. Finally, the subjective and objective weights are comprehensively considered through an optimized combination strategy to reduce the bias of a single method and obtain a more reasonable and balanced comprehensive weight.
[0164] Step 5: Calculate the risk value of the root node based on the attack tree model to assess the overall security risk level of the edge intelligent control platform. Utilizing a dynamic Bayesian network, real-time operational data from the edge intelligent control platform is collected, including system logs, network traffic monitoring data, and device status information. The conditional probability distribution between risk factors is updated based on this data to reflect the dynamic changes in the relationships between risk factors. Simultaneously, based on the inference capabilities of the dynamic Bayesian network, combined with the initial risk value of the node, real-time data, and the relationships between risk factors, the calculation of the node risk value is optimized to more accurately assess the risk status of each node at the current moment.
[0165] Based on the optimized attack graph model and node risk values using a dynamic Bayesian network, the risk value of the root node is calculated according to the structure and node relationships of the attack graph. The risk level of the system is determined by the proportion of the root node's risk value to the total risk value of the edge intelligent control platform. Based on the ratio of the root node's risk value to the total platform risk value, the risk level is divided into different levels, such as low risk, medium risk, and high risk. This assesses the overall security risk level of the edge intelligent control platform, providing security managers with an intuitive risk distribution map to guide the formulation of security strategies and the optimal allocation of resources.
[0166] Example 2
[0167] The technical solutions in the implementation of the present invention will be clearly and completely described below with reference to the accompanying drawings in the examples of the present invention.
[0168] In step 1, combined with Figure 2This invention provides a hierarchical structure diagram of security risk assessment elements integrating information and physical domains based on an edge intelligent control platform. The information domain is divided into four aspects: terminal device security, authentication service security, access control security, and communication security. Terminal device security includes seven elements: vulnerability detection and removal, malicious code detection and removal, online updates, software fault tolerance, and attack resistance. Authentication service security includes three elements: configuration management, session management, and identity authentication. Access control security includes three elements: user access control, information access control, and service access control. Communication security includes two elements: communication integrity and communication confidentiality. The physical domain is divided into three aspects: physical device security, physical environment security, and physical interface security. Physical device security includes three elements: device hardening measures, physical access control, and environmental security (such as fire prevention, waterproofing, and theft prevention). Physical environment security includes four elements: disaster protection (such as earthquakes and floods), power supply stability, humidity control, and temperature control. Physical interface security includes three elements: interface protection mechanisms, physical interface security, and interface access control.
[0169] In step 2, combined Figure 3 The first step is to construct an attack graph model. When assessing the risk of an edge intelligent control platform, both the information domain and the physical domain must be considered. Therefore, it needs to be modeled from three key levels: the physical layer, the transport layer, and the decision layer. Assuming the entire edge intelligent control platform consists of ns sensors, nh controllers, and na actuators, these components and their network vulnerabilities are abstracted into sensor nodes, controller nodes, and actuator nodes, thus achieving joint modeling of the edge intelligent control platform. The edge intelligent control platform consists of the following set of nodes:
[0170] s = {s1, s2, ..., s} ns}
[0171] h = {h1, h2, ..., h} nh}
[0172] a = {a1, a2, ..., a} na}
[0173] Where s is the set of sensors, h is the set of controllers, a is the set of actuators, and s1, s2, s3 are the sets ... actuators, h is the set of actuators, h is the set of actuators ns These are the 1st, 2nd, and ns-th sensors, h1, h2, and h3 respectively. nh Let a1, a2, and a be the 1st, 2nd, and nh-th controllers, respectively. na These are the 1st, 2nd, and nath executors, respectively.
[0174] Within the framework of the edge intelligent control platform, the attack graph structure is designed as follows: Figure 2As shown in the diagram, the root node of the attack graph represents the normal operation of the entire platform. Intermediate nodes represent attack points related to different attack stages or components, connected by directed edges to indicate the attack flow and dependencies. Leaf nodes represent the physical components or attack actions involved in specific attack events, i.e., the specific attack behaviors that the attacker might target, such as sensors, actuators, or controller nodes. Based on these nodes, a hybrid attack-defense game strategy is introduced, simulating the interactive decision-making process between attackers and defenders. When choosing an attack path, the attacker evaluates potential defensive measures, while the defender adjusts and optimizes its defense strategy based on the attacker's potential actions.
