A game-theoretic defense method, system, device and medium in B5G networks

CN122579129APending Publication Date: 2026-08-14BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-25
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0003]然而,该网络架构面临严重的拒绝服务(DoS)攻击威胁,尤其是SYN泛洪攻击

Benefits of technology

本发明利用M/M/1/N排队模型精确量化攻击对时延和丢包率的影响,并以时延和丢包率效用函数作为防御决策的核心指标,能够有效保障低延迟、高可靠性业务的QoS需求,基于此,将攻防交互建模为完全信息静态博弈并求解纳什均衡,可主动预测攻击策略,实现动态、精准的防御决策,避免传统静态防御被高估的问题,并借助动态调整流表,将受攻击MEC的部分业务流量转移至云端服务器并分配额外计算资源,缓解了边缘节点资源有限的瓶颈,在降低防御成本的同时,有效恢复网络服务可用性,确保SYN洪泛攻击下合法业务请求的正常处理。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122579129A_ABST
    Figure CN122579129A_ABST
Patent Text Reader

Abstract

This invention discloses a game-theoretic defense method, system, device, and medium in B5G networks, relating to the field of network defense technology. The steps include: constructing an M / M / 1 / N queuing model; establishing a service utility function with latency and packet loss rate as core indicators; modeling the attack-defense interaction as a static game of complete information; obtaining the optimal defense strategy by solving for the Nash equilibrium; and finally, dynamically adjusting the flow table by the SDN controller to offload the service traffic of the attacked MEC to the cloud and allocate additional computing resources. This invention can proactively predict attack behavior, reduce defense costs while ensuring the QoS of low-latency services, and effectively restore network service availability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of deep learning security technology, and in particular to a game-theoretic defense method, system, device and medium in B5G networks. Background Technology

[0002] With the evolution of fifth-generation mobile communication systems (5G) to B5G and 6G networks, the number of Internet of Things (IoT) devices is growing explosively, creating an increasingly urgent demand for low-latency and high-reliability services. Cloud-edge-device distributed networks with software-defined networking (SDN) as the controller, by deploying mobile edge computing (MEC) at the network edge, can effectively reduce service response latency and have become a key technical architecture for B5G networks.

[0003] However, this network architecture faces a serious threat of denial-of-service (DoS) attacks, especially SYN flood attacks. Attackers use malicious viruses to capture a large number of IoT nodes and send massive amounts of SYN requests to the target MEC server without completing the three-way handshake. This exhausts the computing resources of the MEC server and the buffer resources of the switches, causing legitimate business requests to be severely blocked or dropped, rendering network services unavailable. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of the prior art by providing a game-theoretic defense method, system, device, and medium in B5G networks, thereby solving the problems in the prior art.

[0005] The present invention specifically provides the following technical solution: A game-theoretic defense method in B5G networks includes the following steps: Under the steady state of no network attack, the initial average queuing delay and packet loss rate are obtained based on the steady-state probability distribution of the M / M / 1 / N queuing model, and the defender utility function is generated under no attack. When an attack occurs, the amount of switch buffer space occupied by the attacker and the cloud computing resources requested by the defender are introduced into the M / M / 1 / N queuing model to obtain the effective buffer capacity and service rate. Based on the steady-state probability under the effective buffer capacity and service rate, the current transmission strength, packet loss rate and average queuing latency are obtained. Using the transmission strength, packet loss rate, and average queuing delay as core variables, the attacker utility function and the defender utility function during an attack are obtained; wherein, the attacker utility function is defined as the difference between the defender utility function without an attack, the defender utility function during an attack, and the attack cost, and the defender utility function is defined as the difference between the total utility of the business data packet and the cloud defense cost; Treating the interaction between attackers and defenders as a static game with complete information, we obtain equilibrium policy pairs containing the optimal attack and defense strategies by solving the Nash equilibrium. Based on the optimal defense strategy, the switch flow table is dynamically adjusted to transfer some of the business traffic of the attacked mobile edge computing server to the cloud server and allocate additional cloud computing resources.

[0006] Preferably, the generation of the defender utility function when there is no attack is specifically as follows: Using initial average queuing delay and packet loss rate as the core indicators, we define the delay utility function and packet loss rate utility function for a single data packet; By combining the aforementioned delay utility function and packet loss rate utility function with the average value of a single data packet and the service arrival rate, the defender utility function under no-attack conditions is obtained.

