A simulation deduction and strategy evaluation platform for malicious group governance

CN122764643APending Publication Date: 2026-09-15ZHEJIANG YUEXIU UNIV OF FOREIGN LANGUAGES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610995002.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-06
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

当前针对恶意群体的治理工作多采用事后处置的被动模式,治理策略的有效性验证高度依赖真实场景落地试错,存在试错成本高、合规风险大、处置滞后性强的核心痛点;

Benefits of technology

[0014] 1. This invention enables pre-emptive simulation verification of malicious group governance strategies, fully recreating the real two-way attack and defense game process between malicious groups and the governance party. It effectively solves the problems of lagging strategy verification and insufficient practical adaptability in traditional governance models. It can complete the full-dimensional effectiveness verification and shortcoming optimization before the strategy is implemented, reducing the risk of implementation and trial and error costs of governance strategies. At the same time, it can accurately simulate the dynamic confrontation and avoidance behavior of malicious groups, effectively improving the resistance and robustness of governance strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764643A_ABST
    Figure CN122764643A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of natural language processing, and discloses a simulation deduction and strategy evaluation platform for malicious group governance, which comprises a malicious group attack and defense element ontology modeling and basic library construction module, a multi-agent confrontation scene customized deduction environment construction module, a round system bidirectional attack and defense confrontation dynamic simulation deduction execution module, an attack and defense confrontation strategy full-dimension quantitative evaluation and short-board diagnosis module, and a governance strategy iteration optimization and attack and defense capability closed-loop precipitation module; the application realizes preposition simulation verification of a malicious group governance strategy, completely restores a real bidirectional attack and defense game process of a malicious group and a governance party, effectively solves the problems of strategy verification lag and insufficient real combat adaptability in a traditional governance mode, can complete full-dimension effectiveness verification and short-board optimization before the strategy is landed, and reduces the landing risk and trial and error cost of the governance strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cyberspace security governance technology, and in particular to a simulation and strategy evaluation platform for the governance of malicious groups. Background Technology

[0002] With the rapid development and widespread adoption of cyberspace, various organized malicious groups have been carrying out acts such as malicious public opinion incitement, telecommunications fraud, and illegal coordinated attacks, which have posed a serious threat to the ecological order of cyberspace, public safety, and the legitimate rights and interests of citizens.

[0003] Malicious groups are increasingly exhibiting characteristics such as hierarchical organization, cross-domain collaboration, dynamic confrontation, and rapid iteration of techniques and tactics, posing significant challenges to traditional governance models. Current governance efforts against malicious groups largely adopt a reactive, post-incident approach. The effectiveness of governance strategies heavily relies on trial-and-error implementation in real-world scenarios, resulting in core pain points such as high trial-and-error costs, significant compliance risks, and significant delays in response.

[0004] Existing simulation and deduction technologies and platforms are mostly designed for risk prediction of single network attack behaviors and fixed scenarios. They lack the ability to standardize modeling of the entire chain and all elements for organized malicious groups. They cannot reproduce the dynamic two-way attack and defense game process between malicious groups and governance parties. At the same time, they lack a sound mechanism for comprehensive quantitative evaluation and closed-loop iteration of governance strategies. They cannot provide full-process and practical technical support for the governance of malicious groups and cannot meet the current development needs of refined, proactive, and long-term cyberspace governance. Summary of the Invention

[0005] The purpose of this invention is to provide a simulation and strategy evaluation platform for the governance of malicious groups, so as to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] A simulation and strategy evaluation platform for malicious group governance includes a malicious group attack and defense element ontology modeling and basic library construction module, a multi-agent adversarial scenario customized simulation environment construction module, a turn-based two-way attack and defense dynamic simulation execution module, an attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module, and a governance strategy iterative optimization and attack and defense capability closed-loop accumulation module. The output of the malicious group attack and defense element ontology modeling and basic library construction module is connected to the input of the multi-agent adversarial scenario customized simulation environment construction module; the output of the multi-agent adversarial scenario customized simulation environment construction module is connected to the input of the turn-based two-way attack and defense dynamic simulation execution module; the output of the turn-based two-way attack and defense dynamic simulation execution module is connected to the input of the attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module; the output of the attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module is connected to the input of the governance strategy iterative optimization and attack and defense capability closed-loop accumulation module; and the output of the governance strategy iterative optimization and attack and defense capability closed-loop accumulation module is connected to the input of the malicious group attack and defense element ontology modeling and basic library construction module.