[0175] In the attack graph, a hybrid attack and defense game strategy is added to the nodes of the attack graph to realize the game between the attacker and the defender.
[0176] In step 3, the attack-defense game model ADGM is defined in the attack graph nodes:
[0177] S301:ADGM={O,V,π,Z}
[0178] Where, O = (O At O De ), representing participants who control multiple activities in a game, with the subscript At indicating the attacker, the subscript De indicating the defender, and O At As the attacker, O De For the defender; V = {V At V De}, where V At ={v At 1 ,v At 2 ,…,v At m}, V De ={v De 1 ,v De 2 ,…,v De n}, where m represents the m possible attack actions the attacker can take during the game, n represents the n possible defensive actions the defender can take during the game, and V At V represents the attack actions that the attacker might take during the game. De v represents the defensive actions that the defender might take during the game. At 1 v At 2 v At m These represent the first, second, and m-th attack actions that the attacker might take during the game, where v represents the attack action.De 1 v De 2 v De n These represent the first, second, and nth defensive actions that the defender might take during the game; π = {π At ,π De π represents a specific decision made by the attacker and defender during the game. At π represents the attack decisions made by the attacker during the game. De Let π represent a defensive decision made by the defender during the game. If multiple actions are distributed with certain probabilities, forming a mixed strategy, then π... At ={p(v At 1 ),p(v At 2 ),…,p(v At m )},p(v At m Let be the probability that the attacker performs the m-th action, where m is a positive integer, such as 1, 2, π. De ={p(v De 1 ),p(v De 2 ),…,p(v De n)},p(v De (n) represents the probability that the defender will perform the nth action, where n is a positive integer, such as 1, 2, etc.; Z = (Z At Z De Z represents the payoff matrix. At and Z De These represent the payoffs of the attacker and defender at the end of the game, respectively, and these payoffs are influenced by the strategies chosen by both sides. In the case of mixed games, the payoffs can be represented by a payoff matrix Z.
[0179] S302: The different attack and defense benefit function calculation methods are defined as follows:
[0180] S3021: Define the defender's benefit function RF D This represents the defender's benefit, calculated using the following formula:
[0181] RF D = (1-θ)×(1-υ)SL-θSL-DR
[0182] Where θ represents the success rate of different attack methods against different defense methods, 1-θ represents the probability of a successful defense using this method, υ represents the benefit factor for indirect rewards gained after a failed attack, DR represents the cost of the defense method, i.e., the cost incurred in using a particular defense method, and SL represents the potential loss caused by the attack method corresponding to this defense method. The benefit function of the defense method is calculated as follows:
[0183] First, calculate the benefits of successfully employing this defense method, then subtract the attacker's benefits if the defense fails, and finally subtract the cost of implementing this defense.
[0184] S3022: Define the attacker's profit function RF A This represents the attacker's gain, calculated using the following formula:
[0185] RF A =θSL-(1-θ)υSL-AR
[0186] Where θ is the probability of success for this attack method, AR represents the cost of the attack method, i.e., the expense incurred in employing a particular attack method, and υ is the benefit factor for the indirect reward gained if this attack method fails. The benefit function of the defense method is calculated as follows:
[0187] The gains from a successful attack minus the indirect gains from a failed attack, plus the cost of carrying out the attack.
[0188] S303: After determining the payoff functions of the attacker and defender, the attack-defense game problem can be further solved. The solution to the Nash equilibrium describes the state where, given the strategies of other players, no one has an incentive to unilaterally change their own strategy; that is, the probability of all players' decisions. In the attack-defense game of the edge intelligent control platform, the attacker and defender each adopt their optimal strategies to form a strategy combination. in, It is the attacker's strategy against the defender. The best strategy It is the defender's strategy against the attacker. The optimal strategy, i.e., for any p(v) At m)∈π At ,p(v De n)∈π De ,p(v At m) represents the probability that the attacker chooses attack behavior m, p(v De n Let ) represent the probability that the defender chooses action n, satisfying:
[0189]
[0190]
[0191] in, Z represents the attacker's gain under the optimal combination of attack and defense strategies. At (p(v At m ),p(v De n Given the probability that the attacker chooses attack behavior m and the probability that the defender chooses defensive behavior n, the attacker's payoff is calculated. Z represents the defender's benefit under the optimal combination of attack and defense strategies. De (p(v At m ),p(v De n Given the probability that the attacker chooses attack action m and the probability that the defender chooses defensive action n, the defender's payoff is calculated. Therefore, the strategy... It is the solution to the Nash equilibrium of the ADGM (Advanced Game Theory) model.
