A network security risk dynamic evaluation and attack path prediction method
Patent Information
- Application Number
- CN202610915104.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-24
- Publication Date
- 2026-09-22
AI Technical Summary
[0002]随着工业互联网、云计算、物联网技术的普及,网络拓扑结构趋于动态化、复杂化,网络攻击呈现出多步骤、持续性、动态博弈的特征,传统网络安全风险评估与攻击路径预测技术存在显著的技术缺陷,无法适配复杂动态网络的安全防护需求,具体存在以下问题:
与现有技术相比,本发明的有益效果是:
Smart Images

Figure CN122802208A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security risk assessment and attack prediction, specifically a method for dynamic network security risk assessment and attack path prediction. Background Technology
[0002] With the popularization of industrial internet, cloud computing, and IoT technologies, network topologies are becoming more dynamic and complex. Network attacks are exhibiting characteristics of multi-step, persistent, and dynamic game-like behavior. Traditional network security risk assessment and attack path prediction technologies have significant technical shortcomings and cannot adapt to the security protection needs of complex and dynamic networks. Specifically, the following problems exist: Traditional risk assessments rely on fixed weights, which fail to adapt to the dynamic spatiotemporal characteristics of networks, leading to assessment distortion. Current network risk assessments often employ fixed entropy weighting and the Analytic Hierarchy Process (AHP) to assign weights to risk indicators, quantifying risk solely based on static vulnerabilities, ports, and access permissions. This neglects the spatiotemporal dynamics of network node traffic fluctuations, vulnerability exploit timeliness, and link communication status. The fixed weighting system cannot iteratively update with network operating conditions, resulting in risk assessment deviations exceeding 30% during peak traffic periods and vulnerability decay phases, exhibiting a serious assessment lag problem.
[0003] Existing attack path prediction models neglect the dynamic game relationship between attack and defense, resulting in simplistic and inaccurate path predictions. Traditional attack path prediction methods often rely on static Markov chains and Dijkstra's shortest path algorithm, generating fixed attack paths based solely on preset attack rules. They fail to consider the two-way game process of attacker strategy iteration and optimization, as well as defender dynamic protection adjustments. Furthermore, existing models do not correlate with real-time network risk states, cannot identify hidden, cross-node composite attack paths, and achieve less than 60% accuracy in attack path prediction for dynamic networks. They also cannot predict multi-stage, progressive attack behaviors.
[0004] Risk assessment and path prediction are disconnected and lack a closed-loop linkage mechanism. In existing technologies, risk assessment is an independent module, and the output static risk results cannot enable real-time attack path prediction. Furthermore, the feedback data from attack path traversal cannot optimize the risk assessment indicator system. The two core processes are disconnected in data and logically independent, failing to form a dynamic closed loop of "risk quantification - path prediction - risk iterative optimization." This significantly limits the real-time performance and accuracy of overall network security situation awareness.
[0005] In summary, existing technologies suffer from core problems such as static and fixed assessments, non-game-theoretic predictions, and lack of interconnected closed loops, making it difficult to meet the security risk management needs of today's dynamic and complex networks. There is an urgent need for a dynamic network security risk assessment and attack path prediction method. Summary of the Invention
[0006] The purpose of this invention is to provide a method for dynamic assessment of network security risks and prediction of attack paths, so as to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for dynamic assessment of network security risks and prediction of attack paths, comprising the following steps: Step S1: Network situation data collection and preprocessing: Collect five types of core situation data from each network node in real time, including vulnerability status, traffic data, port open status, permission configuration, and link communication latency. Perform data denoising and normalization processing to construct a dynamic network situation dataset. Step S2: By using the improved spatiotemporal iterative entropy weight risk dynamic quantification module, the risk index weights are iteratively updated in combination with the spatiotemporal dynamic characteristics of the network, and the real-time risk value and link risk coefficient of each network node are quantified. Step S3: Using the dynamic risk value and link risk coefficient output in step S2 as constraints, construct the attack and defense game payoff matrix through the multi-constraint attack and defense game evolution path prediction module, and iteratively evolve to generate the optimal attack path set. Step S4: Extract the attack frequency and node breach probability feedback data of the attack path in step S3, and iteratively optimize the risk indicator weight in step S2 to realize the closed-loop dynamic update of the improved spatiotemporal iterative entropy weight risk dynamic quantification module and the multi-constraint attack and defense game evolution path prediction module. Step S5: Output a dynamic risk assessment report and multi-level attack path prediction results to complete dynamic early warning of network security risks.
[0008] Preferably, the specific implementation steps of step S2 are as follows: Step S21: Construct a multi-dimensional risk assessment indicator system: Based on the core influencing factors of cybersecurity, a 5-dimensional risk assessment index system is established, including: vulnerability risk coefficient. Traffic anomaly Port exposure risk value Permission redundancy Vulnerability of link communication All indicators were preprocessed and normalized to [value missing]. interval; Step S22: Introduce spatiotemporal characteristic factors to improve the traditional entropy weight calculation formula. The traditional entropy weight method only calculates weights based on the dispersion of index data. This invention adds a time decay factor. Spatial correlation coefficient An improved formula for calculating information entropy is constructed: ;in For the first Improved information entropy for risk indicators; This is a time decay factor used to characterize the timeliness of metrics such as vulnerabilities and traffic. , The attenuation coefficient is... For the current moment, This refers to the time when the indicator data is updated; The spatial correlation coefficient is used to characterize the risk transmission characteristics of adjacent network nodes. Its value is determined by the frequency and correlation of inter-node link communication, and its range is [range missing]. ; For the first The first item under the indicator The percentage of indicators for each node, if ,but ; This represents the total number of network nodes. Step S23: Dynamically iteratively calculate the index weights: Based on the improved information entropy, the calculation of the first... Dynamic weight of the indicator The calculation formula is: The weight values iterate in real time with the spatiotemporal state of the network, which can accurately adapt to the dynamic changes of the network compared with traditional fixed weights. Step S24: Quantify the real-time risk value of the node: By combining dynamic weights and normalized index data, the real-time comprehensive risk value of each network node is calculated. : ;in For the first The node of the first Normalized index value, The interval is The higher the value, the higher the risk of the node.
[0009] Preferably, the spatial correlation coefficient in step S22 The specific calculation steps are as follows: Step 1: Calculate the normalization coefficient of node link communication frequency. : For any adjacent nodes , Effective communication frequency between two nodes within the sampling period of the statistical unit Combined with the highest link communication frequency in the entire network The basic coefficients of link communication association are obtained by normalization, and the calculation formula is as follows: ;in, The link communication status data collected in step S1 is obtained through real-time statistical analysis. This represents the maximum communication frequency across all links in the current network topology, used to eliminate the impact of differences in network size. The interval is The larger the value, the more frequent the communication and interaction between nodes, and the higher the probability of risk transmission. Step 2: Calculate the correlation degree of node risk transmission. ; The node comprehensive risk value is calculated in real time using an improved spatiotemporal iterative entropy weight risk dynamic quantification module. , Construct a formula for the risk coupling correlation between adjacent nodes to quantify the risk transmission ability of high-risk nodes to neighboring nodes: ,in, , Adjacent nodes , Real-time risk value; The interval is When the risk values of two nodes are closer, the degree of risk homogeneity is higher, the transmission link is more fragile, and the risk correlation is stronger. Step 3: Calculate the dynamic spatial correlation coefficient And interval constraints: By integrating link communication characteristics and risk transmission characteristics, weighted fusion of two-dimensional parameters is achieved. Simultaneously, a lower threshold is set to avoid algorithm failure caused by coefficients returning to zero when there is no communication link. The calculation formula is: ,in, To balance the impact of link communication frequency and risk correlation, a fixed value of 0.5 is used as the fusion weighting coefficient. The lower limit of the mandatory constraint coefficient is 0.2 to ensure that isolated nodes without communication interaction still possess basic spatial association attributes, avoiding the extreme value failure problem in the improved information entropy calculation. Stable landing interval; Step 4: Algorithm Iteration and Adaptation: Calculated dynamics Real-world input of the improved information entropy formula Complete the entropy value iterative calculation, and at the same time Risk coefficient of participation in subsequent links The generation of .
