An entropy change driven network space multi-domain fusion intelligent security method and device and electronic equipment

CN122802282APending Publication Date: 2026-09-22NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202611283824.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-24
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0007]针对现有技术在多域融合对抗中无法对异构不确定性进行统一度量、无法推演其跨域耦合演化、也无法以其为核心自适应生成防御策略的缺陷,本申请的实施例提供了一种熵变驱动的网络空间多域融合智能安全方法、装置及电子设备

Benefits of technology

能够克服现有技术在多域融合对抗场景中缺乏统一度量标尺、缺乏跨域耦合推演结构、缺乏以不确定性管控为核心的策略生成机制等缺陷,将“降己之熵、增敌之熵”的理论思想转化为可计算、可推演、可闭环的工程化技术方案,实现多域融合对抗场景下不确定性的统一度量、跨域演化推演以及攻防策略的自适应生成,显著提升关键信息基础设施在多域复杂环境下的主动防御能力和自适应决策效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802282A_ABST
    Figure CN122802282A_ABST
Patent Text Reader

Abstract

The application provides an entropy change driven network space multi-domain fusion intelligent security method and device and electronic equipment, relates to the network space security technical field, and the method is first based on the defense party's own observation to update the defense party's belief, and estimates the belief and the conditional probability distribution of the attack action of the attack party through the mirror deduction; secondly, the attack entropy and the defense entropy are calculated based on the beliefs of both parties, the unified quantification of multi-source heterogeneous uncertainty is realized; then, a discrete random dynamics model containing a cross-domain coupling term is established, and the evolution trajectory of uncertainty under the driving of attack and defense behaviors is deduced; finally, the minimum defense entropy and the maximum attack entropy are taken as the target, the optimal defense action is adaptively selected, and an executable instruction is generated. The above process is executed in a loop, forming a continuous "perception-deduction-decision-execution" closed loop. The method can significantly improve the active defense capability and adaptive decision efficiency of the key information infrastructure in a multi-domain complex environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cyberspace security technology, and more specifically, to an entropy change-driven multi-domain fusion intelligent security method, device, and electronic device for cyberspace. Background Technology

[0002] Cyberspace confrontation is fundamentally characterized by uncertainty. Both attackers and defenders are constantly mired in multiple dilemmas, including inaccurate observational information, unclear adversary strategies, and unpredictable attack and defense effects. In recent years, as the boundaries of cyberspace have extended from the traditional network information domain to domains such as geographical environment, electromagnetic spectrum, and social cognition, confrontation has evolved into a complex game involving multiple domains. The sources of uncertainty have become more diverse, the forms more complex, and the degree of uncertainty has further intensified. Attackers may launch attacks from any domain or in a coordinated effort across multiple domains. Their attack paths, timing, and methods are all highly uncertain, and the effects of attacks can cascade and propagate between domains. For example, cross-domain cascading attacks in power grid scenarios and multi-domain coordinated penetration in telecommunications network scenarios both exemplify this characteristic. Existing research has explored solutions to these problems from multiple directions, but all have struggled to address this complex uncertainty. Specifically, research has mainly focused on the following three paths: Path 1: Formal Modeling and Probabilistic Statistical Methods. This type of method utilizes tools such as Markov decision processes, hybrid automata, and Bayesian games to characterize system state evolution, and can describe some known uncertainties. However, it primarily focuses on state transitions in the physical and network domains, and is insufficient in characterizing uncertainties arising from subjective perception (such as scheduler misjudgments or concealed attacker intent) and policy interactions. In multi-domain, high-dimensional scenarios, model parameters grow exponentially, severely limiting scalability.

[0003] Path Two: Entropy-Based Network Security Measurement Methods. In recent years, researchers have attempted to introduce information entropy into the security field to quantify the uncertainty in the attack and defense process. For example, the patent "A Calculation Method for Network Attack and Defense Uncertainty Measurement Based on Entropy" (CN202410649771.7) uses Shannon entropy to characterize the uncertainty of the attacker's beliefs; another patent, "A Method for Determining the Effectiveness of Network Attack and Defense Based on Lyapunov Stability" (CN202610220599.2), constructs attack entropy, defense entropy, and structural entropy into a three-dimensional Lyapunov function for security level assessment. However, the former only addresses unilateral cognition and does not involve cross-domain coupling, while the latter's model is a continuous differential equation with no cross-domain coupling terms, and its output is only the security level, relying on a preset ideal entropy value. Neither can output an executable defense strategy.

[0004] Path Three: Reinforcement Learning-Based Attack and Defense Strategy Generation. This type of method learns the optimal strategy through interaction between the agent and the environment, and some works have used uncertainty as an auxiliary input. However, existing research has not yet used uncertainty measurement as the core driver of strategy generation, lacks semantic alignment with the phased evolution of multi-domain security chains, and cannot provide support for the synchronous updating of beliefs and the allocation of long-term benefits in multi-stage games.

[0005] In 2025, Janani proposed the concept of "Cybersecurity through EntropyInjection: A Paradigm Shift from Reactive Defense to Proactive Uncertainty" (arXiv:2504.11661), which aims to increase the uncertainty for attackers by actively injecting randomness into the system, and presented this approach as a new paradigm for cybersecurity. However, this work remains at the level of conceptual advocacy and existing technology overview, failing to address core issues such as unified measurement of uncertainty in multi-domain integrated scenarios, cross-domain coupled inference, and adaptive policy generation, and has not yet formed a complete theoretical and technical system.

[0006] Furthermore, the academic monograph *Theory and Methods of Multi-Domain Fusion Intelligent Security System in Cyberspace* (published in 2026) systematically defines the mathematical forms of attack entropy and defense entropy from an information theory perspective. It proposes the theoretical idea of ​​"reducing one's own entropy and increasing the enemy's entropy" and a closed-loop logical framework of "perception-deduction-decision," and constructs a formalized model of attack-defense game theory using dynamic Bayesian networks and partially observable Markov decision processes. However, this monograph remains at the theoretical modeling level: it constructs a general theoretical framework for attack-defense game theory, rather than an explicit dynamic model for engineering implementation; its approach to multi-domain scenarios is an abstract description of the joint state space, without providing the specific mathematical structure of cross-domain coupling terms; and its decision-making solution relies on theoretical Bayesian inference and Bellman equations, without providing an online belief update method based on deterministic observation data. Therefore, although this monograph establishes a theoretical path from uncertainty measurement to optimal decision-making, it fails to translate this path into a complete solution that can be directly implemented in engineering. Summary of the Invention

[0007] To address the shortcomings of existing technologies in multi-domain fusion confrontation—namely, their inability to uniformly measure heterogeneous uncertainty, deduce its cross-domain coupling evolution, and adaptively generate defense strategies based on it—this application provides an entropy-change-driven intelligent security method, device, and electronic device for multi-domain fusion in cyberspace. This method establishes an engineering measurement of attack entropy and defense entropy based on a parameterized belief distribution. It deduces belief evolution through a discrete stochastic dynamics model including cross-domain coupling terms, and adaptively generates defense strategies with the weighted change of defense entropy and attack entropy as the optimization objective, forming a closed loop from situational awareness to strategy execution.