[0008] As a further improvement to this technical solution: the malicious group attack and defense element ontology modeling and basic library construction module includes a multi-source data fusion and feature extraction device, an attack and defense element standardized classification and storage device, and an attack and defense element ontology modeling and association mapping device; the multi-source data fusion and feature extraction device accesses multi-source heterogeneous data, completes data standardization processing, and extracts core feature data of malicious groups and governance entities; the attack and defense element standardized classification and storage device completes the classification, storage, and attribute labeling of attacker elements, defender elements, and environmental elements; the attack and defense element ontology modeling and association mapping device uses the OWL ontology language to construct a unified ontology model of attack and defense elements, defines three core mapping units: entities, attributes, and relationships, and completes the standardized semantic unification and logical association of all attack and defense elements; the attack and defense element ontology modeling and association mapping device completes the standardized construction of the ontology model through a triplet structure, with the corresponding formula being: , For the ontology model of offensive and defensive elements; It is the set of entities in the ontology model, which includes three categories: attacker entities, defender entities, and environment entities. This is the set of attributes corresponding to an entity. The attribute set includes three categories: entity-specific attributes, dynamic attributes, and constraint attributes. It is a set of relationships between entities, which includes four types: hierarchical relationships, execution relationships, triggering relationships, and constraint relationships.

[0009] As a further improvement to this technical solution: the multi-agent adversarial scenario customized simulation environment construction module includes an adversarial scenario customized configuration device, a multi-agent subject modeling and behavior decision-making device, and a simulation environment initialization and baseline calibration device; the adversarial scenario customized configuration device completes the parameter configuration and boundary condition setting for typical adversarial scenarios; the multi-agent subject modeling and behavior decision-making device constructs three types of independent agents for the simulation environment, namely, malicious group agents, governance subject agents, and environmental control agents; the multi-agent subject modeling and behavior decision-making device constructs a hierarchical decision model for the malicious group agents, matches the organizational topology of the malicious group, sets independent behavior decision logic for core nodes, backbone nodes, and ordinary nodes, and completes behavior decision calculation based on deep reinforcement learning; the multi-agent subject modeling and behavior decision-making device sets a dual operating mode for the governance subject agents, completing the switching between automatic execution of preset strategies and real-time manual intervention; the multi-agent subject modeling and behavior decision-making device sets global state synchronization rules for the environmental control agents, completing unified state control throughout the simulation process; the corresponding formula for the behavior decision logic of the malicious group agents in the multi-agent subject modeling and behavior decision-making device is: , For intelligent agents in The action to be performed at any given moment; For intelligent agents in The global environment state acquired in real time; The action value function; These are the training parameters for deep reinforcement learning networks; To select actions that maximize the action value function; the simulation environment initialization and baseline calibration device completes the loading of all elements and initial state settings of the simulation environment, and completes the blank baseline simulation execution without governance strategy.

[0010] As a further improvement to this technical solution: the round-based bidirectional attack and defense dynamic simulation and deduction execution module includes a round-based deduction timing control device, a malicious attack action execution and state update device, a governance strategy response and handling action execution device, and a global environment state synchronization and deduction termination determination device; the round-based deduction timing control device sets a fixed step size for the round-based deduction timing, and executes a single round of deduction according to the fixed timing of malicious attack execution, governance response and handling, and global state update; the round-based deduction timing control device controls the timing synchronization of the entire deduction process, ensuring that the actions of the three types of intelligent agents are executed in a fixed order within a single round. Completed; the turn-based simulation timing control device completes the custom configuration of the simulation step size and completes the pause, resume, and reset operations of the simulation process; the malicious attack action execution and state update device completes the execution of the decision-making actions of the malicious group intelligent agent and synchronously updates the full state data of the malicious group; the governance strategy response and disposal action execution device completes the triggering of the monitoring rules of the governance subject intelligent agent and the execution of the corresponding disposal actions, and synchronously updates the full state data of the governance subject; the global environment state synchronization and simulation termination judgment device completes the synchronous update of the global environment state, executes the judgment of the simulation termination condition, and outputs the timing data of the entire simulation process.

[0011] As a further improvement to this technical solution: the comprehensive quantitative evaluation and weakness diagnosis module for offensive and defensive countermeasure strategies includes a standardized construction device for the evaluation index system, a quantitative evaluation and benchmark comparison device for strategy effectiveness, and a weakness diagnosis and sensitivity analysis device for strategy. The standardized construction device for the evaluation index system completes the construction of the governance strategy evaluation index system and the configuration of index weights. The quantitative evaluation and benchmark comparison device for strategy effectiveness completes the statistical analysis of the full set of data, completes the comparison analysis with blank baselines and existing governance baselines, and outputs the comprehensive evaluation results. The weakness diagnosis and sensitivity analysis device for strategy uses full-process time-series data to complete the full-link backtracking of the simulation process, locates the failure links and response weaknesses in the strategy execution process. The weakness diagnosis and sensitivity analysis device for strategy uses the single-variable control method to complete the sensitivity analysis of the core parameters of the strategy, quantitatively identifies the degree of impact of different parameter changes on the overall effect of the strategy, and outputs the priority ranking of parameter optimization. The weakness diagnosis and sensitivity analysis device for strategy identifies resource bottlenecks and compliance risk points in the strategy execution process.