[0010] Preferably, the node comprehensive risk value in step 2 , The specific calculation steps are as follows: Step 2.1: Obtain node normalized risk indicator data: Based on the standardized dataset preprocessed in step S1, neighboring nodes are extracted respectively. , The corresponding 5-dimensional normalized risk index values; where nodes The set of indicators is ,node The set of indicators is All indicator values are normalized to interval, Representing the The node of the first Risk indicator values; Step 2.2: Calculate the improved spatiotemporal information entropy for each indicator: Substituting into the improved information entropy formula, and combining it with the real-time updated time decay factor... Spatial correlation coefficient The dynamic information entropy of the five risk indicators is generated one by one. : In the formula, The first in the entire network node system The first item under the indicator The percentage of indicators for each node, covering nodes , The indicator data ensures that the calculation of risk entropy value is based on the overall situation of the entire network, avoiding the one-sidedness of single-node calculation; It iterates and updates in real time with the spatiotemporal state of the network, providing a dynamic basis for subsequent weight calculation; Step 2.3: Solve for the dynamic index weights: Based on the improved information entropy obtained in step 2.2 Substitute the values into the dynamic weight calculation formula to solve for the real-time weights of the five risk indicators. : All indicator weights satisfy the normalization constraint. The weights are dynamically iterated based on network traffic, vulnerability expiration time, and link association status, which is different from traditional fixed weights. Step 2.4: Calculate the real-time risk value of each node using weighted summation. The method of linear weighting and fusion of index weights and normalized indexes is used to calculate the values of adjacent nodes. , The real-time comprehensive risk value is calculated using the following core formula: ; ;in For nodes The Normalized risk indicator value, For nodes The The normalized risk index value; the final calculated value. , The range of values is The larger the value, the higher the security risk of the corresponding node.
[0011] The dynamic obtained through the above steps , The formula for calculating the correlation between risk transmission can be applied in practice. Then, the spatial correlation coefficient is iteratively updated. This enables the internal parameters of the improved spatiotemporal iterative entropy weight risk dynamic quantification module to be self-iterated. At the same time, it provides core dynamic parameters for the attack and defense game payoff calculation and attack transfer probability calculation of the multi-constraint attack and defense game evolution path prediction module, ensuring the real-time performance and accuracy of the closed-loop linkage between the two modules. The interval is When the risk values of two nodes are closer, the degree of risk homogeneity is higher, the transmission link is more fragile, and the risk correlation is stronger.
[0012] Preferably, the specific implementation steps of step S3 are as follows: Step S31: Construct the offensive and defensive game subjects and strategy space: Define the two sides in the game as the attacker and the defender, and the attacker's strategy space is: The defensive strategy space is The node risk value output by the first module. The link risk coefficient serves as a core constraint on game payoffs. Step S32: Construct an improved attack-defense game payoff matrix: By combining dynamic risk parameters to construct a real-time game payoff matrix, the attacker's payoff function formula is as follows: The formula for the defensive side's payoff function is: The parameters are explained as follows: For the attacker's benefit, For the benefit of the defending side; The node risk-reward weight is fixed at 0.6; The defense cost coefficient is determined by the overhead of implementing the network defense strategy. The real-time protection strength of the defender is positively correlated with the node security configuration and the operating status of the protection equipment. Step S33, Game Evolution Iteration and Path Selection: Based on the evolutionary game replication dynamic equation, the stability probability of the strategies of both attackers and defenders is iteratively calculated, and the traditional Markov state transition probability formula is improved to construct a dynamic state transition probability: ,in For attacking from the node Transfer to node The probability of; For nodes and The link connectivity risk coefficient is calculated; based on the dynamic transition probability, all feasible attack paths are generated through traversal, and the optimal attack path set with the top-N probabilities is selected.
[0013] Preferably, the defense cost coefficient in step S32 The logic for obtaining it is as follows: Step S32.1: Construct a quantitative indicator system for defense strategy costs: Combined with the defensive strategy space Based on the real-time network situational data collected in step S1, three types of core defense overhead indicators are defined. All defense overhead indicators are normalized to... Range: Vulnerability remediation costs Based on the node vulnerability risk factor The overhead is determined by both the computational cost of vulnerability remediation and the cost of traffic interception. Higher vulnerability risk results in greater remediation costs. Based on node traffic anomaly The overhead of abnormal traffic scrubbing is determined by the computing power required; the more drastic the abnormal traffic fluctuations, the higher the interception and protection overhead. Access control overhead is also a factor. Due to node permission redundancy The cost of adjusting permissions is determined by the operational expenses; the more redundant the permissions, the higher the cost of managing and banning permissions. Step S32.2: Introduce risk weight constraints and construct the basic formula for defense cost: The real-time node risk value is output by the improved spatiotemporal iterative entropy weight risk dynamic quantification module. As an adaptive constraint, high-risk nodes correspond to higher priority in the execution of defense strategies and greater resource investment, resulting in a corresponding increase in defense costs. Therefore, the initial defense cost coefficient calculation formula is constructed as follows: ,in, This represents the unconstrained initial defense cost coefficient. This provides a real-time comprehensive risk value for the current protection node, enabling dynamic linking of risk status with defense costs. , , For the three types of normalized defense strategy cost indicators; Step S32.3, interval threshold constraint, yields the final defense cost coefficient. : To avoid the failure of the defense cost coefficient under extreme network conditions and to ensure the stable iteration of the attack-defense game model, the initial coefficients are adjusted. With upper and lower limit constraints applied, the final calculation formula is: In the formula, For interval constraint functions, force the... Value constraints The interval; when the node risk is extremely low and the network situation is stable, A value close to 0.1 indicates extremely low defense overhead; however, when nodes are at high risk or network anomalies are severe, A value close to 0.9 indicates that defense requires a large investment of resources and incurs extremely high costs. Step S32.4, Parameter linkage iterative adaptation: Dynamically calculated Real-time input of attack and defense benefit functions , Completing the payout calculation directly affects the probability of attack and defense strategy evolution and the probability of attack state transition. Ultimately, this affects the attack path prediction results; simultaneously, the back-feedback data from the path prediction optimizes the node risk value. Iterative updates are possible. The value is selected to achieve deep linkage between the defense cost coefficient and the closed-loop iteration of the two modules, ensuring that the entire game model fits the real-time dynamic state of the network.