[0008] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.

[0009] According to a first aspect of the embodiments of this application, an entropy-change driven multi-domain fusion intelligent security method for cyberspace is provided, comprising: The defender's belief parameters are updated based on the defender's own observations; Estimate the attacker's belief parameters and conditional probability distribution of the attacker's actions by mirroring the attacker's actions. Based on the defender's belief parameters and the attacker's belief parameters, an entropy value is calculated to quantify the situation of both sides, the entropy value including defense entropy and attack entropy; A discrete stochastic dynamic model containing cross-domain coupling terms is established to deduce the belief parameters of the defender and attacker at the next moment. Based on the deduced beliefs of both parties, the attack entropy and defense entropy at the next moment are calculated to obtain the deduction results of entropy value changes. With the goal of minimizing defense entropy and maximizing attack entropy, the optimal defense action is adaptively selected based on the entropy value change deduction results to generate an entropy control strategy.

[0010] In some embodiments of this application, based on the foregoing scheme, updating the defender's belief parameters based on the defender's own observations includes: The defender obtains the noisy observation vector at the current moment by deploying heterogeneous probes in various domains; Based on the parameterized beliefs of the previous moment and the observation vector of the current moment, the defender updates and generates the parameterized belief distribution of the current moment through a filtering method, thus obtaining the defender's belief parameters.

[0011] In some embodiments of this application, based on the foregoing scheme, estimating the attacker's belief parameters and conditional probability distribution of the attacker's actions through mirror modeling of the attacker includes: The defender infers the attacker's belief parameters at the current moment based on its own historical observation sequence and prior knowledge of the attacker, and uses these as estimates of the attacker's belief parameters. Based on the inferred subjective posterior belief distribution and the pre-set attacker decision model, the defender calculates the conditional probability of the attacker selecting each candidate action and outputs the conditional probability distribution of the attacker's actions.

[0012] In some embodiments of this application, after the belief distribution is represented in a parameterized form, the attack entropy and defense entropy can be calculated in the following manner.

[0013] Set the attacker's expected distribution This causes the attacker's probability of success to focus on the set of "damaged and controlled" states of the system; Set the expected distribution of the defender This allows the defender's probability quality to be concentrated in the system's "safe and controllable" state set; Based on the attacker's expected distribution Calculate the attack entropy using the attacker's belief parameters. :

[0014] Based on the defender's expected distribution Calculate the defense entropy based on the defender's belief parameters. :

[0015] in, Shannon entropy is calculated by integrating the probability density function of the belief distribution or summing the probability mass function, and is used to quantify cognitive uncertainty. Relative entropy is used to quantify the degree of deviation between current beliefs and expected goals; To balance the factors, the decision-makers pre-determine them based on the task scenario; These are the attacker's belief parameters estimated by the defender through mirror simulation. Indicates by parameters The only known distribution of the attacker's beliefs; For the defender's belief parameters; Indicates by parameters The only known distribution of defensive beliefs.

[0016] In some embodiments of this application, based on the aforementioned scheme, a discrete stochastic dynamical model including cross-domain coupling terms is established to deduce the defender's belief parameters at the next moment, including: A discrete-time stochastic difference equation with the defender's belief distribution parameters as state variables is established to obtain the defender's discrete stochastic dynamic model. Mathematical expectation of the defender's belief parameters at the next moment, based on the defender's discrete stochastic dynamics model:

[0017] in, Actions of the attacker The conditional probability distribution; This is the domain drift function from the defender's perspective, which characterizes the direct impact of defensive and offensive behaviors within the domain. Indicates the defending side's position on the first The belief parameter vector of the domain; Candidate actions for the defending side; The superscript represents the cross-domain coupling coefficient of the defending side. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the defensive coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; This is an independent random perturbation term for the defender.

[0018] In some embodiments of this application, based on the aforementioned scheme, a discrete stochastic dynamic model including cross-domain coupling terms is established to deduce the attacker's belief parameters at the next moment, including: Based on prior knowledge of the attacker, the defender adopts a dynamic model that is symmetric to the defender's discrete stochastic dynamic model as the attacker's discrete stochastic dynamic model. The candidate defensive actions currently being evaluated are input as the defender's actions into the attacker's discrete stochastic dynamics model to calculate the attacker's belief parameter components at the next time step:

[0019] in, The drift function, cross-domain coupling coefficient, and coupling function from the attacker's perspective can be obtained based on prior assumptions about the attacker's behavior patterns or learned from historical data. For the attacker to the third The belief parameter vector of the domain; Candidate actions for the defending side; The defender's estimate of the attacker's actions is derived from the conditional probability distribution of the attacker's actions. Representative actions selected from the text; The cross-domain coupling coefficient of the attacker is indicated by a superscript. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the attacker's coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; This is an independent random perturbation term for the attacker.

[0020] In some embodiments of this application, based on the foregoing scheme, the step of adaptively selecting the optimal defense action to generate an entropy control strategy based on the entropy value change deduction result, with the goal of minimizing defense entropy and maximizing attack entropy, includes: Based on the entropy change deduction results, the optimization objective is solved using the following formula to select the optimal defensive action. ;

[0021] in, For the set of candidate defensive actions; This represents the change in the defender's entropy value. This represents the change in the attacker's entropy value. The preference coefficient reflects the relative importance that the defender attaches to reducing its own entropy and increasing the enemy's entropy. Among them, when At that time, the optimization objective degenerates into The defender only focuses on reducing its own defense entropy, which is suitable for scenarios where the system is in a high-risk state and needs to be restored to stability first; when At that time, the optimization objective degenerates into The defender focuses solely on increasing the attacker's attack entropy, that is, confusing the opponent by actively injecting uncertainty; when At that time, the defender weighs the reduction of its own cognitive uncertainty against the increase of the opponent's cognitive uncertainty.

[0022] According to a second aspect of the embodiments of this application, an entropy-change driven multi-domain fusion intelligent security device for cyberspace is provided, comprising: The update unit is used to update the defender's belief parameters based on the defender's own observations. The mirror simulation unit is used to estimate the attacker's belief parameters and the conditional probability distribution of the attacker's actions by performing mirror simulation on the attacker. The calculation unit is used to calculate the attack entropy and defense entropy based on the defender's belief parameters and the attacker's belief parameters. The dynamics deduction unit is used to establish a discrete stochastic dynamics model containing cross-domain coupling terms, deduce the belief parameters of the defender and attacker at the next moment, and calculate the attack entropy and defense entropy at the next moment based on the deduced beliefs of both parties, and obtain the deduction results of entropy value changes. The strategy generation unit is used to generate an entropy control strategy by adaptively selecting the optimal defense action based on the entropy value change deduction result with the goal of minimizing defense entropy and maximizing attack entropy.

[0023] According to a third aspect of the embodiments of this application, an electronic device is provided, including: a memory and a processor; The memory is used to store computer instructions; The processor is configured to invoke computer instructions stored in the memory, causing the electronic device to execute the method described in the first aspect.