[0007] Preferably, the utility value is zero when the initial average queuing delay exceeds a preset delay threshold or the packet loss rate exceeds a preset packet loss rate threshold.

[0008] Preferably, when the cloud computing resources requested by the defender are introduced into the M / M / 1 / N queuing model, the introduced cloud computing resources are D times the cloud computing resources occupied by the defender's request.

[0009] Preferably, the defender utility function further includes the impact of the propagation delay between the cloud server and the mobile edge computing server on the total latency.

[0010] Preferred options also include: The attacker's total utility function is the sum of the attack utility across all mobile edge computing cells, and is constrained by the total attack resources. The total utility function of the defender is constructed using the Eisenberg-Gale model. Specifically, it is the sum of the logarithms of the defense utility on all mobile edge computing cells, weighted by their respective service arrival rates, and is constrained by the total defense resources.

[0011] Preferably, the process of obtaining the equilibrium strategy pair by solving for the Nash equilibrium, using backward induction, includes the following steps: Enumerate all possible discrete defense strategy combinations for the defender; For each combination of defense strategies, obtain the optimal combination of attack strategies that maximizes the attacker's utility; The defender selects the combination of defense strategies that maximizes its own utility from all possible combinations of defense strategies as the optimal defense strategy. The optimal defense strategy and the corresponding optimal attack strategy are output as a balanced strategy pair.

[0012] This invention provides a game-theoretic defense system in a B5G network, comprising: The no-attack module is used to obtain the initial average queuing delay and packet loss rate based on the steady-state probability distribution of the M / M / 1 / N queuing model under the steady-state condition of no network attack, and generate the defender utility function under the condition of no attack. The attack module is used to, when an attack occurs, introduce the amount of switch buffer occupied by the attacker's resources and the cloud computing resources requested by the defender into the M / M / 1 / N queuing model to obtain the effective buffer capacity and service rate, and obtain the current transmission strength, packet loss rate and average queuing latency based on the steady-state probability under the effective buffer capacity and service rate. The function construction module is used to obtain the attacker utility function and the defender utility function during an attack, using the transmission strength, packet loss rate and average queuing delay as core variables; wherein, the attacker utility function is defined as the difference between the defender utility function without an attack, the defender utility function during an attack and the attack cost, and the defender utility function is defined as the difference between the total utility of the business data packet and the cloud defense cost; The strategy acquisition module is used to treat the interaction between the attacker and the defender as a static game with complete information, and obtain the equilibrium strategy pair containing the optimal attack strategy and the optimal defense strategy by solving the Nash equilibrium. The adjustment module is used to dynamically adjust the switch flow table according to the optimal defense strategy, transfer some of the business traffic of the attacked mobile edge computing server to the cloud server, and allocate additional cloud computing resources.

[0013] The present invention provides a computer device, including a memory and a processor. The memory stores a program, and when the program is executed by the processor, the processor performs the steps of the game defense method in a B5G network described above.

[0014] The present invention provides a storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, implements the steps of the aforementioned game-theoretic defense method in a B5G network.

[0015] Compared with the prior art, the present invention has the following significant advantages: This invention utilizes the M / M / 1 / N queuing model to accurately quantify the impact of attacks on latency and packet loss rate, and uses the latency and packet loss rate utility function as the core indicator for defense decisions. This effectively guarantees the QoS requirements of low-latency, high-reliability services. Based on this, the attack-defense interaction is modeled as a static game of complete information and the Nash equilibrium is solved. This allows for proactive prediction of attack strategies, enabling dynamic and accurate defense decisions, avoiding the overestimation problem of traditional static defense. Furthermore, by dynamically adjusting flow tables, some service traffic from the attacked MEC is transferred to the cloud server and additional computing resources are allocated, alleviating the bottleneck of limited edge node resources. While reducing defense costs, this effectively restores network service availability and ensures the normal processing of legitimate service requests under SYN flood attacks. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of SYN flood attack and defense in a single MEC scenario according to the present invention; Figure 2 This is a graph showing the relationship between single data packet latency and packet loss rate utility function in this invention; Figure 3 This is a schematic diagram of the data packet flow queuing model provided by the present invention; Figure 4 This is a schematic diagram of the data packet flow queuing model in the attack and defense scenario provided by the present invention; Figure 5 This is a schematic diagram of a multi-MEC node attack and defense game scenario provided by the present invention; Figure 6 A flowchart of a game-theoretic defense method in a B5G network provided by the present invention. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0018] In view of the shortcomings of existing technical solutions, the technical problem to be solved by the present invention is explained as follows: (1) Establish an IoT service utility evaluation system for cloud-edge-device networks: Taking the core indicators of B5G MEC network—latency and packet loss rate—as the core, construct a utility function model for a single data packet and global services based on queuing theory, and quantify the impact of SYN flooding attacks on network QoS.