[0014] Preferably, in step S33, the node and Link connectivity risk coefficient The specific calculation logic is as follows: First, extract the vulnerability features of basic link communication: through the link communication frequency normalization coefficient. This characterizes the communication activity level of the link. Higher communication frequency indicates more favorable conditions for attackers to move laterally, but also a higher vulnerability in the link's foundation. Basic dimensional features; Second, a node risk coupling correction term is introduced: the node risk transmission correlation degree is calculated in real time by calling the improved spatiotemporal iterative entropy weight risk dynamic quantification module. As a link risk coupling correction item; if the risk values of two adjacent nodes are highly similar, it means that the vulnerability types and security status of the two nodes are similar. After an attacker breaks through a single node, it is very easy to adapt to the environment of the adjacent node. The link risk transmission is significantly improved, and dynamic correction of the inherent vulnerability of the link is achieved. Third, introduce the spatiotemporal decay constraint factor: obtain the time decay factor in step S2. This is used to characterize the time-dependent decay characteristics of network link risks. Network link vulnerabilities and communication vulnerabilities iterate and update over time; older risks decrease over time, while new real-time anomaly risks increase. Achieve dynamic time-dimensional calibration of link risks; Fourth, construct a formula for calculating the link connectivity risk coefficient: This formula integrates link communication characteristics, node risk coupling characteristics, and time-sensitivity characteristics, while also matching the spatial correlation logic described earlier, to construct a dynamic formula for the link connectivity risk coefficient. By merging square roots to balance the fluctuations of two variables, the extreme values of a single parameter can be avoided to prevent the link risk assessment from being distorted. Fifth, interval steady-state constraints and parameter linkage: To ensure the iterative stability of the attack transfer probability model, interval constraints are applied to the calculation results, and the final effective link risk coefficient is: ,Will Constraints The interval is used to prevent the occurrence of zero values in silent or disconnected links, which could lead to path prediction failure; the solution is dynamically obtained. Real-world attack state transition probability formula This directly constrains the attack path generation results; simultaneously, the path traversal feedback data from the multi-constraint attack-defense game evolution path prediction module will perform reverse optimization. , and And then iteratively update This enables the link risk coefficient to dynamically evolve with the overall network attack and defense situation.
[0015] Preferably, the specific implementation steps of step S4 are as follows: Step S41: Statistically analyze the attack traversal characteristics of all nodes on the network: Based on the set of all optimal attack paths generated iteratively by the multi-constraint attack-defense game evolution path prediction module, all predicted paths are traversed one by one, and two core dynamic feature parameters are statistically analyzed: node attack traversal frequency and node breakthrough probability. Specifically: Define nodes attack traversal frequency Within the unit update cycle, nodes The total number of times a node appears in all optimal attack paths is used to characterize how frequently a node is targeted by attackers. Define nodes probability of breach The probability of attack transfer based on the in-degree of a node is accumulated, and the calculation formula is as follows: ,in, For nodes The set of all adjacent nodes; Adjacent nodes To the node The dynamic attack transfer probability, as stated in the preceding text Calculated; The range of values is The larger the value, the higher the probability that the node can be breached under the current offensive and defensive situation; Step S42: Construct the node dynamic risk feedback coefficient: By combining attack traversal frequency and breakthrough probability with the average attack characteristics across the entire network, a normalized risk feedback coefficient is constructed. This is used to quantify the degree of correction that the current offensive and defensive situation makes to the original risk assessment results of the node. The calculation formula is as follows: ,in, This is the average attack traversal frequency of all nodes across the entire network, used to eliminate statistical bias caused by differences in the number of network nodes; For nodes The risk feedback correction coefficient, with a value range of [value range missing]. ;like This indicates that the actual attack and defense risk of the node is higher than the currently assessed risk, and the risk weight and temporal decay intensity need to be positively amplified; if This indicates that the actual risk of the node is overestimated, and the corresponding risk parameters need to be weakened. Step S43, reverse correction of time decay factor : The time decay factor is the core time-series parameter for spatiotemporal dynamic assessment in the improved spatiotemporal iterative entropy weight risk dynamic quantification module. The original basic calculation formula is: This step introduces a risk feedback coefficient to achieve adaptive correction and constructs the time decay factor after iteration: ,in, This is the corrected real-time time decay factor; the correction coefficient of 0.2 represents a small iteration step size to avoid excessively large single feedback corrections that could cause algorithm oscillations; when high-risk nodes... hour, Increase, delay the decay of risk over time, and retain the long-term risk characteristics of high-risk nodes; when low-risk nodes hour, This reduces and accelerates the decay of obsolescence risk characteristics, enabling precise calibration of time-series risks; the corrected... Directly substituting into the improved spatiotemporal iterative entropy weight risk dynamic quantification module improves information entropy. Participate in the next round of iteration calculation; Step S44: Iterate backwards to correct the risk indicator weights. : Combining the node risk feedback coefficient with the risk contribution of each indicator, the dynamic weight of the improved spatiotemporal iterative entropy weight risk dynamic quantification module is adjusted. To perform adaptive fine-tuning, construct an iterative weight correction formula: ,in, For the revised first Weighting of each risk indicator; The average risk feedback coefficient of all nodes in the network represents the overall risk correction trend of the entire network. To adjust the sensitivity of the indicators, a value of 0.15 is set for highly dynamic risk indicators such as vulnerabilities and traffic, and a value of 0.08 is set for less dynamic indicators such as ports and permissions, thus differentiating and adapting to the risk update characteristics of different indicators. To ensure the weight normalization constraint, the corrected weights are standardized: In the formula, The final updated indicator weights satisfy the following conditions: ; Step S45, Iterative Update: The corrected time decay factor with normalized index weights Substitute back to the improved spatiotemporal iterative entropy weight risk dynamic quantification module and re-iterate the real-time risk value of the node. Spatial correlation coefficient Link connectivity risk coefficient The updated parameters are then input into the multi-constraint attack-defense game evolution path prediction module to update the attack-defense game payoffs, attack transition probabilities, and attack path prediction results. Compared with the prior art, the beneficial effects of the present invention are: The improved spatiotemporal iterative entropy weight risk dynamic quantification module of this invention improves the entropy weight algorithm by introducing spatiotemporal feature factors, overcomes the defects of the traditional fixed risk assessment weight, accurately adapts to the dynamic spatiotemporal change characteristics of network nodes and links, reduces the network risk assessment deviation rate, and significantly improves the accuracy of dynamic network risk quantification.
[0016] The multi-constraint attack-defense game evolution path prediction module of this invention is based on an improved path prediction model of attack-defense game evolution. It combines real-time dynamic risk constraints to realize bidirectional game path evolution, which solves the problems of path fixation and lack of game characteristics in traditional models. The accuracy of attack path prediction is improved, and it can effectively identify multi-stage composite attack paths.
[0017] The improved spatiotemporal iterative entropy weight risk dynamic quantification module and the multi-constraint attack and defense game evolution path prediction module form a closed-loop linkage mechanism. Risk assessment provides real-time constraints for path prediction, and path prediction optimizes the risk assessment system in reverse. This completely solves the problem of the two links being separated and lacking dynamic iteration in the existing technology, and realizes real-time and accurate perception of network security situation. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the overall structure of the present invention; Figure 2 This is a schematic diagram of the workflow of the improved spatiotemporal iterative entropy weight risk dynamic quantification module of the present invention; Figure 3 This is a schematic diagram of the workflow of the multi-constraint attack and defense game evolution path prediction module of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Please see Figure 1-3This invention provides a technical solution: a method for dynamic assessment of network security risks and prediction of attack paths, comprising the following steps: Step S1: Network Situation Data Acquisition and Preprocessing: Real-time acquisition of five core situation data types from each network node: vulnerability status, traffic data, port open status, permission configuration, and link communication latency. Data denoising and normalization are then performed to construct a dynamic network situation dataset. Specific implementation steps are as follows: Step S11: Real-time acquisition of multi-dimensional and accurate situational data: Using all network nodes and adjacent communication links across the entire network as the data collection targets, a fixed sampling period of 10 seconds is set (consistent with subsequent dynamic iteration periods). Five types of core raw situational data are collected simultaneously, and each of the five types of data corresponds one-to-one with the 5-dimensional risk assessment indicators of the improved spatiotemporal iterative entropy weight risk dynamic quantification module of this invention, ensuring accurate matching between data and algorithm parameters. 1) Node vulnerability status data: Collect raw data on node vulnerability level, number of vulnerabilities, and vulnerability exploitability to generate a normalized vulnerability risk coefficient. ; 2) Node traffic data: Collect raw data on node inbound / outbound traffic rates, traffic fluctuation amplitude, and the proportion of abnormal data packets to generate normalized traffic anomaly index. ; 3) Node port status data: Collect raw data on the number of open ports on nodes, the proportion of high-risk ports, and the frequency of port access, to generate normalized port exposure risk values. ; 4) Node permission configuration data: Collect raw data on node account permission levels, number of redundant permissions, and unauthorized access records to generate normalized permission redundancy. ; 5) Link communication latency data: Collect link communication latency, packet loss rate, and effective communication frequency between adjacent nodes. Raw data, used to generate normalized link communication vulnerability. , and is also a spatial correlation coefficient Required link communication frequency normalization coefficient Provide the original data source.