[0012] As a further improvement to this technical solution: the governance strategy iteration optimization and attack-defense capability closed-loop accumulation module includes a governance strategy targeted optimization device, an attack-defense element library iteration update device, and a strategy closed-loop iteration and standardization output device; the governance strategy targeted optimization device completes the parameter adjustment and process optimization of the governance strategy and outputs the optimized governance strategy solution; the attack-defense element library iteration update device completes the input and update of newly added attack-defense elements during the simulation process and continuously improves the basic element library; the strategy closed-loop iteration and standardization output device completes a new round of simulation verification of the optimized strategy and outputs a standardized governance solution and supporting documents.

[0013] Compared with the prior art, the beneficial effects of the present invention are:

[0014] 1. This invention enables pre-emptive simulation verification of malicious group governance strategies, fully recreating the real two-way attack and defense game process between malicious groups and the governance party. It effectively solves the problems of lagging strategy verification and insufficient practical adaptability in traditional governance models. It can complete the full-dimensional effectiveness verification and shortcoming optimization before the strategy is implemented, reducing the risk of implementation and trial and error costs of governance strategies. At the same time, it can accurately simulate the dynamic confrontation and avoidance behavior of malicious groups, effectively improving the resistance and robustness of governance strategies.

[0015] 2. This invention constructs a closed-loop governance system covering the entire process from element modeling, environment setup, simulation execution, assessment and diagnosis to strategy optimization. It enables continuous iteration and standardized accumulation of governance capabilities, adapting to various malicious group governance scenarios such as regulatory enforcement, internet platform risk control, and public safety management. At the same time, it achieves standardized reuse of attack and defense elements through a unified ontology model, possessing strong scalability and adaptability. It can effectively promote the transformation and upgrading of malicious group governance models from passive post-event handling to proactive pre-event prevention and refined long-term governance.

[0016] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it according to the contents of the specification, the preferred embodiments of the present invention are described in detail below with reference to the accompanying drawings. Specific embodiments of the present invention are given in detail below with reference to the accompanying drawings. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0018] Figure 1 This is a schematic diagram of the methodological structure of a simulation and strategy evaluation platform for the governance of malicious groups. Detailed Implementation

[0019] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are for illustrative purposes only and are not intended to limit the scope of the invention. The invention is described more specifically in the following paragraphs by way of example with reference to the accompanying drawings. It should be noted that the drawings are in a very simplified form and use non-precise proportions, and are only used to facilitate and clarify the illustration of the embodiments of the present invention.

[0020] Please see Figure 1 In this embodiment of the invention, a simulation and strategy evaluation platform for malicious group governance includes a malicious group attack and defense element ontology modeling and basic library construction module, a multi-agent adversarial scenario customized simulation environment construction module, a turn-based two-way attack and defense dynamic simulation execution module, an attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module, and a governance strategy iterative optimization and attack and defense capability closed-loop accumulation module. The output of the malicious group attack and defense element ontology modeling and basic library construction module is connected to the input of the multi-agent adversarial scenario customized simulation environment construction module; the output of the multi-agent adversarial scenario customized simulation environment construction module is connected to the input of the turn-based two-way attack and defense dynamic simulation execution module; the output of the turn-based two-way attack and defense dynamic simulation execution module is connected to the input of the attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module; the output of the attack and defense strategy full-dimensional quantitative evaluation and weakness diagnosis module is connected to the input of the governance strategy iterative optimization and attack and defense capability closed-loop accumulation module; and the output of the governance strategy iterative optimization and attack and defense capability closed-loop accumulation module is connected to the input of the malicious group attack and defense element ontology modeling and basic library construction module.

[0021] Specifically, the standardized attack and defense element data output by the malicious group attack and defense element ontology modeling and basic library construction module is transmitted to the multi-agent adversarial scenario customized inference environment construction module as the basic data for setting up the inference environment; the initial inference environment data output by the multi-agent adversarial scenario customized inference environment construction module is transmitted to the turn-based bidirectional attack and defense adversarial dynamic simulation inference execution module as the basic environment for inference execution; the full-process inference time-series data output by the turn-based bidirectional attack and defense adversarial dynamic simulation inference execution module is transmitted to the attack and defense adversarial strategy full-dimensional quantitative evaluation and shortcoming diagnosis module as the basic data for strategy evaluation; the strategy evaluation and diagnosis result data output by the attack and defense adversarial strategy full-dimensional quantitative evaluation and shortcoming diagnosis module is transmitted to the governance strategy iteration optimization and attack and defense capability closed-loop accumulation module as the basic data for strategy optimization; the optimized strategy data and newly added attack and defense element data output by the governance strategy iteration optimization and attack and defense capability closed-loop accumulation module are returned to the malicious group attack and defense element ontology modeling and basic library construction module to complete the closed-loop iteration of the entire process.