[0019] (2) Establish a game theory model to predict attack and defense dynamics: In view of the dynamic interaction of the strategies of the attacker and defender, game theory is used to model the strategy interaction and resource allocation between the attacker and the defender, predict attack strategies, and identify network vulnerabilities.

[0020] (3) Construct a defense framework dedicated to cloud-edge-device architecture: Combining SDN controller and cloud services, a dynamic defense strategy is proposed to offload services to cloud servers, and the EG model is used to solve the problem of fair allocation of defense resources in multi-MEC scenarios.

[0021] (4) Analyze the impact of the attacker’s prior knowledge on the attack and defense results: Study the difference in damage caused by SYN flooding attacks under two scenarios: whether the attacker has knowledge of MEC cell feature information or not, so as to provide a theoretical basis for the optimization of defense strategies.

[0022] like Figure 1 As shown, the B5G cloud-edge-device network is built on the 5G core (5GC) architecture defined by 3GPP. The MEC orchestrator (MEO) interacts with the 5GC's Network Open Function (NEF) as an Application Function (AF). The MEC host consists of the MEC platform (MEP), which provides computing and storage resources for MEC applications. The SDN controller decouples the network packet forwarding process (user plane) from the routing process (control plane) and controls the switches through the OpenFlow protocol. IoT terminals access the 5GC through the Radio Access Network (RAN), and data packets are distributed to the MEC server or cloud server via the switches.

[0023] SDN controller: Connects the control plane and user plane, managing switch flow tables via the OpenFlow protocol. Enables dynamic routing, traffic monitoring, and defense policy execution. The connection relationships and working principles of each component are as follows:

[0024] MEC servers connect IoT terminals and cloud servers via switches.

[0025] Under normal circumstances, IoT services are primarily processed by MEC servers to achieve low-latency service.

[0026] Attack occurred: The SDN controller diverted some business traffic to the cloud server and allocated additional computing resources to support the attacked MEC.

[0027] like Figure 6 As shown, this invention provides a game-theoretic defense method in a B5G network. Specifically, it includes the following steps:

[0028] Step 1: Under the steady state of no network attack, obtain the initial average queuing delay and packet loss rate based on the steady-state probability distribution of the M / M / 1 / N queuing model (the incoming flow process follows a Poisson distribution, the service time follows an exponential distribution, there is only one server, and the system capacity limit is N), and construct the defender utility function under no attack using the initial average queuing delay and packet loss rate.

[0029] This invention uses an M / M / 1 / N queuing model to describe the data packet flow between IoT terminals and switches, where: λ is the IoT service packet arrival rate (Poisson distribution), μ is the average service rate of the MEC server, and N is the switch buffer capacity.

[0030] (a) Single data packet utility function: With time delay t D and packet loss rate P L Define the latency utility function for a single data packet as the core metric. and packet loss rate utility function as follows: (1); (2); When the latency exceeds 100ms or the packet loss rate exceeds 5%, the utility approaches zero, which is consistent with the eMBB standard of B5G networks.

[0031] (b) Steady-state analysis without attack: Under steady-state conditions, what is the steady-state probability of i data packets in a switching system? satisfy: (3); in For transmission strength. Based on normalization conditions, initial probability... for:

[0032] (4); Probabilities of each state for: (5); Packet loss rate without attack (The probability of packet loss when the cache is full) is: (6); Average queue length for: (7); Average queuing and processing latency for: (8); Defender utility function when no attack for: (9); Where w is the average value of a single data packet.