[0192] S304: For mixed-policy models, the game actions of the attacker and the strategist are no longer single deterministic choices, but follow a certain probability distribution. If the attacker's policy is π... At ={p(v At 1 ),p(v At 2 ),...,p(v At m)}, the defender's strategy is π De ={p(v De 1 ),p(v De 2 ),...,p(v De Then, under the hybrid strategy, the payoff functions (Z) for the attacker and defender are as follows: At Z De This will form a profit matrix. Where z Atmn , z Denm This represents the individual gains for the attacker and defender after selecting their respective attack and defense methods. For both the attacker and defender, the overall expected payoff function is:
[0193]
[0194]
[0195] Where p(v) At i p(v) represents the probability that the attacker chooses attack behavior i. Dej ) represents the probability that the defender chooses action j.
[0196] S305: If for any p(v) At i ), p(v De j If both of the following equations hold true, then p is called p. * =(p(v) At * ),p(v De * )) is the solution to the mixed-strategy Nash equilibrium, where p(v At * p(v) can be viewed as a probability prediction of attacker behavior, indicating which attack method the attacker might use. De * p represents the probability prediction of the defender's behavior, that is, what defensive method the defender might adopt. * This is the solution for the Nash equilibrium of the mixed strategy.
[0197] Z At (p(v At * ),p(v De j ))≥Z At (p(v At i ),p(v De j ))
[0198] Z De (p(v At i ),p(v De * ))≥Z De (p(v At i ),p(v De j ))
[0199] Among them, Z At (p(v At * ),p(v De j Z represents the attacker's payoff given the probability prediction of the attacker's behavior and the probability of the defender choosing behavior j. De (p(v At i ),p(v De * The probability of the attacker choosing attack behavior i and the likelihood of the defender's behavior are used to predict the defender's profit.
[0200] In step 4, in order to correctly assess the impact of different defense methods on attack graph nodes, a combination of subjective and objective methods is used to determine the weight of each defense method, overcoming the limitations of single weighting.
[0201] S401: Fuzzy Hierarchical Analysis. Fuzzy Hierarchical Analysis (FAHP) is an extension of the classic Analytic Hierarchy Process (AHP). It primarily addresses the issue of weight allocation for evaluation factors during the decision-making process when subjective judgment and uncertainty influence the evaluation. FAHP allows decision-makers to express their evaluation opinions using fuzzy language, such as "slightly important" or "very important," thereby transforming qualitative evaluations into quantitative data and making the decision-making process more flexible and realistic.
[0202] The steps for FAHP are as follows:
[0203] S4011: Determine the evaluation indicators and hierarchical structure. First, based on the characteristics and potential threats of the edge intelligent control platform, clarify the specific elements to be assessed, such as information leakage risk, physical security risk, and access control risk. Construct an evaluation hierarchical structure, typically including an objective layer (e.g., overall platform security), a criterion layer (e.g., the effectiveness of security control measures), and an indicator layer (e.g., the soundness of specific security configurations).
[0204] S4012: Establish a hierarchical structure model. Based on the hierarchical structure diagram determined in the previous step, establish a hierarchical structure model, that is, arrange the various factors into multiple levels in descending order, and form a hierarchical structure system containing criteria, sub-criteria, and leaf nodes.
[0205] S4013: Establish the judgment matrix. For the relationship between each level, use the 0.1-0.9 nine-scale method to establish the judgment matrix, and construct the fuzzy judgment matrix A = (a ij ) N×N As shown in Table 1. When the fuzzy matrix A = (a ij ) N×N The elements in satisfy a ij +a ji When = 1, matrix A is a fuzzy complementary matrix.