[0022] The malicious group attack and defense element ontology modeling and basic library construction module includes a multi-source data fusion and feature extraction device, an attack and defense element standardized classification and storage device, and an attack and defense element ontology modeling and association mapping device. The multi-source data fusion and feature extraction device accesses multi-source heterogeneous data, completes data standardization processing, and extracts core feature data of malicious groups and governance entities. The attack and defense element standardized classification and storage device completes the classification, storage, and attribute labeling of attacker elements, defender elements, and environmental elements. The attack and defense element ontology modeling and association mapping device uses the OWL ontology language to construct a unified ontology model of attack and defense elements, defining three core mapping units: entities, attributes, and relationships, and completing the standardized semantic unification and logical association of all attack and defense elements. The attack and defense element ontology modeling and association mapping device completes the standardized construction of the ontology model through a triplet structure, with the corresponding formula as follows: , For the ontology model of offensive and defensive elements; It is the set of entities in the ontology model, which includes three categories: attacker entities, defender entities, and environment entities. This is the set of attributes corresponding to an entity. The attribute set includes three categories: entity-specific attributes, dynamic attributes, and constraint attributes. It is a set of relationships between entities, which includes four types: hierarchical relationships, execution relationships, triggering relationships, and constraint relationships.

[0023] Specifically, the multi-source data fusion and feature extraction device is used to access the multi-source heterogeneous data required by the platform, including law enforcement case data, platform black market attack and defense data, regulatory notification data, academic research results and other data from different sources and in different formats. The device completes the standardization processing of the accessed data, such as cleaning, deduplication and format unification. From the standardized data, it extracts the core feature data of malicious groups and governance entities, providing basic data support for subsequent element storage and ontology modeling.

[0024] The standardized classification and storage device for offensive and defensive elements is used to classify the extracted core feature data into three categories: attacker elements, defender elements, and environmental elements. The device completes the corresponding attribute labeling for each type of element, including the triggering conditions, execution rules, applicable boundaries, and other attribute information. The labeled element data is then classified and stored in the corresponding element library to form the platform's basic offensive and defensive element library.

[0025] The attack and defense element ontology modeling and association mapping device is used to construct the core attack and defense element ontology model of the platform. It uses the OWL ontology language to build the model, defining three core mapping units: entities, attributes, and relationships, achieving standardized semantic unification and logical association of all attack and defense elements. This device completes the standardized construction of the ontology model through a triple structure, with the corresponding formula being: Detailed annotation and explanation of the formula: This formula is the core construction formula for the attack and defense element ontology model. It is used to standardize and define the ontology structure of all attack and defense elements on the platform, ensuring that the attack and defense elements of the entire platform have unified semantic standards and logical relationships, and providing a unified basic data model for subsequent inference environment construction and simulation execution; in the formula, It serves as the ontological model of offensive and defensive elements, and is the standardized carrier of all offensive and defensive elements on the entire platform; It is the set of entities in the ontology model. The entity set includes three categories: attacker entities, defender entities, and environment entities, covering all participating subjects and environment carriers in the platform simulation process. This is the set of attributes corresponding to an entity. The attribute set includes three categories: entity inherent attributes, dynamic attributes, and constraint attributes, which fully define all the features and boundary conditions of each entity. It is a set of relationships between entities, which includes four types: hierarchical relationships, execution relationships, triggering relationships, and constraint relationships, and fully defines the logical associations and interaction rules between different entities.

[0026] The multi-agent adversarial scenario customized simulation environment construction module includes an adversarial scenario customized configuration device, a multi-agent agent modeling and behavior decision-making device, and a simulation environment initialization and baseline calibration device. The adversarial scenario customized configuration device completes the parameter configuration and boundary condition setting for typical adversarial scenarios. The multi-agent agent modeling and behavior decision-making device constructs three types of independent agents for the simulation environment: malicious group agents, governance agent agents, and environment control agents. For the malicious group agents, the multi-agent agent modeling and behavior decision-making device constructs a hierarchical decision model, matching the organizational topology of the malicious group, and setting independent behavior decision logic for core nodes, backbone nodes, and ordinary nodes, completing behavior decision calculation based on deep reinforcement learning. For the governance agent agents, the multi-agent agent modeling and behavior decision-making device sets up dual operating modes, completing the switching between automatic execution of preset strategies and real-time manual intervention. For the environment control agents, the multi-agent agent modeling and behavior decision-making device sets global state synchronization rules, completing unified state control throughout the simulation process. The corresponding formula for the behavior decision logic of the malicious group agents in the multi-agent agent modeling and behavior decision-making device is: , For intelligent agents in The action to be performed at any given moment; For intelligent agents in The global environment state acquired in real time; The action value function; These are the training parameters for deep reinforcement learning networks; To select actions that maximize the action value function; the simulation environment initialization and baseline calibration device completes the loading of all elements and initial state settings of the simulation environment, and completes the blank baseline simulation execution without governance strategy;

[0027] Specifically, the customized configuration device for adversarial scenarios is used to configure parameters and set boundary conditions for typical adversarial scenarios of the platform. Typical adversarial scenarios include the governance of the entire chain of telecommunications network fraud gangs, the governance of malicious public opinion groups inciting on social platforms, the governance of malicious actions by black and gray market accounts, and the governance of cross-border malicious group coordinated attacks. For the selected scenario, the device completes the parameter configuration of the initial size, organizational topology, initial resources, and malicious targets of the malicious group, completes the parameter configuration of the initial governance strategy, resource limit, response latency, and law enforcement linkage mechanism of the defender, and completes the setting of boundary conditions such as environmental constraints, evolution rules, and simulation termination conditions.