[0021] Step S12: Raw data denoising and cleaning process: To address the issues of missing data, abnormal pulses, and redundant interference in network situational awareness data, targeted cleaning is conducted to ensure data validity. 1) Missing value handling: For a small number of missing data in a single period, the average of adjacent sampling periods is used to fill the missing data; for failed data with missing data in multiple consecutive periods, the corresponding node / link samples are marked and removed to avoid null values interfering with subsequent information entropy calculations. 2) Outlier handling: Based on The criteria exclude non-steady-state pulse anomaly data such as sudden changes in traffic and sudden increases in latency, as this type of data is invalid data generated by instantaneous jitter of equipment and cannot truly reflect the steady-state risk situation of the network. 3) Redundant data removal: Remove duplicate data from the same port and link, retain only the unique and valid time series data, and reduce the computational overhead of the algorithm.
[0022] Step 3: Standardize and normalize indicators All risk indicators in this invention are positive risk indicators (the larger the value, the higher the corresponding security risk). To unify the units of measurement and adapt to subsequent improvements in information entropy, node risk values, spatial correlation coefficients, and other full-process algorithm calculations, a Min-Max positive normalization formula is used to uniformly map all indicator data to... The standard interval is defined by the following formula: ,in: For the normalized first The node of the first Risk indicator values; For the first The node The original data collected for each indicator; For all nodes in the entire network The maximum value of the original data for each indicator; For all nodes in the entire network The minimum value of the original data for each indicator; after normalization, all indicators are fully adapted to subsequent... Information entropy calculation Weight iteration, Algorithm requirements for solving node risk values.
[0023] Step 14: Construction of Dynamic Network Situation Dataset: Using timestamps as indexes, the system associates the topological relationships and link adjacency relationships of all nodes in the network, integrating all normalized data. , , , , Indicator data, link communication frequency Communication latency data is used to construct a dynamic time-series correlated situational dataset. This dataset is updated in real-time, iterating and refreshing synchronously every 10 seconds, and can serve as the time decay factor for an improved spatiotemporal iterative entropy weight risk dynamic quantification module. Spatial correlation coefficient Dynamic iteration, and the attack-defense game payoff and link risk coefficient of the multi-constraint attack-defense game evolution path prediction module. The calculation and reverse feedback correction provide a full and standardized real-time data source, ensuring that the data foundation for the closed-loop iteration of the two innovative modules is accurate, unified, and synchronized in time. Step S2: Using the improved spatiotemporal iterative entropy weight risk dynamic quantification module, the risk indicator weights are iteratively updated based on the network's spatiotemporal dynamic characteristics to quantify the real-time risk value and link risk coefficient of each network node; the specific implementation steps are as follows: Step S21: Construct a multi-dimensional risk assessment indicator system: Based on the core influencing factors of cybersecurity, a 5-dimensional risk assessment index system is established, including: vulnerability risk coefficient. Traffic anomaly Port exposure risk value Permission redundancy Vulnerability of link communication All indicators were preprocessed and normalized to [value missing]. interval; Step S22: Introduce spatiotemporal characteristic factors to improve the traditional entropy weight calculation formula. The traditional entropy weight method only calculates weights based on the dispersion of index data. This invention adds a time decay factor. Spatial correlation coefficient An improved formula for calculating information entropy is constructed: ;in For the first Improved information entropy for risk indicators; This is a time decay factor used to characterize the timeliness of metrics such as vulnerabilities and traffic. , The attenuation coefficient is... For the current moment, This refers to the time when the indicator data is updated; The spatial correlation coefficient is used to characterize the risk transmission characteristics of adjacent network nodes. Its value is determined by the frequency and correlation of inter-node link communication, and its range is [range missing]. ; For the first The first item under the indicator The percentage of indicators for each node, if ,but ; The total number of network nodes; where the spatial correlation coefficient is... The specific calculation steps are as follows: Step 1: Calculate the normalization coefficient of node link communication frequency. : For any adjacent nodes , Effective communication frequency between two nodes within the sampling period of the statistical unit Combined with the highest link communication frequency in the entire network The basic coefficients of link communication association are obtained by normalization, and the calculation formula is as follows: ;in, The link communication status data collected in step S1 is obtained through real-time statistical analysis. This represents the maximum communication frequency across all links in the current network topology, used to eliminate the impact of differences in network size. The interval is The larger the value, the more frequent the communication and interaction between nodes, and the higher the probability of risk transmission. Step 2: Calculate the correlation degree of node risk transmission. ; The node comprehensive risk value is calculated in real time using an improved spatiotemporal iterative entropy weight risk dynamic quantification module. , Construct a formula for the risk coupling correlation between adjacent nodes to quantify the risk transmission ability of high-risk nodes to neighboring nodes: ,in, , Adjacent nodes , Real-time risk value; The interval is When the risk values of two nodes are closer, the degree of risk homogeneity is higher, the transmission link is more fragile, and the risk correlation is stronger; the overall risk value of a node , The specific calculation steps are as follows: Step 2.1: Obtain node normalized risk indicator data: Based on the standardized dataset preprocessed in step S1, neighboring nodes are extracted respectively. , The corresponding 5-dimensional normalized risk index values; where nodes The set of indicators is ,node The set of indicators is All indicator values are normalized to interval, Representing the The node of the first Risk indicator values; Step 2.2: Calculate the improved spatiotemporal information entropy for each indicator: Substituting into the improved information entropy formula, and combining it with the real-time updated time decay factor... Spatial correlation coefficient The dynamic information entropy of the five risk indicators is generated one by one. : In the formula, The first in the entire network node system The first item under the indicator The percentage of indicators for each node, covering nodes , The indicator data ensures that the calculation of risk entropy value is based on the overall situation of the entire network, avoiding the one-sidedness of single-node calculation; It iterates and updates in real time with the spatiotemporal state of the network, providing a dynamic basis for subsequent weight calculation; Step 2.3: Solve for the dynamic index weights: Based on the improved information entropy obtained in step 2.2 Substitute the values into the dynamic weight calculation formula to solve for the real-time weights of the five risk indicators. : All indicator weights satisfy the normalization constraint. The weights are dynamically iterated based on network traffic, vulnerability expiration time, and link association status, which is different from traditional fixed weights. Step 2.4: Calculate the real-time risk value of each node using weighted summation. The method of linear weighting and fusion of index weights and normalized indexes is used to calculate the values of adjacent nodes. , The real-time comprehensive risk value is calculated using the following core formula: ; ;in For nodes The Normalized risk indicator value, For nodes The The normalized risk index value; the final calculated value. , The range of values is The larger the value, the higher the security risk of the corresponding node.