[0206] Table 1
[0207]
[0208]
[0209] S4014: Establish a fuzzy consistency matrix. First, construct a fuzzy complementary discriminant matrix A, then perform a consistency check on it, finally converting it into a fuzzy consistency matrix R. When comparing two factors, due to the subjectivity of judgment and the complexity of the problem, it is necessary to perform a consistency check on the discriminant matrix to ensure the objectivity and accuracy of the evaluation results. Then, convert the fuzzy complementary matrix A = (a ij ) N×N Summing each row yields the fuzzy consistency matrix R = (r ij ) N×N ,Right now Through mathematical transformation We obtain matrix R, where a ij Let be an element in the fuzzy complementary discrimination matrix A, representing the fuzzy complementary judgment value of factor i relative to factor j, where N is the order of the matrix and represents the number of factors. ik Let be the element in the i-th row of matrix A, where i is the row index, j is the column index, k is the index variable in the summation formula used to calculate the sum of the elements in the i-th row of matrix A, and r is an element in the fuzzy consistency matrix R. i Let r be the sum of the elements in the i-th row of matrix A. j Let be the sum of the elements in the j-th row of matrix A.
[0210] S4015: Calculate the weight vector. Using fuzzy mathematics, the judgment matrix is transformed into a fuzzy judgment matrix, and the weight vectors for each level are calculated. This is done using the weight value formula. Calculate the weights of matrix R, then multiply the weights of the first-level and second-level indicators respectively, and summarize them level by level to finally obtain a comprehensive weight. Here, N is the order of the matrix, representing the number of factors, and a is a parameter in the weight vector calculation formula, the specific meaning of which needs to be determined in combination with the application scenario.
[0211] S402: The CRITIC method comprehensively measures the objective weight of indicators based on the comparative strength and conflict between them. It considers both the magnitude of indicator variability and the correlation between indicators, recognizing that a larger number does not necessarily indicate greater importance. It relies entirely on the objective attributes of the data itself for scientific evaluation.
[0212] Comparison strength refers to the magnitude of the difference between the values of different evaluation schemes for the same indicator, expressed in the form of standard deviation. The larger the standard deviation, the greater the fluctuation, that is, the greater the difference in values between the schemes, and the higher the weight will be.
[0213] The conflict between indicators is represented by the correlation coefficient. If two indicators have a strong positive correlation, it means that the conflict is smaller and the weight will be lower.
[0214] For the CRITIC method, when the standard deviation is constant, the smaller the conflict between indicators, the smaller the weight; the greater the conflict, the greater the weight. In addition, when the positive correlation between two indicators is greater (the closer the correlation coefficient is to 1), the smaller the conflict, which indicates that the two indicators reflect a large similarity in the information of evaluating the merits of the scheme.
[0215] The steps of the CRITIC method are as follows:
[0216] S4021: Dimensionless Processing of Indicators. To eliminate the impact of different dimensions on the evaluation results, it is necessary to perform dimensionless processing on each indicator. The CRITIC weighting method generally uses forward or reverse processing, but standardization is not recommended because if standardization is used, the standard deviation of all indicators becomes the number 1, meaning that the standard deviation of all indicators is exactly the same, which renders the volatility indicators meaningless. Based on the correlation between each indicator and the security of the edge intelligent control platform, it can be seen that the selected indicators are all positive indicators, that is, when the security level of the edge intelligent control platform is high, their values all increase positively. Forward processing is then performed on them:
[0217]
[0218] Where, x j The original value, x′ ij The processed value, x max x min These are the maximum and minimum values in the indicator, respectively.
[0219] S4022: Analyze the variability and conflict of indicators. Calculate the standard deviation δ of each indicator and use correlation analysis to analyze the conflict between two indicators. The formula for quantifying conflict is:
[0220]
[0221] Among them, R j For conflict quantification, r ij is the correlation coefficient between evaluation indicators i and j; M is the total number of evaluation indicators, and i is the index of the evaluation indicator.
[0222] S4023: Calculate the objective weights of each indicator. Determine the information content C of each indicator. j And calculate the objective weight W of each indicator. cj The calculation formula is:
[0223] C j =R j ×δ j
[0224]
[0225] In the formula, δ j Let C be the standard deviation of the j-th indicator. j Let be the information content of the j-th indicator.