[0028] A multi-agent modeling and behavior decision-making device is used to construct three independent agents for the simulation environment: a malicious group agent, a governance agent, and an environmental control agent. The device constructs a hierarchical decision-making model for the malicious group agent, matching the group's organizational topology, and sets independent behavior decision-making logic for core nodes, backbone nodes, and ordinary nodes, completing behavior decision calculations based on deep reinforcement learning. The device sets up a dual-operation mode for the governance agent, switching between automatic execution of preset strategies and real-time manual intervention. The device sets global state synchronization rules for the environmental control agent, achieving unified state control throughout the simulation process. The corresponding formula for the behavior decision-making logic of the malicious group agent in this device is: Detailed annotation and explanation of the formula: This formula is the core formula for the behavioral decision-making of malicious swarm intelligence agents. It is used to simulate the dynamic behavioral decision-making logic of real malicious swarms during the simulation process, reproducing the real attack and defense game process between the malicious swarm and the governance party, and ensuring the fidelity of the simulation; in the formula, For intelligent agents in The actions chosen at any given moment correspond to the specific actions, such as malicious acts, confrontation and evasion actions, that the malicious group chooses to perform in the corresponding round. For intelligent agents in The global environment status is constantly acquired, and corresponding global information such as governance strategies, environmental changes, and their own status that the malicious group can obtain in the corresponding round is deduced. This is the action value function, used to evaluate the expected returns for different actions performed in a given state. To train the parameters of the deep reinforcement learning network, training was completed based on the behavioral data of real malicious groups, ensuring that the decision-making logic of the agent conforms to the behavioral patterns of real malicious groups; To select the action that maximizes the action value function, the corresponding behavioral logic of a malicious group in the decision-making process is to select the action with the highest expected benefit.

[0029] The simulation environment initialization and baseline calibration device is used to complete the full-element loading and initial state setting of the simulation environment. The loading content includes the attack and defense element ontology model constructed in claim 2, the scene parameters completed by the adversarial scenario customized configuration device, and the agent model completed by the multi-agent agent modeling and behavior decision-making device. The device completes the blank baseline simulation execution without governance strategy, obtains the natural evolution benchmark data of the malicious group under the state of no intervention, and provides a reference benchmark for subsequent strategy evaluation.

[0030] The round-based two-way attack and defense dynamic simulation and deduction execution module includes a round-based deduction timing control device, a malicious attack action execution and state update device, a governance strategy response and handling action execution device, and a global environment state synchronization and deduction termination determination device. The round-based deduction timing control device sets a fixed-step round-based deduction timing sequence, executing a single round of deduction according to a fixed sequence of malicious attack execution, governance response and handling, and global state update. The round-based deduction timing control device manages the timing synchronization of the entire deduction process, ensuring that the actions of the three types of intelligent agents are completed in a fixed order within a single round. During the round-based deduction... The sequence control device completes the custom configuration of the simulation step size and completes the pause, resume, and reset operations of the simulation process; the malicious attack action execution and state update device completes the execution of the decision-making actions of the malicious group intelligent agent and synchronously updates the full state data of the malicious group; the governance strategy response and disposal action execution device completes the triggering of the monitoring rules of the governance subject intelligent agent and the execution of the corresponding disposal actions, and synchronously updates the full state data of the governance subject; the global environment state synchronization and simulation termination judgment device completes the synchronous update of the global environment state, executes the judgment of the simulation termination condition, and outputs the time sequence data of the entire simulation process.

[0031] Specifically, the round-based simulation timing control device is used to set a fixed-step round-based simulation timing sequence, and execute a single round of simulation according to a fixed timing sequence of malicious attack execution, governance response handling, and global state update; the device controls the timing synchronization of the entire simulation process, ensuring that the actions of the three types of intelligent agents are completed in a fixed order within a single round, avoiding simulation result deviations caused by timing disorder; the device completes the custom configuration of the simulation step size to adapt to the simulation accuracy requirements of different scenarios, and also completes the pause, resume, and reset operations of the simulation process to adapt to the need for manual intervention during the simulation process;

[0032] The malicious attack action execution and status update device is used to execute the decision-making actions of the malicious group's intelligent agent. The execution content includes adjusting the malicious link, changing the evasion rhetoric, switching resources, organizing coordinated attacks, and adding new countermeasures. After the action is executed, the device synchronously updates the full status data of the malicious group, including status data such as member size, resource inventory, malicious gains, and risk exposure level.