[0024] The technical solution of this application has the following beneficial effects: It can overcome the shortcomings of existing technologies in multi-domain fusion confrontation scenarios, such as the lack of a unified measurement scale, the lack of cross-domain coupling deduction structure, and the lack of a strategy generation mechanism with uncertainty management as the core. It transforms the theoretical idea of ​​"reducing one's own entropy and increasing the enemy's entropy" into a computable, deducible, and closed-loop engineering technical solution. It realizes the unified measurement of uncertainty, cross-domain evolution deduction, and adaptive generation of attack and defense strategies in multi-domain fusion confrontation scenarios, significantly improving the proactive defense capability and adaptive decision-making efficiency of critical information infrastructure in multi-domain complex environments.

[0025] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0026] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort. In the drawings: Figure 1 A flowchart illustrating an entropy-driven multi-domain fusion intelligent security method for cyberspace according to an embodiment of this application is shown. Figure 2 A block diagram of an entropy-change driven multi-domain fusion intelligent security device for cyberspace according to an embodiment of this application is shown. Figure 3 A block diagram of an electronic device according to one embodiment of this application is shown. Detailed Implementation

[0027] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this application more comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art.

[0028] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this application. However, those skilled in the art will recognize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this application.

[0029] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0030] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0031] It should be noted that "multiple" in this article refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such uses of these terms can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described.

[0033] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0034] The following detailed description of some embodiments of this application will be provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0035] Specifically, this invention first updates the defender's beliefs based on their own observations and estimates the conditional probability distribution of the attacker's beliefs and actions through mirrored extrapolation. Second, it calculates entropy values ​​for quantifying the situation based on both sides' beliefs, including defense entropy and attack entropy, achieving unified quantification of multi-source heterogeneous uncertainties. Then, it establishes a discrete stochastic dynamics model containing cross-domain coupling terms to extrapolate the beliefs of both sides at the next moment and calculates the entropy change based on the extrapolation results. Finally, with the goal of minimizing defense entropy and maximizing attack entropy, it adaptively selects the optimal defense action and generates executable instructions. This process is executed cyclically, forming a continuous "perception-extrapolation-decision-execution" closed loop.

[0036] It should be noted that the decision-making process of this invention is based on discrete time steps. Run. At each time step Steps S100 to S300 update the belief and entropy values ​​at the current moment based on the current observations; step S400 uses a dynamic model to predict future moments. The system is in a state to assess the expected effects of different defensive actions; step S500 selects the optimal action and executes it. After execution, the system enters... At any given moment, acquire new observations and repeat the above process.

[0037] See Figure 1 The diagram illustrates a flowchart of an entropy-driven multi-domain fusion intelligent security method for cyberspace according to an embodiment of this application.

[0038] like Figure 1 As shown, an entropy-driven multi-domain fusion intelligent security method for cyberspace is demonstrated, specifically including steps S100 to S500.

[0039] refer to Figure 1 Step S100: Update the defender's belief parameters based on the defender's own observations.

[0040] In some feasible embodiments, based on the foregoing scheme, updating the defender's belief parameters based on the defender's own observations includes: The defender obtains the noisy observation vector at the current moment by deploying heterogeneous probes in various domains; Based on the parameterized beliefs of the previous moment and the observation vector of the current moment, the defender updates and generates the parameterized belief distribution of the current moment through a filtering method, thus obtaining the defender's belief parameters.

[0041] For example, step S100 specifically includes the following process: Suppose the target system is at time 10:00. The true state is a multidimensional random vector Their components characterize key attributes in the geographic environment domain, electromagnetic spectrum domain, network information domain, and social cognitive domain, respectively. The defender acquires noisy observation vectors through heterogeneous probes deployed in each domain. Record the defending side's cutoff time. The historical observation sequence is .

[0042] The defender is based on the previous moment Posterior beliefs and current observations The current time step is updated using filtering methods (such as Bayesian filtering, Kalman filtering, particle filtering, etc.). Distribution of subjective posterior beliefs:

[0043] To utilize the aforementioned belief distribution for subsequent evolutionary deduction and entropy calculation, it is represented in a parameterized form: It is assumed that the belief distribution belongs to a certain parameterized distribution family (e.g., Gaussian distribution, Gaussian mixture model, etc.), represented by the parameter vector. The only certainty:

[0044] Updated belief parameters This will be used as the input for step S300.

[0045] It should be noted that the above filtering method can be implemented using various recursive filtering methods. This embodiment only uses Bayesian filtering as an example for illustration and does not constitute a limitation on the filtering method.

[0046] Continue to refer to Figure 1 Step S200: Estimate the attacker's belief parameters and the conditional probability distribution of the attacker's actions by mirroring the attacker's actions.

[0047] In some feasible embodiments, based on the foregoing scheme, estimating the attacker's belief parameters and conditional probability distribution of the attacker's actions through mirror modeling of the attacker includes: The defender infers the attacker's belief parameters at the current moment based on its own historical observation sequence and prior knowledge of the attacker, and uses these as estimates of the attacker's belief parameters. Based on the inferred subjective posterior belief distribution and the pre-set attacker decision model, the defender calculates the conditional probability of the attacker selecting each candidate action and outputs the conditional probability distribution of the attacker's actions.

[0048] For example, step S200 specifically includes: The defender constructs a mirror model of the attacker within its own cognitive framework. This model simulates the attacker's observation methods, belief update rules, and decision-making logic. This step is divided into two sub-steps: attacker belief estimation and action prediction. Sub-step S210: Attacker's belief estimation The defender bases its observation history on the entirety of its own observations. In addition to prior knowledge of the attacker (such as the types of strategies the attacker might employ, observation noise characteristics, behavioral preferences, etc.), the distribution of the attacker's subjective posterior beliefs at the current moment is inferred, denoted as . :

[0049] To utilize the aforementioned belief distribution for subsequent evolutionary deduction and entropy calculation, it is represented in a parameterized form: It is assumed that the belief distribution belongs to a certain parameterized distribution family (e.g., Gaussian distribution, Gaussian mixture model, etc.), represented by the parameter vector. The only certainty:

[0050] Sub-step S220: Predicting the attacker's actions The defender's belief distribution is based on the inferred attackor's belief distribution. It also includes a pre-defined attacker decision-making model, which calculates the conditional probability of the attacker selecting each candidate action and outputs the attacker's action. conditional probability distribution The decision model is used to characterize the mapping relationship between the attacker's beliefs and actions. It can be a utility-based rational decision model (e.g., the attacker chooses the action that maximizes its expected benefits) or a behavior prediction model learned from historical adversarial data.

[0051] The attacker's belief parameters output in this step The attack entropy calculation used in step S300 outputs the probability distribution of the attacker's actions. The dynamic deduction used in step S400 is marginalized.

[0052] Continue to refer to Figure 1 Step S300: Calculate the attack entropy and defense entropy based on the defender's belief parameters and the attacker's belief parameters.

[0053] In some feasible embodiments, based on the aforementioned scheme, after the belief distribution is represented in a parameterized form, the attack entropy and defense entropy can be calculated in the following way.