[0033] Step 2: When an attack occurs, the amount of switch buffer space occupied by the attacker and the cloud computing resources requested by the defender are introduced into the M / M / 1 / N queuing model to obtain the effective buffer capacity and service rate. Based on the steady-state probability under the effective buffer capacity and service rate, the current transmission strength, packet loss rate and average queuing latency are obtained.

[0034] c) Queuing theory models in offensive and defensive scenarios: During a SYN flood attack, the attacker consumes resource A to occupy the switch's buffer, reducing the effective buffer capacity to N−A; the defender requests additional MEC computing power from the cloud service, multiplied by D. Transmission strength under attack and defense scenarios. for:

[0035] (10); Steady-state initial probability of the system in attack and defense scenarios Determined by the following normalization conditions (Formula 11a): (11a); Packet loss rate in attack and defense scenarios for: (12); in, The packet loss rate is given by an effective cache capacity of N−A.

[0036] Average queuing delay for: (13); in, This represents the average queue length in both offensive and defensive scenarios. This refers to the arrival rate of IoT service packages in offensive and defensive scenarios.

[0037] Step 3: Using transmission strength, packet loss rate, and average queuing delay under attack and defense scenarios as core variables, obtain the attacker's utility function and the defender's utility function during an attack; wherein, the attacker's utility function is defined as the difference between the defender's utility function without an attack, the defender's utility function during an attack, and the attack cost, and the defender's utility function is defined as the difference between the total utility of the business data packet and the cloud defense cost.

[0038] d) Offense and defense utility function: Defender utility function (In a single MEC scenario, including the impact of cloud propagation latency), the specific expression is: (15); Where C D Calculate resource costs for cloud service providers, t d This refers to the propagation latency between MEC and cloud services.

[0039] Attacker utility function The specific expression for (the difference in the defender's utility before and after the attack minus the cost of the attack) is: (16); in The cost for an attacker to establish each half-open connection. The effect of the defender when there is no attack.

[0040] Step 4: Treat the interaction between the attacker and the defender as a static game with complete information, and obtain the equilibrium policy pair containing the optimal attack strategy and the optimal defense strategy by solving the Nash equilibrium.

[0041] Game equilibrium solution: The attack-defense game is modeled as a static game with complete information, and the Nash equilibrium condition (attacker optimal) is as follows: (17); Nash equilibrium condition (defender optimal): (18); A backward induction method is used to solve the perfect Nash equilibrium of the subgame: the attacker predicts the defender's optimal strategy and then chooses the optimal attack strategy, after which the defender responds. Since the defender's computing power is a discrete set of strategies that are integer multiples of the MEC computing power, the equilibrium is solved by enumeration search.

[0042] Attack and defense game model in multi-MEC scenarios: Suppose there are n MEC cells, and the attacker assigns a vector as follows: The defender's resource vector is .

[0043] The attacker's total utility function is the sum of the utility functions of each MEC: (19); The defender uses the Eisenberg-Gale (EG) model for resource allocation, comprehensively considering marginal utility and fairness, with a total utility function. for: (twenty one); Balanced search algorithm: The multi-MEC attack and defense game uses backward induction to solve for the perfect Nash equilibrium of the subgames. The specific steps are as follows: ① Enumerate all possible discrete strategies D for the defender; ② Under each defense strategy, solve for the attacker's optimal attack strategy A*; ③ The defender chooses the strategy D* that maximizes its own utility; ④ Output the equilibrium strategy pair (A*, D*). The equilibrium solution algorithm for multi-MEC game scenarios is shown below.

[0044] Input: Attacker's total resources A, defender's total resources D, MEC average task traffic vector λ={ , , …, }, average service rate vector μ={ , , …, Attack cost CA, defense cost CD.

[0045] Output: Optimal attack strategy A*={ *, *,…, *}, Optimal defense strategy D*={ *, *, …, *}

[0046] 1. For D in all possible defense strategies do: 2. Under the defense strategy D, find the attacker's optimal attack strategy A* that maximizes UA(A, D).

[0047] 3.end.

[0048] 4.[UD(A*, D*), D*]=max(UA(A*, D)).