[0033] The governance strategy response and action execution device is used to trigger the monitoring rules of the governance entity's intelligent agent. Based on the malicious behavior data of the current round, it triggers the corresponding governance strategy and executes the corresponding action. The execution content includes account banning, content blocking, fund freezing, source tracing and evidence collection, public opinion guidance, and law enforcement linkage. After the action is executed, the device synchronously updates the full status data of the governance entity, including resource consumption, handling coverage, response latency, and false positives.

[0034] The global environment status synchronization and simulation termination determination device is used to synchronize and update the global environment status based on the action execution results of both the attacker and defender. The updated content includes global status data such as the impact of malicious group actions, public opinion heat, platform ecosystem health, compliance indicators, and user experience impact. The device performs simulation termination condition determination, judging whether the current simulation status has reached the preset simulation termination condition. If the termination condition is reached, the simulation stops; otherwise, it proceeds to the next round of simulation. Throughout the entire simulation process, the device synchronously collects and outputs the time-series data of the entire simulation process, providing full data support for subsequent strategy evaluation.

[0035] The comprehensive quantitative assessment and vulnerability diagnosis module for offensive and defensive strategies includes a standardized construction device for the assessment indicator system, a quantitative assessment and benchmarking device for strategy effectiveness, and a vulnerability diagnosis and sensitivity analysis device. The standardized construction device for the assessment indicator system establishes the governance strategy assessment indicator system and configures the indicator weights. The quantitative assessment and benchmarking device performs statistical analysis of the entire dataset, compares it with blank baselines and existing governance baselines, and outputs a comprehensive assessment result. The vulnerability diagnosis and sensitivity analysis device performs a full-link backtracking of the simulation process based on full-process time-series data, locating failure points and response weaknesses in the strategy execution process. The device uses a single-variable control method to perform sensitivity analysis on the core parameters of the strategy, quantifying the impact of different parameter changes on the overall strategy effect and outputting a priority ranking of parameter optimization. Finally, the device identifies resource bottlenecks and compliance risks in the strategy execution process.

[0036] Specifically, the standardized construction device for the evaluation indicator system is used to build an evaluation indicator system for governance strategies. The constructed indicator system covers four core dimensions: governance effectiveness, resilience against adversarial forces, cost efficiency, compliance, and secondary impacts. The device completes the weight configuration of each indicator in the indicator system to adapt to the evaluation focus requirements of different scenarios.

[0037] The strategy effectiveness quantitative evaluation and benchmark comparison device is used to complete the statistical analysis of the full amount of time series data and calculate the corresponding values ​​of all indicators in the evaluation index system. The device completes the comparison analysis of the calculation results with the blank baseline and the existing governance baseline, clarifies the changes of the governance strategy to be evaluated relative to the benchmark, and outputs the comprehensive evaluation results of the strategy.

[0038] The strategy weakness diagnosis and sensitivity analysis device is used to perform full-link backtracking of the simulation process based on full-process time-series data, locating failure points and response weaknesses in the strategy execution process. This device performs sensitivity analysis on core strategy parameters using a single-variable control method. While keeping other parameters constant, it adjusts the values ​​of individual core parameters one by one, quantifying the impact of different parameter changes on the overall strategy effect and outputting a priority ranking of parameter optimization. The device also identifies resource bottlenecks and compliance risks in the strategy execution process, providing precise guidance for subsequent strategy optimization.

[0039] The governance strategy iteration optimization and attack / defense capability closed-loop accumulation module includes a governance strategy targeted optimization device, an attack / defense element library iteration update device, and a strategy closed-loop iteration and standardization output device. The governance strategy targeted optimization device completes the parameter adjustment and process optimization of the governance strategy and outputs the optimized governance strategy solution. The attack / defense element library iteration update device completes the input and update of new attack / defense elements during the simulation process and continuously improves the basic element library. The strategy closed-loop iteration and standardization output device completes a new round of simulation verification of the optimized strategy and outputs standardized governance solutions and supporting documents.

[0040] Specifically, the governance strategy targeted optimization device is used to adjust the parameters and optimize the process of the governance strategy based on the strategy evaluation results and the shortcoming diagnosis results output by claim 5. The adjustment content includes the disposal threshold, response process, resource allocation, linkage mechanism, etc., and outputs the optimized governance strategy solution.

[0041] The attack and defense element library iteration and update device is used to extract new attack and defense elements that appear during the simulation process, including new malicious tactics, countermeasures, verified effective governance strategies, emergency plans, etc., to complete the standardization processing and attribute labeling of new elements, to complete the entry and update of new elements into the library, to continuously improve the basic attack and defense element library of the platform, and to simultaneously send the updated element data back to the malicious group attack and defense element ontology modeling and basic library construction module in claim 1, to complete the closed-loop iteration of the platform;

[0042] The strategy closed-loop iteration and standardization output device is used to re-input the optimized governance strategy scheme into the multi-agent adversarial scenario customized inference environment construction module in claim 1 to complete a new round of inference verification of the optimized strategy; after completing multiple rounds of iterative verification, the device outputs a standardized governance scheme and supporting documents to complete the accumulation of platform governance capabilities.