[0226] S403: Determine the combined weights of the indicators using the combined weighting method. The subjective weights W obtained from the fuzzy analytic hierarchy process are then combined using the combined weighting method. aj The objective weight W obtained by the CRITIC method cj Combining these methods to calculate the combined weights improves the reasonableness of the results. The combined weight w j The calculation formula is:
[0227]
[0228] In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
[0229] S404: The fused weights are applied to the nodes of the attack graph model, and the risk value of the node is calculated by combining the payoff function of the attack and defense strategy of each node with the probability of occurrence.
[0230] In step 5, based on the risk assessment elements of the edge intelligent control platform, the combined weighted indicators are used as nodes in a dynamic Bayesian network. Attack graph model. Figure 2 This is a dynamic Bayesian network structure. The directed connections between nodes in the model represent the transmission paths of risk between different components and security elements of the platform. The platform's operation is divided into several time slices to reflect how risk changes over time. In each time slice, the state of nodes and the relationships between nodes may change. For example, in one time slice, the platform may suffer an external attack, causing changes in the state of some nodes, and these changes may affect the risk status of other nodes in subsequent time slices.
[0231] S501: Calculate the conditional probability table: For each node, calculate the conditional probability under different combinations of parent node states based on the collected data. Let node X... i The state at time slice t is x i,t Its parent node set is Pa(X) i,t If X ), then the conditional probability P(X) i,t =x i,t Pa(X i,tThe probability of maintaining good or broken communication confidentiality can be estimated by analyzing the frequency of the corresponding conditions in statistical data. For example, for a node with "communication confidentiality", its parent node may include "access control security", etc. Calculate the probability that communication confidentiality is maintained or broken under different access control security states.
[0232] S502: Predicting Node Changes: Using the constructed dynamic Bayesian network and learned parameters, predict the state of nodes within future time slices. For node X in time slice t+1... i,t+1 Its predicted state probability distribution P(X) i,t+1 E 1:t (where E) 1:t The evidence (representing all observations from time slice 1 to time slice t) can be computed using inference algorithms for Bayesian networks (such as the forward-backward algorithm). For example, predicting the probability that an actuator node is attacked in the next time slice. For node i, calculate the probability P(Xi) that it is in a high-risk state H. i =HO), where O represents the observation data at the current moment.
[0233] S503: Calculate the dynamic change of risk value: Based on the predicted node status and the combined weighting results, calculate the dynamic change of risk value. Let node X after combined weighting... i,t The weight is w i,t The risk value corresponding to its state is r. i,t The risk value is calculated based on the previous return function and probability. Therefore, the platform risk value for time slice t is... (Where L is the total number of nodes). By comparing the risk values of different time slices, the dynamic trend of risk can be analyzed.
[0234] S504: Optimized Portfolio Weighting: The portfolio weighting is optimized based on the dynamic changes in risk values. If a certain indicator is found to play a crucial role in the risk change process, but its current weight does not accurately reflect its importance, its weight can be adjusted. The goal of optimization is to make the risk assessment results more accurately reflect the actual risk situation of the platform. The optimized weight w′ i,t The goal should be to ensure that the risk value calculated under the new weights better matches the actual risk trend, i.e., to minimize the risk assessment error. (where T is the total number of time slices) R represents the risk value for the actual observed time slice t. t (Platform risk value for time slice t).
[0235] Adjusted weight w′ i,t It can be calculated using the following formula:
[0236] w′ i,t =w i,t ×(1+k×P(Xi =H|O))
[0237] Where k is an adjustment coefficient, determined according to the actual situation; P(X i =H|O) represents the probability of being in a high-risk state H; w i,t After assigning weights to the combined node X i,t The weight.
[0238] S505: Update Risk Value Calculation: Recalculate the risk value of each node in the attack graph model using the adjusted weights. The risk value calculation combines the node's attack / defense strategy payoff function and the probability of occurrence, as shown in the following formula:
[0239]
[0240] Where R i Let p be the risk value of node i. ij Let f be the probability of node i occurring under the j-th attack defense strategy. ij Let be the profit function value of node i under the j-th attack defense strategy, and K be the total number of attack defense strategies.
[0241] In step 6, based on the attack graph model optimized by the dynamic Bayesian network and the node risk values, the risk value of the root node is solved according to the structure and node relationships of the attack graph. The risk level of the system, such as low risk, medium risk, or high risk, is determined by the proportion of the root node's risk value to the total risk value of the edge intelligent control platform. This provides security managers with intuitive risk assessment results, enabling them to formulate corresponding security strategies and resource optimization configuration schemes.