[0049] 5. Output the equalization strategy pair (A*, D*).

[0050] Step 5: The network controller dynamically adjusts the switch flow table according to the optimal defense strategy, transfers some of the service traffic of the attacked mobile edge computing server to the cloud server, and allocates additional computing resources to support the attacked mobile edge computing server.

[0051] Beneficial effects: (1) Improved defense effectiveness. By predicting attacker strategies using game theory models, proactive and dynamic DoS defense is achieved. Simulation results show that the error between the theoretical model and simulation results is less than 2% (see...). Figure 6 ).

[0052] (2) Reduce defense costs. When the defense resources reach 4 times the computing power of the MEC itself, the SYN flood attack can be completely blocked, and the defense cost is lower than the existing solution.

[0053] (3) Optimize the core indicator of latency. Accurately model system latency using queuing theory, which is particularly suitable for B5G low-latency service scenarios.

[0054] (4) Achieve fair and effective resource allocation. The Eisenberg-Gale model is adopted to achieve fair allocation of resources among MEC nodes under limited defense resources.

[0055] (5) Cross-plane collaborative deployment. Based on 5GC and SDN, unified deployment of policies in the control plane and user plane is achieved.

[0056] Based on the above method, this invention proposes a game-theoretic defense system in a B5G network, comprising: The attack-free module is used to obtain the initial average queuing latency and packet loss rate based on the M / M / 1 / N queuing model under a steady-state network without attacks, and to construct the defender utility function under attack-free conditions using the initial average queuing latency and packet loss rate. The attack module is used to construct a queuing model under attack and defense scenarios when an attack occurs, based on the amount of switch buffer space occupied by the attacker and the cloud computing resources requested by the defender, to determine the current transmission strength, packet loss rate, and average queuing latency. The function construction module is used to construct the attacker utility function and the defender utility function using the queuing indicators under attack and defense scenarios as core variables. The attacker... The utility function is defined as the difference between the defender's utility before and after the attack, minus the attack cost. The defender's utility function is defined as the difference between the total utility of the service data packet and the cloud defense cost. The strategy acquisition module is used to model the interaction between the attacker and the defender as a static game of complete information. By solving the Nash equilibrium, an equilibrium strategy pair containing the optimal attack strategy and the optimal defense strategy is obtained. The adjustment module is used to define how the network controller dynamically adjusts the switch flow table according to the optimal defense strategy, transferring part of the service traffic of the attacked mobile edge computing server to the cloud server, and allocating additional computing resources to support the attacked mobile edge computing server.

[0057] The present invention provides a computer device, including a memory and a processor. The memory stores a program, and when the program is executed by the processor, the processor performs the steps of the game defense method in a B5G network described above.

[0058] According to the disclosed embodiments, the computer device can communicate with one or more external devices (e.g., keyboard, pointing device, Bluetooth communication, etc.) or with any device that enables the computing device to communicate with one or more other computing devices (e.g., router, demodulator, etc.).

[0059] The present invention provides a storage medium on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the above-described game defense method in a B5G network.

[0060] According to the disclosed embodiments, the storage medium can be a non-volatile computer-readable storage medium, such as, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, the storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0061] The above description, in conjunction with specific preferred embodiments, provides a more detailed explanation of the present invention. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of the present invention, and all such deductions or substitutions should be considered to fall within the scope of protection of the present invention.

Claims

1. A game-theoretic defense method in a B5G network, characterized in that, Includes the following steps: Under the steady state of no network attack, the initial average queuing delay and packet loss rate are obtained based on the steady-state probability distribution of the M / M / 1 / N queuing model, and the defender utility function is generated under no attack. When an attack occurs, the amount of switch buffer space occupied by the attacker and the cloud computing resources requested by the defender are introduced into the M / M / 1 / N queuing model to obtain the effective buffer capacity and service rate. Based on the steady-state probability under the effective buffer capacity and service rate, the current transmission strength, packet loss rate and average queuing latency are obtained. Using the transmission strength, packet loss rate, and average queuing delay as core variables, the attacker utility function and the defender utility function during an attack are obtained; wherein, the attacker utility function is defined as the difference between the defender utility function without an attack, the defender utility function during an attack, and the attack cost, and the defender utility function is defined as the difference between the total utility of the business data packet and the cloud defense cost; Treating the interaction between attackers and defenders as a static game with complete information, we obtain equilibrium policy pairs containing the optimal attack and defense strategies by solving the Nash equilibrium. Based on the optimal defense strategy, the switch flow table is dynamically adjusted to transfer some of the business traffic of the attacked mobile edge computing server to the cloud server and allocate additional cloud computing resources.