[0024] The dynamic obtained through the above steps , The formula for calculating the correlation between risk transmission can be applied in practice. Then, the spatial correlation coefficient is iteratively updated. This enables the internal parameters of the improved spatiotemporal iterative entropy weight risk dynamic quantification module to be self-iterated. At the same time, it provides core dynamic parameters for the attack and defense game payoff calculation and attack transfer probability calculation of the multi-constraint attack and defense game evolution path prediction module, ensuring the real-time performance and accuracy of the closed-loop linkage between the two modules. The interval is When the risk values of two nodes are closer, the degree of risk homogeneity is higher, the transmission link is more fragile, and the risk correlation is stronger. Step 3: Calculate the dynamic spatial correlation coefficient And interval constraints: By integrating link communication characteristics and risk transmission characteristics, weighted fusion of two-dimensional parameters is achieved. Simultaneously, a lower threshold is set to avoid algorithm failure caused by coefficients returning to zero when there is no communication link. The calculation formula is: ,in, To balance the impact of link communication frequency and risk correlation, a fixed value of 0.5 is used as the fusion weighting coefficient. The lower limit of the mandatory constraint coefficient is 0.2 to ensure that isolated nodes without communication interaction still possess basic spatial association attributes, avoiding the extreme value failure problem in the improved information entropy calculation. Stable landing interval; Step 4: Algorithm Iteration and Adaptation: Calculated dynamics Real-world input of the improved information entropy formula Complete the entropy value iterative calculation, and at the same time Risk coefficient of participation in subsequent links The generation Step S23: Dynamically iteratively calculate the index weights: Based on the improved information entropy, the calculation of the first... Dynamic weight of the indicator The calculation formula is: The weight values iterate in real time with the spatiotemporal state of the network, which can accurately adapt to the dynamic changes of the network compared with traditional fixed weights. Step S24: Quantify the real-time risk value of the node: By combining dynamic weights and normalized index data, the real-time comprehensive risk value of each network node is calculated. : ;in For the first The node of the first Normalized index value, The interval is The higher the value, the higher the risk of the node.
[0025] Step S3: Using the dynamic risk value and link risk coefficient output in Step S2 as constraints, construct the attack-defense game payoff matrix through the multi-constraint attack-defense game evolution path prediction module, and iteratively evolve to generate the optimal attack path set; the specific implementation steps of Step S3 are as follows: Step S31: Construct the offensive and defensive game subjects and strategy space: Define the two sides in the game as the attacker and the defender, and the attacker's strategy space is: The defensive strategy space is The node risk value output by the first module. The link risk coefficient serves as a core constraint on game payoffs. Step S32: Construct an improved attack-defense game payoff matrix: By combining dynamic risk parameters to construct a real-time game payoff matrix, the attacker's payoff function formula is as follows: The formula for the defensive side's payoff function is: The parameters are explained as follows: For the attacker's benefit, For the benefit of the defending side; The node risk-reward weight is fixed at 0.6; The defense cost coefficient is determined by the overhead of implementing the network defense strategy. The real-time protection strength of the defender is positively correlated with the node security configuration and the operational status of the protection equipment; the defense cost coefficient The logic for obtaining it is as follows: Step S32.1: Construct a quantitative indicator system for defense strategy costs: Combined with the defensive strategy space Based on the real-time network situational data collected in step S1, three types of core defense overhead indicators are defined. All defense overhead indicators are normalized to... Range: Vulnerability remediation costs Based on the node vulnerability risk factor The overhead is determined by both the computational cost of vulnerability remediation and the cost of traffic interception. Higher vulnerability risk results in greater remediation costs. Based on node traffic anomaly The overhead of abnormal traffic scrubbing is determined by the computing power required; the more drastic the abnormal traffic fluctuations, the higher the interception and protection overhead. Access control overhead is also a factor. Due to node permission redundancy The cost of adjusting permissions is determined by the operational expenses; the more redundant the permissions, the higher the cost of managing and banning permissions. Step S32.2: Introduce risk weight constraints and construct the basic formula for defense cost: The real-time node risk value is output by the improved spatiotemporal iterative entropy weight risk dynamic quantification module. As an adaptive constraint, high-risk nodes correspond to higher priority in the execution of defense strategies and greater resource investment, resulting in a corresponding increase in defense costs. Therefore, the initial defense cost coefficient calculation formula is constructed as follows: ,in, This represents the unconstrained initial defense cost coefficient. This provides a real-time comprehensive risk value for the current protection node, enabling dynamic linking of risk status with defense costs. , , For the three types of normalized defense strategy cost indicators; Step S32.3, interval threshold constraint, yields the final defense cost coefficient. : To avoid the failure of the defense cost coefficient under extreme network conditions and to ensure the stable iteration of the attack-defense game model, the initial coefficients are adjusted. With upper and lower limit constraints applied, the final calculation formula is: In the formula, For interval constraint functions, force the... Value constraints The interval; when the node risk is extremely low and the network situation is stable, A value close to 0.1 indicates extremely low defense overhead; however, when nodes are at high risk or network anomalies are severe, A value close to 0.9 indicates that defense requires a large investment of resources and incurs extremely high costs. Step S32.4, Parameter linkage iterative adaptation: Dynamically calculated Real-time input of attack and defense benefit functions , Completing the payout calculation directly affects the probability of attack and defense strategy evolution and the probability of attack state transition. Ultimately, this affects the attack path prediction results; simultaneously, the back-feedback data from the path prediction optimizes the node risk value. Iterative updates are possible. The value is selected to achieve deep linkage between the defense cost coefficient and the closed-loop iteration of the two modules, ensuring that the entire game model fits the real-time dynamic state of the network.
[0026] Step S33, Game Evolution Iteration and Path Selection: Based on the evolutionary game replication dynamic equation, the stability probability of the strategies of both attackers and defenders is iteratively calculated, and the traditional Markov state transition probability formula is improved to construct a dynamic state transition probability: ,in For attacking from the node Transfer to node The probability of; For nodes and The link connectivity risk coefficient; based on the dynamic transition probability, all feasible attack paths are generated through traversal, and the optimal attack path set with the top-N probabilities is selected; in step S33, the nodes and Link connectivity risk coefficient The specific calculation logic is as follows: First, extract the vulnerability features of basic link communication: through the link communication frequency normalization coefficient. This characterizes the communication activity level of the link. Higher communication frequency indicates more favorable conditions for attackers to move laterally, but also a higher vulnerability in the link's foundation. Basic dimensional features; Second, a node risk coupling correction term is introduced: the node risk transmission correlation degree is calculated in real time by calling the improved spatiotemporal iterative entropy weight risk dynamic quantification module. As a link risk coupling correction item; if the risk values of two adjacent nodes are highly similar, it means that the vulnerability types and security status of the two nodes are similar. After an attacker breaks through a single node, it is very easy to adapt to the environment of the adjacent node. The link risk transmission is significantly improved, and dynamic correction of the inherent vulnerability of the link is achieved. Third, introduce the spatiotemporal decay constraint factor: obtain the time decay factor in step S2. This is used to characterize the time-dependent decay characteristics of network link risks. Network link vulnerabilities and communication vulnerabilities iterate and update over time; older risks decrease over time, while new real-time anomaly risks increase. Achieve dynamic time-dimensional calibration of link risks; Fourth, construct a formula for calculating the link connectivity risk coefficient: This formula integrates link communication characteristics, node risk coupling characteristics, and time-sensitivity characteristics, while also matching the spatial correlation logic described earlier, to construct a dynamic formula for the link connectivity risk coefficient. By merging square roots to balance the fluctuations of two variables, the extreme values of a single parameter can be avoided to prevent the link risk assessment from being distorted. Fifth, interval steady-state constraints and parameter linkage: To ensure the iterative stability of the attack transfer probability model, interval constraints are applied to the calculation