[0054] Set the attacker's expected distribution This causes the attacker's probability of success to focus on the set of "damaged and controlled" states of the system; Set the expected distribution of the defender This allows the defender's probability quality to be concentrated in the system's "safe and controllable" state set; Based on the attacker's expected distribution Calculate the attack entropy using the attacker's belief parameters. :

[0055] Based on the defender's expected distribution Calculate the defense entropy based on the defender's belief parameters. :

[0056] in, Shannon entropy is calculated by integrating the probability density function of the belief distribution or summing the probability mass function, and is used to quantify cognitive uncertainty. Relative entropy is used to quantify the degree of deviation between current beliefs and expected goals; To balance the factors, the decision-makers pre-determine them based on the task scenario; These are the attacker's belief parameters estimated by the defender through mirror simulation. Indicates by parameters The only known distribution of the attacker's beliefs; For the defender's belief parameters; Indicates by parameters The only known distribution of defensive beliefs.

[0057] For example, step S300 specifically includes: Based on the defender's belief parameters obtained in step S100 And the attacker's belief parameter estimation obtained in step S200 The defense entropy and attack entropy are calculated separately to quantify the cognitive uncertainty and target deviation of both sides in the current situation.

[0058] First, define the attacker's expected distribution. This concentrates the probability quality of the system on the set of "damaged and controlled" states; and sets the expected distribution of the defender. This ensures that its probability quality is concentrated within the set of "safe and controllable" states of the system. The expected distribution can be pre-configured according to the system's security requirements, for example, by... It is set to a Gaussian distribution centered at a safety threshold.

[0059] Then, calculate the attack entropy using the following formula. With defense entropy :

[0060]

[0061] in: Shannon entropy is calculated by integrating the probability density function of the belief distribution (continuous case) or summing the probability mass function (discrete case), and is used to quantify cognitive uncertainty. The relative entropy (KL divergence) is used to quantify the degree of deviation between the current belief and the expected goal. To balance the factors, the decision-makers pre-determine the coefficients based on the task scenario.

[0062] In engineering implementation, if the belief distribution is continuous, the above entropy value can be approximated using Monte Carlo sampling or grid discretization methods. The calculated attack entropy... and defense entropy This will serve as the benchmark value for deriving the expected entropy change in step S400.

[0063] Continue to refer to Figure 1 Step S400: Establish a discrete stochastic dynamic model containing cross-domain coupling terms, deduce the belief parameters of the defender and attacker at the next moment, and calculate the attack entropy and defense entropy at the next moment based on the deduced beliefs of both parties to obtain the entropy value change deduction results.

[0064] In some feasible embodiments, based on the aforementioned scheme, a discrete stochastic dynamical model including cross-domain coupling terms is established to deduce the defender's belief parameters at the next moment, including: A discrete-time stochastic difference equation with the defender's belief distribution parameters as state variables is established to obtain the defender's discrete stochastic dynamic model. Mathematical expectation of the defender's belief parameters at the next moment, based on the defender's discrete stochastic dynamics model:

[0065] in, Actions of the attacker The conditional probability distribution; This is the domain drift function from the defender's perspective, which characterizes the direct impact of defensive and offensive behaviors within the domain. Indicates the defending side's position on the first The belief parameter vector of the domain; Candidate actions for the defending side; The superscript represents the cross-domain coupling coefficient of the defending side. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the defensive coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; The term represents the independent random perturbation of the defending side, which follows a normal distribution with a mean of zero.

[0066] In some feasible embodiments, based on the aforementioned scheme, a discrete stochastic dynamical model containing cross-domain coupling terms is established to deduce the attacker's belief parameters at the next moment, including: Based on prior knowledge of the attacker, the defender adopts a dynamic model that is symmetric to the defender's discrete stochastic dynamic model as the attacker's discrete stochastic dynamic model. The candidate defensive actions currently being evaluated are input as the defender's actions into the attacker's discrete stochastic dynamics model to calculate the attacker's belief parameter components at the next time step:

[0067] in, The drift function, cross-domain coupling coefficient, and coupling function from the attacker's perspective can be obtained based on prior assumptions about the attacker's behavior patterns or learned from historical data. For the attacker to the third The belief parameter vector of the domain; Candidate actions for the defending side; The defender's estimate of the attacker's actions is derived from the conditional probability distribution of the attacker's actions. Representative actions selected from the text; The cross-domain coupling coefficient of the attacker is indicated by a superscript. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the attacker's coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; The attacker's independent random perturbation term follows a normal distribution with a mean of zero.

[0068] For example, step S400 includes three sub-steps: defender belief deduction, attacker belief deduction, and expected entropy change calculation.

[0069] Specifically, sub-step S410: Deduction of the evolution of the defender's beliefs. Establish a discrete-time stochastic difference equation with the defender's belief distribution parameters as state variables, i.e., a discrete stochastic dynamic model of the defender. Let... Indicates the defending side's position on the first domain( These are belief parameter vectors (corresponding to four domains: geographical environment, electromagnetic spectrum, network information, and social cognition), respectively. The defender's actions against the attacker. The cognition is determined by the conditional probability distribution output in step S200. Characterization. To extrapolate the evolution of the defender's beliefs, the dynamic model is marginalized in terms of the distribution of attack actions, i.e., the mathematical expectation of the belief parameters at the next moment is calculated:

[0070] in: This is the domain drift function from the defender's perspective, which characterizes the direct impact of defensive and offensive behaviors within the domain. Candidate actions for the defending side; The superscript represents the cross-domain coupling coefficient of the defending side. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is a coupling function used to characterize the propagation effect of uncertainty from the source domain to the target domain; The term is an independent random disturbance that follows a normal distribution with a mean of zero.

[0071] The drift function in the above dynamic model With coupling coefficient It can be learned from historical adversarial data through system identification methods or machine learning methods, or it can be modeled based on physical / protocol constraints (such as power flow equations and communication protocol state machines).

[0072] For continuous distributions, the above summation can be replaced by integration or approximation using Monte Carlo sampling. As a simplified implementation, it can also be derived from... If a representative action (such as the mode or expectation) is selected as the point estimate and substituted into the equation, then the marginalization method degenerates into the point estimation method.

[0073] Sub-step S420: Deduction of the attacker's belief evolution To calculate the expected attack entropy change, the defender needs to deduce the evolution of the attacker's beliefs. The attacker's belief parameter vector is obtained from step S200. , record its first Domain components are The defender, based on its prior knowledge of the attacker's dynamics model, adopts a dynamics model symmetrical to sub-step S410. During the deduction, the candidate defensive actions currently being evaluated are considered. As input to the attacker's dynamic model, the attacker's belief parameter components at the next moment are calculated:

[0074] in The drift function, cross-domain coupling coefficient, and coupling function are from the attacker's perspective and can be obtained based on prior assumptions about the attacker's behavior patterns or learned from historical data. The cross-domain coupling coefficient of the attacker is indicated by a superscript. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the attacker's coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; Let be the attacker's independent random perturbation term, following a normal distribution with a mean of zero. In practical implementation, to simplify calculations, it can be assumed that the attacker and defender have the same dynamic structure (i.e., However, different belief parameters are used as input.