[0043] The method of use and working principle of this invention are as follows:

[0044] Usage: First, the malicious group attack and defense element ontology modeling and basic library construction module completes the multi-source data access, feature extraction, element storage, and ontology model construction, completing the platform's basic data layer. Then, the multi-agent adversarial scenario customized simulation environment construction module completes the parameter configuration of the target governance scenario, multi-agent modeling, and simulation environment initialization, completing the simulation environment construction. Subsequently, the turn-based two-way attack and defense adversarial dynamic simulation execution module completes the full-process attack and defense adversarial simulation according to the preset time sequence, collecting and outputting the full-process simulation time sequence data. Then, the attack and defense adversarial strategy full-dimensional quantitative evaluation and shortcoming diagnosis module completes the comprehensive evaluation and shortcoming diagnosis of the governance strategy, outputting the evaluation results and optimization directions. Finally, the governance strategy iteration optimization and attack and defense capability closed-loop accumulation module completes the optimization and adjustment of the governance strategy, element library update, and standardized governance solution output, while the optimized data is sent back to the basic library construction module to complete the closed-loop iteration.

[0045] Working principle: First, a unified ontology model of attack and defense elements is constructed based on the OWL ontology language. The standardized semantics and logical association of all attack and defense elements are realized through the triple structure, providing high-fidelity basic data support for simulation and inference. Then, a hierarchical decision-making agent that fits the organizational structure of a real malicious group is constructed through multi-agent modeling technology. Based on deep reinforcement learning, the dynamic behavior decision of the malicious group is realized, restoring the two-way attack and defense game process in the real scenario. Subsequently, the orderly execution of attack and defense actions and the synchronous update of the global state are realized through a turn-based time sequence control mechanism, completing the dynamic simulation and inference of the whole process. Then, the quantitative evaluation and weakness location of the governance strategy are realized through full-link backtracking and sensitivity analysis. Finally, through the closed-loop data transmission link between modules, the iterative optimization of the governance strategy and the continuous update of the attack and defense element library are realized, forming a cyclical governance capability accumulation system.

[0046] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any way. Those skilled in the art can readily implement the present invention based on the description and drawings above. However, any modifications, alterations, and variations made by those skilled in the art without departing from the scope of the present invention using the disclosed technical content are equivalent embodiments of the present invention. Furthermore, any modifications, alterations, and variations made to the above embodiments based on the essential technology of the present invention are still within the protection scope of the present invention.

Claims

1. A simulation and strategy evaluation platform for the governance of malicious groups, characterized in that, The system includes modules for modeling and building a basic library of malicious group attack and defense elements, building a customized simulation environment for multi-agent adversarial scenarios, executing a round-based bidirectional attack and defense dynamic simulation, conducting a comprehensive quantitative evaluation and vulnerability diagnosis of attack and defense strategies, and iterative optimization and closed-loop accumulation of governance strategies and attack and defense capabilities. The output of the module for modeling and building a basic library of malicious group attack and defense elements is connected to the input of the module for building a customized simulation environment for multi-agent adversarial scenarios. The output of the module for building a customized simulation environment for multi-agent adversarial scenarios is connected to the input of the module for executing a comprehensive dynamic simulation of attack and defense strategies. The output of the module for executing a comprehensive dynamic simulation of attack and defense strategies is connected to the input of the module for conducting a comprehensive quantitative evaluation and vulnerability diagnosis of attack and defense strategies. The output of the module for conducting a comprehensive quantitative evaluation and vulnerability diagnosis of attack and defense strategies is connected to the input of the module for iterative optimization and closed-loop accumulation of governance strategies and attack and defense capabilities. The output of the module for iterative optimization and closed-loop accumulation of governance strategies and attack and defense capabilities is connected to the input of the module for modeling and building a basic library of malicious group attack and defense elements.

2. The simulation and strategy evaluation platform for malicious group governance according to claim 1, characterized in that, The malicious group attack and defense element ontology modeling and basic library construction module includes a multi-source data fusion and feature extraction device, an attack and defense element standardized classification and storage device, and an attack and defense element ontology modeling and association mapping device. The multi-source data fusion and feature extraction device accesses multi-source heterogeneous data, completes data standardization processing, and extracts core feature data of malicious groups and governance entities. The attack and defense element standardized classification and storage device completes the classification, storage, and attribute labeling of attacker elements, defender elements, and environmental elements. The attack and defense element ontology modeling and association mapping device uses the OWL ontology language to construct a unified ontology model of attack and defense elements, defining three core mapping units: entities, attributes, and relationships, and completing the standardized semantic unification and logical association of all attack and defense elements. The attack and defense element ontology modeling and association mapping device completes the standardized construction of the ontology model through a triplet structure, with the corresponding formula being: , For the ontology model of offensive and defensive elements; It is the set of entities in the ontology model, which includes three categories: attacker entities, defender entities, and environment entities. This is the set of attributes corresponding to an entity. The attribute set includes three categories: entity-specific attributes, dynamic attributes, and constraint attributes. It is a set of relationships between entities, which includes four types: hierarchical relationships, execution relationships, triggering relationships, and constraint relationships.