results, and the final effective link risk coefficient is: ,Will Constraints The interval is used to prevent the occurrence of zero values in silent or disconnected links, which could lead to path prediction failure; the solution is dynamically obtained. Real-world attack state transition probability formula This directly constrains the attack path generation results; simultaneously, the path traversal feedback data from the multi-constraint attack-defense game evolution path prediction module will perform reverse optimization. , and And then iteratively update This enables the link risk coefficient to evolve dynamically with the overall network attack and defense situation; Step S4: Extract the attack frequency and node breach probability feedback data of the attack path in Step S3, and iteratively optimize the risk indicator weights in Step S2 to realize the closed-loop dynamic update of the improved spatiotemporal iterative entropy weight risk dynamic quantification module and the multi-constraint attack and defense game evolution path prediction module. The specific implementation steps are as follows: Step S41: Statistically analyze the attack traversal characteristics of all nodes on the network: Based on the set of all optimal attack paths generated iteratively by the multi-constraint attack-defense game evolution path prediction module, all predicted paths are traversed one by one, and two core dynamic feature parameters are statistically analyzed: node attack traversal frequency and node breakthrough probability. Specifically: Define nodes attack traversal frequency Within the unit update cycle, nodes The total number of times a node appears in all optimal attack paths is used to characterize how frequently a node is targeted by attackers. Define nodes probability of breach The probability of attack transfer based on the in-degree of a node is accumulated, and the calculation formula is as follows: ,in, For nodes The set of all adjacent nodes; Adjacent nodes To the node The dynamic attack transfer probability, as stated in the preceding text Calculated; The range of values is The larger the value, the higher the probability that the node can be breached under the current offensive and defensive situation; Step S42: Construct the node dynamic risk feedback coefficient: By combining attack traversal frequency and breakthrough probability with the average attack characteristics across the entire network, a normalized risk feedback coefficient is constructed. This is used to quantify the degree of correction that the current offensive and defensive situation makes to the original risk assessment results of the node. The calculation formula is as follows: ,in, This is the average attack traversal frequency of all nodes across the entire network, used to eliminate statistical bias caused by differences in the number of network nodes; For nodes The risk feedback correction coefficient, with a value range of [value range missing]. ;like This indicates that the actual attack and defense risk of the node is higher than the currently assessed risk, and the risk weight and temporal decay intensity need to be positively amplified; if This indicates that the actual risk of the node is overestimated, and the corresponding risk parameters need to be weakened. Step S43, reverse correction of time decay factor : The time decay factor is the core time-series parameter for spatiotemporal dynamic assessment in the improved spatiotemporal iterative entropy weight risk dynamic quantification module. The original basic calculation formula is: This step introduces a risk feedback coefficient to achieve adaptive correction and constructs the time decay factor after iteration: ,in, This is the corrected real-time time decay factor; the correction coefficient of 0.2 represents a small iteration step size to avoid excessively large single feedback corrections that could cause algorithm oscillations; when high-risk nodes... hour, Increase, delay the decay of risk over time, and retain the long-term risk characteristics of high-risk nodes; when low-risk nodes hour, This reduces and accelerates the decay of obsolescence risk characteristics, enabling precise calibration of time-series risks; the corrected... Directly substituting into the improved spatiotemporal iterative entropy weight risk dynamic quantification module improves information entropy. Participate in the next round of iteration calculation; Step S44: Iterate backwards to correct the risk indicator weights. : Combining the node risk feedback coefficient with the risk contribution of each indicator, the dynamic weight of the improved spatiotemporal iterative entropy weight risk dynamic quantification module is adjusted. To perform adaptive fine-tuning, construct an iterative weight correction formula: ,in, For the revised first Weighting of each risk indicator; The average risk feedback coefficient of all nodes in the network represents the overall risk correction trend of the entire network. To adjust the sensitivity of the indicators, a value of 0.15 is set for highly dynamic risk indicators such as vulnerabilities and traffic, and a value of 0.08 is set for less dynamic indicators such as ports and permissions, thus differentiating and adapting to the risk update characteristics of different indicators. To ensure the weight normalization constraint, the corrected weights are standardized: In the formula, The final updated indicator weights satisfy the following conditions: ; Step S45, Iterative Update: The corrected time decay factor with normalized index weights Substitute back to the improved spatiotemporal iterative entropy weight risk dynamic quantification module and re-iterate the real-time risk value of the node. Spatial correlation coefficient Link connectivity risk coefficient The updated parameters are then input into the multi-constraint attack-defense game evolution path prediction module to update the attack-defense game payoffs, attack transfer probabilities, and attack path prediction results.
[0027] Step S4: Extract the attack frequency and node breach probability feedback data of the attack path in step S3, and iteratively optimize the risk indicator weight in step S2 to realize the closed-loop dynamic update of the improved spatiotemporal iterative entropy weight risk dynamic quantification module and the multi-constraint attack and defense game evolution path prediction module. Step S5: Output a dynamic risk assessment report and multi-level attack path prediction results to complete dynamic early warning of network security risks. The specific implementation steps are as follows: Step S51: Summarize the latest iterative dynamic parameter dataset from the entire network: The core dynamic parameters, updated throughout the entire S1-S4 process, serve as the foundational data source for early warning and reporting outputs. All parameters are real-time valid values after a 10-second cycle of iteration, specifically including: corrected and normalized risk indicator weights. Optimized time decay factor Real-time comprehensive risk value of all nodes across the network Risk coefficient of connectivity between adjacent nodes Node breach probability Inter-node attack transfer probability The optimal attack path set and the traversal frequency of each path are determined. All parameters are interconnected and matched to ensure that the output results closely reflect the current real-time attack and defense situation.
[0028] Step S52, Quantitative Classification of Network Node and Link Risk Levels: Based on core risk parameters By using a range of values and combining the dynamic risk quantification standard of this invention, a three-level risk classification and assessment is conducted on all network nodes and communication links to achieve precise risk positioning. 1) Node risk classification: based on the real-time risk value of the node. Division, This is a high-risk node with an extremely high risk of being penetrated and compromised. This node is classified as medium-risk and poses a potential attack risk. It is a low-risk node, and the network security situation is stable.
[0029] 2) Link risk classification: based on link connectivity risk coefficient Division, This is a high-risk penetration link, which is easily exploited by attackers to achieve lateral movement; This is a medium-risk link, posing a certain risk of infiltration. It is a low-risk and stable link with extremely low attack and defense risks.
[0030] Step S53: Prioritizing and filtering multi-level attack paths: For all optimal attack paths generated by S3 iteration, a comprehensive risk probability formula for a single attack path is constructed to quantify the overall attack severity of the path and achieve multi-level ranking and filtering of paths. The comprehensive breakthrough probability of a single attack path is defined. : In the formula, The dynamic attack transfer probability of each adjacent node in the path is determined by the payoff of the attack-defense game. , Link risk coefficient Calculated together; The value range is [0,1]. The larger the value, the higher the feasibility of the attack path being used by the attacker and the greater the harm.
[0031] in accordance with Attack paths are divided into three levels: high-risk attack paths ( ), medium-risk attack paths ( Low-risk attack paths The final output is a set of Top-N high-risk priority attack paths, highlighting the composite attack paths that involve multi-node collaboration and cross-link progression.
[0032] Step S54, Differentiated Dynamic Security Warning Triggered: Based on the classification results of nodes, links, and attack paths, a dynamic early warning mechanism of the corresponding level is matched to achieve precise classification-based early warning: 1) High-risk level: For high-risk nodes, high-risk links, and high-risk attack paths, trigger a level 1 emergency alert and push priority protection strategies such as vulnerability patching, traffic blocking, and permission banning in real time; 2) Medium-risk level: For medium-risk nodes, medium-risk links, and medium-risk attack paths, a level 2 routine warning is triggered, prompting operations and maintenance personnel to regularly check for security risks and optimize protection strategies; 3) Low-risk level: No early warning is pushed for low-risk nodes and links, and continuous and normalized situation monitoring is carried out.