2. The game-theoretic defense method in a B5G network as described in claim 1, characterized in that, The generation of the defender utility function under no-attack conditions is specifically as follows: Using initial average queuing delay and packet loss rate as the core indicators, we define the delay utility function and packet loss rate utility function for a single data packet; By combining the aforementioned delay utility function and packet loss rate utility function with the average value of a single data packet and the service arrival rate, the defender utility function under no-attack conditions is obtained.

3. The game-theoretic defense method in a B5G network as described in claim 2, characterized in that, The utility value is zero when the initial average queuing delay exceeds a preset delay threshold or the packet loss rate exceeds a preset packet loss rate threshold.

4. The game-theoretic defense method in a B5G network as described in claim 1, characterized in that, When the cloud computing resources requested by the defender are introduced into the M / M / 1 / N queuing model, the introduced cloud computing resources are D times the cloud computing resources occupied by the defender's request.

5. The game-theoretic defense method in a B5G network as described in claim 1, characterized in that, The defender utility function also includes the impact of propagation delay between the cloud server and the mobile edge computing server on the total latency.

6. The game-theoretic defense method in a B5G network as described in claim 1, characterized in that, Also includes: The attacker's total utility function is the sum of the attack utility across all mobile edge computing cells, and is constrained by the total attack resources. The total utility function of the defender is constructed using the Eisenberg-Gale model. Specifically, it is the sum of the logarithms of the defense utility on all mobile edge computing cells, weighted by their respective service arrival rates, and is constrained by the total defense resources.

7. The game-theoretic defense method in a B5G network as described in claim 1, characterized in that, The process of obtaining equilibrium strategy pairs by solving for Nash equilibrium, and solving using backward induction, includes the following steps: Enumerate all possible discrete defense strategy combinations for the defender; For each combination of defense strategies, obtain the optimal combination of attack strategies that maximizes the attacker's utility; The defender selects the combination of defense strategies that maximizes its own utility from all possible combinations of defense strategies as the optimal defense strategy. The optimal defense strategy and the corresponding optimal attack strategy are output as a balanced strategy pair.

8. A game-theoretic defense system in a B5G network, characterized in that, include: The no-attack module is used to obtain the initial average queuing delay and packet loss rate based on the steady-state probability distribution of the M / M / 1 / N queuing model under the steady-state condition of no network attack, and generate the defender utility function under the condition of no attack. The attack module is used to, when an attack occurs, introduce the amount of switch buffer occupied by the attacker's resources and the cloud computing resources requested by the defender into the M / M / 1 / N queuing model to obtain the effective buffer capacity and service rate, and obtain the current transmission strength, packet loss rate and average queuing latency based on the steady-state probability under the effective buffer capacity and service rate. The function construction module is used to obtain the attacker utility function and the defender utility function during an attack, using the transmission strength, packet loss rate and average queuing delay as core variables; wherein, the attacker utility function is defined as the difference between the defender utility function without an attack, the defender utility function during an attack and the attack cost, and the defender utility function is defined as the difference between the total utility of the business data packet and the cloud defense cost; The strategy acquisition module is used to treat the interaction between the attacker and the defender as a static game with complete information, and obtain the equilibrium strategy pair containing the optimal attack strategy and the optimal defense strategy by solving the Nash equilibrium. The adjustment module is used to dynamically adjust the switch flow table according to the optimal defense strategy, transfer some of the business traffic of the attacked mobile edge computing server to the cloud server, and allocate additional cloud computing resources.

9. A computer device, characterized in that, The device includes a memory and a processor, wherein the memory stores a program that, when executed by the processor, causes the processor to perform the steps of a game-theoretic defense method in a B5G network as described in any one of claims 1 to 7.

10. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the game-theoretic defense method in a B5G network according to any one of claims 1 to 7.