[0075] Sub-step S430: Calculation of expected entropy change For any candidate defensive action Using sub-step S410 to obtain the current defender's belief parameters Deducing the defender's belief parameters for the next moment ; Estimating the current attacker's beliefs using sub-step S420 Deducing the attacker's belief parameters for the next moment Based on the derived belief parameters of both sides, the defense entropy for the next moment is recalculated according to the entropy measurement formula in step S300. With attack entropy This leads to the expected change in defense entropy. and expected attack entropy changes .

[0076] The entropy change deduction results in this step provide a quantitative basis for the strategy selection in step S500.

[0077] Continue to refer to Figure 1 Step S500: With the goal of minimizing defense entropy and maximizing attack entropy, the optimal defense action is adaptively selected based on the entropy value change deduction result to generate an entropy control strategy.

[0078] In some feasible embodiments, based on the foregoing scheme, the step of adaptively selecting the optimal defense action to generate an entropy control strategy based on the entropy value change deduction result, with the goal of minimizing defense entropy and maximizing attack entropy, includes: Based on the entropy change deduction results, the optimization objective is solved using the following formula to select the optimal defensive action. ;

[0079] in, For the set of candidate defensive actions; This represents the change in the defender's entropy value. This represents the change in the attacker's entropy value. The preference coefficient reflects the relative importance that the defender attaches to reducing its own entropy and increasing the enemy's entropy. Among them, when At that time, the optimization objective degenerates into The defender only focuses on reducing its own defense entropy, which is suitable for scenarios where the system is in a high-risk state and needs to be restored to stability first, such as when the critical control link has been interfered with and the primary task is to quickly converge to a safe state. when At that time, the optimization objective degenerates into The defender focuses solely on increasing the attacker's attack entropy, i.e., deliberately injecting uncertainty to confuse the adversary. This idea aligns with Janani's concept of "entropy injection," aiming to weaken the attacker's attack effectiveness by making it difficult for them to form a stable understanding. This approach is suitable for scenarios where the system is relatively secure and the goal is to deplete the attacker's resources through proactive defense.

[0080] when At that time, the defender weighs the reduction of its own cognitive uncertainty against the increase of the opponent's cognitive uncertainty.

[0081] It should be noted that the obtained optimal defensive action This is the strategy output in this step. This strategy can be converted into specific instructions by an external execution system and issued to the corresponding strategy execution point. After execution, return to step S100 to enter the next decision-making cycle, forming a continuous "perception-deduction-decision-execution" closed loop.

[0082] The following describes an apparatus embodiment of this application, which can be used to execute an entropy-change-driven intelligent security method for multi-domain fusion in cyberspace as described in the above embodiments of this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in the above embodiments of this application.

[0083] Reference Figure 2 As shown, an entropy-change driven multi-domain fusion intelligent security device 200 for cyberspace according to an embodiment of this application includes: Update unit 201 is used to update the defender's belief parameters based on the defender's own observations; The mirror simulation unit 202 is used to estimate the attacker's belief parameters and the conditional probability distribution of the attacker's actions through mirror simulation of the attacker. The calculation unit 203 is used to calculate the attack entropy and defense entropy based on the defender's belief parameters and the attacker's belief parameters; The dynamics deduction unit 204 is used to establish a discrete stochastic dynamics model containing cross-domain coupling terms, deduce the belief parameters of the defender and attacker at the next moment, and calculate the attack entropy and defense entropy at the next moment based on the deduced beliefs of both parties, and obtain the deduction results of entropy value change. The strategy generation unit 205 is used to generate an entropy control strategy by adaptively selecting the optimal defense action based on the entropy value change deduction result with the goal of minimizing defense entropy and maximizing attack entropy.

[0084] It should be noted that, in practical applications, this device also includes: Input interface: Used to receive multi-source data collected by heterogeneous probes deployed in the four domains of geography, electromagnetics, network, and cognition; Output interface: Connected to the policy generation unit, used to output the entropy control policy to an external policy execution system.

[0085] Below, a specific embodiment is provided.

[0086] Example 1: Multi-domain integrated security protection for power dispatch data networks Part 1: Deployment Environment and Data Preprocessing This embodiment is applied to a regional power grid dispatch and control center, covering three 500kV substations and twelve 220kV substations. The entire system uses the IEEE 1588 PTP protocol for time synchronization, with a synchronization accuracy better than 1 μs. The probe configurations for each domain are as follows: Geographic environment domain: Deploy synchronous phasor measurement devices in substations to collect data on main transformer oil temperature, circuit breaker location, and bus voltage frequency; Electromagnetic spectrum domain: Deploy spectrum monitoring equipment in the dispatch communication room to cover the power wireless private network frequency band (230MHz) and monitor the signal-to-noise ratio and interference power in real time; Network Information Domain: Deploy traffic probes at the core switching nodes of the scheduling data network to collect SCADA system heartbeat packets and IEC 61850 MMS protocol status; Social cognitive domain: Deploy an operation audit terminal at the dispatcher's workstation to record the sequence of dispatch instructions and operation response delays.

[0087] Selecting frequency deviation Signal-to-noise ratio Heartbeat packet loss rate and operation response latency As representative state attributes of each domain. Given the differences in the dimensions and value ranges of these attributes, before dynamic deduction and entropy calculation, the original observations of each domain are first mapped to a dimensionless state space using the Min-Max normalization method. Obtain the state vector All subsequent calculations are performed in the normalized state space described above. The correspondence between each component and attribute is shown in Table 1.

[0088] Table 1. Correspondence between components and attributes .

[0089] Part Two: Step S100, Defender's Belief Update Initial time Assume the defender obtains the observation data shown in Table 2.

[0090] Table 2 Observation Data Table .

[0091] Assuming that each component follows a Gaussian distribution and is independent of the others (the covariance matrix is ​​a diagonal matrix), the prior distribution parameters and observation noise variance of each attribute are shown in Table 3.

[0092] Table 3. Prior distribution parameters and observation noise variance .

[0093] The posterior beliefs are updated using a Bayesian filtering method. For example, substituting the prior mean (0.6000), prior variance (0.006400), observed value (0.6500), and observation noise variance (0.000225) into the standard Bayesian update formula, we can obtain the posterior mean (0.6483) and posterior variance... The remaining three components were calculated using the same method, and the results are summarized in Table 4.

[0094] Table 4. Posterior mean and posterior variance of the defending side. .

[0095] Therefore, the initial belief distribution of the defenders parameter vector for: Posterior mean vector:

[0096] Posterior variance vector: .

[0097] Three: Step S200, Opponent Mirror Simulation The defender constructs a mirror model of the attacker within its own cognitive framework. This model simulates the attacker's observation methods, belief update rules, and decision-making logic. All attacker parameters below are based on the defender's own observation history. And the inference results based on prior knowledge, rather than the attacker's actual state.