[0242] Example 3
[0243] Based on the same inventive concept, this invention also provides a risk assessment system for an edge intelligent control platform based on hybrid game theory, including:
[0244] The structural building module is used to construct a security risk hierarchy based on the information domain and physical domain of the edge intelligent control platform.
[0245] The risk value calculation module is used to describe potential attack paths in the edge intelligent control platform using an attack graph model, and to add a hybrid attack and defense game strategy to the nodes. It combines fuzzy hierarchical analysis and Critic combined weighting to determine the risk value of the nodes in the attack graph.
[0246] The risk assessment module is used to update the correlation of risk factors based on real-time monitoring data using a dynamic Bayesian network, optimize the risk value of nodes, calculate the risk value of the root node, and assess the risk of the intelligent control platform based on the optimized node and root node risk values.
[0247] Optionally, the structure building module is specifically used for:
[0248] The target layer is the edge intelligent control platform;
[0249] The information domain and physical domain of the edge intelligent control platform are used as primary indicators;
[0250] The attack methods and techniques in the information domain and physical domain are used as secondary indicators of the primary indicator;
[0251] The specific attack behaviors or conditions derived from the secondary indicators are the tertiary indicators of the secondary indicator layer.
[0252] Optionally, the risk value calculation module includes:
[0253] The abstract processing submodule is used to take the normal operation of the edge intelligent control platform as the root node, the attack points related to different attack stages or components as intermediate nodes, and the physical components or attack actions involved in specific attack events as leaf nodes.
[0254] The simulation submodule is used to introduce a hybrid attack and defense game strategy on the leaf nodes, intermediate nodes and root nodes to simulate the interactive decision-making process between the attacker and the defender, and to obtain the probability that the attacker will choose a certain attack behavior and the probability that the defender will take a certain defensive measure.
[0255] The risk calculation submodule is used to determine the weight of each defense method by using fuzzy hierarchical analysis and Critic combined weighting, and then determine the risk value of the leaf nodes and root nodes in the attack graph.
[0256] Optionally, the simulation submodule is specifically used for:
[0257] Calculate the defender's and attacker's profits based on different attack and defense profit functions;
[0258] Based on the defender's and attacker's payoffs, the attack-defense game problem is solved to obtain the optimal strategies for each of the attacker and defender.
[0259] A payoff matrix is formed based on the payoff functions of the optimal strategies adopted by the attacker and defender, respectively.
[0260] If the payoff matrix satisfies the judgment condition under the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action, then the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action are taken as the solution of the mixed strategy Nash equilibrium, thereby obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure.
[0261] Optionally, the risk calculation submodule includes:
[0262] The supervisory weight calculation unit is used to construct a judgment matrix based on expert judgment using fuzzy hierarchical analysis, quantify the relative importance of each evaluation factor using a comparative scale, and calculate the subjective weight of each level of indicator.
[0263] The objective weight calculation unit is used to calculate the objective weight of each indicator based on the variability and interrelationship of the indicators using the Critic weighting method.
[0264] A combined weighting unit is used to determine the weight of an indicator based on the subjective weight and the objective weight using a combined weighting method.
[0265] The calculation unit is used to apply the weights of the indicators to the nodes, and calculate the risk value of the nodes by combining the payoff function of each node's attack and defense strategy with the probability of occurrence.
[0266] Optionally, the supervisor weight calculation unit is specifically used for:
[0267] Based on the relationships between each level in the safety risk hierarchy, a fuzzy judgment matrix is established using the 0.1-0.9 nine-scale method;
[0268] When the elements in the fuzzy judgment matrix meet the set judgment conditions, the fuzzy judgment matrix is a fuzzy complementary matrix;
[0269] The fuzzy complementary matrix is subjected to a consistency check, converted into a fuzzy consistent matrix, and the weights of the fuzzy consistent matrix are calculated based on the weight value formula.
[0270] The subjective weight of an indicator is obtained by multiplying the weights of each level of indicator.
[0271] Optionally, the objective weight calculation unit is specifically used for:
[0272] Dimensionless processing is performed on indicators at all levels;
[0273] Calculate the standard deviation of each indicator and use correlation analysis to analyze the conflict between two indicators to obtain a quantitative index of conflict.