[0033] Step S55: Generate a standardized dynamic risk assessment report: By integrating end-to-end iterative data, risk classification results, multi-level attack paths, early warning information, and protection recommendations, a time-series dynamic risk assessment report is generated. The core content of the report includes: a ranking of risky nodes across the entire network, a list of high-risk links, details of multi-level attack paths, node breach probability distribution, risk iteration and optimization records, and targeted security protection strategy recommendations. The report updates in real-time with a 10-second iteration cycle, fully recording the dynamic evolution of the network attack and defense situation.
[0034] Step S56, Continuous closed-loop monitoring iteration: After completing this round of early warning and report output, the system automatically enters the next 10-second data collection and algorithm iteration cycle, continuously updating risk parameters and prediction results based on the latest network situation, realizing all-weather, dynamic, and closed-loop assessment, prediction, and early warning of network security risks, and solving the shortcomings of traditional static early warnings that are lagging and have low accuracy.
[0035] This invention discloses a method for dynamic assessment of network security risks and prediction of attack paths, belonging to the field of network security technology. Addressing the technical problems of fixed weights in existing network risk assessments, lack of attack-defense game theory in attack path prediction, and lack of interconnected closed-loop modules, this invention employs an improved spatiotemporal iterative entropy-weighted dynamic risk quantification module. This module introduces a time decay factor and spatial correlation coefficient to optimize the traditional entropy-weighted algorithm, achieving spatiotemporal dynamic quantification of network risk indicator weights and node risk values, thus solving the problem of static assessment distortion. Then, a multi-constraint attack-defense game evolution path prediction module, using the dynamic risk quantification results as constraints, constructs an attack-defense game payoff model and dynamic state transition probabilities to achieve dynamic attack path prediction, while simultaneously providing back-feedback to optimize risk assessment parameters. This effectively improves the accuracy of risk assessment and attack path prediction in complex dynamic networks.
[0036] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for dynamic assessment of network security risks and prediction of attack paths, characterized in that, Includes the following steps: Step S1: Network situation data collection and preprocessing: Collect five types of core situation data from each network node in real time, including vulnerability status, traffic data, port open status, permission configuration, and link communication latency. Perform data denoising and normalization processing to construct a dynamic network situation dataset. Step S2: By using the improved spatiotemporal iterative entropy weight risk dynamic quantification module, the risk index weights are iteratively updated in combination with the spatiotemporal dynamic characteristics of the network, and the real-time risk value and link risk coefficient of each network node are quantified. Step S3: Using the dynamic risk value and link risk coefficient output in step S2 as constraints, construct the attack and defense game payoff matrix through the multi-constraint attack and defense game evolution path prediction module, and iteratively evolve to generate the optimal attack path set. Step S4: Extract the attack frequency and node breach probability feedback data of the attack path in step S3, and iteratively optimize the risk indicator weight in step S2 to realize the closed-loop dynamic update of the improved spatiotemporal iterative entropy weight risk dynamic quantification module and the multi-constraint attack and defense game evolution path prediction module. Step S5: Output a dynamic risk assessment report and multi-level attack path prediction results to complete dynamic early warning of network security risks.
2. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 1, characterized in that: The specific implementation steps of step S2 are as follows: Step S21: Construct a multi-dimensional risk assessment indicator system: Based on the core influencing factors of network security, establish a 5-dimensional risk assessment indicator system, including: vulnerability risk coefficient. Traffic anomaly Port exposure risk value Permission redundancy Vulnerability of link communication All indicators were preprocessed and normalized to [value missing]. interval; Step S22: Introduce spatiotemporal feature factors and construct an improved information entropy calculation formula: ;in For the first Improved information entropy for risk indicators; This is a time decay factor used to characterize the timeliness of metrics such as vulnerabilities and traffic. , The attenuation coefficient is... For the current moment, This refers to the time when the indicator data is updated; The spatial correlation coefficient is used to characterize the risk transmission characteristics of adjacent network nodes. Its value is determined by the frequency and correlation of inter-node link communication, and its range is [range missing]. ; For the first The first item under the indicator The percentage of indicators for each node, if ,but ; This represents the total number of network nodes. Step S23: Dynamically iteratively calculate the index weights: Based on the improved information entropy, the calculation of the first... Dynamic weight of the indicator The calculation formula is: The weight values iterate in real time with the spatiotemporal state of the network, which can accurately adapt to the dynamic changes of the network compared with traditional fixed weights. Step S24: Quantify the real-time risk value of the node: By combining dynamic weights and normalized index data, the real-time comprehensive risk value of each network node is calculated. : ;in For the first The node of the first Normalized index value, The interval is The higher the value, the higher the risk of the node.
3. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 2, characterized in that: Spatial correlation coefficient in step S22 The specific calculation steps are as follows: Step 1: Calculate the normalization coefficient of node link communication frequency. : For any adjacent nodes , Effective communication frequency between two nodes within the sampling period of the statistical unit Combined with the highest link communication frequency in the entire network The basic coefficients of link communication association are obtained by normalization, and the calculation formula is as follows: ;in, The link communication status data collected in step S1 is obtained through real-time statistical analysis. This represents the maximum communication frequency across all links in the current network topology, used to eliminate the impact of differences in network size. The interval is The larger the value, the more frequent the communication and interaction between nodes, and the higher the probability of risk transmission. Step 2: Calculate the correlation degree of node risk transmission. ; The node comprehensive risk value is calculated in real time using an improved spatiotemporal iterative entropy weight risk dynamic quantification module. , Construct a formula for the risk coupling correlation between adjacent nodes to quantify the risk transmission ability of high-risk nodes to neighboring nodes: ,in, , Adjacent nodes , Real-time risk value; The interval is ; Step 3: Calculate the dynamic spatial correlation coefficient And interval constraints: By integrating link communication characteristics and risk transmission characteristics, weighted and fused dual-dimensional parameters are obtained. The calculation formula is: ,in, The fusion weighting coefficient is fixed at 0.5; through The lower limit of the mandatory constraint coefficient is 0.2; Step 4: Algorithm Iteration and Adaptation: Calculated dynamics Real-world input of the improved information entropy formula Complete the iterative calculation of the entropy value.
4. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 3, characterized in that: The node comprehensive risk value in step 2 , The specific calculation steps are as follows: Step 2.1: Obtain node normalized risk indicator data: Based on the standardized dataset preprocessed in step S1, neighboring nodes are extracted respectively. , The corresponding 5-dimensional normalized risk index value; Among the nodes The set of indicators is ,node The set of indicators is All indicator values are normalized to interval, Representing the The node of the first Risk indicator values; Step 2.2: Calculate the improved spatiotemporal information entropy for each indicator: Substituting into the improved information entropy formula, and combining it with the real-time updated time decay factor... Spatial correlation coefficient The dynamic information entropy of the five risk indicators is generated one by one. ; Step 2.3: Solve for the dynamic index weights: Based on the improved information entropy obtained in step 2.2 Substitute the values into the dynamic weight calculation formula to solve for the real-time weights of the five risk indicators. : All indicator weights satisfy the normalization constraint. ; Step 2.4: Calculate the real-time risk value of each node using weighted summation. The method of linear weighting and fusion of index weights and normalized indexes is used to calculate the values of adjacent nodes. , The real-time comprehensive risk value is calculated using the following core formula: ; ;in For nodes The Normalized risk indicator value, For nodes The The normalized risk index value; the final calculated value. , The range of values is The larger the value, the higher the security risk of the corresponding node.
5. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 1, characterized in that: The specific implementation steps of step S3 are as follows: Step S31: Construct the offensive and defensive game subjects and strategy space: Define the two sides in the game as the attacker and the defender, and the attacker's strategy space is: The defensive strategy space is The node risk value output by the first module. The link risk coefficient serves as a core constraint on game payoffs. Step S32: Construct an improved attack-defense game payoff matrix: By combining dynamic risk parameters to construct a real-time game payoff matrix, the attacker's payoff function formula is as follows: The formula for the defensive side's payoff function is: The parameters are explained as follows: For the attacker's benefit, For the benefit of the defending side; The node risk-reward weight is fixed at 0.6; The defense cost coefficient is determined by the overhead of implementing the network defense strategy. The real-time protection strength of the defender is positively correlated with the node security configuration and the operating status of the protection equipment. Step S33, Game Evolution Iteration and Path Selection: Based on the evolutionary game replication dynamic equation, the stability probability of the strategies of both the attacker and defender is iteratively calculated to construct the dynamic state transition probability: ,in For attacking from the node Transfer to node The probability of; For nodes and The link connectivity risk coefficient; based on the dynamic transition probability, all feasible attack paths are generated through traversal, and the optimal attack path set with the top-N probabilities is selected; Step S34: Parameters of the improved spatiotemporal iterative entropy weight risk dynamic quantification module with reverse feedback optimization: The attack traversal frequency and breakthrough probability of each node in the statistical prediction path are used to generate risk feedback coefficients, which are then used to correct the time decay factor of the improved spatiotemporal iterative entropy weight risk dynamic quantification module. With indicator weights This enables the dynamic iteration of the risk assessment system.
6. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 5, characterized in that: The defense cost coefficient in step S32 The logic for obtaining it is as follows: Step S32.1: Construct a quantitative indicator system for defense strategy costs: Combined with the defensive strategy space Based on the real-time network situational data collected in step S1, three types of core defense overhead indicators are defined. All defense overhead indicators are normalized to... Range: Vulnerability remediation costs Traffic interception overhead Access banning overhead ; Step S32.2: Introduce risk weight constraints and construct the basic formula for defense cost: The real-time node risk value is output by the improved spatiotemporal iterative entropy weight risk dynamic quantification module. As an adaptive constraint, the formula for calculating the initial defense cost coefficient is constructed as follows: ,in, This represents the unconstrained initial defense cost coefficient. This represents the real-time comprehensive risk value of the current protected node. Step S32.3, interval threshold constraint, yields the final defense cost coefficient. : For initial coefficients With upper and lower limit constraints applied, the final calculation formula is: In the formula, For interval constraint functions, force the... Value constraints The interval; when the node risk is extremely low and the network situation is stable, Approaching 0.1; when nodes are high-risk and network anomalies are severe, Approaching 0.9; Step S32.4, Parameter linkage iterative adaptation: Dynamically calculated Real-time input of attack and defense benefit functions , Completing the payout calculation directly affects the probability of attack and defense strategy evolution and the probability of attack state transition. Ultimately, this affects the attack path prediction results.
7. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 5, characterized in that: Nodes in step S33 and Link connectivity risk coefficient The specific calculation logic is as follows: First, extract the vulnerability features of basic link communication: through the link communication frequency normalization coefficient. This characterizes the communication activity level of the link. Higher communication frequency indicates more favorable conditions for attackers to move laterally, but also a higher vulnerability in the link's foundation. Basic dimensional features; Second, a node risk coupling correction term is introduced: the node risk transmission correlation degree is calculated in real time by calling the improved spatiotemporal iterative entropy weight risk dynamic quantification module. , as a link risk coupling correction term; Third, introduce the spatiotemporal decay constraint factor: obtain the time decay factor in step S2. This is used to characterize the time-degradation characteristics of link risk, through... Achieve dynamic time-dimensional calibration of link risks; Fourth, construct a formula for calculating the link connectivity risk coefficient: This formula integrates link communication characteristics, node risk coupling characteristics, and time-sensitivity characteristics, while also matching the spatial correlation logic described earlier, to construct a dynamic formula for the link connectivity risk coefficient. ; Fifth, interval steady-state constraints and parameter linkage: The calculation results are subjected to interval constraints, and the final effective link risk coefficient is: ,Will Constraints The interval is used to prevent the occurrence of zero values in silent or disconnected links, which could lead to path prediction failure; the solution is dynamically obtained. Real-world attack state transition probability formula This directly constrains the attack path generation results.
8. The method for dynamic assessment of network security risks and prediction of attack paths according to claim 5, characterized in that: The specific implementation steps of step S4 are as follows: Step S41: Statistically analyze the attack traversal characteristics of all nodes on the network: Based on the set of all optimal attack paths generated iteratively by the multi-constraint attack-defense game evolution path prediction module, all predicted paths are traversed one by one, and two core dynamic feature parameters are statistically analyzed: node attack traversal frequency and node breakthrough probability. Specifically: Define nodes attack traversal frequency Within the unit update cycle, nodes The total number of times a node appears in all optimal attack paths is used to characterize how frequently a node is targeted by attackers. Define nodes probability of breach The probability of attack transfer based on the in-degree of a node is accumulated, and the calculation formula is as follows: ,in, For nodes The set of all adjacent nodes; Adjacent nodes To the node The probability of dynamic attack transfer; Step S42: Construct the node dynamic risk feedback coefficient: By combining attack traversal frequency and breakthrough probability with the average attack characteristics across the entire network, a normalized risk feedback coefficient is constructed. This is used to quantify the degree of correction that the current offensive and defensive situation makes to the original risk assessment results of the node. The calculation formula is as follows: ,in, This represents the average attack traversal frequency across all nodes in the entire network. For nodes The risk feedback correction coefficient, with a value range of [value range missing]. ;like This indicates that the actual attack and defense risk of the node is higher than the currently assessed risk, and the risk weight and temporal decay intensity need to be positively amplified; if This indicates that the actual risk of the node is overestimated, and the corresponding risk parameters need to be weakened. Step S43, reverse correction of time decay factor : Introducing a risk feedback coefficient to achieve adaptive correction, and constructing a time decay factor after iteration: ,in, This is the corrected real-time time decay factor; the correction coefficient of 0.2 represents the small iteration step size; when a high-risk node... hour, Increase, delay the decay of risk over time, and retain the long-term risk characteristics of high-risk nodes; when low-risk nodes hour, This reduces and accelerates the decay of obsolescence risk characteristics, enabling precise calibration of time-series risks; the corrected... Directly substituting into the improved spatiotemporal iterative entropy weight risk dynamic quantification module improves information entropy. Participate in the next round of iteration calculation; Step S44: Iterate backwards to correct the risk indicator weights. : Combining the node risk feedback coefficient with the risk contribution of each indicator, the dynamic weight of the improved spatiotemporal iterative entropy weight risk dynamic quantification module is adjusted. To perform adaptive fine-tuning, construct an iterative weight correction formula: ,in, For the revised first Weighting of each risk indicator; The average risk feedback coefficient of all nodes in the network represents the overall risk correction trend of the entire network. Adjust the sensitivity of the indicator; To ensure the weight normalization constraint, the corrected weights are standardized: In the formula, The final updated indicator weights satisfy the following conditions: ; Step S45, Iterative Update: The corrected time decay factor with normalized index weights Substitute back to the improved spatiotemporal iterative entropy weight risk dynamic quantification module and re-iterate the real-time risk value of the node. Spatial correlation coefficient Link connectivity risk coefficient The updated parameters are then input into the multi-constraint attack-defense game evolution path prediction module to update the attack-defense game payoffs, attack transfer probabilities, and attack path prediction results.