[0098] Sub-step: S210, Attacker's belief estimation The defender infers the attacker's possible observation status based on prior knowledge: the attacker may observe electromagnetic interference (decreased signal-to-noise ratio, increased packet loss rate) through its deployed probes or intercepted communication data. The attacker's inferred observation data is shown in Table 5.

[0099] Table 5 Attacker's Observation Data .

[0100] The prior distribution parameters and observation noise variance of each domain of the attacker are shown in Table 6.

[0101] Table 6. Prior distribution parameters and observation noise variance of the attacker in each domain. .

[0102] The defender simulates the attacker's Bayesian update process in the mirror model, calculating the attacker's posterior beliefs based on the inferred prior parameters and observed data. The calculation process is the same as in S100, and is omitted here. The results are summarized in Table 7.

[0103] Table 7. Posterior Mean and Posterior Variance of the Attacker .

[0104] Therefore, the attacker's belief distribution The estimated parameter vector for: Posterior mean vector:

[0105] Posterior variance vector: .

[0106] Sub-step S220, attacking action prediction The defensive assumption is that the attacker's candidate actions are: : Continuous electromagnetic suppression (enhanced electromagnetic spectrum domain attack). : Injecting forged control commands (attacking the social cognitive domain).

[0107] Based on the attacker's belief distribution and expected distribution (See step S3) It is estimated that continuous electromagnetic suppression can reduce the attack entropy from the baseline value to a lower level. Based on this, the probability distribution of the attacker's actions is as follows: (Continuous electromagnetic suppression); (Injecting forged control commands).

[0108] The above action probability distribution will be used for the marginalization calculation of the defender's belief evolution in step S410.

[0109] 4. Step S300: Calculation of Attack Entropy / Defense Entropy In the normalized state space, the expected distribution of the defender is pre-configured. (Safe state) and attacker's expected distribution (Damaged state). The expected distribution parameters of each state component are shown in Table 8.

[0110] Table 8 Expected Distribution Parameters of Each State Component .

[0111] Since it is assumed that the belief distributions of the state components in each domain are independent, the total attack entropy / defense entropy is the sum of the entropy values ​​of each dimension. The Shannon entropy and KL divergence are calculated using standard information theory methods. The Shannon entropy is obtained through discretized numerical integration (using 401 grid points); the KL divergence is obtained through the analytical formula of the Gaussian distribution. The entropy value decomposition calculation results for each dimension are shown in Table 9 (unit: bits).

[0112] Table 9. Entropy decomposition calculation results for each dimension .

[0113] Take the trade-off coefficient ,available Attack entropy at time and defense entropy : ; .

[0114] Step 5: Step S400: Cross-domain uncertainty evolution simulation Sub-step S410, Deduction of the evolution of the defender's beliefs In this embodiment, the candidate defense action set The definitions of each action are as follows: (Switching to fiber optic cable): Switch the communication link to the backup fiber optic channel to avoid interference from the wireless link; (Power Increase + Redundancy): Increase transmission power to improve the electromagnetic spectrum signal-to-noise ratio, and at the same time enable redundant channels to eliminate network packet loss; (No action): Maintain the current system configuration and do not perform any proactive defense operations.

[0115] The attack action is the conditional probability distribution output by step S220. Characterization. Based on the simplified implementation described in the technical solution, the representative action with the highest probability is selected from this distribution. (Continuous electromagnetic suppression, probability 0.65) Make a point estimate.

[0116] Intradomain drift function This characterizes the joint direct impact of attack and defense actions on the system state. Based on the above point estimation, the attack action is set to a constant value. The function degenerates into a form that depends solely on defensive actions, and is abbreviated as: ,in The effects have been incorporated into the parameter settings.

[0117] Each candidate defensive action Corresponding intra-domain drift function Based on physical mechanisms and the expected effects of defense strategies. For example, middle The drift function of (heartbeat packet loss rate) takes This characterizes the strong suppression effect of redundant channels on packet loss rate. The specific settings of each function are shown in Table 10 below.

[0118] Table 10 Function Setting Table .

[0119] Cross-domain coupling matrix (row = target domain) , column = source domain The strength of the transmission of uncertainty between domains is characterized by the pre-defined physical associations and protocol dependencies of each domain, as shown in Table 11.

[0120] Table 11 Target Domain With source domain Relationship table .

[0121] Coupling function Map the source domain belief mean to This function characterizes the coupling strength of the source domain uncertainty to the target domain. It decays to zero at the extreme values ​​and reaches its maximum at intermediate values, consistent with the non-saturation characteristic of cross-domain propagation.

[0122] Assume random disturbance term It follows a normal distribution with a mean of zero; the expected value is taken in the deduction. .under mean exist Taking the evolution calculation under certain conditions as an example, the evolution equation is as follows:

[0123] Intra-domain drift:

[0124] Coupled input: ;

[0125] Summation of coupling terms:

[0126] result:

[0127] The calculation process is similar for other cases, yielding the final deduction results for each action. As shown in Table 12.

[0128] Table 12 Final Calculation Results for the Defender .

[0129] This embodiment assumes that the variance of the belief distribution of each state component remains constant during the simulation time, that is: .

[0130] Sub-step S420, Attacker's Belief Evolution Deduction The attacker's dynamics model is symmetric to the defender's, and this embodiment uses the same intra-domain drift function structure. Cross-domain coupling matrix and coupling function The specific numerical settings for the drift function and coupling matrix are detailed in Section 5.1. The input is the attacker's belief parameters. Defender's candidate actions and the probability distribution of attacker's actions During the simulation, The point estimation is simplified, and the effects of the attacker's own actions are comprehensively incorporated into the simulation results.

[0131] Assume random disturbance term It follows a normal distribution with a mean of zero; the expected value is taken in the deduction. The following is based on mean exist Taking the evolution calculation under certain conditions as an example, the evolution equation is as follows:

[0132] Intra-domain drift:

[0133] Coupled input: ,

[0134] Summation of coupling terms:

[0135] result:

[0136] The calculation process is similar for other cases, yielding the final deduction results for each action. As shown in Table 13.

[0137] Table 13 Final Deduction Results of the Attacker .

[0138] This embodiment assumes that the variance of the belief distribution of each state component remains constant during the simulation time, that is: .

[0139] Sub-step S430, Calculation of expected entropy change The calculation methods for the defense entropy and attack entropy at time step are consistent with step S300, i.e., the Shannon entropy is obtained based on the discretized numerical integration of 401 grid points, and the KL divergence uses the Gaussian analytical formula. The input is the defense strategy derived in Section 5.1. Time mean parameter and variance And the attacking side derived in Section 5.2 Time mean parameter and variance .

[0140] Since the variance remains constant during the derivation, the Shannon entropy for each action is the same as that in step S300: The calculated KL divergences of the belief distributions of the defenders and attackers are shown in Table 14.

[0141] Table 14 KL divergence table of belief distributions for defenders and attackers. .

[0142] Take the trade-off coefficient ,by The attack entropy / defense entropy at any given moment is used as the baseline value. , The expected entropy change values ​​for each action were calculated and are shown in Table 15.

[0143] Table 15 Expected Entropy Change Table .