[0274] The objective weights of each indicator are calculated based on the standard deviation and the conflict quantification index.
[0275] Optionally, the weight of the indicator is calculated using the following formula:
[0276]
[0277] In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
[0278] Example 4
[0279] like Figure 5 As shown, the present invention also provides an electronic device, which may be a computer device, a microcontroller device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, processor, and transceiver component are connected via a bus; the memory can be used to store executable programs, and an exemplary executable program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be accessed and / or modified when instructions are executed.
[0280] The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, and it is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to realize the corresponding method flow or corresponding function, so as to realize the steps of the risk assessment method of the edge intelligent control platform based on hybrid game theory in the above embodiments.
[0281] Example 5
[0282] Based on the same inventive concept, this invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). This readable storage medium is a memory device within an electronic device used to store programs and data. It is understood that the storage medium here can include both built-in storage media within the electronic device and extended storage media supported by the electronic device. The storage medium provides storage space, which stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more executable programs (including program code). It should be noted that the storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. Loading and executing one or more instructions stored in the storage medium by the processor can implement the steps of the risk assessment method for the edge intelligent control platform based on hybrid game theory in the above embodiments.
[0283] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0284] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0285] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1The function specified in one or more boxes.
[0286] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0287] The above are merely embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of the claims of the present invention pending approval.
Claims
1. A risk assessment method for an edge intelligent control platform based on hybrid game theory, characterized in that, include: A security risk hierarchy is constructed based on the information domain and physical domain of the edge intelligent control platform; The attack graph model is used to describe potential attack paths in the edge intelligent control platform. A hybrid attack and defense game strategy is added to the nodes. The risk value of the nodes in the attack graph is determined by combining fuzzy hierarchical analysis and Critic combined weighting. Based on dynamic Bayesian networks, the correlation between risk factors is updated according to real-time monitoring data, the risk values of nodes are optimized, and the risk value of the root node is calculated. The risk of the intelligent control platform is then assessed based on the optimized node and root node risk values.
2. The method as described in claim 1, characterized in that, The security risk hierarchy structure built on the edge intelligent control platform's ground information domain and physical domain includes: The target layer is the edge intelligent control platform; The information domain and physical domain of the edge intelligent control platform are used as primary indicators; The attack methods and techniques in the information domain and physical domain are used as secondary indicators of the primary indicator; The specific attack behaviors or conditions derived from the secondary indicators are the tertiary indicators of the secondary indicator layer.
3. The method as described in claim 1, characterized in that, The method utilizes an attack graph model to describe potential attack paths in the edge intelligent control platform, incorporates a hybrid attack-defense game strategy into the nodes, and combines fuzzy hierarchical analysis and Critic weighting to determine the risk value of nodes in the attack graph, including: The normal operation of the edge intelligent control platform is taken as the root node, the attack points related to different attack stages or components are taken as intermediate nodes, and the physical components or attack actions involved in specific attack events are taken as leaf nodes. A hybrid attack-defense game strategy is introduced on the leaf nodes, intermediate nodes, and root nodes to simulate the interactive decision-making process between attackers and defenders, and to obtain the probability that the attacker will choose a certain attack behavior and the probability that the defender will take a certain defensive measure. The weights of each defense method are determined by using fuzzy hierarchical analysis and Critic combined weighting, thereby determining the risk values of leaf nodes and root nodes in the attack graph.
4. The method as described in claim 3, characterized in that, The introduction of a hybrid attack-defense game strategy at the leaf nodes, intermediate nodes, and root node simulates the interactive decision-making process between attackers and defenders, obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure, including: Calculate the defender's and attacker's profits based on different attack and defense profit functions; Based on the defender's and attacker's payoffs, the attack-defense game problem is solved to obtain the optimal strategies for each of the attacker and defender. A payoff matrix is formed based on the payoff functions of the optimal strategies adopted by the attacker and defender, respectively. If the payoff matrix satisfies the judgment condition under the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action, then the probability of the attacker choosing an attack behavior and the probability of the defender choosing an action are taken as the solution of the mixed strategy Nash equilibrium, thereby obtaining the probability of the attacker choosing a certain attack behavior and the probability of the defender taking a certain defensive measure.