3. The simulation and strategy evaluation platform for malicious group governance according to claim 1, characterized in that, The multi-agent adversarial scenario customized inference environment construction module includes an adversarial scenario customized configuration device, a multi-agent agent modeling and behavior decision-making device, and an inference environment initialization and baseline calibration device. The adversarial scenario customized configuration device completes the parameter configuration and boundary condition setting for typical adversarial scenarios. The multi-agent agent modeling and behavior decision-making device constructs three types of independent agents for the inference environment: malicious group agents, governance agent agents, and environmental control agents. The multi-agent agent modeling and behavior decision-making device constructs a hierarchical decision model for the malicious group agents, matches the organizational topology of the malicious group, sets independent behavior decision logic for core nodes, backbone nodes, and ordinary nodes, and completes behavior decision calculation based on deep reinforcement learning. The multi-agent agent modeling and behavior decision-making device sets up a dual operating mode for the governance agent agents, completing the switching between automatic execution of preset strategies and real-time manual intervention. The multi-agent modeling and behavior decision-making device sets global state synchronization rules for environmental management agents, achieving unified state management throughout the entire simulation process; the corresponding formula for the behavior decision-making logic of malicious group agents in the multi-agent modeling and behavior decision-making device is: , For intelligent agents in The action to be performed at any given moment; For intelligent agents in The global environment state acquired in real time; The action value function; These are the training parameters for deep reinforcement learning networks; To select actions that maximize the action value function; the simulation environment initialization and baseline calibration device completes the loading of all elements and initial state settings of the simulation environment, and completes the blank baseline simulation execution without governance strategy.

4. The simulation and strategy evaluation platform for malicious group governance according to claim 3, characterized in that, The round-based bidirectional attack and defense dynamic simulation and deduction execution module includes a round-based deduction timing control device, a malicious attack action execution and state update device, a governance strategy response and handling action execution device, and a global environment state synchronization and deduction termination determination device. The round-based deduction timing control device sets a fixed-step round-based deduction timing sequence, executing a single round of deduction according to a fixed sequence of malicious attack execution, governance response and handling, and global state update. The round-based deduction timing control device manages the timing synchronization of the entire deduction process, ensuring that the actions of the three types of intelligent agents are completed in a fixed order within a single round. The timing control device completes the custom configuration of the simulation step size and performs pause, resume, and reset operations during the simulation process; the malicious attack action execution and state update device completes the execution of the decision-making actions of the malicious group's intelligent agents and synchronously updates the full state data of the malicious group; the governance strategy response and disposal action execution device completes the triggering of the monitoring rules of the governance subject's intelligent agents and the execution of corresponding disposal actions, and synchronously updates the full state data of the governance subject; the global environment state synchronization and simulation termination judgment device completes the synchronous update of the global environment state, executes the judgment of the simulation termination condition, and outputs the timing data of the entire simulation process.

5. The simulation and strategy evaluation platform for malicious group governance according to claim 1, characterized in that, The comprehensive quantitative evaluation and vulnerability diagnosis module for offensive and defensive strategies includes a standardized evaluation indicator system construction device, a strategy effectiveness quantitative evaluation and benchmark comparison device, and a strategy vulnerability diagnosis and sensitivity analysis device. The standardized evaluation indicator system construction device completes the construction of the governance strategy evaluation indicator system and the configuration of indicator weights. The strategy effectiveness quantitative evaluation and benchmark comparison device completes the statistical analysis of the full dataset, performs comparative analysis with blank baselines and existing governance baselines, and outputs comprehensive evaluation results. The strategy vulnerability diagnosis and sensitivity analysis device completes the full-link backtracking of the simulation process based on full-process time-series data, locating failure points and response vulnerabilities in the strategy execution process. The strategy vulnerability diagnosis and sensitivity analysis device completes the sensitivity analysis of the core strategy parameters using a single-variable control method, quantitatively identifying the impact of different parameter changes on the overall strategy effect, and outputting the priority ranking of parameter optimization. The strategy vulnerability diagnosis and sensitivity analysis device identifies resource bottlenecks and compliance risk points in the strategy execution process.

6. The simulation and strategy evaluation platform for malicious group governance according to claim 1, characterized in that, The governance strategy iteration optimization and attack / defense capability closed-loop accumulation module includes a governance strategy targeted optimization device, an attack / defense element library iteration update device, and a strategy closed-loop iteration and standardization output device. The governance strategy targeted optimization device completes the parameter adjustment and process optimization of the governance strategy and outputs the optimized governance strategy solution. The attack / defense element library iteration update device completes the input and update of newly added attack / defense elements during the simulation process and continuously improves the basic element library. The strategy closed-loop iteration and standardization output device completes a new round of simulation verification of the optimized strategy and outputs a standardized governance solution and supporting documents.