[0144] Step S500: Generation of Entropy Control Strategy Take the preference coefficient Based on the optimization objectives described in the technical solution, the comprehensive expected entropy change value of each candidate defense action is calculated.

[0145] For candidate actions The expected entropy change value as well as Substituting the optimization objective, we get:

[0146] For candidate actions The expected entropy change value as well as Substituting the optimization objective, we get:

[0147] For candidate actions The expected entropy change value as well as Substituting the optimization objective, we get:

[0148] Comparing the combined entropy change values ​​of the three candidate actions above, and based on the optimization objective described in the technical solution, the candidate action that minimizes this entropy change value is selected as the optimal defensive action, i.e.:

[0149] Therefore, the current moment is determined. The optimal defense strategy is That is, increasing the transmit power and enabling redundant channels, the corresponding overall expected entropy becomes .

[0150] The first comparative example A is provided below: Traditional threshold alarm method. Method Description: Deploy only single-domain threshold rules – when An alarm is triggered when the normalized threshold of 0.1667 (corresponding to a raw packet loss rate of 5%) is exceeded, and the alarm is manually assessed and handled by the on-duty dispatcher. The defender did not execute the closed-loop process from steps S100 to S500, but only... Perform localized processing.

[0151] Execution process: The dispatcher misjudged it as "switch port congestion" and executed a port restart. The mean temporarily dropped to 0.2000; however, electromagnetic interference persisted, and cross-domain coupling led to... , , It continues to worsen. The time-state parameters are:

[0152] in The average is the result of local treatment, because no treatment was performed. The average and The projections remained consistent. The variance, in turn, remained unchanged.

[0153] Quantization calculation: Since the variance remains unchanged, the Shannon entropy is still 22.1312 bits; calculate the KL divergence of each dimension according to step S300.

[0154] Table 16 KL Divergence Table .

[0155] Pick Under traditional methods, the defense entropy is:

[0156] .

[0157] Conclusion Analysis: Traditional methods lack the strategy selection mechanism described in steps S100 to S500. They rely solely on single-domain thresholds to trigger manual intervention, with actions determined by the scheduler's experience, without multi-domain belief updates, adversary mirroring, or expected entropy change assessment. In this scenario, the defensive entropy becomes... The system continues to deteriorate under the same initial conditions. This invention, under the same initial conditions, executes steps S100 to S500 to evaluate candidate actions. The expected entropy change, determine The optimal strategy is to reduce defense entropy. The above results indicate that traditional methods, lacking a strategy selection mechanism centered on uncertainty management, still lead to system deterioration even when local measures are implemented due to the failure to anticipate cross-domain transmission effects. This invention verifies the technical effectiveness of the entropy change-driven strategy selection mechanism described in steps S100 to S500 through a closed loop of "perception-deduction-decision-execution".

[0158] It should be noted that traditional methods lack the adversary mirroring and deduction mechanism described in step S200, and therefore cannot estimate the attacker's belief distribution. Therefore, attack entropy cannot be calculated. Furthermore, it is impossible to assess the entropy change of the attack. Its decision-making basis only contains local information in a single domain and does not form an entropy control objective with duality between offense and defense. The optimization objective of step S500 of this invention depends on both the entropy change of defense and the entropy change of attack. Traditional methods cannot reproduce this objective function due to the lack of mechanism, which further verifies the necessity of the mechanism described in steps S200 and S500.

[0159] The following is a second comparative example B: a method lacking cross-domain coupling terms. Method description: Perform steps S100 to S500, but in steps S410 and S420, set all cross-domain coupling coefficients... Only intra-domain drift terms are retained.

[0160] Execution process: For candidate actions Perform uncoupled derivation separately. For example, Intra-domain drift In the complete method, this value is subject to... Coupled conduction, in practice The deductions for all other actions and domains, as well as the deduction for the attacking side, are the same as step S400 in Embodiment 1, and will be omitted here.

[0161] Quantitative calculation: The mean of the defender's belief and the change in defense entropy corresponding to each action were derived using the uncoupled method, as shown in Table 17.

[0162] Table 17 Mean of Defender's Beliefs and Change in Defense Entropy .

[0163] Conclusion Analysis: The comparison between the complete method and the uncoupled method is shown in Table 18 below. In particular, the uncoupled method considers... This results in the largest decrease in defense entropy, according to predictions. This reduces the defense entropy to 12.9769 bits. (This appears to be a significant improvement; however, the complete method...) defense entropy The actual value is 22.7590 bits. (), instead of decreasing, it increased slightly.

[0164] Table 18 Comparison of Complete Methods and Uncoupled Methods .

[0165] The above results indicate that cross-domain coupling terms This is the key technical feature of the present invention for realizing realistic situational simulation and avoiding false convergence of strategies. Uncoupled methods, by ignoring the propagation of uncertainties between domains, lead to the defender severely underestimating the overall risk of the system, resulting in false convergence misjudgments where the expected entropy change shows a decrease, but the actual change increases due to coupling rebound.

[0166] In summary, this application has the following advantages: 1. It can achieve unified quantification of multi-domain heterogeneous uncertainties, improving the accuracy of situational awareness. This invention employs attack entropy and defense entropy as unified metrics for multi-domain heterogeneous uncertainty, quantifying heterogeneous uncertainties from different domains such as geography, electromagnetics, networks, and cognition under the same scale. Compared to existing single-domain or expert-based methods, this invention provides consistent and comparable quantitative data, thereby improving the accuracy of understanding the real security situation in multi-domain integrated scenarios.

[0167] 2. It can dynamically predict cross-domain coupling risks, enhancing the ability to anticipate cascading attacks. This invention explicitly introduces cross-domain coupling terms into the dynamic model, enabling quantitative deduction of the propagation and amplification process of uncertainty from one domain to other domains (e.g., electromagnetic interference causing network packet loss, which in turn triggers physical device malfunctions). Compared to existing single-domain or weakly coupled models, the discrete-time stochastic difference equations of this invention more closely resemble the discrete event characteristics of offensive and defensive confrontations, allowing the defender to predict the evolution trajectory of the system state in advance for different defensive actions, thereby enhancing the ability to predict multi-stage, cross-domain cascading attacks.

[0168] 3. It can generate strategies with uncertainty management as the core, thereby improving the adaptability of defense decisions. This invention transforms the theoretical concept of "reducing one's own entropy and increasing the enemy's entropy" into a calculable optimization objective, by adjusting the preference coefficient. This allows the defender to flexibly choose strategic priorities based on real-time mission requirements: when the system is in a high-risk state, it can prioritize reducing its own cognitive uncertainty to quickly converge to a safe zone; when the system is relatively safe, it can prioritize increasing the opponent's uncertainty to implement proactive defense. Compared to existing methods that only treat uncertainty as auxiliary information or background noise, this invention uses uncertainty management as the core driving force for decision-making, resulting in strategies with stronger adversarial adaptability and proactivity.