5. The method as described in claim 3, characterized in that, The method employs a combination of fuzzy hierarchical analysis and Critic weighting to determine the weight of each defense method, thereby determining the risk values of leaf nodes and root nodes in the attack graph, including: The fuzzy hierarchical analysis method is used to construct a judgment matrix based on expert judgment, and the comparative scale is used to quantify the relative importance of each evaluation factor and calculate the subjective weight of each level of indicator. Using the Critic weighting method, the objective weights of each indicator are calculated based on the variability and interrelationships of the indicators. The weights of the indicators are determined by a combined weighting method based on the subjective weights and the objective weights. The weights of the indicators are applied to the nodes, and the risk value of each node is calculated by combining the payoff function of the attack and defense strategy for each node with the probability of occurrence.
6. The method as described in claim 5, characterized in that, The method employs fuzzy hierarchical analysis to construct a judgment matrix based on expert judgment, uses a comparison scale to quantify the relative importance of each evaluation factor, and calculates the subjective weights of each level of indicators, including: Based on the relationships between each level in the safety risk hierarchy, a fuzzy judgment matrix is established using the 0.1-0.9 nine-scale method; When the elements in the fuzzy judgment matrix meet the set judgment conditions, the fuzzy judgment matrix is a fuzzy complementary matrix; The fuzzy complementary matrix is subjected to a consistency check, converted into a fuzzy consistent matrix, and the weights of the fuzzy consistent matrix are calculated based on the weight value formula. The subjective weight of an indicator is obtained by multiplying the weights of each level of indicator.
7. The method as described in claim 5, characterized in that, The method of using Critic weights to calculate the objective weights of each indicator based on the variability and interrelationships of the indicators includes: Dimensionless processing is performed on indicators at all levels; Calculate the standard deviation of each indicator and use correlation analysis to analyze the conflict between two indicators to obtain a quantitative index of conflict. The objective weights of each indicator are calculated based on the standard deviation and the conflict quantification index.
8. The method as described in claim 6, characterized in that, The weights of the indicators are calculated using the following formula: In the formula, w j W represents the weight of the indicator. aj For subjective weighting, W cj Let i be the objective weight, i be the index variable of the summation symbol, and p be the number of subjective and objective weights obtained through fuzzy hierarchical analysis and the Critic method.
9. The method as described in claim 5, characterized in that, The method based on dynamic Bayesian networks, which updates the correlation between risk factors and optimizes the risk values of nodes according to real-time monitoring data, includes: For each node, calculate the conditional probability under different combinations of parent node states based on the collected data; Using the constructed dynamic Bayesian network and the learned parameters, the state of nodes within future time slices is predicted; Based on the predicted node status and combined with weighting, the dynamic changes in risk value are calculated. The portfolio weighting is optimized based on the dynamic changes in risk value; By using optimized combined weighting, the risk value of each node in the attack graph model is recalculated.
10. The method as described in claim 5, characterized in that, The calculation of the root node risk value, and the assessment of the risk of the intelligent control platform based on the optimized node and root node risk values, includes: The risk value of the root node is determined based on the structure and node relationships of the attack graph. The risk level of the system is determined by the proportion of the risk value of the root node to the total risk value of the edge intelligent control platform.
11. A risk assessment system for an edge intelligent control platform based on hybrid game theory, characterized in that, include: The structural building module is used to construct a security risk hierarchy based on the information domain and physical domain of the edge intelligent control platform. The risk value calculation module is used to describe potential attack paths in the edge intelligent control platform using an attack graph model, and to add a hybrid attack and defense game strategy to the nodes. It combines fuzzy hierarchical analysis and Critic combined weighting to determine the risk value of the nodes in the attack graph. The risk assessment module is used to update the correlation of risk factors based on real-time monitoring data using a dynamic Bayesian network, optimize the risk value of nodes, calculate the risk value of the root node, and assess the risk of the intelligent control platform based on the optimized node and root node risk values.
12. An electronic device, characterized in that, include: At least one processor and memory; The memory and processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the risk assessment method for the edge intelligent control platform based on hybrid game theory as described in any one of claims 1 to 10 is implemented.
13. A readable storage medium, characterized in that, It contains an execution program, which, when executed, implements the risk assessment method for an edge intelligent control platform based on hybrid game theory as described in any one of claims 1 to 10.