[0169] 4. It can estimate adversary behavior under incomplete information, improving decision robustness in multi-domain adversarial scenarios. This invention utilizes an adversary mirroring mechanism, enabling the defender to dynamically estimate the attacker's belief distribution and action probabilities based solely on their own observation history, even without direct knowledge of the attacker's observations and strategies. This mechanism helps the defender effectively predict the attacker's behavior in incomplete information warfare, reducing decision-making biases caused by information gaps and thus improving the robustness of the overall defense strategy.

[0170] 5. It can form a complete closed loop from perception to decision-making, reducing the cost of manual intervention. This invention organically integrates belief updating, entropy measurement, dynamics deduction, and strategy generation into an automated closed-loop process. The system can autonomously complete the entire process from data acquisition and situation assessment to defense action generation, without requiring manual judgment or intervention at each level. Compared to existing methods that only output security levels or alarm information and still require manual decision-making, this invention can significantly reduce response latency and the risk of human error.

[0171] like Figure 3As shown, this application embodiment also provides an electronic device 300, including a memory 310 and a processor 320. The memory 310 stores a computer program 311, and the processor 320 executes the computer program 311 to implement the above-described method. This electronic device can be a server, a computer, or a dedicated hardware platform, and its specific structure does not limit the implementation of this invention.

[0172] Other embodiments of this application will readily conceive of by those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. It should be understood that this application is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. An entropy-change-driven multi-domain fusion intelligent security method for cyberspace, characterized in that, include: The defender's belief parameters are updated based on the defender's own observations; Estimate the attacker's belief parameters and conditional probability distribution of the attacker's actions by mirroring the attacker's actions. Based on the defender's belief parameters and the attacker's belief parameters, an entropy value is calculated to quantify the situation of both sides, the entropy value including defense entropy and attack entropy; A discrete stochastic dynamic model containing cross-domain coupling terms is established to deduce the belief parameters of the defender and attacker at the next moment. Based on the deduced beliefs of both parties, the attack entropy and defense entropy at the next moment are calculated to obtain the deduction results of entropy value changes. With the goal of minimizing defense entropy and maximizing attack entropy, the optimal defense action is adaptively selected based on the entropy value change deduction results to generate an entropy control strategy.

2. The method according to claim 1, characterized in that, The update of the defender's belief parameters based on the defender's own observations includes: The defender obtains the noisy observation vector at the current moment by deploying heterogeneous probes in various domains; Based on the parameterized beliefs of the previous moment and the observation vector of the current moment, the defender updates and generates the parameterized belief distribution of the current moment through a filtering method, thus obtaining the defender's belief parameters.

3. The method according to claim 1, characterized in that, The estimation of the attacker's belief parameters and conditional probability distribution of the attacker's actions through mirror modeling includes: The defender infers the attacker's belief parameters at the current moment based on its own historical observation sequence and prior knowledge of the attacker, and uses these as estimates of the attacker's belief parameters. Based on the inferred subjective posterior belief distribution and the pre-set attacker decision model, the defender calculates the conditional probability of the attacker selecting each candidate action and outputs the conditional probability distribution of the attacker's actions.

4. The method according to claim 1, characterized in that, Establish a discrete stochastic dynamical model including cross-domain coupling terms to deduce the defender's belief parameters at the next time step, including: A discrete-time stochastic difference equation with the defender's belief distribution parameters as state variables is established to obtain the defender's discrete stochastic dynamic model. Mathematical expectation of the defender's belief parameters at the next moment, based on the defender's discrete stochastic dynamics model: in, Actions of the attacker The conditional probability distribution; This is the domain drift function from the defender's perspective, which characterizes the direct impact of defensive and offensive behaviors within the domain. Indicates the defending side's position on the first The belief parameter vector of the domain; Candidate actions for the defending side; The superscript represents the cross-domain coupling coefficient of the defending side. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the defensive coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; This is an independent random perturbation term for the defender.

5. The method according to claim 4, characterized in that, Establish a discrete stochastic dynamical model including cross-domain coupling terms to deduce the attacker's belief parameters at the next time step, including: Based on prior knowledge of the attacker, the defender adopts a dynamic model that is symmetric to the defender's discrete stochastic dynamic model as the attacker's discrete stochastic dynamic model. The candidate defensive actions currently being evaluated are input as the defender's actions into the attacker's discrete stochastic dynamics model to calculate the attacker's belief parameter components at the next time step: in, The drift function, cross-domain coupling coefficient, and coupling function from the attacker's perspective can be obtained based on prior assumptions about the attacker's behavior patterns or learned from historical data. For the attacker to the third The belief parameter vector of the domain; Candidate actions for the defending side; The defender's estimate of the attacker's actions is derived from the conditional probability distribution of the attacker's actions. Representative actions selected from the text; The cross-domain coupling coefficient of the attacker is indicated by a superscript. Indicates the target domain. This represents the source domain, i.e., the uncertainty originating from the source domain. To target domain The conduction strength; This is the attacker's coupling function, used to characterize the propagation effect of uncertainty from the source domain to the target domain; This is an independent random perturbation term for the attacker.

6. The method according to claim 1, characterized in that, The goal of minimizing defense entropy and maximizing attack entropy, and the adaptive selection of optimal defense actions to generate an entropy control strategy based on the entropy change deduction results, includes: Based on the entropy change deduction results, the optimization objective is solved using the following formula to select the optimal defensive action. ; in, For the set of candidate defensive actions; This represents the change in the defender's entropy value. This represents the change in the attacker's entropy value. This is the preference coefficient; Among them, when At that time, the optimization objective degenerates into The defender only focuses on reducing its own defense entropy, which is suitable for scenarios where the system is in a high-risk state and needs to be restored to stability first; when At that time, the optimization objective degenerates into The defender focuses solely on increasing the attacker's attack entropy, that is, confusing the opponent by actively injecting uncertainty; when At that time, the defender weighs the reduction of its own cognitive uncertainty against the increase of the opponent's cognitive uncertainty.

7. An entropy-change driven multi-domain fusion intelligent security device for cyberspace, characterized in that, include: The update unit is used to update the defender's belief parameters based on the defender's own observations. The mirror simulation unit is used to estimate the attacker's belief parameters and the conditional probability distribution of the attacker's actions by performing mirror simulation on the attacker. The calculation unit is used to calculate the attack entropy and defense entropy based on the defender's belief parameters and the attacker's belief parameters. The dynamics deduction unit is used to establish a discrete stochastic dynamics model containing cross-domain coupling terms, deduce the belief parameters of the defender and attacker at the next moment, and calculate the attack entropy and defense entropy at the next moment based on the deduced beliefs of both parties, and obtain the deduction results of entropy value changes. The strategy generation unit is used to generate an entropy control strategy by adaptively selecting the optimal defense action based on the entropy value change deduction result with the goal of minimizing defense entropy and maximizing attack entropy.

8. An electronic device, characterized in that, include: Memory and processor; The memory is used to store computer instructions; The processor is configured to invoke computer instructions stored in the memory, causing the electronic device to perform the method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • A computational method for uncertainty measurement of network attack and defense based on entropy

    CN118233221B

  • Network attack and defense effectiveness judgment method based on Lyapunov stability theory

    CN122053175A